commit e5d80b105dcfe2c3813ae745d9a1a71936ae0e71
parent 41c3d98368d879c7ba0419d8d72548064956ae06
Author: Marcel <MTRNord@users.noreply.github.com>
Date: Wed, 16 Oct 2024 19:36:11 +0200
Merge pull request #4 from MTRNord/update-flux
Update to flux version 2.4.0
Diffstat:
3 files changed, 701 insertions(+), 628 deletions(-)
diff --git a/apps/2024_cluster/postgres-operator-values.yaml b/apps/2024_cluster/postgres-operator-values.yaml
@@ -11,35 +11,35 @@ spec:
configKubernetes:
cluster_name_label: "midnightthoughts"
enable_readiness_probe: true
-# ---
-# apiVersion: helm.toolkit.fluxcd.io/v2beta2
-# kind: HelmRelease
-# metadata:
-# name: postgres-operator-ui
-# namespace: postgres-operator
-# spec:
-# chart:
-# spec:
-# version: "1.11.x"
-# values:
-# envs:
-# teams:
-# - "midnightthoughts"
-# - "matrix"
-# superuser_team: "midnightthoughts"
-# targetNamespace: "*"
-# operatorClusterNameLabel: "midnightthoughts"
-# ingress:
-# enabled: true
-# annotations:
-# traefik.ingress.kubernetes.io/router.middlewares: traefik-ingress-sso@kubernetescrd
-# cert-manager.io/cluster-issuer: letsencrypt-dns
-# hosts:
-# - host: postgres-ui.midnightthoughts.space
-# paths: ["/"]
-# tls:
-# - secretName: postgres-ui.midnightthoughts.space-tls
-# hosts:
-# - postgres-ui.midnightthoughts.space
-# configKubernetes:
-# enable_pod_antiaffinity: true
+ # ---
+ # apiVersion: helm.toolkit.fluxcd.io/v2beta2
+ # kind: HelmRelease
+ # metadata:
+ # name: postgres-operator-ui
+ # namespace: postgres-operator
+ # spec:
+ # chart:
+ # spec:
+ # version: "1.11.x"
+ # values:
+ # envs:
+ # teams:
+ # - "midnightthoughts"
+ # - "matrix"
+ # superuser_team: "midnightthoughts"
+ # targetNamespace: "*"
+ # operatorClusterNameLabel: "midnightthoughts"
+ # ingress:
+ # enabled: true
+ # annotations:
+ # traefik.ingress.kubernetes.io/router.middlewares: traefik-ingress-sso@kubernetescrd
+ # cert-manager.io/cluster-issuer: letsencrypt-dns
+ # hosts:
+ # - host: postgres-ui.midnightthoughts.space
+ # paths: ["/"]
+ # tls:
+ # - secretName: postgres-ui.midnightthoughts.space-tls
+ # hosts:
+ # - postgres-ui.midnightthoughts.space
+ # configKubernetes:
+ # enable_pod_antiaffinity: true
diff --git a/apps/base/traefik-sso/deployment.yaml b/apps/base/traefik-sso/deployment.yaml
@@ -55,7 +55,7 @@ spec:
value: "false"
- name: DEFAULT_PROVIDER
value: "oidc"
- # - name: URL_PATH
+ # - name: URL_PATH
# value: /_oauth
#- name: WHITELIST
# value: joooostb@gmail.com
diff --git a/clusters/2024_cluster/flux-system/gotk-components.yaml b/clusters/2024_cluster/flux-system/gotk-components.yaml
@@ -1,5 +1,5 @@
# This manifest was generated by flux. DO NOT EDIT.
-# Flux Version: v2.3.0
+# Flux Version: v2.4.0
# Components: source-controller,kustomize-controller,helm-controller,notification-controller,image-reflector-controller,image-automation-controller
apiVersion: v1
kind: Namespace
@@ -7,7 +7,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
pod-security.kubernetes.io/warn: restricted
pod-security.kubernetes.io/warn-version: latest
name: flux-system
@@ -18,7 +18,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: allow-egress
namespace: flux-system
spec:
@@ -38,7 +38,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: allow-scraping
namespace: flux-system
spec:
@@ -58,7 +58,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: allow-webhooks
namespace: flux-system
spec:
@@ -77,7 +77,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: critical-pods-flux-system
namespace: flux-system
spec:
@@ -97,7 +97,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: crd-controller-flux-system
rules:
- apiGroups:
@@ -191,7 +191,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
rbac.authorization.k8s.io/aggregate-to-admin: "true"
rbac.authorization.k8s.io/aggregate-to-edit: "true"
name: flux-edit-flux-system
@@ -217,7 +217,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
rbac.authorization.k8s.io/aggregate-to-admin: "true"
rbac.authorization.k8s.io/aggregate-to-edit: "true"
rbac.authorization.k8s.io/aggregate-to-view: "true"
@@ -242,7 +242,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: cluster-reconciler-flux-system
roleRef:
apiGroup: rbac.authorization.k8s.io
@@ -262,7 +262,7 @@ metadata:
labels:
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: crd-controller-flux-system
roleRef:
apiGroup: rbac.authorization.k8s.io
@@ -292,12 +292,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: source-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: buckets.source.toolkit.fluxcd.io
spec:
group: source.toolkit.fluxcd.io
@@ -312,6 +312,350 @@ spec:
- jsonPath: .spec.endpoint
name: Endpoint
type: string
+ - jsonPath: .metadata.creationTimestamp
+ name: Age
+ type: date
+ - jsonPath: .status.conditions[?(@.type=="Ready")].status
+ name: Ready
+ type: string
+ - jsonPath: .status.conditions[?(@.type=="Ready")].message
+ name: Status
+ type: string
+ name: v1
+ schema:
+ openAPIV3Schema:
+ description: Bucket is the Schema for the buckets API.
+ properties:
+ apiVersion:
+ description: |-
+ APIVersion defines the versioned schema of this representation of an object.
+ Servers should convert recognized schemas to the latest internal value, and
+ may reject unrecognized values.
+ More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
+ type: string
+ kind:
+ description: |-
+ Kind is a string value representing the REST resource this object represents.
+ Servers may infer this from the endpoint the client submits requests to.
+ Cannot be updated.
+ In CamelCase.
