commit ccd1b6a1a946695c3f089745f7c827aef50fa91c
parent b56ba517df3f6e6f5c4752975aa24bc639869d49
Author: MTRNord <mtrnord1@gmail.com>
Date: Mon, 15 Jul 2024 08:41:53 +0200
Cleanup
Diffstat:
70 files changed, 0 insertions(+), 29020 deletions(-)
diff --git a/apps/2024_cluster/namespaces/kustomization.yaml b/apps/2024_cluster/namespaces/kustomization.yaml
@@ -4,7 +4,6 @@ resources:
- monitoring.yaml
- matrix.yaml
- postgres-operator.yaml
- - mailu.yaml
- authentik.yaml
- traefik-ingress.yaml
- vaultwarden.yaml
diff --git a/apps/2024_cluster/namespaces/mailu.yaml b/apps/2024_cluster/namespaces/mailu.yaml
@@ -1,4 +0,0 @@
-apiVersion: v1
-kind: Namespace
-metadata:
- name: mailu
diff --git a/apps/base/forgejo/keydb.yaml b/apps/base/forgejo/keydb.yaml
@@ -1,49 +0,0 @@
----
-apiVersion: apps/v1
-kind: Deployment
-metadata:
- name: forgejo-keydb
-spec:
- replicas: 1
- selector:
- matchLabels:
- app: forgejo-keydb
- template:
- metadata:
- labels:
- app: forgejo-keydb
- spec:
- containers:
- - name: forgejo-keydb
- image: eqalpha/keydb:latest
- command: ["keydb-server"]
- args: [ "/etc/keydb/keydb.conf", "--protected-mode", "no"]
- imagePullPolicy: Always
- ports:
- - containerPort: 6379
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- livenessProbe:
- exec:
- command:
- - sh
- - -c
- - keydb-cli ping
- initialDelaySeconds: 10
- timeoutSeconds: 5
----
-apiVersion: v1
-kind: Service
-metadata:
- name: forgejo-keydb
-spec:
- selector:
- app: forgejo-keydb
- ports:
- - name: redis
- protocol: TCP
- port: 6379
- targetPort: 6379
diff --git a/apps/base/forgejo/kustomization.yaml b/apps/base/forgejo/kustomization.yaml
@@ -1,8 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: forgejo
-resources:
- - repository.yaml
- - release.yaml
- - ssh-ingress.yaml
- - keydb.yaml
diff --git a/apps/base/forgejo/release.yaml b/apps/base/forgejo/release.yaml
@@ -1,158 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: forgejo
- namespace: forgejo
-spec:
- releaseName: forgejo
- chart:
- spec:
- chart: forgejo
- sourceRef:
- kind: HelmRepository
- name: forgejo
- interval: 50m
- timeout: 25m
- install:
- timeout: 25m
- remediation:
- retries: 3
- values:
- # image:
- # # Codeberg.org was down.
- # registry: docker.io
- # repository: mtrnord/forgejo
- # # Overrides the image tag whose default is the chart appVersion.
- # tag: "1.20"
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- containerSecurityContext:
- capabilities:
- add:
- - SYS_CHROOT
- signing:
- enabled: true
- privateKey: ENC[AES256_GCM,data:20d2bEsxqwbpUYJX3LBifuN4adZ9qTRX5jk5L4Cj+Rx//zftxSLm6YQYG6zCuRbzHlLZufmU783fiwExGoapAgY8+8JAYxMwr58s/2Rqwps5Sacvf80R6VNglD1dxnYPkT5goltRckSDwOCylplc1jy9inD/gkW3YPbJ44j0tqpyxFQYy5Q+GhhgUWoBAIyEQJpdvCF8pF0ISFvfV8G2oHIOpCOqZSHmxUjZNfqZmqnUQ3f+kj8jTBD9bhqW0D8Zy+wKROQs5UaKTe5RBC6ihfcomdWvDAU36x2YFzPj3APm+lGxh6SWGooL25BCrQ8bpe+TWJF/TvSm/HREfyLVTAhYbTfyjLOTpQrBX45DO03yjafjvcCizn98gd3QHPH6HAJDdvXgOoFZLY44lEEc0skRbHb25SLrBwTZ5lTGcBFY7e46fL61N0/WwXbWqX2uoN4NZiYvZV5z/y6Hdk8yp/9xVhbsDAtR6uRUMiXl40Hse4U1mR5Mk7HzKn/8mmyNyYKwUGJ4M3MADsv73ZbsbVd64CaXGFkB3JGWHcroveIvLCuqrgjUU/JJc32pJboFVKrHCeJDFbScSHWThapxHV2S57qz+OrcVOhVwiUk2vNr+NPE1QsT6Eh0vcfFrhZZK3PLNPlA17yO7Wfiyc20M022Mzwog2GlkUiRz4q/H0WyvYDi8pJoHHVHVYIoDC+K4jpeStf9y4g0LrOyzfwrFj2K+BI5QWqC+URi6GC16MvjYQ4vottNpcNuaT6jPBu+vqDhEaS40z7slA1oNjhc5mgGkjdk4PIV5NXKowL9qiiKF+ShjNCYIwKFfkFtqsRXhf+/GzCPcZvl7ZGzO9Ow02gCdvxeVwbw9CmnjsRbnztBnUzLlnTpff9u5rLAz64wdpLNqN62icxeJI5z2ubAyLamE/KOAweUuQMqx753gQyX2tce2zUys8yozFjeclW+F9gB2q8kXt10mxpBPYV6L4ayBCoJ4mbhjWYKhWScS36sUMk1MZVvoQ==,iv:SDi95tvmeMtKbxztu+4GzoPXftDh6FF5cVD3N4Pycv4=,tag:GRZHHP3JoWsSQ3mlXI97CQ==,type:str]
- persistence:
- enabled: true
- create: false
- size: 50Gi
- claimName: data-forgejo-0
- ingress:
- enabled: true
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- hosts:
- - host: git.nordgedanken.dev
- paths:
- - path: /
- pathType: Prefix
- tls:
- - secretName: git.nordgedanken.dev-tls
- hosts:
- - git.nordgedanken.dev
- gitea:
- oauth:
- - name: keycloak
- provider: openidConnect
- key: gitea
- secret: ENC[AES256_GCM,data:2EzV0JrdQkfAWrteqkgnzHwzAC4Z5tB0T9Cp3Xr/9Jg=,iv:gKdEFfBbA/0xnqoIY5O7SWWarKTvZFTjv/86MCsaJx0=,tag:AKF529TrCfEtnCavlmB9AQ==,type:str]
- autoDiscoverUrl: https://keycloak.midnightthoughts.space/realms/Gitea/.well-known/openid-configuration
- admin:
- username: gitea_admin
- password: ENC[AES256_GCM,data:5Y4Ux8kv7/9P1jh3rdO3QadnJeaTgYU/xaR9gVT9x85nhpKjcAi49ln1h5s/08VBUQnWRWh61o8knReqdt816g==,iv:M27y3zNX6goC6rdkojmY/YocaQYzm3fODKmVg7ojkYU=,tag:Ywn3YTY8yzM3gvLsMmwxiQ==,type:str]
- email: ops@nordgedanken.dev
- metrics:
- enabled: true
- serviceMonitor:
- enabled: true
- config:
- time:
- DEFAULT_UI_LOCATION: Europe/Berlin
- security:
- INSTALL_LOCK: true
- metrics:
- ENABLED: true
- ENABLED_ISSUE_BY_REPOSITORY: true
- ENABLED_ISSUE_BY_LABEL: true
- actions:
- ENABLED: true
- DEFAULT_ACTIONS_URL: https://git.nordgedanken.dev
- indexer:
- ISSUE_INDEXER_TYPE: bleve
- REPO_INDEXER_ENABLED: true
- repository:
- MAX_CREATION_LIMIT: 0
- DISABLE_HTTP_GIT: false
- service:
- DISABLE_REGISTRATION: true
- ALLOW_ONLY_EXTERNAL_REGISTRATION: true
- DEFAULT_KEEP_EMAIL_PRIVATE: true
- oauth2_client:
- ENABLE_AUTO_REGISTRATION: true
- server:
- ROOT_URL: https://git.nordgedanken.dev
- SSH_PORT: 2222
- LFS_START_SERVER: true
- START_SSH_SERVER: true
- federation:
- ENABLED: true
- mailer:
- ENABLED: true
- FROM: ops@nordgedanken.dev
- SMTP_ADDR: mail.nordgedanken.dev
- SMTP_PORT: 465
- PROTOCOL: smtps
- USER: ops@nordgedanken.dev
- PASSWD: ENC[AES256_GCM,data:6m3GRvlNGctk,iv:dM2bgyjzeRWMZqOcslZXQBYYGiKzATh90xKJZq8CErs=,tag:xjFGdeXbn4/Mx1RKNDpBxg==,type:str]
- session:
- #PROVIDER: redis-cluster
- PROVIDER: redis
- PROVIDER_CONFIG: redis://:@forgejo-keydb.forgejo.svc.cluster.local:6379/0
- #PROVIDER_CONFIG: redis+cluster://:@forgejo-redis-cluster-headless.forgejo.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
- cache:
- ENABLED: true
- ADAPTER: redis
- #ADAPTER: redis-cluster
- #HOST: redis+cluster://:@forgejo-redis-cluster-headless.forgejo.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
- HOST: redis://:@forgejo-keydb.forgejo.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s
- queue:
- TYPE: redis
- #CONN_STR: redis+cluster://:@forgejo-redis-cluster-headless.forgejo.svc.cluster.local:6379/0?pool_size=100&idle_timeout=180s&
- CONN_STR: redis://:@forgejo-keydb.forgejo.svc.cluster.local:6379/0
- database:
- DB_TYPE: postgres
- HOST: matrix-postgres-cluster.matrix-postgres-cluster.svc.cluster.local:5432
- NAME: forgejo
- USER: forgejo
- PASSWD: ENC[AES256_GCM,data:0E4NT/jY+UcxJ25IO08dhgz/Y4QqWOLBY5GSVIOW3UgCfWS49StMROV79kzu+wG3S+xVRMU7+fbTr7j2GSxp2w==,iv:xVtsyZUxQhocVZyIg4YreS+AFs8mMqZUU+W1dJscNm0=,tag:QHaBEgG17e9RTbm0ZsTIiA==,type:str]
- SSL_MODE: require
- redis-cluster:
- enabled: false
- postgresql-ha:
- enabled: false
- postgresql:
- enabled: false
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBoRzR6TjZzR0pXcC9GYTlR
- SzlRSVpaNytvVnc4cEJxZHFrK1pnUkNWM0ZnCis1UFEvS21rU01SNndYelBlS1FD
- eEM1aWpuYVhiaFY1RjBjTU5qN2MvQkUKLS0tIFVOR1F2MjFXWmN2MjVIUnFYYklv
- TnBmQTVYY2FTM1NFNE1jaUx1S3RrL0kKYNECp/as/AeFWSXQ2fPFNASo7P9iVpXo
- aShkQPsML/OZqzNZXeQXY8EoLwrcNDEKlXUYPbKykw8NvQLpNCevRw==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-04-21T13:24:07Z"
- mac: ENC[AES256_GCM,data:orjdbynwyPnhVHbBqZI0lD0xS77cTYEsVxSNjOHMZvCIDiBMv99TQd6AkTjjd3/4F4RXefIGoBlGCouc3IXG9R6sO3pX3zn0vInnSKBcMdkwV0kK7SfBCBQhL2+PTjw+IaJfEU5EdKFM+4V5ORj7M7Tbagy/xa6RpVME9FJBtLc=,iv:QJf6Cmbyic80zE27l/bhgeDSZLrQHFsMAiaxaK3qyuQ=,tag:pMmNikXkp7+QpdYo+pHESg==,type:str]
- pgp: []
- encrypted_regex: ^(PASSWD|AUTHENTICATION_PASSWORD|ROOM_API_SECRET_KEY|adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
diff --git a/apps/base/forgejo/repository.yaml b/apps/base/forgejo/repository.yaml
@@ -1,10 +0,0 @@
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: forgejo
- namespace: forgejo
-spec:
- interval: 5m
- url: oci://codeberg.org/forgejo-contrib
- type: "oci"
diff --git a/apps/base/forgejo/ssh-ingress.yaml b/apps/base/forgejo/ssh-ingress.yaml
@@ -1,14 +0,0 @@
----
-apiVersion: traefik.containo.us/v1alpha1
-kind: IngressRouteTCP
-metadata:
- name: forgejo-ssh
- namespace: forgejo
-spec:
- entryPoints:
- - ssh
- routes:
- - match: HostSNI(`*`)
- services:
- - name: forgejo-ssh
- port: 22
diff --git a/apps/base/keycloak/kustomization.yaml b/apps/base/keycloak/kustomization.yaml
@@ -1,6 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: keycloak
-resources:
- - repository.yaml
- - release.yaml
diff --git a/apps/base/keycloak/release.yaml b/apps/base/keycloak/release.yaml
@@ -1,89 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: keycloak
- namespace: keycloak
-spec:
- releaseName: keycloak
- chart:
- spec:
- chart: keycloak
- sourceRef:
- kind: HelmRepository
- name: keycloak
- interval: 50m
- timeout: 25m
- install:
- timeout: 25m
- remediation:
- retries: 3
- values:
- auth:
- adminUser: MTRNord
- adminPassword: ENC[AES256_GCM,data:gfpevRlVAOcq,iv:4Hkn2IjthQ2JAF9tYb3/ocTkqpCgn1j8vk2Ds6VW8HQ=,tag:v6RwHKC52VuFQOLuKJalpQ==,type:str]
- ingress:
- enabled: true
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- hostname: keycloak.midnightthoughts.space
- tls: false
- extraTls:
- - hosts:
- - keycloak.midnightthoughts.space
- secretName: keycloak.midnightthoughts.space-tls
- extraEnvVars:
- - name: KEYCLOAK_PROXY_ADDRESS_FORWARDING
- value: "true"
- - name: KEYCLOAK_FRONTEND_URL
- value: https://keycloak.midnightthoughts.space/
- - name: KC_HOSTNAME_URL
- value: https://keycloak.midnightthoughts.space
- - name: KC_HOSTNAME_ADMIN_URL
- value: https://keycloak.midnightthoughts.space
- metrics:
- enabled: true
- serviceMonitor:
- enabled: true
- postgresql:
- enabled: true
- auth:
- username: bn_keycloak
- password: ENC[AES256_GCM,data:6d7TKB1J3va5dQ==,iv:LSMR5zxU6oxJ3mCGMOtQBKATNaKFUZE2uf5BaKxJc44=,tag:AmGi5mBqxvarQU+MPWxiIg==,type:str]
- database: bitnami_keycloak
- architecture: standalone
- image:
- tag: 14-debian-11
- primary:
- persistence:
- storageClass: nfs-csi
- existingClaim: data-keycloak-postgresql-csi
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSAxbFVtOW52Sm03NkEyQ2tp
- WTdBbEJ6cU8ycndPN0VNVnI4Z2hnaCtpVnpBCmp6TmtwN0p4ZG9aOVJRYW9pRktC
- RGR0QjhFVEtyb1A1bHNlRjF4S0NGVlUKLS0tIGdsZUppZ1EyL3ppNXgwSkc2ZklH
- TzJqMkFsZ0l2aldNdFlrM3VMbk1jWUEKMRRltSz2onYx+PXmun444runEechmpB5
- KSEctI7OQIPmG/nV/UcypT9XXpvrB2C0grdQDDWgC9FOyDHbJpESFg==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-01-25T09:25:43Z"
- mac: ENC[AES256_GCM,data:bJH2QE2/r4sPgn/EpRDxhDERfjbcM7MXyHHYtWc+iiQ2Jrwd93wgGhZiXcqUnuDP9dZrMwygqymWRzqtfYwsZ3k2innXyENYaBnDpkFSosY3+Ok5bUdEyl2i+x0SA1qkX5PohPuW0Og4cDV6DuBHddGit/vg3pNzXC2/35fgwdI=,iv:WMPFznUOC6XxXsvbfKOeowrJscLBn0Lg2u1LvBQOBbc=,tag:7tTw7+4IcSVkMq5jZTZ5sw==,type:str]
- pgp: []
- encrypted_regex: ^(adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
diff --git a/apps/base/keycloak/repository.yaml b/apps/base/keycloak/repository.yaml
@@ -1,9 +0,0 @@
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: keycloak
- namespace: keycloak
-spec:
- interval: 5m
- url: https://charts.bitnami.com/bitnami
diff --git a/apps/base/kube-prometheus-stack/kustomization.yaml b/apps/base/kube-prometheus-stack/kustomization.yaml
@@ -1,7 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: monitoring
-resources:
- - repository.yaml
- - release.yaml
- - minio_loki_metrics.yaml
diff --git a/apps/base/kube-prometheus-stack/minio_loki_metrics.yaml b/apps/base/kube-prometheus-stack/minio_loki_metrics.yaml
@@ -1,34 +0,0 @@
----
-apiVersion: monitoring.coreos.com/v1
-kind: ServiceMonitor
-metadata:
- name: minio-cluster
-spec:
- selector:
- matchLabels:
- v1.min.io/tenant: loki
- endpoints:
- - port: https-minio
- path: /minio/v2/metrics/cluster
- scheme: https
- interval: 30s
- tlsConfig:
- serverName: minio.monitoring.svc.cluster.local
- insecureSkipVerify: true
----
-apiVersion: monitoring.coreos.com/v1
-kind: ServiceMonitor
-metadata:
- name: minio-buckets
-spec:
- selector:
- matchLabels:
- v1.min.io/tenant: loki
- endpoints:
- - port: https-minio
- path: /minio/v2/metrics/bucket
- scheme: https
- interval: 30s
- tlsConfig:
- serverName: minio.monitoring.svc.cluster.local
- insecureSkipVerify: true
diff --git a/apps/base/kube-prometheus-stack/release.yaml b/apps/base/kube-prometheus-stack/release.yaml
@@ -1,773 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: kube-prometheus
- namespace: monitoring
-spec:
- interval: 5m
- chart:
- spec:
- version: 58.1.x
- chart: kube-prometheus-stack
- sourceRef:
- kind: HelmRepository
- name: prometheus-community
- interval: 60m
- install:
- crds: Create
- upgrade:
- crds: CreateReplace
- # Force recreation due to Helm not properly patching Deployment with e.g. added port,
- # causing spurious drift detection
- force: true
- # https://github.com/prometheus-community/helm-charts/blob/main/charts/kube-prometheus-stack/values.yaml
- values:
- prometheus:
- prometheusSpec:
- retention: 365d
- secrets:
- - prometheus-asterisk-secret
- additionalScrapeConfigs:
- - job_name: asterisk
- scheme: https
- basic_auth:
- username: asterisk
- password_file: /etc/prometheus/secrets/prometheus-asterisk-secret/asterisk-secret
- static_configs:
- - targets:
- - pbx.midnightthoughts.space
- resources:
- requests:
- cpu: 0m
- memory: 0Mi
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- enableRemoteWriteReceiver: true
- podMonitorSelectorNilUsesHelmValues: false
- serviceMonitorSelectorNilUsesHelmValues: false
- storageSpec:
- volumeClaimTemplate:
- spec:
- storageClassName: nfs-csi
- accessModes:
- - ReadWriteMany
- resources:
- requests:
- storage: 25Gi
- selector: {}
- alertmanager:
- alertmanagerSpec:
- useExistingSecret: true
- namespaceOverride: monitoring
- grafana:
- adminPassword: ENC[AES256_GCM,data:L6yfEaJ0gYc3JaL+xnqeoSynhU+HbhC+iaM2xRh0yiFgDUXFaEoNZI7cur4nlrsmEj8OPetKUdDpD6MRm+jzQg==,iv:ZH3MhJUlSmIzBxZ4WcAtBkcVfu75R3jfMer7Cep2B5s=,tag:K7eJ4h50NVW0XBr96U/byA==,type:str]
- alerting:
- rules.yaml:
- apiVersion: 1
- groups:
- - orgId: 1
- name: Kube-system
- folder: Cluster
- interval: 1m
- rules:
- - uid: d2b94d3a-2483-4be4-bf2a-2fd9f9fac406
- title: Coredns Failure
- condition: Thresh
- data:
- - refId: ENC[AES256_GCM,data:XrjbgFM=,iv:ZRUDAfC4h/car2MYVXMPGndkhs7CU/PD0f4xynCw1Ss=,tag:z+qURh9xZ/NTH8Sl8tKsKg==,type:str]
- queryType: ENC[AES256_GCM,data:C7gCmXw=,iv:IlE3u7K9RQMhXapeS/CkbRaIFZi6I33cPlzcUkVkCHg=,tag:GxQyI/owsu/LPv7uXyCvZQ==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:CX6O,iv:ILNXt63GERzWFkuofr6Lyvl/D2lXcWw9+dgnQF3FA+M=,tag:DrxiC7cDyGRh5Km0aK3cqA==,type:int]
- to: ENC[AES256_GCM,data:Fg==,iv:7zIMfA/lL9cN7ikBxTNDMBX0FIlVFiC1yjdF/xQne6c=,tag:cRymIdceGkqRwq+bLFdGwg==,type:int]
- datasourceUid: ENC[AES256_GCM,data:vAVJjw==,iv:1O5oFo+S4wT2/+wBYXkI1oE3Ds/E9XCi3DWHq6jAmAI=,tag:MER2rAWUceZIx2NmMuP30A==,type:str]
- model:
- datasource:
- type: ENC[AES256_GCM,data:CEVBNw==,iv:Gcn2ucS8gon9St5EGiBJwAGeoGj6ETo9+IiZlXi7d1U=,tag:mmEMJ+2OPgQL94/DlXNd1A==,type:str]
- uid: ENC[AES256_GCM,data:ozw52A==,iv:n3i6R5pkLJ3LPau4/cTeeKC9uii3mnUYWBs+X908Gl4=,tag:c4D0lyT6TV21ncyjpbKUeQ==,type:str]
- editorMode: ENC[AES256_GCM,data:HbsbFgxkXA==,iv:v5DwuwMRGmFcUsqPHO4jixgRqEaTPyxUBmpeyLjhYWE=,tag:ycfVYJqCoEHInJx6Qyg10w==,type:str]
- expr: ENC[AES256_GCM,data:AIunUBCr7jSn5p7k7dPsTHX/xD+8Gmv6iM2fL/suETlrxLBQUj6wDsdDyPSKbLxzYeC2oJmgZbREod61YXF9tjzKmHS1,iv:hlC+dIyVHn76lDP5rdeNS2b8EIOwiWdEuovpAXJ6WVQ=,tag:G/XZoStg6kiIIBEn13H47g==,type:str]
- hide: ENC[AES256_GCM,data:gBMVeKg=,iv:tnxlGc+/w6ahqD+wepXioYQZAxmvwnhqoo4duxaEApA=,tag:R24UdUpeTHZ/OVbv8ezNAQ==,type:bool]
- intervalMs: ENC[AES256_GCM,data:W8G1Uw==,iv:WYgu5qL6bqtTe+kRT1GhUndSyBcV744FDlTQd4G4bgI=,tag:sLEviVLD6MoyT3VjEuFHqQ==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:3pe0/Q4=,iv:KUa5KsgMPwchD9UPRZy6QHAM57MAs5dN4wVNtrKueBw=,tag:GYV3iymoEx4ax87jr0c8Sg==,type:int]
- queryType: ENC[AES256_GCM,data:wLaQly4=,iv:8U+3M6GC1f3IgiI3/xcPjWTjreyYPi0vk9WupF4kAbE=,tag:gN9J4BmoFho6NOiFLqIv6Q==,type:str]
- range: ENC[AES256_GCM,data:T0KJVQ==,iv:DVefQmbPmmG5hhmEQP3EUiogrJXj09NqWYyh2CZvNW4=,tag:KVE0oKRt7JrMlLmXAaZ+fQ==,type:bool]
- refId: ENC[AES256_GCM,data:hyayqjk=,iv:4Or92QiO9QFPEDmzrzukRp+iKDSks/ZoAS2K7e+Q9vQ=,tag:iXgXzgFKQla7Hh66pIP8Xw==,type:str]
- - refId: ENC[AES256_GCM,data:ffoL/Uce,iv:+ERAPgggoOGv7a25/wTMlLBd8aG32sqFPCoC1WT/26I=,tag:11wCZGe3aaNeRstfPO2wYg==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:MBgn,iv:BHNhIOwza4PMAwItrxYh/1z4m3LL1/ojlSLDNkhtwLE=,tag:memlRggdOCudIak87ak2NQ==,type:int]
- to: ENC[AES256_GCM,data:6w==,iv:rXddawBZ1SgbNeRbGwMfqcJt/FXSFDiH1y+ZwFxNU3A=,tag:eaRSoDAOmY/hBZbiROV7Lg==,type:int]
- datasourceUid: ENC[AES256_GCM,data:OzLGMcilpKk=,iv:c7YsfiLIvizCzAq21uMD1lx9NWJv0InFPcWGenvqNW4=,tag:62WBI+Z2X11leVlFVmDmxg==,type:str]
- model:
- conditions:
- - evaluator:
- params:
- - ENC[AES256_GCM,data:Uw==,iv:wZZ7Zi4R3VZhraPhZZBvsqja+1z/RBaRJVXUGXjfm7k=,tag:5Pocp+nAdKa9DV2PXNMbTA==,type:int]
- type: ENC[AES256_GCM,data:ChA=,iv:71SKoBCYCNBdnF346KsLKYNSnS+xOhCL82OBNt6nG9k=,tag:AxwQ1RmlwyrHqpJLCYwNyQ==,type:str]
- operator:
- type: ENC[AES256_GCM,data:K+Dz,iv:zgws46i9KUoeKbQUkMqzM0A0YevkjHvAqcvcoyNEzcY=,tag:Cj70wkzLOZKdtXPG+jmPPw==,type:str]
- query:
- params:
- - ENC[AES256_GCM,data:XA==,iv:TLeSOpvzk7pMmNJ2Dun8C+GCcn3b7BfpsVBoglbKMPk=,tag:HEScGNCn+N3xquekG9/nOQ==,type:str]
- reducer:
- params: []
- type: ENC[AES256_GCM,data:tiwMeg==,iv:wHUrQ0uQuihfpjTA4rVx3qQIj+wQ3+5Q0lwOLvD2wHg=,tag:EiZ5qDA6XGjDxGvKty3F8g==,type:str]
- type: ENC[AES256_GCM,data:2vi4wQA=,iv:wl+qq4l4bGOwnlBi11dQb/mXoNDdjKGg+JzNMTGNQS8=,tag:9e/TB+Glffc9APp7WuQMIw==,type:str]
- datasource:
- type: ENC[AES256_GCM,data:6vKoZmvVa98=,iv:LDWymRVZBz+yn4aTrO8f4EZXoeQBA8seZMT4ICydA5Y=,tag:mgA88dKdbM7F+CkL7/+Zbw==,type:str]
- uid: ENC[AES256_GCM,data:Ef3WlIDVFtk=,iv:4k/1/JScSEmJRzls/4fga+K5udKFE88K91b2fEkrOyk=,tag:eNaPgqmpGYM9EcxCX1GPJw==,type:str]
- expression: ENC[AES256_GCM,data:sQ==,iv:xB8BzVnrXSQ5lbyC0puBzsHTXfTJQeRou1OYbxYkjoE=,tag:JSsxvkLDh79vOPR2Adsi3Q==,type:str]
- hide: ENC[AES256_GCM,data:XccfM5E=,iv:Uy14SksmY0ML412FA26CuzZ/kbFEP329xByKIQ4LkqI=,tag:Hg4bPjSVhmYOc9kwiBHxoQ==,type:bool]
- intervalMs: ENC[AES256_GCM,data:VG25kQ==,iv:WYjoOc/LYkXalKf+g1k7xbLPQhqWwpMtb/uZskv1eRY=,tag:y6sOrTPcZWlrkj5geOLPSg==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:KITzqzQ=,iv:3MKxIAc1GCqOwOPmCvg1cdIRbcNadjm9dlEd5uEkhTA=,tag:4ndHC6s6rGcpX0ZL4ZN0Gw==,type:int]
- refId: ENC[AES256_GCM,data:9zUySsxb,iv:aIK6gU/pgmMWrvwB3J0BrSEn/D47KzGgFcDaY3L/OMQ=,tag:M/e8C/PwdKBww3gRftrQXA==,type:str]
- type: ENC[AES256_GCM,data:jyRvo1HSC9eb,iv:/DBCMCWbUkP9k4FnN38vZnLZ8ZstGiYjAGSTp8Kz/Bc=,tag:4pjWAeIxfAeHU+Ds5TYAhA==,type:str]
- - refId: ENC[AES256_GCM,data:ag==,iv:YyD/tNAUC4hLYT5MyUd3TPvY3RRRgtgQw2DfpS4E6xQ=,tag:K7jyzgxTvCwdKEBzflJyuw==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:/xg4,iv:pQCtinVXqyfOb25xj8tfXTz8bZX6V29it9faJIYDJlI=,tag:pnGKHFMKGRhnTv72Tv6BRw==,type:int]
- to: ENC[AES256_GCM,data:JA==,iv:bENsUizlR/VL2DyIGGp4LeOjSLNnoQHbOKg3WoA8t6I=,tag:1Khp5hndp4tyWMOfUWwdHg==,type:int]
- datasourceUid: ENC[AES256_GCM,data:xWr9mL5WsyE=,iv:r3Vjb7pP8PwfM7+W3UtnB9qV13B10yl/EHNo3RYJCIw=,tag:fZUrhNhuzADepE3NzPTi5w==,type:str]
- model:
- conditions:
- - evaluator:
- params:
- - ENC[AES256_GCM,data:EQ==,iv:wJdZMTzTX+Za8wYLW0Ka6xy6MN2PSIgwY/iBHiaOzv8=,tag:FRoGJkYVHz097u6stScQOw==,type:int]
- - ENC[AES256_GCM,data:2Q==,iv:WFKEKa3GQVc6t1nvs+md6n2we4nKrNMOmOX2Px1o1z4=,tag:EQ+0Zb6bCIHjyYklA5zwIA==,type:int]
- type: ENC[AES256_GCM,data:qmY=,iv:Ym/udyMtYOEWN9cLeK2jBE2eNrdr8llqVaaP20Ohm68=,tag:qPkAcpexa9DcYz6qPOoGMg==,type:str]
- operator:
- type: ENC[AES256_GCM,data:34ar,iv:AspAEd2NTpunmFpSmUG+eHFT9V5HpI3AZ/zbDt4OPgI=,tag:frf1r9SXw4/rDsFe3meopA==,type:str]
- query:
- params: []
- reducer:
- params: []
- type: ENC[AES256_GCM,data:36Gi,iv:TnANgljyRltQo7Q9/g3/tzeT/YLnUJTmVsbbQi7Eo34=,tag:iuR1MYoGKB261/N3jCzMlQ==,type:str]
- type: ENC[AES256_GCM,data:66BVygI=,iv:boozxqdHUr5xuVXKHs64+VZFAuXdxJkG+iub0xXYKhU=,tag:dKBLe8DAHWvZkvqMfLBmCg==,type:str]
- datasource:
- name: ENC[AES256_GCM,data:g8Y17p88Dmsd7Q==,iv:ADOGfVVJoR/ZBHyfES1bqJAmUAEwGvRZCl7iaj8f3Vg=,tag:bRFOXJgCBNm7F9BdaM5aVQ==,type:str]
- type: ENC[AES256_GCM,data:H8+sNxhWZjw=,iv:3V+wpINK60hdXEtCvUVmY5TxTLeKlnxW4T+BaeT8VlQ=,tag:eT0KDbowKW4YvFrCbHJrAQ==,type:str]
- uid: ENC[AES256_GCM,data:TAS9UtKKIlo=,iv:13bcWcqa7Vze0aZYDyEbzeBNXUsZI7OOGQNn5zBQeMk=,tag:ePNX6wcE9YdmXsRFOWdQdw==,type:str]
- expression: ENC[AES256_GCM,data:D8DnPUE=,iv:1n46Bh7Z5AGQ68TCVQwXerByr9Pb73cYOv76K79a5Wo=,tag:+JgDzR7Wec1gE5EOo3gOHg==,type:str]
- intervalMs: ENC[AES256_GCM,data:CnMBDw==,iv:wC5eEmYcJjv2WO6uhGF8wiq4Ad0LWEYRhKclUGREyUQ=,tag:Cdji1suDqaMhXmCL5Rz/5Q==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:8IVZ2TI=,iv:0eNgp5msgfGQW65DuySRrTX+TXHwmUcNaPp/SRjEg38=,tag:JrbATjsqGhyaX4PXr19oUQ==,type:int]
- reducer: ENC[AES256_GCM,data:F4cG0w==,iv:QT1eo7L8V6dYs8sHaZm5rISXgAs1318osSnYMBaLfaw=,tag:+WI4XCJtNb6KXVpO1n/PUw==,type:str]
- refId: ENC[AES256_GCM,data:Tg==,iv:Z0IxT/jQDHE9ag3QplzsCnCYTDMYVDv581sYC0BYl+g=,tag:DykKRmUid8CNL5+QFyO28A==,type:str]
- settings:
- mode: ENC[AES256_GCM,data:4ASz4oPaofKA,iv:V9i4J4EYeB0UltpbLI8lci9s3tawgLpi5FAJfEhSDeI=,tag:Eq5UEed2FcA89W4a3YGhmQ==,type:str]
- replaceWithValue: ENC[AES256_GCM,data:kg==,iv:NMtyi7kizRzXIgtD09rp4lpm5FsaOpIgvsUB6hLuDEM=,tag:rHTxbq85PpfvcYOQK9qNWw==,type:int]
- type: ENC[AES256_GCM,data:MRA4PK1O,iv:5bYhHG0lR8Qbmc7fb6g/VA6SUUkI1sw9F/hbAqc990w=,tag:8hmCZZCFzNynvR/0e+bv3w==,type:str]
- noDataState: OK
- execErrState: Error
- for: 5m
- annotations:
- summary: High amount of i/o timeouts in coredns
- isPaused: false
- - orgId: 1
- name: Matrix Synapse
- folder: Matrix
- interval: 1m
- rules:
- - uid: b6db960c-c0bd-4d4f-b0f1-e1f216ec81cc
- title: DNSQueryRefusedError
- condition: Thresh
- data:
- - refId: ENC[AES256_GCM,data:FQuje9c=,iv:JbZnLpjWguWC6KhRx8OXEzHrDYPw8/d7o7dhB+B2P9s=,tag:iOOIit4xssoznuCu4SlHiw==,type:str]
- queryType: ENC[AES256_GCM,data:j9zDVPQ=,iv:GvzV04OqsiYRFER/uvUYJ9C7jj51iAx1eyW/Jzieles=,tag:yPSD9Z0PbGxbJYPvB9Dx0A==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:2Z0w,iv:AWFuTbQeiGo1A0ZhP+AauK49k6B3BX558dYFyVLRJtw=,tag:HSE/d054YhGviJbSmQmkpA==,type:int]
- to: ENC[AES256_GCM,data:Xw==,iv:6lR2HVxatpRgoB4/nKir7/lxzaFi6QMN7GtsCv3pe/g=,tag:wTmOy+XBLg5wxVEnutQccg==,type:int]
- datasourceUid: ENC[AES256_GCM,data:HLAN7Q==,iv:yarcWCkJ3eA6NMrUYPEi4FrFuYyzsYO3AQZ+mSeCUPQ=,tag:hc3gg34JW7NNtnCH4fX70w==,type:str]
- model:
- datasource:
- type: ENC[AES256_GCM,data:s9R/9A==,iv:HaXwNCRVQMSEv+dn/YToCEfODS01ea57hGmJWNsWdng=,tag:ulhXOidRDmroWQz9Fu4ayg==,type:str]
- uid: ENC[AES256_GCM,data:W9vOOg==,iv:N6z75mcQ+heYe7Z8YoQmSub7kUgRkkPQxzZy9dHX6Yg=,tag:H/lDaDkzhj+bwF5pbLoOcA==,type:str]
- editorMode: ENC[AES256_GCM,data:a/0dpVRlKA==,iv:MlQ8INNYfLkEjtiL7B+swoiK1hlz/1O0AJT5ItHuphc=,tag:5V8XTVMPijTm9xg+CPFPiA==,type:str]
- expr: ENC[AES256_GCM,data:P90nUR1CuVs2WLz83aRJWaFhL6fxh5XRi8h0D0yq2viW9JIHGApZ3oOua4kCwYemLVfE07lyIXEFilD+Y5XhiMA3MZQFzw0Rtyt2UYzeDP0=,iv:mAErEyLh6fy2oe5SPoP53/P4o6rxFuw9c/1+2danLKY=,tag:hXCC0BBWh1yRHmqvG/7XLw==,type:str]
- hide: ENC[AES256_GCM,data:c325FMU=,iv:Bhpg9EYAPTvWuqP+AHM//+kwmpK0/GLCBu4zTFdovlg=,tag:gxRKdyE9zpUTcjBBPnm+mA==,type:bool]
- intervalMs: ENC[AES256_GCM,data:3Q63RQ==,iv:GEhR3FqnGHoSfyS12w7l7XnaCXJIQIZxj5+IuOPt8kM=,tag:bK5s2bHVOQAZKZt6qEEOoA==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:r+OtcFQ=,iv:yDwAMABbDIxERMt2vJiNt2c0/Zin3AfS3wb/BJQLezs=,tag:edOUuxSxGbfXjszjd/wbGg==,type:int]
- queryType: ENC[AES256_GCM,data:Gr6O5sA=,iv:MTVc80c70j9g9Uyaqsh4lvKA03Q5w7xNxVme8K5em3o=,tag:rue5dOrOP+t8PAxNby+vfA==,type:str]
- range: ENC[AES256_GCM,data:cWOYnA==,iv:A0qfk7FwOd+6Gkrtqi/DM6ZKIfFxe1b0pZSlGn+Pk5A=,tag:DS57Kmymp2LTh1CXO+6MLw==,type:bool]
- refId: ENC[AES256_GCM,data:MFMFysg=,iv:2FTqRLF5TYu7XxZ3Y6ihpwiVL4YHucEOaDWKJS7PcGg=,tag:XHR/gXPGyDBIss/d9Z8SVA==,type:str]
- - refId: ENC[AES256_GCM,data:CUB2GGgx,iv:qeojKuwc31FGmHcwsNsX4OoWQbYe/8GPgUe7+2JAnJw=,tag:1ExgXI97dL2Ue6pFODlShg==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:ikMt,iv:UAFObbrkYe+Lc6go/Eb5KMgmpx42q1r8G3tmj/Grtao=,tag:gnF8xPkcwUTTPpbGwpinQg==,type:int]
- to: ENC[AES256_GCM,data:PA==,iv:MSbRm87mlGXCtiLbhFtmcry19ExIxOQCDjr0b+xV+8Q=,tag:/R11BaSi2dV4ebJaeUTEbg==,type:int]
- datasourceUid: ENC[AES256_GCM,data:O0/Q7UT/X90=,iv:yTxhGL8heVyTlxj+F5wmXNbTbO0xAwFPOfvf/RnMP9M=,tag:QX8RpeUH+EpkQVm13I9irA==,type:str]
- model:
- conditions:
- - evaluator:
- params:
- - ENC[AES256_GCM,data:zQ==,iv:664Yw92gRYSVIlBNQ4hA3F/v+yA9ADcxSVd/Ll9S9QE=,tag:QbAlx9qTs1m3XdXx6VTIYg==,type:int]
- type: ENC[AES256_GCM,data:vtU=,iv:fYy6A2CI1uSBYyyBdYUM8rOY0sfwr4eiINVt1XYpPrI=,tag:KSNotJbEdMiPWoBXb9PbIg==,type:str]
- operator:
- type: ENC[AES256_GCM,data:lLJZ,iv:6qcMGeSCCBLlymfxN+KuC06nLF4bJ9qDu5iS3fDXEiQ=,tag:xjIhQmeRS2OT57e9Zg2F2w==,type:str]
- query:
- params:
- - ENC[AES256_GCM,data:pA==,iv:OxlNLpEaijJSDuqeWjortDw0HbnigGWHaHdFu5gIyDE=,tag:lyrQetKHR6mQmFHMLWccww==,type:str]
- reducer:
- params: []
- type: ENC[AES256_GCM,data:gQql0w==,iv:a8N6ttVvMhI0kwVQmdgjZ7kkq3vMW5SfJgL0IQMR6DI=,tag:AW4DTNMJChSE8czPUng7HA==,type:str]
- type: ENC[AES256_GCM,data:0k6548g=,iv:5s5YP7n+nGDOg6k43AJEYa/ZU/5D51y7eAbW6L+ut44=,tag:F52EC7ZW++r+aWqe7W3dWw==,type:str]
- datasource:
- type: ENC[AES256_GCM,data:+U1r/0ebZ8c=,iv:NR9uvFipeH5l9D1KEoZT2oS534lECdl2aaq1MiPl+yo=,tag:CBqIVU0u39eVUWW1F54Ljw==,type:str]
- uid: ENC[AES256_GCM,data:rWuK34X+bAg=,iv:ye5Jn773TS6nJsVwczrcjysLSraDFgoSFOQYRquX6OU=,tag:PgyqnHDbjhDDKe6rDpbkxQ==,type:str]
- expression: ENC[AES256_GCM,data:uw==,iv:vPuTArs6PXXtA0YlWdYUusegZ0WdiDrpH2DYpgDZcZI=,tag:g6mW9CQ7M2YZPecWytsjpA==,type:str]
- hide: ENC[AES256_GCM,data:YSMAX0g=,iv:39jg/3fyKpKHRhdaaD/3E3/UgmhP5P5dX/Lojrw7osc=,tag:fkRxCmZaSgEWNi91TCb+HA==,type:bool]
- intervalMs: ENC[AES256_GCM,data:M/2bLQ==,iv:IxNdBZbyu2HX2SalGKitOWe0b+OUIhLr9qbORIGxCsI=,tag:Ced6M9iTryaILHFOM930uw==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:lluaznU=,iv:a0qDd5EQfrARKsmEDW8R18E9oSa4uwGM1uVIV368Kl0=,tag:D9wHTFwALD5kpDeuz/hadw==,type:int]
- refId: ENC[AES256_GCM,data:j81CLjlD,iv:h37WaWyPZuDEO0Z0j+SZ7wsFVhCScGKJjfx/B6t+Vck=,tag:jRRSU9i2b4bG1MfyMp2qsg==,type:str]
- type: ENC[AES256_GCM,data:ANPgDYvmLPsD,iv:bOVIdOnOtv2iDuLa9LFRj3vvL/N3tMY+fKvlmt+u3ko=,tag:aW78i+mi1UDY6/oHCYvxfQ==,type:str]
- - refId: ENC[AES256_GCM,data:Cg==,iv:6HwwX+Ip3yPIrlahsWDmkQELoGGn/s+OcLOWRRUkdiQ=,tag:YZM33uNhICJvN6ENlcBd0Q==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:c9ue,iv:p0lQvKglncGqxtXsVy0AN8F70SnslNhLJRNSVpwGhq4=,tag:exm9lyFQew9TXF00Fl0xbw==,type:int]
- to: ENC[AES256_GCM,data:pw==,iv:9FFE479aB34rywWBlcWUIN0JU0HDCgai6UBcPwqrKmA=,tag:aXx/8VUqIzSEtW38wSmQoA==,type:int]
- datasourceUid: ENC[AES256_GCM,data:wlg5OawPfyw=,iv:/6hix5QbFOfycJu+1nWwDSWbpTBjsiP0VILQGFGQkIU=,tag:jW4ytDFKS36uAZtO/YiQTA==,type:str]
- model:
- conditions:
- - evaluator:
- params:
- - ENC[AES256_GCM,data:xw==,iv:905zBOax36EnxJmOO9IPdkHYNC7MDiPOgR895cls+p0=,tag:kHMOtOdWoiY/vjXRKdG/+g==,type:int]
- - ENC[AES256_GCM,data:cQ==,iv:stG2ww8bM7tWCKGaiCY3NZU0/wtDe9TOXBY+8CYvpdY=,tag:UiCEwlzbOpFh7r8qFIMb3g==,type:int]
- type: ENC[AES256_GCM,data:Xog=,iv:DGwzxfaqxeW79VFNKuRUjc6aRNj8MP0SA7LoTqDyaOA=,tag:or88hFJty5Qxr1bwisJ0xw==,type:str]
- operator:
- type: ENC[AES256_GCM,data:n3z4,iv:V69mjqT/yMXB0zZvrIkSWp4pi0/MOBiw0lF8AFqp01k=,tag:dn7qJGNf5UsYXB3ROZe3GA==,type:str]
- query:
- params: []
- reducer:
- params: []
- type: ENC[AES256_GCM,data:toKW,iv:9DlbkadSBrWd0o4Zq3+JWUEq2Il09qPTUBwd39OtKWw=,tag:31vHqZMlpCbiBl9/usSkCw==,type:str]
- type: ENC[AES256_GCM,data:QeO1yVk=,iv:P4GjY+nTZcOA6LBOM+MiDXRFKQD8+wkD8SyA/7pifO4=,tag:+ttAy3NDY66Js3dbB5U4rA==,type:str]
- datasource:
- name: ENC[AES256_GCM,data:Ug8SL/FYrOxJfg==,iv:H9dNUtJCxn/PC5oAvre+LDABb79w54IdWwkqNw8AFcs=,tag:0pHZ7u8TPRNjsE+2ZoUlyw==,type:str]
- type: ENC[AES256_GCM,data:58559WSybrU=,iv:rKa6E0MTK9NaMEVoxhX8k0vjAAbtGJWtGOzaE035jz8=,tag:kHlUgA0n19KL6lNiY9bI7w==,type:str]
- uid: ENC[AES256_GCM,data:HHuGzyDVuRY=,iv:oq+7pGxqwBtC/sNh3noB/xi1ddmdb+1XfZoPGuEKAMo=,tag:zvnGNUmI2lQUcQ6bs6KyGQ==,type:str]
- expression: ENC[AES256_GCM,data:OM3GonM=,iv:8GGXWYri0bVrA7O7eOA0fDk+6ZzPuedbM+QeLWYWXh8=,tag:kSmpjNlEJktNWpoe9PCb4A==,type:str]
- intervalMs: ENC[AES256_GCM,data:D3707A==,iv:X3ua7UYw0+cx5KERPb8Onh06NdKAMLSjceTAGHwNwXc=,tag:KPviOtaZ9+6qR/vwUAc3ZQ==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:kNgv050=,iv:gBibKhzTzqFss+YqZTIS8pqt4osSgpvSNFLmbK0qYgc=,tag:nW+uDqrTyiXAgzJex/eI9A==,type:int]
- reducer: ENC[AES256_GCM,data:mKXHOA==,iv:vuXl3883d2oo4HdV+mPZp+91mD9f8MLThmYXWYSfL+M=,tag:b/Hcn/QKmYQG5zEYr92iCg==,type:str]
- refId: ENC[AES256_GCM,data:Yw==,iv:8X7Tya7BIOP5w9ZQvDXZTQj1zxPPG1QJ9EBVHp9brVw=,tag:yRB0a3/TPa3zxacCsWuknQ==,type:str]
- settings:
- mode: ENC[AES256_GCM,data:sbyBah68TY2E,iv:CzXsCdVZmO/CdxPanaJmvjYBynKXXaR2umQJTMXCjVw=,tag:eCNht/ssKz3sARgXMKD+gA==,type:str]
- replaceWithValue: ENC[AES256_GCM,data:aQ==,iv:aWjh08ddS6All6bfTdK81bZOlW/b1mNsTq5gveCExzI=,tag:g6eqmBRq69QA2lIKO48Tuw==,type:int]
- type: ENC[AES256_GCM,data:qjhEUUKm,iv:Um8c05WmXdYZoMAB41ps4i/PagOhdYejjAb+Fo8ApIA=,tag:Rdc+lnErxZQ6hMHR2Eu9mw==,type:str]
- noDataState: OK
- execErrState: Error
- for: 5m
- annotations:
- summary: Matrix Synapse DNS Errors are higher than usual
- isPaused: false
- - uid: de30a1da-84da-45f4-a4a5-d641dbd92e6c
- title: psycopg2.errors.ReadOnlySqlTransaction
- condition: Thresh
- data:
- - refId: ENC[AES256_GCM,data:+iq3Skg=,iv:Q72W2U5uC2SyrQQX5ObTqrfHeTV9lAohSV+y246lY78=,tag:M5zk6EhVdz2g9gbAUeBCDw==,type:str]
- queryType: ENC[AES256_GCM,data:yq2iVo8=,iv:/S+d8l2tEe0SaB40yw+8yXpGIUUp73XgOXj7Is75dZg=,tag:LpRFPFSBaYhrEFu9D2AWVw==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:+LPi,iv:5bX/ZSgoBBN0lPUdBk+8AJ9CnkfD5rfbSkdmiLp5AGg=,tag:SFUslisI9uGFIZ+A7UNfPg==,type:int]
- to: ENC[AES256_GCM,data:LA==,iv:aqpjdB2pko1n+3O7YrW3ADT4cIpL8FixV75i1AuuzQw=,tag:nCKgVZLu7kkKr8vXjuEZAw==,type:int]
- datasourceUid: ENC[AES256_GCM,data:gFkIDg==,iv:WMffwRNU5VwMplJAp0FPTW/zP5vPnzJf7sR6a0rLgXM=,tag:6azVH6zIUoNlVRZheh3r+A==,type:str]
- model:
- datasource:
- type: ENC[AES256_GCM,data:7Nys5A==,iv:wgzr7JO+VSkQJDjg2nZ3FRRv0ROGqx8TrATZ5Ufh9E4=,tag:pDwVQbmsjJRYoytC0qREPw==,type:str]
- uid: ENC[AES256_GCM,data:ERMBYg==,iv:y4Lycx4nJTwx6NfzNucqWry5Vd5KwEDt0jvNQXCRPYk=,tag:esv3BqaCRY+SDr4wjtmilg==,type:str]
- editorMode: ENC[AES256_GCM,data:Lh4KjzJ8iA==,iv:NDVIh4gJzH2aKWXFPdbxeat8VL6jE9idRcz75qqb0IU=,tag:epPkmobn/ZzDNYTbMjS7Pw==,type:str]
- expr: ENC[AES256_GCM,data:43Ewd1vq/7hoOOZv/mqt15uS5yP2N6dwOKSWg6uR9XzV1u1oERa+So43LxkUV8NzE9YQLxGuD3A+jOPjRZMTMD9wAFLFTkWwh+7a5Rzqkulp/wB7cSrbgXgnBG96D5z73rY=,iv:rpOG3jeBbL5iwZ78Icf82fJoGKTTPzDK6EvKYMIkLxg=,tag:mo9R8/ZgVARZNl2wTMKGhw==,type:str]
- hide: ENC[AES256_GCM,data:oOkYWkI=,iv:C/8r2qdJvRUTQQOZFl9l+YKXL7B4vu5NYr+TszHBwZg=,tag:fL/+0DbmgNd6NKwuCTpJog==,type:bool]
- intervalMs: ENC[AES256_GCM,data:2gR/xA==,iv:zuYc515pEqsBkwlDyDnQNLi6vv6YXvBdSYE5hamcLSA=,tag:PyiCrOu3e55d4BBg7KQs1g==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:eQ4Ms80=,iv:ZivHmfAE9NLXCrodvdZ+1a5ynWNW0HRjpOdzkeY14JY=,tag:6QU2gmOQHcRKBOHS2CMc1A==,type:int]
- queryType: ENC[AES256_GCM,data:dcbVJI4=,iv:FI7yxjjd7V4zx105rHeNKaHi76BTJW6kuzrZyoCfBho=,tag:fBzYgJoxmhNVL4MHb1oz6Q==,type:str]
- range: ENC[AES256_GCM,data:UjkHPQ==,iv:/jQ0VSVjpxJ1360URI41s7jxoqhvf9Cl0gt4/cHAzYk=,tag:20fOdgCxJxAg3uWLL02MSw==,type:bool]
- refId: ENC[AES256_GCM,data:JOkm7O4=,iv:Sxjbk7q/t5in7y3vqa3Awp9IPj2RHUMTkay3eI/0+0A=,tag:kVX9q8cjJeRkpuyLNLYHCA==,type:str]
- - refId: ENC[AES256_GCM,data:XM1u6EUe,iv:ZMS1trYOdvj8XOGdh+B62sfo9Hr86pxmJ2OInxSd6BA=,tag:0ueMNZEDbhA8Z7rcpN2QEg==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:8jbO,iv:YByIfWhK6XQC8HtC6ozyUo5qjr/BMWKf3QzExnAlVxk=,tag:oQjvYv5Ja7NJSFtLMtK9Cw==,type:int]
- to: ENC[AES256_GCM,data:cA==,iv:yr8lA+PuF3gR42ULjNNUFYroW6+w0+7U/9CEuupjN4A=,tag:tZy4qeHFw9wL1hvAxxXpFw==,type:int]
- datasourceUid: ENC[AES256_GCM,data:+Gnvll+/tYM=,iv:K0QvzaDlZC+kmHlI3KnBbtWL8ZLivCgFc7/6feEQoS8=,tag:55wsXHKycDxTFY1zGT1+Wg==,type:str]
- model:
- conditions:
- - evaluator:
- params:
- - ENC[AES256_GCM,data:G13h,iv:VtUHJvRlv9YIBPS3Lna7J6rdzB4RUpfaiFx35Oo8f3s=,tag:oIu+xASEmyPBQ9vHhuuyuQ==,type:float]
- type: ENC[AES256_GCM,data:Emw=,iv:hAv1KWqASs+OCHhLbs1e+9RgvCGaFEZ/gj/KiKQFbP0=,tag:mMp0P0zs2DWtzS6ychmIkw==,type:str]
- operator:
- type: ENC[AES256_GCM,data:ds/f,iv:3DuSH55ndKZaPEzP7QiUAUXIrSKAKtlRns5wbCPcqHY=,tag:RAB+uKm8Zf+ABdi8YPkzkg==,type:str]
- query:
- params:
- - ENC[AES256_GCM,data:zQ==,iv:vUT2UW3p6v5QAiuOxlizrcydWdfaDj9dp8IoPUH6Dpw=,tag:da1HTUrpK9bS1I/7OGIG9Q==,type:str]
- reducer:
- params: []
- type: ENC[AES256_GCM,data:SyNl+w==,iv:93NwxIGo6buLvZbvhFWVN9KiFClzlvCPtjEvGAC94xI=,tag:qEdbN/fJwJwT+dOKEJDKhA==,type:str]
- type: ENC[AES256_GCM,data:CZZS8HA=,iv:P30OzOJLtnHSKCnJXuvjyDVRUKfHgpIYv5ddfT1e9T8=,tag:TKASo17r4HgNhclGNjKoeQ==,type:str]
- datasource:
- type: ENC[AES256_GCM,data:wMhoJwHK5so=,iv:TefwTT4uahxNp0OBanIq96Fo7d1T0qLmQwYuBRbD0ZM=,tag:T0K/09UvDt/vrL37sIJ0Cg==,type:str]
- uid: ENC[AES256_GCM,data:5JF7Gji0Xas=,iv:eVzzY72KldzOj5W44kfDU1+4t159mhkqBdjHfqvRQ94=,tag:ziCBAuZrURT7YN9AePeAEw==,type:str]
- expression: ENC[AES256_GCM,data:aw==,iv:vL981nzEcnGm6/crCD2ZbJvj8IxrvyfCNc74Y9PKvQs=,tag:oUInZhSdpTuv/su8VvUDEQ==,type:str]
- hide: ENC[AES256_GCM,data:F9C0ie8=,iv:3dGsIClAqKY6ohyGqGVuaItC6FpxzdE61PwFchQf5uc=,tag:eewKNUPtlCRe7YnfcP5lQQ==,type:bool]
- intervalMs: ENC[AES256_GCM,data:tjxcnw==,iv:gL5AwPEP8n/C2ueS2SAiMV/SNUl16Zaq9QwJNgj+48E=,tag:BgcUyVlgYZKeE6efiWlmfQ==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:lKBsqxM=,iv:H9oUR8rbS0/0p9ggP7J2/AP2tHe3xbEFoElH7i+E6t4=,tag:7ZQEwpOcX4IKHATk7nRSaw==,type:int]
- refId: ENC[AES256_GCM,data:8TNCzjd/,iv:wREdhnSOiDhVHrnUJPxLGJiSfec7fACeEw+gAOX7MRI=,tag:6VtYfDj2xpZI39gTF7uviA==,type:str]
- type: ENC[AES256_GCM,data:JF1ExwVus0Df,iv:WviCsFhJQEnm17k4TMvV8Plk9HGSa3c9oMvLJJ7UkWc=,tag:njkad0Ljwz1HW8t+DSVXww==,type:str]
- - refId: ENC[AES256_GCM,data:FQ==,iv:xp6uYbS3usbPCfeDekdZ8sYVvebHJiisQ7F5knb2+Ow=,tag:/IH9ewn9zKcjPJoFQTB6vw==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:NWrj,iv:ID+u5Ji1jBHtuqjxyLUa0Hsz6acXEoO+r5Ebx+N1ux8=,tag:wV+ztI1VFaWjlaGfPqYiMA==,type:int]
- to: ENC[AES256_GCM,data:Sw==,iv:sTQ4IBeokkTOR7WHlijWij67aEXe9PbHJrAIiU2FyU8=,tag:BpW3WrA5TKefXses2l1R2w==,type:int]
- datasourceUid: ENC[AES256_GCM,data:mQw3ZMlU7ro=,iv:NB11jrRjjKdFKC3myNhCM45QauVc2X0O8IHfyi0ubDE=,tag:Rm2f8WWivGJW2ErSm5Fs5w==,type:str]
- model:
- conditions:
- - evaluator:
- params:
- - ENC[AES256_GCM,data:0A==,iv:q8tk9xz28XxYqjgCEroiirFUnqMG5nHwYHs8rbrReFI=,tag:xChc8CxDzt58W9aeXUhyhQ==,type:int]
- - ENC[AES256_GCM,data:AA==,iv:k34XJxi+1vnh/FIelvErLIYPWB0yboazATfrWIUIKn4=,tag:5rzaJNMKPoZm7bnXPwLang==,type:int]
- type: ENC[AES256_GCM,data:Qko=,iv:/iJvnzaQ5AIn1rGP/pULzN3R4Rp8uQwCjwOJkxAZ8BE=,tag:EXB+aimTsONdoEzyDVPk6w==,type:str]
- operator:
- type: ENC[AES256_GCM,data:oX1p,iv:CIRWIfUlXqVG2tErc0IfXm+YM48XzF/4XwMosj7HJCE=,tag:wfUvlyQglSfTKK47N+aHIw==,type:str]
- query:
- params: []
- reducer:
- params: []
- type: ENC[AES256_GCM,data:2GTE,iv:dKHmKGdjUBln87ak4tFX3o0sL+LmHdTJU75FTjqTQiQ=,tag:+Aec34izdR7VwFFLX7A7BA==,type:str]
- type: ENC[AES256_GCM,data:dg9hRqQ=,iv:chEwaOPVSzqxwsD7dwLx1UfOQZ8t6eE/Y1Juec9+2/Y=,tag:FJndxw8F1871SJrJOGZKqg==,type:str]
- datasource:
- name: ENC[AES256_GCM,data:gxnvBtunMd4F/Q==,iv:gHboVcI3T2oxbx436OdKkepr7mH5/Dm0dqlXJ4ggeZw=,tag:kmC7pe4/2Bfst6cBZiWQ1w==,type:str]
- type: ENC[AES256_GCM,data:/X9WUtXGIic=,iv:xXL3Kb8TZ7qjslJMB0g84HEimc926JmYk6RWzwP5Yuo=,tag:8dDnV1F8qvyP49tvbYXmpA==,type:str]
- uid: ENC[AES256_GCM,data:X9j84zkEtZ8=,iv:HMWU+QS/gwTE3d3Ok1XvfBO85idjMj2HGwoUP92wCt8=,tag:2iKcTeAta958V8xx4SViJw==,type:str]
- expression: ENC[AES256_GCM,data:tAVGaZU=,iv:8lngxa4j/GRIGba/GgiHf4MqZKbRG+5soA0IYY5bJek=,tag:04tfPb/z5Ym9J2XerFl08w==,type:str]
- intervalMs: ENC[AES256_GCM,data:PYg85w==,iv:i82pMujeatetp1DzzdJ9hn+v/nrfyAijRndhU92xjfw=,tag:987+wC0j/Qz6mBbGwXYN7Q==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:qrans9o=,iv:MATPkPO9fMlpBeJDm967RWqAPdksbTujxdCJdirAsaA=,tag:8/bM7tQAWq3cL7wju9KiBw==,type:int]
- reducer: ENC[AES256_GCM,data:a7gkmA==,iv:+VleYkH3ZnI35IV52h3HpOfaTGPe+2dot8LoVHjWGaQ=,tag:Bn5sdXE++knJt9yjilno8w==,type:str]
- refId: ENC[AES256_GCM,data:AA==,iv:l7GAAoXn2O2omWfp0OxShTwq8R05OgHK1C6fMnyqd0E=,tag:iUcAKpaqfwyNj5/WTfOAjg==,type:str]
- settings:
- mode: ENC[AES256_GCM,data:MvCD130GO1h9,iv:mfKDQkXfNIemcNfkJltzOU3PFB5hZHiFocElNxzT3HA=,tag:8VUKvZ5rVooauuek0tscKA==,type:str]
- replaceWithValue: ENC[AES256_GCM,data:PQ==,iv:j6rlOk30YRAnO/VWzXXyhe+6RNYjpK6oZeOE8AkZYA0=,tag:ofQIjc+K5m+FJ9a6DrtLCA==,type:int]
- type: ENC[AES256_GCM,data:j/uh9hhk,iv:TqDql0KmMmyHSuqVr925C5Lvng/Ta875gmPD8pTSZis=,tag:9uwWvM7tMY9lYdYrmKLIDQ==,type:str]
- noDataState: OK
- execErrState: Error
- for: 5m
- annotations:
- summary: Matrix Database rolled over but synapse crashed
- isPaused: false
- - uid: d16dc343-31d9-466a-bdc1-c2466b0bc18f
- title: Unusual synapse logging
- condition: Thresh
- data:
- - refId: ENC[AES256_GCM,data:Q7pGec4=,iv:ZdEDSRHz2WjetHnUaBazuvOJ6wRmIfABOv/h9kRN5oQ=,tag:BgDq4hjYojvccdMRrsY2tw==,type:str]
- queryType: ENC[AES256_GCM,data:y9KeUrA=,iv:qgDSNh1fjJlh8/ussvgKwVPtKvfSAOxagXAnZvRSJuE=,tag:/KcYLv0Mgal7y+C7nsPCSQ==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:frvz,iv:EEOV1jeUqGxB6N05rXca2nUcHn16zmzwt7eccbDFCEg=,tag:Zb18qDZlxZNtZ6tIgzWtXA==,type:int]
- to: ENC[AES256_GCM,data:FQ==,iv:Iy0t6Gs7ITPAhbRwSMlymPo1dP1ivuKUR2J4bV1Dj2k=,tag:s7oqLAt+N4DYNQ2HZYIyyw==,type:int]
- datasourceUid: ENC[AES256_GCM,data:y7jdYw==,iv:Ktfhzx0LTn1hi8uebJ/QvU0hPPClk++3EzadxflqvTg=,tag:DkBI8bmo1Oc0JHRVYvUlSg==,type:str]
- model:
- datasource:
- type: ENC[AES256_GCM,data:HI56YQ==,iv:na7khjhH5y0JYvEhbaXlKH56Dj/Ne57+aLlw66oUvSA=,tag:PEmXxBNMOe6xPk5ycJjNqg==,type:str]
- uid: ENC[AES256_GCM,data:4RmIYA==,iv:b+2XwWrwbOt+ACQDHzo/DyrcSezqKpdSHeol49IbEWA=,tag:b+beVtYBfuw5YPe7BRQFog==,type:str]
- editorMode: ENC[AES256_GCM,data:GU+MC7lRIA==,iv:U7VZBjfKNOItZYSSwzXinB2Nqs5fv9fC9jE3wvWhDIk=,tag:cxhev4lup18cuG6DptBBeQ==,type:str]
- expr: ENC[AES256_GCM,data:ILM8gP5Z5cJT+Z46gmqjwWhQce66Mu5XwimIu5VIAZHGLmX+YBS0LE+1GUgJjXTIj07YEQNwdq0wt3XctGbMHnkBwH5/GHf7bMhuBX1/nZjs5nN9bt54uKLfAM1tgI3syzLSq1PlMrfOHt6hQnCCqiU+Gg5lJwuSHPqL1y1qIj01Ntg4DHGwP0Q2txJyGfFgypHIPPD0Rnqc2WXJAogPjNEKgYyQaKP+0oaJEEw=,iv:hqbZKnVSMtt+nOwUZPFpCmhRnDOazBi7NKqEGftFWuU=,tag:CHe5YjKFnD6akbTsrKTnXQ==,type:str]
- hide: ENC[AES256_GCM,data:Mp/xbq0=,iv:ScyvWL3LT3E3iAAtvOszITwhKqMvyyTRFn8gmhNk0oY=,tag:wHQj/QB8CJRckOpvQETkIQ==,type:bool]
- intervalMs: ENC[AES256_GCM,data:Ef8vcg==,iv:KeWLpX5xwJwbh4Z6BJyI3JfEvsyr9Rfx63hoWQt+SsA=,tag:ma/WZZ7cD3iWAuUWFXwB4g==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:+JOR68Y=,iv:h1ewrfChh5bzMk6n91tG7/zOc7dGIdVxpXun/85c1ms=,tag:lZ0sjVnVpNzPQCA4WzbxNA==,type:int]
- queryType: ENC[AES256_GCM,data:VDTriZs=,iv:16NFPSpCurVmEOn7KldasVSQQO3wqzEpPVkp3p2oJoI=,tag:Uef2PPgwbLc5PSsIEL1wBQ==,type:str]
- range: ENC[AES256_GCM,data:1NWVcA==,iv:nYheeN7Dk9aUG96Z2+QzCQka4mzWo2p3a0INZXC9wFU=,tag:bz576QhORXJD87geW8HUZA==,type:bool]
- refId: ENC[AES256_GCM,data:sBtmS4s=,iv:EdcYILNkUI6bdEiArX9ucDFekGGAykln57LTdDiWbRs=,tag:2fOr6OnUAag0dONBLvepSw==,type:str]
- - refId: ENC[AES256_GCM,data:xJxM2ZxE,iv:+1mBiIUDUPTG28KY3tf/bwgB5uVgoDKMhl6cuONvLW4=,tag:5H4V8fNdMuVEJ7hZuclo8g==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:pZYL,iv:KFys6EaOid5h20PHfrVSW2YruoP/JntXFDOfy+FCQFA=,tag:yy24qdEbbdaAwwuCAMTiYA==,type:int]
- to: ENC[AES256_GCM,data:aQ==,iv:JxaLAS09C8kEYsV5DoZaqDenQEaDZWnyrIdOLxXqeSg=,tag:ocH8Lzmo5fBYU8S/w9U25A==,type:int]
- datasourceUid: ENC[AES256_GCM,data:nh7odBYG7Bo=,iv:/iLZdiuvL/xI09btlFyAxa59uaMDZTQuyVRZb6XSftE=,tag:hJjyCzoIePeZkgtq3nGySQ==,type:str]
- model:
- conditions:
- - evaluator:
- params:
- - ENC[AES256_GCM,data:zvU=,iv:J/OmM4xOK3m+8Cfc2XLW4ZgnyllhxunScy37yE1mQvo=,tag:63GIL4LzVXT2+JEiH2PTrA==,type:int]
- type: ENC[AES256_GCM,data:2aA=,iv:UTZi+DUbqzOGqbaJx7bFiBYfxHID5BxHvm9eatyB1JE=,tag:vkWOkyu8dodzHetaI1a9tw==,type:str]
- operator:
- type: ENC[AES256_GCM,data:gLGS,iv:UcoDo6ODi/mth5NY9O4qi2kaSPAv8j/1Bpqpc90KIdY=,tag:+TZ3cyAaXdoxfCOFmEMnfQ==,type:str]
- query:
- params:
- - ENC[AES256_GCM,data:hw==,iv:dMpk6sfpn/HXyLST3J3vwzB8/pOE1nZTusVapIunX8U=,tag:dSH64K8iON4+LGM7TwsMMQ==,type:str]
- reducer:
- params: []
- type: ENC[AES256_GCM,data:piqylw==,iv:kSwoDnRS2sXT6nWiJ1Sym/68QN6RVA4/5OkUX77XWTU=,tag:N+NS7NTncQVhf73MU+WXBQ==,type:str]
- type: ENC[AES256_GCM,data:OgQuzz0=,iv:/n8HzOvK/KkM6HYBlRS0LIO8+sNkaQbpB0bdmeEVE1c=,tag:8IeH163PhaKhUoJAgA2upA==,type:str]
- datasource:
- type: ENC[AES256_GCM,data:Eo4cVH1+2Lg=,iv:8iEn2dlK3rlpMZtdCm/ECIBNuniO6BacyYuDx7521jE=,tag:0CLdWqYSIejyjc/Xk1PKjw==,type:str]
- uid: ENC[AES256_GCM,data:3ZP7ZwbjTxU=,iv:JUsyzPwPTli9KXNQCJZZ6vx8WSTaX0oTbfk4uNnzijA=,tag:Fcu8cN8n09rc0SfR54CHIQ==,type:str]
- expression: ENC[AES256_GCM,data:KQ==,iv:Hmks9T1d99cJ1qmLV0tMvvNLyYFdmsodmInN37uTvKo=,tag:zhs+x9/YdJc7KVk4BvKMAw==,type:str]
- hide: ENC[AES256_GCM,data:fEKC/Do=,iv:ebYOYTJd6Yt1VXo2TWelUg5Pm1hHWZfYJOZ5ca8me2w=,tag:lwHFbhi6tVpBoV70XoUnHQ==,type:bool]
- intervalMs: ENC[AES256_GCM,data:XEV2hA==,iv:ewPtq7F2KqyOJQT97hgr3YGAKENyaEhL1btALkPMR20=,tag:5TGGE0swyD5SyQy1C8Vd6w==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:ft2nEAo=,iv:0xKYPIJbpwzAfwsZhd9lxF3iWUsdHhtpnnDcDDi21MA=,tag:N2JAjLRdCKKYD6yEZ0lpfg==,type:int]
- refId: ENC[AES256_GCM,data:4v6PCxKm,iv:gFqH6EGawvaryKaIRwQRtIoC00ZepfDI0zv2546Vavc=,tag:EZtvANN/f0I1yqHv7PT/iw==,type:str]
- type: ENC[AES256_GCM,data:PgDmJaUX840F,iv:XbuXlDlXagYfzcIoJI81iQQu0DjLc2Ksj4vqpG/cEwM=,tag:epD7SElMswcv0s2NWqWeoQ==,type:str]
- - refId: ENC[AES256_GCM,data:lw==,iv:vpXiXAm8BLc1robufE4+6d9arIK2QDRcNOO+z3ETd9k=,tag:nbpZHjbls3y0MczXyMS/pg==,type:str]
- relativeTimeRange:
- from: ENC[AES256_GCM,data:rof+,iv:Pg/c2gI5DOfErVZOz9WbkwJ6NJ3ZQogz0ETh0clTJXI=,tag:IlUTQv/cjNx6dlEYU9hg1A==,type:int]
- to: ENC[AES256_GCM,data:nw==,iv:WhKBUpguS3CUpH0K9ZgGSZWN2Elo2UFYC3ZgznaG+Is=,tag:79MD+F86zpx1q/naDrUZjQ==,type:int]
- datasourceUid: ENC[AES256_GCM,data:ffFTy5o+k9E=,iv:ICyA0YyW7RvMZDilLcZTZtaL1AevNdczBY/pawU7Qss=,tag:wr5OEZuYtkfMGgECtUOTGA==,type:str]
- model:
- conditions:
- - evaluator:
- params:
- - ENC[AES256_GCM,data:sw==,iv:kVq2YoJWliZ4DUDGBfu2KZX1DA3EFqIBqf+lu/Z+5lU=,tag:WPlXq48HdIEZdV4gyDo4sw==,type:int]
- - ENC[AES256_GCM,data:Mw==,iv:EOdVUKRztBMEjaZNIQjuDnRZaVrO3untXYYhUj+/oe0=,tag:zXjd4rhfklTcqZbL0l1XgQ==,type:int]
- type: ENC[AES256_GCM,data:rvs=,iv:X0KXqoz3Tx0EQdgZmMX+LSKbE1TmN0Slnl2EH1d/IaM=,tag:rcmnvcPK4iOvuRO+UAPTkg==,type:str]
- operator:
- type: ENC[AES256_GCM,data:+1AE,iv:K34xjtG4796OOaF9LoB+crEP1ibq9UCF8VQJymJwALw=,tag:iec/Eezar14CiydftIZBvg==,type:str]
- query:
- params: []
- reducer:
- params: []
- type: ENC[AES256_GCM,data:r0A3,iv:OMszF8XVjkQStttgc7Ihequ5TJnpki1KZ1uFbW/QRVw=,tag:/EZg5/0Kk9TML7cWdmYxrA==,type:str]
- type: ENC[AES256_GCM,data:6YC3Hbs=,iv:OPYbN1h6KCxF/V/q8AANneBZeDSLva/vC7FFh5/QxdM=,tag:lVA6M5yxXquu9J5EW0EdrA==,type:str]
- datasource:
- name: ENC[AES256_GCM,data:X0RwKv1kc1TrzQ==,iv:oLlNGpFJxUlho3EfdEBv0X+9fBQW7JowfFWtGD9+aT0=,tag:cxcHT42IrR1XQoiafhbViA==,type:str]
- type: ENC[AES256_GCM,data:JJK85SsN1E4=,iv:gq/2LSBkvGWb8JgPtH+j6p9efc6Cq0s3jZpbJKXOsko=,tag:GiIhQyiRUnVD1JZcOw5k3Q==,type:str]
- uid: ENC[AES256_GCM,data:YyxDNN2nXEI=,iv:k73Jj33CgpQI3us7j91J2R1Ksx92nJ6cNoNkx6/hJ/I=,tag:AoF7sJNM3Fu+ZmxMt4K4jQ==,type:str]
- expression: ENC[AES256_GCM,data:BTed8J0=,iv:T+6+DYQT1CJ41i7mgG+40ZK4aHDcvcvQNW/ueG+Yhyk=,tag:mRRXsV/7VdP9AbEiTYc34Q==,type:str]
- intervalMs: ENC[AES256_GCM,data:IoFAEw==,iv:qVbZ6HNZ09Fy3zgCF6nciYWgbMd94NWTldcdSG01l0E=,tag:xH+bZn85BlN0gkZlSqVRlA==,type:int]
- maxDataPoints: ENC[AES256_GCM,data:260W+5A=,iv:p7/aa4XZQHVkSn9V8D1yBUlSqUxh2bEGmNnhKcRwqoA=,tag:Qdc9nzeGjmfeCLSNPC0upA==,type:int]
- reducer: ENC[AES256_GCM,data:ABuFZw==,iv:z9J1Nz/BIQ3ozI7M8Q0xcVWxDX6n4ua1YYdqbV/Yv5A=,tag:GJpnNDiXkOk5ZdLI9pfTPQ==,type:str]
- refId: ENC[AES256_GCM,data:fw==,iv:+EK79g3nvxM1zpl24wivnrh4HTYkyoBTSkme3DloA0I=,tag:Ws7TtHhuXrAMVRWKMBhb0Q==,type:str]
- settings:
- mode: ENC[AES256_GCM,data:IgdIYALiCVSL,iv:u+8z2yrJLVWPIPBJlrF0yyM8e0GQp5rzZA5Q2P2Xf8k=,tag:Qlbweeh22t8uxSIKeEjmpg==,type:str]
- replaceWithValue: ENC[AES256_GCM,data:6A==,iv:Bu6f66vyOMIgcw7gZHXS9+xlpKKgp9WIup7rSZJbYog=,tag:CpzSKfT4z2WpIjafc/Rnag==,type:int]
- type: ENC[AES256_GCM,data:+kYAumQS,iv:8g7OMfmH8h9KDV0sfd/zJ31z9wfrcxHbBYPmsnEVH1Y=,tag:FJnIFx08uqiyJdLf44mIOA==,type:str]
- noDataState: OK
- execErrState: Error
- for: 5m
- annotations:
- summary: Unusual logging for synapse.