+ More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
+ type: string
+ metadata:
+ type: object
+ spec:
+ description: |-
+ BucketSpec specifies the required configuration to produce an Artifact for
+ an object storage bucket.
+ properties:
+ bucketName:
+ description: BucketName is the name of the object storage bucket.
+ type: string
+ certSecretRef:
+ description: |-
+ CertSecretRef can be given the name of a Secret containing
+ either or both of
+
+ - a PEM-encoded client certificate (`tls.crt`) and private
+ key (`tls.key`);
+ - a PEM-encoded CA certificate (`ca.crt`)
+
+ and whichever are supplied, will be used for connecting to the
+ bucket. The client cert and key are useful if you are
+ authenticating with a certificate; the CA cert is useful if
+ you are using a self-signed server certificate. The Secret must
+ be of type `Opaque` or `kubernetes.io/tls`.
+
+ This field is only supported for the `generic` provider.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
+ endpoint:
+ description: Endpoint is the object storage address the BucketName is located at.
+ type: string
+ ignore:
+ description: |-
+ Ignore overrides the set of excluded patterns in the .sourceignore format
+ (which is the same as .gitignore). If not provided, a default will be used,
+ consult the documentation for your version to find out what those are.
+ type: string
+ insecure:
+ description: Insecure allows connecting to a non-TLS HTTP Endpoint.
+ type: boolean
+ interval:
+ description: |-
+ Interval at which the Bucket Endpoint is checked for updates.
+ This interval is approximate and may be subject to jitter to ensure
+ efficient use of resources.
+ pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$
+ type: string
+ prefix:
+ description: Prefix to use for server-side filtering of files in the Bucket.
+ type: string
+ provider:
+ default: generic
+ description: |-
+ Provider of the object storage bucket.
+ Defaults to 'generic', which expects an S3 (API) compatible object
+ storage.
+ enum:
+ - generic
+ - aws
+ - gcp
+ - azure
+ type: string
+ proxySecretRef:
+ description: |-
+ ProxySecretRef specifies the Secret containing the proxy configuration
+ to use while communicating with the Bucket server.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
+ region:
+ description: Region of the Endpoint where the BucketName is located in.
+ type: string
+ secretRef:
+ description: |-
+ SecretRef specifies the Secret containing authentication credentials
+ for the Bucket.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
+ sts:
+ description: |-
+ STS specifies the required configuration to use a Security Token
+ Service for fetching temporary credentials to authenticate in a
+ Bucket provider.
+
+ This field is only supported for the `aws` and `generic` providers.
+ properties:
+ certSecretRef:
+ description: |-
+ CertSecretRef can be given the name of a Secret containing
+ either or both of
+
+ - a PEM-encoded client certificate (`tls.crt`) and private
+ key (`tls.key`);
+ - a PEM-encoded CA certificate (`ca.crt`)
+
+ and whichever are supplied, will be used for connecting to the
+ STS endpoint. The client cert and key are useful if you are
+ authenticating with a certificate; the CA cert is useful if
+ you are using a self-signed server certificate. The Secret must
+ be of type `Opaque` or `kubernetes.io/tls`.
+
+ This field is only supported for the `ldap` provider.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
+ endpoint:
+ description: |-
+ Endpoint is the HTTP/S endpoint of the Security Token Service from
+ where temporary credentials will be fetched.
+ pattern: ^(http|https)://.*$
+ type: string
+ provider:
+ description: Provider of the Security Token Service.
+ enum:
+ - aws
+ - ldap
+ type: string
+ secretRef:
+ description: |-
+ SecretRef specifies the Secret containing authentication credentials
+ for the STS endpoint. This Secret must contain the fields `username`
+ and `password` and is supported only for the `ldap` provider.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
+ required:
+ - endpoint
+ - provider
+ type: object
+ suspend:
+ description: |-
+ Suspend tells the controller to suspend the reconciliation of this
+ Bucket.
+ type: boolean
+ timeout:
+ default: 60s
+ description: Timeout for fetch operations, defaults to 60s.
+ pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$
+ type: string
+ required:
+ - bucketName
+ - endpoint
+ - interval
+ type: object
+ x-kubernetes-validations:
+ - message: STS configuration is only supported for the 'aws' and 'generic' Bucket providers
+ rule: self.provider == 'aws' || self.provider == 'generic' || !has(self.sts)
+ - message: '''aws'' is the only supported STS provider for the ''aws'' Bucket provider'
+ rule: self.provider != 'aws' || !has(self.sts) || self.sts.provider == 'aws'
+ - message: '''ldap'' is the only supported STS provider for the ''generic'' Bucket provider'
+ rule: self.provider != 'generic' || !has(self.sts) || self.sts.provider == 'ldap'
+ - message: spec.sts.secretRef is not required for the 'aws' STS provider
+ rule: '!has(self.sts) || self.sts.provider != ''aws'' || !has(self.sts.secretRef)'
+ - message: spec.sts.certSecretRef is not required for the 'aws' STS provider
+ rule: '!has(self.sts) || self.sts.provider != ''aws'' || !has(self.sts.certSecretRef)'
+ status:
+ default:
+ observedGeneration: -1
+ description: BucketStatus records the observed state of a Bucket.
+ properties:
+ artifact:
+ description: Artifact represents the last successful Bucket reconciliation.
+ properties:
+ digest:
+ description: Digest is the digest of the file in the form of '<algorithm>:<checksum>'.
+ pattern: ^[a-z0-9]+(?:[.+_-][a-z0-9]+)*:[a-zA-Z0-9=_-]+$
+ type: string
+ lastUpdateTime:
+ description: |-
+ LastUpdateTime is the timestamp corresponding to the last update of the
+ Artifact.
+ format: date-time
+ type: string
+ metadata:
+ additionalProperties:
+ type: string
+ description: Metadata holds upstream information such as OCI annotations.
+ type: object
+ path:
+ description: |-
+ Path is the relative file path of the Artifact. It can be used to locate
+ the file in the root of the Artifact storage on the local file system of
+ the controller managing the Source.
+ type: string
+ revision:
+ description: |-
+ Revision is a human-readable identifier traceable in the origin source
+ system. It can be a Git commit SHA, Git tag, a Helm chart version, etc.
+ type: string
+ size:
+ description: Size is the number of bytes in the file.
+ format: int64
+ type: integer
+ url:
+ description: |-
+ URL is the HTTP address of the Artifact as exposed by the controller
+ managing the Source. It can be used to retrieve the Artifact for
+ consumption, e.g. by another controller applying the Artifact contents.
+ type: string
+ required:
+ - lastUpdateTime
+ - path
+ - revision
+ - url
+ type: object
+ conditions:
+ description: Conditions holds the conditions for the Bucket.
+ items:
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
+ properties:
+ lastTransitionTime:
+ description: |-
+ lastTransitionTime is the last time the condition transitioned from one status to another.
+ This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
+ format: date-time
+ type: string
+ message:
+ description: |-
+ message is a human readable message indicating details about the transition.
+ This may be an empty string.
+ maxLength: 32768
+ type: string
+ observedGeneration:
+ description: |-
+ observedGeneration represents the .metadata.generation that the condition was set based upon.
+ For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
+ with respect to the current state of the instance.
+ format: int64
+ minimum: 0
+ type: integer
+ reason:
+ description: |-
+ reason contains a programmatic identifier indicating the reason for the condition's last transition.
+ Producers of specific condition types may define expected values and meanings for this field,
+ and whether the values are considered a guaranteed API.
+ The value should be a CamelCase string.
+ This field may not be empty.
+ maxLength: 1024
+ minLength: 1
+ pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
+ type: string
+ status:
+ description: status of the condition, one of True, False, Unknown.
+ enum:
+ - "True"
+ - "False"
+ - Unknown
+ type: string
+ type:
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
+ maxLength: 316
+ pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
+ type: string
+ required:
+ - lastTransitionTime
+ - message
+ - reason
+ - status
+ - type
+ type: object
+ type: array
+ lastHandledReconcileAt:
+ description: |-
+ LastHandledReconcileAt holds the value of the most recent
+ reconcile request value, so a change of the annotation value
+ can be detected.
+ type: string
+ observedGeneration:
+ description: ObservedGeneration is the last observed generation of the Bucket object.
+ format: int64
+ type: integer
+ observedIgnore:
+ description: |-
+ ObservedIgnore is the observed exclusion patterns used for constructing
+ the source artifact.
+ type: string
+ url:
+ description: |-
+ URL is the dynamic fetch link for the latest Artifact.
+ It is provided on a "best effort" basis, and using the precise
+ BucketStatus.Artifact data is recommended.
+ type: string
+ type: object
+ type: object
+ served: true
+ storage: true
+ subresources:
+ status: {}
+ - additionalPrinterColumns:
+ - jsonPath: .spec.endpoint
+ name: Endpoint
+ type: string
- jsonPath: .status.conditions[?(@.type=="Ready")].status
name: Ready
type: string
@@ -322,7 +666,7 @@ spec:
name: Age
type: date
deprecated: true
- deprecationWarning: v1beta1 Bucket is deprecated, upgrade to v1beta2
+ deprecationWarning: v1beta1 Bucket is deprecated, upgrade to v1
name: v1beta1
schema:
openAPIV3Schema:
@@ -456,21 +800,15 @@ spec:
description: URL is the HTTP address of this artifact.
type: string
required:
+ - lastUpdateTime
- path
- url
type: object
conditions:
description: Conditions holds the conditions for the Bucket.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -511,12 +849,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -560,6 +893,8 @@ spec:
- jsonPath: .status.conditions[?(@.type=="Ready")].message
name: Status
type: string
+ deprecated: true
+ deprecationWarning: v1beta2 Bucket is deprecated, upgrade to v1
name: v1beta2
schema:
openAPIV3Schema:
@@ -618,6 +953,29 @@ spec:
bucketName:
description: BucketName is the name of the object storage bucket.
type: string
+ certSecretRef:
+ description: |-
+ CertSecretRef can be given the name of a Secret containing
+ either or both of
+
+ - a PEM-encoded client certificate (`tls.crt`) and private
+ key (`tls.key`);
+ - a PEM-encoded CA certificate (`ca.crt`)
+
+ and whichever are supplied, will be used for connecting to the
+ bucket. The client cert and key are useful if you are
+ authenticating with a certificate; the CA cert is useful if
+ you are using a self-signed server certificate. The Secret must
+ be of type `Opaque` or `kubernetes.io/tls`.
+
+ This field is only supported for the `generic` provider.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
endpoint:
description: Endpoint is the object storage address the BucketName is located at.
type: string
@@ -652,6 +1010,17 @@ spec:
- gcp
- azure
type: string
+ proxySecretRef:
+ description: |-
+ ProxySecretRef specifies the Secret containing the proxy configuration
+ to use while communicating with the Bucket server.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
region:
description: Region of the Endpoint where the BucketName is located in.
type: string
@@ -666,6 +1035,65 @@ spec:
required:
- name
type: object
+ sts:
+ description: |-
+ STS specifies the required configuration to use a Security Token
+ Service for fetching temporary credentials to authenticate in a
+ Bucket provider.
+
+ This field is only supported for the `aws` and `generic` providers.
+ properties:
+ certSecretRef:
+ description: |-
+ CertSecretRef can be given the name of a Secret containing
+ either or both of
+
+ - a PEM-encoded client certificate (`tls.crt`) and private
+ key (`tls.key`);
+ - a PEM-encoded CA certificate (`ca.crt`)
+
+ and whichever are supplied, will be used for connecting to the
+ STS endpoint. The client cert and key are useful if you are
+ authenticating with a certificate; the CA cert is useful if
+ you are using a self-signed server certificate. The Secret must
+ be of type `Opaque` or `kubernetes.io/tls`.
+
+ This field is only supported for the `ldap` provider.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
+ endpoint:
+ description: |-
+ Endpoint is the HTTP/S endpoint of the Security Token Service from
+ where temporary credentials will be fetched.
+ pattern: ^(http|https)://.*$
+ type: string
+ provider:
+ description: Provider of the Security Token Service.