- isPaused: false
- contactpoints.yaml:
- apiVersion: 1
- contactPoints:
- - orgId: 1
- name: MidnightThoughts Ops
- receivers:
- - uid: "1"
- name: MidnightThoughts Ops
- type: email
- sendReminder: true
- frequency: 1m
- settings:
- addresses: ops@nordgedanken.dev;mtrnord@nordgedanken.dev;mtrnord1@gmail.com
- policies.yaml:
- apiVersion: 1
- policies:
- - orgId: 1
- receiver: MidnightThoughts Ops
- group_by:
- - grafana_folder
- - alertname
- plugins:
- - grafana-piechart-panel
- - grafana-worldmap-panel
- - https://grafana.com/api/plugins/parseable-parseable-datasource/versions/1.0.2/download;parseable-parseable-datasource
- - isovalent-hubble-datasource
- - isovalent-hubbleprocessancestry-panel
- - chaosmeshorg-datasource
- smtp:
- existingSecret: smtp-auth-secret
- extraSecretMounts:
- - name: auth-generic-oauth-secret-mount
- secretName: auth-generic-oauth-secret
- defaultMode: 288
- mountPath: /etc/secrets/auth_generic_oauth
- readOnly: true
- - name: parseable-secret-mount
- secretName: parseable-secret
- defaultMode: 288
- mountPath: /etc/secrets/parseable
- readOnly: true
- defaultDashboardsTimezone: Europe/Berlin
- dashboardProviders:
- dashboardproviders.yaml:
- apiVersion: 1
- providers:
- - name: monitoring
- orgId: 1
- folder: Monitoring
- type: file
- disableDeletion: true
- editable: false
- updateIntervalSeconds: 10
- allowUiUpdates: false
- options:
- path: /var/lib/grafana/dashboards/monitoring
- - name: zammad
- orgId: 1
- folder: Zammad
- type: file
- disableDeletion: true
- editable: false
- updateIntervalSeconds: 10
- allowUiUpdates: false
- options:
- path: /var/lib/grafana/dashboards/zammad
- - name: matrix
- orgId: 1
- folder: Matrix
- type: file
- disableDeletion: true
- editable: false
- updateIntervalSeconds: 10
- allowUiUpdates: false
- options:
- path: /var/lib/grafana/dashboards/matrix
- - name: nats
- orgId: 1
- folder: Nats
- type: file
- disableDeletion: true
- editable: false
- updateIntervalSeconds: 10
- allowUiUpdates: false
- options:
- path: /var/lib/grafana/dashboards/nats
- datasources:
- datasources.yaml:
- apiVersion: 1
- datasources:
- - name: Parseable
- type: parseable-parseable-datasource
- url: http://parseable.parseable.svc.cluster.local
- access: proxy
- isDefault: false
- basicAuth: true
- basicAuthUser: MTRNord
- secureJsonData:
- basicAuthPassword: $__file{/etc/secrets/parseable/password}
- - name: ChaosMesh
- type: chaosmeshorg-datasource
- url: http://chaos-dashboard.chaosmesh.svc.cluster.local:2333
- access: proxy
- isDefault: false
- - name: Tempo
- type: tempo
- uid: tempo
- access: proxy
- url: http://tempo.monitoring.svc.cluster.local:3100
- isDefault: false
- jsonData:
- httpMethod: GET
- serviceMap:
- datasourceUid: prometheus
- lokiSearch:
- datasourceUid: loki
- - name: Hubble
- type: isovalent-hubble-datasource
- uid: hubble
- access: proxy
- url: http://hubble-relay.kube-system.svc.cluster.local:80
- isDefault: false
- jsonData:
- serviceMap:
- datasourceUid: prometheus
- tempoDatasourceUid: tempo
- prometheusDatasourceUid: prometheus
- - name: ES - Chat Sessions
- type: elasticsearch
- access: proxy
- url: http://zammad-elasticsearch.zammad.svc.cluster.local:9200
- isDefault: false
- uid: zammad-es-chat_sessions
- jsonData:
- index: zammad_production_chat_session
- timeField: created_at
- - name: ES - CTI Log
- type: elasticsearch
- access: proxy
- url: http://zammad-elasticsearch.zammad.svc.cluster.local:9200
- isDefault: false
- uid: zammad-es-cti_log
- jsonData:
- index: zammad_production_cti_log
- timeField: start_at
- - name: ES - Ticket Articles
- type: elasticsearch
- access: proxy
- url: http://zammad-elasticsearch.zammad.svc.cluster.local:9200
- isDefault: false
- uid: zammad-es-ticket_articles
- jsonData:
- index: zammad_production_ticket
- timeField: article.created_at
- - name: ES - Tickets by closed_at
- type: elasticsearch
- access: proxy
- url: http://zammad-elasticsearch.zammad.svc.cluster.local:9200
- isDefault: false
- uid: zammad-es-closed_ticket
- jsonData:
- index: zammad_production_ticket
- timeField: close_at
- - name: ES - Tickets by created_at
- type: elasticsearch
- access: proxy
- url: http://zammad-elasticsearch.zammad.svc.cluster.local:9200
- isDefault: false
- uid: zammad-es-created_ticket
- jsonData:
- index: zammad_production_ticket
- timeField: created_at
- - name: ES - Tickets by first_response_at
- type: elasticsearch
- access: proxy
- url: http://zammad-elasticsearch.zammad.svc.cluster.local:9200
- isDefault: false
- uid: zammad-es-first_response_at
- jsonData:
- index: zammad_production_ticket
- timeField: first_response_at
- dashboards:
- monitoring:
- asterisk:
- url: https://git.nordgedanken.dev/kubernetes/grafana/raw/branch/main/asterisk.json
- traefik:
- url: https://git.nordgedanken.dev/kubernetes/grafana/raw/branch/main/traefik.json
- postgres-dashboard:
- url: https://raw.githubusercontent.com/prometheus-community/postgres_exporter/master/postgres_mixin/dashboards/postgres-overview.json
- minio-dashboard:
- url: https://raw.githubusercontent.com/minio/minio/master/docs/metrics/prometheus/grafana/minio-dashboard.json
- #minio-bucket:
- # url: https://raw.githubusercontent.com/minio/minio/master/docs/metrics/prometheus/grafana/minio-bucket.json
- #minio-replication:
- # url: https://raw.githubusercontent.com/minio/minio/master/docs/metrics/prometheus/grafana/minio-replication.json
- zammad:
- ticket_statistics:
- gnetId: 14222
- revision: 2
- datasource:
- - name: DS_ES_- TICKETS BY CREATED_AT
- value: zammad-es-created_ticket
- - name: DS_ES_- TICKETS BY CLOSED_AT
- value: zammad-es-closed_ticket
- - name: DS_ES_- TICKET ARTICLES
- value: zammad-es-ticket_articles
- - name: DS_ES_- CHAT SESSIONS
- value: zammad-es-chat_sessions
- - name: DS_ES_- CTI LOG
- value: zammad-es-cti_log
- chat_sessions_statistics:
- gnetId: 14224
- revision: 1
- datasource:
- - name: DS_ES_- TICKETS BY CREATED_AT
- value: zammad-es-created_ticket
- - name: DS_ES_- TICKETS BY CLOSED_AT
- value: zammad-es-closed_ticket
- - name: DS_ES_- TICKET ARTICLES
- value: zammad-es-ticket_articles
- - name: DS_ES_- CHAT SESSIONS
- value: zammad-es-chat_sessions
- - name: DS_ES_- CTI LOG
- value: zammad-es-cti_log
- cti_log_statistics:
- gnetId: 14223
- revision: 1
- datasource:
- - name: DS_ES_- TICKETS BY CREATED_AT
- value: zammad-es-created_ticket
- - name: DS_ES_- TICKETS BY CLOSED_AT
- value: zammad-es-closed_ticket
- - name: DS_ES_- TICKET ARTICLES
- value: zammad-es-ticket_articles
- - name: DS_ES_- CHAT SESSIONS
- value: zammad-es-chat_sessions
- - name: DS_ES_- CTI LOG
- value: zammad-es-cti_log
- matrix:
- synapse-dashboard:
- #url: https://git.nordgedanken.dev/kubernetes/grafana/raw/branch/main/synapse.json
- url: https://raw.githubusercontent.com/element-hq/synapse/develop/contrib/grafana/synapse.json
- datasource:
- - name: DS_PROMETHEUS
- value: Prometheus
- draupnir4all:
- url: https://git.nordgedanken.dev/kubernetes/grafana/raw/branch/main/draupnir4all.json
- matrix-media-repo-dashboard:
- url: https://raw.githubusercontent.com/t2bot/matrix-media-repo/main/docs/grafana.json
- datasource:
- - name: DS_PROMETHEUS
- value: Prometheus
- ingress:
- enabled: true
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- hosts:
- - grafana.midnightthoughts.space
- tls:
- - secretName: grafana.midnightthoughts.space
- hosts:
- - grafana.midnightthoughts.space
- grafana.ini:
- server:
- root_url: https://grafana.midnightthoughts.space
- smtp:
- enabled: true
- host: mail.nordgedanken.dev:465
- from_address: ops@nordgedanken.dev
- paths:
- data: ENC[AES256_GCM,data:NLlX8+KqfY/yxj46ts6LWl4=,iv:NoZzydt9Oe+P8cWDBju1WX1zmZw6k7JffVsxd6Yi8LU=,tag:QEVA3FupDhY/qtIzik2poQ==,type:str]
- logs: /var/log/grafana
- plugins: /var/lib/grafana/plugins
- provisioning: /etc/grafana/provisioning
- analytics:
- check_for_updates: true
- log:
- mode: console
- grafana_net:
- url: https://grafana.net
- auth.generic_oauth:
- enabled: true
- scopes: openid email profile roles
- name: OAuth
- allow_sign_up: true
- client_id: $__file{/etc/secrets/auth_generic_oauth/client_id}
- client_secret: $__file{/etc/secrets/auth_generic_oauth/client_secret}
- auth_url: https://keycloak.midnightthoughts.space/realms/master/protocol/openid-connect/auth
- token_url: https://keycloak.midnightthoughts.space/realms/master/protocol/openid-connect/token
- api_url: https://keycloak.midnightthoughts.space/realms/master/protocol/openid-connect/userinfo
- role_attribute_path: contains(resource_access.grafana.roles[*], 'admin') && 'Admin' || contains(resource_access.grafana.roles[*], 'editor') && 'Editor' || 'Viewer'
- imageRenderer:
- enabled: true
- kubeProxy:
- enabled: false
- postRenderers:
- - kustomize:
- patches:
- - target:
- # Ignore these objects from Flux diff as they are mutated from chart hooks
- kind: (ValidatingWebhookConfiguration|MutatingWebhookConfiguration)
- name: kube-prometheus-stack-admission
- patch: |
- - op: add
- path: /metadata/annotations/helm.toolkit.fluxcd.io~1driftDetection
- value: disabled
- - target:
- # Ignore these objects from Flux diff as they are mutated at apply time but not at dry-run time
- kind: PrometheusRule
- patch: |
- - op: add
- path: /metadata/annotations/helm.toolkit.fluxcd.io~1driftDetection
- value: disabled
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBCeHQ3Wk5qMkpEUWdYQ2do
- elZOcWNZNlh5RXRTRWkyUmNkRXpaVmhqeVhjCnRJT1YxWFN4cTdWRlpxWE9JUkJ4
- NHltY0FDSUlsU3dvQlNxSVJRaDRjYVUKLS0tIFBHVjA2NVpsVTVnb1czY0NFd1Nn
- eHZ2eWdFOXlucWZiTDBtdGRza0YyVFUKTeb47DmYxKFXGC4d4fan+I73Zcpg3NyY
- H6ZxRxhSHQOIrYP6nUCb4cYNWmAsi1A3YY3fA7Blx6WE/gacYrWIWw==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-04-16T10:11:31Z"
- mac: ENC[AES256_GCM,data:FXYPw1zgGSEpjAlzYljgkjjMZqj+v6zJ9LVxhfIQ2S4yUYuCWYTuzYn7VoB3mbXId5+oFEFPPpiwJSw3KOIoJ91TBvvttp4IP/TKBRstGr7dNxRhfm4NL3gRQCF4Hw858thki1gBVdidsX09oI95zfTwChzoB08DZqRs8Zackn8=,iv:DQ/xoV0OCCbRtNzgP1/0UoKAVEbq5gYEBtgt/RVLcGI=,tag:Fbgvyv9zPpiLEi8A9Xq+uQ==,type:str]
- pgp: []
- encrypted_regex: ^(AUTHENTICATION_PASSWORD|ROOM_API_SECRET_KEY|adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
diff --git a/apps/base/kube-prometheus-stack/repository.yaml b/apps/base/kube-prometheus-stack/repository.yaml
@@ -1,10 +0,0 @@
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: prometheus-community
- namespace: monitoring
-spec:
- interval: 120m
- # OCI builds for kube-prometheus-stack have been temporarily disabled (see https://github.com/prometheus-community/helm-charts/issues/2940).
- type: default
- url: https://prometheus-community.github.io/helm-charts
diff --git a/apps/base/mailu/ingress.yaml b/apps/base/mailu/ingress.yaml
@@ -1,25 +0,0 @@
----
-apiVersion: networking.k8s.io/v1
-kind: Ingress
-metadata:
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- name: mailu
- namespace: mailu
-spec:
- ingressClassName: traefik
- rules:
- - host: mail.k8s.nordgedanken.dev
- http:
- paths:
- - backend:
- service:
- name: mailu-front
- port:
- name: http
- path: /
- pathType: ImplementationSpecific
- tls:
- - hosts:
- - mail.k8s.nordgedanken.dev
- secretName: mailu-certificates
diff --git a/apps/base/mailu/kustomization.yaml b/apps/base/mailu/kustomization.yaml
@@ -1,7 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: mailu
-resources:
- - ingress.yaml
- - repository.yaml
- - release.yaml
diff --git a/apps/base/mailu/release.yaml b/apps/base/mailu/release.yaml
@@ -1,143 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: mailu
- namespace: mailu
-spec:
- releaseName: mailu
- chart:
- spec:
- chart: mailu
- sourceRef:
- kind: HelmRepository
- name: mailu
- interval: 50m
- timeout: 25m
- install:
- timeout: 25m
- remediation:
- retries: 3
- values:
- domain: "mail.k8s.nordgedanken.dev"
- hostnames:
- - "mail.k8s.nordgedanken.dev"
- - "mta-sts.mail.k8s.nordgedanken.dev"
- timezone: "Europe/Berlin"
- subnet: 10.244.0.0/16
- subnet6: fc00:0::/96
- postgresql:
- enabled: true
- image:
- tag: "14.8.0-debian-11-r14"
- primary:
- initdb:
- ## @skip postgresql.primary.initdb.scripts.create_roundcube_database.sh
- ## DO NOT EDIT Script to create the roundcube database
- scripts:
- create_roundcube_database.sh: |
- #!/bin/bash
- # set -o errexit
- # set -o nounset
- # set -o pipefail
- info "Running DB initialisation..."
- info "Creating database ${ROUNDCUBE_DB_NAME}..."
- echo "CREATE DATABASE \"$ROUNDCUBE_DB_NAME\"" | postgresql_execute "" "postgres" "$POSTGRES_POSTGRES_PASSWORD"
- info "Creating user ${ROUNDCUBE_DB_USER}"
- echo "CREATE ROLE \"${ROUNDCUBE_DB_USER}\" WITH LOGIN CREATEDB PASSWORD '${ROUNDCUBE_DB_PW}';" | postgresql_execute "" "postgres" "$POSTGRES_POSTGRES_PASSWORD"
- info "Granting access to \"${ROUNDCUBE_DB_USER}\" to the database \"${ROUNDCUBE_DB_NAME}\""
- echo "GRANT ALL PRIVILEGES ON DATABASE \"${ROUNDCUBE_DB_NAME}\" TO \"${ROUNDCUBE_DB_USER}\"\;" | postgresql_execute "" "postgres" "$POSTGRES_POSTGRES_PASSWORD"
- echo "ALTER DATABASE \"${ROUNDCUBE_DB_NAME}\" OWNER TO \"${ROUNDCUBE_DB_USER}\"\;" | postgresql_execute "" "postgres" "$POSTGRES_POSTGRES_PASSWORD"
- info "Setting ownership for the 'public' schema database \"${ROUNDCUBE_DB_NAME}\" to \"${ROUNDCUBE_DB_USER}\""
- echo "ALTER SCHEMA public OWNER TO \"${ROUNDCUBE_DB_USER}\"\;" | postgresql_execute "$ROUNDCUBE_DB_NAME" "postgres" "$POSTGRES_POSTGRES_PASSWORD"
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- persistence:
- enabled: true
- subPath: "postgresql"
- existingClaim: mailu-storage
- persistence:
- single_pvc: true
- storageClass: "nfs-client"
- accessModes:
- - ReadWriteMany
- size: 15Gi
- claimNameOverride: mailu-storage
- ingress:
- # The default one is stupid af
- enabled: false
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- front:
- hostPort:
- enabled: false
- externalService:
- enabled: false
- ports:
- pop3s: false
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- redis:
- master:
- persistence:
- subPath: "redis"
- existingClaim: mailu-storage
- #admin:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- #postfix:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- #dovecot:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- #rspamd:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- #clamav:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- #webmail:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- #radicale:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- #fetchmail:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
- #oletools:
- #tolerations:
- # - key: "arch"
- # operator: "Equal"
- # value: "arm64"
- # effect: "NoSchedule"
diff --git a/apps/base/mailu/repository.yaml b/apps/base/mailu/repository.yaml
@@ -1,8 +0,0 @@
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: mailu
- namespace: mailu
-spec:
- interval: 5m
- url: https://mailu.github.io/helm-charts/
diff --git a/apps/base/n8n/kustomization.yaml b/apps/base/n8n/kustomization.yaml
@@ -1,7 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: n8n
-resources:
- - pvc.yaml
- - repository.yaml
- - release.yaml
diff --git a/apps/base/n8n/pvc.yaml b/apps/base/n8n/pvc.yaml
@@ -1,13 +0,0 @@
----
-apiVersion: v1
-kind: PersistentVolumeClaim
-metadata:
- name: n8n
- namespace: n8n
-spec:
- storageClassName: "nfs-csi"
- accessModes:
- - ReadWriteOnce
- resources:
- requests:
- storage: 10Gi
diff --git a/apps/base/n8n/release.yaml b/apps/base/n8n/release.yaml
@@ -1,76 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: n8n
- namespace: n8n
-spec:
- interval: 5m
- chart:
- spec:
- chart: n8n
- sourceRef:
- kind: HelmRepository
- name: n8n
- interval: 60m
- version: 0.23.0
- install:
- crds: Create
- upgrade:
- crds: CreateReplace
- # Force recreation due to Helm not properly patching Deployment with e.g. added port,
- # causing spurious drift detection
- force: true
- values:
- config:
- database:
- type: postgresdb
- postgresdb:
- database: n8n
- host: matrix-postgres-cluster.matrix-postgres-cluster.svc.cluster.local
- user: n8n
- ssl:
- enabled: true
- rejectUnauthorized: false
- generic:
- timezone: Europe/Berlin
- secret:
- database:
- postgresdb:
- password: ENC[AES256_GCM,data:efz9EautjqGTDkkZIyBEVIf83rWxdiOFRimQcyfnEUiORZtxFtmjpeERIcBVlk0uAy9eFRPfgQMCnY/EO0YVPw==,iv:TcI4a9pPAkDSSa95fthfxD9fIJCB79oYIUKIv7wjR8Q=,tag:92+M5p4HXUETAIILYCWv0g==,type:str]
- persistence:
- enabled: true
- type: existing
- existingClaim: n8n
- storageClass: nfs-csi
- ingress:
- enabled: true
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- hosts:
- - host: n8n.midnightthoughts.space
- paths:
- - /
- tls:
- - secretName: n8n.midnightthoughts.space-tls
- hosts:
- - n8n.midnightthoughts.space
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBWV2ptOFFROFBLZG9PRGJM
- bktRNW01d0h2STNXSkpSOE5zemh3YUFWcTM0Cks4eHFYKzBnRGV0bVptSUFMWFQ1
- T2IzdkR6V1poK28xY3dmaitwQ3RNTjgKLS0tIHVyVXV3MzNJTHBjeHhvTXRzY0o4
- b0Zkd1ZRRHJuQjBFM2syaEpFVWNLU1kKz4bjn5Y1zfG7JKXzWVuhj3JZeSJNB613
- XaMq42F5AAFQoUz6t3X3+gDsSCi/4iNOZpB1JzTTEPoXbH2XRsw2Rg==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-03-22T22:40:27Z"
- mac: ENC[AES256_GCM,data:HPKNXWrsHT6OKY/cEWWFju3UhFSQEaUGNEsRsCMYo/uSJDlhjVIJwWsf70miEr3Y+i6a+ZyI4yA95FBFmSjUeMo5U62MXp+yKlNdF6MX3ZkebDw24dz+3UZ2+td1tb+Pu+n8ROVl0efbsXg3QkqYcy1jANVVsMJ/pn0FW8d2qvQ=,iv:cMqw5NCKWJmaV6yF/JbN0jgnRrCZMi2Gz45HS1MLGrI=,tag:wkolFXKEshqF6hurdD4GBw==,type:str]
- pgp: []
- encrypted_regex: ^(adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
diff --git a/apps/base/n8n/repository.yaml b/apps/base/n8n/repository.yaml
@@ -1,10 +0,0 @@
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: n8n
- namespace: n8n
-spec:
- type: "oci"
- interval: 5m
- url: oci://8gears.container-registry.com/library
diff --git a/apps/base/openldap/kustomization.yaml b/apps/base/openldap/kustomization.yaml
@@ -1,7 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: openldap
-resources:
- - repository.yaml
- - release.yaml
- - ldap-ingress.yaml
diff --git a/apps/base/openldap/ldap-ingress.yaml b/apps/base/openldap/ldap-ingress.yaml
@@ -1,16 +0,0 @@
----
-apiVersion: traefik.containo.us/v1alpha1
-kind: IngressRouteTCP
-metadata:
- name: openldap
- namespace: openldap
-spec:
- entryPoints:
- - ldap
- routes:
- - match: HostSNI(`*`)
- services:
- - name: openldap
- port: ldap-port
- tls:
- secretName: users.midnightthoughts.space-tls
diff --git a/apps/base/openldap/release.yaml b/apps/base/openldap/release.yaml
@@ -1,85 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: openldap
- namespace: openldap
-spec:
- releaseName: openldap
- chart:
- spec:
- chart: openldap-stack-ha
- sourceRef:
- kind: HelmRepository
- name: openldap
- interval: 50m
- timeout: 25m
- install:
- timeout: 25m
- remediation:
- retries: 3
- values:
- replicaCount: 3
- image:
- repository: bitnami/openldap
- tag: 2.6.7
- global:
- ldapDomain: users.midnightthoughts.space
- adminUser: ENC[AES256_GCM,data:Kxna7FcULQ==,iv:BBpo1x+nv5UbhVDZKLq3w6VWKz9tP7LDuHoXY5s5DZY=,tag:X20MKxF28fgCcU2lNOC4Xg==,type:str]
- adminPassword: ENC[AES256_GCM,data:5m5ZXpNA7vhE,iv:5m+SHIZaSOAkW9vhmUdqUyet0E+mvum+KKOs5FN/RMs=,tag:l4hxTnSey4hJSyn5nMxePQ==,type:str]
- configUser: ENC[AES256_GCM,data:nY3Bw3KwPg==,iv:LHcdo0zpdAj3dGcvtdzWnM9WGQXznsbs4IKJGOrNqPg=,tag:bjghoGPwG6n4luSipAwm/Q==,type:str]
- configPassword: ENC[AES256_GCM,data:ueKvtlxnGSoi,iv:cwe9CvhtGggZJDE8e/QSTULSAHsi+8AsA8OsSI0FYNw=,tag:zerCcr16g8nkw8YlqdlLaw==,type:str]
- pdb:
- enabled: false
- persistence:
- storageClass: nfs-csi
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- initTLSSecret:
- tls_enabled: true
- secret: ENC[AES256_GCM,data:pfk0coq4zHLLdTmNHGU=,iv:+EufLq59u7nTgaSBF+xfTMmHbNneHDoUQXeEHfBkAu8=,tag:iT8qDutQquCahBGKcbkINw==,type:str]
- ltb-passwd:
- enabled: false
- env:
- LDAP_ALLOW_ANON_BINDING: "false"
- #LDAP_ENABLE_TLS: "no"
- #LDAP_LOGLEVEL: "64"
- phpldapadmin:
- enabled: true
- ingress:
- enabled: true
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- path: /
- pathType: Prefix
- ## Ingress Host
- hosts:
- - admin.users.midnightthoughts.space
- ## Ingress cert
- tls:
- - secretName: users.midnightthoughts.space-tls
- hosts:
- - users.midnightthoughts.space
- - admin.users.midnightthoughts.space
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBXWVp5MGdUL2J2Mk1URE11
- dFBidFptQjJlVlk1UGpiS0o1SnJOc09ibGg0CmZnUkticmRTT3NQWUY2TnBQM1Zq
- RE8wcDY3c3ljTHhkSmc1RUlVWWc5dWMKLS0tIERWSFdXVEMwSjJlOXMxSG5lU1BP
- bmVNalZKd3dCZFdnQU5uTERpRWluMWsKCfy6cnJuISlHdcDOhVcIno6MYWGRH6KU
- E1oDTl/Br6oiSft9TMEhAft2YdXxs8Q8Irh7pMMUtBYV1CLeYGKN0g==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-03-20T09:49:41Z"
- mac: ENC[AES256_GCM,data:UdmteMlg3MMk20IKIyZsqacO1gYzxdIFwE7KbJ4nv6jVSSqw1fdDhbYwaLvV46T97LO+sdOzhoJY+rqeiMDszLqDB+s6B7CDfravx1KPbFxaypt7hybL4yffFihSejbJCejcaCcp44M9L/bCpcI3313jWqM2oRi28L/iXbl7T3Y=,iv:MlbfoUohBOPwaQP67kFg8NQp8voz3awxEhEoK9fniRQ=,tag:orBPzLVshbjZjETPZKqu2Q==,type:str]
- pgp: []
- encrypted_regex: ^(adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
diff --git a/apps/base/openldap/repository.yaml b/apps/base/openldap/repository.yaml
@@ -1,9 +0,0 @@
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: openldap
- namespace: openldap
-spec:
- interval: 5m
- url: https://jp-gouin.github.io/helm-openldap/
diff --git a/apps/base/piwigo/kustomization.yaml b/apps/base/piwigo/kustomization.yaml
@@ -1,6 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: piwigo
-resources:
- - repository.yaml
- - release.yaml
diff --git a/apps/base/piwigo/release.yaml b/apps/base/piwigo/release.yaml
@@ -1,95 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: piwigo
- namespace: piwigo
-spec:
- releaseName: piwigo
- chart:
- spec:
- version: 9.0.5
- chart: piwigo
- sourceRef:
- kind: HelmRepository
- name: piwigo
- interval: 50m
- timeout: 25m
- install:
- timeout: 25m
- remediation:
- retries: 3
- values:
- image:
- repository: ghcr.io/linuxserver/piwigo
- pullPolicy: IfNotPresent
- tag: 14.1.0@sha256:c2183b9d2e21d025bb98ef2c32e6ee9ae71820e8b10b940899aa33572555deb2
- podOptions:
- nodeSelector: {}
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- piwigo:
- language: en_US
- admin_user: admin
- admin_pass: ENC[AES256_GCM,data:qg8JDXvEvmbu,iv:Lx58G6oqztQ21FCv2+5tnajVus0uNgY8BBskEyuBZMA=,tag:cpiSr1Z6oGA2jQlF45jKhg==,type:str]
- admin_email: ENC[AES256_GCM,data:jTaUBqrSYNMjMxJn7N4HQfn8MgUgIY8e,iv:CT9WyaE3LAHGsgfH4MPlh73Ke6zuGq+z+FiAwA0abiI=,tag:RpZZpkZiH9X65tRFOOCmOQ==,type:str]
- persistence:
- config:
- enabled: true
- type: pvc
- mountPath: /config
- size: 2Gi
- storageClass: nfs-csi
- gallery:
- enabled: true
- type: pvc
- mountPath: /gallery
- size: 25Gi
- storageClass: nfs-csi
- mariadb:
- enabled: true
- mariadbUsername: piwigo
- mariadbDatabase: piwigo
- ingress:
- main:
- enabled: true
- hosts:
- - host: piwigo.nordgedanken.dev
- paths:
- - path: /
- pathType: Prefix
- tls:
- - secretName: piwigo.nordgedanken.dev-tls
- hosts:
- - piwigo.nordgedanken.dev
- integrations:
- certManager:
- enabled: true
- certificateIssuer: letsencrypt-http
- traefik:
- enabled: false
- operator:
- verify:
- enabled: false
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSB5bm5sSGF1U0VKNEMrVitE
- RWhZSEZSRFptbXppc0V0WDhReTU2N2RXa3hjCldsTGY1SE5vcXhQL3ZwKzlnS1N6
- Y0RJRFplYXZaeDJtY0hXME9ORUVVUFEKLS0tIFljaHVsSmFielVHTTU1d0l1cWgz
- aEFSSitDeEp5bW9vZlR4OE96UXd1aFEK6S/dQHAI5ZkcX/W6kUAZHItYRrsOvuQq
- //ZB5DTAfmDeTOZFVcJJGH5TMklwBwyp7V87J+1HXc1Sd6csiMVznQ==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2023-12-31T00:44:07Z"
- mac: ENC[AES256_GCM,data:A5R8dgqx2f8jPjD8pUwWdKFOBErNaZ1YunEtHhEkq+xduMv0nqaB77IVCohYxfWfVyYowd+Xl2rbeOjlFuOTFzs37K6N6kesg7+W1dlZhBcVdiCEUliju/V/EVQZzrh93LUWhYx2OB+yc23EPrKrOZfcaIYACHof2alsSOVdHLE=,iv:mvfSzRdhQ8ENxZ4fe1l1rcf40vwk5mccD94GejUtdCE=,tag:0A5QVUImBz18NFSyjkra8g==,type:str]
- pgp: []
- encrypted_regex: ^(admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
diff --git a/apps/base/piwigo/repository.yaml b/apps/base/piwigo/repository.yaml
@@ -1,9 +0,0 @@
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: piwigo
- namespace: piwigo
-spec:
- interval: 5m
- url: https://charts.truecharts.org
diff --git a/apps/base/redmine/kustomization.yaml b/apps/base/redmine/kustomization.yaml
@@ -1,6 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: redmine
-resources:
- - repository.yaml
- - release.yaml
diff --git a/apps/base/redmine/release.yaml b/apps/base/redmine/release.yaml
@@ -1,85 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: redmine
- namespace: redmine
-spec:
- releaseName: redmine
- chart:
- spec:
- chart: redmine
- sourceRef:
- kind: HelmRepository
- name: redmine
- interval: 50m
- timeout: 25m
- install:
- timeout: 25m
- remediation:
- retries: 3
- values:
- image:
- registry: coreharbor.kubernetes.midnightthoughts.space
- repository: bitnami/redmine
- tag: latest
- pullPolicy: Always
- postgresql:
- enabled: true
- primary:
- tolerations:
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
- persistence:
- storageClass: "nfs-client"
- accessModes:
- - ReadWriteMany
- service:
- type: ClusterIP
- ingress:
- enabled: true
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- tls: true
- persistence:
- storageClass: "nfs-client"
- accessModes:
- - ReadWriteMany
- databaseType: postgresql
- mariadb:
- enabled: false
- containerSecurityContext:
- enabled: true
- capabilities:
- add: [SYS_CHROOT]
- resources:
- requests:
- cpu: 0m
- memory: 0Mi
- # initContainers:
- # - name: install-plugins
- # image: bitnami/redmine:5.0.5-debian-11-r23
- # imagePullPolicy: Always
- # env:
- # - name: REDMINE_DATABASE_TYPE
- # value: postgresql
- # - name: REDMINE_DATABASE_HOST
- # value: redmine-postgresql
- # - name: REDMINE_DATABASE_NAME
- # value: bitnami_redmine
- # - name: REDMINE_DATABASE_USER
- # value: bn_redmine
- # - name: REDMINE_DATABASE_PASSWORD
- # valueFrom:
- # secretKeyRef:
- # key: password
- # name: redmine-postgresql
- # - name: REDMINE_DATABASE_PORT_NUMBER
- # value: "5432"
- # volumeMounts:
- # - name: redmine-data
- # mountPath: /bitnami/redmine
- # command: ['/opt/bitnami/scripts/redmine/entrypoint.sh', 'source /opt/bitnami/scripts/redmine-env.sh && rm -r /bitnami/redmine/plugins && mkdir /bitnami/redmine/plugins && cd /bitnami/redmine/plugins && git clone https://github.com/devopskube/redmine_openid_connect.git && cd /opt/bitnami/redmine && bundle install && bundle exec rake redmine:plugins:migrate $REDMINE_ENV RAILS_ENV=production']
- volumePermissions:
- enabled: true
diff --git a/apps/base/redmine/repository.yaml b/apps/base/redmine/repository.yaml
@@ -1,9 +0,0 @@
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: redmine
- namespace: redmine
-spec:
- interval: 5m
- url: oci://registry-1.docker.io/bitnamicharts
- type: "oci"
diff --git a/apps/base/rook/filesystem.yaml b/apps/base/rook/filesystem.yaml
@@ -1,645 +0,0 @@
----
-apiVersion: ceph.rook.io/v1
-kind: CephCluster
-metadata:
- name: main-fs-cluster
- namespace: rook-ceph # namespace:cluster
-spec:
- cephVersion:
- # The container image used to launch the Ceph daemon pods (mon, mgr, osd, mds, rgw).
- # v16 is Pacific, and v17 is Quincy.
- # RECOMMENDATION: In production, use a specific version tag instead of the general v17 flag, which pulls the latest release and could result in different
- # versions running within the cluster. See tags available at https://hub.docker.com/r/ceph/ceph/tags/.
- # If you want to be more precise, you can always use a timestamp tag such quay.io/ceph/ceph:v17.2.6-20230410
- # This tag might not contain a new Ceph version, just security fixes from the underlying operating system, which will reduce vulnerabilities
- image: quay.io/ceph/ceph:v17.2.6
- # Whether to allow unsupported versions of Ceph. Currently `pacific` and `quincy` are supported.
- # Future versions such as `reef` (v18) would require this to be set to `true`.
- # Do not set to true in production.
- allowUnsupported: false
- # The path on the host where configuration files will be persisted. Must be specified.
- # Important: if you reinstall the cluster, make sure you delete this directory from each host or else the mons will fail to start on the new cluster.
- # In Minikube, the '/data' directory is configured to persist across reboots. Use "/data/rook" in Minikube environment.
- dataDirHostPath: /var/lib/rook
- # Whether or not upgrade should continue even if a check fails
- # This means Ceph's status could be degraded and we don't recommend upgrading but you might decide otherwise
- # Use at your OWN risk
- # To understand Rook's upgrade process of Ceph, read https://rook.io/docs/rook/latest/ceph-upgrade.html#ceph-version-upgrades
- skipUpgradeChecks: false
- # Whether or not continue if PGs are not clean during an upgrade
- continueUpgradeAfterChecksEvenIfNotHealthy: false
- # WaitTimeoutForHealthyOSDInMinutes defines the time (in minutes) the operator would wait before an OSD can be stopped for upgrade or restart.
- # If the timeout exceeds and OSD is not ok to stop, then the operator would skip upgrade for the current OSD and proceed with the next one
- # if `continueUpgradeAfterChecksEvenIfNotHealthy` is `false`. If `continueUpgradeAfterChecksEvenIfNotHealthy` is `true`, then operator would
- # continue with the upgrade of an OSD even if its not ok to stop after the timeout. This timeout won't be applied if `skipUpgradeChecks` is `true`.
- # The default wait timeout is 10 minutes.
- waitTimeoutForHealthyOSDInMinutes: 10
- mon:
- # Set the number of mons to be started. Generally recommended to be 3.
- # For highest availability, an odd number of mons should be specified.
- count: 3
- # The mons should be on unique nodes. For production, at least 3 nodes are recommended for this reason.
- # Mons should only be allowed on the same node for test environments where data loss is acceptable.
- allowMultiplePerNode: false
- mgr:
- # When higher availability of the mgr is needed, increase the count to 2.
- # In that case, one mgr will be active and one in standby. When Ceph updates which
- # mgr is active, Rook will update the mgr services to match the active mgr.
- count: 2
- allowMultiplePerNode: false
- modules:
- # Several modules should not need to be included in this list. The "dashboard" and "monitoring" modules
- # are already enabled by other settings in the cluster CR.
- - name: pg_autoscaler
- enabled: true
- - name: rook
- enabled: true
- # enable the ceph dashboard for viewing cluster status
- dashboard:
- enabled: true
- # serve the dashboard under a subpath (useful when you are accessing the dashboard via a reverse proxy)
- # urlPrefix: /ceph-dashboard
- # serve the dashboard at the given port.
- # port: 8443
- # serve the dashboard using SSL
- ssl: false
- # enable prometheus alerting for cluster
- monitoring:
- # requires Prometheus to be pre-installed
- enabled: true
- network:
- connections:
- # Whether to encrypt the data in transit across the wire to prevent eavesdropping the data on the network.
- # The default is false. When encryption is enabled, all communication between clients and Ceph daemons, or between Ceph daemons will be encrypted.
- # When encryption is not enabled, clients still establish a strong initial authentication and data integrity is still validated with a crc check.
- # IMPORTANT: Encryption requires the 5.11 kernel for the latest nbd and cephfs drivers. Alternatively for testing only,
- # you can set the "mounter: rbd-nbd" in the rbd storage class, or "mounter: fuse" in the cephfs storage class.
- # The nbd and fuse drivers are *not* recommended in production since restarting the csi driver pod will disconnect the volumes.
- encryption:
- enabled: false
- # Whether to compress the data in transit across the wire. The default is false.
- # Requires Ceph Quincy (v17) or newer. Also see the kernel requirements above for encryption.
- compression:
- enabled: false
- # Whether to require communication over msgr2. If true, the msgr v1 port (6789) will be disabled
- # and clients will be required to connect to the Ceph cluster with the v2 port (3300).
- # Requires a kernel that supports msgr v2 (kernel 5.11 or CentOS 8.4 or newer).
- requireMsgr2: false
- # enable host networking
- #provider: host
- # enable the Multus network provider
- #provider: multus
- #selectors:
- # The selector keys are required to be `public` and `cluster`.
- # Based on the configuration, the operator will do the following:
- # 1. if only the `public` selector key is specified both public_network and cluster_network Ceph settings will listen on that interface
- # 2. if both `public` and `cluster` selector keys are specified the first one will point to 'public_network' flag and the second one to 'cluster_network'
- #
- # In order to work, each selector value must match a NetworkAttachmentDefinition object in Multus
- #
- #public: public-conf --> NetworkAttachmentDefinition object name in Multus
- #cluster: cluster-conf --> NetworkAttachmentDefinition object name in Multus
- # Provide internet protocol version. IPv6, IPv4 or empty string are valid options. Empty string would mean IPv4
- #ipFamily: "IPv6"
- # Ceph daemons to listen on both IPv4 and Ipv6 networks
- #dualStack: false
- # Enable multiClusterService to export the mon and OSD services to peer cluster.
- # This is useful to support RBD mirroring between two clusters having overlapping CIDRs.
- # Ensure that peer clusters are connected using an MCS API compatible application, like Globalnet Submariner.
- #multiClusterService:
- # enabled: false
-
- # enable the crash collector for ceph daemon crash collection
- crashCollector:
- disable: false
- # Uncomment daysToRetain to prune ceph crash entries older than the
- # specified number of days.
- #daysToRetain: 30
- # enable log collector, daemons will log on files and rotate
- logCollector:
- enabled: true
- periodicity: daily # one of: hourly, daily, weekly, monthly
- maxLogSize: 500M # SUFFIX may be 'M' or 'G'. Must be at least 1M.
- # automate [data cleanup process](https://github.com/rook/rook/blob/master/Documentation/Storage-Configuration/ceph-teardown.md#delete-the-data-on-hosts) in cluster destruction.
- cleanupPolicy:
- # Since cluster cleanup is destructive to data, confirmation is required.
- # To destroy all Rook data on hosts during uninstall, confirmation must be set to "yes-really-destroy-data".
- # This value should only be set when the cluster is about to be deleted. After the confirmation is set,
- # Rook will immediately stop configuring the cluster and only wait for the delete command.
- # If the empty string is set, Rook will not destroy any data on hosts during uninstall.
- confirmation: ""
- # sanitizeDisks represents settings for sanitizing OSD disks on cluster deletion
- sanitizeDisks:
- # method indicates if the entire disk should be sanitized or simply ceph's metadata
- # in both case, re-install is possible
- # possible choices are 'complete' or 'quick' (default)
- method: quick
- # dataSource indicate where to get random bytes from to write on the disk
- # possible choices are 'zero' (default) or 'random'
- # using random sources will consume entropy from the system and will take much more time then the zero source
- dataSource: zero
- # iteration overwrite N times instead of the default (1)
- # takes an integer value
- iteration: 1
- # allowUninstallWithVolumes defines how the uninstall should be performed
- # If set to true, cephCluster deletion does not wait for the PVs to be deleted.
- allowUninstallWithVolumes: false
- # To control where various services will be scheduled by kubernetes, use the placement configuration sections below.
- # The example under 'all' would have all services scheduled on kubernetes nodes labeled with 'role=storage-node' and
- # tolerate taints with a key of 'storage-node'.
- placement:
- all:
- nodeAffinity: {}
- tolerations:
- - effect: NoSchedule
- key: node-role.kubernetes.io/control-plane
- operator: Exists
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
-
- # nodeAffinity:
- # requiredDuringSchedulingIgnoredDuringExecution:
- # nodeSelectorTerms:
- # - matchExpressions:
- # - key: role
- # operator: In
- # values:
- # - storage-node
- # podAffinity:
- # podAntiAffinity:
- # topologySpreadConstraints:
- # tolerations:
- # - key: storage-node
- # operator: Exists
- # The above placement information can also be specified for mon, osd, and mgr components
- # mon:
- # Monitor deployments may contain an anti-affinity rule for avoiding monitor
- # collocation on the same node. This is a required rule when host network is used
- # or when AllowMultiplePerNode is false. Otherwise this anti-affinity rule is a
- # preferred rule with weight: 50.
- # osd:
- # prepareosd:
- # mgr:
- # cleanup:
- annotations: {}
- # all:
- # mon:
- # osd:
- # cleanup:
- # prepareosd:
- # clusterMetadata annotations will be applied to only `rook-ceph-mon-endpoints` configmap and the `rook-ceph-mon` and `rook-ceph-admin-keyring` secrets.
- # And clusterMetadata annotations will not be merged with `all` annotations.
- # clusterMetadata:
- # kubed.appscode.com/sync: "true"
- # If no mgr annotations are set, prometheus scrape annotations will be set by default.
- # mgr:
- labels: {}
- # all:
- # mon:
- # osd:
- # cleanup:
- # mgr:
- # prepareosd:
- # monitoring is a list of key-value pairs. It is injected into all the monitoring resources created by operator.
- # These labels can be passed as LabelSelector to Prometheus
- # monitoring:
- # crashcollector:
- resources:
- #The requests and limits set here, allow the mgr pod to use half of one CPU core and 1 gigabyte of memory
- mgr:
- limits:
- cpu: "1000m"
- memory: "1024Mi"
- requests:
- cpu: "0m"
- memory: "512Mi"
- # The above example requests/limits can also be added to the other components
- mon:
- limits:
- cpu: "2000m"
- memory: "2Gi"
- requests:
- cpu: "0m"
- memory: "1024Mi"
- osd:
- limits:
- cpu: "2000m"
- memory: "4Gi"
- requests:
- cpu: "0m"
- memory: "2Gi"
- # For OSD it also is a possible to specify requests/limits based on device class
- osd-hdd:
- limits:
- cpu: "500m"
- memory: "4Gi"
- requests:
- cpu: "0m"
- memory: "2Gi"
- osd-ssd:
- limits:
- cpu: "500m"
- memory: "4Gi"
- requests:
- cpu: "0m"
- memory: "2Gi"
- osd-nvme:
- limits:
- cpu: "500m"
- memory: "4Gi"
- requests:
- cpu: "0m"
- memory: "2Gi"
- prepareosd:
- requests:
- cpu: "0m"
- memory: "50Mi"
- mgr-sidecar:
- limits:
- cpu: "500m"
- memory: "100Mi"
- requests:
- cpu: "0m"
- memory: "40Mi"
- crashcollector:
- limits:
- cpu: "500m"
- memory: "60Mi"
- requests:
- cpu: "0m"
- memory: "60Mi"
- logcollector:
- limits:
- cpu: "500m"
- memory: "1Gi"
- requests:
- cpu: "0m"
- memory: "100Mi"
- cleanup:
- limits:
- cpu: "500m"
- memory: "1Gi"
- requests:
- cpu: "0m"
- memory: "100Mi"
- # The option to automatically remove OSDs that are out and are safe to destroy.
- removeOSDsIfOutAndSafeToRemove: false
- priorityClassNames:
- #all: rook-ceph-default-priority-class
- mon: system-node-critical
- osd: system-node-critical
- mgr: system-cluster-critical
- #crashcollector: rook-ceph-crashcollector-priority-class
- storage: # cluster level storage configuration and selection
- useAllNodes: false
- useAllDevices: false
- #deviceFilter:
- #config: {}
- # crushRoot: "custom-root" # specify a non-default root label for the CRUSH map
- # metadataDevice: "md0" # specify a non-rotational storage so ceph-volume will use it as block db device of bluestore.
- # databaseSizeMB: "1024" # uncomment if the disks are smaller than 100 GB
- # journalSizeMB: "1024" # uncomment if the disks are 20 GB or smaller
- # osdsPerDevice: "1" # this value can be overridden at the node or device level
- # encryptedDevice: "true" # the default value for this option is "false"
- # Individual nodes and their config can be specified as well, but 'useAllNodes' above must be set to false. Then, only the named
- # nodes below will be used as storage resources. Each node's 'name' field should match their 'kubernetes.io/hostname' label.