+ enum:
+ - aws
+ - ldap
+ type: string
+ secretRef:
+ description: |-
+ SecretRef specifies the Secret containing authentication credentials
+ for the STS endpoint. This Secret must contain the fields `username`
+ and `password` and is supported only for the `ldap` provider.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
+ required:
+ - endpoint
+ - provider
+ type: object
suspend:
description: |-
Suspend tells the controller to suspend the reconciliation of this
@@ -681,6 +1109,17 @@ spec:
- endpoint
- interval
type: object
+ x-kubernetes-validations:
+ - message: STS configuration is only supported for the 'aws' and 'generic' Bucket providers
+ rule: self.provider == 'aws' || self.provider == 'generic' || !has(self.sts)
+ - message: '''aws'' is the only supported STS provider for the ''aws'' Bucket provider'
+ rule: self.provider != 'aws' || !has(self.sts) || self.sts.provider == 'aws'
+ - message: '''ldap'' is the only supported STS provider for the ''generic'' Bucket provider'
+ rule: self.provider != 'generic' || !has(self.sts) || self.sts.provider == 'ldap'
+ - message: spec.sts.secretRef is not required for the 'aws' STS provider
+ rule: '!has(self.sts) || self.sts.provider != ''aws'' || !has(self.sts.secretRef)'
+ - message: spec.sts.certSecretRef is not required for the 'aws' STS provider
+ rule: '!has(self.sts) || self.sts.provider != ''aws'' || !has(self.sts.certSecretRef)'
status:
default:
observedGeneration: -1
@@ -734,15 +1173,8 @@ spec:
conditions:
description: Conditions holds the conditions for the Bucket.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -783,12 +1215,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -824,7 +1251,7 @@ spec:
type: object
type: object
served: true
- storage: true
+ storage: false
subresources:
status: {}
---
@@ -832,12 +1259,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: source-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: gitrepositories.source.toolkit.fluxcd.io
spec:
group: source.toolkit.fluxcd.io
@@ -937,6 +1364,14 @@ spec:
efficient use of resources.
pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$
type: string
+ provider:
+ description: |-
+ Provider used for authentication, can be 'azure', 'generic'.
+ When not specified, defaults to 'generic'.
+ enum:
+ - generic
+ - azure
+ type: string
proxySecretRef:
description: |-
ProxySecretRef specifies the Secret containing the proxy configuration
@@ -965,7 +1400,6 @@ spec:
description: |-
Commit SHA to check out, takes precedence over all reference fields.
-
This can be combined with Branch to shallow clone the branch, in which
the commit is expected to exist.
type: string
@@ -973,7 +1407,6 @@ spec:
description: |-
Name of the reference to check out; takes precedence over Branch, Tag and SemVer.
-
It must be a valid Git reference: https://git-scm.com/docs/git-check-ref-format#_description
Examples: "refs/heads/main", "refs/tags/v0.1.0", "refs/pull/420/head", "refs/merge-requests/1/head"
type: string
@@ -1023,7 +1456,6 @@ spec:
description: |-
Mode specifies which Git object(s) should be verified.
-
The variants "head" and "HEAD" both imply the same thing, i.e. verify
the commit that the HEAD of the Git repository points to. The variant
"head" solely exists to ensure backwards compatibility.
@@ -1104,15 +1536,8 @@ spec:
conditions:
description: Conditions holds the conditions for the GitRepository.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -1153,12 +1578,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -1499,21 +1919,15 @@ spec:
description: URL is the HTTP address of this artifact.
type: string
required:
+ - lastUpdateTime
- path
- url
type: object
conditions:
description: Conditions holds the conditions for the GitRepository.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -1554,12 +1968,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -1599,6 +2008,7 @@ spec:
description: URL is the HTTP address of this artifact.
type: string
required:
+ - lastUpdateTime
- path
- url
type: object
@@ -1766,7 +2176,6 @@ spec:
description: |-
Commit SHA to check out, takes precedence over all reference fields.
-
This can be combined with Branch to shallow clone the branch, in which
the commit is expected to exist.
type: string
@@ -1774,7 +2183,6 @@ spec:
description: |-
Name of the reference to check out; takes precedence over Branch, Tag and SemVer.
-
It must be a valid Git reference: https://git-scm.com/docs/git-check-ref-format#_description
Examples: "refs/heads/main", "refs/tags/v0.1.0", "refs/pull/420/head", "refs/merge-requests/1/head"
type: string
@@ -1896,15 +2304,8 @@ spec:
conditions:
description: Conditions holds the conditions for the GitRepository.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -1945,12 +2346,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -1974,7 +2370,6 @@ spec:
changed.
It has the format of `<algo>:<checksum>`, for example: `sha256:<checksum>`.
-
Deprecated: Replaced with explicit fields for observed artifact content
config in the status.
type: string
@@ -2101,12 +2496,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: source-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: helmcharts.source.toolkit.fluxcd.io
spec:
group: source.toolkit.fluxcd.io
@@ -2352,15 +2747,8 @@ spec:
conditions:
description: Conditions holds the conditions for the HelmChart.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -2401,12 +2789,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -2634,21 +3017,15 @@ spec:
description: URL is the HTTP address of this artifact.
type: string
required:
+ - lastUpdateTime
- path
- url
type: object
conditions:
description: Conditions holds the conditions for the HelmChart.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -2689,12 +3066,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -2995,15 +3367,8 @@ spec:
conditions:
description: Conditions holds the conditions for the HelmChart.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -3044,12 +3409,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -3108,12 +3468,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: source-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: helmrepositories.source.toolkit.fluxcd.io
spec:
group: source.toolkit.fluxcd.io
@@ -3199,19 +3559,16 @@ spec:
CertSecretRef can be given the name of a Secret containing
either or both of
-
- a PEM-encoded client certificate (`tls.crt`) and private
key (`tls.key`);
- a PEM-encoded CA certificate (`ca.crt`)
-
and whichever are supplied, will be used for connecting to the
registry. The client cert and key are useful if you are
authenticating with a certificate; the CA cert is useful if
you are using a self-signed server certificate. The Secret must
be of type `Opaque` or `kubernetes.io/tls`.
-
It takes precedence over the values specified in the Secret referred
to by `.spec.secretRef`.
properties:
@@ -3352,15 +3709,8 @@ spec:
conditions:
description: Conditions holds the conditions for the HelmRepository.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -3401,12 +3751,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -3579,21 +3924,15 @@ spec:
description: URL is the HTTP address of this artifact.
type: string
required:
+ - lastUpdateTime
- path
- url
type: object
conditions:
description: Conditions holds the conditions for the HelmRepository.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -3634,12 +3973,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -3745,19 +4079,16 @@ spec:
CertSecretRef can be given the name of a Secret containing
either or both of
-
- a PEM-encoded client certificate (`tls.crt`) and private
key (`tls.key`);
- a PEM-encoded CA certificate (`ca.crt`)
-
and whichever are supplied, will be used for connecting to the
registry. The client cert and key are useful if you are
authenticating with a certificate; the CA cert is useful if
you are using a self-signed server certificate. The Secret must
be of type `Opaque` or `kubernetes.io/tls`.
-
It takes precedence over the values specified in the Secret referred
to by `.spec.secretRef`.
properties:
@@ -3898,15 +4229,8 @@ spec:
conditions:
description: Conditions holds the conditions for the HelmRepository.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -3947,12 +4271,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -3993,12 +4312,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: source-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: ocirepositories.source.toolkit.fluxcd.io
spec:
group: source.toolkit.fluxcd.io
@@ -4054,19 +4373,16 @@ spec:
CertSecretRef can be given the name of a Secret containing
either or both of
-
- a PEM-encoded client certificate (`tls.crt`) and private
key (`tls.key`);
- a PEM-encoded CA certificate (`ca.crt`)
-
and whichever are supplied, will be used for connecting to the
registry. The client cert and key are useful if you are
authenticating with a certificate; the CA cert is useful if
you are using a self-signed server certificate. The Secret must
be of type `Opaque` or `kubernetes.io/tls`.
-
Note: Support for the `caFile`, `certFile` and `keyFile` keys have
been deprecated.
properties:
@@ -4125,6 +4441,17 @@ spec:
- azure
- gcp
type: string
+ proxySecretRef:
+ description: |-
+ ProxySecretRef specifies the Secret containing the proxy configuration
+ to use while communicating with the container registry.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
ref:
description: |-
The OCI reference to pull and monitor for changes,
@@ -4292,15 +4619,8 @@ spec:
conditions:
description: Conditions holds the conditions for the OCIRepository.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -4341,12 +4661,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -4369,7 +4684,6 @@ spec:
artifact needs to be rebuilt.
It has the format of `<algo>:<checksum>`, for example: `sha256:<checksum>`.
-
Deprecated: Replaced with explicit fields for observed artifact content
config in the status.
type: string
@@ -4427,7 +4741,7 @@ metadata:
app.kubernetes.io/component: source-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: source-controller
namespace: flux-system
---
@@ -4438,7 +4752,7 @@ metadata:
app.kubernetes.io/component: source-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: source-controller
namespace: flux-system
@@ -4459,7 +4773,7 @@ metadata:
app.kubernetes.io/component: source-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: source-controller
namespace: flux-system
@@ -4504,7 +4818,7 @@ spec:
resourceFieldRef:
containerName: manager
resource: limits.memory
- image: ghcr.io/fluxcd/source-controller:v1.3.0
+ image: ghcr.io/fluxcd/source-controller:v1.4.1
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
@@ -4563,12 +4877,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: kustomize-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: kustomizations.kustomize.toolkit.fluxcd.io
spec:
group: kustomize.toolkit.fluxcd.io
@@ -4984,15 +5298,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -5033,12 +5340,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -5262,6 +5564,8 @@ spec:
required:
- name
type: object
+ required:
+ - secretRef
type: object
patches:
description: |-
@@ -5552,15 +5856,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -5601,12 +5898,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -6170,15 +6462,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -6219,12 +6504,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -6295,7 +6575,7 @@ metadata:
app.kubernetes.io/component: kustomize-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: kustomize-controller
namespace: flux-system
---
@@ -6306,7 +6586,7 @@ metadata:
app.kubernetes.io/component: kustomize-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: kustomize-controller
namespace: flux-system
@@ -6345,7 +6625,7 @@ spec:
resourceFieldRef:
containerName: manager
resource: limits.memory
- image: ghcr.io/fluxcd/kustomize-controller:v1.3.0
+ image: ghcr.io/fluxcd/kustomize-controller:v1.4.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
@@ -6397,12 +6677,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: helm-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: helmreleases.helm.toolkit.fluxcd.io
spec:
group: helm.toolkit.fluxcd.io
@@ -6530,6 +6810,7 @@ spec:
minLength: 1
type: string
required:
+ - kind
- name
type: object
valuesFiles:
@@ -6727,17 +7008,13 @@ spec:
`Create` or `CreateReplace`. Default is `Create` and if omitted
CRDs are installed but not updated.
-
Skip: do neither install nor replace (update) any CRDs.
-
Create: new CRDs are created, existing CRDs are neither updated nor deleted.
-
CreateReplace: new CRDs are created, existing CRDs are updated (replaced)
but not deleted.
-
By default, CRDs are applied (installed) during Helm install action.
With this option users can opt in to CRD replace existing CRDs on Helm
install actions, which is not (yet) natively supported by Helm.
@@ -6761,6 +7038,11 @@ spec:
DisableOpenAPIValidation prevents the Helm install action from validating
rendered templates against the Kubernetes OpenAPI Schema.
type: boolean
+ disableSchemaValidation:
+ description: |-
+ DisableSchemaValidation prevents the Helm install action from validating
+ the values against the JSON Schema.
+ type: boolean
disableWait:
description: |-
DisableWait disables the waiting for resources to be ready after a Helm
@@ -6804,7 +7086,6 @@ spec:
SkipCRDs tells the Helm install action to not install any CRDs. By default,
CRDs are installed if not already present.
-
Deprecated use CRD policy (`crds`) attribute with value `Skip` instead.
type: boolean
timeout:
@@ -6865,13 +7146,11 @@ spec:
duration of the reconciliation, instead of being created and destroyed
for each (step of a) Helm action.
-
This can improve performance, but may cause issues with some Helm charts
that for example do create Custom Resource Definitions during installation
outside Helm's CRD lifecycle hooks, which are then not observed to be
available by e.g. post-install hooks.
-
If not set, it defaults to true.
type: boolean
postRenderers:
@@ -7137,17 +7416,13 @@ spec:
`Create` or `CreateReplace`. Default is `Skip` and if omitted
CRDs are neither installed nor upgraded.