- nodes:
- - name: "control-plane-2"
- devices: # specific devices to use for storage can be specified for each node
- - name: "/dev/sdb"
- resources:
- limits:
- cpu: "2"
- memory: "4096Mi"
- requests:
- cpu: "0"
- memory: "0Mi"
- - name: "control-plane-3"
- devices: # specific devices to use for storage can be specified for each node
- - name: "/dev/sdb"
- resources:
- limits:
- cpu: "2"
- memory: "4096Mi"
- requests:
- cpu: "0"
- memory: "0Mi"
- - name: "worker-1"
- devices: # specific devices to use for storage can be specified for each node
- - name: "/dev/sdb"
- resources:
- limits:
- cpu: "2"
- memory: "4096Mi"
- requests:
- cpu: "0"
- memory: "0Mi"
- # - name: "nvme01" # multiple osds can be created on high performance devices
- # config:
- # osdsPerDevice: "5"
- # - name: "/dev/disk/by-id/ata-ST4000DM004-XXXX" # devices can be specified using full udev paths
- # config: # configuration can be specified at the node level which overrides the cluster level config
- # - name: "172.17.4.301"
- # deviceFilter: "^sd."
- # when onlyApplyOSDPlacement is false, will merge both placement.All() and placement.osd
- onlyApplyOSDPlacement: false
- # The section for configuring management of daemon disruptions during upgrade or fencing.
- disruptionManagement:
- # If true, the operator will create and manage PodDisruptionBudgets for OSD, Mon, RGW, and MDS daemons. OSD PDBs are managed dynamically
- # via the strategy outlined in the [design](https://github.com/rook/rook/blob/master/design/ceph/ceph-managed-disruptionbudgets.md). The operator will
- # block eviction of OSDs by default and unblock them safely when drains are detected.
- managePodBudgets: true
- # A duration in minutes that determines how long an entire failureDomain like `region/zone/host` will be held in `noout` (in addition to the
- # default DOWN/OUT interval) when it is draining. This is only relevant when `managePodBudgets` is `true`. The default value is `30` minutes.
- osdMaintenanceTimeout: 30
- # A duration in minutes that the operator will wait for the placement groups to become healthy (active+clean) after a drain was completed and OSDs came back up.
- # Operator will continue with the next drain if the timeout exceeds. It only works if `managePodBudgets` is `true`.
- # No values or 0 means that the operator will wait until the placement groups are healthy before unblocking the next drain.
- pgHealthCheckTimeout: 0
-
- # healthChecks
- # Valid values for daemons are 'mon', 'osd', 'status'
- healthCheck:
- daemonHealth:
- mon:
- disabled: false
- interval: 45s
- osd:
- disabled: false
- interval: 60s
- status:
- disabled: false
- interval: 60s
- # Change pod liveness probe timing or threshold values. Works for all mon,mgr,osd daemons.
- livenessProbe:
- mon:
- disabled: false
- mgr:
- disabled: false
- osd:
- disabled: false
- # Change pod startup probe timing or threshold values. Works for all mon,mgr,osd daemons.
- startupProbe:
- mon:
- disabled: false
- mgr:
- disabled: false
- osd:
- disabled: false
----
-apiVersion: ceph.rook.io/v1
-kind: CephFilesystem
-metadata:
- name: main-fs
- namespace: rook-ceph
-spec:
- # The metadata pool spec. Must use replication.
- metadataPool:
- replicated:
- size: 2
- requireSafeReplicaSize: true
- parameters:
- # Inline compression mode for the data pool
- # Further reference: https://docs.ceph.com/docs/master/rados/configuration/bluestore-config-ref/#inline-compression
- compression_mode:
- none
- # gives a hint (%) to Ceph in terms of expected consumption of the total cluster capacity of a given pool
- # for more info: https://docs.ceph.com/docs/master/rados/operations/placement-groups/#specifying-expected-pool-size
- #target_size_ratio: ".5"
- # The list of data pool specs. Can use replication or erasure coding.
- dataPools:
- - name: replicated
- failureDomain: host
- replicated:
- size: 2
- # Disallow setting pool with replica 1, this could lead to data loss without recovery.
- # Make sure you're *ABSOLUTELY CERTAIN* that is what you want
- requireSafeReplicaSize: true
- parameters:
- # Inline compression mode for the data pool
- # Further reference: https://docs.ceph.com/docs/master/rados/configuration/bluestore-config-ref/#inline-compression
- compression_mode:
- none
- # gives a hint (%) to Ceph in terms of expected consumption of the total cluster capacity of a given pool
- # for more info: https://docs.ceph.com/docs/master/rados/operations/placement-groups/#specifying-expected-pool-size
- #target_size_ratio: ".5"
- # Whether to preserve filesystem after CephFilesystem CRD deletion
- preserveFilesystemOnDelete: true
- # The metadata service (mds) configuration
- metadataServer:
- # The number of active MDS instances
- activeCount: 1
- # Whether each active MDS instance will have an active standby with a warm metadata cache for faster failover.
- # If false, standbys will be available, but will not have a warm cache.
- activeStandby: true
- # The affinity rules to apply to the mds deployment
- placement:
- tolerations:
- - effect: NoSchedule
- key: node-role.kubernetes.io/control-plane
- operator: Exists
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
- # nodeAffinity:
- # requiredDuringSchedulingIgnoredDuringExecution:
- # nodeSelectorTerms:
- # - matchExpressions:
- # - key: role
- # operator: In
- # values:
- # - mds-node
- # topologySpreadConstraints:
- # tolerations:
- # - key: mds-node
- # operator: Exists
- # podAffinity:
- podAntiAffinity:
- requiredDuringSchedulingIgnoredDuringExecution:
- - labelSelector:
- matchExpressions:
- - key: app
- operator: In
- values:
- - rook-ceph-mds
- ## Add this if you want to allow mds daemons for different filesystems to run on one
- ## node. The value in "values" must match .metadata.name.
- # - key: rook_file_system
- # operator: In
- # values:
- # - myfs
- # topologyKey: kubernetes.io/hostname will place MDS across different hosts
- topologyKey: kubernetes.io/hostname
- preferredDuringSchedulingIgnoredDuringExecution:
- - weight: 100
- podAffinityTerm:
- labelSelector:
- matchExpressions:
- - key: app
- operator: In
- values:
- - rook-ceph-mds
- # topologyKey: */zone can be used to spread MDS across different AZ
- # Use <topologyKey: failure-domain.beta.kubernetes.io/zone> in k8s cluster if your cluster is v1.16 or lower
- # Use <topologyKey: topology.kubernetes.io/zone> in k8s cluster is v1.17 or upper
- topologyKey: topology.kubernetes.io/zone
- # A key/value list of annotations
- # annotations:
- # key: value
- # A key/value list of labels
- # labels:
- # key: value
- resources:
- # The requests and limits set here, allow the filesystem MDS Pod(s) to use half of one CPU core and 1 gigabyte of memory
- limits:
- cpu: "500m"
- memory: "1024Mi"
- requests:
- cpu: "0m"
- memory: "1024Mi"
- priorityClassName: system-cluster-critical
- livenessProbe:
- disabled: false
- startupProbe:
- disabled: false
----
-apiVersion: storage.k8s.io/v1
-kind: StorageClass
-metadata:
- name: rook-main-fs
- namespace: rook-cephfs
- annotations:
- storageclass.kubernetes.io/is-default-class: "false"
-# Change "rook-ceph" provisioner prefix to match the operator namespace if needed
-provisioner: rook-ceph.cephfs.csi.ceph.com # driver:namespace:operator
-parameters:
- # clusterID is the namespace where the rook cluster is running
- # If you change this namespace, also change the namespace below where the secret namespaces are defined
- clusterID: rook-ceph # namespace:cluster
-
- # CephFS filesystem name into which the volume shall be created
- fsName: main-fs
-
- # Ceph pool into which the volume shall be created
- # Required for provisionVolume: "true"
- pool: main-fs-replicated
-
- # The secrets contain Ceph admin credentials. These are generated automatically by the operator
- # in the same namespace as the cluster.
- csi.storage.k8s.io/provisioner-secret-name: rook-csi-cephfs-provisioner
- csi.storage.k8s.io/provisioner-secret-namespace: rook-ceph # namespace:cluster
- csi.storage.k8s.io/controller-expand-secret-name: rook-csi-cephfs-provisioner
- csi.storage.k8s.io/controller-expand-secret-namespace: rook-ceph # namespace:cluster
- csi.storage.k8s.io/node-stage-secret-name: rook-csi-cephfs-node
- csi.storage.k8s.io/node-stage-secret-namespace: rook-ceph # namespace:cluster
-
- # (optional) The driver can use either ceph-fuse (fuse) or ceph kernel client (kernel)
- # If omitted, default volume mounter will be used - this is determined by probing for ceph-fuse
- # or by setting the default mounter explicitly via --volumemounter command-line argument.
- # mounter: kernel
-reclaimPolicy: Retain
-allowVolumeExpansion: true
-mountOptions:
- []
- # uncomment the following line for debugging
- #- debug
----
-apiVersion: ceph.rook.io/v1
-kind: CephBlockPool
-metadata:
- name: postgres-fs
- namespace: rook-ceph
-spec:
- failureDomain: host
- replicated:
- size: 1
----
-apiVersion: storage.k8s.io/v1
-kind: StorageClass
-metadata:
- name: postgres-fs-block
-# Change "rook-ceph" provisioner prefix to match the operator namespace if needed
-provisioner: rook-ceph.rbd.csi.ceph.com
-parameters:
- # clusterID is the namespace where the rook cluster is running
- clusterID: rook-ceph
- # Ceph pool into which the RBD image shall be created
- pool: postgres-fs
-
- # (optional) mapOptions is a comma-separated list of map options.
- # For krbd options refer
- # https://docs.ceph.com/docs/master/man/8/rbd/#kernel-rbd-krbd-options
- # For nbd options refer
- # https://docs.ceph.com/docs/master/man/8/rbd-nbd/#options
- # mapOptions: lock_on_read,queue_depth=1024
-
- # (optional) unmapOptions is a comma-separated list of unmap options.
- # For krbd options refer
- # https://docs.ceph.com/docs/master/man/8/rbd/#kernel-rbd-krbd-options
- # For nbd options refer
- # https://docs.ceph.com/docs/master/man/8/rbd-nbd/#options
- # unmapOptions: force
-
- # RBD image format. Defaults to "2".
- imageFormat: "2"
-
- # RBD image features
- # Available for imageFormat: "2". Older releases of CSI RBD
- # support only the `layering` feature. The Linux kernel (KRBD) supports the
- # full complement of features as of 5.4
- # `layering` alone corresponds to Ceph's bitfield value of "2" ;
- # `layering` + `fast-diff` + `object-map` + `deep-flatten` + `exclusive-lock` together
- # correspond to Ceph's OR'd bitfield value of "63". Here we use
- # a symbolic, comma-separated format:
- # For 5.4 or later kernels:
- #imageFeatures: layering,fast-diff,object-map,deep-flatten,exclusive-lock
- # For 5.3 or earlier kernels:
- imageFeatures: layering
-
- # The secrets contain Ceph admin credentials.
- csi.storage.k8s.io/provisioner-secret-name: rook-csi-rbd-provisioner
- csi.storage.k8s.io/provisioner-secret-namespace: rook-ceph
- csi.storage.k8s.io/controller-expand-secret-name: rook-csi-rbd-provisioner
- csi.storage.k8s.io/controller-expand-secret-namespace: rook-ceph
- csi.storage.k8s.io/node-stage-secret-name: rook-csi-rbd-node
- csi.storage.k8s.io/node-stage-secret-namespace: rook-ceph
-
- # Specify the filesystem type of the volume. If not specified, csi-provisioner
- # will set default as `ext4`. Note that `xfs` is not recommended due to potential deadlock
- # in hyperconverged settings where the volume is mounted on the same node as the osds.
- csi.storage.k8s.io/fstype: ext4
-
-# Delete the rbd volume when a PVC is deleted
-reclaimPolicy: Delete
-
-# Optional, if you want to add dynamic resize for PVC.
-# For now only ext3, ext4, xfs resize support provided, like in Kubernetes itself.
-allowVolumeExpansion: true
----
-apiVersion: networking.k8s.io/v1
-kind: Ingress
-metadata:
- name: rook-main-fs-mgr-dashboard
- namespace: rook-ceph
- annotations:
- traefik.ingress.kubernetes.io/router.middlewares: traefik-ingress-sso@kubernetescrd
- cert-manager.io/cluster-issuer: letsencrypt-http
-spec:
- tls:
- - hosts:
- - rook.ceph.midnightthoughts.space
- secretName: rook.ceph.midnightthoughts.space-tls
- rules:
- - host: rook.ceph.midnightthoughts.space
- http:
- paths:
- - path: /
- pathType: Prefix
- backend:
- service:
- name: rook-ceph-mgr-dashboard
- port:
- name: http-dashboard
diff --git a/apps/base/rook/kustomization.yaml b/apps/base/rook/kustomization.yaml
@@ -1,8 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: rook-ceph
-resources:
- - repository.yaml
- - release.yaml
- - filesystem.yaml
- - monitoring.yaml
diff --git a/apps/base/rook/monitoring.yaml b/apps/base/rook/monitoring.yaml
@@ -1,652 +0,0 @@
----
-apiVersion: monitoring.coreos.com/v1
-kind: ServiceMonitor
-metadata:
- name: rook-ceph-mgr
- namespace: rook-ceph
- labels:
- team: rook
-spec:
- namespaceSelector:
- matchNames:
- - rook-ceph
- selector:
- matchLabels:
- app: rook-ceph-mgr
- rook_cluster: rook-ceph
- endpoints:
- - port: http-metrics
- path: /metrics
- interval: 5s
----
-apiVersion: monitoring.coreos.com/v1
-kind: ServiceMonitor
-metadata:
- name: rook-ceph-exporter
- namespace: rook-ceph
- labels:
- team: rook
-spec:
- namespaceSelector:
- matchNames:
- - rook-ceph
- selector:
- matchLabels:
- app: rook-ceph-exporter
- rook_cluster: rook-ceph
- ceph_daemon_id: exporter
- endpoints:
- - port: ceph-exporter-http-metrics
- path: /metrics
- interval: 5s
----
-apiVersion: monitoring.coreos.com/v1
-kind: PrometheusRule
-metadata:
- labels:
- prometheus: rook-prometheus
- role: alert-rules
- name: prometheus-ceph-rules
- namespace: rook-ceph
-spec:
- groups:
- - name: "cluster health"
- rules:
- - alert: "CephHealthError"
- annotations:
- description: "The cluster state has been HEALTH_ERROR for more than 5 minutes. Please check 'ceph health detail' for more information."
- summary: "Ceph is in the ERROR state"
- expr: "ceph_health_status == 2"
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.2.1"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephHealthWarning"
- annotations:
- description: "The cluster state has been HEALTH_WARN for more than 15 minutes. Please check 'ceph health detail' for more information."
- summary: "Ceph is in the WARNING state"
- expr: "ceph_health_status == 1"
- for: "15m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - name: "mon"
- rules:
- - alert: "CephMonDownQuorumAtRisk"
- annotations:
- description: "{{ $min := query \"floor(count(ceph_mon_metadata) / 2) + 1\" | first | value }}Quorum requires a majority of monitors (x {{ $min }}) to be active. Without quorum the cluster will become inoperable, affecting all services and connected clients. The following monitors are down: {{- range query \"(ceph_mon_quorum_status == 0) + on(ceph_daemon) group_left(hostname) (ceph_mon_metadata * 0)\" }} - {{ .Labels.ceph_daemon }} on {{ .Labels.hostname }} {{- end }}"
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-down"
- summary: "Monitor quorum is at risk"
- expr: |
- (
- (ceph_health_detail{name="MON_DOWN"} == 1) * on() (
- count(ceph_mon_quorum_status == 1) == bool (floor(count(ceph_mon_metadata) / 2) + 1)
- )
- ) == 1
- for: "30s"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.3.1"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephMonDown"
- annotations:
- description: |
- {{ $down := query "count(ceph_mon_quorum_status == 0)" | first | value }}{{ $s := "" }}{{ if gt $down 1.0 }}{{ $s = "s" }}{{ end }}You have {{ $down }} monitor{{ $s }} down. Quorum is still intact, but the loss of an additional monitor will make your cluster inoperable. The following monitors are down: {{- range query "(ceph_mon_quorum_status == 0) + on(ceph_daemon) group_left(hostname) (ceph_mon_metadata * 0)" }} - {{ .Labels.ceph_daemon }} on {{ .Labels.hostname }} {{- end }}
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-down"
- summary: "One or more monitors down"
- expr: |
- count(ceph_mon_quorum_status == 0) <= (count(ceph_mon_metadata) - floor(count(ceph_mon_metadata) / 2) + 1)
- for: "30s"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephMonDiskspaceCritical"
- annotations:
- description: "The free space available to a monitor's store is critically low. You should increase the space available to the monitor(s). The default directory is /var/lib/ceph/mon-*/data/store.db on traditional deployments, and /var/lib/rook/mon-*/data/store.db on the mon pod's worker node for Rook. Look for old, rotated versions of *.log and MANIFEST*. Do NOT touch any *.sst files. Also check any other directories under /var/lib/rook and other directories on the same filesystem, often /var/log and /var/tmp are culprits. Your monitor hosts are; {{- range query \"ceph_mon_metadata\"}} - {{ .Labels.hostname }} {{- end }}"
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-disk-crit"
- summary: "Filesystem space on at least one monitor is critically low"
- expr: "ceph_health_detail{name=\"MON_DISK_CRIT\"} == 1"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.3.2"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephMonDiskspaceLow"
- annotations:
- description: "The space available to a monitor's store is approaching full (>70% is the default). You should increase the space available to the monitor(s). The default directory is /var/lib/ceph/mon-*/data/store.db on traditional deployments, and /var/lib/rook/mon-*/data/store.db on the mon pod's worker node for Rook. Look for old, rotated versions of *.log and MANIFEST*. Do NOT touch any *.sst files. Also check any other directories under /var/lib/rook and other directories on the same filesystem, often /var/log and /var/tmp are culprits. Your monitor hosts are; {{- range query \"ceph_mon_metadata\"}} - {{ .Labels.hostname }} {{- end }}"
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-disk-low"
- summary: "Drive space on at least one monitor is approaching full"
- expr: "ceph_health_detail{name=\"MON_DISK_LOW\"} == 1"
- for: "5m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephMonClockSkew"
- annotations:
- description: "Ceph monitors rely on closely synchronized time to maintain quorum and cluster consistency. This event indicates that the time on at least one mon has drifted too far from the lead mon. Review cluster status with ceph -s. This will show which monitors are affected. Check the time sync status on each monitor host with 'ceph time-sync-status' and the state and peers of your ntpd or chrony daemon."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#mon-clock-skew"
- summary: "Clock skew detected among monitors"
- expr: "ceph_health_detail{name=\"MON_CLOCK_SKEW\"} == 1"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - name: "osd"
- rules:
- - alert: "CephOSDDownHigh"
- annotations:
- description: "{{ $value | humanize }}% or {{ with query \"count(ceph_osd_up == 0)\" }}{{ . | first | value }}{{ end }} of {{ with query \"count(ceph_osd_up)\" }}{{ . | first | value }}{{ end }} OSDs are down (>= 10%). The following OSDs are down: {{- range query \"(ceph_osd_up * on(ceph_daemon) group_left(hostname) ceph_osd_metadata) == 0\" }} - {{ .Labels.ceph_daemon }} on {{ .Labels.hostname }} {{- end }}"
- summary: "More than 10% of OSDs are down"
- expr: "count(ceph_osd_up == 0) / count(ceph_osd_up) * 100 >= 10"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.4.1"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephOSDHostDown"
- annotations:
- description: "The following OSDs are down: {{- range query \"(ceph_osd_up * on(ceph_daemon) group_left(hostname) ceph_osd_metadata) == 0\" }} - {{ .Labels.hostname }} : {{ .Labels.ceph_daemon }} {{- end }}"
- summary: "An OSD host is offline"
- expr: "ceph_health_detail{name=\"OSD_HOST_DOWN\"} == 1"
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.4.8"
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDDown"
- annotations:
- description: |
- {{ $num := query "count(ceph_osd_up == 0)" | first | value }}{{ $s := "" }}{{ if gt $num 1.0 }}{{ $s = "s" }}{{ end }}{{ $num }} OSD{{ $s }} down for over 5mins. The following OSD{{ $s }} {{ if eq $s "" }}is{{ else }}are{{ end }} down: {{- range query "(ceph_osd_up * on(ceph_daemon) group_left(hostname) ceph_osd_metadata) == 0"}} - {{ .Labels.ceph_daemon }} on {{ .Labels.hostname }} {{- end }}
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-down"
- summary: "An OSD has been marked down"
- expr: "ceph_health_detail{name=\"OSD_DOWN\"} == 1"
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.4.2"
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDNearFull"
- annotations:
- description: "One or more OSDs have reached the NEARFULL threshold. Use 'ceph health detail' and 'ceph osd df' to identify the problem. To resolve, add capacity to the affected OSD's failure domain, restore down/out OSDs, or delete unwanted data."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-nearfull"
- summary: "OSD(s) running low on free space (NEARFULL)"
- expr: "ceph_health_detail{name=\"OSD_NEARFULL\"} == 1"
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.4.3"
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDFull"
- annotations:
- description: "An OSD has reached the FULL threshold. Writes to pools that share the affected OSD will be blocked. Use 'ceph health detail' and 'ceph osd df' to identify the problem. To resolve, add capacity to the affected OSD's failure domain, restore down/out OSDs, or delete unwanted data."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-full"
- summary: "OSD full, writes blocked"
- expr: "ceph_health_detail{name=\"OSD_FULL\"} > 0"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.4.6"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephOSDBackfillFull"
- annotations:
- description: "An OSD has reached the BACKFILL FULL threshold. This will prevent rebalance operations from completing. Use 'ceph health detail' and 'ceph osd df' to identify the problem. To resolve, add capacity to the affected OSD's failure domain, restore down/out OSDs, or delete unwanted data."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-backfillfull"
- summary: "OSD(s) too full for backfill operations"
- expr: "ceph_health_detail{name=\"OSD_BACKFILLFULL\"} > 0"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDTooManyRepairs"
- annotations:
- description: "Reads from an OSD have used a secondary PG to return data to the client, indicating a potential failing drive."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#osd-too-many-repairs"
- summary: "OSD reports a high number of read errors"
- expr: "ceph_health_detail{name=\"OSD_TOO_MANY_REPAIRS\"} == 1"
- for: "30s"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDTimeoutsPublicNetwork"
- annotations:
- description: "OSD heartbeats on the cluster's 'public' network (frontend) are running slow. Investigate the network for latency or loss issues. Use 'ceph health detail' to show the affected OSDs."
- summary: "Network issues delaying OSD heartbeats (public network)"
- expr: "ceph_health_detail{name=\"OSD_SLOW_PING_TIME_FRONT\"} == 1"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDTimeoutsClusterNetwork"
- annotations:
- description: "OSD heartbeats on the cluster's 'cluster' network (backend) are slow. Investigate the network for latency issues on this subnet. Use 'ceph health detail' to show the affected OSDs."
- summary: "Network issues delaying OSD heartbeats (cluster network)"
- expr: "ceph_health_detail{name=\"OSD_SLOW_PING_TIME_BACK\"} == 1"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDInternalDiskSizeMismatch"
- annotations:
- description: "One or more OSDs have an internal inconsistency between metadata and the size of the device. This could lead to the OSD(s) crashing in future. You should redeploy the affected OSDs."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#bluestore-disk-size-mismatch"
- summary: "OSD size inconsistency error"
- expr: "ceph_health_detail{name=\"BLUESTORE_DISK_SIZE_MISMATCH\"} == 1"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephDeviceFailurePredicted"
- annotations:
- description: "The device health module has determined that one or more devices will fail soon. To review device status use 'ceph device ls'. To show a specific device use 'ceph device info <dev id>'. Mark the OSD out so that data may migrate to other OSDs. Once the OSD has drained, destroy the OSD, replace the device, and redeploy the OSD."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#id2"
- summary: "Device(s) predicted to fail soon"
- expr: "ceph_health_detail{name=\"DEVICE_HEALTH\"} == 1"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephDeviceFailurePredictionTooHigh"
- annotations:
- description: "The device health module has determined that devices predicted to fail can not be remediated automatically, since too many OSDs would be removed from the cluster to ensure performance and availabililty. Prevent data integrity issues by adding new OSDs so that data may be relocated."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#device-health-toomany"
- summary: "Too many devices are predicted to fail, unable to resolve"
- expr: "ceph_health_detail{name=\"DEVICE_HEALTH_TOOMANY\"} == 1"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.4.7"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephDeviceFailureRelocationIncomplete"
- annotations:
- description: "The device health module has determined that one or more devices will fail soon, but the normal process of relocating the data on the device to other OSDs in the cluster is blocked. \nEnsure that the cluster has available free space. It may be necessary to add capacity to the cluster to allow data from the failing device to successfully migrate, or to enable the balancer."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#device-health-in-use"
- summary: "Device failure is predicted, but unable to relocate data"
- expr: "ceph_health_detail{name=\"DEVICE_HEALTH_IN_USE\"} == 1"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDFlapping"
- annotations:
- description: "OSD {{ $labels.ceph_daemon }} on {{ $labels.hostname }} was marked down and back up {{ $value | humanize }} times once a minute for 5 minutes. This may indicate a network issue (latency, packet loss, MTU mismatch) on the cluster network, or the public network if no cluster network is deployed. Check the network stats on the listed host(s)."
- documentation: "https://docs.ceph.com/en/latest/rados/troubleshooting/troubleshooting-osd#flapping-osds"
- summary: "Network issues are causing OSDs to flap (mark each other down)"
- expr: "(rate(ceph_osd_up[5m]) * on(ceph_daemon) group_left(hostname) ceph_osd_metadata) * 60 > 1"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.4.4"
- severity: "warning"
- type: "ceph_default"
- - alert: "CephOSDReadErrors"
- annotations:
- description: "An OSD has encountered read errors, but the OSD has recovered by retrying the reads. This may indicate an issue with hardware or the kernel."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#bluestore-spurious-read-errors"
- summary: "Device read errors detected"
- expr: "ceph_health_detail{name=\"BLUESTORE_SPURIOUS_READ_ERRORS\"} == 1"
- for: "30s"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephPGImbalance"
- annotations:
- description: "OSD {{ $labels.ceph_daemon }} on {{ $labels.hostname }} deviates by more than 30% from average PG count."
- summary: "PGs are not balanced across OSDs"
- expr: |
- abs(
- ((ceph_osd_numpg > 0) - on (job) group_left avg(ceph_osd_numpg > 0) by (job)) /
- on (job) group_left avg(ceph_osd_numpg > 0) by (job)
- ) * on (ceph_daemon) group_left(hostname) ceph_osd_metadata > 0.30
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.4.5"
- severity: "warning"
- type: "ceph_default"
- - name: "mds"
- rules:
- - alert: "CephFilesystemDamaged"
- annotations:
- description: "Filesystem metadata has been corrupted. Data may be inaccessible. Analyze metrics from the MDS daemon admin socket, or escalate to support."
- documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages#cephfs-health-messages"
- summary: "CephFS filesystem is damaged."
- expr: "ceph_health_detail{name=\"MDS_DAMAGE\"} > 0"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.5.1"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephFilesystemOffline"
- annotations:
- description: "All MDS ranks are unavailable. The MDS daemons managing metadata are down, rendering the filesystem offline."
- documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#mds-all-down"
- summary: "CephFS filesystem is offline"
- expr: "ceph_health_detail{name=\"MDS_ALL_DOWN\"} > 0"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.5.3"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephFilesystemDegraded"
- annotations:
- description: "One or more metadata daemons (MDS ranks) are failed or in a damaged state. At best the filesystem is partially available, at worst the filesystem is completely unusable."
- documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#fs-degraded"
- summary: "CephFS filesystem is degraded"
- expr: "ceph_health_detail{name=\"FS_DEGRADED\"} > 0"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.5.4"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephFilesystemMDSRanksLow"
- annotations:
- description: "The filesystem's 'max_mds' setting defines the number of MDS ranks in the filesystem. The current number of active MDS daemons is less than this value."
- documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#mds-up-less-than-max"
- summary: "Ceph MDS daemon count is lower than configured"
- expr: "ceph_health_detail{name=\"MDS_UP_LESS_THAN_MAX\"} > 0"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephFilesystemInsufficientStandby"
- annotations:
- description: "The minimum number of standby daemons required by standby_count_wanted is less than the current number of standby daemons. Adjust the standby count or increase the number of MDS daemons."
- documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#mds-insufficient-standby"
- summary: "Ceph filesystem standby daemons too few"
- expr: "ceph_health_detail{name=\"MDS_INSUFFICIENT_STANDBY\"} > 0"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephFilesystemFailureNoStandby"
- annotations:
- description: "An MDS daemon has failed, leaving only one active rank and no available standby. Investigate the cause of the failure or add a standby MDS."
- documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages/#fs-with-failed-mds"
- summary: "MDS daemon failed, no further standby available"
- expr: "ceph_health_detail{name=\"FS_WITH_FAILED_MDS\"} > 0"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.5.5"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephFilesystemReadOnly"
- annotations:
- description: "The filesystem has switched to READ ONLY due to an unexpected error when writing to the metadata pool. Either analyze the output from the MDS daemon admin socket, or escalate to support."
- documentation: "https://docs.ceph.com/en/latest/cephfs/health-messages#cephfs-health-messages"
- summary: "CephFS filesystem in read only mode due to write error(s)"
- expr: "ceph_health_detail{name=\"MDS_HEALTH_READ_ONLY\"} > 0"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.5.2"
- severity: "critical"
- type: "ceph_default"
- - name: "mgr"
- rules:
- - alert: "CephMgrModuleCrash"
- annotations:
- description: "One or more mgr modules have crashed and have yet to be acknowledged by an administrator. A crashed module may impact functionality within the cluster. Use the 'ceph crash' command to determine which module has failed, and archive it to acknowledge the failure."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#recent-mgr-module-crash"
- summary: "A manager module has recently crashed"
- expr: "ceph_health_detail{name=\"RECENT_MGR_MODULE_CRASH\"} == 1"
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.6.1"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephMgrPrometheusModuleInactive"
- annotations:
- description: "The mgr/prometheus module at {{ $labels.instance }} is unreachable. This could mean that the module has been disabled or the mgr daemon itself is down. Without the mgr/prometheus module metrics and alerts will no longer function. Open a shell to an admin node or toolbox pod and use 'ceph -s' to to determine whether the mgr is active. If the mgr is not active, restart it, otherwise you can determine module status with 'ceph mgr module ls'. If it is not listed as enabled, enable it with 'ceph mgr module enable prometheus'."
- summary: "The mgr/prometheus module is not available"
- expr: "up{job=\"ceph\"} == 0"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.6.2"
- severity: "critical"
- type: "ceph_default"
- - name: "pgs"
- rules:
- - alert: "CephPGsInactive"
- annotations:
- description: "{{ $value }} PGs have been inactive for more than 5 minutes in pool {{ $labels.name }}. Inactive placement groups are not able to serve read/write requests."
- summary: "One or more placement groups are inactive"
- expr: "ceph_pool_metadata * on(pool_id,instance) group_left() (ceph_pg_total - ceph_pg_active) > 0"
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.7.1"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephPGsUnclean"
- annotations:
- description: "{{ $value }} PGs have been unclean for more than 15 minutes in pool {{ $labels.name }}. Unclean PGs have not recovered from a previous failure."
- summary: "One or more placement groups are marked unclean"
- expr: "ceph_pool_metadata * on(pool_id,instance) group_left() (ceph_pg_total - ceph_pg_clean) > 0"
- for: "15m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.7.2"
- severity: "warning"
- type: "ceph_default"
- - alert: "CephPGsDamaged"
- annotations:
- description: "During data consistency checks (scrub), at least one PG has been flagged as being damaged or inconsistent. Check to see which PG is affected, and attempt a manual repair if necessary. To list problematic placement groups, use 'rados list-inconsistent-pg <pool>'. To repair PGs use the 'ceph pg repair <pg_num>' command."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-damaged"
- summary: "Placement group damaged, manual intervention needed"
- expr: "ceph_health_detail{name=~\"PG_DAMAGED|OSD_SCRUB_ERRORS\"} == 1"
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.7.4"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephPGRecoveryAtRisk"
- annotations:
- description: "Data redundancy is at risk since one or more OSDs are at or above the 'full' threshold. Add more capacity to the cluster, restore down/out OSDs, or delete unwanted data."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-recovery-full"
- summary: "OSDs are too full for recovery"
- expr: "ceph_health_detail{name=\"PG_RECOVERY_FULL\"} == 1"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.7.5"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephPGUnavilableBlockingIO"
- annotations:
- description: "Data availability is reduced, impacting the cluster's ability to service I/O. One or more placement groups (PGs) are in a state that blocks I/O."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-availability"
- summary: "PG is unavailable, blocking I/O"
- expr: "((ceph_health_detail{name=\"PG_AVAILABILITY\"} == 1) - scalar(ceph_health_detail{name=\"OSD_DOWN\"})) == 1"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.7.3"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephPGBackfillAtRisk"
- annotations:
- description: "Data redundancy may be at risk due to lack of free space within the cluster. One or more OSDs have reached the 'backfillfull' threshold. Add more capacity, or delete unwanted data."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-backfill-full"
- summary: "Backfill operations are blocked due to lack of free space"
- expr: "ceph_health_detail{name=\"PG_BACKFILL_FULL\"} == 1"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.7.6"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephPGNotScrubbed"
- annotations:
- description: "One or more PGs have not been scrubbed recently. Scrubs check metadata integrity, protecting against bit-rot. They check that metadata is consistent across data replicas. When PGs miss their scrub interval, it may indicate that the scrub window is too small, or PGs were not in a 'clean' state during the scrub window. You can manually initiate a scrub with: ceph pg scrub <pgid>"
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-not-scrubbed"
- summary: "Placement group(s) have not been scrubbed"
- expr: "ceph_health_detail{name=\"PG_NOT_SCRUBBED\"} == 1"
- for: "5m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephPGsHighPerOSD"
- annotations:
- description: "The number of placement groups per OSD is too high (exceeds the mon_max_pg_per_osd setting).\n Check that the pg_autoscaler has not been disabled for any pools with 'ceph osd pool autoscale-status', and that the profile selected is appropriate. You may also adjust the target_size_ratio of a pool to guide the autoscaler based on the expected relative size of the pool ('ceph osd pool set cephfs.cephfs.meta target_size_ratio .1') or set the pg_autoscaler mode to 'warn' and adjust pg_num appropriately for one or more pools."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks/#too-many-pgs"
- summary: "Placement groups per OSD is too high"
- expr: "ceph_health_detail{name=\"TOO_MANY_PGS\"} == 1"
- for: "1m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephPGNotDeepScrubbed"
- annotations:
- description: "One or more PGs have not been deep scrubbed recently. Deep scrubs protect against bit-rot. They compare data replicas to ensure consistency. When PGs miss their deep scrub interval, it may indicate that the window is too small or PGs were not in a 'clean' state during the deep-scrub window."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pg-not-deep-scrubbed"
- summary: "Placement group(s) have not been deep scrubbed"
- expr: "ceph_health_detail{name=\"PG_NOT_DEEP_SCRUBBED\"} == 1"
- for: "5m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - name: "nodes"
- rules:
- - alert: "CephNodeRootFilesystemFull"
- annotations:
- description: "Root volume is dangerously full: {{ $value | humanize }}% free."
- summary: "Root filesystem is dangerously full"
- expr: "node_filesystem_avail_bytes{mountpoint=\"/\"} / node_filesystem_size_bytes{mountpoint=\"/\"} * 100 < 5"
- for: "5m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.8.1"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephNodeNetworkPacketDrops"
- annotations:
- description: "Node {{ $labels.instance }} experiences packet drop > 0.5% or > 10 packets/s on interface {{ $labels.device }}."
- summary: "One or more NICs reports packet drops"
- expr: |
- (
- rate(node_network_receive_drop_total{device!="lo"}[1m]) +
- rate(node_network_transmit_drop_total{device!="lo"}[1m])
- ) / (
- rate(node_network_receive_packets_total{device!="lo"}[1m]) +
- rate(node_network_transmit_packets_total{device!="lo"}[1m])
- ) >= 0.0050000000000000001 and (
- rate(node_network_receive_drop_total{device!="lo"}[1m]) +
- rate(node_network_transmit_drop_total{device!="lo"}[1m])
- ) >= 10
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.8.2"
- severity: "warning"
- type: "ceph_default"
- - alert: "CephNodeNetworkPacketErrors"
- annotations:
- description: "Node {{ $labels.instance }} experiences packet errors > 0.01% or > 10 packets/s on interface {{ $labels.device }}."
- summary: "One or more NICs reports packet errors"
- expr: |
- (
- rate(node_network_receive_errs_total{device!="lo"}[1m]) +
- rate(node_network_transmit_errs_total{device!="lo"}[1m])
- ) / (
- rate(node_network_receive_packets_total{device!="lo"}[1m]) +
- rate(node_network_transmit_packets_total{device!="lo"}[1m])
- ) >= 0.0001 or (
- rate(node_network_receive_errs_total{device!="lo"}[1m]) +
- rate(node_network_transmit_errs_total{device!="lo"}[1m])
- ) >= 10
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.8.3"
- severity: "warning"
- type: "ceph_default"
- - alert: "CephNodeNetworkBondDegraded"
- annotations:
- summary: "Degraded Bond on Node {{ $labels.instance }}"
- description: "Bond {{ $labels.master }} is degraded on Node {{ $labels.instance }}."
- expr: |
- node_bonding_slaves - node_bonding_active != 0
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephNodeDiskspaceWarning"
- annotations:
- description: "Mountpoint {{ $labels.mountpoint }} on {{ $labels.nodename }} will be full in less than 5 days based on the 48 hour trailing fill rate."
- summary: "Host filesystem free space is getting low"
- expr: "predict_linear(node_filesystem_free_bytes{device=~\"/.*\"}[2d], 3600 * 24 * 5) *on(instance) group_left(nodename) node_uname_info < 0"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.8.4"
- severity: "warning"
- type: "ceph_default"
- - alert: "CephNodeInconsistentMTU"
- annotations:
- description: "Node {{ $labels.instance }} has a different MTU size ({{ $value }}) than the median of devices named {{ $labels.device }}."
- summary: "MTU settings across Ceph hosts are inconsistent"
- expr: "node_network_mtu_bytes * (node_network_up{device!=\"lo\"} > 0) == scalar( max by (device) (node_network_mtu_bytes * (node_network_up{device!=\"lo\"} > 0)) != quantile by (device) (.5, node_network_mtu_bytes * (node_network_up{device!=\"lo\"} > 0)) )or node_network_mtu_bytes * (node_network_up{device!=\"lo\"} > 0) == scalar( min by (device) (node_network_mtu_bytes * (node_network_up{device!=\"lo\"} > 0)) != quantile by (device) (.5, node_network_mtu_bytes * (node_network_up{device!=\"lo\"} > 0)) )"
- labels:
- severity: "warning"
- type: "ceph_default"
- - name: "pools"
- rules:
- - alert: "CephPoolBackfillFull"
- annotations:
- description: "A pool is approaching the near full threshold, which will prevent recovery/backfill operations from completing. Consider adding more capacity."
- summary: "Free space in a pool is too low for recovery/backfill"
- expr: "ceph_health_detail{name=\"POOL_BACKFILLFULL\"} > 0"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephPoolFull"
- annotations:
- description: "A pool has reached its MAX quota, or OSDs supporting the pool have reached the FULL threshold. Until this is resolved, writes to the pool will be blocked. Pool Breakdown (top 5) {{- range query \"topk(5, sort_desc(ceph_pool_percent_used * on(pool_id) group_right ceph_pool_metadata))\" }} - {{ .Labels.name }} at {{ .Value }}% {{- end }} Increase the pool's quota, or add capacity to the cluster first then increase the pool's quota (e.g. ceph osd pool set quota <pool_name> max_bytes <bytes>)"
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#pool-full"
- summary: "Pool is full - writes are blocked"
- expr: "ceph_health_detail{name=\"POOL_FULL\"} > 0"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.9.1"
- severity: "critical"
- type: "ceph_default"
- - alert: "CephPoolNearFull"
- annotations:
- description: "A pool has exceeded the warning (percent full) threshold, or OSDs supporting the pool have reached the NEARFULL threshold. Writes may continue, but you are at risk of the pool going read-only if more capacity isn't made available. Determine the affected pool with 'ceph df detail', looking at QUOTA BYTES and STORED. Increase the pool's quota, or add capacity to the cluster first then increase the pool's quota (e.g. ceph osd pool set quota <pool_name> max_bytes <bytes>). Also ensure that the balancer is active."
- summary: "One or more Ceph pools are nearly full"
- expr: "ceph_health_detail{name=\"POOL_NEAR_FULL\"} > 0"
- for: "5m"
- labels:
- severity: "warning"
- type: "ceph_default"
- - name: "healthchecks"
- rules:
- - alert: "CephSlowOps"
- annotations:
- description: "{{ $value }} OSD requests are taking too long to process (osd_op_complaint_time exceeded)"
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#slow-ops"
- summary: "OSD operations are slow to complete"
- expr: "ceph_healthcheck_slow_ops > 0"
- for: "30s"
- labels:
- severity: "warning"
- type: "ceph_default"
- - alert: "CephDaemonSlowOps"
- for: "30s"
- expr: "ceph_daemon_health_metrics{type=\"SLOW_OPS\"} > 0"
- labels:
- severity: 'warning'
- type: 'ceph_default'
- annotations:
- summary: "{{ $labels.ceph_daemon }} operations are slow to complete"
- description: "{{ $labels.ceph_daemon }} operations are taking too long to process (complaint time exceeded)"
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#slow-ops"
- - name: "rados"
- rules:
- - alert: "CephObjectMissing"
- annotations:
- description: "The latest version of a RADOS object can not be found, even though all OSDs are up. I/O requests for this object from clients will block (hang). Resolving this issue may require the object to be rolled back to a prior version manually, and manually verified."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks#object-unfound"
- summary: "Object(s) marked UNFOUND"
- expr: "(ceph_health_detail{name=\"OBJECT_UNFOUND\"} == 1) * on() (count(ceph_osd_up == 1) == bool count(ceph_osd_metadata)) == 1"
- for: "30s"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.10.1"
- severity: "critical"
- type: "ceph_default"
- - name: "generic"
- rules:
- - alert: "CephDaemonCrash"
- annotations:
- description: "One or more daemons have crashed recently, and need to be acknowledged. This notification ensures that software crashes do not go unseen. To acknowledge a crash, use the 'ceph crash archive <id>' command."
- documentation: "https://docs.ceph.com/en/latest/rados/operations/health-checks/#recent-crash"
- summary: "One or more Ceph daemons have crashed, and are pending acknowledgement"
- expr: "ceph_health_detail{name=\"RECENT_CRASH\"} == 1"
- for: "1m"
- labels:
- oid: "1.3.6.1.4.1.50495.1.2.1.1.2"
- severity: "critical"
- type: "ceph_default"
diff --git a/apps/base/rook/release.yaml b/apps/base/rook/release.yaml
@@ -1,286 +0,0 @@
----
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: rook-ceph
- namespace: rook-ceph
-spec:
- interval: 5m
- chart:
- spec:
- version: "1.11.x"
- chart: rook-ceph
- sourceRef:
- kind: HelmRepository
- name: rook-ceph
- interval: 60m
- install:
- crds: Create
- upgrade:
- crds: CreateReplace
- values:
- crds:
- enabled: false
- monitoring:
- enabled: true
- enableDiscoveryDaemon: true
-# ---
-# apiVersion: helm.toolkit.fluxcd.io/v2beta1
-# kind: HelmRelease
-# metadata:
-# name: rook-ceph-cluster
-# namespace: rook-ceph
-# spec:
-# interval: 5m
-# chart:
-# spec:
-# version: "1.11.x"
-# chart: rook-ceph-cluster
-# sourceRef:
-# kind: HelmRepository
-# name: rook-ceph
-# interval: 60m
-# install:
-# crds: Create
-# upgrade:
-# crds: CreateReplace
-# values:
-# toolbox:
-# enabled: false
-# monitoring:
-# enabled: true
-# createPrometheusRules: true
-# cephClusterSpec:
-# cephVersion:
-# image: quay.io/ceph/ceph:v17.2.6
-# mon:
-# # Set the number of mons to be started. Generally recommended to be 3.
-# # For highest availability, an odd number of mons should be specified.
-# count: 3
-# # The mons should be on unique nodes. For production, at least 3 nodes are recommended for this reason.
-# # Mons should only be allowed on the same node for test environments where data loss is acceptable.
-# allowMultiplePerNode: false
-# mgr:
-# # When higher availability of the mgr is needed, increase the count to 2.
-# # In that case, one mgr will be active and one in standby. When Ceph updates which
-# # mgr is active, Rook will update the mgr services to match the active mgr.
-# count: 2
-# allowMultiplePerNode: false
-# modules:
-# # Several modules should not need to be included in this list. The "dashboard" and "monitoring" modules
-# # are already enabled by other settings in the cluster CR.
-# - name: pg_autoscaler
-# enabled: true
-
-# # enable the ceph dashboard for viewing cluster status
-# dashboard:
-# enabled: true
-# # serve the dashboard under a subpath (useful when you are accessing the dashboard via a reverse proxy)
-# # urlPrefix: /ceph-dashboard
-# # serve the dashboard at the given port.
-# # port: 8443
-# # Serve the dashboard using SSL (if using ingress to expose the dashboard and `ssl: true` you need to set
-# # the corresponding "backend protocol" annotation(s) for your ingress controller of choice)
-# ssl: false
-# storage:
-# useAllNodes: false
-# nodes:
-# - name: "control-plane-2"
-# devices:
-# - name: "sdb"
-# - name: "control-plane-3"
-# devices:
-# - name: "sdb"
-# placement:
-# all:
-# nodeAffinity: null
-# tolerations:
-# - effect: NoSchedule
-# key: node-role.kubernetes.io/control-plane
-# operator: Exists
-# resources:
-# mgr:
-# limits:
-# cpu: "1000m"
-# memory: "1Gi"
-# requests:
-# cpu: "0m"
-# memory: "512Mi"
-# mon:
-# limits:
-# cpu: "2000m"
-# memory: "2Gi"
-# requests:
-# cpu: "0m"
-# memory: "1Gi"
-# osd:
-# limits:
-# cpu: "2000m"
-# memory: "4Gi"
-# requests:
-# cpu: "0m"
-# memory: "4Gi"
-# prepareosd:
-# # limits: It is not recommended to set limits on the OSD prepare job
-# # since it's a one-time burst for memory that must be allowed to
-# # complete without an OOM kill. Note however that if a k8s
-# # limitRange guardrail is defined external to Rook, the lack of
-# # a limit here may result in a sync failure, in which case a
-# # limit should be added. 1200Mi may suffice for up to 15Ti
-# # OSDs ; for larger devices 2Gi may be required.
-# # cf. https://github.com/rook/rook/pull/11103
-# requests:
-# cpu: "0m"
-# memory: "50Mi"
-# mgr-sidecar:
-# limits:
-# cpu: "500m"
-# memory: "100Mi"
-# requests:
-# cpu: "0m"
-# memory: "40Mi"
-# crashcollector:
-# limits:
-# cpu: "500m"
-# memory: "60Mi"
-# requests:
-# cpu: "0m"
-# memory: "60Mi"
-# logcollector:
-# limits:
-# cpu: "500m"
-# memory: "1Gi"
-# requests:
-# cpu: "0m"
-# memory: "100Mi"
-# cleanup:
-# limits:
-# cpu: "500m"
-# memory: "1Gi"
-# requests:
-# cpu: "0m"
-# memory: "100Mi"
-# ingress:
-# # -- Enable an ingress for the ceph-dashboard
-# dashboard:
-# annotations:
-# traefik.ingress.kubernetes.io/router.middlewares: traefik-ingress-sso@kubernetescrd
-# cert-manager.io/cluster-issuer: letsencrypt-http
-# host:
-# name: dashboard.ceph.midnightthoughts.space
-# #path: "/ceph-dashboard(/|$)(.*)"
-# path: /
-# tls:
-# - hosts:
-# - dashboard.ceph.midnightthoughts.space
-# secretName: dashboard.ceph.midnightthoughts.space-tls
-# cephBlockPools: []
-# # - name: ceph-blockpool
-# # # see https://github.com/rook/rook/blob/master/Documentation/CRDs/Block-Storage/ceph-block-pool-crd.md#spec for available configuration
-# # spec:
-# # failureDomain: host
-# # replicated:
-# # size: 2
-# # # Enables collecting RBD per-image IO statistics by enabling dynamic OSD performance counters. Defaults to false.
-# # # For reference: https://docs.ceph.com/docs/master/mgr/prometheus/#rbd-io-statistics
-# # # enableRBDStats: true
-# # storageClass:
-# # enabled: true
-# # name: ceph-block
-# # isDefault: false
-# # reclaimPolicy: Retain
-# # allowVolumeExpansion: true
-# # volumeBindingMode: "Immediate"
-# # mountOptions: []
-# # # see https://kubernetes.io/docs/concepts/storage/storage-classes/#allowed-topologies
-# # allowedTopologies: []
-# # # - matchLabelExpressions:
-# # # - key: rook-ceph-role
-# # # values:
-# # # - storage-node
-# # # see https://github.com/rook/rook/blob/master/Documentation/ceph-block.md#provision-storage for available configuration
-# # parameters:
-# # # (optional) mapOptions is a comma-separated list of map options.
-# # # For krbd options refer
-# # # https://docs.ceph.com/docs/master/man/8/rbd/#kernel-rbd-krbd-options
-# # # For nbd options refer
-# # # https://docs.ceph.com/docs/master/man/8/rbd-nbd/#options
-# # # mapOptions: lock_on_read,queue_depth=1024
-
-# # # (optional) unmapOptions is a comma-separated list of unmap options.
-# # # For krbd options refer
-# # # https://docs.ceph.com/docs/master/man/8/rbd/#kernel-rbd-krbd-options
-# # # For nbd options refer
-# # # https://docs.ceph.com/docs/master/man/8/rbd-nbd/#options
-# # # unmapOptions: force
-
-# # # RBD image format. Defaults to "2".
-# # imageFormat: "2"
-
-# # # RBD image features, equivalent to OR'd bitfield value: 63
-# # # Available for imageFormat: "2". Older releases of CSI RBD
-# # # support only the `layering` feature. The Linux kernel (KRBD) supports the
-# # # full feature complement as of 5.4
-# # imageFeatures: layering
-
-# # # These secrets contain Ceph admin credentials.
-# # csi.storage.k8s.io/provisioner-secret-name: rook-csi-rbd-provisioner
-# # csi.storage.k8s.io/provisioner-secret-namespace: "{{ .Release.Namespace }}"
-# # csi.storage.k8s.io/controller-expand-secret-name: rook-csi-rbd-provisioner
-# # csi.storage.k8s.io/controller-expand-secret-namespace: "{{ .Release.Namespace }}"
-# # csi.storage.k8s.io/node-stage-secret-name: rook-csi-rbd-node
-# # csi.storage.k8s.io/node-stage-secret-namespace: "{{ .Release.Namespace }}"
-# # # Specify the filesystem type of the volume. If not specified, csi-provisioner
-# # # will set default as `ext4`. Note that `xfs` is not recommended due to potential deadlock
-# # # in hyperconverged settings where the volume is mounted on the same node as the osds.
-# # csi.storage.k8s.io/fstype: ext4
-# # -- A list of CephFileSystem configurations to deploy
-# # @default -- See [below](#ceph-file-systems)
-# cephFileSystems:
-# - name: ceph-filesystem
-# # see https://github.com/rook/rook/blob/master/Documentation/CRDs/Shared-Filesystem/ceph-filesystem-crd.md#filesystem-settings for available configuration
-# spec:
-# metadataPool:
-# replicated:
-# size: 2
-# dataPools:
-# - failureDomain: host
-# replicated:
-# size: 2
-# # Optional and highly recommended, 'data0' by default, see https://github.com/rook/rook/blob/master/Documentation/CRDs/Shared-Filesystem/ceph-filesystem-crd.md#pools
-# name: data0
-# metadataServer:
-# activeCount: 1
-# activeStandby: true
-# resources:
-# limits:
-# cpu: "2000m"
-# memory: "4Gi"
-# requests:
-# cpu: "0m"
-# memory: "4Gi"
-# priorityClassName: system-cluster-critical
-# storageClass:
-# enabled: true
-# isDefault: false
-# name: ceph-filesystem
-# # (Optional) specify a data pool to use, must be the name of one of the data pools above, 'data0' by default
-# pool: data0
-# reclaimPolicy: Retain
-# allowVolumeExpansion: true
-# volumeBindingMode: "Immediate"
-# mountOptions: []
-# # see https://github.com/rook/rook/blob/master/Documentation/ceph-filesystem.md#provision-storage for available configuration
-# parameters:
-# # The secrets contain Ceph admin credentials.
-# csi.storage.k8s.io/provisioner-secret-name: rook-csi-cephfs-provisioner
-# csi.storage.k8s.io/provisioner-secret-namespace: "{{ .Release.Namespace }}"
-# csi.storage.k8s.io/controller-expand-secret-name: rook-csi-cephfs-provisioner
-# csi.storage.k8s.io/controller-expand-secret-namespace: "{{ .Release.Namespace }}"
-# csi.storage.k8s.io/node-stage-secret-name: rook-csi-cephfs-node
-# csi.storage.k8s.io/node-stage-secret-namespace: "{{ .Release.Namespace }}"
-# # Specify the filesystem type of the volume. If not specified, csi-provisioner
-# # will set default as `ext4`. Note that `xfs` is not recommended due to potential deadlock
-# # in hyperconverged settings where the volume is mounted on the same node as the osds.
-# csi.storage.k8s.io/fstype: ext4
-# cephObjectStores: []
diff --git a/apps/base/rook/repository.yaml b/apps/base/rook/repository.yaml
@@ -1,9 +0,0 @@
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: rook-ceph
- namespace: rook-ceph
-spec:
- interval: 120m
- type: default
- url: https://charts.rook.io/release
diff --git a/apps/base/woodpecker/kustomization.yaml b/apps/base/woodpecker/kustomization.yaml
@@ -1,6 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: woodpecker
-resources:
- - repository.yaml
- - release.yaml
diff --git a/apps/base/woodpecker/release.yaml b/apps/base/woodpecker/release.yaml
@@ -1,54 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: woodpecker
- namespace: woodpecker
-spec:
- releaseName: woodpecker
- chart:
- spec:
- chart: woodpecker-server
- sourceRef:
- kind: HelmRepository
- name: woodpecker
- interval: 50m
- install:
- remediation:
- retries: 3
- # Default values
- # https://github.com/stefanprodan/podinfo/blob/master/charts/podinfo/values.yaml
- values:
- image:
- registry: docker.io
- repository: woodpeckerci/woodpecker-server
- pullPolicy: Always
- # Overrides the image tag whose default is the chart appVersion.
- tag: "next"
- replicaCount: 1
-
- updateStrategy:
- rollingUpdate:
- maxUnavailable: 1
- maxSurge: 0
- type: RollingUpdate
-
- env:
- WOODPECKER_GITEA: true
- WOODPECKER_GITHUB: false
- WOODPECKER_DEBUG_PRETTY: "true"
- WOODPECKER_LOG_LEVEL: debug
-
- persistentVolume:
- enabled: true
- size: 10Gi
- mountPath: "/var/lib/woodpecker"
- storageClass: "nfs-client"
-
- extraSecretNamesForEnvFrom:
- - woodpecker-gitea-client
- - woodpecker-gitea-secret
- - woodpecker-secret
-
- serviceAccount:
- # Specifies whether a service account should be created (also see RBAC subsection)
- create: true
diff --git a/apps/base/woodpecker/repository.yaml b/apps/base/woodpecker/repository.yaml
@@ -1,8 +0,0 @@
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: woodpecker
- namespace: woodpecker
-spec:
- interval: 5m
- url: https://woodpecker-ci.org/
diff --git a/apps/base/workadventure/kustomization.yaml b/apps/base/workadventure/kustomization.yaml
@@ -1,6 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: workadventure
-resources:
- - repository.yaml
- - release.yaml
diff --git a/apps/base/workadventure/release.yaml b/apps/base/workadventure/release.yaml
@@ -1,113 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: workadventure
- namespace: workadventure
-spec:
- interval: 5m
- chart:
- spec:
- chart: workadventure
- sourceRef:
- kind: HelmRepository
- name: workadventure
- interval: 60m
- version: 0.0.9-dev1
- install:
- crds: Create
- upgrade:
- crds: CreateReplace
- # Force recreation due to Helm not properly patching Deployment with e.g. added port,
- # causing spurious drift detection
- force: true
- values:
- domainName: workadventure.midnightthoughts.space
- ejabberdDomain: ejabberd.workadventure.midnightthoughts.space
- play:
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- secretEnv:
- ROOM_API_SECRET_KEY: ENC[AES256_GCM,data:CSafytKq0HQErE5yUsJubdTzUMRwyfxRbz0YyhFDdsw5hXtOvxpT0MWdOmterCjoaI8SEcLhiYrB62mM4cq88g==,iv:v4ZgN06iwC+dt2FH4plUTefBrKdxEBvvWC/ezPkW8PY=,tag:bLlYnU/Cb8GKBQmDTG/aOA==,type:str]
- ingress:
- tls: true
- chat:
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- ingress:
- tls: true
- uploader:
- ingress:
- tls: true
- maps:
- ingress:
- tls: true
- icon:
- ingress:
- tls: true
- back:
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- ejabberd:
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- ingress:
- tls: true
- mapstorage:
- tolerations:
- - key: arch
- operator: Equal
- value: arm64
- effect: NoSchedule
- ingress:
- tls: true
- persistence:
- enabled: true
- storageClass: nfs-csi
- accessMode: ReadWriteOnce
- storageSize: 1Gi
- secretEnv:
- AUTHENTICATION_PASSWORD: ENC[AES256_GCM,data:NgKi2dF9vPV26DhS/Vg5JnC72bktKvxK+msMVxMhBzMUQXCFP8UMkWa2ZKfovb7SsAOq2HK0TMZbnwO1JFlsLg==,iv:4sPOIeyogKzx6PYpiVVRBvzi9C8a4P6JA0/NIZTANjg=,tag:7DVx9pY0zB6fSsaOuRLZNA==,type:str]
- ingress:
- enabled: false
- tls: true
- secretName: workadventure.midnightthoughts.space-tls
- annotationsRoot:
- cert-manager.io/cluster-issuer: letsencrypt-http
- annotationsPath:
- cert-manager.io/cluster-issuer: letsencrypt-http
- annotationsMapstoragePath:
- cert-manager.io/cluster-issuer: letsencrypt-http
- annotationsEjabbberd:
- cert-manager.io/cluster-issuer: letsencrypt-http
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBIVjAvby96RGxsN0p0OThQ
- ZmNlRUhPNkpreDI3TlE2ekdUUjNkSjRRREhNCllHZXg1dTlhUjRPaE15N0x3bWM5
- bDFyUnBHOTVmaDN2c25xMkIrdTFSdTAKLS0tIEJ5Zk5LZjBOUUhUV1k0SldSZnNr
- ajdUVXhGd1pYM2pXYTgrRFRzTHgwT1EKAGQDPLTqSNUOGt9WdY6y8/3Edr6/MNlF
- C/AAh+2C4Cr7bUQ++/CdlRBlBVeKuk2iSMXi42Im0kFNGG3CNvNJJg==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-03-27T11:03:19Z"
- mac: ENC[AES256_GCM,data:BqmNaZhfC/sxcUoZevK/+5tGcc87HXAaR0Jn761bkln0RGkezwiJ4XB+VvpthkQMRLyqFZuQJbnnHWN/pBFRy+1vVeQRUpwBSWQRQbusk4NvX72m2wCz9PONlzPMhWRNW0x6UrkN0XdwWf8q1ptgn0zWU1fR+TDFBOAV59zSUQE=,iv:Xt47bGfp76DgmpPdLugOZIiGEvMLBtYZKjmpRtnyLZU=,tag:e4+Yel25ozzIl6gf/ZVfaw==,type:str]
- pgp: []
- encrypted_regex: ^(AUTHENTICATION_PASSWORD|ROOM_API_SECRET_KEY|adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
diff --git a/apps/base/workadventure/repository.yaml b/apps/base/workadventure/repository.yaml
@@ -1,9 +0,0 @@
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: workadventure
- namespace: workadventure
-spec:
- interval: 5m
- url: https://charts.workadventu.re/
diff --git a/apps/base/xandikos/kustomization.yaml b/apps/base/xandikos/kustomization.yaml
@@ -1,5 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: xandikos
-resources:
- - release.yaml
diff --git a/apps/base/xandikos/release.yaml b/apps/base/xandikos/release.yaml
@@ -1,168 +0,0 @@
----
-apiVersion: apps/v1
-kind: Deployment
-metadata:
- name: xandikos
- namespace: xandikos
-spec:
- strategy:
- rollingUpdate:
- maxSurge: 1
- maxUnavailable: 1
- type: RollingUpdate
- replicas: 1
- selector:
- matchLabels:
- app: xandikos
- template:
- metadata:
- labels:
- app: xandikos
- spec:
- containers:
- - name: xandikos
- image: ghcr.io/jelmer/xandikos
- imagePullPolicy: Always
- command:
- - "python3"
- - "-m"
- - "xandikos.web"
- - "--port=8080"
- - "-d/data"
- - "--defaults"
- - "--listen-address=0.0.0.0"
- - "--current-user-principal=/mtrnord"
- - "--route-prefix=/dav"
- resources:
- limits:
- cpu: "2"
- memory: "2Gi"
- requests:
- cpu: "0.1"
- memory: "10M"
- livenessProbe:
- httpGet:
- path: /health
- port: 8081
- initialDelaySeconds: 30
- periodSeconds: 3
- timeoutSeconds: 90
- ports:
- - containerPort: 8080
- - containerPort: 8081
- volumeMounts:
- - name: xandikos-volume
- mountPath: /data
- volumes:
- - name: xandikos-volume
- persistentVolumeClaim:
- claimName: xandikos
----
-apiVersion: v1
-kind: PersistentVolumeClaim
-metadata:
- name: xandikos
- namespace: xandikos
-spec:
- storageClassName: "nfs-client"
- accessModes:
- - ReadWriteMany
- resources:
- requests:
- storage: 10Gi
----
-apiVersion: v1
-kind: Service
-metadata:
- name: xandikos
- labels:
- app: xandikos
- namespace: xandikos
-spec:
- ports:
- - port: 8080
- name: web
- - port: 8081
- name: metrics
- selector:
- app: xandikos
- type: ClusterIP
----
-apiVersion: monitoring.coreos.com/v1
-kind: ServiceMonitor
-metadata:
- name: xandikos
- namespace: xandikos
- labels:
- app: xandikos
-spec:
- selector:
- matchLabels:
- app: xandikos
- endpoints:
- - port: metrics
----
-apiVersion: networking.k8s.io/v1
-kind: Ingress
-metadata:
- name: xandikos
- namespace: xandikos
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- traefik.ingress.kubernetes.io/router.middlewares: xandikos-xandikos-auth@kubernetescrd
-spec:
- rules:
- - host: midnightthoughts.space
- http:
- paths:
- - backend:
- service:
- name: xandikos
- port:
- name: web
- path: /dav
- pathType: Prefix
- tls:
- - hosts:
- - midnightthoughts.space
- secretName: midnightthoughts.space-tls
----
-apiVersion: networking.k8s.io/v1
-kind: Ingress
-metadata:
- name: xandikos-wellknown
- namespace: xandikos
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
-spec:
- rules:
- - host: midnightthoughts.space
- http:
- paths:
- - backend:
- service:
- name: xandikos
- port:
- name: web
- path: /.well-known/carddav
- pathType: Exact
- - backend:
- service:
- name: xandikos
- port:
- name: web
- path: /.well-known/caldav
- pathType: Exact
- tls:
- - hosts:
- - midnightthoughts.space
- secretName: midnightthoughts.space-tls
----
-apiVersion: traefik.io/v1alpha1
-kind: Middleware
-metadata:
- name: xandikos-auth
- namespace: xandikos
-spec:
- basicAuth:
- secret: authsecret-xandikos
diff --git a/apps/production/forgejo.yaml b/apps/production/forgejo.yaml
@@ -1,10 +0,0 @@
----
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: forgejo
- namespace: forgejo
-spec:
- chart:
- spec:
- version: "5.0.5"
diff --git a/apps/production/woodpecker-values.yaml b/apps/production/woodpecker-values.yaml
@@ -1,27 +0,0 @@
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: woodpecker
- namespace: woodpecker
-spec:
- chart:
- spec:
- version: "0.15.6"
- values:
- env:
- WOODPECKER_ADMIN: "mtrnord"
- WOODPECKER_HOST: https://ci.nordgedanken.dev
- WOODPECKER_GITEA_URL: https://git.nordgedanken.dev
- ingress:
- enabled: true
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
-
- hosts:
- - host: ci.nordgedanken.dev
- paths:
- - path: /
- tls:
- - secretName: ci.nordgedanken.dev-tls
- hosts:
- - ci.nordgedanken.dev
diff --git a/infrastructure_old/configs/calico.yaml b/infrastructure_old/configs/calico.yaml
@@ -1,119 +0,0 @@
----
-apiVersion: operator.tigera.io/v1
-kind: Installation
-metadata:
- name: default
-spec:
- typhaMetricsPort: 9093
- # Configures Calico networking.