-
Skip: do neither install nor replace (update) any CRDs.
-
Create: new CRDs are created, existing CRDs are neither updated nor deleted.
-
CreateReplace: new CRDs are created, existing CRDs are updated (replaced)
but not deleted.
-
By default, CRDs are not applied during Helm upgrade action. With this
option users can opt-in to CRD upgrade, which is not (yet) natively supported by Helm.
https://helm.sh/docs/chart_best_practices/custom_resource_definitions.
@@ -7164,6 +7439,11 @@ spec:
DisableOpenAPIValidation prevents the Helm upgrade action from validating
rendered templates against the Kubernetes OpenAPI Schema.
type: boolean
+ disableSchemaValidation:
+ description: |-
+ DisableSchemaValidation prevents the Helm upgrade action from validating
+ the values against the JSON Schema.
+ type: boolean
disableWait:
description: |-
DisableWait disables the waiting for resources to be ready after a Helm
@@ -7285,15 +7565,8 @@ spec:
conditions:
description: Conditions holds the conditions for the HelmRelease.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -7334,12 +7607,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -7663,6 +7931,7 @@ spec:
minLength: 1
type: string
required:
+ - kind
- name
type: object
valuesFile:
@@ -7728,7 +7997,6 @@ spec:
ChartRef holds a reference to a source controller resource containing the
Helm chart artifact.
-
Note: this field is provisional to the v2 API, and not actively used
by v2beta1 HelmReleases.
properties:
@@ -7783,7 +8051,6 @@ spec:
differences between the manifest in the Helm storage and the resources
currently existing in the cluster.
-
Note: this field is provisional to the v2beta2 API, and not actively used
by v2beta1 HelmReleases.
properties:
@@ -7873,17 +8140,13 @@ spec:
`Create` or `CreateReplace`. Default is `Create` and if omitted
CRDs are installed but not updated.
-
Skip: do neither install nor replace (update) any CRDs.
-
Create: new CRDs are created, existing CRDs are neither updated nor deleted.
-
CreateReplace: new CRDs are created, existing CRDs are updated (replaced)
but not deleted.
-
By default, CRDs are applied (installed) during Helm install action.
With this option users can opt-in to CRD replace existing CRDs on Helm
install actions, which is not (yet) natively supported by Helm.
@@ -7950,7 +8213,6 @@ spec:
SkipCRDs tells the Helm install action to not install any CRDs. By default,
CRDs are installed if not already present.
-
Deprecated use CRD policy (`crds`) attribute with value `Skip` instead.
type: boolean
timeout:
@@ -8014,13 +8276,11 @@ spec:
duration of the reconciliation, instead of being created and destroyed
for each (step of a) Helm action.
-
This can improve performance, but may cause issues with some Helm charts
that for example do create Custom Resource Definitions during installation
outside Helm's CRD lifecycle hooks, which are then not observed to be
available by e.g. post-install hooks.
-
If not set, it defaults to true.
type: boolean
postRenderers:
@@ -8366,17 +8626,13 @@ spec:
`Create` or `CreateReplace`. Default is `Skip` and if omitted
CRDs are neither installed nor upgraded.
-
Skip: do neither install nor replace (update) any CRDs.
-
Create: new CRDs are created, existing CRDs are neither updated nor deleted.
-
CreateReplace: new CRDs are created, existing CRDs are updated (replaced)
but not deleted.
-
By default, CRDs are not applied during Helm upgrade action. With this
option users can opt-in to CRD upgrade, which is not (yet) natively supported by Helm.
https://helm.sh/docs/chart_best_practices/custom_resource_definitions.
@@ -8503,6 +8759,7 @@ spec:
type: object
type: array
required:
+ - chart
- interval
type: object
status:
@@ -8513,15 +8770,8 @@ spec:
conditions:
description: Conditions holds the conditions for the HelmRelease.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -8562,12 +8812,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -8595,7 +8840,6 @@ spec:
History holds the history of Helm releases performed for this HelmRelease
up to the last successfully completed release.
-
Note: this field is provisional to the v2beta2 API, and not actively used
by v2beta1 HelmReleases.
items:
@@ -8707,7 +8951,6 @@ spec:
LastAttemptedConfigDigest is the digest for the config (better known as
"values") of the last reconciliation attempt.
-
Note: this field is provisional to the v2beta2 API, and not actively used
by v2beta1 HelmReleases.
type: string
@@ -8716,7 +8959,6 @@ spec:
LastAttemptedGeneration is the last generation the controller attempted
to reconcile.
-
Note: this field is provisional to the v2beta2 API, and not actively used
by v2beta1 HelmReleases.
format: int64
@@ -8726,7 +8968,6 @@ spec:
LastAttemptedReleaseAction is the last release action performed for this
HelmRelease. It is used to determine the active remediation strategy.
-
Note: this field is provisional to the v2beta2 API, and not actively used
by v2beta1 HelmReleases.
type: string
@@ -8743,7 +8984,6 @@ spec:
LastHandledForceAt holds the value of the most recent force request
value, so a change of the annotation value can be detected.
-
Note: this field is provisional to the v2beta2 API, and not actively used
by v2beta1 HelmReleases.
type: string
@@ -8758,7 +8998,6 @@ spec:
LastHandledResetAt holds the value of the most recent reset request
value, so a change of the annotation value can be detected.
-
Note: this field is provisional to the v2beta2 API, and not actively used
by v2beta1 HelmReleases.
type: string
@@ -8779,7 +9018,6 @@ spec:
StorageNamespace is the namespace of the Helm release storage for the
current release.
-
Note: this field is provisional to the v2beta2 API, and not actively used
by v2beta1 HelmReleases.
type: string
@@ -8912,6 +9150,7 @@ spec:
minLength: 1
type: string
required:
+ - kind
- name
type: object
valuesFile:
@@ -8979,7 +9218,6 @@ spec:
ChartRef holds a reference to a source controller resource containing the
Helm chart artifact.
-
Note: this field is provisional to the v2 API, and not actively used
by v2beta2 HelmReleases.
properties:
@@ -9120,17 +9358,13 @@ spec:
`Create` or `CreateReplace`. Default is `Create` and if omitted
CRDs are installed but not updated.