- calicoNetwork:
- #Limited by the vms. The main host can do jumbo packages
- mtu: 1380
- nodeAddressAutodetectionV4:
- firstFound: false
- kubernetes: NodeInternalIP
- nodeAddressAutodetectionV6:
- firstFound: false
- kubernetes: NodeInternalIP
- # Note: The ipPools section cannot be modified post-install.
- ipPools:
- - blockSize: 24
- cidr: 10.244.0.0/16
- encapsulation: VXLANCrossSubnet
- natOutgoing: Enabled
- nodeSelector: all()
- - blockSize: 116
- cidr: fc00:0::/96
- encapsulation: VXLANCrossSubnet
- natOutgoing: Enabled
- nodeSelector: all()
----
-apiVersion: crd.projectcalico.org/v1
-kind: IPPool
-metadata:
- annotations:
- projectcalico.org/metadata: '{"uid":"97ec4c07-4a0e-47c5-9774-edf72c1fe0de","creationTimestamp":"2023-04-09T20:03:11Z"}'
- creationTimestamp: "2023-04-09T20:03:11Z"
- name: default-ipv4-ippool
- uid: efbc8cb5-aee0-4686-9ffa-955d888fed2b
-spec:
- allowedUses:
- - Workload
- - Tunnel
- blockSize: 24
- cidr: 10.244.0.0/16
- ipipMode: Never
- natOutgoing: true
- nodeSelector: all()
- vxlanMode: CrossSubnet
----
-apiVersion: crd.projectcalico.org/v1
-kind: IPPool
-metadata:
- annotations:
- projectcalico.org/metadata: '{"uid":"d12ff40b-eae6-4923-9646-2e62633c54de","creationTimestamp":"2023-04-09T20:03:11Z"}'
- creationTimestamp: "2023-04-09T20:03:11Z"
- name: default-ipv6-ippool
- uid: b749fcca-8f0d-4729-8625-cb012d85a467
-spec:
- allowedUses:
- - Workload
- - Tunnel
- blockSize: 116
- cidr: fc00::/96
- ipipMode: Never
- natOutgoing: true
- nodeSelector: all()
- vxlanMode: CrossSubnet
----
-# This section configures the Calico API server.
-# For more information, see: https://projectcalico.docs.tigera.io/master/reference/installation/api#operator.tigera.io/v1.APIServer
-apiVersion: operator.tigera.io/v1
-kind: APIServer
-metadata:
- name: default
-spec: {}
----
-apiVersion: v1
-kind: Service
-metadata:
- labels:
- k8s-app: calico-felix
- name: felix-metrics-svc
- namespace: calico-system
-spec:
- clusterIP: None
- ports:
- - name: metrics-port
- port: 9091
- selector:
- k8s-app: calico-node
----
-apiVersion: v1
-kind: Service
-metadata:
- labels:
- k8s-app: calico-typha
- name: typha-metrics-svc
- namespace: calico-system
-spec:
- clusterIP: None
- ports:
- - name: metrics-port
- port: 9093
- selector:
- k8s-app: calico-typha
----
-apiVersion: monitoring.coreos.com/v1
-kind: ServiceMonitor
-metadata:
- name: calico
- namespace: calico-system
-spec:
- endpoints:
- - port: metrics-port
- selector:
- matchExpressions:
- - key: k8s-app
- operator: In
- values: ["calico-node", "calico-typha", "calico-kube-controllers"]
diff --git a/infrastructure_old/configs/cluster-issuers.yaml b/infrastructure_old/configs/cluster-issuers.yaml
@@ -1,87 +0,0 @@
-# ---
-# apiVersion: cert-manager.io/v1
-# kind: ClusterIssuer
-# metadata:
-# name: letsencrypt-dns
-# spec:
-# acme:
-# email: info@nordgedanken.dev
-# # The server is replaced in /clusters/production/infrastructure.yaml
-# server: https://acme-staging-v02.api.letsencrypt.org/directory
-# privateKeySecretRef:
-# name: letsencrypt-dns-account-key
-# solvers:
-# # - dns01:
-# # rfc2136:
-# # nameserver: "[2a01:4f9:4a:451c:2::5]:53"
-# # tsigAlgorithm: HMACSHA256
-# # tsigKeyName: lego_letsencrypt
-# # tsigSecretSecretRef:
-# # key: tsig-secret
-# # name: tsig-secret
-# - http01:
-# ingress:
-# ingressClassName: traefik
-# serviceType: ClusterIP
-#
-# Blocked by https://github.com/cilium/cilium/issues/21926
-# ---
-# apiVersion: gateway.networking.k8s.io/v1
-# kind: Gateway
-# metadata:
-# name: cert-manager
-# namespace: cert-manager
-# spec:
-# gatewayClassName: cilium
-# listeners:
-# - name: http
-# protocol: HTTP
-# port: 80
-# allowedRoutes:
-# namespaces:
-# from: All
-# addresses:
-# - type: "IPAddress"
-# value: 10.0.1.2
-# - type: "IPAddress"
-# value: 10.0.2.3
-# - type: "IPAddress"
-# value: 10.0.2.2
----
-apiVersion: cert-manager.io/v1
-kind: ClusterIssuer
-metadata:
- name: letsencrypt-http
-spec:
- acme:
- email: info@nordgedanken.dev
- # The server is replaced in /clusters/production/infrastructure.yaml
- server: https://acme-staging-v02.api.letsencrypt.org/directory
- privateKeySecretRef:
- name: letsencrypt-dns-account-key
- solvers:
- - http01:
- ingress:
- ingressClassName: traefik
- serviceType: ClusterIP
-# ---
-# apiVersion: cert-manager.io/v1
-# kind: ClusterIssuer
-# metadata:
-# name: letsencrypt-http-gwapi
-# spec:
-# acme:
-# email: info@nordgedanken.dev
-# # The server is replaced in /clusters/production/infrastructure.yaml
-# server: https://acme-staging-v02.api.letsencrypt.org/directory
-# privateKeySecretRef:
-# name: letsencrypt-dns-account-key
-# solvers:
-# - http01:
-# gatewayHTTPRoute:
-# parentRefs:
-# - name: cert-manager
-# namespace: cert-manager
-# kind: Gateway
----
-# Fix for flux
diff --git a/infrastructure_old/configs/flux-grafana.yaml b/infrastructure_old/configs/flux-grafana.yaml
@@ -1,25 +0,0 @@
----
-apiVersion: notification.toolkit.fluxcd.io/v1beta2
-kind: Alert
-metadata:
- name: grafana
- namespace: monitoring
-spec:
- providerRef:
- name: grafana
- eventSeverity: info
- eventSources:
- - kind: GitRepository
- name: "*"
- namespace: flux-system
----
-apiVersion: notification.toolkit.fluxcd.io/v1beta2
-kind: Provider
-metadata:
- name: grafana
- namespace: monitoring
-spec:
- type: grafana
- address: "http://kube-prometheus-grafana.monitoring/api/annotations"
- secretRef:
- name: grafana-auth
diff --git a/infrastructure_old/configs/kustomization.yaml b/infrastructure_old/configs/kustomization.yaml
@@ -1,8 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-resources:
- - cluster-issuers.yaml
- - flux-grafana.yaml
- - priority-classes.yaml
- - postgres-clusters.yaml
- #- calico.yaml
diff --git a/infrastructure_old/configs/postgres-clusters.yaml b/infrastructure_old/configs/postgres-clusters.yaml
@@ -1,160 +0,0 @@
----
-apiVersion: v1
-kind: Namespace
-metadata:
- name: matrix-postgres-cluster
----
-apiVersion: acid.zalan.do/v1
-kind: postgresql
-metadata:
- labels:
- team: matrix
- name: matrix-postgres-cluster
- namespace: matrix-postgres-cluster
-spec:
- tolerations:
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
- enableShmVolume: true
- databases:
- synapse: synapse
- draupnir_synapse: draupnir_synapse
- element_call_synapse: element_call_synapse
- matrix_media_repo: matrix_media_repo
- syncv3: syncv3
- signal_bridge: signal_bridge
- instagram_bridge: instagram_bridge
- zammad: zammad
- bench: bench
- paperless: paperless
- umami: umami
- authentik: authentik
- netbox: netbox
- spec_testing: spec_testing
- n8n: n8n
- forgejo: forgejo
- numberOfInstances: 3
- resources:
- requests:
- cpu: 150m
- memory: 5Gi
- limits:
- cpu: 2000m
- memory: 10Gi
- postgresql:
- version: "15"
- parameters:
- # Connectivity
- max_connections: "340"
- superuser_reserved_connections: "3"
-
- # Memory settings
- shared_buffers: "4GB"
- work_mem: "64 MB"
- maintenance_work_mem: "1GB"
- huge_pages: off
- effective_cache_size: "11 GB"
- effective_io_concurrency: "100"
- random_page_cost: "1.1"
-
- # Cost of a sequentially-fetched disk page
- seq_page_cost: "0.7"
- # Cost of processing each row in a query
- cpu_tuple_cost: "0.01"
-
- # Cost of processing each index entry during an index scan
- cpu_index_tuple_cost: "0.005"
-
- # Cost of processing each operator or function executed during a query
- cpu_operator_cost: "0.0025"
-
- # Cost of setting up parallel workers for a parallel operation
- parallel_setup_cost: "1000.0"
-
- # Minimum amount of table data for a parallel scan to be considered
- min_parallel_table_scan_size: "8MB"
-
-
- # Monitoring
- shared_preload_libraries: "pg_buffercache,pg_stat_statements"
- track_io_timing: on
- track_functions: pl
-
- # Replication
- wal_level: replica
- max_wal_senders: "10"
- synchronous_commit: on
-
- # Checkpointing
- checkpoint_timeout: "15 min"
- checkpoint_completion_target: "0.9"
- min_wal_size: "1GB"
- max_wal_size: "8GB"
-
- # archive_mode: on # having it on enables activating P.I.T.R. at a later time without restart
- # archive_command: "/bin/true" # not doing anything yet with WAL-s
-
- password_encryption: scram-sha-256
-
- # WAL writing
- wal_compression: "on"
- wal_buffers: "-1"
- wal_writer_delay: 200ms
- wal_writer_flush_after: 1MB
- wal_keep_size: "3650 MB"
-
- # Background writer
- bgwriter_delay: 200ms
- bgwriter_lru_maxpages: "100"
- bgwriter_lru_multiplier: "2.0"
- bgwriter_flush_after: "0"
-
- # Parallel queries
- max_worker_processes: "12"
- max_parallel_workers_per_gather: "6"
- max_parallel_maintenance_workers: "6"
- max_parallel_workers: "12"
- parallel_leader_participation: "on"
-
- # Advanced features
- enable_partitionwise_join: "on"
- enable_partitionwise_aggregate: "on"
- jit: "on"
- max_slot_wal_keep_size: "1000 MB"
- track_wal_io_timing: "on"
- maintenance_io_concurrency: "150"
- wal_recycle: "on"
-
- autovacuum_analyze_scale_factor: "0.05"
- autovacuum_vacuum_scale_factor: "0.02"
- autovacuum_vacuum_cost_limit: "400"
- vacuum_cost_limit: "300"
-
- teamId: matrix
- users:
- synapse: []
- draupnir_synapse: []
- element_call_synapse: []
- matrix_media_repo: []
- syncv3: []
- signal_bridge: []
- instagram_bridge: []
- zammad: []
- bench: []
- paperless: []
- umami: []
- authentik: []
- netbox: []
- spec_testing: []
- n8n: []
- forgejo: []
- volume:
- size: 50Gi
- storageClass: local-hostpath
-
- patroni:
- failsafe_mode: true
- synchronous_mode: false
- #synchronous_mode: true
diff --git a/infrastructure_old/configs/priority-classes.yaml b/infrastructure_old/configs/priority-classes.yaml
@@ -1,8 +0,0 @@
----
-apiVersion: scheduling.k8s.io/v1
-kind: PriorityClass
-metadata:
- name: gitea
-value: 1000000000
-globalDefault: false
-description: "This priority class should be used for things related to the gitea instance only. It contains the configurations and therefor is highly important."
diff --git a/infrastructure_old/controllers/calico.yaml b/infrastructure_old/controllers/calico.yaml
@@ -1,23747 +0,0 @@
-apiVersion: v1
-kind: Namespace
-metadata:
- name: tigera-operator
- labels:
- name: tigera-operator
----
-# Source: crds/calico/crd.projectcalico.org_bgpconfigurations.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: bgpconfigurations.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: BGPConfiguration
- listKind: BGPConfigurationList
- plural: bgpconfigurations
- singular: bgpconfiguration
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- description: BGPConfiguration contains the configuration for any BGP routing.
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description: BGPConfigurationSpec contains the values of the BGP configuration.
- properties:
- asNumber:
- description:
- "ASNumber is the default AS number used by a node. [Default:
- 64512]"
- format: int32
- type: integer
- bindMode:
- description:
- BindMode indicates whether to listen for BGP connections
- on all addresses (None) or only on the node's canonical IP address
- Node.Spec.BGP.IPvXAddress (NodeIP). Default behaviour is to listen
- for BGP connections on all addresses.
- type: string
- communities:
- description:
- Communities is a list of BGP community values and their
- arbitrary names for tagging routes.
- items:
- description:
- Community contains standard or large community value
- and its name.
- properties:
- name:
- description: Name given to community value.
- type: string
- value:
- description:
- Value must be of format `aa:nn` or `aa:nn:mm`.
- For standard community use `aa:nn` format, where `aa` and
- `nn` are 16 bit number. For large community use `aa:nn:mm`
- format, where `aa`, `nn` and `mm` are 32 bit number. Where,
- `aa` is an AS Number, `nn` and `mm` are per-AS identifier.
- pattern: ^(\d+):(\d+)$|^(\d+):(\d+):(\d+)$
- type: string
- type: object
- type: array
- ignoredInterfaces:
- description:
- IgnoredInterfaces indicates the network interfaces that
- needs to be excluded when reading device routes.
- items:
- type: string
- type: array
- listenPort:
- description:
- ListenPort is the port where BGP protocol should listen.
- Defaults to 179
- maximum: 65535
- minimum: 1
- type: integer
- logSeverityScreen:
- description:
- "LogSeverityScreen is the log severity above which logs
- are sent to the stdout. [Default: INFO]"
- type: string
- nodeMeshMaxRestartTime:
- description:
- Time to allow for software restart for node-to-mesh peerings. When
- specified, this is configured as the graceful restart timeout. When
- not specified, the BIRD default of 120s is used. This field can
- only be set on the default BGPConfiguration instance and requires
- that NodeMesh is enabled
- type: string
- nodeMeshPassword:
- description:
- Optional BGP password for full node-to-mesh peerings.
- This field can only be set on the default BGPConfiguration instance
- and requires that NodeMesh is enabled
- properties:
- secretKeyRef:
- description: Selects a key of a secret in the node pod's namespace.
- properties:
- key:
- description:
- The key of the secret to select from. Must be
- a valid secret key.
- type: string
- name:
- description:
- "Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
- TODO: Add other useful fields. apiVersion, kind, uid?"
- type: string
- optional:
- description:
- Specify whether the Secret or its key must be
- defined
- type: boolean
- required:
- - key
- type: object
- type: object
- nodeToNodeMeshEnabled:
- description:
- "NodeToNodeMeshEnabled sets whether full node to node
- BGP mesh is enabled. [Default: true]"
- type: boolean
- prefixAdvertisements:
- description:
- PrefixAdvertisements contains per-prefix advertisement
- configuration.
- items:
- description:
- PrefixAdvertisement configures advertisement properties
- for the specified CIDR.
- properties:
- cidr:
- description: CIDR for which properties should be advertised.
- type: string
- communities:
- description:
- Communities can be list of either community names
- already defined in `Specs.Communities` or community value
- of format `aa:nn` or `aa:nn:mm`. For standard community use
- `aa:nn` format, where `aa` and `nn` are 16 bit number. For
- large community use `aa:nn:mm` format, where `aa`, `nn` and
- `mm` are 32 bit number. Where,`aa` is an AS Number, `nn` and
- `mm` are per-AS identifier.
- items:
- type: string
- type: array
- type: object
- type: array
- serviceClusterIPs:
- description:
- ServiceClusterIPs are the CIDR blocks from which service
- cluster IPs are allocated. If specified, Calico will advertise these
- blocks, as well as any cluster IPs within them.
- items:
- description:
- ServiceClusterIPBlock represents a single allowed ClusterIP
- CIDR block.
- properties:
- cidr:
- type: string
- type: object
- type: array
- serviceExternalIPs:
- description:
- ServiceExternalIPs are the CIDR blocks for Kubernetes
- Service External IPs. Kubernetes Service ExternalIPs will only be
- advertised if they are within one of these blocks.
- items:
- description:
- ServiceExternalIPBlock represents a single allowed
- External IP CIDR block.
- properties:
- cidr:
- type: string
- type: object
- type: array
- serviceLoadBalancerIPs:
- description:
- ServiceLoadBalancerIPs are the CIDR blocks for Kubernetes
- Service LoadBalancer IPs. Kubernetes Service status.LoadBalancer.Ingress
- IPs will only be advertised if they are within one of these blocks.
- items:
- description:
- ServiceLoadBalancerIPBlock represents a single allowed
- LoadBalancer IP CIDR block.
- properties:
- cidr:
- type: string
- type: object
- type: array
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_bgpfilters.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- annotations:
- controller-gen.kubebuilder.io/version: (devel)
- creationTimestamp: null
- name: bgpfilters.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: BGPFilter
- listKind: BGPFilterList
- plural: bgpfilters
- singular: bgpfilter
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- BGPFilterSpec contains the IPv4 and IPv6 filter rules of
- the BGP Filter.
- properties:
- exportV4:
- description:
- The ordered set of IPv4 BGPFilter rules acting on exporting
- routes to a peer.
- items:
- description:
- BGPFilterRuleV4 defines a BGP filter rule consisting
- a single IPv4 CIDR block and a filter action for this CIDR.
- properties:
- action:
- type: string
- cidr:
- type: string
- matchOperator:
- type: string
- required:
- - action
- - cidr
- - matchOperator
- type: object
- type: array
- exportV6:
- description:
- The ordered set of IPv6 BGPFilter rules acting on exporting
- routes to a peer.
- items:
- description:
- BGPFilterRuleV6 defines a BGP filter rule consisting
- a single IPv6 CIDR block and a filter action for this CIDR.
- properties:
- action:
- type: string
- cidr:
- type: string
- matchOperator:
- type: string
- required:
- - action
- - cidr
- - matchOperator
- type: object
- type: array
- importV4:
- description:
- The ordered set of IPv4 BGPFilter rules acting on importing
- routes from a peer.
- items:
- description:
- BGPFilterRuleV4 defines a BGP filter rule consisting
- a single IPv4 CIDR block and a filter action for this CIDR.
- properties:
- action:
- type: string
- cidr:
- type: string
- matchOperator:
- type: string
- required:
- - action
- - cidr
- - matchOperator
- type: object
- type: array
- importV6:
- description:
- The ordered set of IPv6 BGPFilter rules acting on importing
- routes from a peer.
- items:
- description:
- BGPFilterRuleV6 defines a BGP filter rule consisting
- a single IPv6 CIDR block and a filter action for this CIDR.
- properties:
- action:
- type: string
- cidr:
- type: string
- matchOperator:
- type: string
- required:
- - action
- - cidr
- - matchOperator
- type: object
- type: array
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_bgppeers.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: bgppeers.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: BGPPeer
- listKind: BGPPeerList
- plural: bgppeers
- singular: bgppeer
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description: BGPPeerSpec contains the specification for a BGPPeer resource.
- properties:
- asNumber:
- description: The AS Number of the peer.
- format: int32
- type: integer
- filters:
- description: The ordered set of BGPFilters applied on this BGP peer.
- items:
- type: string
- type: array
- keepOriginalNextHop:
- description:
- Option to keep the original nexthop field when routes
- are sent to a BGP Peer. Setting "true" configures the selected BGP
- Peers node to use the "next hop keep;" instead of "next hop self;"(default)
- in the specific branch of the Node on "bird.cfg".
- type: boolean
- maxRestartTime:
- description:
- Time to allow for software restart. When specified,
- this is configured as the graceful restart timeout. When not specified,
- the BIRD default of 120s is used.
- type: string
- node:
- description:
- The node name identifying the Calico node instance that
- is targeted by this peer. If this is not set, and no nodeSelector
- is specified, then this BGP peer selects all nodes in the cluster.
- type: string
- nodeSelector:
- description:
- Selector for the nodes that should have this peering. When
- this is set, the Node field must be empty.
- type: string
- numAllowedLocalASNumbers:
- description:
- Maximum number of local AS numbers that are allowed in
- the AS path for received routes. This removes BGP loop prevention
- and should only be used if absolutely necesssary.
- format: int32
- type: integer
- password:
- description:
- Optional BGP password for the peerings generated by this
- BGPPeer resource.
- properties:
- secretKeyRef:
- description: Selects a key of a secret in the node pod's namespace.
- properties:
- key:
- description:
- The key of the secret to select from. Must be
- a valid secret key.
- type: string
- name:
- description:
- "Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
- TODO: Add other useful fields. apiVersion, kind, uid?"
- type: string
- optional:
- description:
- Specify whether the Secret or its key must be
- defined
- type: boolean
- required:
- - key
- type: object
- type: object
- peerIP:
- description:
- The IP address of the peer followed by an optional port
- number to peer with. If port number is given, format should be `[<IPv6>]:port`
- or `<IPv4>:<port>` for IPv4. If optional port number is not set,
- and this peer IP and ASNumber belongs to a calico/node with ListenPort
- set in BGPConfiguration, then we use that port to peer.
- type: string
- peerSelector:
- description:
- Selector for the remote nodes to peer with. When this
- is set, the PeerIP and ASNumber fields must be empty. For each
- peering between the local node and selected remote nodes, we configure
- an IPv4 peering if both ends have NodeBGPSpec.IPv4Address specified,
- and an IPv6 peering if both ends have NodeBGPSpec.IPv6Address specified. The
- remote AS number comes from the remote node's NodeBGPSpec.ASNumber,
- or the global default if that is not set.
- type: string
- reachableBy:
- description:
- Add an exact, i.e. /32, static route toward peer IP in
- order to prevent route flapping. ReachableBy contains the address
- of the gateway which peer can be reached by.
- type: string
- sourceAddress:
- description:
- Specifies whether and how to configure a source address
- for the peerings generated by this BGPPeer resource. Default value
- "UseNodeIP" means to configure the node IP as the source address. "None"
- means not to configure a source address.
- type: string
- ttlSecurity:
- description:
- TTLSecurity enables the generalized TTL security mechanism
- (GTSM) which protects against spoofed packets by ignoring received
- packets with a smaller than expected TTL value. The provided value
- is the number of hops (edges) between the peers.
- type: integer
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_blockaffinities.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: blockaffinities.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: BlockAffinity
- listKind: BlockAffinityList
- plural: blockaffinities
- singular: blockaffinity
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- BlockAffinitySpec contains the specification for a BlockAffinity
- resource.
- properties:
- cidr:
- type: string
- deleted:
- description:
- Deleted indicates that this block affinity is being deleted.
- This field is a string for compatibility with older releases that
- mistakenly treat this field as a string.
- type: string
- node:
- type: string
- state:
- type: string
- required:
- - cidr
- - deleted
- - node
- - state
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_caliconodestatuses.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- annotations:
- controller-gen.kubebuilder.io/version: (devel)
- creationTimestamp: null
- name: caliconodestatuses.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: CalicoNodeStatus
- listKind: CalicoNodeStatusList
- plural: caliconodestatuses
- singular: caliconodestatus
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- CalicoNodeStatusSpec contains the specification for a CalicoNodeStatus
- resource.
- properties:
- classes:
- description:
- Classes declares the types of information to monitor
- for this calico/node, and allows for selective status reporting
- about certain subsets of information.
- items:
- type: string
- type: array
- node:
- description:
- The node name identifies the Calico node instance for
- node status.
- type: string
- updatePeriodSeconds:
- description:
- UpdatePeriodSeconds is the period at which CalicoNodeStatus
- should be updated. Set to 0 to disable CalicoNodeStatus refresh.
- Maximum update period is one day.
- format: int32
- type: integer
- type: object
- status:
- description:
- CalicoNodeStatusStatus defines the observed state of CalicoNodeStatus.
- No validation needed for status since it is updated by Calico.
- properties:
- agent:
- description: Agent holds agent status on the node.
- properties:
- birdV4:
- description: BIRDV4 represents the latest observed status of bird4.
- properties:
- lastBootTime:
- description:
- LastBootTime holds the value of lastBootTime
- from bird.ctl output.
- type: string
- lastReconfigurationTime:
- description:
- LastReconfigurationTime holds the value of lastReconfigTime
- from bird.ctl output.
- type: string
- routerID:
- description: Router ID used by bird.
- type: string
- state:
- description: The state of the BGP Daemon.
- type: string
- version:
- description: Version of the BGP daemon
- type: string
- type: object
- birdV6:
- description: BIRDV6 represents the latest observed status of bird6.
- properties:
- lastBootTime:
- description:
- LastBootTime holds the value of lastBootTime
- from bird.ctl output.
- type: string
- lastReconfigurationTime:
- description:
- LastReconfigurationTime holds the value of lastReconfigTime
- from bird.ctl output.
- type: string
- routerID:
- description: Router ID used by bird.
- type: string
- state:
- description: The state of the BGP Daemon.
- type: string
- version:
- description: Version of the BGP daemon
- type: string
- type: object
- type: object
- bgp:
- description: BGP holds node BGP status.
- properties:
- numberEstablishedV4:
- description: The total number of IPv4 established bgp sessions.
- type: integer
- numberEstablishedV6:
- description: The total number of IPv6 established bgp sessions.
- type: integer
- numberNotEstablishedV4:
- description: The total number of IPv4 non-established bgp sessions.
- type: integer
- numberNotEstablishedV6:
- description: The total number of IPv6 non-established bgp sessions.
- type: integer
- peersV4:
- description: PeersV4 represents IPv4 BGP peers status on the node.
- items:
- description:
- CalicoNodePeer contains the status of BGP peers
- on the node.
- properties:
- peerIP:
- description:
- IP address of the peer whose condition we are
- reporting.
- type: string
- since:
- description: Since the state or reason last changed.
- type: string
- state:
- description: State is the BGP session state.
- type: string
- type:
- description:
- Type indicates whether this peer is configured
- via the node-to-node mesh, or via en explicit global or
- per-node BGPPeer object.
- type: string
- type: object
- type: array
- peersV6:
- description: PeersV6 represents IPv6 BGP peers status on the node.
- items:
- description:
- CalicoNodePeer contains the status of BGP peers
- on the node.
- properties:
- peerIP:
- description:
- IP address of the peer whose condition we are
- reporting.
- type: string
- since:
- description: Since the state or reason last changed.
- type: string
- state:
- description: State is the BGP session state.
- type: string
- type:
- description:
- Type indicates whether this peer is configured
- via the node-to-node mesh, or via en explicit global or
- per-node BGPPeer object.
- type: string
- type: object
- type: array
- required:
- - numberEstablishedV4
- - numberEstablishedV6
- - numberNotEstablishedV4
- - numberNotEstablishedV6
- type: object
- lastUpdated:
- description:
- LastUpdated is a timestamp representing the server time
- when CalicoNodeStatus object last updated. It is represented in
- RFC3339 form and is in UTC.
- format: date-time
- nullable: true
- type: string
- routes:
- description:
- Routes reports routes known to the Calico BGP daemon
- on the node.
- properties:
- routesV4:
- description: RoutesV4 represents IPv4 routes on the node.
- items:
- description:
- CalicoNodeRoute contains the status of BGP routes
- on the node.
- properties:
- destination:
- description: Destination of the route.
- type: string
- gateway:
- description: Gateway for the destination.
- type: string
- interface:
- description: Interface for the destination
- type: string
- learnedFrom:
- description:
- LearnedFrom contains information regarding
- where this route originated.
- properties:
- peerIP:
- description:
- If sourceType is NodeMesh or BGPPeer, IP
- address of the router that sent us this route.
- type: string
- sourceType:
- description:
- Type of the source where a route is learned
- from.
- type: string
- type: object
- type:
- description:
- Type indicates if the route is being used for
- forwarding or not.
- type: string
- type: object
- type: array
- routesV6:
- description: RoutesV6 represents IPv6 routes on the node.
- items:
- description:
- CalicoNodeRoute contains the status of BGP routes
- on the node.
- properties:
- destination:
- description: Destination of the route.
- type: string
- gateway:
- description: Gateway for the destination.
- type: string
- interface:
- description: Interface for the destination
- type: string
- learnedFrom:
- description:
- LearnedFrom contains information regarding
- where this route originated.
- properties:
- peerIP:
- description:
- If sourceType is NodeMesh or BGPPeer, IP
- address of the router that sent us this route.
- type: string
- sourceType:
- description:
- Type of the source where a route is learned
- from.
- type: string
- type: object
- type:
- description:
- Type indicates if the route is being used for
- forwarding or not.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_clusterinformations.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: clusterinformations.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: ClusterInformation
- listKind: ClusterInformationList
- plural: clusterinformations
- singular: clusterinformation
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- description: ClusterInformation contains the cluster specific information.
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- ClusterInformationSpec contains the values of describing
- the cluster.
- properties:
- calicoVersion:
- description:
- CalicoVersion is the version of Calico that the cluster
- is running
- type: string
- clusterGUID:
- description: ClusterGUID is the GUID of the cluster
- type: string
- clusterType:
- description: ClusterType describes the type of the cluster
- type: string
- datastoreReady:
- description:
- DatastoreReady is used during significant datastore migrations
- to signal to components such as Felix that it should wait before
- accessing the datastore.
- type: boolean
- variant:
- description: Variant declares which variant of Calico should be active.
- type: string
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_felixconfigurations.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: felixconfigurations.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: FelixConfiguration
- listKind: FelixConfigurationList
- plural: felixconfigurations
- singular: felixconfiguration
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- description: Felix Configuration contains the configuration for Felix.
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description: FelixConfigurationSpec contains the values of the Felix configuration.
- properties:
- allowIPIPPacketsFromWorkloads:
- description:
- "AllowIPIPPacketsFromWorkloads controls whether Felix
- will add a rule to drop IPIP encapsulated traffic from workloads
- [Default: false]"
- type: boolean
- allowVXLANPacketsFromWorkloads:
- description:
- "AllowVXLANPacketsFromWorkloads controls whether Felix
- will add a rule to drop VXLAN encapsulated traffic from workloads
- [Default: false]"
- type: boolean
- awsSrcDstCheck:
- description:
- 'Set source-destination-check on AWS EC2 instances. Accepted
- value must be one of "DoNothing", "Enable" or "Disable". [Default:
- DoNothing]'
- enum:
- - DoNothing
- - Enable
- - Disable
- type: string
- bpfConnectTimeLoadBalancingEnabled:
- description:
- "BPFConnectTimeLoadBalancingEnabled when in BPF mode,
- controls whether Felix installs the connection-time load balancer. The
- connect-time load balancer is required for the host to be able to
- reach Kubernetes services and it improves the performance of pod-to-service
- connections. The only reason to disable it is for debugging purposes. [Default:
- true]"
- type: boolean
- bpfDSROptoutCIDRs:
- description:
- BPFDSROptoutCIDRs is a list of CIDRs which are excluded
- from DSR. That is, clients in those CIDRs will accesses nodeports
- as if BPFExternalServiceMode was set to Tunnel.
- items:
- type: string
- type: array
- bpfDataIfacePattern:
- description:
- BPFDataIfacePattern is a regular expression that controls
- which interfaces Felix should attach BPF programs to in order to
- catch traffic to/from the network. This needs to match the interfaces
- that Calico workload traffic flows over as well as any interfaces
- that handle incoming traffic to nodeports and services from outside
- the cluster. It should not match the workload interfaces (usually
- named cali...).
- type: string
- bpfDisableUnprivileged:
- description:
- "BPFDisableUnprivileged, if enabled, Felix sets the kernel.unprivileged_bpf_disabled
- sysctl to disable unprivileged use of BPF. This ensures that unprivileged
- users cannot access Calico's BPF maps and cannot insert their own
- BPF programs to interfere with Calico's. [Default: true]"
- type: boolean
- bpfEnabled:
- description:
- "BPFEnabled, if enabled Felix will use the BPF dataplane.
- [Default: false]"
- type: boolean
- bpfEnforceRPF:
- description:
- "BPFEnforceRPF enforce strict RPF on all host interfaces
- with BPF programs regardless of what is the per-interfaces or global
- setting. Possible values are Disabled, Strict or Loose. [Default:
- Loose]"
- type: string
- bpfExtToServiceConnmark:
- description:
- "BPFExtToServiceConnmark in BPF mode, control a 32bit
- mark that is set on connections from an external client to a local
- service. This mark allows us to control how packets of that connection
- are routed within the host and how is routing interpreted by RPF
- check. [Default: 0]"
- type: integer
- bpfExternalServiceMode:
- description:
- 'BPFExternalServiceMode in BPF mode, controls how connections
- from outside the cluster to services (node ports and cluster IPs)
- are forwarded to remote workloads. If set to "Tunnel" then both
- request and response traffic is tunneled to the remote node. If
- set to "DSR", the request traffic is tunneled but the response traffic
- is sent directly from the remote node. In "DSR" mode, the remote
- node appears to use the IP of the ingress node; this requires a
- permissive L2 network. [Default: Tunnel]'
- type: string
- bpfHostConntrackBypass:
- description:
- "BPFHostConntrackBypass Controls whether to bypass Linux
- conntrack in BPF mode for workloads and services. [Default: true
- - bypass Linux conntrack]"
- type: boolean
- bpfKubeProxyEndpointSlicesEnabled:
- description:
- BPFKubeProxyEndpointSlicesEnabled in BPF mode, controls
- whether Felix's embedded kube-proxy accepts EndpointSlices or not.
- type: boolean
- bpfKubeProxyIptablesCleanupEnabled:
- description:
- "BPFKubeProxyIptablesCleanupEnabled, if enabled in BPF
- mode, Felix will proactively clean up the upstream Kubernetes kube-proxy's
- iptables chains. Should only be enabled if kube-proxy is not running. [Default:
- true]"
- type: boolean
- bpfKubeProxyMinSyncPeriod:
- description:
- "BPFKubeProxyMinSyncPeriod, in BPF mode, controls the
- minimum time between updates to the dataplane for Felix's embedded
- kube-proxy. Lower values give reduced set-up latency. Higher values
- reduce Felix CPU usage by batching up more work. [Default: 1s]"
- type: string
- bpfL3IfacePattern:
- description:
- BPFL3IfacePattern is a regular expression that allows
- to list tunnel devices like wireguard or vxlan (i.e., L3 devices)
- in addition to BPFDataIfacePattern. That is, tunnel interfaces not
- created by Calico, that Calico workload traffic flows over as well
- as any interfaces that handle incoming traffic to nodeports and
- services from outside the cluster.
- type: string
- bpfLogLevel:
- description:
- 'BPFLogLevel controls the log level of the BPF programs
- when in BPF dataplane mode. One of "Off", "Info", or "Debug". The
- logs are emitted to the BPF trace pipe, accessible with the command
- `tc exec bpf debug`. [Default: Off].'
- type: string
- bpfMapSizeConntrack:
- description:
- "BPFMapSizeConntrack sets the size for the conntrack
- map. This map must be large enough to hold an entry for each active
- connection. Warning: changing the size of the conntrack map can
- cause disruption."
- type: integer
- bpfMapSizeIPSets:
- description:
- BPFMapSizeIPSets sets the size for ipsets map. The IP
- sets map must be large enough to hold an entry for each endpoint
- matched by every selector in the source/destination matches in network
- policy. Selectors such as "all()" can result in large numbers of
- entries (one entry per endpoint in that case).
- type: integer
- bpfMapSizeIfState:
- description:
- BPFMapSizeIfState sets the size for ifstate map. The
- ifstate map must be large enough to hold an entry for each device
- (host + workloads) on a host.
- type: integer
- bpfMapSizeNATAffinity:
- type: integer
- bpfMapSizeNATBackend:
- description:
- BPFMapSizeNATBackend sets the size for nat back end map.
- This is the total number of endpoints. This is mostly more than
- the size of the number of services.
- type: integer
- bpfMapSizeNATFrontend:
- description:
- BPFMapSizeNATFrontend sets the size for nat front end
- map. FrontendMap should be large enough to hold an entry for each
- nodeport, external IP and each port in each service.
- type: integer
- bpfMapSizeRoute:
- description:
- BPFMapSizeRoute sets the size for the routes map. The
- routes map should be large enough to hold one entry per workload
- and a handful of entries per host (enough to cover its own IPs and
- tunnel IPs).
- type: integer
- bpfPSNATPorts:
- anyOf:
- - type: integer
- - type: string
- description:
- "BPFPSNATPorts sets the range from which we randomly
- pick a port if there is a source port collision. This should be
- within the ephemeral range as defined by RFC 6056 (1024–65535) and
- preferably outside the ephemeral ranges used by common operating
- systems. Linux uses 32768–60999, while others mostly use the IANA
- defined range 49152–65535. It is not necessarily a problem if this
- range overlaps with the operating systems. Both ends of the range
- are inclusive. [Default: 20000:29999]"
- pattern: ^.*
- x-kubernetes-int-or-string: true
- bpfPolicyDebugEnabled:
- description:
- BPFPolicyDebugEnabled when true, Felix records detailed
- information about the BPF policy programs, which can be examined
- with the calico-bpf command-line tool.
- type: boolean
- chainInsertMode:
- description:
- "ChainInsertMode controls whether Felix hooks the kernel's
- top-level iptables chains by inserting a rule at the top of the
- chain or by appending a rule at the bottom. insert is the safe default
- since it prevents Calico's rules from being bypassed. If you switch
- to append mode, be sure that the other rules in the chains signal
- acceptance by falling through to the Calico rules, otherwise the
- Calico policy will be bypassed. [Default: insert]"
- type: string
- dataplaneDriver:
- description:
- DataplaneDriver filename of the external dataplane driver
- to use. Only used if UseInternalDataplaneDriver is set to false.
- type: string
- dataplaneWatchdogTimeout:
- description:
- "DataplaneWatchdogTimeout is the readiness/liveness timeout
- used for Felix's (internal) dataplane driver. Increase this value
- if you experience spurious non-ready or non-live events when Felix
- is under heavy load. Decrease the value to get felix to report non-live
- or non-ready more quickly. [Default: 90s] \n Deprecated: replaced
- by the generic HealthTimeoutOverrides."
- type: string
- debugDisableLogDropping:
- type: boolean
- debugMemoryProfilePath:
- type: string
- debugSimulateCalcGraphHangAfter:
- type: string
- debugSimulateDataplaneHangAfter:
- type: string
- defaultEndpointToHostAction:
- description:
- 'DefaultEndpointToHostAction controls what happens to
- traffic that goes from a workload endpoint to the host itself (after
- the traffic hits the endpoint egress policy). By default Calico
- blocks traffic from workload endpoints to the host itself with an
- iptables "DROP" action. If you want to allow some or all traffic
- from endpoint to host, set this parameter to RETURN or ACCEPT. Use
- RETURN if you have your own rules in the iptables "INPUT" chain;
- Calico will insert its rules at the top of that chain, then "RETURN"
- packets to the "INPUT" chain once it has completed processing workload
- endpoint egress policy. Use ACCEPT to unconditionally accept packets
- from workloads after processing workload endpoint egress policy.
- [Default: Drop]'
- type: string
- deviceRouteProtocol:
- description:
- This defines the route protocol added to programmed device
- routes, by default this will be RTPROT_BOOT when left blank.
- type: integer
- deviceRouteSourceAddress:
- description:
- This is the IPv4 source address to use on programmed
- device routes. By default the source address is left blank, leaving
- the kernel to choose the source address used.
- type: string
- deviceRouteSourceAddressIPv6:
- description:
- This is the IPv6 source address to use on programmed
- device routes. By default the source address is left blank, leaving
- the kernel to choose the source address used.
- type: string
- disableConntrackInvalidCheck:
- type: boolean
- endpointReportingDelay:
- type: string
- endpointReportingEnabled:
- type: boolean
- externalNodesList:
- description:
- ExternalNodesCIDRList is a list of CIDR's of external-non-calico-nodes
- which may source tunnel traffic and have the tunneled traffic be
- accepted at calico nodes.
- items:
- type: string
- type: array
- failsafeInboundHostPorts:
- description:
- 'FailsafeInboundHostPorts is a list of UDP/TCP ports
- and CIDRs that Felix will allow incoming traffic to host endpoints
- on irrespective of the security policy. This is useful to avoid
- accidentally cutting off a host with incorrect configuration. For
- back-compatibility, if the protocol is not specified, it defaults
- to "tcp". If a CIDR is not specified, it will allow traffic from
- all addresses. To disable all inbound host ports, use the value
- none. The default value allows ssh access and DHCP. [Default: tcp:22,
- udp:68, tcp:179, tcp:2379, tcp:2380, tcp:6443, tcp:6666, tcp:6667]'
- items:
- description:
- ProtoPort is combination of protocol, port, and CIDR.
- Protocol and port must be specified.
- properties:
- net:
- type: string
- port:
- type: integer
- protocol:
- type: string
- required:
- - port
- - protocol
- type: object
- type: array
- failsafeOutboundHostPorts:
- description:
- 'FailsafeOutboundHostPorts is a list of UDP/TCP ports
- and CIDRs that Felix will allow outgoing traffic from host endpoints
- to irrespective of the security policy. This is useful to avoid
- accidentally cutting off a host with incorrect configuration. For
- back-compatibility, if the protocol is not specified, it defaults
- to "tcp". If a CIDR is not specified, it will allow traffic from
- all addresses. To disable all outbound host ports, use the value
- none. The default value opens etcd''s standard ports to ensure that
- Felix does not get cut off from etcd as well as allowing DHCP and
- DNS. [Default: tcp:179, tcp:2379, tcp:2380, tcp:6443, tcp:6666,
- tcp:6667, udp:53, udp:67]'
- items:
- description:
- ProtoPort is combination of protocol, port, and CIDR.
- Protocol and port must be specified.
- properties:
- net:
- type: string
- port:
- type: integer
- protocol:
- type: string
- required:
- - port
- - protocol
- type: object
- type: array
- featureDetectOverride:
- description:
- FeatureDetectOverride is used to override feature detection
- based on auto-detected platform capabilities. Values are specified
- in a comma separated list with no spaces, example; "SNATFullyRandom=true,MASQFullyRandom=false,RestoreSupportsLock=". "true"
- or "false" will force the feature, empty or omitted values are auto-detected.
- type: string
- featureGates:
- description:
- FeatureGates is used to enable or disable tech-preview
- Calico features. Values are specified in a comma separated list
- with no spaces, example; "BPFConnectTimeLoadBalancingWorkaround=enabled,XyZ=false".
- This is used to enable features that are not fully production ready.
- type: string
- floatingIPs:
- description:
- FloatingIPs configures whether or not Felix will program
- non-OpenStack floating IP addresses. (OpenStack-derived floating
- IPs are always programmed, regardless of this setting.)
- enum:
- - Enabled
- - Disabled
- type: string
- genericXDPEnabled:
- description:
- "GenericXDPEnabled enables Generic XDP so network cards
- that don't support XDP offload or driver modes can use XDP. This
- is not recommended since it doesn't provide better performance
- than iptables. [Default: false]"
- type: boolean
- healthEnabled:
- type: boolean
- healthHost:
- type: string
- healthPort:
- type: integer
- healthTimeoutOverrides:
- description:
- HealthTimeoutOverrides allows the internal watchdog timeouts
- of individual subcomponents to be overridden. This is useful for
- working around "false positive" liveness timeouts that can occur
- in particularly stressful workloads or if CPU is constrained. For
- a list of active subcomponents, see Felix's logs.
- items:
- properties:
- name:
- type: string
- timeout:
- type: string
- required:
- - name
- - timeout
- type: object
- type: array
- interfaceExclude:
- description:
- "InterfaceExclude is a comma-separated list of interfaces
- that Felix should exclude when monitoring for host endpoints. The
- default value ensures that Felix ignores Kubernetes' IPVS dummy
- interface, which is used internally by kube-proxy. If you want to
- exclude multiple interface names using a single value, the list
- supports regular expressions. For regular expressions you must wrap
- the value with '/'. For example having values '/^kube/,veth1'
- will exclude all interfaces that begin with 'kube' and also the
- interface 'veth1'. [Default: kube-ipvs0]"
- type: string
- interfacePrefix:
- description:
- "InterfacePrefix is the interface name prefix that identifies
- workload endpoints and so distinguishes them from host endpoint
- interfaces. Note: in environments other than bare metal, the orchestrators
- configure this appropriately. For example our Kubernetes and Docker
- integrations set the 'cali' value, and our OpenStack integration
- sets the 'tap' value. [Default: cali]"
- type: string
- interfaceRefreshInterval:
- description:
- InterfaceRefreshInterval is the period at which Felix
- rescans local interfaces to verify their state. The rescan can be
- disabled by setting the interval to 0.
- type: string
- ipipEnabled:
- description:
- "IPIPEnabled overrides whether Felix should configure
- an IPIP interface on the host. Optional as Felix determines this
- based on the existing IP pools. [Default: nil (unset)]"
- type: boolean
- ipipMTU:
- description:
- "IPIPMTU is the MTU to set on the tunnel device. See
- Configuring MTU [Default: 1440]"
- type: integer
- ipsetsRefreshInterval:
- description:
- "IpsetsRefreshInterval is the period at which Felix re-checks
- all iptables state to ensure that no other process has accidentally
- broken Calico's rules. Set to 0 to disable iptables refresh. [Default:
- 90s]"
- type: string
- iptablesBackend:
- description:
- IptablesBackend specifies which backend of iptables will
- be used. The default is Auto.
- type: string
- iptablesFilterAllowAction:
- type: string
- iptablesFilterDenyAction:
- description:
- IptablesFilterDenyAction controls what happens to traffic
- that is denied by network policy. By default Calico blocks traffic
- with an iptables "DROP" action. If you want to use "REJECT" action
- instead you can configure it in here.
- type: string
- iptablesLockFilePath:
- description:
- "IptablesLockFilePath is the location of the iptables
- lock file. You may need to change this if the lock file is not in
- its standard location (for example if you have mapped it into Felix's
- container at a different path). [Default: /run/xtables.lock]"
- type: string
- iptablesLockProbeInterval:
- description:
- "IptablesLockProbeInterval is the time that Felix will
- wait between attempts to acquire the iptables lock if it is not
- available. Lower values make Felix more responsive when the lock
- is contended, but use more CPU. [Default: 50ms]"
- type: string
- iptablesLockTimeout:
- description:
- "IptablesLockTimeout is the time that Felix will wait
- for the iptables lock, or 0, to disable. To use this feature, Felix
- must share the iptables lock file with all other processes that
- also take the lock. When running Felix inside a container, this
- requires the /run directory of the host to be mounted into the calico/node
- or calico/felix container. [Default: 0s disabled]"
- type: string
- iptablesMangleAllowAction:
- type: string
- iptablesMarkMask:
- description:
- "IptablesMarkMask is the mask that Felix selects its
- IPTables Mark bits from. Should be a 32 bit hexadecimal number with
- at least 8 bits set, none of which clash with any other mark bits
- in use on the system. [Default: 0xff000000]"
- format: int32
- type: integer
- iptablesNATOutgoingInterfaceFilter:
- type: string
- iptablesPostWriteCheckInterval:
- description:
- "IptablesPostWriteCheckInterval is the period after Felix
- has done a write to the dataplane that it schedules an extra read
- back in order to check the write was not clobbered by another process.
- This should only occur if another application on the system doesn't
- respect the iptables lock. [Default: 1s]"
- type: string
- iptablesRefreshInterval:
- description:
- "IptablesRefreshInterval is the period at which Felix
- re-checks the IP sets in the dataplane to ensure that no other process
- has accidentally broken Calico's rules. Set to 0 to disable IP
- sets refresh. Note: the default for this value is lower than the
- other refresh intervals as a workaround for a Linux kernel bug that
- was fixed in kernel version 4.11. If you are using v4.11 or greater
- you may want to set this to, a higher value to reduce Felix CPU
- usage. [Default: 10s]"
- type: string
- ipv6Support:
- description:
- IPv6Support controls whether Felix enables support for
- IPv6 (if supported by the in-use dataplane).
- type: boolean
- kubeNodePortRanges:
- description:
- "KubeNodePortRanges holds list of port ranges used for
- service node ports. Only used if felix detects kube-proxy running
- in ipvs mode. Felix uses these ranges to separate host and workload
- traffic. [Default: 30000:32767]."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- logDebugFilenameRegex:
- description:
- LogDebugFilenameRegex controls which source code files
- have their Debug log output included in the logs. Only logs from
- files with names that match the given regular expression are included. The
- filter only applies to Debug level logs.
- type: string
- logFilePath:
- description:
- "LogFilePath is the full path to the Felix log. Set to
- none to disable file logging. [Default: /var/log/calico/felix.log]"
- type: string
- logPrefix:
- description:
- "LogPrefix is the log prefix that Felix uses when rendering
- LOG rules. [Default: calico-packet]"
- type: string
- logSeverityFile:
- description:
- "LogSeverityFile is the log severity above which logs
- are sent to the log file. [Default: Info]"
- type: string
- logSeverityScreen:
- description:
- "LogSeverityScreen is the log severity above which logs
- are sent to the stdout. [Default: Info]"
- type: string
- logSeveritySys:
- description:
- "LogSeveritySys is the log severity above which logs
- are sent to the syslog. Set to None for no logging to syslog. [Default:
- Info]"
- type: string
- maxIpsetSize:
- type: integer
- metadataAddr:
- description:
- "MetadataAddr is the IP address or domain name of the
- server that can answer VM queries for cloud-init metadata. In OpenStack,
- this corresponds to the machine running nova-api (or in Ubuntu,
- nova-api-metadata). A value of none (case insensitive) means that
- Felix should not set up any NAT rule for the metadata path. [Default:
- 127.0.0.1]"
- type: string
- metadataPort:
- description:
- "MetadataPort is the port of the metadata server. This,
- combined with global.MetadataAddr (if not 'None'), is used to
- set up a NAT rule, from 169.254.169.254:80 to MetadataAddr:MetadataPort.
- In most cases this should not need to be changed [Default: 8775]."
- type: integer
- mtuIfacePattern:
- description:
- MTUIfacePattern is a regular expression that controls
- which interfaces Felix should scan in order to calculate the host's
- MTU. This should not match workload interfaces (usually named cali...).
- type: string
- natOutgoingAddress:
- description:
- NATOutgoingAddress specifies an address to use when performing
- source NAT for traffic in a natOutgoing pool that is leaving the
- network. By default the address used is an address on the interface
- the traffic is leaving on (ie it uses the iptables MASQUERADE target)
- type: string
- natPortRange:
- anyOf:
- - type: integer
- - type: string
- description:
- NATPortRange specifies the range of ports that is used
- for port mapping when doing outgoing NAT. When unset the default
- behavior of the network stack is used.
- pattern: ^.*
- x-kubernetes-int-or-string: true
- netlinkTimeout:
- type: string
- openstackRegion:
- description:
- "OpenstackRegion is the name of the region that a particular
- Felix belongs to. In a multi-region Calico/OpenStack deployment,
- this must be configured somehow for each Felix (here in the datamodel,
- or in felix.cfg or the environment on each compute node), and must
- match the [calico] openstack_region value configured in neutron.conf
- on each node. [Default: Empty]"
- type: string
- policySyncPathPrefix:
- description:
- "PolicySyncPathPrefix is used to by Felix to communicate
- policy changes to external services, like Application layer policy.
- [Default: Empty]"
- type: string
- prometheusGoMetricsEnabled:
- description:
- "PrometheusGoMetricsEnabled disables Go runtime metrics
- collection, which the Prometheus client does by default, when set
- to false. This reduces the number of metrics reported, reducing
- Prometheus load. [Default: true]"
- type: boolean
- prometheusMetricsEnabled:
- description:
- "PrometheusMetricsEnabled enables the Prometheus metrics
- server in Felix if set to true. [Default: false]"
- type: boolean
- prometheusMetricsHost:
- description:
- "PrometheusMetricsHost is the host that the Prometheus
- metrics server should bind to. [Default: empty]"
- type: string
- prometheusMetricsPort:
- description:
- "PrometheusMetricsPort is the TCP port that the Prometheus
- metrics server should bind to. [Default: 9091]"
- type: integer
- prometheusProcessMetricsEnabled:
- description:
- "PrometheusProcessMetricsEnabled disables process metrics
- collection, which the Prometheus client does by default, when set
- to false. This reduces the number of metrics reported, reducing
- Prometheus load. [Default: true]"
- type: boolean
- prometheusWireGuardMetricsEnabled:
- description:
- "PrometheusWireGuardMetricsEnabled disables wireguard
- metrics collection, which the Prometheus client does by default,
- when set to false. This reduces the number of metrics reported,
- reducing Prometheus load. [Default: true]"
- type: boolean
- removeExternalRoutes:
- description:
- Whether or not to remove device routes that have not
- been programmed by Felix. Disabling this will allow external applications
- to also add device routes. This is enabled by default which means
- we will remove externally added routes.
- type: boolean
- reportingInterval:
- description:
- "ReportingInterval is the interval at which Felix reports
- its status into the datastore or 0 to disable. Must be non-zero
- in OpenStack deployments. [Default: 30s]"
- type: string
- reportingTTL:
- description:
- "ReportingTTL is the time-to-live setting for process-wide
- status reports. [Default: 90s]"
- type: string
- routeRefreshInterval:
- description:
- "RouteRefreshInterval is the period at which Felix re-checks
- the routes in the dataplane to ensure that no other process has
- accidentally broken Calico's rules. Set to 0 to disable route refresh.
- [Default: 90s]"
- type: string
- routeSource:
- description:
- "RouteSource configures where Felix gets its routing
- information. - WorkloadIPs: use workload endpoints to construct
- routes. - CalicoIPAM: the default - use IPAM data to construct routes."
- type: string
- routeSyncDisabled:
- description:
- RouteSyncDisabled will disable all operations performed
- on the route table. Set to true to run in network-policy mode only.
- type: boolean
- routeTableRange:
- description:
- Deprecated in favor of RouteTableRanges. Calico programs
- additional Linux route tables for various purposes. RouteTableRange
- specifies the indices of the route tables that Calico should use.
- properties:
- max:
- type: integer
- min:
- type: integer
- required:
- - max
- - min
- type: object
- routeTableRanges:
- description:
- Calico programs additional Linux route tables for various
- purposes. RouteTableRanges specifies a set of table index ranges
- that Calico should use. Deprecates`RouteTableRange`, overrides `RouteTableRange`.
- items:
- properties:
- max:
- type: integer
- min:
- type: integer
- required:
- - max
- - min
- type: object
- type: array
- serviceLoopPrevention:
- description:
- 'When service IP advertisement is enabled, prevent routing
- loops to service IPs that are not in use, by dropping or rejecting
- packets that do not get DNAT''d by kube-proxy. Unless set to "Disabled",
- in which case such routing loops continue to be allowed. [Default:
- Drop]'
- type: string
- sidecarAccelerationEnabled:
- description:
- "SidecarAccelerationEnabled enables experimental sidecar
- acceleration [Default: false]"
- type: boolean
- usageReportingEnabled:
- description:
- "UsageReportingEnabled reports anonymous Calico version
- number and cluster size to projectcalico.org. Logs warnings returned
- by the usage server. For example, if a significant security vulnerability
- has been discovered in the version of Calico being used. [Default:
- true]"
- type: boolean
- usageReportingInitialDelay:
- description:
- "UsageReportingInitialDelay controls the minimum delay
- before Felix makes a report. [Default: 300s]"
- type: string
- usageReportingInterval:
- description:
- "UsageReportingInterval controls the interval at which
- Felix makes reports. [Default: 86400s]"
- type: string
- useInternalDataplaneDriver:
- description:
- UseInternalDataplaneDriver, if true, Felix will use its
- internal dataplane programming logic. If false, it will launch
- an external dataplane driver and communicate with it over protobuf.
- type: boolean
- vxlanEnabled:
- description:
- "VXLANEnabled overrides whether Felix should create the
- VXLAN tunnel device for IPv4 VXLAN networking. Optional as Felix
- determines this based on the existing IP pools. [Default: nil (unset)]"
- type: boolean
- vxlanMTU:
- description:
- "VXLANMTU is the MTU to set on the IPv4 VXLAN tunnel
- device. See Configuring MTU [Default: 1410]"
- type: integer
- vxlanMTUV6:
- description:
- "VXLANMTUV6 is the MTU to set on the IPv6 VXLAN tunnel
- device. See Configuring MTU [Default: 1390]"
- type: integer
- vxlanPort:
- type: integer
- vxlanVNI:
- type: integer
- wireguardEnabled:
- description:
- "WireguardEnabled controls whether Wireguard is enabled
- for IPv4 (encapsulating IPv4 traffic over an IPv4 underlay network).
- [Default: false]"
- type: boolean
- wireguardEnabledV6:
- description:
- "WireguardEnabledV6 controls whether Wireguard is enabled
- for IPv6 (encapsulating IPv6 traffic over an IPv6 underlay network).
- [Default: false]"
- type: boolean
- wireguardHostEncryptionEnabled:
- description:
- "WireguardHostEncryptionEnabled controls whether Wireguard
- host-to-host encryption is enabled. [Default: false]"
- type: boolean
- wireguardInterfaceName:
- description:
- "WireguardInterfaceName specifies the name to use for
- the IPv4 Wireguard interface. [Default: wireguard.cali]"
- type: string
- wireguardInterfaceNameV6:
- description:
- "WireguardInterfaceNameV6 specifies the name to use for
- the IPv6 Wireguard interface. [Default: wg-v6.cali]"
- type: string
- wireguardKeepAlive:
- description:
- "WireguardKeepAlive controls Wireguard PersistentKeepalive
- option. Set 0 to disable. [Default: 0]"
- type: string
- wireguardListeningPort:
- description:
- "WireguardListeningPort controls the listening port used
- by IPv4 Wireguard. [Default: 51820]"
- type: integer
- wireguardListeningPortV6:
- description:
- "WireguardListeningPortV6 controls the listening port
- used by IPv6 Wireguard. [Default: 51821]"
- type: integer
- wireguardMTU:
- description:
- "WireguardMTU controls the MTU on the IPv4 Wireguard
- interface. See Configuring MTU [Default: 1440]"
- type: integer
- wireguardMTUV6:
- description:
- "WireguardMTUV6 controls the MTU on the IPv6 Wireguard
- interface. See Configuring MTU [Default: 1420]"
- type: integer
- wireguardRoutingRulePriority:
- description:
- "WireguardRoutingRulePriority controls the priority value
- to use for the Wireguard routing rule. [Default: 99]"
- type: integer
- workloadSourceSpoofing:
- description:
- WorkloadSourceSpoofing controls whether pods can use
- the allowedSourcePrefixes annotation to send traffic with a source
- IP address that is not theirs. This is disabled by default. When
- set to "Any", pods can request any prefix.
- type: string
- xdpEnabled:
- description:
- "XDPEnabled enables XDP acceleration for suitable untracked
- incoming deny rules. [Default: true]"
- type: boolean
- xdpRefreshInterval:
- description:
- "XDPRefreshInterval is the period at which Felix re-checks
- all XDP state to ensure that no other process has accidentally broken
- Calico's BPF maps or attached programs. Set to 0 to disable XDP
- refresh. [Default: 90s]"
- type: string
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_globalnetworkpolicies.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: globalnetworkpolicies.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: GlobalNetworkPolicy
- listKind: GlobalNetworkPolicyList
- plural: globalnetworkpolicies
- singular: globalnetworkpolicy
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- properties:
- applyOnForward:
- description:
- ApplyOnForward indicates to apply the rules in this policy
- on forward traffic.
- type: boolean
- doNotTrack:
- description:
- DoNotTrack indicates whether packets matched by the rules
- in this policy should go through the data plane's connection tracking,
- such as Linux conntrack. If True, the rules in this policy are
- applied before any data plane connection tracking, and packets allowed
- by this policy are marked as not to be tracked.
- type: boolean
- egress:
- description:
- The ordered set of egress rules. Each rule contains
- a set of packet match criteria and a corresponding action to apply.
- items:
- description:
- "A Rule encapsulates a set of match criteria and an
- action. Both selector-based security Policy and security Profiles
- reference rules - separated out as a list of rules for both ingress
- and egress packet matching. \n Each positive match criteria has
- a negated version, prefixed with \"Not\". All the match criteria
- within a rule must be satisfied for a packet to match. A single
- rule can contain the positive and negative version of a match
- and both must be satisfied for the rule to match."
- properties:
- action:
- type: string
- destination:
- description:
- Destination contains the match criteria that apply
- to destination entity.
- properties:
- namespaceSelector:
- description:
- "NamespaceSelector is an optional field that
- contains a selector expression. Only traffic that originates
- from (or terminates at) endpoints within the selected
- namespaces will be matched. When both NamespaceSelector
- and another selector are defined on the same rule, then
- only workload endpoints that are matched by both selectors
- will be selected by the rule. \n For NetworkPolicy, an
- empty NamespaceSelector implies that the Selector is limited
- to selecting only workload endpoints in the same namespace
- as the NetworkPolicy. \n For NetworkPolicy, `global()`
- NamespaceSelector implies that the Selector is limited
- to selecting only GlobalNetworkSet or HostEndpoint. \n
- For GlobalNetworkPolicy, an empty NamespaceSelector implies
- the Selector applies to workload endpoints across all
- namespaces."
- type: string
- nets:
- description:
- Nets is an optional field that restricts the
- rule to only apply to traffic that originates from (or
- terminates at) IP addresses in any of the given subnets.
- items:
- type: string
- type: array
- notNets:
- description:
- NotNets is the negated version of the Nets
- field.
- items:
- type: string
- type: array
- notPorts:
- description:
- NotPorts is the negated version of the Ports
- field. Since only some protocols have ports, if any ports
- are specified it requires the Protocol match in the Rule
- to be set to "TCP" or "UDP".
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- notSelector:
- description:
- NotSelector is the negated version of the Selector
- field. See Selector field for subtleties with negated
- selectors.
- type: string
- ports:
- description:
- "Ports is an optional field that restricts
- the rule to only apply to traffic that has a source (destination)
- port that matches one of these ranges/values. This value
- is a list of integers or strings that represent ranges
- of ports. \n Since only some protocols have ports, if
- any ports are specified it requires the Protocol match
- in the Rule to be set to \"TCP\" or \"UDP\"."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- selector:
- description:
- "Selector is an optional field that contains
- a selector expression (see Policy for sample syntax).
- \ Only traffic that originates from (terminates at) endpoints
- matching the selector will be matched. \n Note that: in
- addition to the negated version of the Selector (see NotSelector
- below), the selector expression syntax itself supports
- negation. The two types of negation are subtly different.
- One negates the set of matched endpoints, the other negates
- the whole match: \n \tSelector = \"!has(my_label)\" matches
- packets that are from other Calico-controlled \tendpoints
- that do not have the label \"my_label\". \n \tNotSelector
- = \"has(my_label)\" matches packets that are not from
- Calico-controlled \tendpoints that do have the label \"my_label\".
- \n The effect is that the latter will accept packets from
- non-Calico sources whereas the former is limited to packets
- from Calico-controlled endpoints."
- type: string
- serviceAccounts:
- description:
- ServiceAccounts is an optional field that restricts
- the rule to only apply to traffic that originates from
- (or terminates at) a pod running as a matching service
- account.
- properties:
- names:
- description:
- Names is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account whose name is in the list.
- items:
- type: string
- type: array
- selector:
- description:
- Selector is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account that matches the given label selector. If
- both Names and Selector are specified then they are
- AND'ed.
- type: string
- type: object
- services:
- description:
- "Services is an optional field that contains
- options for matching Kubernetes Services. If specified,
- only traffic that originates from or terminates at endpoints
- within the selected service(s) will be matched, and only
- to/from each endpoint's port. \n Services cannot be specified
- on the same rule as Selector, NotSelector, NamespaceSelector,
- Nets, NotNets or ServiceAccounts. \n Ports and NotPorts
- can only be specified with Services on ingress rules."
- properties:
- name:
- description:
- Name specifies the name of a Kubernetes
- Service to match.
- type: string
- namespace:
- description:
- Namespace specifies the namespace of the
- given Service. If left empty, the rule will match
- within this policy's namespace.
- type: string
- type: object
- type: object
- http:
- description:
- HTTP contains match criteria that apply to HTTP
- requests.
- properties:
- methods:
- description:
- Methods is an optional field that restricts
- the rule to apply only to HTTP requests that use one of
- the listed HTTP Methods (e.g. GET, PUT, etc.) Multiple
- methods are OR'd together.
- items:
- type: string
- type: array
- paths:
- description:
- "Paths is an optional field that restricts
- the rule to apply to HTTP requests that use one of the
- listed HTTP Paths. Multiple paths are OR'd together.
- e.g: - exact: /foo - prefix: /bar NOTE: Each entry may
- ONLY specify either a `exact` or a `prefix` match. The
- validator will check for it."
- items:
- description:
- "HTTPPath specifies an HTTP path to match.
- It may be either of the form: exact: <path>: which matches
- the path exactly or prefix: <path-prefix>: which matches
- the path prefix"
- properties:
- exact:
- type: string
- prefix:
- type: string
- type: object
- type: array
- type: object
- icmp:
- description:
- ICMP is an optional field that restricts the rule
- to apply to a specific type and code of ICMP traffic. This
- should only be specified if the Protocol field is set to "ICMP"
- or "ICMPv6".
- properties:
- code:
- description:
- Match on a specific ICMP code. If specified,
- the Type value must also be specified. This is a technical
- limitation imposed by the kernel's iptables firewall,
- which Calico uses to enforce the rule.
- type: integer
- type:
- description:
- Match on a specific ICMP type. For example
- a value of 8 refers to ICMP Echo Request (i.e. pings).
- type: integer
- type: object
- ipVersion:
- description:
- IPVersion is an optional field that restricts the
- rule to only match a specific IP version.
- type: integer
- metadata:
- description:
- Metadata contains additional information for this
- rule
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a set of key value pairs that
- give extra information about the rule
- type: object
- type: object
- notICMP:
- description: NotICMP is the negated version of the ICMP field.
- properties:
- code:
- description:
- Match on a specific ICMP code. If specified,
- the Type value must also be specified. This is a technical
- limitation imposed by the kernel's iptables firewall,
- which Calico uses to enforce the rule.
- type: integer
- type:
- description:
- Match on a specific ICMP type. For example
- a value of 8 refers to ICMP Echo Request (i.e. pings).
- type: integer
- type: object
- notProtocol:
- anyOf:
- - type: integer
- - type: string
- description:
- NotProtocol is the negated version of the Protocol
- field.
- pattern: ^.*
- x-kubernetes-int-or-string: true
- protocol:
- anyOf:
- - type: integer
- - type: string
- description:
- "Protocol is an optional field that restricts the
- rule to only apply to traffic of a specific IP protocol. Required
- if any of the EntityRules contain Ports (because ports only
- apply to certain protocols). \n Must be one of these string
- values: \"TCP\", \"UDP\", \"ICMP\", \"ICMPv6\", \"SCTP\",
- \"UDPLite\" or an integer in the range 1-255."
- pattern: ^.*
- x-kubernetes-int-or-string: true
- source:
- description:
- Source contains the match criteria that apply to
- source entity.
- properties:
- namespaceSelector:
- description:
- "NamespaceSelector is an optional field that
- contains a selector expression. Only traffic that originates
- from (or terminates at) endpoints within the selected
- namespaces will be matched. When both NamespaceSelector
- and another selector are defined on the same rule, then
- only workload endpoints that are matched by both selectors
- will be selected by the rule. \n For NetworkPolicy, an
- empty NamespaceSelector implies that the Selector is limited
- to selecting only workload endpoints in the same namespace
- as the NetworkPolicy. \n For NetworkPolicy, `global()`
- NamespaceSelector implies that the Selector is limited
- to selecting only GlobalNetworkSet or HostEndpoint. \n
- For GlobalNetworkPolicy, an empty NamespaceSelector implies
- the Selector applies to workload endpoints across all
- namespaces."
- type: string
- nets:
- description:
- Nets is an optional field that restricts the
- rule to only apply to traffic that originates from (or
- terminates at) IP addresses in any of the given subnets.
- items:
- type: string
- type: array
- notNets:
- description:
- NotNets is the negated version of the Nets
- field.
- items:
- type: string
- type: array
- notPorts:
- description:
- NotPorts is the negated version of the Ports
- field. Since only some protocols have ports, if any ports
- are specified it requires the Protocol match in the Rule
- to be set to "TCP" or "UDP".
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- notSelector:
- description:
- NotSelector is the negated version of the Selector
- field. See Selector field for subtleties with negated
- selectors.
- type: string
- ports:
- description:
- "Ports is an optional field that restricts
- the rule to only apply to traffic that has a source (destination)
- port that matches one of these ranges/values. This value
- is a list of integers or strings that represent ranges
- of ports. \n Since only some protocols have ports, if
- any ports are specified it requires the Protocol match
- in the Rule to be set to \"TCP\" or \"UDP\"."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- selector:
- description:
- "Selector is an optional field that contains
- a selector expression (see Policy for sample syntax).
- \ Only traffic that originates from (terminates at) endpoints
- matching the selector will be matched. \n Note that: in
- addition to the negated version of the Selector (see NotSelector
- below), the selector expression syntax itself supports
- negation. The two types of negation are subtly different.
- One negates the set of matched endpoints, the other negates
- the whole match: \n \tSelector = \"!has(my_label)\" matches
- packets that are from other Calico-controlled \tendpoints
- that do not have the label \"my_label\". \n \tNotSelector
- = \"has(my_label)\" matches packets that are not from
- Calico-controlled \tendpoints that do have the label \"my_label\".
- \n The effect is that the latter will accept packets from
- non-Calico sources whereas the former is limited to packets
- from Calico-controlled endpoints."
- type: string
- serviceAccounts:
- description:
- ServiceAccounts is an optional field that restricts
- the rule to only apply to traffic that originates from
- (or terminates at) a pod running as a matching service
- account.
- properties:
- names:
- description:
- Names is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account whose name is in the list.
- items:
- type: string
- type: array
- selector:
- description:
- Selector is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account that matches the given label selector. If
- both Names and Selector are specified then they are
- AND'ed.
- type: string
- type: object
- services:
- description:
- "Services is an optional field that contains
- options for matching Kubernetes Services. If specified,
- only traffic that originates from or terminates at endpoints
- within the selected service(s) will be matched, and only
- to/from each endpoint's port. \n Services cannot be specified
- on the same rule as Selector, NotSelector, NamespaceSelector,
- Nets, NotNets or ServiceAccounts. \n Ports and NotPorts
- can only be specified with Services on ingress rules."
- properties:
- name:
- description:
- Name specifies the name of a Kubernetes
- Service to match.
- type: string
- namespace:
- description:
- Namespace specifies the namespace of the
- given Service. If left empty, the rule will match
- within this policy's namespace.
- type: string
- type: object
- type: object
- required:
- - action
- type: object
- type: array
- ingress:
- description:
- The ordered set of ingress rules. Each rule contains
- a set of packet match criteria and a corresponding action to apply.
- items:
- description:
- "A Rule encapsulates a set of match criteria and an
- action. Both selector-based security Policy and security Profiles
- reference rules - separated out as a list of rules for both ingress
- and egress packet matching. \n Each positive match criteria has
- a negated version, prefixed with \"Not\". All the match criteria
- within a rule must be satisfied for a packet to match. A single
- rule can contain the positive and negative version of a match
- and both must be satisfied for the rule to match."
- properties:
- action:
- type: string
- destination:
- description:
- Destination contains the match criteria that apply
- to destination entity.
- properties:
- namespaceSelector:
- description:
- "NamespaceSelector is an optional field that
- contains a selector expression. Only traffic that originates
- from (or terminates at) endpoints within the selected
- namespaces will be matched. When both NamespaceSelector
- and another selector are defined on the same rule, then
- only workload endpoints that are matched by both selectors
- will be selected by the rule. \n For NetworkPolicy, an
- empty NamespaceSelector implies that the Selector is limited
- to selecting only workload endpoints in the same namespace
- as the NetworkPolicy. \n For NetworkPolicy, `global()`
- NamespaceSelector implies that the Selector is limited
- to selecting only GlobalNetworkSet or HostEndpoint. \n
- For GlobalNetworkPolicy, an empty NamespaceSelector implies
- the Selector applies to workload endpoints across all
- namespaces."
- type: string
- nets:
- description:
- Nets is an optional field that restricts the
- rule to only apply to traffic that originates from (or
- terminates at) IP addresses in any of the given subnets.
- items:
- type: string
- type: array
- notNets:
- description:
- NotNets is the negated version of the Nets
- field.
- items:
- type: string
- type: array
- notPorts:
- description:
- NotPorts is the negated version of the Ports
- field. Since only some protocols have ports, if any ports
- are specified it requires the Protocol match in the Rule
- to be set to "TCP" or "UDP".
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- notSelector:
- description:
- NotSelector is the negated version of the Selector
- field. See Selector field for subtleties with negated
- selectors.
- type: string
- ports:
- description:
- "Ports is an optional field that restricts
- the rule to only apply to traffic that has a source (destination)
- port that matches one of these ranges/values. This value
- is a list of integers or strings that represent ranges
- of ports. \n Since only some protocols have ports, if
- any ports are specified it requires the Protocol match
- in the Rule to be set to \"TCP\" or \"UDP\"."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- selector:
- description:
- "Selector is an optional field that contains
- a selector expression (see Policy for sample syntax).
- \ Only traffic that originates from (terminates at) endpoints
- matching the selector will be matched. \n Note that: in
- addition to the negated version of the Selector (see NotSelector
- below), the selector expression syntax itself supports
- negation. The two types of negation are subtly different.
- One negates the set of matched endpoints, the other negates
- the whole match: \n \tSelector = \"!has(my_label)\" matches
- packets that are from other Calico-controlled \tendpoints
- that do not have the label \"my_label\". \n \tNotSelector
- = \"has(my_label)\" matches packets that are not from
- Calico-controlled \tendpoints that do have the label \"my_label\".
- \n The effect is that the latter will accept packets from
- non-Calico sources whereas the former is limited to packets
- from Calico-controlled endpoints."
- type: string
- serviceAccounts:
- description:
- ServiceAccounts is an optional field that restricts
- the rule to only apply to traffic that originates from
- (or terminates at) a pod running as a matching service
- account.
- properties:
- names:
- description:
- Names is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account whose name is in the list.
- items:
- type: string
- type: array
- selector:
- description:
- Selector is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account that matches the given label selector. If
- both Names and Selector are specified then they are
- AND'ed.
- type: string
- type: object
- services:
- description:
- "Services is an optional field that contains
- options for matching Kubernetes Services. If specified,
- only traffic that originates from or terminates at endpoints
- within the selected service(s) will be matched, and only
- to/from each endpoint's port. \n Services cannot be specified
- on the same rule as Selector, NotSelector, NamespaceSelector,
- Nets, NotNets or ServiceAccounts. \n Ports and NotPorts
- can only be specified with Services on ingress rules."
- properties:
- name:
- description:
- Name specifies the name of a Kubernetes
- Service to match.
- type: string
- namespace:
- description:
- Namespace specifies the namespace of the
- given Service. If left empty, the rule will match
- within this policy's namespace.
- type: string
- type: object
- type: object
- http:
- description:
- HTTP contains match criteria that apply to HTTP
- requests.
- properties:
- methods:
- description:
- Methods is an optional field that restricts
- the rule to apply only to HTTP requests that use one of
- the listed HTTP Methods (e.g. GET, PUT, etc.) Multiple
- methods are OR'd together.
- items:
- type: string
- type: array
- paths:
- description:
- "Paths is an optional field that restricts
- the rule to apply to HTTP requests that use one of the
- listed HTTP Paths. Multiple paths are OR'd together.
- e.g: - exact: /foo - prefix: /bar NOTE: Each entry may
- ONLY specify either a `exact` or a `prefix` match. The
- validator will check for it."
- items:
- description:
- "HTTPPath specifies an HTTP path to match.
- It may be either of the form: exact: <path>: which matches
- the path exactly or prefix: <path-prefix>: which matches
- the path prefix"
- properties:
- exact:
- type: string
- prefix:
- type: string
- type: object
- type: array
- type: object
- icmp:
- description:
- ICMP is an optional field that restricts the rule
- to apply to a specific type and code of ICMP traffic. This
- should only be specified if the Protocol field is set to "ICMP"
- or "ICMPv6".
- properties:
- code:
- description:
- Match on a specific ICMP code. If specified,
- the Type value must also be specified. This is a technical
- limitation imposed by the kernel's iptables firewall,
- which Calico uses to enforce the rule.
- type: integer
- type:
- description:
- Match on a specific ICMP type. For example
- a value of 8 refers to ICMP Echo Request (i.e. pings).
- type: integer
- type: object
- ipVersion:
- description:
- IPVersion is an optional field that restricts the
- rule to only match a specific IP version.
- type: integer
- metadata:
- description:
- Metadata contains additional information for this
- rule
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a set of key value pairs that
- give extra information about the rule
- type: object
- type: object
- notICMP:
- description: NotICMP is the negated version of the ICMP field.
- properties:
- code:
- description:
- Match on a specific ICMP code. If specified,
- the Type value must also be specified. This is a technical
- limitation imposed by the kernel's iptables firewall,
- which Calico uses to enforce the rule.
- type: integer
- type:
- description:
- Match on a specific ICMP type. For example
- a value of 8 refers to ICMP Echo Request (i.e. pings).
- type: integer
- type: object
- notProtocol:
- anyOf:
- - type: integer
- - type: string
- description:
- NotProtocol is the negated version of the Protocol
- field.
- pattern: ^.*
- x-kubernetes-int-or-string: true
- protocol:
- anyOf:
- - type: integer
- - type: string
- description:
- "Protocol is an optional field that restricts the
- rule to only apply to traffic of a specific IP protocol. Required
- if any of the EntityRules contain Ports (because ports only
- apply to certain protocols). \n Must be one of these string
- values: \"TCP\", \"UDP\", \"ICMP\", \"ICMPv6\", \"SCTP\",
- \"UDPLite\" or an integer in the range 1-255."
- pattern: ^.*
- x-kubernetes-int-or-string: true
- source:
- description:
- Source contains the match criteria that apply to
- source entity.
- properties:
- namespaceSelector:
- description:
- "NamespaceSelector is an optional field that
- contains a selector expression. Only traffic that originates
- from (or terminates at) endpoints within the selected
- namespaces will be matched. When both NamespaceSelector
- and another selector are defined on the same rule, then
- only workload endpoints that are matched by both selectors
- will be selected by the rule. \n For NetworkPolicy, an
- empty NamespaceSelector implies that the Selector is limited
- to selecting only workload endpoints in the same namespace
- as the NetworkPolicy. \n For NetworkPolicy, `global()`
- NamespaceSelector implies that the Selector is limited
- to selecting only GlobalNetworkSet or HostEndpoint. \n
- For GlobalNetworkPolicy, an empty NamespaceSelector implies
- the Selector applies to workload endpoints across all
- namespaces."
- type: string
- nets:
- description:
- Nets is an optional field that restricts the
- rule to only apply to traffic that originates from (or
- terminates at) IP addresses in any of the given subnets.
- items:
- type: string
- type: array
- notNets:
- description:
- NotNets is the negated version of the Nets
- field.
- items:
- type: string
- type: array
- notPorts:
- description:
- NotPorts is the negated version of the Ports
- field. Since only some protocols have ports, if any ports
- are specified it requires the Protocol match in the Rule
- to be set to "TCP" or "UDP".
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- notSelector:
- description:
- NotSelector is the negated version of the Selector
- field. See Selector field for subtleties with negated
- selectors.
- type: string
- ports:
- description:
- "Ports is an optional field that restricts
- the rule to only apply to traffic that has a source (destination)
- port that matches one of these ranges/values. This value
- is a list of integers or strings that represent ranges
- of ports. \n Since only some protocols have ports, if
- any ports are specified it requires the Protocol match
- in the Rule to be set to \"TCP\" or \"UDP\"."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- selector:
- description:
- "Selector is an optional field that contains
- a selector expression (see Policy for sample syntax).
- \ Only traffic that originates from (terminates at) endpoints
- matching the selector will be matched. \n Note that: in
- addition to the negated version of the Selector (see NotSelector
- below), the selector expression syntax itself supports
- negation. The two types of negation are subtly different.
- One negates the set of matched endpoints, the other negates
- the whole match: \n \tSelector = \"!has(my_label)\" matches
- packets that are from other Calico-controlled \tendpoints
- that do not have the label \"my_label\". \n \tNotSelector
- = \"has(my_label)\" matches packets that are not from
- Calico-controlled \tendpoints that do have the label \"my_label\".
- \n The effect is that the latter will accept packets from
- non-Calico sources whereas the former is limited to packets
- from Calico-controlled endpoints."
- type: string
- serviceAccounts:
- description:
- ServiceAccounts is an optional field that restricts
- the rule to only apply to traffic that originates from
- (or terminates at) a pod running as a matching service
- account.
- properties:
- names:
- description:
- Names is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account whose name is in the list.
- items:
- type: string
- type: array
- selector:
- description:
- Selector is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account that matches the given label selector. If
- both Names and Selector are specified then they are
- AND'ed.
- type: string
- type: object
- services:
- description:
- "Services is an optional field that contains
- options for matching Kubernetes Services. If specified,
- only traffic that originates from or terminates at endpoints
- within the selected service(s) will be matched, and only
- to/from each endpoint's port. \n Services cannot be specified
- on the same rule as Selector, NotSelector, NamespaceSelector,
- Nets, NotNets or ServiceAccounts. \n Ports and NotPorts
- can only be specified with Services on ingress rules."
- properties:
- name:
- description:
- Name specifies the name of a Kubernetes
- Service to match.
- type: string
- namespace:
- description:
- Namespace specifies the namespace of the
- given Service. If left empty, the rule will match
- within this policy's namespace.
- type: string
- type: object
- type: object
- required:
- - action
- type: object
- type: array
- namespaceSelector:
- description:
- NamespaceSelector is an optional field for an expression
- used to select a pod based on namespaces.
- type: string
- order:
- description:
- Order is an optional field that specifies the order in
- which the policy is applied. Policies with higher "order" are applied
- after those with lower order. If the order is omitted, it may be
- considered to be "infinite" - i.e. the policy will be applied last. Policies
- with identical order will be applied in alphanumerical order based
- on the Policy "Name".
- type: number
- preDNAT:
- description:
- PreDNAT indicates to apply the rules in this policy before
- any DNAT.
- type: boolean
- selector:
- description:
- "The selector is an expression used to pick pick out
- the endpoints that the policy should be applied to. \n Selector
- expressions follow this syntax: \n \tlabel == \"string_literal\"
- \ -> comparison, e.g. my_label == \"foo bar\" \tlabel != \"string_literal\"
- \ -> not equal; also matches if label is not present \tlabel in
- { \"a\", \"b\", \"c\", ... } -> true if the value of label X is
- one of \"a\", \"b\", \"c\" \tlabel not in { \"a\", \"b\", \"c\",
- ... } -> true if the value of label X is not one of \"a\", \"b\",
- \"c\" \thas(label_name) -> True if that label is present \t! expr
- -> negation of expr \texpr && expr -> Short-circuit and \texpr
- || expr -> Short-circuit or \t( expr ) -> parens for grouping \tall()
- or the empty selector -> matches all endpoints. \n Label names are
- allowed to contain alphanumerics, -, _ and /. String literals are
- more permissive but they do not support escape characters. \n Examples
- (with made-up labels): \n \ttype == \"webserver\" && deployment
- == \"prod\" \ttype in {\"frontend\", \"backend\"} \tdeployment !=
- \"dev\" \t! has(label_name)"
- type: string
- serviceAccountSelector:
- description:
- ServiceAccountSelector is an optional field for an expression
- used to select a pod based on service accounts.
- type: string
- types:
- description:
- "Types indicates whether this policy applies to ingress,
- or to egress, or to both. When not explicitly specified (and so
- the value on creation is empty or nil), Calico defaults Types according
- to what Ingress and Egress rules are present in the policy. The
- default is: \n - [ PolicyTypeIngress ], if there are no Egress rules
- (including the case where there are also no Ingress rules) \n
- - [ PolicyTypeEgress ], if there are Egress rules but no Ingress
- rules \n - [ PolicyTypeIngress, PolicyTypeEgress ], if there are
- both Ingress and Egress rules. \n When the policy is read back again,
- Types will always be one of these values, never empty or nil."
- items:
- description:
- PolicyType enumerates the possible values of the PolicySpec
- Types field.
- type: string
- type: array
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_globalnetworksets.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: globalnetworksets.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: GlobalNetworkSet
- listKind: GlobalNetworkSetList
- plural: globalnetworksets
- singular: globalnetworkset
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- description:
- GlobalNetworkSet contains a set of arbitrary IP sub-networks/CIDRs
- that share labels to allow rules to refer to them via selectors. The labels
- of GlobalNetworkSet are not namespaced.
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- GlobalNetworkSetSpec contains the specification for a NetworkSet
- resource.
- properties:
- nets:
- description: The list of IP networks that belong to this set.
- items:
- type: string
- type: array
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_hostendpoints.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: hostendpoints.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: HostEndpoint
- listKind: HostEndpointList
- plural: hostendpoints
- singular: hostendpoint
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- HostEndpointSpec contains the specification for a HostEndpoint
- resource.
- properties:
- expectedIPs:
- description:
- "The expected IP addresses (IPv4 and IPv6) of the endpoint.
- If \"InterfaceName\" is not present, Calico will look for an interface
- matching any of the IPs in the list and apply policy to that. Note:
- \tWhen using the selector match criteria in an ingress or egress
- security Policy \tor Profile, Calico converts the selector into
- a set of IP addresses. For host \tendpoints, the ExpectedIPs field
- is used for that purpose. (If only the interface \tname is specified,
- Calico does not learn the IPs of the interface for use in match
- \tcriteria.)"
- items:
- type: string
- type: array
- interfaceName:
- description:
- "Either \"*\", or the name of a specific Linux interface
- to apply policy to; or empty. \"*\" indicates that this HostEndpoint
- governs all traffic to, from or through the default network namespace
- of the host named by the \"Node\" field; entering and leaving that
- namespace via any interface, including those from/to non-host-networked
- local workloads. \n If InterfaceName is not \"*\", this HostEndpoint
- only governs traffic that enters or leaves the host through the
- specific interface named by InterfaceName, or - when InterfaceName
- is empty - through the specific interface that has one of the IPs
- in ExpectedIPs. Therefore, when InterfaceName is empty, at least
- one expected IP must be specified. Only external interfaces (such
- as \"eth0\") are supported here; it isn't possible for a HostEndpoint
- to protect traffic through a specific local workload interface.
- \n Note: Only some kinds of policy are implemented for \"*\" HostEndpoints;
- initially just pre-DNAT policy. Please check Calico documentation
- for the latest position."
- type: string
- node:
- description: The node name identifying the Calico node instance.
- type: string
- ports:
- description:
- Ports contains the endpoint's named ports, which may
- be referenced in security policy rules.
- items:
- properties:
- name:
- type: string
- port:
- type: integer
- protocol:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- required:
- - name
- - port
- - protocol
- type: object
- type: array
- profiles:
- description:
- A list of identifiers of security Profile objects that
- apply to this endpoint. Each profile is applied in the order that
- they appear in this list. Profile rules are applied after the selector-based
- security policy.
- items:
- type: string
- type: array
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_ipamblocks.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: ipamblocks.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: IPAMBlock
- listKind: IPAMBlockList
- plural: ipamblocks
- singular: ipamblock
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- IPAMBlockSpec contains the specification for an IPAMBlock
- resource.
- properties:
- affinity:
- description:
- Affinity of the block, if this block has one. If set,
- it will be of the form "host:<hostname>". If not set, this block
- is not affine to a host.
- type: string
- allocations:
- description:
- Array of allocations in-use within this block. nil entries
- mean the allocation is free. For non-nil entries at index i, the
- index is the ordinal of the allocation within this block and the
- value is the index of the associated attributes in the Attributes
- array.
- items:
- type: integer
- # TODO: This nullable is manually added in. We should update controller-gen
- # to handle []*int properly itself.
- nullable: true
- type: array
- attributes:
- description:
- Attributes is an array of arbitrary metadata associated
- with allocations in the block. To find attributes for a given allocation,
- use the value of the allocation's entry in the Allocations array
- as the index of the element in this array.
- items:
- properties:
- handle_id:
- type: string
- secondary:
- additionalProperties:
- type: string
- type: object
- type: object
- type: array
- cidr:
- description: The block's CIDR.
- type: string
- deleted:
- description:
- Deleted is an internal boolean used to workaround a limitation
- in the Kubernetes API whereby deletion will not return a conflict
- error if the block has been updated. It should not be set manually.
- type: boolean
- sequenceNumber:
- default: 0
- description:
- We store a sequence number that is updated each time
- the block is written. Each allocation will also store the sequence
- number of the block at the time of its creation. When releasing
- an IP, passing the sequence number associated with the allocation
- allows us to protect against a race condition and ensure the IP
- hasn't been released and re-allocated since the release request.
- format: int64
- type: integer
- sequenceNumberForAllocation:
- additionalProperties:
- format: int64
- type: integer
- description:
- Map of allocated ordinal within the block to sequence
- number of the block at the time of allocation. Kubernetes does not
- allow numerical keys for maps, so the key is cast to a string.
- type: object
- strictAffinity:
- description:
- StrictAffinity on the IPAMBlock is deprecated and no
- longer used by the code. Use IPAMConfig StrictAffinity instead.
- type: boolean
- unallocated:
- description:
- Unallocated is an ordered list of allocations which are
- free in the block.
- items:
- type: integer
- type: array
- required:
- - allocations
- - attributes
- - cidr
- - strictAffinity
- - unallocated
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_ipamconfigs.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: ipamconfigs.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: IPAMConfig
- listKind: IPAMConfigList
- plural: ipamconfigs
- singular: ipamconfig
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- IPAMConfigSpec contains the specification for an IPAMConfig
- resource.
- properties:
- autoAllocateBlocks:
- type: boolean
- maxBlocksPerHost:
- description:
- MaxBlocksPerHost, if non-zero, is the max number of blocks
- that can be affine to each host.
- maximum: 2147483647
- minimum: 0
- type: integer
- strictAffinity:
- type: boolean
- required:
- - autoAllocateBlocks
- - strictAffinity
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_ipamhandles.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: ipamhandles.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: IPAMHandle
- listKind: IPAMHandleList
- plural: ipamhandles
- singular: ipamhandle
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- IPAMHandleSpec contains the specification for an IPAMHandle
- resource.
- properties:
- block:
- additionalProperties:
- type: integer
- type: object
- deleted:
- type: boolean
- handleID:
- type: string
- required:
- - block
- - handleID
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_ippools.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: ippools.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: IPPool
- listKind: IPPoolList
- plural: ippools
- singular: ippool
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description: IPPoolSpec contains the specification for an IPPool resource.
- properties:
- allowedUses:
- description:
- AllowedUse controls what the IP pool will be used for. If
- not specified or empty, defaults to ["Tunnel", "Workload"] for back-compatibility
- items:
- type: string
- type: array
- blockSize:
- description:
- The block size to use for IP address assignments from
- this pool. Defaults to 26 for IPv4 and 122 for IPv6.
- type: integer
- cidr:
- description: The pool CIDR.
- type: string
- disableBGPExport:
- description:
- "Disable exporting routes from this IP Pool's CIDR over
- BGP. [Default: false]"
- type: boolean
- disabled:
- description:
- When disabled is true, Calico IPAM will not assign addresses
- from this pool.
- type: boolean
- ipip:
- description:
- "Deprecated: this field is only used for APIv1 backwards
- compatibility. Setting this field is not allowed, this field is
- for internal use only."
- properties:
- enabled:
- description:
- When enabled is true, ipip tunneling will be used
- to deliver packets to destinations within this pool.
- type: boolean
- mode:
- description:
- The IPIP mode. This can be one of "always" or "cross-subnet". A
- mode of "always" will also use IPIP tunneling for routing to
- destination IP addresses within this pool. A mode of "cross-subnet"
- will only use IPIP tunneling when the destination node is on
- a different subnet to the originating node. The default value
- (if not specified) is "always".
- type: string
- type: object
- ipipMode:
- description:
- Contains configuration for IPIP tunneling for this pool.
- If not specified, then this is defaulted to "Never" (i.e. IPIP tunneling
- is disabled).
- type: string
- nat-outgoing:
- description:
- "Deprecated: this field is only used for APIv1 backwards
- compatibility. Setting this field is not allowed, this field is
- for internal use only."
- type: boolean
- natOutgoing:
- description:
- When natOutgoing is true, packets sent from Calico networked
- containers in this pool to destinations outside of this pool will
- be masqueraded.
- type: boolean
- nodeSelector:
- description:
- Allows IPPool to allocate for a specific node by label
- selector.
- type: string
- vxlanMode:
- description:
- Contains configuration for VXLAN tunneling for this pool.
- If not specified, then this is defaulted to "Never" (i.e. VXLAN
- tunneling is disabled).
- type: string
- required:
- - cidr
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_ipreservations.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- annotations:
- controller-gen.kubebuilder.io/version: (devel)
- creationTimestamp: null
- name: ipreservations.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: IPReservation
- listKind: IPReservationList
- plural: ipreservations
- singular: ipreservation
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- IPReservationSpec contains the specification for an IPReservation
- resource.
- properties:
- reservedCIDRs:
- description:
- ReservedCIDRs is a list of CIDRs and/or IP addresses
- that Calico IPAM will exclude from new allocations.
- items:
- type: string
- type: array
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_kubecontrollersconfigurations.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: kubecontrollersconfigurations.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: KubeControllersConfiguration
- listKind: KubeControllersConfigurationList
- plural: kubecontrollersconfigurations
- singular: kubecontrollersconfiguration
- preserveUnknownFields: false
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- KubeControllersConfigurationSpec contains the values of the
- Kubernetes controllers configuration.
- properties:
- controllers:
- description:
- Controllers enables and configures individual Kubernetes
- controllers
- properties:
- namespace:
- description:
- Namespace enables and configures the namespace controller.
- Enabled by default, set to nil to disable.
- properties:
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform reconciliation
- with the Calico datastore. [Default: 5m]"
- type: string
- type: object
- node:
- description:
- Node enables and configures the node controller.
- Enabled by default, set to nil to disable.
- properties:
- hostEndpoint:
- description:
- HostEndpoint controls syncing nodes to host endpoints.
- Disabled by default, set to nil to disable.
- properties:
- autoCreate:
- description:
- "AutoCreate enables automatic creation of
- host endpoints for every node. [Default: Disabled]"
- type: string
- type: object
- leakGracePeriod:
- description:
- "LeakGracePeriod is the period used by the controller
- to determine if an IP address has been leaked. Set to 0
- to disable IP garbage collection. [Default: 15m]"
- type: string
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform reconciliation
- with the Calico datastore. [Default: 5m]"
- type: string
- syncLabels:
- description:
- "SyncLabels controls whether to copy Kubernetes
- node labels to Calico nodes. [Default: Enabled]"
- type: string
- type: object
- policy:
- description:
- Policy enables and configures the policy controller.
- Enabled by default, set to nil to disable.
- properties:
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform reconciliation
- with the Calico datastore. [Default: 5m]"
- type: string
- type: object
- serviceAccount:
- description:
- ServiceAccount enables and configures the service
- account controller. Enabled by default, set to nil to disable.
- properties:
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform reconciliation
- with the Calico datastore. [Default: 5m]"
- type: string
- type: object
- workloadEndpoint:
- description:
- WorkloadEndpoint enables and configures the workload
- endpoint controller. Enabled by default, set to nil to disable.
- properties:
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform reconciliation
- with the Calico datastore. [Default: 5m]"
- type: string
- type: object
- type: object
- debugProfilePort:
- description:
- DebugProfilePort configures the port to serve memory
- and cpu profiles on. If not specified, profiling is disabled.
- format: int32
- type: integer
- etcdV3CompactionPeriod:
- description:
- "EtcdV3CompactionPeriod is the period between etcdv3
- compaction requests. Set to 0 to disable. [Default: 10m]"
- type: string
- healthChecks:
- description:
- "HealthChecks enables or disables support for health
- checks [Default: Enabled]"
- type: string
- logSeverityScreen:
- description:
- "LogSeverityScreen is the log severity above which logs
- are sent to the stdout. [Default: Info]"
- type: string
- prometheusMetricsPort:
- description:
- "PrometheusMetricsPort is the TCP port that the Prometheus
- metrics server should bind to. Set to 0 to disable. [Default: 9094]"
- type: integer
- required:
- - controllers
- type: object
- status:
- description:
- KubeControllersConfigurationStatus represents the status
- of the configuration. It's useful for admins to be able to see the actual
- config that was applied, which can be modified by environment variables
- on the kube-controllers process.
- properties:
- environmentVars:
- additionalProperties:
- type: string
- description:
- EnvironmentVars contains the environment variables on
- the kube-controllers that influenced the RunningConfig.
- type: object
- runningConfig:
- description:
- RunningConfig contains the effective config that is running
- in the kube-controllers pod, after merging the API resource with
- any environment variables.
- properties:
- controllers:
- description:
- Controllers enables and configures individual Kubernetes
- controllers
- properties:
- namespace:
- description:
- Namespace enables and configures the namespace
- controller. Enabled by default, set to nil to disable.
- properties:
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform
- reconciliation with the Calico datastore. [Default:
- 5m]"
- type: string
- type: object
- node:
- description:
- Node enables and configures the node controller.
- Enabled by default, set to nil to disable.
- properties:
- hostEndpoint:
- description:
- HostEndpoint controls syncing nodes to host
- endpoints. Disabled by default, set to nil to disable.
- properties:
- autoCreate:
- description:
- "AutoCreate enables automatic creation
- of host endpoints for every node. [Default: Disabled]"
- type: string
- type: object
- leakGracePeriod:
- description:
- "LeakGracePeriod is the period used by the
- controller to determine if an IP address has been leaked.
- Set to 0 to disable IP garbage collection. [Default:
- 15m]"
- type: string
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform
- reconciliation with the Calico datastore. [Default:
- 5m]"
- type: string
- syncLabels:
- description:
- "SyncLabels controls whether to copy Kubernetes
- node labels to Calico nodes. [Default: Enabled]"
- type: string
- type: object
- policy:
- description:
- Policy enables and configures the policy controller.
- Enabled by default, set to nil to disable.
- properties:
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform
- reconciliation with the Calico datastore. [Default:
- 5m]"
- type: string
- type: object
- serviceAccount:
- description:
- ServiceAccount enables and configures the service
- account controller. Enabled by default, set to nil to disable.
- properties:
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform
- reconciliation with the Calico datastore. [Default:
- 5m]"
- type: string
- type: object
- workloadEndpoint:
- description:
- WorkloadEndpoint enables and configures the workload
- endpoint controller. Enabled by default, set to nil to disable.
- properties:
- reconcilerPeriod:
- description:
- "ReconcilerPeriod is the period to perform
- reconciliation with the Calico datastore. [Default:
- 5m]"
- type: string
- type: object
- type: object
- debugProfilePort:
- description:
- DebugProfilePort configures the port to serve memory
- and cpu profiles on. If not specified, profiling is disabled.
- format: int32
- type: integer
- etcdV3CompactionPeriod:
- description:
- "EtcdV3CompactionPeriod is the period between etcdv3
- compaction requests. Set to 0 to disable. [Default: 10m]"
- type: string
- healthChecks:
- description:
- "HealthChecks enables or disables support for health
- checks [Default: Enabled]"
- type: string
- logSeverityScreen:
- description:
- "LogSeverityScreen is the log severity above which
- logs are sent to the stdout. [Default: Info]"
- type: string
- prometheusMetricsPort:
- description:
- "PrometheusMetricsPort is the TCP port that the Prometheus
- metrics server should bind to. Set to 0 to disable. [Default:
- 9094]"
- type: integer
- required:
- - controllers
- type: object
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_networkpolicies.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: networkpolicies.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: NetworkPolicy
- listKind: NetworkPolicyList
- plural: networkpolicies
- singular: networkpolicy
- preserveUnknownFields: false
- scope: Namespaced
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- properties:
- egress:
- description:
- The ordered set of egress rules. Each rule contains
- a set of packet match criteria and a corresponding action to apply.
- items:
- description:
- "A Rule encapsulates a set of match criteria and an
- action. Both selector-based security Policy and security Profiles
- reference rules - separated out as a list of rules for both ingress
- and egress packet matching. \n Each positive match criteria has
- a negated version, prefixed with \"Not\". All the match criteria
- within a rule must be satisfied for a packet to match. A single
- rule can contain the positive and negative version of a match
- and both must be satisfied for the rule to match."
- properties:
- action:
- type: string
- destination:
- description:
- Destination contains the match criteria that apply
- to destination entity.
- properties:
- namespaceSelector:
- description:
- "NamespaceSelector is an optional field that
- contains a selector expression. Only traffic that originates
- from (or terminates at) endpoints within the selected
- namespaces will be matched. When both NamespaceSelector
- and another selector are defined on the same rule, then
- only workload endpoints that are matched by both selectors
- will be selected by the rule. \n For NetworkPolicy, an
- empty NamespaceSelector implies that the Selector is limited
- to selecting only workload endpoints in the same namespace
- as the NetworkPolicy. \n For NetworkPolicy, `global()`
- NamespaceSelector implies that the Selector is limited
- to selecting only GlobalNetworkSet or HostEndpoint. \n
- For GlobalNetworkPolicy, an empty NamespaceSelector implies
- the Selector applies to workload endpoints across all
- namespaces."
- type: string
- nets:
- description:
- Nets is an optional field that restricts the
- rule to only apply to traffic that originates from (or
- terminates at) IP addresses in any of the given subnets.
- items:
- type: string
- type: array
- notNets:
- description:
- NotNets is the negated version of the Nets
- field.
- items:
- type: string
- type: array
- notPorts:
- description:
- NotPorts is the negated version of the Ports
- field. Since only some protocols have ports, if any ports
- are specified it requires the Protocol match in the Rule
- to be set to "TCP" or "UDP".
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- notSelector:
- description:
- NotSelector is the negated version of the Selector
- field. See Selector field for subtleties with negated
- selectors.
- type: string
- ports:
- description:
- "Ports is an optional field that restricts
- the rule to only apply to traffic that has a source (destination)
- port that matches one of these ranges/values. This value
- is a list of integers or strings that represent ranges
- of ports. \n Since only some protocols have ports, if
- any ports are specified it requires the Protocol match
- in the Rule to be set to \"TCP\" or \"UDP\"."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- selector:
- description:
- "Selector is an optional field that contains
- a selector expression (see Policy for sample syntax).
- \ Only traffic that originates from (terminates at) endpoints
- matching the selector will be matched. \n Note that: in
- addition to the negated version of the Selector (see NotSelector
- below), the selector expression syntax itself supports
- negation. The two types of negation are subtly different.
- One negates the set of matched endpoints, the other negates
- the whole match: \n \tSelector = \"!has(my_label)\" matches
- packets that are from other Calico-controlled \tendpoints
- that do not have the label \"my_label\". \n \tNotSelector
- = \"has(my_label)\" matches packets that are not from
- Calico-controlled \tendpoints that do have the label \"my_label\".
- \n The effect is that the latter will accept packets from
- non-Calico sources whereas the former is limited to packets
- from Calico-controlled endpoints."
- type: string
- serviceAccounts:
- description:
- ServiceAccounts is an optional field that restricts
- the rule to only apply to traffic that originates from
- (or terminates at) a pod running as a matching service
- account.
- properties:
- names:
- description:
- Names is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account whose name is in the list.
- items:
- type: string
- type: array
- selector:
- description:
- Selector is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account that matches the given label selector. If
- both Names and Selector are specified then they are
- AND'ed.
- type: string
- type: object
- services:
- description:
- "Services is an optional field that contains
- options for matching Kubernetes Services. If specified,
- only traffic that originates from or terminates at endpoints
- within the selected service(s) will be matched, and only
- to/from each endpoint's port. \n Services cannot be specified
- on the same rule as Selector, NotSelector, NamespaceSelector,
- Nets, NotNets or ServiceAccounts. \n Ports and NotPorts
- can only be specified with Services on ingress rules."
- properties:
- name:
- description:
- Name specifies the name of a Kubernetes
- Service to match.
- type: string
- namespace:
- description:
- Namespace specifies the namespace of the
- given Service. If left empty, the rule will match
- within this policy's namespace.
- type: string
- type: object
- type: object
- http:
- description:
- HTTP contains match criteria that apply to HTTP
- requests.
- properties:
- methods:
- description:
- Methods is an optional field that restricts
- the rule to apply only to HTTP requests that use one of
- the listed HTTP Methods (e.g. GET, PUT, etc.) Multiple
- methods are OR'd together.
- items:
- type: string
- type: array
- paths:
- description:
- "Paths is an optional field that restricts
- the rule to apply to HTTP requests that use one of the
- listed HTTP Paths. Multiple paths are OR'd together.
- e.g: - exact: /foo - prefix: /bar NOTE: Each entry may
- ONLY specify either a `exact` or a `prefix` match. The
- validator will check for it."
- items:
- description:
- "HTTPPath specifies an HTTP path to match.
- It may be either of the form: exact: <path>: which matches
- the path exactly or prefix: <path-prefix>: which matches
- the path prefix"
- properties:
- exact:
- type: string
- prefix:
- type: string
- type: object
- type: array
- type: object
- icmp:
- description:
- ICMP is an optional field that restricts the rule
- to apply to a specific type and code of ICMP traffic. This
- should only be specified if the Protocol field is set to "ICMP"
- or "ICMPv6".
- properties:
- code:
- description:
- Match on a specific ICMP code. If specified,
- the Type value must also be specified. This is a technical
- limitation imposed by the kernel's iptables firewall,
- which Calico uses to enforce the rule.
- type: integer
- type:
- description:
- Match on a specific ICMP type. For example
- a value of 8 refers to ICMP Echo Request (i.e. pings).
- type: integer
- type: object
- ipVersion:
- description:
- IPVersion is an optional field that restricts the
- rule to only match a specific IP version.
- type: integer
- metadata:
- description:
- Metadata contains additional information for this
- rule
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a set of key value pairs that
- give extra information about the rule
- type: object
- type: object
- notICMP:
- description: NotICMP is the negated version of the ICMP field.
- properties:
- code:
- description:
- Match on a specific ICMP code. If specified,
- the Type value must also be specified. This is a technical
- limitation imposed by the kernel's iptables firewall,
- which Calico uses to enforce the rule.
- type: integer
- type:
- description:
- Match on a specific ICMP type. For example
- a value of 8 refers to ICMP Echo Request (i.e. pings).
- type: integer
- type: object
- notProtocol:
- anyOf:
- - type: integer
- - type: string
- description:
- NotProtocol is the negated version of the Protocol
- field.
- pattern: ^.*
- x-kubernetes-int-or-string: true
- protocol:
- anyOf:
- - type: integer
- - type: string
- description:
- "Protocol is an optional field that restricts the
- rule to only apply to traffic of a specific IP protocol. Required
- if any of the EntityRules contain Ports (because ports only
- apply to certain protocols). \n Must be one of these string
- values: \"TCP\", \"UDP\", \"ICMP\", \"ICMPv6\", \"SCTP\",
- \"UDPLite\" or an integer in the range 1-255."
- pattern: ^.*
- x-kubernetes-int-or-string: true
- source:
- description:
- Source contains the match criteria that apply to
- source entity.
- properties:
- namespaceSelector:
- description:
- "NamespaceSelector is an optional field that
- contains a selector expression. Only traffic that originates
- from (or terminates at) endpoints within the selected
- namespaces will be matched. When both NamespaceSelector
- and another selector are defined on the same rule, then
- only workload endpoints that are matched by both selectors
- will be selected by the rule. \n For NetworkPolicy, an
- empty NamespaceSelector implies that the Selector is limited
- to selecting only workload endpoints in the same namespace
- as the NetworkPolicy. \n For NetworkPolicy, `global()`
- NamespaceSelector implies that the Selector is limited
- to selecting only GlobalNetworkSet or HostEndpoint. \n
- For GlobalNetworkPolicy, an empty NamespaceSelector implies
- the Selector applies to workload endpoints across all
- namespaces."
- type: string
- nets:
- description:
- Nets is an optional field that restricts the
- rule to only apply to traffic that originates from (or
- terminates at) IP addresses in any of the given subnets.
- items:
- type: string
- type: array
- notNets:
- description:
- NotNets is the negated version of the Nets
- field.
- items:
- type: string
- type: array
- notPorts:
- description:
- NotPorts is the negated version of the Ports
- field. Since only some protocols have ports, if any ports
- are specified it requires the Protocol match in the Rule
- to be set to "TCP" or "UDP".
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- notSelector:
- description:
- NotSelector is the negated version of the Selector
- field. See Selector field for subtleties with negated
- selectors.
- type: string
- ports:
- description:
- "Ports is an optional field that restricts
- the rule to only apply to traffic that has a source (destination)
- port that matches one of these ranges/values. This value
- is a list of integers or strings that represent ranges
- of ports. \n Since only some protocols have ports, if
- any ports are specified it requires the Protocol match
- in the Rule to be set to \"TCP\" or \"UDP\"."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- selector:
- description:
- "Selector is an optional field that contains
- a selector expression (see Policy for sample syntax).
- \ Only traffic that originates from (terminates at) endpoints
- matching the selector will be matched. \n Note that: in
- addition to the negated version of the Selector (see NotSelector
- below), the selector expression syntax itself supports
- negation. The two types of negation are subtly different.
- One negates the set of matched endpoints, the other negates
- the whole match: \n \tSelector = \"!has(my_label)\" matches
- packets that are from other Calico-controlled \tendpoints
- that do not have the label \"my_label\". \n \tNotSelector
- = \"has(my_label)\" matches packets that are not from
- Calico-controlled \tendpoints that do have the label \"my_label\".
- \n The effect is that the latter will accept packets from
- non-Calico sources whereas the former is limited to packets
- from Calico-controlled endpoints."
- type: string
- serviceAccounts:
- description:
- ServiceAccounts is an optional field that restricts
- the rule to only apply to traffic that originates from
- (or terminates at) a pod running as a matching service
- account.
- properties:
- names:
- description:
- Names is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account whose name is in the list.
- items:
- type: string
- type: array
- selector:
- description:
- Selector is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account that matches the given label selector. If
- both Names and Selector are specified then they are
- AND'ed.
- type: string
- type: object
- services:
- description:
- "Services is an optional field that contains
- options for matching Kubernetes Services. If specified,
- only traffic that originates from or terminates at endpoints
- within the selected service(s) will be matched, and only
- to/from each endpoint's port. \n Services cannot be specified
- on the same rule as Selector, NotSelector, NamespaceSelector,
- Nets, NotNets or ServiceAccounts. \n Ports and NotPorts
- can only be specified with Services on ingress rules."
- properties:
- name:
- description:
- Name specifies the name of a Kubernetes
- Service to match.
- type: string
- namespace:
- description:
- Namespace specifies the namespace of the
- given Service. If left empty, the rule will match
- within this policy's namespace.
- type: string
- type: object
- type: object
- required:
- - action
- type: object
- type: array
- ingress:
- description:
- The ordered set of ingress rules. Each rule contains
- a set of packet match criteria and a corresponding action to apply.
- items:
- description:
- "A Rule encapsulates a set of match criteria and an
- action. Both selector-based security Policy and security Profiles
- reference rules - separated out as a list of rules for both ingress
- and egress packet matching. \n Each positive match criteria has
- a negated version, prefixed with \"Not\". All the match criteria
- within a rule must be satisfied for a packet to match. A single
- rule can contain the positive and negative version of a match
- and both must be satisfied for the rule to match."
- properties:
- action:
- type: string
- destination:
- description:
- Destination contains the match criteria that apply
- to destination entity.
- properties:
- namespaceSelector:
- description:
- "NamespaceSelector is an optional field that
- contains a selector expression. Only traffic that originates
- from (or terminates at) endpoints within the selected
- namespaces will be matched. When both NamespaceSelector
- and another selector are defined on the same rule, then
- only workload endpoints that are matched by both selectors
- will be selected by the rule. \n For NetworkPolicy, an
- empty NamespaceSelector implies that the Selector is limited
- to selecting only workload endpoints in the same namespace
- as the NetworkPolicy. \n For NetworkPolicy, `global()`
- NamespaceSelector implies that the Selector is limited
- to selecting only GlobalNetworkSet or HostEndpoint. \n
- For GlobalNetworkPolicy, an empty NamespaceSelector implies
- the Selector applies to workload endpoints across all
- namespaces."
- type: string
- nets:
- description:
- Nets is an optional field that restricts the
- rule to only apply to traffic that originates from (or
- terminates at) IP addresses in any of the given subnets.
- items:
- type: string
- type: array
- notNets:
- description:
- NotNets is the negated version of the Nets
- field.
- items:
- type: string
- type: array
- notPorts:
- description:
- NotPorts is the negated version of the Ports
- field. Since only some protocols have ports, if any ports
- are specified it requires the Protocol match in the Rule
- to be set to "TCP" or "UDP".
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- notSelector:
- description:
- NotSelector is the negated version of the Selector
- field. See Selector field for subtleties with negated
- selectors.
- type: string
- ports:
- description:
- "Ports is an optional field that restricts
- the rule to only apply to traffic that has a source (destination)
- port that matches one of these ranges/values. This value
- is a list of integers or strings that represent ranges
- of ports. \n Since only some protocols have ports, if
- any ports are specified it requires the Protocol match
- in the Rule to be set to \"TCP\" or \"UDP\"."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- selector:
- description:
- "Selector is an optional field that contains
- a selector expression (see Policy for sample syntax).
- \ Only traffic that originates from (terminates at) endpoints
- matching the selector will be matched. \n Note that: in
- addition to the negated version of the Selector (see NotSelector
- below), the selector expression syntax itself supports
- negation. The two types of negation are subtly different.
- One negates the set of matched endpoints, the other negates
- the whole match: \n \tSelector = \"!has(my_label)\" matches
- packets that are from other Calico-controlled \tendpoints
- that do not have the label \"my_label\". \n \tNotSelector
- = \"has(my_label)\" matches packets that are not from
- Calico-controlled \tendpoints that do have the label \"my_label\".
- \n The effect is that the latter will accept packets from
- non-Calico sources whereas the former is limited to packets
- from Calico-controlled endpoints."
- type: string
- serviceAccounts:
- description:
- ServiceAccounts is an optional field that restricts
- the rule to only apply to traffic that originates from
- (or terminates at) a pod running as a matching service
- account.
- properties:
- names:
- description:
- Names is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account whose name is in the list.
- items:
- type: string
- type: array
- selector:
- description:
- Selector is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account that matches the given label selector. If
- both Names and Selector are specified then they are
- AND'ed.
- type: string
- type: object
- services:
- description:
- "Services is an optional field that contains
- options for matching Kubernetes Services. If specified,
- only traffic that originates from or terminates at endpoints
- within the selected service(s) will be matched, and only
- to/from each endpoint's port. \n Services cannot be specified
- on the same rule as Selector, NotSelector, NamespaceSelector,
- Nets, NotNets or ServiceAccounts. \n Ports and NotPorts
- can only be specified with Services on ingress rules."
- properties:
- name:
- description:
- Name specifies the name of a Kubernetes
- Service to match.
- type: string
- namespace:
- description:
- Namespace specifies the namespace of the
- given Service. If left empty, the rule will match
- within this policy's namespace.
- type: string
- type: object
- type: object
- http:
- description:
- HTTP contains match criteria that apply to HTTP
- requests.
- properties:
- methods:
- description:
- Methods is an optional field that restricts
- the rule to apply only to HTTP requests that use one of
- the listed HTTP Methods (e.g. GET, PUT, etc.) Multiple
- methods are OR'd together.
- items:
- type: string
- type: array
- paths:
- description:
- "Paths is an optional field that restricts
- the rule to apply to HTTP requests that use one of the
- listed HTTP Paths. Multiple paths are OR'd together.
- e.g: - exact: /foo - prefix: /bar NOTE: Each entry may
- ONLY specify either a `exact` or a `prefix` match. The
- validator will check for it."
- items:
- description:
- "HTTPPath specifies an HTTP path to match.
- It may be either of the form: exact: <path>: which matches
- the path exactly or prefix: <path-prefix>: which matches
- the path prefix"
- properties:
- exact:
- type: string
- prefix:
- type: string
- type: object
- type: array
- type: object
- icmp:
- description:
- ICMP is an optional field that restricts the rule
- to apply to a specific type and code of ICMP traffic. This
- should only be specified if the Protocol field is set to "ICMP"
- or "ICMPv6".
- properties:
- code:
- description:
- Match on a specific ICMP code. If specified,
- the Type value must also be specified. This is a technical
- limitation imposed by the kernel's iptables firewall,
- which Calico uses to enforce the rule.
- type: integer
- type:
- description:
- Match on a specific ICMP type. For example
- a value of 8 refers to ICMP Echo Request (i.e. pings).
- type: integer
- type: object
- ipVersion:
- description:
- IPVersion is an optional field that restricts the
- rule to only match a specific IP version.
- type: integer
- metadata:
- description:
- Metadata contains additional information for this
- rule
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a set of key value pairs that
- give extra information about the rule
- type: object
- type: object
- notICMP:
- description: NotICMP is the negated version of the ICMP field.
- properties:
- code:
- description:
- Match on a specific ICMP code. If specified,
- the Type value must also be specified. This is a technical
- limitation imposed by the kernel's iptables firewall,
- which Calico uses to enforce the rule.
- type: integer
- type:
- description:
- Match on a specific ICMP type. For example
- a value of 8 refers to ICMP Echo Request (i.e. pings).
- type: integer
- type: object
- notProtocol:
- anyOf:
- - type: integer
- - type: string
- description:
- NotProtocol is the negated version of the Protocol
- field.
- pattern: ^.*
- x-kubernetes-int-or-string: true
- protocol:
- anyOf:
- - type: integer
- - type: string
- description:
- "Protocol is an optional field that restricts the
- rule to only apply to traffic of a specific IP protocol. Required
- if any of the EntityRules contain Ports (because ports only
- apply to certain protocols). \n Must be one of these string
- values: \"TCP\", \"UDP\", \"ICMP\", \"ICMPv6\", \"SCTP\",
- \"UDPLite\" or an integer in the range 1-255."
- pattern: ^.*
- x-kubernetes-int-or-string: true
- source:
- description:
- Source contains the match criteria that apply to
- source entity.
- properties:
- namespaceSelector:
- description:
- "NamespaceSelector is an optional field that
- contains a selector expression. Only traffic that originates
- from (or terminates at) endpoints within the selected
- namespaces will be matched. When both NamespaceSelector
- and another selector are defined on the same rule, then
- only workload endpoints that are matched by both selectors
- will be selected by the rule. \n For NetworkPolicy, an
- empty NamespaceSelector implies that the Selector is limited
- to selecting only workload endpoints in the same namespace
- as the NetworkPolicy. \n For NetworkPolicy, `global()`
- NamespaceSelector implies that the Selector is limited
- to selecting only GlobalNetworkSet or HostEndpoint. \n
- For GlobalNetworkPolicy, an empty NamespaceSelector implies
- the Selector applies to workload endpoints across all
- namespaces."
- type: string
- nets:
- description:
- Nets is an optional field that restricts the
- rule to only apply to traffic that originates from (or
- terminates at) IP addresses in any of the given subnets.
- items:
- type: string
- type: array
- notNets:
- description:
- NotNets is the negated version of the Nets
- field.
- items:
- type: string
- type: array
- notPorts:
- description:
- NotPorts is the negated version of the Ports
- field. Since only some protocols have ports, if any ports
- are specified it requires the Protocol match in the Rule
- to be set to "TCP" or "UDP".
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- notSelector:
- description:
- NotSelector is the negated version of the Selector
- field. See Selector field for subtleties with negated
- selectors.
- type: string
- ports:
- description:
- "Ports is an optional field that restricts
- the rule to only apply to traffic that has a source (destination)
- port that matches one of these ranges/values. This value
- is a list of integers or strings that represent ranges
- of ports. \n Since only some protocols have ports, if
- any ports are specified it requires the Protocol match
- in the Rule to be set to \"TCP\" or \"UDP\"."
- items:
- anyOf:
- - type: integer
- - type: string
- pattern: ^.*
- x-kubernetes-int-or-string: true
- type: array
- selector:
- description:
- "Selector is an optional field that contains
- a selector expression (see Policy for sample syntax).
- \ Only traffic that originates from (terminates at) endpoints
- matching the selector will be matched. \n Note that: in
- addition to the negated version of the Selector (see NotSelector
- below), the selector expression syntax itself supports
- negation. The two types of negation are subtly different.
- One negates the set of matched endpoints, the other negates
- the whole match: \n \tSelector = \"!has(my_label)\" matches
- packets that are from other Calico-controlled \tendpoints
- that do not have the label \"my_label\". \n \tNotSelector
- = \"has(my_label)\" matches packets that are not from
- Calico-controlled \tendpoints that do have the label \"my_label\".
- \n The effect is that the latter will accept packets from
- non-Calico sources whereas the former is limited to packets
- from Calico-controlled endpoints."
- type: string
- serviceAccounts:
- description:
- ServiceAccounts is an optional field that restricts
- the rule to only apply to traffic that originates from
- (or terminates at) a pod running as a matching service
- account.
- properties:
- names:
- description:
- Names is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account whose name is in the list.
- items:
- type: string
- type: array
- selector:
- description:
- Selector is an optional field that restricts
- the rule to only apply to traffic that originates
- from (or terminates at) a pod running as a service
- account that matches the given label selector. If
- both Names and Selector are specified then they are
- AND'ed.
- type: string
- type: object
- services:
- description:
- "Services is an optional field that contains
- options for matching Kubernetes Services. If specified,
- only traffic that originates from or terminates at endpoints
- within the selected service(s) will be matched, and only
- to/from each endpoint's port. \n Services cannot be specified
- on the same rule as Selector, NotSelector, NamespaceSelector,
- Nets, NotNets or ServiceAccounts. \n Ports and NotPorts
- can only be specified with Services on ingress rules."
- properties:
- name:
- description:
- Name specifies the name of a Kubernetes
- Service to match.
- type: string
- namespace:
- description:
- Namespace specifies the namespace of the
- given Service. If left empty, the rule will match
- within this policy's namespace.
- type: string
- type: object
- type: object
- required:
- - action
- type: object
- type: array
- order:
- description:
- Order is an optional field that specifies the order in
- which the policy is applied. Policies with higher "order" are applied
- after those with lower order. If the order is omitted, it may be
- considered to be "infinite" - i.e. the policy will be applied last. Policies
- with identical order will be applied in alphanumerical order based
- on the Policy "Name".
- type: number
- selector:
- description:
- "The selector is an expression used to pick pick out
- the endpoints that the policy should be applied to. \n Selector
- expressions follow this syntax: \n \tlabel == \"string_literal\"
- \ -> comparison, e.g. my_label == \"foo bar\" \tlabel != \"string_literal\"
- \ -> not equal; also matches if label is not present \tlabel in
- { \"a\", \"b\", \"c\", ... } -> true if the value of label X is
- one of \"a\", \"b\", \"c\" \tlabel not in { \"a\", \"b\", \"c\",
- ... } -> true if the value of label X is not one of \"a\", \"b\",
- \"c\" \thas(label_name) -> True if that label is present \t! expr
- -> negation of expr \texpr && expr -> Short-circuit and \texpr
- || expr -> Short-circuit or \t( expr ) -> parens for grouping \tall()
- or the empty selector -> matches all endpoints. \n Label names are
- allowed to contain alphanumerics, -, _ and /. String literals are
- more permissive but they do not support escape characters. \n Examples
- (with made-up labels): \n \ttype == \"webserver\" && deployment
- == \"prod\" \ttype in {\"frontend\", \"backend\"} \tdeployment !=
- \"dev\" \t! has(label_name)"
- type: string
- serviceAccountSelector:
- description:
- ServiceAccountSelector is an optional field for an expression
- used to select a pod based on service accounts.
- type: string
- types:
- description:
- "Types indicates whether this policy applies to ingress,
- or to egress, or to both. When not explicitly specified (and so
- the value on creation is empty or nil), Calico defaults Types according
- to what Ingress and Egress are present in the policy. The default
- is: \n - [ PolicyTypeIngress ], if there are no Egress rules (including
- the case where there are also no Ingress rules) \n - [ PolicyTypeEgress
- ], if there are Egress rules but no Ingress rules \n - [ PolicyTypeIngress,
- PolicyTypeEgress ], if there are both Ingress and Egress rules.
- \n When the policy is read back again, Types will always be one
- of these values, never empty or nil."
- items:
- description:
- PolicyType enumerates the possible values of the PolicySpec
- Types field.
- type: string
- type: array
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/calico/crd.projectcalico.org_networksets.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- name: networksets.crd.projectcalico.org
-spec:
- group: crd.projectcalico.org
- names:
- kind: NetworkSet
- listKind: NetworkSetList
- plural: networksets
- singular: networkset
- preserveUnknownFields: false
- scope: Namespaced
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- description: NetworkSet is the Namespaced-equivalent of the GlobalNetworkSet.
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- NetworkSetSpec contains the specification for a NetworkSet
- resource.
- properties:
- nets:
- description: The list of IP networks that belong to this set.
- items:
- type: string
- type: array
- type: object
- type: object
- served: true
- storage: true
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/operator.tigera.io_apiservers_crd.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- annotations:
- controller-gen.kubebuilder.io/version: v0.3.0
- name: apiservers.operator.tigera.io
-spec:
- group: operator.tigera.io
- names:
- kind: APIServer
- listKind: APIServerList
- plural: apiservers
- singular: apiserver
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- description:
- APIServer installs the Tigera API server and related resources.
- At most one instance of this resource is supported. It must be named "tigera-secure".
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description: Specification of the desired state for the Tigera API server.
- properties:
- apiServerDeployment:
- description:
- APIServerDeployment configures the calico-apiserver (or
- tigera-apiserver in Enterprise) Deployment. If used in conjunction
- with ControlPlaneNodeSelector or ControlPlaneTolerations, then these
- overrides take precedence.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's metadata
- that is added to the Deployment.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to the
- object's annotations provided the key does not already exist
- in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values that
- may match replicaset and service selectors. Each of these
- key/value pairs are added to the object's labels provided
- the key does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the specification of the API server Deployment.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of seconds
- for which a newly created Deployment pod should be ready
- without any of its container crashing, for it to be considered
- available. If specified, this overrides any minReadySeconds
- value that may be set on the API server Deployment. If omitted,
- the API server Deployment will use its default value for
- minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the API server Deployment
- pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added
- to the object's annotations provided the key does
- not already exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors.
- Each of these key/value pairs are added to the object's
- labels provided the key does not already exist in
- the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the API server Deployment's PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity scheduling
- rules for the API server pods. If specified, this
- overrides any affinity that may be set on the API
- server Deployment. If omitted, the API server Deployment
- will use its default value for affinity. WARNING:
- Please note that this field will override the default
- API server Deployment affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node matches the corresponding matchExpressions;
- the node(s) with the highest sum are the
- most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null preferred
- scheduling term matches no objects (i.e.
- is also a no-op).
- properties:
- preference:
- description:
- A node selector term, associated
- with the corresponding weight.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node selector
- term matches no objects. The requirements
- of them are ANDed. The TopologySelectorTerm
- type implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- type: array
- required:
- - nodeSelectorTerms
- type: object
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same node,
- zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node has pods which matches the corresponding
- podAffinityTerm; the node(s) with the highest
- sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- This field is beta-level and is
- only honored when PodAffinityNamespaceSelector
- feature is enabled.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace"
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to a pod
- label update), the system may or may not
- try to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces. This field
- is beta-level and is only honored
- when PodAffinityNamespaceSelector
- feature is enabled.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace"
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- anti-affinity expressions specified by this
- field, but it may choose a node that violates
- one or more of the expressions. The node
- that is most preferred is the one with the
- greatest sum of weights, i.e. for each node
- that meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- anti-affinity expressions, etc.), compute
- a sum by iterating through the elements
- of this field and adding "weight" to the
- sum if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- This field is beta-level and is
- only honored when PodAffinityNamespaceSelector
- feature is enabled.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace"
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the anti-affinity requirements
- specified by this field cease to be met
- at some point during pod execution (e.g.
- due to a pod label update), the system may
- or may not try to eventually evict the pod
- from its node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces. This field
- is beta-level and is only honored
- when PodAffinityNamespaceSelector
- feature is enabled.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace"
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of API server containers.
- If specified, this overrides the specified API server
- Deployment containers. If omitted, the API server
- Deployment will use its default values for its containers.
- items:
- description:
- APIServerDeploymentContainer is an
- API server Deployment container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the API server Deployment container by name.
- enum:
- - calico-apiserver
- - tigera-queryserver
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named API server Deployment
- container's resources. If omitted, the API
- server Deployment will use its default value
- for this container's resources. If used in
- conjunction with the deprecated ComponentResources,
- then this value takes precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- initContainers:
- description:
- InitContainers is a list of API server
- init containers. If specified, this overrides the
- specified API server Deployment init containers.
- If omitted, the API server Deployment will use its
- default values for its init containers.
- items:
- description:
- APIServerDeploymentInitContainer is
- an API server Deployment init container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the API server Deployment init container by
- name.
- enum:
- - calico-apiserver-certs-key-cert-provisioner
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named API server Deployment
- init container's resources. If omitted, the
- API server Deployment will use its default
- value for this init container's resources.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the API server pod's
- scheduling constraints. If specified, each of the
- key/value pairs are added to the API server Deployment
- nodeSelector provided the key does not already exist
- in the object's nodeSelector. If used in conjunction
- with ControlPlaneNodeSelector, that nodeSelector
- is set on the API server Deployment and each of
- this field's key/value pairs are added to the API
- server Deployment nodeSelector provided the key
- does not already exist in the object's nodeSelector.
- If omitted, the API server Deployment will use its
- default value for nodeSelector. WARNING: Please
- note that this field will modify the default API
- server Deployment nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the API server pod's
- tolerations. If specified, this overrides any tolerations
- that may be set on the API server Deployment. If
- omitted, the API server Deployment will use its
- default value for tolerations. WARNING: Please note
- that this field will override the default API server
- Deployment tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint effect
- to match. Empty means match all taint effects.
- When specified, allowed values are NoSchedule,
- PreferNoSchedule and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the toleration
- applies to. Empty means match all taint keys.
- If the key is empty, operator must be Exists;
- this combination means to match all values
- and all keys.
- type: string
- operator:
- description:
- Operator represents a key's relationship
- to the value. Valid operators are Exists and
- Equal. Defaults to Equal. Exists is equivalent
- to wildcard for value, so that a pod can tolerate
- all taints of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents the
- period of time the toleration (which must
- be of effect NoExecute, otherwise this field
- is ignored) tolerates the taint. By default,
- it is not set, which means tolerate the taint
- forever (do not evict). Zero and negative
- values will be treated as 0 (evict immediately)
- by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the toleration
- matches to. If the operator is Exists, the
- value should be empty, otherwise just a regular
- string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- type: object
- status:
- description: Most recently observed status for the Tigera API server.
- properties:
- state:
- description: State provides user-readable status.
- type: string
- type: object
- type: object
- served: true
- storage: true
- subresources:
- status: {}
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/operator.tigera.io_imagesets_crd.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- annotations:
- controller-gen.kubebuilder.io/version: v0.3.0
- name: imagesets.operator.tigera.io
-spec:
- group: operator.tigera.io
- names:
- kind: ImageSet
- listKind: ImageSetList
- plural: imagesets
- singular: imageset
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- description:
- ImageSet is used to specify image digests for the images that
- the operator deploys. The name of the ImageSet is expected to be in the
- format `<variant>-<release>`. The `variant` used is `enterprise` if the
- InstallationSpec Variant is `TigeraSecureEnterprise` otherwise it is `calico`.
- The `release` must match the version of the variant that the operator is
- built to deploy, this version can be obtained by passing the `--version`
- flag to the operator binary.
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description: ImageSetSpec defines the desired state of ImageSet.
- properties:
- images:
- description:
- Images is the list of images to use digests. All images
- that the operator will deploy must be specified.
- items:
- properties:
- digest:
- description:
- Digest is the image identifier that will be used
- for the Image. The field should not include a leading `@`
- and must be prefixed with `sha256:`.
- type: string
- image:
- description:
- Image is an image that the operator deploys and
- instead of using the built in tag the operator will use the
- Digest for the image identifier. The value should be the image
- name without registry or tag or digest. For the image `docker.io/calico/node:v3.17.1`
- it should be represented as `calico/node`
- type: string
- required:
- - digest
- - image
- type: object
- type: array
- type: object
- type: object
- served: true
- storage: true
- subresources:
- status: {}
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: crds/operator.tigera.io_installations_crd.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- annotations:
- controller-gen.kubebuilder.io/version: v0.11.3
- name: installations.operator.tigera.io
-spec:
- group: operator.tigera.io
- names:
- kind: Installation
- listKind: InstallationList
- plural: installations
- singular: installation
- scope: Cluster
- versions:
- - name: v1
- schema:
- openAPIV3Schema:
- description:
- Installation configures an installation of Calico or Calico Enterprise.
- At most one instance of this resource is supported. It must be named "default".
- The Installation API installs core networking and network policy components,
- and provides general install-time configuration.
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description:
- Specification of the desired state for the Calico or Calico
- Enterprise installation.
- properties:
- calicoKubeControllersDeployment:
- description:
- CalicoKubeControllersDeployment configures the calico-kube-controllers
- Deployment. If used in conjunction with the deprecated ComponentResources,
- then these overrides take precedence.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's metadata
- that is added to the Deployment.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to the
- object's annotations provided the key does not already exist
- in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values that
- may match replicaset and service selectors. Each of these
- key/value pairs are added to the object's labels provided
- the key does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description:
- Spec is the specification of the calico-kube-controllers
- Deployment.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of seconds
- for which a newly created Deployment pod should be ready
- without any of its container crashing, for it to be considered
- available. If specified, this overrides any minReadySeconds
- value that may be set on the calico-kube-controllers Deployment.
- If omitted, the calico-kube-controllers Deployment will
- use its default value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the calico-kube-controllers
- Deployment pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added
- to the object's annotations provided the key does
- not already exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors.
- Each of these key/value pairs are added to the object's
- labels provided the key does not already exist in
- the object's labels.
- type: object
- type: object
- spec:
- description:
- Spec is the calico-kube-controllers Deployment's
- PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity scheduling
- rules for the calico-kube-controllers pods. If specified,
- this overrides any affinity that may be set on the
- calico-kube-controllers Deployment. If omitted,
- the calico-kube-controllers Deployment will use
- its default value for affinity. WARNING: Please
- note that this field will override the default calico-kube-controllers
- Deployment affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node matches the corresponding matchExpressions;
- the node(s) with the highest sum are the
- most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null preferred
- scheduling term matches no objects (i.e.
- is also a no-op).
- properties:
- preference:
- description:
- A node selector term, associated
- with the corresponding weight.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node selector
- term matches no objects. The requirements
- of them are ANDed. The TopologySelectorTerm
- type implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same node,
- zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node has pods which matches the corresponding
- podAffinityTerm; the node(s) with the highest
- sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to a pod
- label update), the system may or may not
- try to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- anti-affinity expressions specified by this
- field, but it may choose a node that violates
- one or more of the expressions. The node
- that is most preferred is the one with the
- greatest sum of weights, i.e. for each node
- that meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- anti-affinity expressions, etc.), compute
- a sum by iterating through the elements
- of this field and adding "weight" to the
- sum if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the anti-affinity requirements
- specified by this field cease to be met
- at some point during pod execution (e.g.
- due to a pod label update), the system may
- or may not try to eventually evict the pod
- from its node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of calico-kube-controllers
- containers. If specified, this overrides the specified
- calico-kube-controllers Deployment containers. If
- omitted, the calico-kube-controllers Deployment
- will use its default values for its containers.
- items:
- description:
- CalicoKubeControllersDeploymentContainer
- is a calico-kube-controllers Deployment container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the calico-kube-controllers Deployment container
- by name.
- enum:
- - calico-kube-controllers
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named calico-kube-controllers
- Deployment container's resources. If omitted,
- the calico-kube-controllers Deployment will
- use its default value for this container's
- resources. If used in conjunction with the
- deprecated ComponentResources, then this value
- takes precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the calico-kube-controllers
- pod's scheduling constraints. If specified, each
- of the key/value pairs are added to the calico-kube-controllers
- Deployment nodeSelector provided the key does not
- already exist in the object's nodeSelector. If
- used in conjunction with ControlPlaneNodeSelector,
- that nodeSelector is set on the calico-kube-controllers
- Deployment and each of this field's key/value pairs
- are added to the calico-kube-controllers Deployment
- nodeSelector provided the key does not already exist
- in the object's nodeSelector. If omitted, the calico-kube-controllers
- Deployment will use its default value for nodeSelector.
- WARNING: Please note that this field will modify
- the default calico-kube-controllers Deployment nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the calico-kube-controllers
- pod's tolerations. If specified, this overrides
- any tolerations that may be set on the calico-kube-controllers
- Deployment. If omitted, the calico-kube-controllers
- Deployment will use its default value for tolerations.
- WARNING: Please note that this field will override
- the default calico-kube-controllers Deployment tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint effect
- to match. Empty means match all taint effects.
- When specified, allowed values are NoSchedule,
- PreferNoSchedule and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the toleration
- applies to. Empty means match all taint keys.
- If the key is empty, operator must be Exists;
- this combination means to match all values
- and all keys.
- type: string
- operator:
- description:
- Operator represents a key's relationship
- to the value. Valid operators are Exists and
- Equal. Defaults to Equal. Exists is equivalent
- to wildcard for value, so that a pod can tolerate
- all taints of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents the
- period of time the toleration (which must
- be of effect NoExecute, otherwise this field
- is ignored) tolerates the taint. By default,
- it is not set, which means tolerate the taint
- forever (do not evict). Zero and negative
- values will be treated as 0 (evict immediately)
- by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the toleration
- matches to. If the operator is Exists, the
- value should be empty, otherwise just a regular
- string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- calicoNetwork:
- description:
- CalicoNetwork specifies networking configuration options
- for Calico.
- properties:
- bgp:
- description:
- BGP configures whether or not to enable Calico's
- BGP capabilities.
- enum:
- - Enabled
- - Disabled
- type: string
- containerIPForwarding:
- description:
- "ContainerIPForwarding configures whether ip forwarding
- will be enabled for containers in the CNI configuration. Default:
- Disabled"
- enum:
- - Enabled
- - Disabled
- type: string
- hostPorts:
- description:
- "HostPorts configures whether or not Calico will
- support Kubernetes HostPorts. Valid only when using the Calico
- CNI plugin. Default: Enabled"
- enum:
- - Enabled
- - Disabled
- type: string
- ipPools:
- description:
- IPPools contains a list of IP pools to create if
- none exist. At most one IP pool of each address family may be
- specified. If omitted, a single pool will be configured if needed.
- items:
- properties:
- blockSize:
- description:
- "BlockSize specifies the CIDR prefex length
- to use when allocating per-node IP blocks from the main
- IP pool CIDR. Default: 26 (IPv4), 122 (IPv6)"
- format: int32
- type: integer
- cidr:
- description:
- CIDR contains the address range for the IP
- Pool in classless inter-domain routing format.
- type: string
- disableBGPExport:
- default: false
- description:
- "DisableBGPExport specifies whether routes
- from this IP pool's CIDR are exported over BGP. Default:
- false"
- type: boolean
- encapsulation:
- description:
- "Encapsulation specifies the encapsulation
- type that will be used with the IP Pool. Default: IPIP"
- enum:
- - IPIPCrossSubnet
- - IPIP
- - VXLAN
- - VXLANCrossSubnet
- - None
- type: string
- natOutgoing:
- description:
- "NATOutgoing specifies if NAT will be enabled
- or disabled for outgoing traffic. Default: Enabled"
- enum:
- - Enabled
- - Disabled
- type: string
- nodeSelector:
- description:
- "NodeSelector specifies the node selector that
- will be set for the IP Pool. Default: 'all()'"
- type: string
- required:
- - cidr
- type: object
- type: array
- linuxDataplane:
- description:
- "LinuxDataplane is used to select the dataplane used
- for Linux nodes. In particular, it causes the operator to add
- required mounts and environment variables for the particular
- dataplane. If not specified, iptables mode is used. Default:
- Iptables"
- enum:
- - Iptables
- - BPF
- - VPP
- type: string
- mtu:
- description:
- MTU specifies the maximum transmission unit to use
- on the pod network. If not specified, Calico will perform MTU
- auto-detection based on the cluster network.
- format: int32
- type: integer
- multiInterfaceMode:
- description:
- "MultiInterfaceMode configures what will configure
- multiple interface per pod. Only valid for Calico Enterprise
- installations using the Calico CNI plugin. Default: None"
- enum:
- - None
- - Multus
- type: string
- nodeAddressAutodetectionV4:
- description:
- NodeAddressAutodetectionV4 specifies an approach
- to automatically detect node IPv4 addresses. If not specified,
- will use default auto-detection settings to acquire an IPv4
- address for each node.
- properties:
- canReach:
- description:
- CanReach enables IP auto-detection based on which
- source address on the node is used to reach the specified
- IP or domain.
- type: string
- cidrs:
- description:
- CIDRS enables IP auto-detection based on which
- addresses on the nodes are within one of the provided CIDRs.
- items:
- type: string
- type: array
- firstFound:
- description:
- FirstFound uses default interface matching parameters
- to select an interface, performing best-effort filtering
- based on well-known interface names.
- type: boolean
- interface:
- description:
- Interface enables IP auto-detection based on
- interfaces that match the given regex.
- type: string
- kubernetes:
- description:
- Kubernetes configures Calico to detect node addresses
- based on the Kubernetes API.
- enum:
- - NodeInternalIP
- type: string
- skipInterface:
- description:
- SkipInterface enables IP auto-detection based
- on interfaces that do not match the given regex.
- type: string
- type: object
- nodeAddressAutodetectionV6:
- description:
- NodeAddressAutodetectionV6 specifies an approach
- to automatically detect node IPv6 addresses. If not specified,
- IPv6 addresses will not be auto-detected.
- properties:
- canReach:
- description:
- CanReach enables IP auto-detection based on which
- source address on the node is used to reach the specified
- IP or domain.
- type: string
- cidrs:
- description:
- CIDRS enables IP auto-detection based on which
- addresses on the nodes are within one of the provided CIDRs.
- items:
- type: string
- type: array
- firstFound:
- description:
- FirstFound uses default interface matching parameters
- to select an interface, performing best-effort filtering
- based on well-known interface names.
- type: boolean
- interface:
- description:
- Interface enables IP auto-detection based on
- interfaces that match the given regex.
- type: string
- kubernetes:
- description:
- Kubernetes configures Calico to detect node addresses
- based on the Kubernetes API.
- enum:
- - NodeInternalIP
- type: string
- skipInterface:
- description:
- SkipInterface enables IP auto-detection based
- on interfaces that do not match the given regex.
- type: string
- type: object
- type: object
- calicoNodeDaemonSet:
- description:
- CalicoNodeDaemonSet configures the calico-node DaemonSet.
- If used in conjunction with the deprecated ComponentResources, then
- these overrides take precedence.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's metadata
- that is added to the DaemonSet.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to the
- object's annotations provided the key does not already exist
- in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values that
- may match replicaset and service selectors. Each of these
- key/value pairs are added to the object's labels provided
- the key does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the specification of the calico-node DaemonSet.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of seconds
- for which a newly created DaemonSet pod should be ready
- without any of its container crashing, for it to be considered
- available. If specified, this overrides any minReadySeconds
- value that may be set on the calico-node DaemonSet. If omitted,
- the calico-node DaemonSet will use its default value for
- minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the calico-node DaemonSet
- pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added
- to the object's annotations provided the key does
- not already exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors.
- Each of these key/value pairs are added to the object's
- labels provided the key does not already exist in
- the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the calico-node DaemonSet's PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity scheduling
- rules for the calico-node pods. If specified, this
- overrides any affinity that may be set on the calico-node
- DaemonSet. If omitted, the calico-node DaemonSet
- will use its default value for affinity. WARNING:
- Please note that this field will override the default
- calico-node DaemonSet affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node matches the corresponding matchExpressions;
- the node(s) with the highest sum are the
- most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null preferred
- scheduling term matches no objects (i.e.
- is also a no-op).
- properties:
- preference:
- description:
- A node selector term, associated
- with the corresponding weight.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node selector
- term matches no objects. The requirements
- of them are ANDed. The TopologySelectorTerm
- type implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same node,
- zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node has pods which matches the corresponding
- podAffinityTerm; the node(s) with the highest
- sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to a pod
- label update), the system may or may not
- try to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- anti-affinity expressions specified by this
- field, but it may choose a node that violates
- one or more of the expressions. The node
- that is most preferred is the one with the
- greatest sum of weights, i.e. for each node
- that meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- anti-affinity expressions, etc.), compute
- a sum by iterating through the elements
- of this field and adding "weight" to the
- sum if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the anti-affinity requirements
- specified by this field cease to be met
- at some point during pod execution (e.g.
- due to a pod label update), the system may
- or may not try to eventually evict the pod
- from its node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of calico-node containers.
- If specified, this overrides the specified calico-node
- DaemonSet containers. If omitted, the calico-node
- DaemonSet will use its default values for its containers.
- items:
- description:
- CalicoNodeDaemonSetContainer is a calico-node
- DaemonSet container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the calico-node DaemonSet container by name.
- enum:
- - calico-node
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named calico-node DaemonSet
- container's resources. If omitted, the calico-node
- DaemonSet will use its default value for this
- container's resources. If used in conjunction
- with the deprecated ComponentResources, then
- this value takes precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- initContainers:
- description:
- InitContainers is a list of calico-node
- init containers. If specified, this overrides the
- specified calico-node DaemonSet init containers.
- If omitted, the calico-node DaemonSet will use its
- default values for its init containers.
- items:
- description:
- CalicoNodeDaemonSetInitContainer is
- a calico-node DaemonSet init container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the calico-node DaemonSet init container by
- name.
- enum:
- - install-cni
- - hostpath-init
- - flexvol-driver
- - mount-bpffs
- - node-certs-key-cert-provisioner
- - calico-node-prometheus-server-tls-key-cert-provisioner
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named calico-node DaemonSet
- init container's resources. If omitted, the
- calico-node DaemonSet will use its default
- value for this container's resources. If used
- in conjunction with the deprecated ComponentResources,
- then this value takes precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the calico-node pod's
- scheduling constraints. If specified, each of the
- key/value pairs are added to the calico-node DaemonSet
- nodeSelector provided the key does not already exist
- in the object's nodeSelector. If omitted, the calico-node
- DaemonSet will use its default value for nodeSelector.
- WARNING: Please note that this field will modify
- the default calico-node DaemonSet nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the calico-node pod's
- tolerations. If specified, this overrides any tolerations
- that may be set on the calico-node DaemonSet. If
- omitted, the calico-node DaemonSet will use its
- default value for tolerations. WARNING: Please note
- that this field will override the default calico-node
- DaemonSet tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint effect
- to match. Empty means match all taint effects.
- When specified, allowed values are NoSchedule,
- PreferNoSchedule and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the toleration
- applies to. Empty means match all taint keys.
- If the key is empty, operator must be Exists;
- this combination means to match all values
- and all keys.
- type: string
- operator:
- description:
- Operator represents a key's relationship
- to the value. Valid operators are Exists and
- Equal. Defaults to Equal. Exists is equivalent
- to wildcard for value, so that a pod can tolerate
- all taints of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents the
- period of time the toleration (which must
- be of effect NoExecute, otherwise this field
- is ignored) tolerates the taint. By default,
- it is not set, which means tolerate the taint
- forever (do not evict). Zero and negative
- values will be treated as 0 (evict immediately)
- by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the toleration
- matches to. If the operator is Exists, the
- value should be empty, otherwise just a regular
- string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- calicoWindowsUpgradeDaemonSet:
- description:
- CalicoWindowsUpgradeDaemonSet configures the calico-windows-upgrade
- DaemonSet.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's metadata
- that is added to the Deployment.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to the
- object's annotations provided the key does not already exist
- in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values that
- may match replicaset and service selectors. Each of these
- key/value pairs are added to the object's labels provided
- the key does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description:
- Spec is the specification of the calico-windows-upgrade
- DaemonSet.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of seconds
- for which a newly created Deployment pod should be ready
- without any of its container crashing, for it to be considered
- available. If specified, this overrides any minReadySeconds
- value that may be set on the calico-windows-upgrade DaemonSet.
- If omitted, the calico-windows-upgrade DaemonSet will use
- its default value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the calico-windows-upgrade
- DaemonSet pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added
- to the object's annotations provided the key does
- not already exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors.
- Each of these key/value pairs are added to the object's
- labels provided the key does not already exist in
- the object's labels.
- type: object
- type: object
- spec:
- description:
- Spec is the calico-windows-upgrade DaemonSet's
- PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity scheduling
- rules for the calico-windows-upgrade pods. If specified,
- this overrides any affinity that may be set on the
- calico-windows-upgrade DaemonSet. If omitted, the
- calico-windows-upgrade DaemonSet will use its default
- value for affinity. WARNING: Please note that this
- field will override the default calico-windows-upgrade
- DaemonSet affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node matches the corresponding matchExpressions;
- the node(s) with the highest sum are the
- most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null preferred
- scheduling term matches no objects (i.e.
- is also a no-op).
- properties:
- preference:
- description:
- A node selector term, associated
- with the corresponding weight.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node selector
- term matches no objects. The requirements
- of them are ANDed. The TopologySelectorTerm
- type implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same node,
- zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node has pods which matches the corresponding
- podAffinityTerm; the node(s) with the highest
- sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to a pod
- label update), the system may or may not
- try to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- anti-affinity expressions specified by this
- field, but it may choose a node that violates
- one or more of the expressions. The node
- that is most preferred is the one with the
- greatest sum of weights, i.e. for each node
- that meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- anti-affinity expressions, etc.), compute
- a sum by iterating through the elements
- of this field and adding "weight" to the
- sum if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the anti-affinity requirements
- specified by this field cease to be met
- at some point during pod execution (e.g.
- due to a pod label update), the system may
- or may not try to eventually evict the pod
- from its node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of calico-windows-upgrade
- containers. If specified, this overrides the specified
- calico-windows-upgrade DaemonSet containers. If
- omitted, the calico-windows-upgrade DaemonSet will
- use its default values for its containers.
- items:
- description:
- CalicoWindowsUpgradeDaemonSetContainer
- is a calico-windows-upgrade DaemonSet container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the calico-windows-upgrade DaemonSet container
- by name.
- enum:
- - calico-windows-upgrade
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named calico-windows-upgrade
- DaemonSet container's resources. If omitted,
- the calico-windows-upgrade DaemonSet will
- use its default value for this container's
- resources.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the calico-windows-upgrade
- pod's scheduling constraints. If specified, each
- of the key/value pairs are added to the calico-windows-upgrade
- DaemonSet nodeSelector provided the key does not
- already exist in the object's nodeSelector. If
- omitted, the calico-windows-upgrade DaemonSet will
- use its default value for nodeSelector. WARNING:
- Please note that this field will modify the default
- calico-windows-upgrade DaemonSet nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the calico-windows-upgrade
- pod's tolerations. If specified, this overrides
- any tolerations that may be set on the calico-windows-upgrade
- DaemonSet. If omitted, the calico-windows-upgrade
- DaemonSet will use its default value for tolerations.
- WARNING: Please note that this field will override
- the default calico-windows-upgrade DaemonSet tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint effect
- to match. Empty means match all taint effects.
- When specified, allowed values are NoSchedule,
- PreferNoSchedule and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the toleration
- applies to. Empty means match all taint keys.
- If the key is empty, operator must be Exists;
- this combination means to match all values
- and all keys.
- type: string
- operator:
- description:
- Operator represents a key's relationship
- to the value. Valid operators are Exists and
- Equal. Defaults to Equal. Exists is equivalent
- to wildcard for value, so that a pod can tolerate
- all taints of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents the
- period of time the toleration (which must
- be of effect NoExecute, otherwise this field
- is ignored) tolerates the taint. By default,
- it is not set, which means tolerate the taint
- forever (do not evict). Zero and negative
- values will be treated as 0 (evict immediately)
- by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the toleration
- matches to. If the operator is Exists, the
- value should be empty, otherwise just a regular
- string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- certificateManagement:
- description:
- CertificateManagement configures pods to submit a CertificateSigningRequest
- to the certificates.k8s.io/v1beta1 API in order to obtain TLS certificates.
- This feature requires that you bring your own CSR signing and approval
- process, otherwise pods will be stuck during initialization.
- properties:
- caCert:
- description:
- Certificate of the authority that signs the CertificateSigningRequests
- in PEM format.
- format: byte
- type: string
- keyAlgorithm:
- description:
- "Specify the algorithm used by pods to generate a
- key pair that is associated with the X.509 certificate request.
- Default: RSAWithSize2048"
- enum:
- - ""
- - RSAWithSize2048
- - RSAWithSize4096
- - RSAWithSize8192
- - ECDSAWithCurve256
- - ECDSAWithCurve384
- - ECDSAWithCurve521
- type: string
- signatureAlgorithm:
- description:
- "Specify the algorithm used for the signature of
- the X.509 certificate request. Default: SHA256WithRSA"
- enum:
- - ""
- - SHA256WithRSA
- - SHA384WithRSA
- - SHA512WithRSA
- - ECDSAWithSHA256
- - ECDSAWithSHA384
- - ECDSAWithSHA512
- type: string
- signerName:
- description:
- "When a CSR is issued to the certificates.k8s.io
- API, the signerName is added to the request in order to accommodate
- for clusters with multiple signers. Must be formatted as: `<my-domain>/<my-signername>`."
- type: string
- required:
- - caCert
- - signerName
- type: object
- cni:
- description: CNI specifies the CNI that will be used by this installation.
- properties:
- ipam:
- description:
- IPAM specifies the pod IP address management that
- will be used in the Calico or Calico Enterprise installation.
- properties:
- type:
- description:
- "Specifies the IPAM plugin that will be used
- in the Calico or Calico Enterprise installation. * For CNI
- Plugin Calico, this field defaults to Calico. * For CNI
- Plugin GKE, this field defaults to HostLocal. * For CNI
- Plugin AzureVNET, this field defaults to AzureVNET. * For
- CNI Plugin AmazonVPC, this field defaults to AmazonVPC.
- \n The IPAM plugin is installed and configured only if the
- CNI plugin is set to Calico, for all other values of the
- CNI plugin the plugin binaries and CNI config is a dependency
- that is expected to be installed separately. \n Default:
- Calico"
- enum:
- - Calico
- - HostLocal
- - AmazonVPC
- - AzureVNET
- type: string
- required:
- - type
- type: object
- type:
- description:
- "Specifies the CNI plugin that will be used in the
- Calico or Calico Enterprise installation. * For KubernetesProvider
- GKE, this field defaults to GKE. * For KubernetesProvider AKS,
- this field defaults to AzureVNET. * For KubernetesProvider EKS,
- this field defaults to AmazonVPC. * If aws-node daemonset exists
- in kube-system when the Installation resource is created, this
- field defaults to AmazonVPC. * For all other cases this field
- defaults to Calico. \n For the value Calico, the CNI plugin
- binaries and CNI config will be installed as part of deployment,
- for all other values the CNI plugin binaries and CNI config
- is a dependency that is expected to be installed separately.
- \n Default: Calico"
- enum:
- - Calico
- - GKE
- - AmazonVPC
- - AzureVNET
- type: string
- required:
- - type
- type: object
- componentResources:
- description:
- Deprecated. Please use CalicoNodeDaemonSet, TyphaDeployment,
- and KubeControllersDeployment. ComponentResources can be used to
- customize the resource requirements for each component. Node, Typha,
- and KubeControllers are supported for installations.
- items:
- description:
- Deprecated. Please use component resource config fields
- in Installation.Spec instead. The ComponentResource struct associates
- a ResourceRequirements with a component by name
- properties:
- componentName:
- description: ComponentName is an enum which identifies the component
- enum:
- - Node
- - Typha
- - KubeControllers
- type: string
- resourceRequirements:
- description:
- ResourceRequirements allows customization of limits
- and requests for compute resources such as cpu and memory.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum amount of compute
- resources allowed. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum amount of compute
- resources required. If Requests is omitted for a container,
- it defaults to Limits if that is explicitly specified,
- otherwise to an implementation-defined value. More info:
- https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - componentName
- - resourceRequirements
- type: object
- type: array
- controlPlaneNodeSelector:
- additionalProperties:
- type: string
- description:
- ControlPlaneNodeSelector is used to select control plane
- nodes on which to run Calico components. This is globally applied
- to all resources created by the operator excluding daemonsets.
- type: object
- controlPlaneReplicas:
- description:
- ControlPlaneReplicas defines how many replicas of the
- control plane core components will be deployed. This field applies
- to all control plane components that support High Availability.
- Defaults to 2.
- format: int32
- type: integer
- controlPlaneTolerations:
- description:
- ControlPlaneTolerations specify tolerations which are
- then globally applied to all resources created by the operator.
- items:
- description:
- The pod this Toleration is attached to tolerates any
- taint that matches the triple <key,value,effect> using the matching
- operator <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint effect to match. Empty
- means match all taint effects. When specified, allowed values
- are NoSchedule, PreferNoSchedule and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the toleration applies
- to. Empty means match all taint keys. If the key is empty,
- operator must be Exists; this combination means to match all
- values and all keys.
- type: string
- operator:
- description:
- Operator represents a key's relationship to the
- value. Valid operators are Exists and Equal. Defaults to Equal.
- Exists is equivalent to wildcard for value, so that a pod
- can tolerate all taints of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents the period of time
- the toleration (which must be of effect NoExecute, otherwise
- this field is ignored) tolerates the taint. By default, it
- is not set, which means tolerate the taint forever (do not
- evict). Zero and negative values will be treated as 0 (evict
- immediately) by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the toleration matches
- to. If the operator is Exists, the value should be empty,
- otherwise just a regular string.
- type: string
- type: object
- type: array
- csiNodeDriverDaemonSet:
- description:
- CSINodeDriverDaemonSet configures the csi-node-driver
- DaemonSet.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's metadata
- that is added to the DaemonSet.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to the
- object's annotations provided the key does not already exist
- in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values that
- may match replicaset and service selectors. Each of these
- key/value pairs are added to the object's labels provided
- the key does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description:
- Spec is the specification of the csi-node-driver
- DaemonSet.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of seconds
- for which a newly created DaemonSet pod should be ready
- without any of its container crashing, for it to be considered
- available. If specified, this overrides any minReadySeconds
- value that may be set on the csi-node-driver DaemonSet.
- If omitted, the csi-node-driver DaemonSet will use its default
- value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the csi-node-driver DaemonSet
- pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added
- to the object's annotations provided the key does
- not already exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors.
- Each of these key/value pairs are added to the object's
- labels provided the key does not already exist in
- the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the csi-node-driver DaemonSet's PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity scheduling
- rules for the csi-node-driver pods. If specified,
- this overrides any affinity that may be set on the
- csi-node-driver DaemonSet. If omitted, the csi-node-driver
- DaemonSet will use its default value for affinity.
- WARNING: Please note that this field will override
- the default csi-node-driver DaemonSet affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node matches the corresponding matchExpressions;
- the node(s) with the highest sum are the
- most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null preferred
- scheduling term matches no objects (i.e.
- is also a no-op).
- properties:
- preference:
- description:
- A node selector term, associated
- with the corresponding weight.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node selector
- term matches no objects. The requirements
- of them are ANDed. The TopologySelectorTerm
- type implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same node,
- zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node has pods which matches the corresponding
- podAffinityTerm; the node(s) with the highest
- sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to a pod
- label update), the system may or may not
- try to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- anti-affinity expressions specified by this
- field, but it may choose a node that violates
- one or more of the expressions. The node
- that is most preferred is the one with the
- greatest sum of weights, i.e. for each node
- that meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- anti-affinity expressions, etc.), compute
- a sum by iterating through the elements
- of this field and adding "weight" to the
- sum if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the anti-affinity requirements
- specified by this field cease to be met
- at some point during pod execution (e.g.
- due to a pod label update), the system may
- or may not try to eventually evict the pod
- from its node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of csi-node-driver
- containers. If specified, this overrides the specified
- csi-node-driver DaemonSet containers. If omitted,
- the csi-node-driver DaemonSet will use its default
- values for its containers.
- items:
- description:
- CSINodeDriverDaemonSetContainer is
- a csi-node-driver DaemonSet container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the csi-node-driver DaemonSet container by
- name.
- enum:
- - csi-node-driver
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named csi-node-driver DaemonSet
- container's resources. If omitted, the csi-node-driver
- DaemonSet will use its default value for this
- container's resources.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the csi-node-driver
- pod's scheduling constraints. If specified, each
- of the key/value pairs are added to the csi-node-driver
- DaemonSet nodeSelector provided the key does not
- already exist in the object's nodeSelector. If
- omitted, the csi-node-driver DaemonSet will use
- its default value for nodeSelector. WARNING: Please
- note that this field will modify the default csi-node-driver
- DaemonSet nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the csi-node-driver pod's
- tolerations. If specified, this overrides any tolerations
- that may be set on the csi-node-driver DaemonSet.
- If omitted, the csi-node-driver DaemonSet will use
- its default value for tolerations. WARNING: Please
- note that this field will override the default csi-node-driver
- DaemonSet tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint effect
- to match. Empty means match all taint effects.
- When specified, allowed values are NoSchedule,
- PreferNoSchedule and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the toleration
- applies to. Empty means match all taint keys.
- If the key is empty, operator must be Exists;
- this combination means to match all values
- and all keys.
- type: string
- operator:
- description:
- Operator represents a key's relationship
- to the value. Valid operators are Exists and
- Equal. Defaults to Equal. Exists is equivalent
- to wildcard for value, so that a pod can tolerate
- all taints of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents the
- period of time the toleration (which must
- be of effect NoExecute, otherwise this field
- is ignored) tolerates the taint. By default,
- it is not set, which means tolerate the taint
- forever (do not evict). Zero and negative
- values will be treated as 0 (evict immediately)
- by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the toleration
- matches to. If the operator is Exists, the
- value should be empty, otherwise just a regular
- string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- fipsMode:
- description:
- "FIPSMode uses images and features only that are using
- FIPS 140-2 validated cryptographic modules and standards. Default:
- Disabled"
- enum:
- - Enabled
- - Disabled
- type: string
- flexVolumePath:
- description:
- FlexVolumePath optionally specifies a custom path for
- FlexVolume. If not specified, FlexVolume will be enabled by default.
- If set to 'None', FlexVolume will be disabled. The default is based
- on the kubernetesProvider.
- type: string
- imagePath:
- description:
- "ImagePath allows for the path part of an image to be
- specified. If specified then the specified value will be used as
- the image path for each image. If not specified or empty, the default
- for each image will be used. A special case value, UseDefault, is
- supported to explicitly specify the default image path will be used
- for each image. \n Image format: `<registry><imagePath>/<imagePrefix><imageName>:<image-tag>`
- \n This option allows configuring the `<imagePath>` portion of the
- above format."
- type: string
- imagePrefix:
- description:
- "ImagePrefix allows for the prefix part of an image to
- be specified. If specified then the given value will be used as
- a prefix on each image. If not specified or empty, no prefix will
- be used. A special case value, UseDefault, is supported to explicitly
- specify the default image prefix will be used for each image. \n
- Image format: `<registry><imagePath>/<imagePrefix><imageName>:<image-tag>`
- \n This option allows configuring the `<imagePrefix>` portion of
- the above format."
- type: string
- imagePullSecrets:
- description:
- ImagePullSecrets is an array of references to container
- registry pull secrets to use. These are applied to all images to
- be pulled.
- items:
- description:
- LocalObjectReference contains enough information to
- let you locate the referenced object inside the same namespace.
- properties:
- name:
- description:
- "Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
- TODO: Add other useful fields. apiVersion, kind, uid?"
- type: string
- type: object
- x-kubernetes-map-type: atomic
- type: array
- kubeletVolumePluginPath:
- description:
- "KubeletVolumePluginPath optionally specifies enablement
- of Calico CSI plugin. If not specified, CSI will be enabled by default.
- If set to 'None', CSI will be disabled. Default: /var/lib/kubelet"
- type: string
- kubernetesProvider:
- description:
- KubernetesProvider specifies a particular provider of
- the Kubernetes platform and enables provider-specific configuration.
- If the specified value is empty, the Operator will attempt to automatically
- determine the current provider. If the specified value is not empty,
- the Operator will still attempt auto-detection, but will additionally
- compare the auto-detected value to the specified value to confirm
- they match.
- enum:
- - ""
- - EKS
- - GKE
- - AKS
- - OpenShift
- - DockerEnterprise
- - RKE2
- type: string
- logging:
- description: Logging Configuration for Components
- properties:
- cni:
- description: Customized logging specification for calico-cni plugin
- properties:
- logFileMaxAgeDays:
- description: "Default: 30 (days)"
- format: int32
- type: integer
- logFileMaxCount:
- description: "Default: 10"
- format: int32
- type: integer
- logFileMaxSize:
- anyOf:
- - type: integer
- - type: string
- description: "Default: 100Mi"
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- logSeverity:
- description: "Default: Info"
- enum:
- - Error
- - Warning
- - Debug
- - Info
- type: string
- type: object
- type: object
- nodeMetricsPort:
- description:
- NodeMetricsPort specifies which port calico/node serves
- prometheus metrics on. By default, metrics are not enabled. If specified,
- this overrides any FelixConfiguration resources which may exist.
- If omitted, then prometheus metrics may still be configured through
- FelixConfiguration.
- format: int32
- type: integer
- nodeUpdateStrategy:
- description:
- NodeUpdateStrategy can be used to customize the desired
- update strategy, such as the MaxUnavailable field.
- properties:
- rollingUpdate:
- description:
- 'Rolling update config params. Present only if type
- = "RollingUpdate". --- TODO: Update this to follow our convention
- for oneOf, whatever we decide it to be. Same as Deployment `strategy.rollingUpdate`.
- See https://github.com/kubernetes/kubernetes/issues/35345'
- properties:
- maxSurge:
- anyOf:
- - type: integer
- - type: string
- description:
- "The maximum number of nodes with an existing
- available DaemonSet pod that can have an updated DaemonSet
- pod during during an update. Value can be an absolute number
- (ex: 5) or a percentage of desired pods (ex: 10%). This
- can not be 0 if MaxUnavailable is 0. Absolute number is
- calculated from percentage by rounding up to a minimum of
- 1. Default value is 0. Example: when this is set to 30%,
- at most 30% of the total number of nodes that should be
- running the daemon pod (i.e. status.desiredNumberScheduled)
- can have their a new pod created before the old pod is marked
- as deleted. The update starts by launching new pods on 30%
- of nodes. Once an updated pod is available (Ready for at
- least minReadySeconds) the old DaemonSet pod on that node
- is marked deleted. If the old pod becomes unavailable for
- any reason (Ready transitions to false, is evicted, or is
- drained) an updated pod is immediatedly created on that
- node without considering surge limits. Allowing surge implies
- the possibility that the resources consumed by the daemonset
- on any given node can double if the readiness check fails,
- and so resource intensive daemonsets should take into account
- that they may cause evictions during disruption."
- x-kubernetes-int-or-string: true
- maxUnavailable:
- anyOf:
- - type: integer
- - type: string
- description:
- "The maximum number of DaemonSet pods that can
- be unavailable during the update. Value can be an absolute
- number (ex: 5) or a percentage of total number of DaemonSet
- pods at the start of the update (ex: 10%). Absolute number
- is calculated from percentage by rounding up. This cannot
- be 0 if MaxSurge is 0 Default value is 1. Example: when
- this is set to 30%, at most 30% of the total number of nodes
- that should be running the daemon pod (i.e. status.desiredNumberScheduled)
- can have their pods stopped for an update at any given time.
- The update starts by stopping at most 30% of those DaemonSet
- pods and then brings up new DaemonSet pods in their place.
- Once the new pods are available, it then proceeds onto other
- DaemonSet pods, thus ensuring that at least 70% of original
- number of DaemonSet pods are available at all times during
- the update."
- x-kubernetes-int-or-string: true
- type: object
- type:
- description:
- Type of daemon set update. Can be "RollingUpdate"
- or "OnDelete". Default is RollingUpdate.
- type: string
- type: object
- nonPrivileged:
- description:
- NonPrivileged configures Calico to be run in non-privileged
- containers as non-root users where possible.
- type: string
- registry:
- description:
- "Registry is the default Docker registry used for component
- Docker images. If specified then the given value must end with a
- slash character (`/`) and all images will be pulled from this registry.
- If not specified then the default registries will be used. A special
- case value, UseDefault, is supported to explicitly specify the default
- registries will be used. \n Image format: `<registry><imagePath>/<imagePrefix><imageName>:<image-tag>`
- \n This option allows configuring the `<registry>` portion of the
- above format."
- type: string
- typhaAffinity:
- description:
- Deprecated. Please use Installation.Spec.TyphaDeployment
- instead. TyphaAffinity allows configuration of node affinity characteristics
- for Typha pods.
- properties:
- nodeAffinity:
- description:
- NodeAffinity describes node affinity scheduling rules
- for typha.
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- description:
- The scheduler will prefer to schedule pods to
- nodes that satisfy the affinity expressions specified by
- this field, but it may choose a node that violates one or
- more of the expressions.
- items:
- description:
- An empty preferred scheduling term matches
- all objects with implicit weight 0 (i.e. it's a no-op).
- A null preferred scheduling term matches no objects (i.e.
- is also a no-op).
- properties:
- preference:
- description:
- A node selector term, associated with the
- corresponding weight.
- properties:
- matchExpressions:
- description:
- A list of node selector requirements
- by node's labels.
- items:
- description:
- A node selector requirement is a
- selector that contains values, a key, and an
- operator that relates the key and values.
- properties:
- key:
- description:
- The label key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents a key's relationship
- to a set of values. Valid operators are
- In, NotIn, Exists, DoesNotExist. Gt, and
- Lt.
- type: string
- values:
- description:
- An array of string values. If
- the operator is In or NotIn, the values
- array must be non-empty. If the operator
- is Exists or DoesNotExist, the values array
- must be empty. If the operator is Gt or
- Lt, the values array must have a single
- element, which will be interpreted as an
- integer. This array is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector requirements
- by node's fields.
- items:
- description:
- A node selector requirement is a
- selector that contains values, a key, and an
- operator that relates the key and values.
- properties:
- key:
- description:
- The label key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents a key's relationship
- to a set of values. Valid operators are
- In, NotIn, Exists, DoesNotExist. Gt, and
- Lt.
- type: string
- values:
- description:
- An array of string values. If
- the operator is In or NotIn, the values
- array must be non-empty. If the operator
- is Exists or DoesNotExist, the values array
- must be empty. If the operator is Gt or
- Lt, the values array must have a single
- element, which will be interpreted as an
- integer. This array is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with matching the corresponding
- nodeSelectorTerm, in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- requiredDuringSchedulingIgnoredDuringExecution:
- description:
- "WARNING: Please note that if the affinity requirements
- specified by this field are not met at scheduling time,
- the pod will NOT be scheduled onto the node. There is no
- fallback to another affinity rules with this setting. This
- may cause networking disruption or even catastrophic failure!
- PreferredDuringSchedulingIgnoredDuringExecution should be
- used for affinity unless there is a specific well understood
- reason to use RequiredDuringSchedulingIgnoredDuringExecution
- and you can guarantee that the RequiredDuringSchedulingIgnoredDuringExecution
- will always have sufficient nodes to satisfy the requirement.
- NOTE: RequiredDuringSchedulingIgnoredDuringExecution is
- set by default for AKS nodes, to avoid scheduling Typhas
- on virtual-nodes. If the affinity requirements specified
- by this field cease to be met at some point during pod execution
- (e.g. due to an update), the system may or may not try to
- eventually evict the pod from its node."
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node selector terms.
- The terms are ORed.
- items:
- description:
- A null or empty node selector term matches
- no objects. The requirements of them are ANDed. The
- TopologySelectorTerm type implements a subset of the
- NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node selector requirements
- by node's labels.
- items:
- description:
- A node selector requirement is a
- selector that contains values, a key, and an
- operator that relates the key and values.
- properties:
- key:
- description:
- The label key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents a key's relationship
- to a set of values. Valid operators are
- In, NotIn, Exists, DoesNotExist. Gt, and
- Lt.
- type: string
- values:
- description:
- An array of string values. If
- the operator is In or NotIn, the values
- array must be non-empty. If the operator
- is Exists or DoesNotExist, the values array
- must be empty. If the operator is Gt or
- Lt, the values array must have a single
- element, which will be interpreted as an
- integer. This array is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector requirements
- by node's fields.
- items:
- description:
- A node selector requirement is a
- selector that contains values, a key, and an
- operator that relates the key and values.
- properties:
- key:
- description:
- The label key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents a key's relationship
- to a set of values. Valid operators are
- In, NotIn, Exists, DoesNotExist. Gt, and
- Lt.
- type: string
- values:
- description:
- An array of string values. If
- the operator is In or NotIn, the values
- array must be non-empty. If the operator
- is Exists or DoesNotExist, the values array
- must be empty. If the operator is Gt or
- Lt, the values array must have a single
- element, which will be interpreted as an
- integer. This array is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- type: object
- typhaDeployment:
- description:
- TyphaDeployment configures the typha Deployment. If used
- in conjunction with the deprecated ComponentResources or TyphaAffinity,
- then these overrides take precedence.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's metadata
- that is added to the Deployment.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to the
- object's annotations provided the key does not already exist
- in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values that
- may match replicaset and service selectors. Each of these
- key/value pairs are added to the object's labels provided
- the key does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the specification of the typha Deployment.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of seconds
- for which a newly created Deployment pod should be ready
- without any of its container crashing, for it to be considered
- available. If specified, this overrides any minReadySeconds
- value that may be set on the typha Deployment. If omitted,
- the typha Deployment will use its default value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- strategy:
- description:
- The deployment strategy to use to replace existing
- pods with new ones.
- properties:
- rollingUpdate:
- description:
- Rolling update config params. Present only
- if DeploymentStrategyType = RollingUpdate. to be.
- properties:
- maxSurge:
- anyOf:
- - type: integer
- - type: string
- description:
- "The maximum number of pods that can
- be scheduled above the desired number of pods. Value
- can be an absolute number (ex: 5) or a percentage
- of desired pods (ex: 10%). This can not be 0 if
- MaxUnavailable is 0. Absolute number is calculated
- from percentage by rounding up. Defaults to 25%.
- Example: when this is set to 30%, the new ReplicaSet
- can be scaled up immediately when the rolling update
- starts, such that the total number of old and new
- pods do not exceed 130% of desired pods. Once old
- pods have been killed, new ReplicaSet can be scaled
- up further, ensuring that total number of pods running
- at any time during the update is at most 130% of
- desired pods."
- x-kubernetes-int-or-string: true
- maxUnavailable:
- anyOf:
- - type: integer
- - type: string
- description:
- "The maximum number of pods that can
- be unavailable during the update. Value can be an
- absolute number (ex: 5) or a percentage of desired
- pods (ex: 10%). Absolute number is calculated from
- percentage by rounding down. This can not be 0 if
- MaxSurge is 0. Defaults to 25%. Example: when this
- is set to 30%, the old ReplicaSet can be scaled
- down to 70% of desired pods immediately when the
- rolling update starts. Once new pods are ready,
- old ReplicaSet can be scaled down further, followed
- by scaling up the new ReplicaSet, ensuring that
- the total number of pods available at all times
- during the update is at least 70% of desired pods."
- x-kubernetes-int-or-string: true
- type: object
- type: object
- template:
- description:
- Template describes the typha Deployment pod that
- will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added
- to the object's annotations provided the key does
- not already exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors.
- Each of these key/value pairs are added to the object's
- labels provided the key does not already exist in
- the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the typha Deployment's PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity scheduling
- rules for the typha pods. If specified, this overrides
- any affinity that may be set on the typha Deployment.
- If omitted, the typha Deployment will use its default
- value for affinity. If used in conjunction with
- the deprecated TyphaAffinity, then this value takes
- precedence. WARNING: Please note that this field
- will override the default calico-typha Deployment
- affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node matches the corresponding matchExpressions;
- the node(s) with the highest sum are the
- most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null preferred
- scheduling term matches no objects (i.e.
- is also a no-op).
- properties:
- preference:
- description:
- A node selector term, associated
- with the corresponding weight.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node selector
- term matches no objects. The requirements
- of them are ANDed. The TopologySelectorTerm
- type implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node selector
- requirements by node's labels.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector
- requirements by node's fields.
- items:
- description:
- A node selector requirement
- is a selector that contains
- values, a key, and an operator
- that relates the key and values.
- properties:
- key:
- description:
- The label key
- that the selector applies
- to.
- type: string
- operator:
- description:
- Represents a
- key's relationship to a
- set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string
- values. If the operator
- is In or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the values
- array must be empty. If
- the operator is Gt or Lt,
- the values array must have
- a single element, which
- will be interpreted as an
- integer. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same node,
- zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- affinity expressions specified by this field,
- but it may choose a node that violates one
- or more of the expressions. The node that
- is most preferred is the one with the greatest
- sum of weights, i.e. for each node that
- meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- affinity expressions, etc.), compute a sum
- by iterating through the elements of this
- field and adding "weight" to the sum if
- the node has pods which matches the corresponding
- podAffinityTerm; the node(s) with the highest
- sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the affinity requirements specified
- by this field cease to be met at some point
- during pod execution (e.g. due to a pod
- label update), the system may or may not
- try to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer to
- schedule pods to nodes that satisfy the
- anti-affinity expressions specified by this
- field, but it may choose a node that violates
- one or more of the expressions. The node
- that is most preferred is the one with the
- greatest sum of weights, i.e. for each node
- that meets all of the scheduling requirements
- (resource request, requiredDuringScheduling
- anti-affinity expressions, etc.), compute
- a sum by iterating through the elements
- of this field and adding "weight" to the
- sum if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the matched
- WeightedPodAffinityTerm fields are added
- per-node to find the most preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met at scheduling
- time, the pod will not be scheduled onto
- the node. If the anti-affinity requirements
- specified by this field cease to be met
- at some point during pod execution (e.g.
- due to a pod label update), the system may
- or may not try to eventually evict the pod
- from its node. When there are multiple elements,
- the lists of nodes corresponding to each
- podAffinityTerm are intersected, i.e. all
- terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this pod
- should be co-located (affinity) or not
- co-located (anti-affinity) with, where
- co-located is defined as running on a
- node whose value of the label with key
- <topologyKey> matches that of any node
- on which a pod of the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over a set
- of resources, in this case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over the
- set of namespaces that the term applies
- to. The term is applied to the union
- of the namespaces selected by this
- field and the ones listed in the namespaces
- field. null selector and null or empty
- namespaces list means "this pod's
- namespace". An empty selector ({})
- matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions is
- a list of label selector requirements.
- The requirements are ANDed.
- items:
- description:
- A label selector
- requirement is a selector that
- contains values, a key, and
- an operator that relates the
- key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to
- a set of values. Valid operators
- are In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is an
- array of string values.
- If the operator is In or
- NotIn, the values array
- must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be
- empty. This array is replaced
- during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map
- of {key,value} pairs. A single
- {key,value} in the matchLabels
- map is equivalent to an element
- of matchExpressions, whose key
- field is "key", the operator is
- "In", and the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies a
- static list of namespace names that
- the term applies to. The term is applied
- to the union of the namespaces listed
- in this field and the ones selected
- by namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be co-located
- (affinity) or not co-located (anti-affinity)
- with the pods matching the labelSelector
- in the specified namespaces, where
- co-located is defined as running on
- a node whose value of the label with
- key topologyKey matches that of any
- node on which any of the selected
- pods is running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of typha containers.
- If specified, this overrides the specified typha
- Deployment containers. If omitted, the typha Deployment
- will use its default values for its containers.
- items:
- description:
- TyphaDeploymentContainer is a typha
- Deployment container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the typha Deployment container by name.
- enum:
- - calico-typha
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named typha Deployment container's
- resources. If omitted, the typha Deployment
- will use its default value for this container's
- resources. If used in conjunction with the
- deprecated ComponentResources, then this value
- takes precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- initContainers:
- description:
- InitContainers is a list of typha init
- containers. If specified, this overrides the specified
- typha Deployment init containers. If omitted, the
- typha Deployment will use its default values for
- its init containers.
- items:
- description:
- TyphaDeploymentInitContainer is a typha
- Deployment init container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the typha Deployment init container by name.
- enum:
- - typha-certs-key-cert-provisioner
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified, this
- overrides the named typha Deployment init
- container's resources. If omitted, the typha
- Deployment will use its default value for
- this init container's resources. If used in
- conjunction with the deprecated ComponentResources,
- then this value takes precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed. More
- info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum
- amount of compute resources required.
- If Requests is omitted for a container,
- it defaults to Limits if that is explicitly
- specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the calico-typha pod's
- scheduling constraints. If specified, each of the
- key/value pairs are added to the calico-typha Deployment
- nodeSelector provided the key does not already exist
- in the object's nodeSelector. If omitted, the calico-typha
- Deployment will use its default value for nodeSelector.
- WARNING: Please note that this field will modify
- the default calico-typha Deployment nodeSelector."
- type: object
- terminationGracePeriodSeconds:
- description:
- Optional duration in seconds the pod
- needs to terminate gracefully. May be decreased
- in delete request. Value must be non-negative integer.
- The value zero indicates stop immediately via the
- kill signal (no opportunity to shut down). If this
- value is nil, the default grace period will be used
- instead. The grace period is the duration in seconds
- after the processes running in the pod are sent
- a termination signal and the time when the processes
- are forcibly halted with a kill signal. Set this
- value longer than the expected cleanup time for
- your process. Defaults to 30 seconds.
- format: int64
- type: integer
- tolerations:
- description:
- "Tolerations is the typha pod's tolerations.
- If specified, this overrides any tolerations that
- may be set on the typha Deployment. If omitted,
- the typha Deployment will use its default value
- for tolerations. WARNING: Please note that this
- field will override the default calico-typha Deployment
- tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint effect
- to match. Empty means match all taint effects.
- When specified, allowed values are NoSchedule,
- PreferNoSchedule and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the toleration
- applies to. Empty means match all taint keys.
- If the key is empty, operator must be Exists;
- this combination means to match all values
- and all keys.
- type: string
- operator:
- description:
- Operator represents a key's relationship
- to the value. Valid operators are Exists and
- Equal. Defaults to Equal. Exists is equivalent
- to wildcard for value, so that a pod can tolerate
- all taints of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents the
- period of time the toleration (which must
- be of effect NoExecute, otherwise this field
- is ignored) tolerates the taint. By default,
- it is not set, which means tolerate the taint
- forever (do not evict). Zero and negative
- values will be treated as 0 (evict immediately)
- by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the toleration
- matches to. If the operator is Exists, the
- value should be empty, otherwise just a regular
- string.
- type: string
- type: object
- type: array
- topologySpreadConstraints:
- description:
- TopologySpreadConstraints describes how
- a group of pods ought to spread across topology
- domains. Scheduler will schedule pods in a way which
- abides by the constraints. All topologySpreadConstraints
- are ANDed.
- items:
- description:
- TopologySpreadConstraint specifies
- how to spread matching pods among the given topology.
- properties:
- labelSelector:
- description:
- LabelSelector is used to find matching
- pods. Pods that match this label selector
- are counted to determine the number of pods
- in their corresponding topology domain.
- properties:
- matchExpressions:
- description:
- matchExpressions is a list
- of label selector requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector requirement
- is a selector that contains values,
- a key, and an operator that relates
- the key and values.
- properties:
- key:
- description:
- key is the label key
- that the selector applies to.
- type: string
- operator:
- description:
- operator represents a
- key's relationship to a set of values.
- Valid operators are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values is an array of
- string values. If the operator is
- In or NotIn, the values array must
- be non-empty. If the operator is
- Exists or DoesNotExist, the values
- array must be empty. This array
- is replaced during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map of {key,value}
- pairs. A single {key,value} in the matchLabels
- map is equivalent to an element of matchExpressions,
- whose key field is "key", the operator
- is "In", and the values array contains
- only "value". The requirements are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- matchLabelKeys:
- description:
- MatchLabelKeys is a set of pod
- label keys to select the pods over which spreading
- will be calculated. The keys are used to lookup
- values from the incoming pod labels, those
- key-value labels are ANDed with labelSelector
- to select the group of existing pods over
- which spreading will be calculated for the
- incoming pod. Keys that don't exist in the
- incoming pod labels will be ignored. A null
- or empty list means only match against labelSelector.
- items:
- type: string
- type: array
- x-kubernetes-list-type: atomic
- maxSkew:
- description:
- "MaxSkew describes the degree to
- which pods may be unevenly distributed. When
- `whenUnsatisfiable=DoNotSchedule`, it is the
- maximum permitted difference between the number
- of matching pods in the target topology and
- the global minimum. The global minimum is
- the minimum number of matching pods in an
- eligible domain or zero if the number of eligible
- domains is less than MinDomains. For example,
- in a 3-zone cluster, MaxSkew is set to 1,
- and pods with the same labelSelector spread
- as 2/2/1: In this case, the global minimum
- is 1. | zone1 | zone2 | zone3 | | P P | P
- P | P | - if MaxSkew is 1, incoming pod
- can only be scheduled to zone3 to become 2/2/2;
- scheduling it onto zone1(zone2) would make
- the ActualSkew(3-1) on zone1(zone2) violate
- MaxSkew(1). - if MaxSkew is 2, incoming pod
- can be scheduled onto any zone. When `whenUnsatisfiable=ScheduleAnyway`,
- it is used to give higher precedence to topologies
- that satisfy it. It's a required field. Default
- value is 1 and 0 is not allowed."
- format: int32
- type: integer
- minDomains:
- description:
- "MinDomains indicates a minimum
- number of eligible domains. When the number
- of eligible domains with matching topology
- keys is less than minDomains, Pod Topology
- Spread treats \"global minimum\" as 0, and
- then the calculation of Skew is performed.
- And when the number of eligible domains with
- matching topology keys equals or greater than
- minDomains, this value has no effect on scheduling.
- As a result, when the number of eligible domains
- is less than minDomains, scheduler won't schedule
- more than maxSkew Pods to those domains. If
- value is nil, the constraint behaves as if
- MinDomains is equal to 1. Valid values are
- integers greater than 0. When value is not
- nil, WhenUnsatisfiable must be DoNotSchedule.
- \n For example, in a 3-zone cluster, MaxSkew
- is set to 2, MinDomains is set to 5 and pods
- with the same labelSelector spread as 2/2/2:
- | zone1 | zone2 | zone3 | | P P | P P |
- \ P P | The number of domains is less than
- 5(MinDomains), so \"global minimum\" is treated
- as 0. In this situation, new pod with the
- same labelSelector cannot be scheduled, because
- computed skew will be 3(3 - 0) if new Pod
- is scheduled to any of the three zones, it
- will violate MaxSkew. \n This is a beta field
- and requires the MinDomainsInPodTopologySpread
- feature gate to be enabled (enabled by default)."
- format: int32
- type: integer
- nodeAffinityPolicy:
- description:
- "NodeAffinityPolicy indicates how
- we will treat Pod's nodeAffinity/nodeSelector
- when calculating pod topology spread skew.
- Options are: - Honor: only nodes matching
- nodeAffinity/nodeSelector are included in
- the calculations. - Ignore: nodeAffinity/nodeSelector
- are ignored. All nodes are included in the
- calculations. \n If this value is nil, the
- behavior is equivalent to the Honor policy.
- This is a alpha-level feature enabled by the
- NodeInclusionPolicyInPodTopologySpread feature
- flag."
- type: string
- nodeTaintsPolicy:
- description:
- "NodeTaintsPolicy indicates how
- we will treat node taints when calculating
- pod topology spread skew. Options are: - Honor:
- nodes without taints, along with tainted nodes
- for which the incoming pod has a toleration,
- are included. - Ignore: node taints are ignored.
- All nodes are included. \n If this value is
- nil, the behavior is equivalent to the Ignore
- policy. This is a alpha-level feature enabled
- by the NodeInclusionPolicyInPodTopologySpread
- feature flag."
- type: string
- topologyKey:
- description:
- TopologyKey is the key of node
- labels. Nodes that have a label with this
- key and identical values are considered to
- be in the same topology. We consider each
- <key, value> as a "bucket", and try to put
- balanced number of pods into each bucket.
- We define a domain as a particular instance
- of a topology. Also, we define an eligible
- domain as a domain whose nodes meet the requirements
- of nodeAffinityPolicy and nodeTaintsPolicy.
- e.g. If TopologyKey is "kubernetes.io/hostname",
- each Node is a domain of that topology. And,
- if TopologyKey is "topology.kubernetes.io/zone",
- each zone is a domain of that topology. It's
- a required field.
- type: string
- whenUnsatisfiable:
- description:
- 'WhenUnsatisfiable indicates how
- to deal with a pod if it doesn''t satisfy
- the spread constraint. - DoNotSchedule (default)
- tells the scheduler not to schedule it. -
- ScheduleAnyway tells the scheduler to schedule
- the pod in any location, but giving higher
- precedence to topologies that would help reduce
- the skew. A constraint is considered "Unsatisfiable"
- for an incoming pod if and only if every possible
- node assignment for that pod would violate
- "MaxSkew" on some topology. For example, in
- a 3-zone cluster, MaxSkew is set to 1, and
- pods with the same labelSelector spread as
- 3/1/1: | zone1 | zone2 | zone3 | | P P P | P | P |
- If WhenUnsatisfiable is set to DoNotSchedule,
- incoming pod can only be scheduled to zone2(zone3)
- to become 3/2/1(3/1/2) as ActualSkew(2-1)
- on zone2(zone3) satisfies MaxSkew(1). In other
- words, the cluster can still be imbalanced,
- but scheduler won''t make it *more* imbalanced.
- It''s a required field.'
- type: string
- required:
- - maxSkew
- - topologyKey
- - whenUnsatisfiable
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- typhaMetricsPort:
- description:
- TyphaMetricsPort specifies which port calico/typha serves
- prometheus metrics on. By default, metrics are not enabled.
- format: int32
- type: integer
- variant:
- description:
- "Variant is the product to install - one of Calico or
- TigeraSecureEnterprise Default: Calico"
- enum:
- - Calico
- - TigeraSecureEnterprise
- type: string
- type: object
- status:
- description:
- Most recently observed state for the Calico or Calico Enterprise
- installation.
- properties:
- calicoVersion:
- description:
- CalicoVersion shows the current running version of calico.
- CalicoVersion along with Variant is needed to know the exact version
- deployed.
- type: string
- computed:
- description:
- Computed is the final installation including overlaid
- resources.
- properties:
- calicoKubeControllersDeployment:
- description:
- CalicoKubeControllersDeployment configures the calico-kube-controllers
- Deployment. If used in conjunction with the deprecated ComponentResources,
- then these overrides take precedence.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the Deployment.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to
- the object's annotations provided the key does not already
- exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors. Each
- of these key/value pairs are added to the object's labels
- provided the key does not already exist in the object's
- labels.
- type: object
- type: object
- spec:
- description:
- Spec is the specification of the calico-kube-controllers
- Deployment.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of
- seconds for which a newly created Deployment pod should
- be ready without any of its container crashing, for
- it to be considered available. If specified, this overrides
- any minReadySeconds value that may be set on the calico-kube-controllers
- Deployment. If omitted, the calico-kube-controllers
- Deployment will use its default value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the calico-kube-controllers
- Deployment pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes
- object's metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary
- non-identifying metadata. Each of these key/value
- pairs are added to the object's annotations
- provided the key does not already exist in the
- object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and
- values that may match replicaset and service
- selectors. Each of these key/value pairs are
- added to the object's labels provided the key
- does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description:
- Spec is the calico-kube-controllers Deployment's
- PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity
- scheduling rules for the calico-kube-controllers
- pods. If specified, this overrides any affinity
- that may be set on the calico-kube-controllers
- Deployment. If omitted, the calico-kube-controllers
- Deployment will use its default value for affinity.
- WARNING: Please note that this field will override
- the default calico-kube-controllers Deployment
- affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node matches the corresponding
- matchExpressions; the node(s) with the
- highest sum are the most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null
- preferred scheduling term matches
- no objects (i.e. is also a no-op).
- properties:
- preference:
- description:
- A node selector term,
- associated with the corresponding
- weight.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node
- selector term matches no objects.
- The requirements of them are ANDed.
- The TopologySelectorTerm type
- implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the
- same node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the anti-affinity expressions specified
- by this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling anti-affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the anti-affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of calico-kube-controllers
- containers. If specified, this overrides the
- specified calico-kube-controllers Deployment
- containers. If omitted, the calico-kube-controllers
- Deployment will use its default values for its
- containers.
- items:
- description:
- CalicoKubeControllersDeploymentContainer
- is a calico-kube-controllers Deployment container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the calico-kube-controllers Deployment
- container by name.
- enum:
- - calico-kube-controllers
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified,
- this overrides the named calico-kube-controllers
- Deployment container's resources. If omitted,
- the calico-kube-controllers Deployment
- will use its default value for this container's
- resources. If used in conjunction with
- the deprecated ComponentResources, then
- this value takes precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the
- minimum amount of compute resources
- required. If Requests is omitted for
- a container, it defaults to Limits
- if that is explicitly specified, otherwise
- to an implementation-defined value.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the calico-kube-controllers
- pod's scheduling constraints. If specified,
- each of the key/value pairs are added to the
- calico-kube-controllers Deployment nodeSelector
- provided the key does not already exist in the
- object's nodeSelector. If used in conjunction
- with ControlPlaneNodeSelector, that nodeSelector
- is set on the calico-kube-controllers Deployment
- and each of this field's key/value pairs are
- added to the calico-kube-controllers Deployment
- nodeSelector provided the key does not already
- exist in the object's nodeSelector. If omitted,
- the calico-kube-controllers Deployment will
- use its default value for nodeSelector. WARNING:
- Please note that this field will modify the
- default calico-kube-controllers Deployment nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the calico-kube-controllers
- pod's tolerations. If specified, this overrides
- any tolerations that may be set on the calico-kube-controllers
- Deployment. If omitted, the calico-kube-controllers
- Deployment will use its default value for tolerations.
- WARNING: Please note that this field will override
- the default calico-kube-controllers Deployment
- tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint
- effect to match. Empty means match all
- taint effects. When specified, allowed
- values are NoSchedule, PreferNoSchedule
- and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the
- toleration applies to. Empty means match
- all taint keys. If the key is empty, operator
- must be Exists; this combination means
- to match all values and all keys.
- type: string
- operator:
- description:
- Operator represents a key's
- relationship to the value. Valid operators
- are Exists and Equal. Defaults to Equal.
- Exists is equivalent to wildcard for value,
- so that a pod can tolerate all taints
- of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents
- the period of time the toleration (which
- must be of effect NoExecute, otherwise
- this field is ignored) tolerates the taint.
- By default, it is not set, which means
- tolerate the taint forever (do not evict).
- Zero and negative values will be treated
- as 0 (evict immediately) by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the
- toleration matches to. If the operator
- is Exists, the value should be empty,
- otherwise just a regular string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- calicoNetwork:
- description:
- CalicoNetwork specifies networking configuration
- options for Calico.
- properties:
- bgp:
- description:
- BGP configures whether or not to enable Calico's
- BGP capabilities.
- enum:
- - Enabled
- - Disabled
- type: string
- containerIPForwarding:
- description:
- "ContainerIPForwarding configures whether ip
- forwarding will be enabled for containers in the CNI configuration.
- Default: Disabled"
- enum:
- - Enabled
- - Disabled
- type: string
- hostPorts:
- description:
- "HostPorts configures whether or not Calico will
- support Kubernetes HostPorts. Valid only when using the
- Calico CNI plugin. Default: Enabled"
- enum:
- - Enabled
- - Disabled
- type: string
- ipPools:
- description:
- IPPools contains a list of IP pools to create
- if none exist. At most one IP pool of each address family
- may be specified. If omitted, a single pool will be configured
- if needed.
- items:
- properties:
- blockSize:
- description:
- "BlockSize specifies the CIDR prefex length
- to use when allocating per-node IP blocks from the
- main IP pool CIDR. Default: 26 (IPv4), 122 (IPv6)"
- format: int32
- type: integer
- cidr:
- description:
- CIDR contains the address range for the
- IP Pool in classless inter-domain routing format.
- type: string
- disableBGPExport:
- default: false
- description:
- "DisableBGPExport specifies whether routes
- from this IP pool's CIDR are exported over BGP. Default:
- false"
- type: boolean
- encapsulation:
- description:
- "Encapsulation specifies the encapsulation
- type that will be used with the IP Pool. Default:
- IPIP"
- enum:
- - IPIPCrossSubnet
- - IPIP
- - VXLAN
- - VXLANCrossSubnet
- - None
- type: string
- natOutgoing:
- description:
- "NATOutgoing specifies if NAT will be enabled
- or disabled for outgoing traffic. Default: Enabled"
- enum:
- - Enabled
- - Disabled
- type: string
- nodeSelector:
- description:
- "NodeSelector specifies the node selector
- that will be set for the IP Pool. Default: 'all()'"
- type: string
- required:
- - cidr
- type: object
- type: array
- linuxDataplane:
- description:
- "LinuxDataplane is used to select the dataplane
- used for Linux nodes. In particular, it causes the operator
- to add required mounts and environment variables for the
- particular dataplane. If not specified, iptables mode is
- used. Default: Iptables"
- enum:
- - Iptables
- - BPF
- - VPP
- type: string
- mtu:
- description:
- MTU specifies the maximum transmission unit to
- use on the pod network. If not specified, Calico will perform
- MTU auto-detection based on the cluster network.
- format: int32
- type: integer
- multiInterfaceMode:
- description:
- "MultiInterfaceMode configures what will configure
- multiple interface per pod. Only valid for Calico Enterprise
- installations using the Calico CNI plugin. Default: None"
- enum:
- - None
- - Multus
- type: string
- nodeAddressAutodetectionV4:
- description:
- NodeAddressAutodetectionV4 specifies an approach
- to automatically detect node IPv4 addresses. If not specified,
- will use default auto-detection settings to acquire an IPv4
- address for each node.
- properties:
- canReach:
- description:
- CanReach enables IP auto-detection based
- on which source address on the node is used to reach
- the specified IP or domain.
- type: string
- cidrs:
- description:
- CIDRS enables IP auto-detection based on
- which addresses on the nodes are within one of the provided
- CIDRs.
- items:
- type: string
- type: array
- firstFound:
- description:
- FirstFound uses default interface matching
- parameters to select an interface, performing best-effort
- filtering based on well-known interface names.
- type: boolean
- interface:
- description:
- Interface enables IP auto-detection based
- on interfaces that match the given regex.
- type: string
- kubernetes:
- description:
- Kubernetes configures Calico to detect node
- addresses based on the Kubernetes API.
- enum:
- - NodeInternalIP
- type: string
- skipInterface:
- description:
- SkipInterface enables IP auto-detection based
- on interfaces that do not match the given regex.
- type: string
- type: object
- nodeAddressAutodetectionV6:
- description:
- NodeAddressAutodetectionV6 specifies an approach
- to automatically detect node IPv6 addresses. If not specified,
- IPv6 addresses will not be auto-detected.
- properties:
- canReach:
- description:
- CanReach enables IP auto-detection based
- on which source address on the node is used to reach
- the specified IP or domain.
- type: string
- cidrs:
- description:
- CIDRS enables IP auto-detection based on
- which addresses on the nodes are within one of the provided
- CIDRs.
- items:
- type: string
- type: array
- firstFound:
- description:
- FirstFound uses default interface matching
- parameters to select an interface, performing best-effort
- filtering based on well-known interface names.
- type: boolean
- interface:
- description:
- Interface enables IP auto-detection based
- on interfaces that match the given regex.
- type: string
- kubernetes:
- description:
- Kubernetes configures Calico to detect node
- addresses based on the Kubernetes API.
- enum:
- - NodeInternalIP
- type: string
- skipInterface:
- description:
- SkipInterface enables IP auto-detection based
- on interfaces that do not match the given regex.
- type: string
- type: object
- type: object
- calicoNodeDaemonSet:
- description:
- CalicoNodeDaemonSet configures the calico-node DaemonSet.
- If used in conjunction with the deprecated ComponentResources,
- then these overrides take precedence.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the DaemonSet.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to
- the object's annotations provided the key does not already
- exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors. Each
- of these key/value pairs are added to the object's labels
- provided the key does not already exist in the object's
- labels.
- type: object
- type: object
- spec:
- description:
- Spec is the specification of the calico-node
- DaemonSet.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of
- seconds for which a newly created DaemonSet pod should
- be ready without any of its container crashing, for
- it to be considered available. If specified, this overrides
- any minReadySeconds value that may be set on the calico-node
- DaemonSet. If omitted, the calico-node DaemonSet will
- use its default value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the calico-node DaemonSet
- pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes
- object's metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary
- non-identifying metadata. Each of these key/value
- pairs are added to the object's annotations
- provided the key does not already exist in the
- object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and
- values that may match replicaset and service
- selectors. Each of these key/value pairs are
- added to the object's labels provided the key
- does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the calico-node DaemonSet's PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity
- scheduling rules for the calico-node pods. If
- specified, this overrides any affinity that
- may be set on the calico-node DaemonSet. If
- omitted, the calico-node DaemonSet will use
- its default value for affinity. WARNING: Please
- note that this field will override the default
- calico-node DaemonSet affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node matches the corresponding
- matchExpressions; the node(s) with the
- highest sum are the most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null
- preferred scheduling term matches
- no objects (i.e. is also a no-op).
- properties:
- preference:
- description:
- A node selector term,
- associated with the corresponding
- weight.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node
- selector term matches no objects.
- The requirements of them are ANDed.
- The TopologySelectorTerm type
- implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the
- same node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the anti-affinity expressions specified
- by this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling anti-affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the anti-affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of calico-node
- containers. If specified, this overrides the
- specified calico-node DaemonSet containers.
- If omitted, the calico-node DaemonSet will use
- its default values for its containers.
- items:
- description:
- CalicoNodeDaemonSetContainer is
- a calico-node DaemonSet container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the calico-node DaemonSet container by
- name.
- enum:
- - calico-node
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified,
- this overrides the named calico-node DaemonSet
- container's resources. If omitted, the
- calico-node DaemonSet will use its default
- value for this container's resources.
- If used in conjunction with the deprecated
- ComponentResources, then this value takes
- precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the
- minimum amount of compute resources
- required. If Requests is omitted for
- a container, it defaults to Limits
- if that is explicitly specified, otherwise
- to an implementation-defined value.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- initContainers:
- description:
- InitContainers is a list of calico-node
- init containers. If specified, this overrides
- the specified calico-node DaemonSet init containers.
- If omitted, the calico-node DaemonSet will use
- its default values for its init containers.
- items:
- description:
- CalicoNodeDaemonSetInitContainer
- is a calico-node DaemonSet init container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the calico-node DaemonSet init container
- by name.
- enum:
- - install-cni
- - hostpath-init
- - flexvol-driver
- - mount-bpffs
- - node-certs-key-cert-provisioner
- - calico-node-prometheus-server-tls-key-cert-provisioner
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified,
- this overrides the named calico-node DaemonSet
- init container's resources. If omitted,
- the calico-node DaemonSet will use its
- default value for this container's resources.
- If used in conjunction with the deprecated
- ComponentResources, then this value takes
- precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the
- minimum amount of compute resources
- required. If Requests is omitted for
- a container, it defaults to Limits
- if that is explicitly specified, otherwise
- to an implementation-defined value.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the calico-node
- pod's scheduling constraints. If specified,
- each of the key/value pairs are added to the
- calico-node DaemonSet nodeSelector provided
- the key does not already exist in the object's
- nodeSelector. If omitted, the calico-node DaemonSet
- will use its default value for nodeSelector.
- WARNING: Please note that this field will modify
- the default calico-node DaemonSet nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the calico-node pod's
- tolerations. If specified, this overrides any
- tolerations that may be set on the calico-node
- DaemonSet. If omitted, the calico-node DaemonSet
- will use its default value for tolerations.
- WARNING: Please note that this field will override
- the default calico-node DaemonSet tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint
- effect to match. Empty means match all
- taint effects. When specified, allowed
- values are NoSchedule, PreferNoSchedule
- and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the
- toleration applies to. Empty means match
- all taint keys. If the key is empty, operator
- must be Exists; this combination means
- to match all values and all keys.
- type: string
- operator:
- description:
- Operator represents a key's
- relationship to the value. Valid operators
- are Exists and Equal. Defaults to Equal.
- Exists is equivalent to wildcard for value,
- so that a pod can tolerate all taints
- of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents
- the period of time the toleration (which
- must be of effect NoExecute, otherwise
- this field is ignored) tolerates the taint.
- By default, it is not set, which means
- tolerate the taint forever (do not evict).
- Zero and negative values will be treated
- as 0 (evict immediately) by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the
- toleration matches to. If the operator
- is Exists, the value should be empty,
- otherwise just a regular string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- calicoWindowsUpgradeDaemonSet:
- description:
- CalicoWindowsUpgradeDaemonSet configures the calico-windows-upgrade
- DaemonSet.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the Deployment.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to
- the object's annotations provided the key does not already
- exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors. Each
- of these key/value pairs are added to the object's labels
- provided the key does not already exist in the object's
- labels.
- type: object
- type: object
- spec:
- description:
- Spec is the specification of the calico-windows-upgrade
- DaemonSet.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of
- seconds for which a newly created Deployment pod should
- be ready without any of its container crashing, for
- it to be considered available. If specified, this overrides
- any minReadySeconds value that may be set on the calico-windows-upgrade
- DaemonSet. If omitted, the calico-windows-upgrade DaemonSet
- will use its default value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the calico-windows-upgrade
- DaemonSet pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes
- object's metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary
- non-identifying metadata. Each of these key/value
- pairs are added to the object's annotations
- provided the key does not already exist in the
- object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and
- values that may match replicaset and service
- selectors. Each of these key/value pairs are
- added to the object's labels provided the key
- does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description:
- Spec is the calico-windows-upgrade DaemonSet's
- PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity
- scheduling rules for the calico-windows-upgrade
- pods. If specified, this overrides any affinity
- that may be set on the calico-windows-upgrade
- DaemonSet. If omitted, the calico-windows-upgrade
- DaemonSet will use its default value for affinity.
- WARNING: Please note that this field will override
- the default calico-windows-upgrade DaemonSet
- affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node matches the corresponding
- matchExpressions; the node(s) with the
- highest sum are the most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null
- preferred scheduling term matches
- no objects (i.e. is also a no-op).
- properties:
- preference:
- description:
- A node selector term,
- associated with the corresponding
- weight.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node
- selector term matches no objects.
- The requirements of them are ANDed.
- The TopologySelectorTerm type
- implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the
- same node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the anti-affinity expressions specified
- by this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling anti-affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the anti-affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of calico-windows-upgrade
- containers. If specified, this overrides the
- specified calico-windows-upgrade DaemonSet containers.
- If omitted, the calico-windows-upgrade DaemonSet
- will use its default values for its containers.
- items:
- description:
- CalicoWindowsUpgradeDaemonSetContainer
- is a calico-windows-upgrade DaemonSet container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the calico-windows-upgrade DaemonSet container
- by name.
- enum:
- - calico-windows-upgrade
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified,
- this overrides the named calico-windows-upgrade
- DaemonSet container's resources. If omitted,
- the calico-windows-upgrade DaemonSet will
- use its default value for this container's
- resources.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the
- minimum amount of compute resources
- required. If Requests is omitted for
- a container, it defaults to Limits
- if that is explicitly specified, otherwise
- to an implementation-defined value.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the calico-windows-upgrade
- pod's scheduling constraints. If specified,
- each of the key/value pairs are added to the
- calico-windows-upgrade DaemonSet nodeSelector
- provided the key does not already exist in the
- object's nodeSelector. If omitted, the calico-windows-upgrade
- DaemonSet will use its default value for nodeSelector.
- WARNING: Please note that this field will modify
- the default calico-windows-upgrade DaemonSet
- nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the calico-windows-upgrade
- pod's tolerations. If specified, this overrides
- any tolerations that may be set on the calico-windows-upgrade
- DaemonSet. If omitted, the calico-windows-upgrade
- DaemonSet will use its default value for tolerations.
- WARNING: Please note that this field will override
- the default calico-windows-upgrade DaemonSet
- tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint
- effect to match. Empty means match all
- taint effects. When specified, allowed
- values are NoSchedule, PreferNoSchedule
- and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the
- toleration applies to. Empty means match
- all taint keys. If the key is empty, operator
- must be Exists; this combination means
- to match all values and all keys.
- type: string
- operator:
- description:
- Operator represents a key's
- relationship to the value. Valid operators
- are Exists and Equal. Defaults to Equal.
- Exists is equivalent to wildcard for value,
- so that a pod can tolerate all taints
- of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents
- the period of time the toleration (which
- must be of effect NoExecute, otherwise
- this field is ignored) tolerates the taint.
- By default, it is not set, which means
- tolerate the taint forever (do not evict).
- Zero and negative values will be treated
- as 0 (evict immediately) by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the
- toleration matches to. If the operator
- is Exists, the value should be empty,
- otherwise just a regular string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- certificateManagement:
- description:
- CertificateManagement configures pods to submit a
- CertificateSigningRequest to the certificates.k8s.io/v1beta1
- API in order to obtain TLS certificates. This feature requires
- that you bring your own CSR signing and approval process, otherwise
- pods will be stuck during initialization.
- properties:
- caCert:
- description:
- Certificate of the authority that signs the CertificateSigningRequests
- in PEM format.
- format: byte
- type: string
- keyAlgorithm:
- description:
- "Specify the algorithm used by pods to generate
- a key pair that is associated with the X.509 certificate
- request. Default: RSAWithSize2048"
- enum:
- - ""
- - RSAWithSize2048
- - RSAWithSize4096
- - RSAWithSize8192
- - ECDSAWithCurve256
- - ECDSAWithCurve384
- - ECDSAWithCurve521
- type: string
- signatureAlgorithm:
- description:
- "Specify the algorithm used for the signature
- of the X.509 certificate request. Default: SHA256WithRSA"
- enum:
- - ""
- - SHA256WithRSA
- - SHA384WithRSA
- - SHA512WithRSA
- - ECDSAWithSHA256
- - ECDSAWithSHA384
- - ECDSAWithSHA512
- type: string
- signerName:
- description:
- "When a CSR is issued to the certificates.k8s.io
- API, the signerName is added to the request in order to
- accommodate for clusters with multiple signers. Must be
- formatted as: `<my-domain>/<my-signername>`."
- type: string
- required:
- - caCert
- - signerName
- type: object
- cni:
- description: CNI specifies the CNI that will be used by this installation.
- properties:
- ipam:
- description:
- IPAM specifies the pod IP address management
- that will be used in the Calico or Calico Enterprise installation.
- properties:
- type:
- description:
- "Specifies the IPAM plugin that will be used
- in the Calico or Calico Enterprise installation. * For
- CNI Plugin Calico, this field defaults to Calico. *
- For CNI Plugin GKE, this field defaults to HostLocal.
- * For CNI Plugin AzureVNET, this field defaults to AzureVNET.
- * For CNI Plugin AmazonVPC, this field defaults to AmazonVPC.
- \n The IPAM plugin is installed and configured only
- if the CNI plugin is set to Calico, for all other values
- of the CNI plugin the plugin binaries and CNI config
- is a dependency that is expected to be installed separately.
- \n Default: Calico"
- enum:
- - Calico
- - HostLocal
- - AmazonVPC
- - AzureVNET
- type: string
- required:
- - type
- type: object
- type:
- description:
- "Specifies the CNI plugin that will be used in
- the Calico or Calico Enterprise installation. * For KubernetesProvider
- GKE, this field defaults to GKE. * For KubernetesProvider
- AKS, this field defaults to AzureVNET. * For KubernetesProvider
- EKS, this field defaults to AmazonVPC. * If aws-node daemonset
- exists in kube-system when the Installation resource is
- created, this field defaults to AmazonVPC. * For all other
- cases this field defaults to Calico. \n For the value Calico,
- the CNI plugin binaries and CNI config will be installed
- as part of deployment, for all other values the CNI plugin
- binaries and CNI config is a dependency that is expected
- to be installed separately. \n Default: Calico"
- enum:
- - Calico
- - GKE
- - AmazonVPC
- - AzureVNET
- type: string
- required:
- - type
- type: object
- componentResources:
- description:
- Deprecated. Please use CalicoNodeDaemonSet, TyphaDeployment,
- and KubeControllersDeployment. ComponentResources can be used
- to customize the resource requirements for each component. Node,
- Typha, and KubeControllers are supported for installations.
- items:
- description:
- Deprecated. Please use component resource config
- fields in Installation.Spec instead. The ComponentResource
- struct associates a ResourceRequirements with a component
- by name
- properties:
- componentName:
- description:
- ComponentName is an enum which identifies the
- component
- enum:
- - Node
- - Typha
- - KubeControllers
- type: string
- resourceRequirements:
- description:
- ResourceRequirements allows customization of
- limits and requests for compute resources such as cpu
- and memory.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum amount of
- compute resources allowed. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the minimum amount
- of compute resources required. If Requests is omitted
- for a container, it defaults to Limits if that is
- explicitly specified, otherwise to an implementation-defined
- value. More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - componentName
- - resourceRequirements
- type: object
- type: array
- controlPlaneNodeSelector:
- additionalProperties:
- type: string
- description:
- ControlPlaneNodeSelector is used to select control
- plane nodes on which to run Calico components. This is globally
- applied to all resources created by the operator excluding daemonsets.
- type: object
- controlPlaneReplicas:
- description:
- ControlPlaneReplicas defines how many replicas of
- the control plane core components will be deployed. This field
- applies to all control plane components that support High Availability.
- Defaults to 2.
- format: int32
- type: integer
- controlPlaneTolerations:
- description:
- ControlPlaneTolerations specify tolerations which
- are then globally applied to all resources created by the operator.
- items:
- description:
- The pod this Toleration is attached to tolerates
- any taint that matches the triple <key,value,effect> using
- the matching operator <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint effect to match.
- Empty means match all taint effects. When specified, allowed
- values are NoSchedule, PreferNoSchedule and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the toleration applies
- to. Empty means match all taint keys. If the key is empty,
- operator must be Exists; this combination means to match
- all values and all keys.
- type: string
- operator:
- description:
- Operator represents a key's relationship to
- the value. Valid operators are Exists and Equal. Defaults
- to Equal. Exists is equivalent to wildcard for value,
- so that a pod can tolerate all taints of a particular
- category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents the period of
- time the toleration (which must be of effect NoExecute,
- otherwise this field is ignored) tolerates the taint.
- By default, it is not set, which means tolerate the taint
- forever (do not evict). Zero and negative values will
- be treated as 0 (evict immediately) by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the toleration matches
- to. If the operator is Exists, the value should be empty,
- otherwise just a regular string.
- type: string
- type: object
- type: array
- csiNodeDriverDaemonSet:
- description:
- CSINodeDriverDaemonSet configures the csi-node-driver
- DaemonSet.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the DaemonSet.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to
- the object's annotations provided the key does not already
- exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors. Each
- of these key/value pairs are added to the object's labels
- provided the key does not already exist in the object's
- labels.
- type: object
- type: object
- spec:
- description:
- Spec is the specification of the csi-node-driver
- DaemonSet.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of
- seconds for which a newly created DaemonSet pod should
- be ready without any of its container crashing, for
- it to be considered available. If specified, this overrides
- any minReadySeconds value that may be set on the csi-node-driver
- DaemonSet. If omitted, the csi-node-driver DaemonSet
- will use its default value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- template:
- description:
- Template describes the csi-node-driver DaemonSet
- pod that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes
- object's metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary
- non-identifying metadata. Each of these key/value
- pairs are added to the object's annotations
- provided the key does not already exist in the
- object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and
- values that may match replicaset and service
- selectors. Each of these key/value pairs are
- added to the object's labels provided the key
- does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description:
- Spec is the csi-node-driver DaemonSet's
- PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity
- scheduling rules for the csi-node-driver pods.
- If specified, this overrides any affinity that
- may be set on the csi-node-driver DaemonSet.
- If omitted, the csi-node-driver DaemonSet will
- use its default value for affinity. WARNING:
- Please note that this field will override the
- default csi-node-driver DaemonSet affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node matches the corresponding
- matchExpressions; the node(s) with the
- highest sum are the most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null
- preferred scheduling term matches
- no objects (i.e. is also a no-op).
- properties:
- preference:
- description:
- A node selector term,
- associated with the corresponding
- weight.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node
- selector term matches no objects.
- The requirements of them are ANDed.
- The TopologySelectorTerm type
- implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the
- same node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the anti-affinity expressions specified
- by this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling anti-affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the anti-affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of csi-node-driver
- containers. If specified, this overrides the
- specified csi-node-driver DaemonSet containers.
- If omitted, the csi-node-driver DaemonSet will
- use its default values for its containers.
- items:
- description:
- CSINodeDriverDaemonSetContainer
- is a csi-node-driver DaemonSet container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the csi-node-driver DaemonSet container
- by name.
- enum:
- - csi-node-driver
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified,
- this overrides the named csi-node-driver
- DaemonSet container's resources. If omitted,
- the csi-node-driver DaemonSet will use
- its default value for this container's
- resources.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the
- minimum amount of compute resources
- required. If Requests is omitted for
- a container, it defaults to Limits
- if that is explicitly specified, otherwise
- to an implementation-defined value.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the csi-node-driver
- pod's scheduling constraints. If specified,
- each of the key/value pairs are added to the
- csi-node-driver DaemonSet nodeSelector provided
- the key does not already exist in the object's
- nodeSelector. If omitted, the csi-node-driver
- DaemonSet will use its default value for nodeSelector.
- WARNING: Please note that this field will modify
- the default csi-node-driver DaemonSet nodeSelector."
- type: object
- tolerations:
- description:
- "Tolerations is the csi-node-driver
- pod's tolerations. If specified, this overrides
- any tolerations that may be set on the csi-node-driver
- DaemonSet. If omitted, the csi-node-driver DaemonSet
- will use its default value for tolerations.
- WARNING: Please note that this field will override
- the default csi-node-driver DaemonSet tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint
- effect to match. Empty means match all
- taint effects. When specified, allowed
- values are NoSchedule, PreferNoSchedule
- and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the
- toleration applies to. Empty means match
- all taint keys. If the key is empty, operator
- must be Exists; this combination means
- to match all values and all keys.
- type: string
- operator:
- description:
- Operator represents a key's
- relationship to the value. Valid operators
- are Exists and Equal. Defaults to Equal.
- Exists is equivalent to wildcard for value,
- so that a pod can tolerate all taints
- of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents
- the period of time the toleration (which
- must be of effect NoExecute, otherwise
- this field is ignored) tolerates the taint.
- By default, it is not set, which means
- tolerate the taint forever (do not evict).
- Zero and negative values will be treated
- as 0 (evict immediately) by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the
- toleration matches to. If the operator
- is Exists, the value should be empty,
- otherwise just a regular string.
- type: string
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- fipsMode:
- description:
- "FIPSMode uses images and features only that are
- using FIPS 140-2 validated cryptographic modules and standards.
- Default: Disabled"
- enum:
- - Enabled
- - Disabled
- type: string
- flexVolumePath:
- description:
- FlexVolumePath optionally specifies a custom path
- for FlexVolume. If not specified, FlexVolume will be enabled
- by default. If set to 'None', FlexVolume will be disabled. The
- default is based on the kubernetesProvider.
- type: string
- imagePath:
- description:
- "ImagePath allows for the path part of an image to
- be specified. If specified then the specified value will be
- used as the image path for each image. If not specified or empty,
- the default for each image will be used. A special case value,
- UseDefault, is supported to explicitly specify the default image
- path will be used for each image. \n Image format: `<registry><imagePath>/<imagePrefix><imageName>:<image-tag>`
- \n This option allows configuring the `<imagePath>` portion
- of the above format."
- type: string
- imagePrefix:
- description:
- "ImagePrefix allows for the prefix part of an image
- to be specified. If specified then the given value will be used
- as a prefix on each image. If not specified or empty, no prefix
- will be used. A special case value, UseDefault, is supported
- to explicitly specify the default image prefix will be used
- for each image. \n Image format: `<registry><imagePath>/<imagePrefix><imageName>:<image-tag>`
- \n This option allows configuring the `<imagePrefix>` portion
- of the above format."
- type: string
- imagePullSecrets:
- description:
- ImagePullSecrets is an array of references to container
- registry pull secrets to use. These are applied to all images
- to be pulled.
- items:
- description:
- LocalObjectReference contains enough information
- to let you locate the referenced object inside the same namespace.
- properties:
- name:
- description:
- "Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
- TODO: Add other useful fields. apiVersion, kind, uid?"
- type: string
- type: object
- x-kubernetes-map-type: atomic
- type: array
- kubeletVolumePluginPath:
- description:
- "KubeletVolumePluginPath optionally specifies enablement
- of Calico CSI plugin. If not specified, CSI will be enabled
- by default. If set to 'None', CSI will be disabled. Default:
- /var/lib/kubelet"
- type: string
- kubernetesProvider:
- description:
- KubernetesProvider specifies a particular provider
- of the Kubernetes platform and enables provider-specific configuration.
- If the specified value is empty, the Operator will attempt to
- automatically determine the current provider. If the specified
- value is not empty, the Operator will still attempt auto-detection,
- but will additionally compare the auto-detected value to the
- specified value to confirm they match.
- enum:
- - ""
- - EKS
- - GKE
- - AKS
- - OpenShift
- - DockerEnterprise
- - RKE2
- type: string
- logging:
- description: Logging Configuration for Components
- properties:
- cni:
- description:
- Customized logging specification for calico-cni
- plugin
- properties:
- logFileMaxAgeDays:
- description: "Default: 30 (days)"
- format: int32
- type: integer
- logFileMaxCount:
- description: "Default: 10"
- format: int32
- type: integer
- logFileMaxSize:
- anyOf:
- - type: integer
- - type: string
- description: "Default: 100Mi"
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- logSeverity:
- description: "Default: Info"
- enum:
- - Error
- - Warning
- - Debug
- - Info
- type: string
- type: object
- type: object
- nodeMetricsPort:
- description:
- NodeMetricsPort specifies which port calico/node
- serves prometheus metrics on. By default, metrics are not enabled.
- If specified, this overrides any FelixConfiguration resources
- which may exist. If omitted, then prometheus metrics may still
- be configured through FelixConfiguration.
- format: int32
- type: integer
- nodeUpdateStrategy:
- description:
- NodeUpdateStrategy can be used to customize the desired
- update strategy, such as the MaxUnavailable field.
- properties:
- rollingUpdate:
- description:
- 'Rolling update config params. Present only if
- type = "RollingUpdate". --- TODO: Update this to follow
- our convention for oneOf, whatever we decide it to be. Same
- as Deployment `strategy.rollingUpdate`. See https://github.com/kubernetes/kubernetes/issues/35345'
- properties:
- maxSurge:
- anyOf:
- - type: integer
- - type: string
- description:
- "The maximum number of nodes with an existing
- available DaemonSet pod that can have an updated DaemonSet
- pod during during an update. Value can be an absolute
- number (ex: 5) or a percentage of desired pods (ex:
- 10%). This can not be 0 if MaxUnavailable is 0. Absolute
- number is calculated from percentage by rounding up
- to a minimum of 1. Default value is 0. Example: when
- this is set to 30%, at most 30% of the total number
- of nodes that should be running the daemon pod (i.e.
- status.desiredNumberScheduled) can have their a new
- pod created before the old pod is marked as deleted.
- The update starts by launching new pods on 30% of nodes.
- Once an updated pod is available (Ready for at least
- minReadySeconds) the old DaemonSet pod on that node
- is marked deleted. If the old pod becomes unavailable
- for any reason (Ready transitions to false, is evicted,
- or is drained) an updated pod is immediatedly created
- on that node without considering surge limits. Allowing
- surge implies the possibility that the resources consumed
- by the daemonset on any given node can double if the
- readiness check fails, and so resource intensive daemonsets
- should take into account that they may cause evictions
- during disruption."
- x-kubernetes-int-or-string: true
- maxUnavailable:
- anyOf:
- - type: integer
- - type: string
- description:
- "The maximum number of DaemonSet pods that
- can be unavailable during the update. Value can be an
- absolute number (ex: 5) or a percentage of total number
- of DaemonSet pods at the start of the update (ex: 10%).
- Absolute number is calculated from percentage by rounding
- up. This cannot be 0 if MaxSurge is 0 Default value
- is 1. Example: when this is set to 30%, at most 30%
- of the total number of nodes that should be running
- the daemon pod (i.e. status.desiredNumberScheduled)
- can have their pods stopped for an update at any given
- time. The update starts by stopping at most 30% of those
- DaemonSet pods and then brings up new DaemonSet pods
- in their place. Once the new pods are available, it
- then proceeds onto other DaemonSet pods, thus ensuring
- that at least 70% of original number of DaemonSet pods
- are available at all times during the update."
- x-kubernetes-int-or-string: true
- type: object
- type:
- description:
- Type of daemon set update. Can be "RollingUpdate"
- or "OnDelete". Default is RollingUpdate.
- type: string
- type: object
- nonPrivileged:
- description:
- NonPrivileged configures Calico to be run in non-privileged
- containers as non-root users where possible.
- type: string
- registry:
- description:
- "Registry is the default Docker registry used for
- component Docker images. If specified then the given value must
- end with a slash character (`/`) and all images will be pulled
- from this registry. If not specified then the default registries
- will be used. A special case value, UseDefault, is supported
- to explicitly specify the default registries will be used. \n
- Image format: `<registry><imagePath>/<imagePrefix><imageName>:<image-tag>`
- \n This option allows configuring the `<registry>` portion of
- the above format."
- type: string
- typhaAffinity:
- description:
- Deprecated. Please use Installation.Spec.TyphaDeployment
- instead. TyphaAffinity allows configuration of node affinity
- characteristics for Typha pods.
- properties:
- nodeAffinity:
- description:
- NodeAffinity describes node affinity scheduling
- rules for typha.
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- description:
- The scheduler will prefer to schedule pods
- to nodes that satisfy the affinity expressions specified
- by this field, but it may choose a node that violates
- one or more of the expressions.
- items:
- description:
- An empty preferred scheduling term matches
- all objects with implicit weight 0 (i.e. it's a no-op).
- A null preferred scheduling term matches no objects
- (i.e. is also a no-op).
- properties:
- preference:
- description:
- A node selector term, associated with
- the corresponding weight.
- properties:
- matchExpressions:
- description:
- A list of node selector requirements
- by node's labels.
- items:
- description:
- A node selector requirement is
- a selector that contains values, a key,
- and an operator that relates the key and
- values.
- properties:
- key:
- description:
- The label key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents a key's relationship
- to a set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string values.
- If the operator is In or NotIn, the
- values array must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be empty. If the
- operator is Gt or Lt, the values array
- must have a single element, which will
- be interpreted as an integer. This array
- is replaced during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector requirements
- by node's fields.
- items:
- description:
- A node selector requirement is
- a selector that contains values, a key,
- and an operator that relates the key and
- values.
- properties:
- key:
- description:
- The label key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents a key's relationship
- to a set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string values.
- If the operator is In or NotIn, the
- values array must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be empty. If the
- operator is Gt or Lt, the values array
- must have a single element, which will
- be interpreted as an integer. This array
- is replaced during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with matching the
- corresponding nodeSelectorTerm, in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- requiredDuringSchedulingIgnoredDuringExecution:
- description:
- "WARNING: Please note that if the affinity
- requirements specified by this field are not met at
- scheduling time, the pod will NOT be scheduled onto
- the node. There is no fallback to another affinity rules
- with this setting. This may cause networking disruption
- or even catastrophic failure! PreferredDuringSchedulingIgnoredDuringExecution
- should be used for affinity unless there is a specific
- well understood reason to use RequiredDuringSchedulingIgnoredDuringExecution
- and you can guarantee that the RequiredDuringSchedulingIgnoredDuringExecution
- will always have sufficient nodes to satisfy the requirement.
- NOTE: RequiredDuringSchedulingIgnoredDuringExecution
- is set by default for AKS nodes, to avoid scheduling
- Typhas on virtual-nodes. If the affinity requirements
- specified by this field cease to be met at some point
- during pod execution (e.g. due to an update), the system
- may or may not try to eventually evict the pod from
- its node."
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node selector terms.
- The terms are ORed.
- items:
- description:
- A null or empty node selector term
- matches no objects. The requirements of them are
- ANDed. The TopologySelectorTerm type implements
- a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node selector requirements
- by node's labels.
- items:
- description:
- A node selector requirement is
- a selector that contains values, a key,
- and an operator that relates the key and
- values.
- properties:
- key:
- description:
- The label key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents a key's relationship
- to a set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string values.
- If the operator is In or NotIn, the
- values array must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be empty. If the
- operator is Gt or Lt, the values array
- must have a single element, which will
- be interpreted as an integer. This array
- is replaced during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node selector requirements
- by node's fields.
- items:
- description:
- A node selector requirement is
- a selector that contains values, a key,
- and an operator that relates the key and
- values.
- properties:
- key:
- description:
- The label key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents a key's relationship
- to a set of values. Valid operators
- are In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array of string values.
- If the operator is In or NotIn, the
- values array must be non-empty. If the
- operator is Exists or DoesNotExist,
- the values array must be empty. If the
- operator is Gt or Lt, the values array
- must have a single element, which will
- be interpreted as an integer. This array
- is replaced during a strategic merge
- patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- type: object
- typhaDeployment:
- description:
- TyphaDeployment configures the typha Deployment.
- If used in conjunction with the deprecated ComponentResources
- or TyphaAffinity, then these overrides take precedence.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes object's
- metadata that is added to the Deployment.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary non-identifying
- metadata. Each of these key/value pairs are added to
- the object's annotations provided the key does not already
- exist in the object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and values
- that may match replicaset and service selectors. Each
- of these key/value pairs are added to the object's labels
- provided the key does not already exist in the object's
- labels.
- type: object
- type: object
- spec:
- description: Spec is the specification of the typha Deployment.
- properties:
- minReadySeconds:
- description:
- MinReadySeconds is the minimum number of
- seconds for which a newly created Deployment pod should
- be ready without any of its container crashing, for
- it to be considered available. If specified, this overrides
- any minReadySeconds value that may be set on the typha
- Deployment. If omitted, the typha Deployment will use
- its default value for minReadySeconds.
- format: int32
- maximum: 2147483647
- minimum: 0
- type: integer
- strategy:
- description:
- The deployment strategy to use to replace
- existing pods with new ones.
- properties:
- rollingUpdate:
- description:
- Rolling update config params. Present
- only if DeploymentStrategyType = RollingUpdate.
- to be.
- properties:
- maxSurge:
- anyOf:
- - type: integer
- - type: string
- description:
- "The maximum number of pods that
- can be scheduled above the desired number of
- pods. Value can be an absolute number (ex: 5)
- or a percentage of desired pods (ex: 10%). This
- can not be 0 if MaxUnavailable is 0. Absolute
- number is calculated from percentage by rounding
- up. Defaults to 25%. Example: when this is set
- to 30%, the new ReplicaSet can be scaled up
- immediately when the rolling update starts,
- such that the total number of old and new pods
- do not exceed 130% of desired pods. Once old
- pods have been killed, new ReplicaSet can be
- scaled up further, ensuring that total number
- of pods running at any time during the update
- is at most 130% of desired pods."
- x-kubernetes-int-or-string: true
- maxUnavailable:
- anyOf:
- - type: integer
- - type: string
- description:
- "The maximum number of pods that
- can be unavailable during the update. Value
- can be an absolute number (ex: 5) or a percentage
- of desired pods (ex: 10%). Absolute number is
- calculated from percentage by rounding down.
- This can not be 0 if MaxSurge is 0. Defaults
- to 25%. Example: when this is set to 30%, the
- old ReplicaSet can be scaled down to 70% of
- desired pods immediately when the rolling update
- starts. Once new pods are ready, old ReplicaSet
- can be scaled down further, followed by scaling
- up the new ReplicaSet, ensuring that the total
- number of pods available at all times during
- the update is at least 70% of desired pods."
- x-kubernetes-int-or-string: true
- type: object
- type: object
- template:
- description:
- Template describes the typha Deployment pod
- that will be created.
- properties:
- metadata:
- description:
- Metadata is a subset of a Kubernetes
- object's metadata that is added to the pod's metadata.
- properties:
- annotations:
- additionalProperties:
- type: string
- description:
- Annotations is a map of arbitrary
- non-identifying metadata. Each of these key/value
- pairs are added to the object's annotations
- provided the key does not already exist in the
- object's annotations.
- type: object
- labels:
- additionalProperties:
- type: string
- description:
- Labels is a map of string keys and
- values that may match replicaset and service
- selectors. Each of these key/value pairs are
- added to the object's labels provided the key
- does not already exist in the object's labels.
- type: object
- type: object
- spec:
- description: Spec is the typha Deployment's PodSpec.
- properties:
- affinity:
- description:
- "Affinity is a group of affinity
- scheduling rules for the typha pods. If specified,
- this overrides any affinity that may be set
- on the typha Deployment. If omitted, the typha
- Deployment will use its default value for affinity.
- If used in conjunction with the deprecated TyphaAffinity,
- then this value takes precedence. WARNING: Please
- note that this field will override the default
- calico-typha Deployment affinity."
- properties:
- nodeAffinity:
- description:
- Describes node affinity scheduling
- rules for the pod.
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node matches the corresponding
- matchExpressions; the node(s) with the
- highest sum are the most preferred.
- items:
- description:
- An empty preferred scheduling
- term matches all objects with implicit
- weight 0 (i.e. it's a no-op). A null
- preferred scheduling term matches
- no objects (i.e. is also a no-op).
- properties:
- preference:
- description:
- A node selector term,
- associated with the corresponding
- weight.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- weight:
- description:
- Weight associated with
- matching the corresponding nodeSelectorTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - preference
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to an update),
- the system may or may not try to eventually
- evict the pod from its node.
- properties:
- nodeSelectorTerms:
- description:
- Required. A list of node
- selector terms. The terms are ORed.
- items:
- description:
- A null or empty node
- selector term matches no objects.
- The requirements of them are ANDed.
- The TopologySelectorTerm type
- implements a subset of the NodeSelectorTerm.
- properties:
- matchExpressions:
- description:
- A list of node
- selector requirements by node's
- labels.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchFields:
- description:
- A list of node
- selector requirements by node's
- fields.
- items:
- description:
- A node selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- The label
- key that the selector
- applies to.
- type: string
- operator:
- description:
- Represents
- a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists, DoesNotExist.
- Gt, and Lt.
- type: string
- values:
- description:
- An array
- of string values. If
- the operator is In or
- NotIn, the values array
- must be non-empty. If
- the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. If the operator
- is Gt or Lt, the values
- array must have a single
- element, which will
- be interpreted as an
- integer. This array
- is replaced during a
- strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- type: object
- x-kubernetes-map-type: atomic
- type: array
- required:
- - nodeSelectorTerms
- type: object
- x-kubernetes-map-type: atomic
- type: object
- podAffinity:
- description:
- Describes pod affinity scheduling
- rules (e.g. co-locate this pod in the same
- node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the affinity expressions specified by
- this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- podAntiAffinity:
- description:
- Describes pod anti-affinity scheduling
- rules (e.g. avoid putting this pod in the
- same node, zone, etc. as some other pod(s)).
- properties:
- ? preferredDuringSchedulingIgnoredDuringExecution
- : description:
- The scheduler will prefer
- to schedule pods to nodes that satisfy
- the anti-affinity expressions specified
- by this field, but it may choose a node
- that violates one or more of the expressions.
- The node that is most preferred is the
- one with the greatest sum of weights,
- i.e. for each node that meets all of
- the scheduling requirements (resource
- request, requiredDuringScheduling anti-affinity
- expressions, etc.), compute a sum by
- iterating through the elements of this
- field and adding "weight" to the sum
- if the node has pods which matches the
- corresponding podAffinityTerm; the node(s)
- with the highest sum are the most preferred.
- items:
- description:
- The weights of all of the
- matched WeightedPodAffinityTerm fields
- are added per-node to find the most
- preferred node(s)
- properties:
- podAffinityTerm:
- description:
- Required. A pod affinity
- term, associated with the corresponding
- weight.
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this
- case pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that
- the term applies to. The term
- is applied to the union of
- the namespaces selected by
- this field and the ones listed
- in the namespaces field. null
- selector and null or empty
- namespaces list means "this
- pod's namespace". An empty
- selector ({}) matches all
- namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values,
- a key, and an operator
- that relates the key
- and values.
- properties:
- key:
- description:
- key is
- the label key that
- the selector applies
- to.
- type: string
- operator:
- description:
- operator
- represents a key's
- relationship to
- a set of values.
- Valid operators
- are In, NotIn, Exists
- and DoesNotExist.
- type: string
- values:
- description:
- values
- is an array of string
- values. If the operator
- is In or NotIn,
- the values array
- must be non-empty.
- If the operator
- is Exists or DoesNotExist,
- the values array
- must be empty. This
- array is replaced
- during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- ? additionalProperties
- : type: string
- description:
- matchLabels
- is a map of {key,value}
- pairs. A single {key,value}
- in the matchLabels map
- is equivalent to an element
- of matchExpressions, whose
- key field is "key", the
- operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace
- names that the term applies
- to. The term is applied to
- the union of the namespaces
- listed in this field and the
- ones selected by namespaceSelector.
- null or empty namespaces list
- and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should
- be co-located (affinity) or
- not co-located (anti-affinity)
- with the pods matching the
- labelSelector in the specified
- namespaces, where co-located
- is defined as running on a
- node whose value of the label
- with key topologyKey matches
- that of any node on which
- any of the selected pods is
- running. Empty topologyKey
- is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- weight:
- description:
- weight associated with
- matching the corresponding podAffinityTerm,
- in the range 1-100.
- format: int32
- type: integer
- required:
- - podAffinityTerm
- - weight
- type: object
- type: array
- ? requiredDuringSchedulingIgnoredDuringExecution
- : description:
- If the anti-affinity requirements
- specified by this field are not met
- at scheduling time, the pod will not
- be scheduled onto the node. If the anti-affinity
- requirements specified by this field
- cease to be met at some point during
- pod execution (e.g. due to a pod label
- update), the system may or may not try
- to eventually evict the pod from its
- node. When there are multiple elements,
- the lists of nodes corresponding to
- each podAffinityTerm are intersected,
- i.e. all terms must be satisfied.
- items:
- description:
- Defines a set of pods (namely
- those matching the labelSelector relative
- to the given namespace(s)) that this
- pod should be co-located (affinity)
- or not co-located (anti-affinity)
- with, where co-located is defined
- as running on a node whose value of
- the label with key <topologyKey> matches
- that of any node on which a pod of
- the set of pods is running
- properties:
- labelSelector:
- description:
- A label query over
- a set of resources, in this case
- pods.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaceSelector:
- description:
- A label query over
- the set of namespaces that the
- term applies to. The term is applied
- to the union of the namespaces
- selected by this field and the
- ones listed in the namespaces
- field. null selector and null
- or empty namespaces list means
- "this pod's namespace". An empty
- selector ({}) matches all namespaces.
- properties:
- matchExpressions:
- description:
- matchExpressions
- is a list of label selector
- requirements. The requirements
- are ANDed.
- items:
- description:
- A label selector
- requirement is a selector
- that contains values, a
- key, and an operator that
- relates the key and values.
- properties:
- key:
- description:
- key is the
- label key that the selector
- applies to.
- type: string
- operator:
- description:
- operator
- represents a key's relationship
- to a set of values.
- Valid operators are
- In, NotIn, Exists and
- DoesNotExist.
- type: string
- values:
- description:
- values is
- an array of string values.
- If the operator is In
- or NotIn, the values
- array must be non-empty.
- If the operator is Exists
- or DoesNotExist, the
- values array must be
- empty. This array is
- replaced during a strategic
- merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is
- a map of {key,value} pairs.
- A single {key,value} in the
- matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key",
- the operator is "In", and
- the values array contains
- only "value". The requirements
- are ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- namespaces:
- description:
- namespaces specifies
- a static list of namespace names
- that the term applies to. The
- term is applied to the union of
- the namespaces listed in this
- field and the ones selected by
- namespaceSelector. null or empty
- namespaces list and null namespaceSelector
- means "this pod's namespace".
- items:
- type: string
- type: array
- topologyKey:
- description:
- This pod should be
- co-located (affinity) or not co-located
- (anti-affinity) with the pods
- matching the labelSelector in
- the specified namespaces, where
- co-located is defined as running
- on a node whose value of the label
- with key topologyKey matches that
- of any node on which any of the
- selected pods is running. Empty
- topologyKey is not allowed.
- type: string
- required:
- - topologyKey
- type: object
- type: array
- type: object
- type: object
- containers:
- description:
- Containers is a list of typha containers.
- If specified, this overrides the specified typha
- Deployment containers. If omitted, the typha
- Deployment will use its default values for its
- containers.
- items:
- description:
- TyphaDeploymentContainer is a typha
- Deployment container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the typha Deployment container by name.
- enum:
- - calico-typha
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified,
- this overrides the named typha Deployment
- container's resources. If omitted, the
- typha Deployment will use its default
- value for this container's resources.
- If used in conjunction with the deprecated
- ComponentResources, then this value takes
- precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the
- minimum amount of compute resources
- required. If Requests is omitted for
- a container, it defaults to Limits
- if that is explicitly specified, otherwise
- to an implementation-defined value.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- initContainers:
- description:
- InitContainers is a list of typha
- init containers. If specified, this overrides
- the specified typha Deployment init containers.
- If omitted, the typha Deployment will use its
- default values for its init containers.
- items:
- description:
- TyphaDeploymentInitContainer is
- a typha Deployment init container.
- properties:
- name:
- description:
- Name is an enum which identifies
- the typha Deployment init container by
- name.
- enum:
- - typha-certs-key-cert-provisioner
- type: string
- resources:
- description:
- Resources allows customization
- of limits and requests for compute resources
- such as cpu and memory. If specified,
- this overrides the named typha Deployment
- init container's resources. If omitted,
- the typha Deployment will use its default
- value for this init container's resources.
- If used in conjunction with the deprecated
- ComponentResources, then this value takes
- precedence.
- properties:
- limits:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Limits describes the maximum
- amount of compute resources allowed.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- requests:
- additionalProperties:
- anyOf:
- - type: integer
- - type: string
- pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
- x-kubernetes-int-or-string: true
- description:
- "Requests describes the
- minimum amount of compute resources
- required. If Requests is omitted for
- a container, it defaults to Limits
- if that is explicitly specified, otherwise
- to an implementation-defined value.
- More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/"
- type: object
- type: object
- required:
- - name
- type: object
- type: array
- nodeSelector:
- additionalProperties:
- type: string
- description:
- "NodeSelector is the calico-typha
- pod's scheduling constraints. If specified,
- each of the key/value pairs are added to the
- calico-typha Deployment nodeSelector provided
- the key does not already exist in the object's
- nodeSelector. If omitted, the calico-typha Deployment
- will use its default value for nodeSelector.
- WARNING: Please note that this field will modify
- the default calico-typha Deployment nodeSelector."
- type: object
- terminationGracePeriodSeconds:
- description:
- Optional duration in seconds the
- pod needs to terminate gracefully. May be decreased
- in delete request. Value must be non-negative
- integer. The value zero indicates stop immediately
- via the kill signal (no opportunity to shut
- down). If this value is nil, the default grace
- period will be used instead. The grace period
- is the duration in seconds after the processes
- running in the pod are sent a termination signal
- and the time when the processes are forcibly
- halted with a kill signal. Set this value longer
- than the expected cleanup time for your process.
- Defaults to 30 seconds.
- format: int64
- type: integer
- tolerations:
- description:
- "Tolerations is the typha pod's
- tolerations. If specified, this overrides any
- tolerations that may be set on the typha Deployment.
- If omitted, the typha Deployment will use its
- default value for tolerations. WARNING: Please
- note that this field will override the default
- calico-typha Deployment tolerations."
- items:
- description:
- The pod this Toleration is attached
- to tolerates any taint that matches the triple
- <key,value,effect> using the matching operator
- <operator>.
- properties:
- effect:
- description:
- Effect indicates the taint
- effect to match. Empty means match all
- taint effects. When specified, allowed
- values are NoSchedule, PreferNoSchedule
- and NoExecute.
- type: string
- key:
- description:
- Key is the taint key that the
- toleration applies to. Empty means match
- all taint keys. If the key is empty, operator
- must be Exists; this combination means
- to match all values and all keys.
- type: string
- operator:
- description:
- Operator represents a key's
- relationship to the value. Valid operators
- are Exists and Equal. Defaults to Equal.
- Exists is equivalent to wildcard for value,
- so that a pod can tolerate all taints
- of a particular category.
- type: string
- tolerationSeconds:
- description:
- TolerationSeconds represents
- the period of time the toleration (which
- must be of effect NoExecute, otherwise
- this field is ignored) tolerates the taint.
- By default, it is not set, which means
- tolerate the taint forever (do not evict).
- Zero and negative values will be treated
- as 0 (evict immediately) by the system.
- format: int64
- type: integer
- value:
- description:
- Value is the taint value the
- toleration matches to. If the operator
- is Exists, the value should be empty,
- otherwise just a regular string.
- type: string
- type: object
- type: array
- topologySpreadConstraints:
- description:
- TopologySpreadConstraints describes
- how a group of pods ought to spread across topology
- domains. Scheduler will schedule pods in a way
- which abides by the constraints. All topologySpreadConstraints
- are ANDed.
- items:
- description:
- TopologySpreadConstraint specifies
- how to spread matching pods among the given
- topology.
- properties:
- labelSelector:
- description:
- LabelSelector is used to find
- matching pods. Pods that match this label
- selector are counted to determine the
- number of pods in their corresponding
- topology domain.
- properties:
- matchExpressions:
- description:
- matchExpressions is a list
- of label selector requirements. The
- requirements are ANDed.
- items:
- description:
- A label selector requirement
- is a selector that contains values,
- a key, and an operator that relates
- the key and values.
- properties:
- key:
- description:
- key is the label
- key that the selector applies
- to.
- type: string
- operator:
- description:
- operator represents
- a key's relationship to a set
- of values. Valid operators are
- In, NotIn, Exists and DoesNotExist.
- type: string
- values:
- description:
- values is an array
- of string values. If the operator
- is In or NotIn, the values array
- must be non-empty. If the operator
- is Exists or DoesNotExist, the
- values array must be empty.
- This array is replaced during
- a strategic merge patch.
- items:
- type: string
- type: array
- required:
- - key
- - operator
- type: object
- type: array
- matchLabels:
- additionalProperties:
- type: string
- description:
- matchLabels is a map of
- {key,value} pairs. A single {key,value}
- in the matchLabels map is equivalent
- to an element of matchExpressions,
- whose key field is "key", the operator
- is "In", and the values array contains
- only "value". The requirements are
- ANDed.
- type: object
- type: object
- x-kubernetes-map-type: atomic
- matchLabelKeys:
- description:
- MatchLabelKeys is a set of
- pod label keys to select the pods over
- which spreading will be calculated. The
- keys are used to lookup values from the
- incoming pod labels, those key-value labels
- are ANDed with labelSelector to select
- the group of existing pods over which
- spreading will be calculated for the incoming
- pod. Keys that don't exist in the incoming
- pod labels will be ignored. A null or
- empty list means only match against labelSelector.
- items:
- type: string
- type: array
- x-kubernetes-list-type: atomic
- maxSkew:
- description:
- "MaxSkew describes the degree
- to which pods may be unevenly distributed.
- When `whenUnsatisfiable=DoNotSchedule`,
- it is the maximum permitted difference
- between the number of matching pods in
- the target topology and the global minimum.
- The global minimum is the minimum number
- of matching pods in an eligible domain
- or zero if the number of eligible domains
- is less than MinDomains. For example,
- in a 3-zone cluster, MaxSkew is set to
- 1, and pods with the same labelSelector
- spread as 2/2/1: In this case, the global
- minimum is 1. | zone1 | zone2 | zone3
- | | P P | P P | P | - if MaxSkew
- is 1, incoming pod can only be scheduled
- to zone3 to become 2/2/2; scheduling it
- onto zone1(zone2) would make the ActualSkew(3-1)
- on zone1(zone2) violate MaxSkew(1). -
- if MaxSkew is 2, incoming pod can be scheduled
- onto any zone. When `whenUnsatisfiable=ScheduleAnyway`,
- it is used to give higher precedence to
- topologies that satisfy it. It's a required
- field. Default value is 1 and 0 is not
- allowed."
- format: int32
- type: integer
- minDomains:
- description:
- "MinDomains indicates a minimum
- number of eligible domains. When the number
- of eligible domains with matching topology
- keys is less than minDomains, Pod Topology
- Spread treats \"global minimum\" as 0,
- and then the calculation of Skew is performed.
- And when the number of eligible domains
- with matching topology keys equals or
- greater than minDomains, this value has
- no effect on scheduling. As a result,
- when the number of eligible domains is
- less than minDomains, scheduler won't
- schedule more than maxSkew Pods to those
- domains. If value is nil, the constraint
- behaves as if MinDomains is equal to 1.
- Valid values are integers greater than
- 0. When value is not nil, WhenUnsatisfiable
- must be DoNotSchedule. \n For example,
- in a 3-zone cluster, MaxSkew is set to
- 2, MinDomains is set to 5 and pods with
- the same labelSelector spread as 2/2/2:
- | zone1 | zone2 | zone3 | | P P | P
- P | P P | The number of domains is
- less than 5(MinDomains), so \"global minimum\"
- is treated as 0. In this situation, new
- pod with the same labelSelector cannot
- be scheduled, because computed skew will
- be 3(3 - 0) if new Pod is scheduled to
- any of the three zones, it will violate
- MaxSkew. \n This is a beta field and requires
- the MinDomainsInPodTopologySpread feature
- gate to be enabled (enabled by default)."
- format: int32
- type: integer
- nodeAffinityPolicy:
- description:
- "NodeAffinityPolicy indicates
- how we will treat Pod's nodeAffinity/nodeSelector
- when calculating pod topology spread skew.
- Options are: - Honor: only nodes matching
- nodeAffinity/nodeSelector are included
- in the calculations. - Ignore: nodeAffinity/nodeSelector
- are ignored. All nodes are included in
- the calculations. \n If this value is
- nil, the behavior is equivalent to the
- Honor policy. This is a alpha-level feature
- enabled by the NodeInclusionPolicyInPodTopologySpread
- feature flag."
- type: string
- nodeTaintsPolicy:
- description:
- "NodeTaintsPolicy indicates
- how we will treat node taints when calculating
- pod topology spread skew. Options are:
- - Honor: nodes without taints, along with
- tainted nodes for which the incoming pod
- has a toleration, are included. - Ignore:
- node taints are ignored. All nodes are
- included. \n If this value is nil, the
- behavior is equivalent to the Ignore policy.
- This is a alpha-level feature enabled
- by the NodeInclusionPolicyInPodTopologySpread
- feature flag."
- type: string
- topologyKey:
- description:
- TopologyKey is the key of node
- labels. Nodes that have a label with this
- key and identical values are considered
- to be in the same topology. We consider
- each <key, value> as a "bucket", and try
- to put balanced number of pods into each
- bucket. We define a domain as a particular
- instance of a topology. Also, we define
- an eligible domain as a domain whose nodes
- meet the requirements of nodeAffinityPolicy
- and nodeTaintsPolicy. e.g. If TopologyKey
- is "kubernetes.io/hostname", each Node
- is a domain of that topology. And, if
- TopologyKey is "topology.kubernetes.io/zone",
- each zone is a domain of that topology.
- It's a required field.
- type: string
- whenUnsatisfiable:
- description:
- 'WhenUnsatisfiable indicates
- how to deal with a pod if it doesn''t
- satisfy the spread constraint. - DoNotSchedule
- (default) tells the scheduler not to schedule
- it. - ScheduleAnyway tells the scheduler
- to schedule the pod in any location, but
- giving higher precedence to topologies
- that would help reduce the skew. A constraint
- is considered "Unsatisfiable" for an incoming
- pod if and only if every possible node
- assignment for that pod would violate
- "MaxSkew" on some topology. For example,
- in a 3-zone cluster, MaxSkew is set to
- 1, and pods with the same labelSelector
- spread as 3/1/1: | zone1 | zone2 | zone3
- | | P P P | P | P | If WhenUnsatisfiable
- is set to DoNotSchedule, incoming pod
- can only be scheduled to zone2(zone3)
- to become 3/2/1(3/1/2) as ActualSkew(2-1)
- on zone2(zone3) satisfies MaxSkew(1).
- In other words, the cluster can still
- be imbalanced, but scheduler won''t make
- it *more* imbalanced. It''s a required
- field.'
- type: string
- required:
- - maxSkew
- - topologyKey
- - whenUnsatisfiable
- type: object
- type: array
- type: object
- type: object
- type: object
- type: object
- typhaMetricsPort:
- description:
- TyphaMetricsPort specifies which port calico/typha
- serves prometheus metrics on. By default, metrics are not enabled.
- format: int32
- type: integer
- variant:
- description:
- "Variant is the product to install - one of Calico
- or TigeraSecureEnterprise Default: Calico"
- enum:
- - Calico
- - TigeraSecureEnterprise
- type: string
- type: object
- conditions:
- description:
- Conditions represents the latest observed set of conditions
- for the component. A component may be one or more of Ready, Progressing,
- Degraded or other customer types.
- items:
- description:
- "Condition contains details for one aspect of the current
- state of this API Resource. --- This struct is intended for direct
- use as an array at the field path .status.conditions. For example,
- \n type FooStatus struct{ // Represents the observations of a
- foo's current state. // Known .status.conditions.type are: \"Available\",
- \"Progressing\", and \"Degraded\" // +patchMergeKey=type // +patchStrategy=merge
- // +listType=map // +listMapKey=type Conditions []metav1.Condition
- `json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\"
- protobuf:\"bytes,1,rep,name=conditions\"` \n // other fields }"
- properties:
- lastTransitionTime:
- description:
- lastTransitionTime is the last time the condition
- transitioned from one status to another. This should be when
- the underlying condition changed. If that is not known, then
- using the time when the API field changed is acceptable.
- format: date-time
- type: string
- message:
- description:
- message is a human readable message indicating
- details about the transition. This may be an empty string.
- maxLength: 32768
- type: string
- observedGeneration:
- description:
- observedGeneration represents the .metadata.generation
- that the condition was set based upon. For instance, if .metadata.generation
- is currently 12, but the .status.conditions[x].observedGeneration
- is 9, the condition is out of date with respect to the current
- state of the instance.
- format: int64
- minimum: 0
- type: integer
- reason:
- description:
- reason contains a programmatic identifier indicating
- the reason for the condition's last transition. Producers
- of specific condition types may define expected values and
- meanings for this field, and whether the values are considered
- a guaranteed API. The value should be a CamelCase string.
- This field may not be empty.
- maxLength: 1024
- minLength: 1
- pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
- type: string
- status:
- description: status of the condition, one of True, False, Unknown.
- enum:
- - "True"
- - "False"
- - Unknown
- type: string
- type:
- description:
- type of condition in CamelCase or in foo.example.com/CamelCase.
- --- Many .condition.type values are consistent across resources
- like Available, but because arbitrary conditions can be useful
- (see .node.status.conditions), the ability to deconflict is
- important. The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
- maxLength: 316
- pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
- type: string
- required:
- - lastTransitionTime
- - message
- - reason
- - status
- - type
- type: object
- type: array
- imageSet:
- description:
- ImageSet is the name of the ImageSet being used, if there
- is an ImageSet that is being used. If an ImageSet is not being used
- then this will not be set.
- type: string
- mtu:
- description:
- MTU is the most recently observed value for pod network
- MTU. This may be an explicitly configured value, or based on Calico's
- native auto-detetion.
- format: int32
- type: integer
- variant:
- description:
- Variant is the most recently observed installed variant
- - one of Calico or TigeraSecureEnterprise
- enum:
- - Calico
- - TigeraSecureEnterprise
- type: string
- type: object
- type: object
- served: true
- storage: true
- subresources:
- status: {}
-
----
-# Source: crds/operator.tigera.io_tigerastatuses_crd.yaml
-apiVersion: apiextensions.k8s.io/v1
-kind: CustomResourceDefinition
-metadata:
- annotations:
- controller-gen.kubebuilder.io/version: v0.3.0
- name: tigerastatuses.operator.tigera.io
-spec:
- group: operator.tigera.io
- names:
- kind: TigeraStatus
- listKind: TigeraStatusList
- plural: tigerastatuses
- singular: tigerastatus
- scope: Cluster
- versions:
- - additionalPrinterColumns:
- - description: Whether the component running and stable.
- jsonPath: .status.conditions[?(@.type=='Available')].status
- name: Available
- type: string
- - description: Whether the component is processing changes.
- jsonPath: .status.conditions[?(@.type=='Progressing')].status
- name: Progressing
- type: string
- - description: Whether the component is degraded.
- jsonPath: .status.conditions[?(@.type=='Degraded')].status
- name: Degraded
- type: string
- - description: The time the component's Available status last changed.
- jsonPath: .status.conditions[?(@.type=='Available')].lastTransitionTime
- name: Since
- type: date
- name: v1
- schema:
- openAPIV3Schema:
- description:
- TigeraStatus represents the most recently observed status for
- Calico or a Calico Enterprise functional area.
- properties:
- apiVersion:
- description:
- "APIVersion defines the versioned schema of this representation
- of an object. Servers should convert recognized schemas to the latest
- internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources"
- type: string
- kind:
- description:
- "Kind is a string value representing the REST resource this
- object represents. Servers may infer this from the endpoint the client
- submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds"
- type: string
- metadata:
- type: object
- spec:
- description: TigeraStatusSpec defines the desired state of TigeraStatus
- type: object
- status:
- description: TigeraStatusStatus defines the observed state of TigeraStatus
- properties:
- conditions:
- description:
- Conditions represents the latest observed set of conditions
- for this component. A component may be one or more of Available,
- Progressing, or Degraded.
- items:
- description:
- TigeraStatusCondition represents a condition attached
- to a particular component.
- properties:
- lastTransitionTime:
- description:
- The timestamp representing the start time for the
- current status.
- format: date-time
- type: string
- message:
- description:
- Optionally, a detailed message providing additional
- context.
- type: string
- observedGeneration:
- description:
- observedGeneration represents the generation that
- the condition was set based upon. For instance, if generation
- is currently 12, but the .status.conditions[x].observedGeneration
- is 9, the condition is out of date with respect to the current
- state of the instance.
- format: int64
- type: integer
- reason:
- description: A brief reason explaining the condition.
- type: string
- status:
- description:
- The status of the condition. May be True, False,
- or Unknown.
- type: string
- type:
- description:
- The type of condition. May be Available, Progressing,
- or Degraded.
- type: string
- required:
- - lastTransitionTime
- - status
- - type
- type: object
- type: array
- required:
- - conditions
- type: object
- type: object
- served: true
- storage: true
- subresources:
- status: {}
-status:
- acceptedNames:
- kind: ""
- plural: ""
- conditions: []
- storedVersions: []
-
----
-# Source: tigera-operator/templates/tigera-operator/02-serviceaccount-tigera-operator.yaml
-apiVersion: v1
-kind: ServiceAccount
-metadata:
- name: tigera-operator
- namespace: tigera-operator
-imagePullSecrets: []
----
-# Source: tigera-operator/templates/tigera-operator/02-role-tigera-operator.yaml
-# Permissions required when running the operator for a Calico cluster.
-apiVersion: rbac.authorization.k8s.io/v1
-kind: ClusterRole
-metadata:
- name: tigera-operator
-rules:
- - apiGroups:
- - ""
- resources:
- - namespaces
- - pods
- - podtemplates
- - services
- - endpoints
- - events
- - configmaps
- - secrets
- - serviceaccounts
- verbs:
- - create
- - get
- - list
- - update
- - delete
- - watch
- - apiGroups:
- - ""
- resources:
- - resourcequotas
- verbs:
- - list
- - get
- - watch
- - apiGroups:
- - ""
- resources:
- - resourcequotas
- verbs:
- - create
- - get
- - list
- - update
- - delete
- - watch
- resourceNames:
- - calico-critical-pods
- - tigera-critical-pods
- - apiGroups:
- - ""
- resources:
- - nodes
- verbs:
- # Need to update node labels when migrating nodes.
- - get
- - patch
- - list
- # We need this for Typha autoscaling
- - watch
- - apiGroups:
- - rbac.authorization.k8s.io
- resources:
- - clusterroles
- - clusterrolebindings
- - rolebindings
- - roles
- verbs:
- - create
- - get
- - list
- - update
- - delete
- - watch
- - bind
- - escalate
- - apiGroups:
- - apps
- resources:
- - deployments
- - daemonsets
- - statefulsets
- verbs:
- - create
- - get
- - list
- - patch
- - update
- - delete
- - watch
- - apiGroups:
- - apps
- resourceNames:
- - tigera-operator
- resources:
- - deployments/finalizers
- verbs:
- - update
- - apiGroups:
- - operator.tigera.io
- resources:
- - "*"
- verbs:
- - create
- - get
- - list
- - update
- - patch
- - delete
- - watch
- - apiGroups:
- - networking.k8s.io
- resources:
- - networkpolicies
- verbs:
- - create
- - update
- - delete
- - get
- - list
- - watch
- - apiGroups:
- - crd.projectcalico.org
- resources:
- - felixconfigurations
- verbs:
- - create
- - patch
- - list
- - get
- - watch
- - apiGroups:
- - crd.projectcalico.org
- resources:
- - ippools
- - kubecontrollersconfigurations
- - bgpconfigurations
- verbs:
- - get
- - list
- - watch
- - apiGroups:
- - scheduling.k8s.io
- resources:
- - priorityclasses
- verbs:
- - create
- - get
- - list
- - update
- - delete
- - watch
- - apiGroups:
- - policy
- resources:
- - poddisruptionbudgets
- verbs:
- - create
- - get
- - list
- - update
- - delete
- - watch
- - apiGroups:
- - apiregistration.k8s.io
- resources:
- - apiservices
- verbs:
- - list
- - watch
- - create
- - update
- # Needed for operator lock
- - apiGroups:
- - coordination.k8s.io
- resources:
- - leases
- verbs:
- - create
- - get
- - list
- - update
- - delete
- - watch
- - apiGroups:
- - storage.k8s.io
- resources:
- - csidrivers
- verbs:
- - list
- - watch
- - update
- - get
- - create
- - delete
- # Add the appropriate pod security policy permissions
- - apiGroups:
- - policy
- resources:
- - podsecuritypolicies
- resourceNames:
- - tigera-operator
- verbs:
- - use
- - apiGroups:
- - policy
- resources:
- - podsecuritypolicies
- verbs:
- - get
- - list
- - watch
- - create
- - update
- - delete
- # Add the permissions to monitor the status of certificatesigningrequests when certificate management is enabled.
- - apiGroups:
- - certificates.k8s.io
- resources:
- - certificatesigningrequests
- verbs:
- - list
- - watch
----
-# Source: tigera-operator/templates/tigera-operator/02-rolebinding-tigera-operator.yaml
-kind: ClusterRoleBinding
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
- name: tigera-operator
-subjects:
- - kind: ServiceAccount
- name: tigera-operator
- namespace: tigera-operator
-roleRef:
- kind: ClusterRole
- name: tigera-operator
- apiGroup: rbac.authorization.k8s.io
----
-# Source: tigera-operator/templates/tigera-operator/02-tigera-operator.yaml
-apiVersion: apps/v1
-kind: Deployment
-metadata:
- name: tigera-operator
- namespace: tigera-operator
- labels:
- k8s-app: tigera-operator
-spec:
- replicas: 1
- selector:
- matchLabels:
- name: tigera-operator
- template:
- metadata:
- labels:
- name: tigera-operator
- k8s-app: tigera-operator
- spec:
- nodeSelector:
- kubernetes.io/os: linux
- tolerations:
- - effect: NoExecute
- operator: Exists
- - effect: NoSchedule
- operator: Exists
- serviceAccountName: tigera-operator
- hostNetwork: true
- # This must be set when hostNetwork is true or else the cluster services won't resolve
- dnsPolicy: ClusterFirstWithHostNet
- containers:
- - name: tigera-operator
- image: quay.io/tigera/operator:v1.30.4
- imagePullPolicy: IfNotPresent
- command:
- - operator
- volumeMounts:
- - name: var-lib-calico
- readOnly: true
- mountPath: /var/lib/calico
- env:
- - name: WATCH_NAMESPACE
- value: ""
- - name: POD_NAME
- valueFrom:
- fieldRef:
- fieldPath: metadata.name
- - name: OPERATOR_NAME
- value: "tigera-operator"
- - name: TIGERA_OPERATOR_INIT_IMAGE_VERSION
- value: v1.30.4
- envFrom:
- - configMapRef:
- name: kubernetes-services-endpoint
- optional: true
- volumes:
- - name: var-lib-calico
- hostPath:
- path: /var/lib/calico
diff --git a/infrastructure_old/controllers/capacitor.yaml b/infrastructure_old/controllers/capacitor.yaml
@@ -1,187 +0,0 @@
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: OCIRepository
-metadata:
- name: capacitor
- namespace: flux-system
-spec:
- interval: 12h
- url: oci://ghcr.io/gimlet-io/capacitor-manifests
- ref:
- semver: '>=0.3.0'
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrZktYSXB6dDgxV2d0TTdj
- Qm0zSzgxcStTa2ZyL0N2aG1MVEFBM0ozWDFVCnhFWS9iWUJyalpwSlJsWTVocUsw
- aEtxL280ZTh6TmNUaWI2WlQwc2tuQWcKLS0tIEUzK29HV0x3M0h2ajY5QlV1TERy
- V0E1R3ZETlBEWVFuWFBtSW5FQmtGSDQKuc9oZDqCLw4fW/BnvyJHyA4XfW/tfxRU
- Vi8Auuzda6DYcpChudMDQu4EIP86SfggX0qL8KepwLt37zRVqQzS4g==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-03-20T10:39:31Z"
- mac: ENC[AES256_GCM,data:LgClZ5tSKRgeYjNL7NJ6CHSOF4T3m8yr4tOCm+HWIIRi8BRY5VQLOHHyLFqX6CQt4AvSgiyMv/AMnHRMSqG5gRtPfrDq9tKWpTqe50OGi7h6I5DiWoDtpfYkN7YJXTYeT3OChv+AyYGzEyJN8v5slv+bMkLLZtNrmKSQKAjmhEg=,iv:g7Vm8y+31Wwwf1NFWkqqvPTWUAsXCmjAAY74hg4iQqM=,tag:ISGptzHAjoqF7r1MxoxUkw==,type:str]
- pgp: []
- encrypted_regex: ^(adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
----
-apiVersion: kustomize.toolkit.fluxcd.io/v1
-kind: Kustomization
-metadata:
- name: capacitor
- namespace: flux-system
-spec:
- targetNamespace: flux-system
- interval: 1h
- retryInterval: 2m
- timeout: 5m
- wait: true
- prune: true
- path: ./
- sourceRef:
- kind: OCIRepository
- name: capacitor
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrZktYSXB6dDgxV2d0TTdj
- Qm0zSzgxcStTa2ZyL0N2aG1MVEFBM0ozWDFVCnhFWS9iWUJyalpwSlJsWTVocUsw
- aEtxL280ZTh6TmNUaWI2WlQwc2tuQWcKLS0tIEUzK29HV0x3M0h2ajY5QlV1TERy
- V0E1R3ZETlBEWVFuWFBtSW5FQmtGSDQKuc9oZDqCLw4fW/BnvyJHyA4XfW/tfxRU
- Vi8Auuzda6DYcpChudMDQu4EIP86SfggX0qL8KepwLt37zRVqQzS4g==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-03-20T10:39:31Z"
- mac: ENC[AES256_GCM,data:LgClZ5tSKRgeYjNL7NJ6CHSOF4T3m8yr4tOCm+HWIIRi8BRY5VQLOHHyLFqX6CQt4AvSgiyMv/AMnHRMSqG5gRtPfrDq9tKWpTqe50OGi7h6I5DiWoDtpfYkN7YJXTYeT3OChv+AyYGzEyJN8v5slv+bMkLLZtNrmKSQKAjmhEg=,iv:g7Vm8y+31Wwwf1NFWkqqvPTWUAsXCmjAAY74hg4iQqM=,tag:ISGptzHAjoqF7r1MxoxUkw==,type:str]
- pgp: []
- encrypted_regex: ^(adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
----
-apiVersion: v1
-kind: Secret
-metadata:
- name: authsecret-capacitor
- namespace: flux-system
-type: kubernetes.io/basic-auth
-stringData:
- username: ENC[AES256_GCM,data:UXJgfJ3ZPQ==,iv:TWH++dcamk5d+ZDR6Vwxk7SF8J+Ciw0Ue7a9ANzDYcU=,tag:XFPb2OFK7GZ5w6t2g2jU6A==,type:str]
- password: ENC[AES256_GCM,data:r8xTZJ6oNaSs,iv:F6ur7klHQQwycKGXzYtIxEi49X+xzX/VXIsElgclGhE=,tag:iSzl0NWfuhthWeq1J3qwdw==,type:str]
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrZktYSXB6dDgxV2d0TTdj
- Qm0zSzgxcStTa2ZyL0N2aG1MVEFBM0ozWDFVCnhFWS9iWUJyalpwSlJsWTVocUsw
- aEtxL280ZTh6TmNUaWI2WlQwc2tuQWcKLS0tIEUzK29HV0x3M0h2ajY5QlV1TERy
- V0E1R3ZETlBEWVFuWFBtSW5FQmtGSDQKuc9oZDqCLw4fW/BnvyJHyA4XfW/tfxRU
- Vi8Auuzda6DYcpChudMDQu4EIP86SfggX0qL8KepwLt37zRVqQzS4g==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-03-20T10:39:31Z"
- mac: ENC[AES256_GCM,data:LgClZ5tSKRgeYjNL7NJ6CHSOF4T3m8yr4tOCm+HWIIRi8BRY5VQLOHHyLFqX6CQt4AvSgiyMv/AMnHRMSqG5gRtPfrDq9tKWpTqe50OGi7h6I5DiWoDtpfYkN7YJXTYeT3OChv+AyYGzEyJN8v5slv+bMkLLZtNrmKSQKAjmhEg=,iv:g7Vm8y+31Wwwf1NFWkqqvPTWUAsXCmjAAY74hg4iQqM=,tag:ISGptzHAjoqF7r1MxoxUkw==,type:str]
- pgp: []
- encrypted_regex: ^(adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
----
-apiVersion: traefik.io/v1alpha1
-kind: Middleware
-metadata:
- name: capacitor-auth
- namespace: flux-system
-spec:
- basicAuth:
- secret: ENC[AES256_GCM,data:JSbclJt+aYOr8x/9sfHZjn+FQ4w=,iv:nLtD9Oixdec81dNEGW+z8a86/tn/Q6rJLrfrzUMdeFE=,tag:aqAqedpaGEEw7ranGfY3PA==,type:str]
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrZktYSXB6dDgxV2d0TTdj
- Qm0zSzgxcStTa2ZyL0N2aG1MVEFBM0ozWDFVCnhFWS9iWUJyalpwSlJsWTVocUsw
- aEtxL280ZTh6TmNUaWI2WlQwc2tuQWcKLS0tIEUzK29HV0x3M0h2ajY5QlV1TERy
- V0E1R3ZETlBEWVFuWFBtSW5FQmtGSDQKuc9oZDqCLw4fW/BnvyJHyA4XfW/tfxRU
- Vi8Auuzda6DYcpChudMDQu4EIP86SfggX0qL8KepwLt37zRVqQzS4g==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-03-20T10:39:31Z"
- mac: ENC[AES256_GCM,data:LgClZ5tSKRgeYjNL7NJ6CHSOF4T3m8yr4tOCm+HWIIRi8BRY5VQLOHHyLFqX6CQt4AvSgiyMv/AMnHRMSqG5gRtPfrDq9tKWpTqe50OGi7h6I5DiWoDtpfYkN7YJXTYeT3OChv+AyYGzEyJN8v5slv+bMkLLZtNrmKSQKAjmhEg=,iv:g7Vm8y+31Wwwf1NFWkqqvPTWUAsXCmjAAY74hg4iQqM=,tag:ISGptzHAjoqF7r1MxoxUkw==,type:str]
- pgp: []
- encrypted_regex: ^(adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
----
-apiVersion: networking.k8s.io/v1
-kind: Ingress
-metadata:
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- traefik.ingress.kubernetes.io/router.middlewares: flux-system-capacitor-auth@kubernetescrd
- name: capacitor
- namespace: flux-system
-spec:
- rules:
- - host: ui.k8s.midnightthoughts.space
- http:
- paths:
- - backend:
- service:
- name: capacitor
- port:
- name: http
- path: /
- pathType: ImplementationSpecific
- tls:
- - hosts:
- - ui.k8s.midnightthoughts.space
- secretName: ui.k8s.midnightthoughts.space-tls
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBrZktYSXB6dDgxV2d0TTdj
- Qm0zSzgxcStTa2ZyL0N2aG1MVEFBM0ozWDFVCnhFWS9iWUJyalpwSlJsWTVocUsw
- aEtxL280ZTh6TmNUaWI2WlQwc2tuQWcKLS0tIEUzK29HV0x3M0h2ajY5QlV1TERy
- V0E1R3ZETlBEWVFuWFBtSW5FQmtGSDQKuc9oZDqCLw4fW/BnvyJHyA4XfW/tfxRU
- Vi8Auuzda6DYcpChudMDQu4EIP86SfggX0qL8KepwLt37zRVqQzS4g==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2024-03-20T10:39:31Z"
- mac: ENC[AES256_GCM,data:LgClZ5tSKRgeYjNL7NJ6CHSOF4T3m8yr4tOCm+HWIIRi8BRY5VQLOHHyLFqX6CQt4AvSgiyMv/AMnHRMSqG5gRtPfrDq9tKWpTqe50OGi7h6I5DiWoDtpfYkN7YJXTYeT3OChv+AyYGzEyJN8v5slv+bMkLLZtNrmKSQKAjmhEg=,iv:g7Vm8y+31Wwwf1NFWkqqvPTWUAsXCmjAAY74hg4iQqM=,tag:ISGptzHAjoqF7r1MxoxUkw==,type:str]
- pgp: []
- encrypted_regex: ^(adminPassword|configPassword|adminUser|configUser|APP_KEY|api_key|api_secret|keys|livekit_key|livekit_secret|secret_key|adminPassword|admin_pass|admin_email|mariadbPassword|mariadbRootPassword|privateKey|data|stringData|PASSWD|password|pass|postgresPassword|postgresqlPassword|redminePassword|smtpPassword|registration_shared_secret|shared_secret|secret)$
- version: 3.8.1
----
-apiVersion: networking.k8s.io/v1
-kind: NetworkPolicy
-metadata:
- name: allow-capacitor
- namespace: flux-system
-spec:
- podSelector:
- matchLabels:
- app.kubernetes.io/instance: "capacitor"
- ingress:
- - ports:
- - protocol: TCP
- port: 9000
- policyTypes:
- - Ingress
diff --git a/infrastructure_old/controllers/cert-manager.yaml b/infrastructure_old/controllers/cert-manager.yaml
@@ -1,78 +0,0 @@
----
-apiVersion: v1
-kind: Namespace
-metadata:
- name: cert-manager
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: cert-manager
- namespace: cert-manager
-spec:
- interval: 24h
- url: https://charts.jetstack.io
----
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: cert-manager
- namespace: cert-manager
-spec:
- interval: 30m
- chart:
- spec:
- chart: cert-manager
- version: "1.x"
- sourceRef:
- kind: HelmRepository
- name: cert-manager
- namespace: cert-manager
- interval: 12h
- values:
- extraArgs:
- - "--feature-gates=ExperimentalGatewayAPISupport=true"
- installCRDs: true
- enableCertificateOwnerRef: false
- tolerations:
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
- webhook:
- tolerations:
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
- cainjector:
- tolerations:
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
- startupapicheck:
- tolerations:
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
- prometheus:
- servicemonitor:
- enabled: true
----
-apiVersion: networking.k8s.io/v1
-kind: NetworkPolicy
-metadata:
- name: allow-certmanager-ingress
- namespace: flux-system
-spec:
- podSelector:
- matchLabels:
- acme.cert-manager.io/http01-solver: "true"
- ingress:
- - ports:
- - protocol: TCP
- port: 8089
- policyTypes:
- - Ingress
diff --git a/infrastructure_old/controllers/descheduler.yaml b/infrastructure_old/controllers/descheduler.yaml
@@ -1,71 +0,0 @@
----
-apiVersion: v1
-kind: Namespace
-metadata:
- name: descheduler
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: descheduler
- namespace: descheduler
-spec:
- interval: 24h
- url: https://kubernetes-sigs.github.io/descheduler/
----
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: descheduler
- namespace: descheduler
-spec:
- interval: 30m
- chart:
- spec:
- chart: descheduler
- version: "0.29.0"
- sourceRef:
- kind: HelmRepository
- name: descheduler
- namespace: descheduler
- interval: 12h
- values:
- tolerations:
- - key: "arch"
- operator: "Equal"
- value: "arm64"
- effect: "NoSchedule"
- service:
- enabled: true
- ipFamilyPolicy: PreferDualStack
- ipFamilies:
- - IPv6
- - IPv4
- serviceMonitor:
- enabled: true
- deschedulerPolicy:
- strategies:
- RemoveDuplicates:
- enabled: false
- RemovePodsHavingTooManyRestarts:
- enabled: false
- RemovePodsViolatingNodeTaints:
- enabled: false
- RemovePodsViolatingNodeAffinity:
- enabled: false
- RemovePodsViolatingInterPodAntiAffinity:
- enabled: false
- RemovePodsViolatingTopologySpreadConstraint:
- enabled: false
- LowNodeUtilization:
- enabled: true
- params:
- nodeResourceUtilizationThresholds:
- thresholds:
- cpu: 20
- memory: 20
- pods: 20
- targetThresholds:
- cpu: 50
- memory: 50
- pods: 50
diff --git a/infrastructure_old/controllers/image-updater.yaml b/infrastructure_old/controllers/image-updater.yaml
@@ -1,26 +0,0 @@
-
----
-apiVersion: image.toolkit.fluxcd.io/v1beta1
-kind: ImageUpdateAutomation
-metadata:
- name: flux-system
- namespace: flux-system
-spec:
- interval: 1m0s
- sourceRef:
- kind: GitRepository
- name: flux-system
- git:
- checkout:
- ref:
- branch: main
- commit:
- author:
- email: fluxcdbot@users.noreply.gitea
- name: fluxcdbot
- messageTemplate: "{{range .Updated.Images}}{{println .}}{{end}}"
- push:
- branch: main
- update:
- path: ./
- strategy: Setters
diff --git a/infrastructure_old/controllers/kube-router.yaml b/infrastructure_old/controllers/kube-router.yaml
@@ -1,198 +0,0 @@
----
-apiVersion: v1
-kind: ConfigMap
-metadata:
- name: kube-router-cfg
- namespace: kube-system
- labels:
- tier: node
- k8s-app: kube-router
-data:
- cni-conf.json: |
- {
- "cniVersion":"0.3.0",
- "name":"mynet",
- "plugins":[
- {
- "name":"kubernetes",
- "type":"bridge",
- "bridge":"kube-bridge",
- "isDefaultGateway":true,
- "ipam":{
- "type":"host-local"
- }
- }
- ]
- }
----
-apiVersion: apps/v1
-kind: DaemonSet
-metadata:
- labels:
- k8s-app: kube-router
- tier: node
- name: kube-router
- namespace: kube-system
-spec:
- selector:
- matchLabels:
- k8s-app: kube-router
- tier: node
- template:
- metadata:
- labels:
- k8s-app: kube-router
- tier: node
- spec:
- priorityClassName: system-node-critical
- serviceAccountName: kube-router
- serviceAccount: kube-router
- containers:
- - name: kube-router
- image: docker.io/cloudnativelabs/kube-router
- imagePullPolicy: Always
- args:
- - --run-router=true
- - --run-firewall=true
- - --run-service-proxy=true
- - --bgp-graceful-restart=true
- - --advertise-cluster-ip
- - "--enable-ipv4=true"
- - "--enable-ipv6=true"
- - "--service-cluster-ip-range=10.96.0.0/16"
- - "--service-cluster-ip-range=fc00:1::/112"
- #- --kubeconfig=/var/lib/kube-router/kubeconfig
- env:
- - name: NODE_NAME
- valueFrom:
- fieldRef:
- fieldPath: spec.nodeName
- - name: KUBE_ROUTER_CNI_CONF_FILE
- value: /etc/cni/net.d/10-kuberouter.conflist
- livenessProbe:
- httpGet:
- path: /healthz
- port: 20244
- initialDelaySeconds: 10
- periodSeconds: 3
- resources:
- requests:
- cpu: 250m
- memory: 250Mi
- securityContext:
- privileged: true
- volumeMounts:
- - name: lib-modules
- mountPath: /lib/modules
- readOnly: true
- - name: cni-conf-dir
- mountPath: /etc/cni/net.d
- #- name: kubeconfig
- # mountPath: /var/lib/kube-router
- # readOnly: true
- - name: xtables-lock
- mountPath: /run/xtables.lock
- readOnly: false
- initContainers:
- - name: install-cni
- image: docker.io/cloudnativelabs/kube-router
- imagePullPolicy: Always
- command:
- - /bin/sh
- - -c
- - set -e -x;
- if [ ! -f /etc/cni/net.d/10-kuberouter.conflist ]; then
- if [ -f /etc/cni/net.d/*.conf ]; then
- rm -f /etc/cni/net.d/*.conf;
- fi;
- TMP=/etc/cni/net.d/.tmp-kuberouter-cfg;
- cp /etc/kube-router/cni-conf.json ${TMP};
- mv ${TMP} /etc/cni/net.d/10-kuberouter.conflist;
- fi
- volumeMounts:
- - name: cni-conf-dir
- mountPath: /etc/cni/net.d
- - name: kube-router-cfg
- mountPath: /etc/kube-router
- hostNetwork: true
- tolerations:
- - effect: NoSchedule
- operator: Exists
- - key: CriticalAddonsOnly
- operator: Exists
- - effect: NoExecute
- operator: Exists
- volumes:
- - name: lib-modules
- hostPath:
- path: /lib/modules
- - name: cni-conf-dir
- hostPath:
- path: /etc/cni/net.d
- - name: kube-router-cfg
- configMap:
- name: kube-router-cfg
- #- name: kubeconfig
- # configMap:
- # name: kube-proxy
- # items:
- # - key: kubeconfig.conf
- # path: kubeconfig
- - name: xtables-lock
- hostPath:
- path: /run/xtables.lock
- type: FileOrCreate
----
-apiVersion: v1
-kind: ServiceAccount
-metadata:
- name: kube-router
- namespace: kube-system
----
-kind: ClusterRole
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
- name: kube-router
- namespace: kube-system
-rules:
- - apiGroups:
- - ""
- resources:
- - namespaces
- - pods
- - services
- - nodes
- - endpoints
- verbs:
- - list
- - get
- - watch
- - apiGroups:
- - "networking.k8s.io"
- resources:
- - networkpolicies
- verbs:
- - list
- - get
- - watch
- - apiGroups:
- - extensions
- resources:
- - networkpolicies
- verbs:
- - get
- - list
- - watch
----
-kind: ClusterRoleBinding
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
- name: kube-router
-roleRef:
- apiGroup: rbac.authorization.k8s.io
- kind: ClusterRole
- name: kube-router
-subjects:
- - kind: ServiceAccount
- name: kube-router
- namespace: kube-system
diff --git a/infrastructure_old/controllers/kube-router_old.yaml b/infrastructure_old/controllers/kube-router_old.yaml
@@ -1,166 +0,0 @@
----
-apiVersion: apps/v1
-kind: DaemonSet
-metadata:
- labels:
- k8s-app: kube-router
- tier: node
- annotations:
- checkov.io/skip1: CKV_K8S_20=The container needs to modify host network rules.
- checkov.io/skip2: CKV_K8S_19=The container needs to modify host network rules.
- checkov.io/skip3: CKV_K8S_38=The container needs to know values from the node.
- checkov.io/skip4: CKV_K8S_28=The container does bgp.
- prometheus.io/scrape: "true"
- prometheus.io/port: "8081"
- name: kube-router
- namespace: kube-system
-spec:
- selector:
- matchLabels:
- k8s-app: kube-router
- tier: node
- template:
- metadata:
- labels:
- k8s-app: kube-router
- tier: node
- spec:
- priorityClassName: system-node-critical
- serviceAccountName: kube-router
- containers:
- - name: kube-router
- image: docker.io/cloudnativelabs/kube-router:v2.0.0-rc3
- imagePullPolicy: Always
- args:
- - "--run-router=true"
- - "--run-firewall=false"
- - "--run-service-proxy=false"
- - "--enable-cni=false"
- - "--enable-pod-egress=false"
- - "--enable-ipv4=true"
- - "--enable-ipv6=true"
- - "--service-cluster-ip-range=10.96.0.0/16"
- - "--service-cluster-ip-range=fc00:1::/112"
- - "--enable-ibgp=true"
- - "--enable-overlay=true"
- - "--advertise-cluster-ip=true"
- - "--advertise-external-ip=true"
- - "--advertise-loadbalancer-ip=true"
- - "--overlay-type=full"
- #- "--bgp-graceful-restart=true"
- - "-v=3"
- #- "--peer-router-ips=<CHANGE ME>"
- #- "--peer-router-asns=<CHANGE ME>"
- #- "--cluster-asn=<CHANGE ME>"
- # Metrics
- - "--metrics-port=8081"
- env:
- - name: NODE_NAME
- valueFrom:
- fieldRef:
- fieldPath: spec.nodeName
- livenessProbe:
- httpGet:
- path: /healthz
- port: 20244
- initialDelaySeconds: 10
- periodSeconds: 3
- ports:
- - containerPort: 8081
- name: monitoring
- resources:
- requests:
- cpu: 250m
- memory: 250Mi
- securityContext:
- privileged: true
- volumeMounts:
- - name: xtables-lock
- mountPath: /run/xtables.lock
- readOnly: false
- hostNetwork: true
- tolerations:
- - effect: NoSchedule
- operator: Exists
- - key: CriticalAddonsOnly
- operator: Exists
- - effect: NoExecute
- operator: Exists
- volumes:
- - name: xtables-lock
- hostPath:
- path: /run/xtables.lock
- type: FileOrCreate
----
-apiVersion: v1
-kind: ServiceAccount
-metadata:
- name: kube-router
- namespace: kube-system
-
----
-kind: ClusterRole
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
- name: kube-router
- namespace: kube-system
-rules:
- - apiGroups:
- - ""
- resources:
- - namespaces
- - pods
- - services
- - nodes
- - endpoints
- verbs:
- - list
- - get
- - watch
- - apiGroups:
- - "networking.k8s.io"
- resources:
- - networkpolicies
- verbs:
- - list
- - get
- - watch
- - apiGroups:
- - extensions
- resources:
- - networkpolicies
- verbs:
- - get
- - list
- - watch
-
----
-kind: ClusterRoleBinding
-apiVersion: rbac.authorization.k8s.io/v1
-metadata:
- name: kube-router
-roleRef:
- apiGroup: rbac.authorization.k8s.io
- kind: ClusterRole
- name: kube-router
-subjects:
- - kind: ServiceAccount
- name: kube-router
- namespace: kube-system
----
-apiVersion: monitoring.coreos.com/v1
-kind: PodMonitor
-metadata:
- name: kube-router
- namespace: kube-system
-spec:
- namespaceSelector:
- matchNames:
- - "kube-system"
- podMetricsEndpoints:
- - interval: 5s
- path: /metrics
- port: monitoring
- selector:
- matchLabels:
- k8s-app: kube-router
diff --git a/infrastructure_old/controllers/kustomization.yaml b/infrastructure_old/controllers/kustomization.yaml
@@ -1,7 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-resources:
- - cert-manager.yaml
- - image-updater.yaml
- - descheduler.yaml
- - capacitor.yaml
diff --git a/infrastructure_old/controllers/metallb.yaml b/infrastructure_old/controllers/metallb.yaml
@@ -1,68 +0,0 @@
----
-apiVersion: v1
-kind: Namespace
-metadata:
- name: metallb-system
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: metallb
- namespace: metallb-system
-spec:
- interval: 24h
- url: https://metallb.github.io/metallb
----
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: metallb
- namespace: metallb-system
-spec:
- interval: 30m
- chart:
- spec:
- chart: metallb
- version: "0.13.x"
- sourceRef:
- kind: HelmRepository
- name: metallb
- namespace: metallb-system
- interval: 12h
- values:
- configInline: null
----
-# This was autogenerated by MetalLB's custom resource generator.
-apiVersion: metallb.io/v1beta1
-kind: IPAddressPool
-metadata:
- name: default
- namespace: metallb-system
-spec:
- autoAssign: false
- addresses:
- - 116.202.1.213/32
- - 65.21.116.73/32
- - 65.21.116.72/32
- # - 2a01:4f9:4a:451c:1000:1::/112
- # - fc00:1::/112
-
- # - 2a01:04f9:004a:451c:1000:0000:0000:0000-2a01:04f9:004a:451c:1fff:ffff:ffff:ffff
- - 2a01:4f9:4a:451c:1000::/68
-# - 2a01:4f9:4a:451c:1000::1/68
-# - 2a01:4f9:4a:451c:1000::2/68
-# This was autogenerated by MetalLB's custom resource generator.
----
-apiVersion: metallb.io/v1beta1
-kind: L2Advertisement
-metadata:
- name: l2advertisement1
- namespace: metallb-system
-spec:
- ipAddressPools:
- - default
- interfaces:
- - enp35s0
- nodeSelectors:
- - matchLabels:
- kubernetes.io/hostname: "nordgedanken.dev"
diff --git a/infrastructure_old/controllers/weave-gitops.yaml b/infrastructure_old/controllers/weave-gitops.yaml
@@ -1,95 +0,0 @@
----
-apiVersion: source.toolkit.fluxcd.io/v1beta2
-kind: HelmRepository
-metadata:
- name: weave-gitops
- namespace: flux-system
-spec:
- type: oci
- interval: 60m0s
- url: oci://ghcr.io/weaveworks/charts
----
-apiVersion: helm.toolkit.fluxcd.io/v2beta2
-kind: HelmRelease
-metadata:
- name: weave-gitops
- namespace: flux-system
-spec:
- interval: 60m
- chart:
- spec:
- chart: weave-gitops
- version: "~4.0.36"
- sourceRef:
- kind: HelmRepository
- name: weave-gitops
- interval: 12h
- # https://github.com/weaveworks/weave-gitops/blob/main/charts/gitops-server/values.yaml
- values:
- resources:
- requests:
- cpu: 100m
- memory: 64Mi
- limits:
- cpu: 1
- memory: 512Mi
- adminUser:
- create: true
- username: mtrnord
- passwordHash: $2a$10$smVGWN9U0qRRzMMNLAipYO0wU12ADk/m2g.fLAVmPiw2Y478ohesi
- oidcSecret:
- create: false
- #additionalArgs:
- # - --auth-methods=oidc
- networkPolicy:
- create: true
- metrics:
- enabled: true
- ingress:
- enabled: true
- annotations:
- cert-manager.io/cluster-issuer: letsencrypt-http
- hosts:
- - host: weave.midnightthoughts.space
- paths:
- - path: /
- pathType: ImplementationSpecific
- tls:
- - secretName: weave.midnightthoughts.space-tls
- hosts:
- - weave.midnightthoughts.space
----
-apiVersion: notification.toolkit.fluxcd.io/v1beta2
-kind: Alert
-metadata:
- name: helm-weave-gitops
- namespace: flux-system
-spec:
- providerRef:
- name: matrix
- eventSeverity: info
- eventSources:
- - kind: HelmRepository
- name: weave-gitops
- - kind: HelmChart
- name: weave-gitops
- - kind: HelmRelease
- name: weave-gitops
- namespace: flux-system
----
-apiVersion: networking.k8s.io/v1
-kind: NetworkPolicy
-metadata:
- name: allow-weave
- namespace: flux-system
-spec:
- podSelector:
- matchLabels:
- app.kubernetes.io/instance: weave-gitops
- ingress:
- - ports:
- - protocol: TCP
- port: 9001
- policyTypes:
- - Ingress
-
diff --git a/infrastructure_old/monitoring/kustomization.yaml b/infrastructure_old/monitoring/kustomization.yaml
@@ -1,5 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-namespace: monitoring
-resources:
- - podmonitor.yaml
diff --git a/infrastructure_old/monitoring/podmonitor.yaml b/infrastructure_old/monitoring/podmonitor.yaml
@@ -1,29 +0,0 @@
-apiVersion: monitoring.coreos.com/v1
-kind: PodMonitor
-metadata:
- name: flux-system
- labels:
- app.kubernetes.io/part-of: flux
- app.kubernetes.io/component: monitoring
-spec:
- namespaceSelector:
- matchNames:
- - flux-system
- selector:
- matchExpressions:
- - key: app
- operator: In
- values:
- - helm-controller
- - source-controller
- - kustomize-controller
- - notification-controller
- - image-automation-controller
- - image-reflector-controller
- podMetricsEndpoints:
- - port: http-prom
- relabelings:
- # https://github.com/prometheus-operator/prometheus-operator/issues/4816
- - sourceLabels: [__meta_kubernetes_pod_phase]
- action: keep
- regex: Running
diff --git a/infrastructure_old/notifications/git-notifications.yaml b/infrastructure_old/notifications/git-notifications.yaml
@@ -1,24 +0,0 @@
----
-apiVersion: notification.toolkit.fluxcd.io/v1beta2
-kind: Provider
-metadata:
- name: flux-system-github
- namespace: flux-system
-spec:
- type: github
- address: https://github.com/MTRNord/cluster
- secretRef:
- name: github
----
-apiVersion: notification.toolkit.fluxcd.io/v1beta2
-kind: Alert
-metadata:
- name: deployment-status-github
- namespace: flux-system
-spec:
- providerRef:
- name: flux-system-github
- eventSeverity: info
- eventSources:
- - kind: Kustomization
- name: "*"
diff --git a/infrastructure_old/notifications/git-tokens.yaml b/infrastructure_old/notifications/git-tokens.yaml
@@ -1,55 +0,0 @@
-apiVersion: v1
-kind: Secret
-metadata:
- name: github
- namespace: flux-system
-stringData:
- token: ENC[AES256_GCM,data:qzoQxD/7x1Y5uG78H2pPe+OTsyHzOy479j4POMsz8SZG6Msaq3DOLg==,iv:i428K+sYlKNEiHyEgMP0Lm5r5ZQDmP3bkYAhaSIr1zo=,tag:RbD/AcVztPBybKa3k0x/Fg==,type:str]
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSByM1RWNDVwWlh1S0RlYW10
- bFVVaUlnc25WeEZneTlZQ1FZSVVCRTVYQ1RzCnlvTTNWNkdMVnJnUm51eURLRDlD
- bEZIK052RUxybDhPY0hQYU1sR044N1UKLS0tIFh4YUhZKzZWMlp3dEZETU56RDVp
- RU5KWnZuYkNtTmJVZlF3RVR4c1pPMGsKLwyOTF4JnvYNtdDUqh/m3Ofc7h6xLewb
- oiya8FBoRC1JNHEaq6sP/3GxXEdjU3wZB4sXQLXAFPMl7G5fXWgMtg==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2023-03-17T19:11:08Z"
- mac: ENC[AES256_GCM,data:kWCr87xTg2ZtqsR1K+34QAKoHABLc1wiPM4+RStR2K/AbVcOb3aIUiThY24cUrh/RDGsk0s0vkZTbS03LmxsjGrHhi9y749pHkstb+2kjsQFqS34Ba8zlJJEApl8MFbj8MYVHNVGuqrCSXNB08nXkVCHR35an+Gn0yqVqP8hMpE=,iv:t+tvpfwmG9UUX//FMxYQBNn0QfmSeRrQoVS4Y3mx0Xo=,tag:F6iJGdi55QLwC1KllSiCHg==,type:str]
- pgp: []
- encrypted_regex: ^(data|stringData)$
- version: 3.7.3
----
-apiVersion: v1
-kind: Secret
-metadata:
- name: gitea
- namespace: flux-system
-stringData:
- token: ENC[AES256_GCM,data:eDEX+k/zN01JhFAV/bEF9bv2ui53UDd4QubD2PbhsCmtD9DFlt6ieA==,iv:uj6efLEUhMk74AnbHtjZvBLHKOvQTYP2mrNYNaQWfuw=,tag:foc3ITS2zs2Fi7fHa9M2qw==,type:str]
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSByM1RWNDVwWlh1S0RlYW10
- bFVVaUlnc25WeEZneTlZQ1FZSVVCRTVYQ1RzCnlvTTNWNkdMVnJnUm51eURLRDlD
- bEZIK052RUxybDhPY0hQYU1sR044N1UKLS0tIFh4YUhZKzZWMlp3dEZETU56RDVp
- RU5KWnZuYkNtTmJVZlF3RVR4c1pPMGsKLwyOTF4JnvYNtdDUqh/m3Ofc7h6xLewb
- oiya8FBoRC1JNHEaq6sP/3GxXEdjU3wZB4sXQLXAFPMl7G5fXWgMtg==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2023-03-17T19:11:08Z"
- mac: ENC[AES256_GCM,data:kWCr87xTg2ZtqsR1K+34QAKoHABLc1wiPM4+RStR2K/AbVcOb3aIUiThY24cUrh/RDGsk0s0vkZTbS03LmxsjGrHhi9y749pHkstb+2kjsQFqS34Ba8zlJJEApl8MFbj8MYVHNVGuqrCSXNB08nXkVCHR35an+Gn0yqVqP8hMpE=,iv:t+tvpfwmG9UUX//FMxYQBNn0QfmSeRrQoVS4Y3mx0Xo=,tag:F6iJGdi55QLwC1KllSiCHg==,type:str]
- pgp: []
- encrypted_regex: ^(data|stringData)$
- version: 3.7.3
diff --git a/infrastructure_old/notifications/kustomization.yaml b/infrastructure_old/notifications/kustomization.yaml
@@ -1,7 +0,0 @@
-apiVersion: kustomize.config.k8s.io/v1beta1
-kind: Kustomization
-resources:
- - matrix-token.yaml
- - matrix-notifications.yaml
- - git-tokens.yaml
- - git-notifications.yaml
diff --git a/infrastructure_old/notifications/matrix-notifications.yaml b/infrastructure_old/notifications/matrix-notifications.yaml
@@ -1,28 +0,0 @@
----
-apiVersion: notification.toolkit.fluxcd.io/v1beta2
-kind: Provider
-metadata:
- name: matrix
- namespace: flux-system
-spec:
- type: matrix
- address: https://matrix.midnightthoughts.space
- channel: "!ZjzjALRuiBeaBxbHhE:nordgedanken.dev"
- secretRef:
- name: matrix-token
----
-apiVersion: notification.toolkit.fluxcd.io/v1beta2
-kind: Alert
-metadata:
- name: main-infos
- namespace: flux-system
-spec:
- summary: "production cluster"
- providerRef:
- name: matrix
- eventSeverity: error
- eventSources:
- - kind: GitRepository
- name: "*"
- - kind: Kustomization
- name: "*"
diff --git a/infrastructure_old/notifications/matrix-token.yaml b/infrastructure_old/notifications/matrix-token.yaml
@@ -1,28 +0,0 @@
-apiVersion: v1
-kind: Secret
-metadata:
- name: matrix-token
- namespace: flux-system
-type: Opaque
-stringData:
- token: ENC[AES256_GCM,data:+XVwTqYf2B6G9ztAZgoVaT8xYPUtzw2oqhFukvcvquRzyBS9PbD0zYwE,iv:h5XLS/RPEgdZHYZ6FWQNAyQIU8zwQGuRpJxj2miabAg=,tag:RIULAFgSZgALHXs7n3w1Mg==,type:str]
-sops:
- kms: []
- gcp_kms: []
- azure_kv: []
- hc_vault: []
- age:
- - recipient: age1esjyg2qfy49awv0ptkzvpk425adczjr38m37w2mmcahzc4p8n54sll2nzh
- enc: |
- -----BEGIN AGE ENCRYPTED FILE-----
- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IFgyNTUxOSBxZTRMUWRnbkdGZHNSSzNY
- SkJwV0d6M2VSSUtZOXNScURCZWxVY3BTdmlnCnRzZGlBdWx6REROeE1yNndxeW96
- bHFnbVB2YUNUeUw2aVd2SGlZcUNLUTgKLS0tIEhCL2FxYTVPcXMwSytjOTlLdjZU
- TGpjMnkzei9CZDlBMzdRVVNkaTBPelEK/T59q2EaCoUcjnrIm754xi5Eb6XkSbEg
- IhfV2b1PMdRoTdVBJ97qdTtHm/oAYcz35SFooacXvONMIT5YAlM3Aw==
- -----END AGE ENCRYPTED FILE-----
- lastmodified: "2023-03-17T17:09:47Z"
- mac: ENC[AES256_GCM,data:WHajvAJisTXdhbOuJhC/R3AiR5IDLq2nrKpeiZk0a254EUmmMRqGFm9xetUPnMO6xmtdk797gS2srDa6oT12nZrkhBaGDfm89gD6xtEnkzOc2bWL4VdVx6EvbzvzMMmFMi9TgtTLIelFS0gWxVgFh0mbSkYRcKchO0VH1N6cyMw=,iv:fAMtFdRx1sF51lnQGojw6rZYOfnNrr58T+IcEEwfuQw=,tag:0esnSovWBNhWC8Zrq/N2gQ==,type:str]
- pgp: []
- encrypted_regex: ^(data|stringData)$
- version: 3.7.3