-
Skip: do neither install nor replace (update) any CRDs.
-
Create: new CRDs are created, existing CRDs are neither updated nor deleted.
-
CreateReplace: new CRDs are created, existing CRDs are updated (replaced)
but not deleted.
-
By default, CRDs are applied (installed) during Helm install action.
With this option users can opt in to CRD replace existing CRDs on Helm
install actions, which is not (yet) natively supported by Helm.
@@ -9197,7 +9431,6 @@ spec:
SkipCRDs tells the Helm install action to not install any CRDs. By default,
CRDs are installed if not already present.
-
Deprecated use CRD policy (`crds`) attribute with value `Skip` instead.
type: boolean
timeout:
@@ -9258,13 +9491,11 @@ spec:
duration of the reconciliation, instead of being created and destroyed
for each (step of a) Helm action.
-
This can improve performance, but may cause issues with some Helm charts
that for example do create Custom Resource Definitions during installation
outside Helm's CRD lifecycle hooks, which are then not observed to be
available by e.g. post-install hooks.
-
If not set, it defaults to true.
type: boolean
postRenderers:
@@ -9633,17 +9864,13 @@ spec:
`Create` or `CreateReplace`. Default is `Skip` and if omitted
CRDs are neither installed nor upgraded.
-
Skip: do neither install nor replace (update) any CRDs.
-
Create: new CRDs are created, existing CRDs are neither updated nor deleted.
-
CreateReplace: new CRDs are created, existing CRDs are updated (replaced)
but not deleted.
-
By default, CRDs are not applied during Helm upgrade action. With this
option users can opt-in to CRD upgrade, which is not (yet) natively supported by Helm.
https://helm.sh/docs/chart_best_practices/custom_resource_definitions.
@@ -9781,15 +10008,8 @@ spec:
conditions:
description: Conditions holds the conditions for the HelmRelease.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -9830,12 +10050,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -10062,7 +10277,7 @@ metadata:
app.kubernetes.io/component: helm-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: helm-controller
namespace: flux-system
---
@@ -10073,7 +10288,7 @@ metadata:
app.kubernetes.io/component: helm-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: helm-controller
namespace: flux-system
@@ -10112,7 +10327,7 @@ spec:
resourceFieldRef:
containerName: manager
resource: limits.memory
- image: ghcr.io/fluxcd/helm-controller:v1.0.1
+ image: ghcr.io/fluxcd/helm-controller:v1.1.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
@@ -10164,12 +10379,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: notification-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: alerts.notification.toolkit.fluxcd.io
spec:
group: notification.toolkit.fluxcd.io
@@ -10269,6 +10484,7 @@ spec:
minLength: 1
type: string
required:
+ - kind
- name
type: object
type: array
@@ -10305,15 +10521,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -10354,12 +10563,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -10533,15 +10737,8 @@ spec:
conditions:
description: Conditions holds the conditions for the Alert.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -10582,12 +10779,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -10760,12 +10952,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: notification-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: providers.notification.toolkit.fluxcd.io
spec:
group: notification.toolkit.fluxcd.io
@@ -10893,15 +11085,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -10942,12 +11127,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -11019,7 +11199,6 @@ spec:
CertSecretRef specifies the Secret containing
a PEM-encoded CA certificate (in the `ca.crt` key).
-
Note: Support for the `caFile` key has
been deprecated.
properties:
@@ -11107,15 +11286,8 @@ spec:
conditions:
description: Conditions holds the conditions for the Provider.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -11156,12 +11328,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -11231,7 +11398,6 @@ spec:
CertSecretRef specifies the Secret containing
a PEM-encoded CA certificate (in the `ca.crt` key).
-
Note: Support for the `caFile` key has
been deprecated.
properties:
@@ -11323,12 +11489,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: notification-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: receivers.notification.toolkit.fluxcd.io
spec:
group: notification.toolkit.fluxcd.io
@@ -11483,15 +11649,8 @@ spec:
conditions:
description: Conditions holds the conditions for the Receiver.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -11532,12 +11691,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -11657,6 +11811,7 @@ spec:
minLength: 1
type: string
required:
+ - kind
- name
type: object
type: array
@@ -11695,6 +11850,7 @@ spec:
type: string
required:
- resources
+ - secretRef
- type
type: object
status:
@@ -11704,15 +11860,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -11753,12 +11902,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -11918,6 +12062,7 @@ spec:
type: string
required:
- resources
+ - secretRef
- type
type: object
status:
@@ -11928,15 +12073,8 @@ spec:
conditions:
description: Conditions holds the conditions for the Receiver.
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -11977,12 +12115,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -12029,7 +12162,7 @@ metadata:
app.kubernetes.io/component: notification-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: notification-controller
namespace: flux-system
---
@@ -12040,7 +12173,7 @@ metadata:
app.kubernetes.io/component: notification-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: notification-controller
namespace: flux-system
@@ -12061,7 +12194,7 @@ metadata:
app.kubernetes.io/component: notification-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: webhook-receiver
namespace: flux-system
@@ -12082,7 +12215,7 @@ metadata:
app.kubernetes.io/component: notification-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: notification-controller
namespace: flux-system
@@ -12120,7 +12253,7 @@ spec:
resourceFieldRef:
containerName: manager
resource: limits.memory
- image: ghcr.io/fluxcd/notification-controller:v1.3.0
+ image: ghcr.io/fluxcd/notification-controller:v1.4.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
@@ -12177,12 +12310,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: image-reflector-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: imagepolicies.image.toolkit.fluxcd.io
spec:
group: image.toolkit.fluxcd.io
@@ -12313,15 +12446,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -12362,12 +12488,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -12514,15 +12635,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -12563,12 +12677,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -12605,12 +12714,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: image-reflector-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: imagerepositories.image.toolkit.fluxcd.io
spec:
group: image.toolkit.fluxcd.io
@@ -12687,12 +12796,10 @@ spec:
CertSecretRef can be given the name of a secret containing
either or both of
-
- a PEM-encoded client certificate (`certFile`) and private
key (`keyFile`);
- a PEM-encoded CA certificate (`caFile`)
-
and whichever are supplied, will be used for connecting to the
registry. The client cert and key are useful if you are
authenticating with a certificate; the CA cert is useful if
@@ -12750,6 +12857,9 @@ spec:
Defaults to 'Interval' duration.
pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$
type: string
+ required:
+ - image
+ - interval
type: object
status:
default:
@@ -12764,15 +12874,8 @@ spec:
type: string
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -12813,12 +12916,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -12923,19 +13021,16 @@ spec:
CertSecretRef can be given the name of a Secret containing
either or both of
-
- a PEM-encoded client certificate (`tls.crt`) and private
key (`tls.key`);
- a PEM-encoded CA certificate (`ca.crt`)
-
and whichever are supplied, will be used for connecting to the
registry. The client cert and key are useful if you are
authenticating with a certificate; the CA cert is useful if
you are using a self-signed server certificate. The Secret must
be of type `Opaque` or `kubernetes.io/tls`.
-
Note: Support for the `caFile`, `certFile` and `keyFile` keys has
been deprecated.
properties:
@@ -12978,6 +13073,17 @@ spec:
- azure
- gcp
type: string
+ proxySecretRef:
+ description: |-
+ ProxySecretRef specifies the Secret containing the proxy configuration
+ to use while communicating with the container registry.
+ properties:
+ name:
+ description: Name of the referent.
+ type: string
+ required:
+ - name
+ type: object
secretRef:
description: |-
SecretRef can be given the name of a secret containing
@@ -13008,6 +13114,9 @@ spec:
Defaults to 'Interval' duration.
pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m))+$
type: string
+ required:
+ - image
+ - interval
type: object
status:
default:
@@ -13022,15 +13131,8 @@ spec:
type: string
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -13071,12 +13173,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -13135,7 +13232,7 @@ metadata:
app.kubernetes.io/component: image-reflector-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: image-reflector-controller
namespace: flux-system
---
@@ -13146,7 +13243,7 @@ metadata:
app.kubernetes.io/component: image-reflector-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: image-reflector-controller
namespace: flux-system
@@ -13185,7 +13282,7 @@ spec:
resourceFieldRef:
containerName: manager
resource: limits.memory
- image: ghcr.io/fluxcd/image-reflector-controller:v0.32.0
+ image: ghcr.io/fluxcd/image-reflector-controller:v0.33.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
@@ -13240,12 +13337,12 @@ apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
- controller-gen.kubebuilder.io/version: v0.15.0
+ controller-gen.kubebuilder.io/version: v0.16.1
labels:
app.kubernetes.io/component: image-automation-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: imageupdateautomations.image.toolkit.fluxcd.io
spec:
group: image.toolkit.fluxcd.io
@@ -13312,7 +13409,6 @@ spec:
description: |-
Commit SHA to check out, takes precedence over all reference fields.
-
This can be combined with Branch to shallow clone the branch, in which
the commit is expected to exist.
type: string
@@ -13320,7 +13416,6 @@ spec:
description: |-
Name of the reference to check out; takes precedence over Branch, Tag and SemVer.
-
It must be a valid Git reference: https://git-scm.com/docs/git-check-ref-format#_description
Examples: "refs/heads/main", "refs/tags/v0.1.0", "refs/pull/420/head", "refs/merge-requests/1/head"
type: string
@@ -13373,6 +13468,8 @@ spec:
required:
- name
type: object
+ required:
+ - secretRef
type: object
required:
- author
@@ -13479,15 +13576,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -13528,12 +13618,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -13630,7 +13715,6 @@ spec:
description: |-
Commit SHA to check out, takes precedence over all reference fields.
-
This can be combined with Branch to shallow clone the branch, in which
the commit is expected to exist.
type: string
@@ -13638,7 +13722,6 @@ spec:
description: |-
Name of the reference to check out; takes precedence over Branch, Tag and SemVer.
-
It must be a valid Git reference: https://git-scm.com/docs/git-check-ref-format#_description
Examples: "refs/heads/main", "refs/tags/v0.1.0", "refs/pull/420/head", "refs/merge-requests/1/head"
type: string
@@ -13691,6 +13774,8 @@ spec:
required:
- name
type: object
+ required:
+ - secretRef
type: object
required:
- author
@@ -13844,15 +13929,8 @@ spec:
properties:
conditions:
items:
- description: "Condition contains details for one aspect of the current state of this API
- Resource.\n---\nThis struct is intended for direct use as an array at the field path
- .status.conditions. For example,\n\n\n\ttype FooStatus struct{\n\t // Represents
- the observations of a foo's current state.\n\t // Known .status.conditions.type
- are: \"Available\", \"Progressing\", and \"Degraded\"\n\t // +patchMergeKey=type\n\t
- \ // +patchStrategy=merge\n\t // +listType=map\n\t // +listMapKey=type\n\t
- \ Conditions []metav1.Condition `json:\"conditions,omitempty\" patchStrategy:\"merge\"
- patchMergeKey:\"type\" protobuf:\"bytes,1,rep,name=conditions\"`\n\n\n\t // other
- fields\n\t}"
+ description: Condition contains details for one aspect of the current state of this API
+ Resource.
properties:
lastTransitionTime:
description: |-
@@ -13893,12 +13971,7 @@ spec:
- Unknown
type: string
type:
- description: |-
- type of condition in CamelCase or in foo.example.com/CamelCase.
- ---
- Many .condition.type values are consistent across resources like Available, but because arbitrary conditions can be
- useful (see .node.status.conditions), the ability to deconflict is important.
- The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
+ description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
@@ -13973,7 +14046,7 @@ metadata:
app.kubernetes.io/component: image-automation-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
name: image-automation-controller
namespace: flux-system
---
@@ -13984,7 +14057,7 @@ metadata:
app.kubernetes.io/component: image-automation-controller
app.kubernetes.io/instance: flux-system
app.kubernetes.io/part-of: flux
- app.kubernetes.io/version: v2.3.0
+ app.kubernetes.io/version: v2.4.0
control-plane: controller
name: image-automation-controller
namespace: flux-system
@@ -14023,7 +14096,7 @@ spec:
resourceFieldRef:
containerName: manager
resource: limits.memory
- image: ghcr.io/fluxcd/image-automation-controller:v0.38.0
+ image: ghcr.io/fluxcd/image-automation-controller:v0.39.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet: