diff --git a/features.md b/features.md index 0ee082ff588..881448e7b9b 100644 --- a/features.md +++ b/features.md @@ -33,6 +33,7 @@ | AWSClusterHostedDNS| | | Enabled | Enabled | | | Enabled | Enabled | | AWSDedicatedHosts| | | Enabled | Enabled | | | Enabled | Enabled | | AWSEuropeanSovereignCloudInstall| | | Enabled | Enabled | | | Enabled | Enabled | +| AuthenticationComponentProxyExternalOIDC| | | Enabled | Enabled | | | Enabled | Enabled | | AutomatedEtcdBackup| | | Enabled | Enabled | | | Enabled | Enabled | | AzureDedicatedHosts| | | Enabled | Enabled | | | Enabled | Enabled | | AzureDualStackInstall| | | Enabled | Enabled | | | Enabled | Enabled | diff --git a/features/features.go b/features/features.go index 482eca57bca..3831174ddf4 100644 --- a/features/features.go +++ b/features/features.go @@ -352,6 +352,14 @@ var ( enable(inClusterProfile(SelfManaged), inTechPreviewNoUpgrade(), inDevPreviewNoUpgrade()). mustRegister() + FeatureGateAuthenticationComponentProxyExternalOIDC = newFeatureGate("AuthenticationComponentProxyExternalOIDC"). + reportProblemsToJiraComponent("authentication"). + contactPerson("tchap"). + productScope(ocpSpecific). + enhancementPR("https://github.com/openshift/enhancements/pull/2097"). + enable(inTechPreviewNoUpgrade(), inDevPreviewNoUpgrade()). + mustRegister() + FeatureGateExternalOIDCWithAdditionalClaimMappings = newFeatureGate("ExternalOIDCWithUIDAndExtraClaimMappings"). reportProblemsToJiraComponent("authentication"). contactPerson("bpalmer"). diff --git a/openapi/generated_openapi/zz_generated.openapi.go b/openapi/generated_openapi/zz_generated.openapi.go index e413292d701..e66bc1fd864 100644 --- a/openapi/generated_openapi/zz_generated.openapi.go +++ b/openapi/generated_openapi/zz_generated.openapi.go @@ -1148,10 +1148,12 @@ func GetOpenAPIDefinitions(ref common.ReferenceCallback) map[string]common.OpenA operatorv1.ConfigSpec{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConfigSpec(ref), operatorv1.ConfigStatus{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConfigStatus(ref), operatorv1.Console{}.OpenAPIModelName(): schema_openshift_api_operator_v1_Console(ref), + operatorv1.ConsoleConfigMapReference{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConsoleConfigMapReference(ref), operatorv1.ConsoleConfigRoute{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConsoleConfigRoute(ref), operatorv1.ConsoleCustomization{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConsoleCustomization(ref), operatorv1.ConsoleList{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConsoleList(ref), operatorv1.ConsoleProviders{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConsoleProviders(ref), + operatorv1.ConsoleProxyConfig{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConsoleProxyConfig(ref), operatorv1.ConsoleSpec{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConsoleSpec(ref), operatorv1.ConsoleStatus{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ConsoleStatus(ref), operatorv1.ContainerLoggingDestinationParameters{}.OpenAPIModelName(): schema_openshift_api_operator_v1_ContainerLoggingDestinationParameters(ref), @@ -55224,6 +55226,27 @@ func schema_openshift_api_operator_v1_Console(ref common.ReferenceCallback) comm } } +func schema_openshift_api_operator_v1_ConsoleConfigMapReference(ref common.ReferenceCallback) common.OpenAPIDefinition { + return common.OpenAPIDefinition{ + Schema: spec.Schema{ + SchemaProps: spec.SchemaProps{ + Description: "ConsoleConfigMapReference references a ConfigMap in the openshift-config namespace.", + Type: []string{"object"}, + Properties: map[string]spec.Schema{ + "name": { + SchemaProps: spec.SchemaProps{ + Description: "name is the metadata.name of the referenced ConfigMap. Must be a valid DNS subdomain name (RFC 1123): at most 253 characters, only lowercase alphanumeric characters, '-' or '.', starting and ending with an alphanumeric character.", + Type: []string{"string"}, + Format: "", + }, + }, + }, + Required: []string{"name"}, + }, + }, + } +} + func schema_openshift_api_operator_v1_ConsoleConfigRoute(ref common.ReferenceCallback) common.OpenAPIDefinition { return common.OpenAPIDefinition{ Schema: spec.Schema{ @@ -55459,6 +55482,61 @@ func schema_openshift_api_operator_v1_ConsoleProviders(ref common.ReferenceCallb } } +func schema_openshift_api_operator_v1_ConsoleProxyConfig(ref common.ReferenceCallback) common.OpenAPIDefinition { + return common.OpenAPIDefinition{ + Schema: spec.Schema{ + SchemaProps: spec.SchemaProps{ + Description: "ConsoleProxyConfig holds proxy configuration scoped to Console's OIDC login clients. At least one of httpProxy or httpsProxy must be specified.", + Type: []string{"object"}, + Properties: map[string]spec.Schema{ + "httpProxy": { + SchemaProps: spec.SchemaProps{ + Description: "httpProxy is the URL of the proxy for HTTP requests. Must be a valid URL with http or https scheme, a non-empty hostname, and no path, query parameters, or fragment. Userinfo (e.g. user:password@host) is allowed for proxy authentication. Maximum length is 2048 characters.", + Type: []string{"string"}, + Format: "", + }, + }, + "httpsProxy": { + SchemaProps: spec.SchemaProps{ + Description: "httpsProxy is the URL of the proxy for HTTPS requests. Must be a valid URL with http or https scheme, a non-empty hostname, and no path, query parameters, or fragment. Userinfo (e.g. user:password@host) is allowed for proxy authentication. Maximum length is 2048 characters.", + Type: []string{"string"}, + Format: "", + }, + }, + "noProxy": { + VendorExtensible: spec.VendorExtensible{ + Extensions: spec.Extensions{ + "x-kubernetes-list-type": "set", + }, + }, + SchemaProps: spec.SchemaProps{ + Description: "noProxy is a list of hostnames and/or CIDRs and/or IPs for which the proxy should not be used. Must contain at least one entry when set. Each entry must be between 1 and 253 characters long and at most 64 entries are allowed. Duplicate entries are not permitted. Entries that are not valid hostnames, CIDRs, or IPs are silently ignored. Cluster-internal defaults (.cluster.local, .svc, 127.0.0.1, localhost) are always appended automatically and do not need to be included.", + Type: []string{"array"}, + Items: &spec.SchemaOrArray{ + Schema: &spec.Schema{ + SchemaProps: spec.SchemaProps{ + Type: []string{"string"}, + Format: "", + }, + }, + }, + }, + }, + "trustedCA": { + SchemaProps: spec.SchemaProps{ + Description: "trustedCA is a reference to a ConfigMap in the openshift-config namespace containing a CA certificate bundle under the key \"ca-bundle.crt\". This bundle is appended to the system trust store used by Console's OIDC login clients for proxy TLS connections. When omitted, only the system trust store is used.", + Default: map[string]interface{}{}, + Ref: ref(operatorv1.ConsoleConfigMapReference{}.OpenAPIModelName()), + }, + }, + }, + }, + }, + Dependencies: []string{ + operatorv1.ConsoleConfigMapReference{}.OpenAPIModelName()}, + } +} + func schema_openshift_api_operator_v1_ConsoleSpec(ref common.ReferenceCallback) common.OpenAPIDefinition { return common.OpenAPIDefinition{ Schema: spec.Schema{ @@ -55500,6 +55578,13 @@ func schema_openshift_api_operator_v1_ConsoleSpec(ref common.ReferenceCallback) Ref: ref(runtime.RawExtension{}.OpenAPIModelName()), }, }, + "authProxy": { + SchemaProps: spec.SchemaProps{ + Description: "authProxy configures proxy settings for outbound connections made by Console's OIDC login clients, including discovery, JWKS retrieval, code exchange, and token refresh. When set, it replaces the cluster-wide proxy (proxy.config.openshift.io/cluster) entirely for these connections; individual fields are not inherited from the cluster-wide configuration. At least one of httpProxy or httpsProxy must be specified. When omitted, the cluster-wide proxy is used if configured; otherwise no proxy is used. Other Console clients retain their existing proxy settings.", + Default: map[string]interface{}{}, + Ref: ref(operatorv1.ConsoleProxyConfig{}.OpenAPIModelName()), + }, + }, "customization": { SchemaProps: spec.SchemaProps{ Description: "customization is used to optionally provide a small set of customization options to the web console.", @@ -55547,7 +55632,7 @@ func schema_openshift_api_operator_v1_ConsoleSpec(ref common.ReferenceCallback) }, }, Dependencies: []string{ - operatorv1.ConsoleConfigRoute{}.OpenAPIModelName(), operatorv1.ConsoleCustomization{}.OpenAPIModelName(), operatorv1.ConsoleProviders{}.OpenAPIModelName(), operatorv1.Ingress{}.OpenAPIModelName(), runtime.RawExtension{}.OpenAPIModelName()}, + operatorv1.ConsoleConfigRoute{}.OpenAPIModelName(), operatorv1.ConsoleCustomization{}.OpenAPIModelName(), operatorv1.ConsoleProviders{}.OpenAPIModelName(), operatorv1.ConsoleProxyConfig{}.OpenAPIModelName(), operatorv1.Ingress{}.OpenAPIModelName(), runtime.RawExtension{}.OpenAPIModelName()}, } } diff --git a/openapi/openapi.json b/openapi/openapi.json index d0cfc398332..3ee5d407d62 100644 --- a/openapi/openapi.json +++ b/openapi/openapi.json @@ -31696,6 +31696,19 @@ } } }, + "com.github.openshift.api.operator.v1.ConsoleConfigMapReference": { + "description": "ConsoleConfigMapReference references a ConfigMap in the openshift-config namespace.", + "type": "object", + "required": [ + "name" + ], + "properties": { + "name": { + "description": "name is the metadata.name of the referenced ConfigMap. Must be a valid DNS subdomain name (RFC 1123): at most 253 characters, only lowercase alphanumeric characters, '-' or '.', starting and ending with an alphanumeric character.", + "type": "string" + } + } + }, "com.github.openshift.api.operator.v1.ConsoleConfigRoute": { "description": "ConsoleConfigRoute holds information on external route access to console. DEPRECATED", "type": "object", @@ -31830,6 +31843,33 @@ } } }, + "com.github.openshift.api.operator.v1.ConsoleProxyConfig": { + "description": "ConsoleProxyConfig holds proxy configuration scoped to Console's OIDC login clients. At least one of httpProxy or httpsProxy must be specified.", + "type": "object", + "properties": { + "httpProxy": { + "description": "httpProxy is the URL of the proxy for HTTP requests. Must be a valid URL with http or https scheme, a non-empty hostname, and no path, query parameters, or fragment. Userinfo (e.g. user:password@host) is allowed for proxy authentication. Maximum length is 2048 characters.", + "type": "string" + }, + "httpsProxy": { + "description": "httpsProxy is the URL of the proxy for HTTPS requests. Must be a valid URL with http or https scheme, a non-empty hostname, and no path, query parameters, or fragment. Userinfo (e.g. user:password@host) is allowed for proxy authentication. Maximum length is 2048 characters.", + "type": "string" + }, + "noProxy": { + "description": "noProxy is a list of hostnames and/or CIDRs and/or IPs for which the proxy should not be used. Must contain at least one entry when set. Each entry must be between 1 and 253 characters long and at most 64 entries are allowed. Duplicate entries are not permitted. Entries that are not valid hostnames, CIDRs, or IPs are silently ignored. Cluster-internal defaults (.cluster.local, .svc, 127.0.0.1, localhost) are always appended automatically and do not need to be included.", + "type": "array", + "items": { + "type": "string" + }, + "x-kubernetes-list-type": "set" + }, + "trustedCA": { + "description": "trustedCA is a reference to a ConfigMap in the openshift-config namespace containing a CA certificate bundle under the key \"ca-bundle.crt\". This bundle is appended to the system trust store used by Console's OIDC login clients for proxy TLS connections. When omitted, only the system trust store is used.", + "default": {}, + "$ref": "#/definitions/com.github.openshift.api.operator.v1.ConsoleConfigMapReference" + } + } + }, "com.github.openshift.api.operator.v1.ConsoleSpec": { "description": "ConsoleSpec is the specification of the desired behavior of the Console.", "type": "object", @@ -31838,6 +31878,11 @@ "providers" ], "properties": { + "authProxy": { + "description": "authProxy configures proxy settings for outbound connections made by Console's OIDC login clients, including discovery, JWKS retrieval, code exchange, and token refresh. When set, it replaces the cluster-wide proxy (proxy.config.openshift.io/cluster) entirely for these connections; individual fields are not inherited from the cluster-wide configuration. At least one of httpProxy or httpsProxy must be specified. When omitted, the cluster-wide proxy is used if configured; otherwise no proxy is used. Other Console clients retain their existing proxy settings.", + "default": {}, + "$ref": "#/definitions/com.github.openshift.api.operator.v1.ConsoleProxyConfig" + }, "customization": { "description": "customization is used to optionally provide a small set of customization options to the web console.", "default": {}, diff --git a/operator/v1/tests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDC.yaml b/operator/v1/tests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDC.yaml new file mode 100644 index 00000000000..cf33866eec7 --- /dev/null +++ b/operator/v1/tests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDC.yaml @@ -0,0 +1,475 @@ +apiVersion: apiextensions.k8s.io/v1 # Hack because controller-gen complains if we don't have this +name: "Console" +crdName: consoles.operator.openshift.io +featureGates: + - AuthenticationComponentProxyExternalOIDC +tests: + onCreate: + - name: Should accept a valid proxy configuration with httpProxy only + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://proxy.example.com:3128" + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: + httpProxy: "http://proxy.example.com:3128" + - name: Should accept a valid proxy configuration with httpsProxy only + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "http://proxy.example.com:3129" + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: + httpsProxy: "http://proxy.example.com:3129" + - name: Should accept a valid proxy configuration with both httpProxy and httpsProxy + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://proxy.example.com:3128" + httpsProxy: "http://proxy.example.com:3129" + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: + httpProxy: "http://proxy.example.com:3128" + httpsProxy: "http://proxy.example.com:3129" + - name: Should accept a valid proxy configuration with noProxy + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "http://proxy.example.com:3128" + noProxy: + - "idp.internal.example.com" + - ".corp.example.com" + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: + httpsProxy: "http://proxy.example.com:3128" + noProxy: + - "idp.internal.example.com" + - ".corp.example.com" + - name: Should accept a valid proxy configuration with trustedCA + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "http://proxy.example.com:3128" + trustedCA: + name: "proxy-ca-bundle" + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: + httpsProxy: "http://proxy.example.com:3128" + trustedCA: + name: "proxy-ca-bundle" + - name: Should reject proxy with neither httpProxy nor httpsProxy + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + noProxy: + - "example.com" + expectedError: "at least one of httpProxy or httpsProxy must be specified" + - name: Should reject httpProxy that is not a valid URL + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "not-a-url" + expectedError: "httpProxy must be a valid URL" + - name: Should reject httpProxy without a hostname + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://:3128" + expectedError: "httpProxy must contain a hostname" + - name: Should reject httpProxy with invalid scheme + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "ftp://proxy.example.com:3128" + expectedError: "httpProxy must use http or https scheme" + - name: Should reject httpProxy with a path + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://proxy.example.com:3128/path" + expectedError: "httpProxy must not contain a path" + - name: Should reject httpProxy with query parameters + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://proxy.example.com:3128?key=value" + expectedError: "httpProxy must not contain query parameters" + - name: Should reject httpProxy with a fragment + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://proxy.example.com:3128#frag" + expectedError: "httpProxy must not contain a fragment" + - name: Should reject httpsProxy that is not a valid URL + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "not-a-url" + expectedError: "httpsProxy must be a valid URL" + - name: Should reject httpsProxy without a hostname + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "http://:3128" + expectedError: "httpsProxy must contain a hostname" + - name: Should reject httpsProxy with invalid scheme + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "ftp://proxy.example.com:3128" + expectedError: "httpsProxy must use http or https scheme" + - name: Should reject httpsProxy with a path + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "http://proxy.example.com:3128/path" + expectedError: "httpsProxy must not contain a path" + - name: Should reject httpsProxy with query parameters + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "http://proxy.example.com:3128?key=value" + expectedError: "httpsProxy must not contain query parameters" + - name: Should reject httpsProxy with a fragment + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpsProxy: "http://proxy.example.com:3128#frag" + expectedError: "httpsProxy must not contain a fragment" + - name: Should reject duplicate noProxy entries + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://proxy.example.com:3128" + noProxy: + - "example.com" + - "example.com" + expectedError: "Duplicate value" + - name: Should reject empty noProxy entry + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://proxy.example.com:3128" + noProxy: + - "" + expectedError: "should be at least 1 chars long" + - name: Should reject empty noProxy list + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + metadata: + name: cluster + spec: + authProxy: + httpProxy: "http://proxy.example.com:3128" + noProxy: [] + expectedError: "should have at least 1 items" + - name: Should accept proxy URLs with credentials and a trailing slash + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://user:password@proxy.example.com:3128/", "httpsProxy": "https://proxy.example.com:3129/"} + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://user:password@proxy.example.com:3128/", "httpsProxy": "https://proxy.example.com:3129/"} + - name: Should reject an empty authProxy configuration + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {} + expectedError: "should have at least 1 properties" + - name: Should reject an empty httpProxy URL + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": ""} + expectedError: "should be at least 1 chars long" + - name: Should reject an empty httpsProxy URL + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": ""} + expectedError: "should be at least 1 chars long" + - name: Should reject an httpProxy URL exceeding 2048 characters + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"} + expectedError: "should be at most 2048 chars long" + - name: Should reject an httpsProxy URL exceeding 2048 characters + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"} + expectedError: "should be at most 2048 chars long" + - name: Should reject a noProxy entry exceeding 253 characters + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://proxy.example.com:3128", "noProxy": ["aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"]} + expectedError: "should be at most 253 chars long" + - name: Should reject more than 64 noProxy entries + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://proxy.example.com:3128", "noProxy": ["host0.example.com", "host1.example.com", "host2.example.com", "host3.example.com", "host4.example.com", "host5.example.com", "host6.example.com", "host7.example.com", "host8.example.com", "host9.example.com", "host10.example.com", "host11.example.com", "host12.example.com", "host13.example.com", "host14.example.com", "host15.example.com", "host16.example.com", "host17.example.com", "host18.example.com", "host19.example.com", "host20.example.com", "host21.example.com", "host22.example.com", "host23.example.com", "host24.example.com", "host25.example.com", "host26.example.com", "host27.example.com", "host28.example.com", "host29.example.com", "host30.example.com", "host31.example.com", "host32.example.com", "host33.example.com", "host34.example.com", "host35.example.com", "host36.example.com", "host37.example.com", "host38.example.com", "host39.example.com", "host40.example.com", "host41.example.com", "host42.example.com", "host43.example.com", "host44.example.com", "host45.example.com", "host46.example.com", "host47.example.com", "host48.example.com", "host49.example.com", "host50.example.com", "host51.example.com", "host52.example.com", "host53.example.com", "host54.example.com", "host55.example.com", "host56.example.com", "host57.example.com", "host58.example.com", "host59.example.com", "host60.example.com", "host61.example.com", "host62.example.com", "host63.example.com", "host64.example.com"]} + expectedError: "should have at most 64 items" + - name: Should reject a trustedCA reference without a name + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://proxy.example.com:3128", "trustedCA": {}} + expectedError: "spec.authProxy.trustedCA.name: Required value" + - name: Should reject an empty trustedCA reference name + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://proxy.example.com:3128", "trustedCA": {"name": ""}} + expectedError: "should be at least 1 chars long" + - name: Should reject an invalid trustedCA reference name + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://proxy.example.com:3128", "trustedCA": {"name": "Proxy_CA"}} + expectedError: "name must be a valid DNS subdomain name" + - name: Should reject a trustedCA reference name exceeding 253 characters + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://proxy.example.com:3128", "trustedCA": {"name": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"}} + expectedError: "should be at most 253 chars long" + onUpdate: + - name: Should allow adding authProxy + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + updated: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://proxy.example.com:3128", "httpsProxy": "https://proxy.example.com:3129", "noProxy": ["idp.internal.example.com"], "trustedCA": {"name": "proxy-ca"}} + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://proxy.example.com:3128", "httpsProxy": "https://proxy.example.com:3129", "noProxy": ["idp.internal.example.com"], "trustedCA": {"name": "proxy-ca"}} + - name: Should allow replacing authProxy without retaining omitted fields + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://proxy.example.com:3128", "httpsProxy": "https://proxy.example.com:3129", "noProxy": ["idp.internal.example.com"], "trustedCA": {"name": "proxy-ca"}} + updated: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://proxy.example.com:3128"} + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpsProxy": "http://proxy.example.com:3128"} + - name: Should allow removing authProxy + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://proxy.example.com:3128", "httpsProxy": "https://proxy.example.com:3129", "noProxy": ["idp.internal.example.com"], "trustedCA": {"name": "proxy-ca"}} + updated: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + - name: Should reject updating authProxy to omit both proxy URLs + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://proxy.example.com:3128", "httpsProxy": "https://proxy.example.com:3129", "noProxy": ["idp.internal.example.com"], "trustedCA": {"name": "proxy-ca"}} + updated: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"noProxy": ["example.com"]} + expectedError: "at least one of httpProxy or httpsProxy must be specified" diff --git a/operator/v1/tests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDCDisabled.yaml b/operator/v1/tests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDCDisabled.yaml new file mode 100644 index 00000000000..8312044b811 --- /dev/null +++ b/operator/v1/tests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDCDisabled.yaml @@ -0,0 +1,21 @@ +apiVersion: apiextensions.k8s.io/v1 # Hack because controller-gen complains if we do not have this +name: "Console" +crdName: consoles.operator.openshift.io +featureGates: + - "-AuthenticationComponentProxyExternalOIDC" +tests: + onCreate: + - name: Should prune authProxy when its feature gate is disabled + initial: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal + authProxy: {"httpProxy": "http://proxy.example.com:3128", "httpsProxy": "https://proxy.example.com:3129", "noProxy": ["idp.internal.example.com"], "trustedCA": {"name": "proxy-ca"}} + expected: | + apiVersion: operator.openshift.io/v1 + kind: Console + spec: + logLevel: Normal + operatorLogLevel: Normal diff --git a/operator/v1/types_console.go b/operator/v1/types_console.go index 35795b2b71b..99d2590a831 100644 --- a/operator/v1/types_console.go +++ b/operator/v1/types_console.go @@ -35,6 +35,19 @@ type Console struct { // ConsoleSpec is the specification of the desired behavior of the Console. type ConsoleSpec struct { OperatorSpec `json:",inline"` + + // authProxy configures proxy settings for outbound connections made by + // Console's OIDC login clients, including discovery, JWKS retrieval, + // code exchange, and token refresh. When set, it replaces the cluster-wide + // proxy (proxy.config.openshift.io/cluster) entirely for these connections; + // individual fields are not inherited from the cluster-wide configuration. + // At least one of httpProxy or httpsProxy must be specified. + // When omitted, the cluster-wide proxy is used if configured; otherwise no + // proxy is used. Other Console clients retain their existing proxy settings. + // +openshift:enable:FeatureGate=AuthenticationComponentProxyExternalOIDC + // +optional + AuthProxy ConsoleProxyConfig `json:"authProxy,omitzero"` + // customization is used to optionally provide a small set of // customization options to the web console. // +optional @@ -63,6 +76,82 @@ type ConsoleSpec struct { Ingress Ingress `json:"ingress"` } +// ConsoleProxyConfig holds proxy configuration scoped to Console's OIDC login clients. +// At least one of httpProxy or httpsProxy must be specified. +// +kubebuilder:validation:MinProperties=1 +// +kubebuilder:validation:XValidation:rule="has(self.httpProxy) || has(self.httpsProxy)",message="at least one of httpProxy or httpsProxy must be specified" +type ConsoleProxyConfig struct { + // httpProxy is the URL of the proxy for HTTP requests. + // Must be a valid URL with http or https scheme, a non-empty + // hostname, and no path, query parameters, or fragment. + // Userinfo (e.g. user:password@host) is allowed for proxy + // authentication. Maximum length is 2048 characters. + // +kubebuilder:validation:MinLength=1 + // +kubebuilder:validation:MaxLength=2048 + // +kubebuilder:validation:XValidation:rule="isURL(self)",message="httpProxy must be a valid URL" + // +kubebuilder:validation:XValidation:rule="!isURL(self) || url(self).getScheme() in ['http', 'https']",message="httpProxy must use http or https scheme" + // +kubebuilder:validation:XValidation:rule="!isURL(self) || size(url(self).getHostname()) > 0",message="httpProxy must contain a hostname" + // +kubebuilder:validation:XValidation:rule="!isURL(self) || url(self).getEscapedPath() == '' || url(self).getEscapedPath() == '/'",message="httpProxy must not contain a path" + // +kubebuilder:validation:XValidation:rule="!isURL(self) || url(self).getQuery().size() == 0",message="httpProxy must not contain query parameters" + // +kubebuilder:validation:XValidation:rule="!self.matches('.*#.*')",message="httpProxy must not contain a fragment" + // +optional + HTTPProxy string `json:"httpProxy,omitempty"` + + // httpsProxy is the URL of the proxy for HTTPS requests. + // Must be a valid URL with http or https scheme, a non-empty + // hostname, and no path, query parameters, or fragment. + // Userinfo (e.g. user:password@host) is allowed for proxy + // authentication. Maximum length is 2048 characters. + // +kubebuilder:validation:MinLength=1 + // +kubebuilder:validation:MaxLength=2048 + // +kubebuilder:validation:XValidation:rule="isURL(self)",message="httpsProxy must be a valid URL" + // +kubebuilder:validation:XValidation:rule="!isURL(self) || url(self).getScheme() in ['http', 'https']",message="httpsProxy must use http or https scheme" + // +kubebuilder:validation:XValidation:rule="!isURL(self) || size(url(self).getHostname()) > 0",message="httpsProxy must contain a hostname" + // +kubebuilder:validation:XValidation:rule="!isURL(self) || url(self).getEscapedPath() == '' || url(self).getEscapedPath() == '/'",message="httpsProxy must not contain a path" + // +kubebuilder:validation:XValidation:rule="!isURL(self) || url(self).getQuery().size() == 0",message="httpsProxy must not contain query parameters" + // +kubebuilder:validation:XValidation:rule="!self.matches('.*#.*')",message="httpsProxy must not contain a fragment" + // +optional + HTTPSProxy string `json:"httpsProxy,omitempty"` + + // noProxy is a list of hostnames and/or CIDRs and/or IPs for which + // the proxy should not be used. Must contain at least one entry + // when set. Each entry must be between 1 and 253 characters long + // and at most 64 entries are allowed. Duplicate + // entries are not permitted. Entries that are not valid hostnames, + // CIDRs, or IPs are silently ignored. Cluster-internal defaults + // (.cluster.local, .svc, 127.0.0.1, localhost) are always appended + // automatically and do not need to be included. + // +listType=set + // +kubebuilder:validation:MinItems=1 + // +kubebuilder:validation:MaxItems=64 + // +kubebuilder:validation:items:MinLength=1 + // +kubebuilder:validation:items:MaxLength=253 + // +optional + NoProxy []string `json:"noProxy,omitempty"` + + // trustedCA is a reference to a ConfigMap in the openshift-config + // namespace containing a CA certificate bundle under the key + // "ca-bundle.crt". This bundle is appended to the system trust store + // used by Console's OIDC login clients for proxy TLS connections. + // When omitted, only the system trust store is used. + // +optional + TrustedCA ConsoleConfigMapReference `json:"trustedCA,omitzero"` +} + +// ConsoleConfigMapReference references a ConfigMap in the +// openshift-config namespace. +type ConsoleConfigMapReference struct { + // name is the metadata.name of the referenced ConfigMap. + // Must be a valid DNS subdomain name (RFC 1123): at most 253 + // characters, only lowercase alphanumeric characters, '-' or + // '.', starting and ending with an alphanumeric character. + // +kubebuilder:validation:MinLength=1 + // +kubebuilder:validation:MaxLength=253 + // +kubebuilder:validation:XValidation:rule="!format.dns1123Subdomain().validate(self).hasValue()",message="name must be a valid DNS subdomain name: contain no more than 253 characters, contain only lowercase alphanumeric characters, '-' or '.', and start and end with an alphanumeric character" + // +required + Name string `json:"name,omitempty"` +} + // ConsoleConfigRoute holds information on external route access to console. // DEPRECATED type ConsoleConfigRoute struct { diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-4-SelfManagedHA-DevPreviewNoUpgrade.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-4-SelfManagedHA-DevPreviewNoUpgrade.crd.yaml new file mode 100644 index 00000000000..db5f1e5d78c --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-4-SelfManagedHA-DevPreviewNoUpgrade.crd.yaml @@ -0,0 +1,1188 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/self-managed-high-availability: "true" + release.openshift.io/feature-set: DevPreviewNoUpgrade + release.openshift.io/major-version: "4" + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + authProxy: + description: |- + authProxy configures proxy settings for outbound connections made by + Console's OIDC login clients, including discovery, JWKS retrieval, + code exchange, and token refresh. When set, it replaces the cluster-wide + proxy (proxy.config.openshift.io/cluster) entirely for these connections; + individual fields are not inherited from the cluster-wide configuration. + At least one of httpProxy or httpsProxy must be specified. + When omitted, the cluster-wide proxy is used if configured; otherwise no + proxy is used. Other Console clients retain their existing proxy settings. + minProperties: 1 + properties: + httpProxy: + description: |- + httpProxy is the URL of the proxy for HTTP requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpProxy must be a valid URL + rule: isURL(self) + - message: httpProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + httpsProxy: + description: |- + httpsProxy is the URL of the proxy for HTTPS requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpsProxy must be a valid URL + rule: isURL(self) + - message: httpsProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpsProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpsProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpsProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpsProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + noProxy: + description: |- + noProxy is a list of hostnames and/or CIDRs and/or IPs for which + the proxy should not be used. Must contain at least one entry + when set. Each entry must be between 1 and 253 characters long + and at most 64 entries are allowed. Duplicate + entries are not permitted. Entries that are not valid hostnames, + CIDRs, or IPs are silently ignored. Cluster-internal defaults + (.cluster.local, .svc, 127.0.0.1, localhost) are always appended + automatically and do not need to be included. + items: + maxLength: 253 + minLength: 1 + type: string + maxItems: 64 + minItems: 1 + type: array + x-kubernetes-list-type: set + trustedCA: + description: |- + trustedCA is a reference to a ConfigMap in the openshift-config + namespace containing a CA certificate bundle under the key + "ca-bundle.crt". This bundle is appended to the system trust store + used by Console's OIDC login clients for proxy TLS connections. + When omitted, only the system trust store is used. + properties: + name: + description: |- + name is the metadata.name of the referenced ConfigMap. + Must be a valid DNS subdomain name (RFC 1123): at most 253 + characters, only lowercase alphanumeric characters, '-' or + '.', starting and ending with an alphanumeric character. + maxLength: 253 + minLength: 1 + type: string + x-kubernetes-validations: + - message: 'name must be a valid DNS subdomain name: contain + no more than 253 characters, contain only lowercase alphanumeric + characters, ''-'' or ''.'', and start and end with an + alphanumeric character' + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - name + type: object + type: object + x-kubernetes-validations: + - message: at least one of httpProxy or httpsProxy must be specified + rule: has(self.httpProxy) || has(self.httpsProxy) + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-4-SelfManagedHA-TechPreviewNoUpgrade.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-4-SelfManagedHA-TechPreviewNoUpgrade.crd.yaml new file mode 100644 index 00000000000..0d2d31a102a --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-4-SelfManagedHA-TechPreviewNoUpgrade.crd.yaml @@ -0,0 +1,1188 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/self-managed-high-availability: "true" + release.openshift.io/feature-set: TechPreviewNoUpgrade + release.openshift.io/major-version: "4" + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + authProxy: + description: |- + authProxy configures proxy settings for outbound connections made by + Console's OIDC login clients, including discovery, JWKS retrieval, + code exchange, and token refresh. When set, it replaces the cluster-wide + proxy (proxy.config.openshift.io/cluster) entirely for these connections; + individual fields are not inherited from the cluster-wide configuration. + At least one of httpProxy or httpsProxy must be specified. + When omitted, the cluster-wide proxy is used if configured; otherwise no + proxy is used. Other Console clients retain their existing proxy settings. + minProperties: 1 + properties: + httpProxy: + description: |- + httpProxy is the URL of the proxy for HTTP requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpProxy must be a valid URL + rule: isURL(self) + - message: httpProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + httpsProxy: + description: |- + httpsProxy is the URL of the proxy for HTTPS requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpsProxy must be a valid URL + rule: isURL(self) + - message: httpsProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpsProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpsProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpsProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpsProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + noProxy: + description: |- + noProxy is a list of hostnames and/or CIDRs and/or IPs for which + the proxy should not be used. Must contain at least one entry + when set. Each entry must be between 1 and 253 characters long + and at most 64 entries are allowed. Duplicate + entries are not permitted. Entries that are not valid hostnames, + CIDRs, or IPs are silently ignored. Cluster-internal defaults + (.cluster.local, .svc, 127.0.0.1, localhost) are always appended + automatically and do not need to be included. + items: + maxLength: 253 + minLength: 1 + type: string + maxItems: 64 + minItems: 1 + type: array + x-kubernetes-list-type: set + trustedCA: + description: |- + trustedCA is a reference to a ConfigMap in the openshift-config + namespace containing a CA certificate bundle under the key + "ca-bundle.crt". This bundle is appended to the system trust store + used by Console's OIDC login clients for proxy TLS connections. + When omitted, only the system trust store is used. + properties: + name: + description: |- + name is the metadata.name of the referenced ConfigMap. + Must be a valid DNS subdomain name (RFC 1123): at most 253 + characters, only lowercase alphanumeric characters, '-' or + '.', starting and ending with an alphanumeric character. + maxLength: 253 + minLength: 1 + type: string + x-kubernetes-validations: + - message: 'name must be a valid DNS subdomain name: contain + no more than 253 characters, contain only lowercase alphanumeric + characters, ''-'' or ''.'', and start and end with an + alphanumeric character' + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - name + type: object + type: object + x-kubernetes-validations: + - message: at least one of httpProxy or httpsProxy must be specified + rule: has(self.httpProxy) || has(self.httpsProxy) + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-5-10-SelfManagedHA-DevPreviewNoUpgrade.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-5-10-SelfManagedHA-DevPreviewNoUpgrade.crd.yaml new file mode 100644 index 00000000000..d2412b33e08 --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-5-10-SelfManagedHA-DevPreviewNoUpgrade.crd.yaml @@ -0,0 +1,1080 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/self-managed-high-availability: "true" + release.openshift.io/feature-set: DevPreviewNoUpgrade + release.openshift.io/major-version: 5,6,7,8,9,10 + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-5-10-SelfManagedHA-TechPreviewNoUpgrade.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-5-10-SelfManagedHA-TechPreviewNoUpgrade.crd.yaml new file mode 100644 index 00000000000..2e9aecb8d3d --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-5-10-SelfManagedHA-TechPreviewNoUpgrade.crd.yaml @@ -0,0 +1,1080 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/self-managed-high-availability: "true" + release.openshift.io/feature-set: TechPreviewNoUpgrade + release.openshift.io/major-version: 5,6,7,8,9,10 + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Default.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Default.crd.yaml new file mode 100644 index 00000000000..8067c81619b --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Default.crd.yaml @@ -0,0 +1,1080 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/ibm-cloud-managed: "true" + include.release.openshift.io/self-managed-high-availability: "true" + release.openshift.io/feature-set: Default + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-CustomNoUpgrade.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-CustomNoUpgrade.crd.yaml new file mode 100644 index 00000000000..74cd6cb8488 --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-CustomNoUpgrade.crd.yaml @@ -0,0 +1,1187 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/ibm-cloud-managed: "true" + release.openshift.io/feature-set: CustomNoUpgrade + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + authProxy: + description: |- + authProxy configures proxy settings for outbound connections made by + Console's OIDC login clients, including discovery, JWKS retrieval, + code exchange, and token refresh. When set, it replaces the cluster-wide + proxy (proxy.config.openshift.io/cluster) entirely for these connections; + individual fields are not inherited from the cluster-wide configuration. + At least one of httpProxy or httpsProxy must be specified. + When omitted, the cluster-wide proxy is used if configured; otherwise no + proxy is used. Other Console clients retain their existing proxy settings. + minProperties: 1 + properties: + httpProxy: + description: |- + httpProxy is the URL of the proxy for HTTP requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpProxy must be a valid URL + rule: isURL(self) + - message: httpProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + httpsProxy: + description: |- + httpsProxy is the URL of the proxy for HTTPS requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpsProxy must be a valid URL + rule: isURL(self) + - message: httpsProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpsProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpsProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpsProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpsProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + noProxy: + description: |- + noProxy is a list of hostnames and/or CIDRs and/or IPs for which + the proxy should not be used. Must contain at least one entry + when set. Each entry must be between 1 and 253 characters long + and at most 64 entries are allowed. Duplicate + entries are not permitted. Entries that are not valid hostnames, + CIDRs, or IPs are silently ignored. Cluster-internal defaults + (.cluster.local, .svc, 127.0.0.1, localhost) are always appended + automatically and do not need to be included. + items: + maxLength: 253 + minLength: 1 + type: string + maxItems: 64 + minItems: 1 + type: array + x-kubernetes-list-type: set + trustedCA: + description: |- + trustedCA is a reference to a ConfigMap in the openshift-config + namespace containing a CA certificate bundle under the key + "ca-bundle.crt". This bundle is appended to the system trust store + used by Console's OIDC login clients for proxy TLS connections. + When omitted, only the system trust store is used. + properties: + name: + description: |- + name is the metadata.name of the referenced ConfigMap. + Must be a valid DNS subdomain name (RFC 1123): at most 253 + characters, only lowercase alphanumeric characters, '-' or + '.', starting and ending with an alphanumeric character. + maxLength: 253 + minLength: 1 + type: string + x-kubernetes-validations: + - message: 'name must be a valid DNS subdomain name: contain + no more than 253 characters, contain only lowercase alphanumeric + characters, ''-'' or ''.'', and start and end with an + alphanumeric character' + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - name + type: object + type: object + x-kubernetes-validations: + - message: at least one of httpProxy or httpsProxy must be specified + rule: has(self.httpProxy) || has(self.httpsProxy) + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-DevPreviewNoUpgrade.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-DevPreviewNoUpgrade.crd.yaml new file mode 100644 index 00000000000..e33cf268156 --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-DevPreviewNoUpgrade.crd.yaml @@ -0,0 +1,1187 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/ibm-cloud-managed: "true" + release.openshift.io/feature-set: DevPreviewNoUpgrade + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + authProxy: + description: |- + authProxy configures proxy settings for outbound connections made by + Console's OIDC login clients, including discovery, JWKS retrieval, + code exchange, and token refresh. When set, it replaces the cluster-wide + proxy (proxy.config.openshift.io/cluster) entirely for these connections; + individual fields are not inherited from the cluster-wide configuration. + At least one of httpProxy or httpsProxy must be specified. + When omitted, the cluster-wide proxy is used if configured; otherwise no + proxy is used. Other Console clients retain their existing proxy settings. + minProperties: 1 + properties: + httpProxy: + description: |- + httpProxy is the URL of the proxy for HTTP requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpProxy must be a valid URL + rule: isURL(self) + - message: httpProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + httpsProxy: + description: |- + httpsProxy is the URL of the proxy for HTTPS requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpsProxy must be a valid URL + rule: isURL(self) + - message: httpsProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpsProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpsProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpsProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpsProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + noProxy: + description: |- + noProxy is a list of hostnames and/or CIDRs and/or IPs for which + the proxy should not be used. Must contain at least one entry + when set. Each entry must be between 1 and 253 characters long + and at most 64 entries are allowed. Duplicate + entries are not permitted. Entries that are not valid hostnames, + CIDRs, or IPs are silently ignored. Cluster-internal defaults + (.cluster.local, .svc, 127.0.0.1, localhost) are always appended + automatically and do not need to be included. + items: + maxLength: 253 + minLength: 1 + type: string + maxItems: 64 + minItems: 1 + type: array + x-kubernetes-list-type: set + trustedCA: + description: |- + trustedCA is a reference to a ConfigMap in the openshift-config + namespace containing a CA certificate bundle under the key + "ca-bundle.crt". This bundle is appended to the system trust store + used by Console's OIDC login clients for proxy TLS connections. + When omitted, only the system trust store is used. + properties: + name: + description: |- + name is the metadata.name of the referenced ConfigMap. + Must be a valid DNS subdomain name (RFC 1123): at most 253 + characters, only lowercase alphanumeric characters, '-' or + '.', starting and ending with an alphanumeric character. + maxLength: 253 + minLength: 1 + type: string + x-kubernetes-validations: + - message: 'name must be a valid DNS subdomain name: contain + no more than 253 characters, contain only lowercase alphanumeric + characters, ''-'' or ''.'', and start and end with an + alphanumeric character' + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - name + type: object + type: object + x-kubernetes-validations: + - message: at least one of httpProxy or httpsProxy must be specified + rule: has(self.httpProxy) || has(self.httpsProxy) + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-TechPreviewNoUpgrade.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-TechPreviewNoUpgrade.crd.yaml new file mode 100644 index 00000000000..cee3458a67f --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-Hypershift-TechPreviewNoUpgrade.crd.yaml @@ -0,0 +1,1187 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/ibm-cloud-managed: "true" + release.openshift.io/feature-set: TechPreviewNoUpgrade + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + authProxy: + description: |- + authProxy configures proxy settings for outbound connections made by + Console's OIDC login clients, including discovery, JWKS retrieval, + code exchange, and token refresh. When set, it replaces the cluster-wide + proxy (proxy.config.openshift.io/cluster) entirely for these connections; + individual fields are not inherited from the cluster-wide configuration. + At least one of httpProxy or httpsProxy must be specified. + When omitted, the cluster-wide proxy is used if configured; otherwise no + proxy is used. Other Console clients retain their existing proxy settings. + minProperties: 1 + properties: + httpProxy: + description: |- + httpProxy is the URL of the proxy for HTTP requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpProxy must be a valid URL + rule: isURL(self) + - message: httpProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + httpsProxy: + description: |- + httpsProxy is the URL of the proxy for HTTPS requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpsProxy must be a valid URL + rule: isURL(self) + - message: httpsProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpsProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpsProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpsProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpsProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + noProxy: + description: |- + noProxy is a list of hostnames and/or CIDRs and/or IPs for which + the proxy should not be used. Must contain at least one entry + when set. Each entry must be between 1 and 253 characters long + and at most 64 entries are allowed. Duplicate + entries are not permitted. Entries that are not valid hostnames, + CIDRs, or IPs are silently ignored. Cluster-internal defaults + (.cluster.local, .svc, 127.0.0.1, localhost) are always appended + automatically and do not need to be included. + items: + maxLength: 253 + minLength: 1 + type: string + maxItems: 64 + minItems: 1 + type: array + x-kubernetes-list-type: set + trustedCA: + description: |- + trustedCA is a reference to a ConfigMap in the openshift-config + namespace containing a CA certificate bundle under the key + "ca-bundle.crt". This bundle is appended to the system trust store + used by Console's OIDC login clients for proxy TLS connections. + When omitted, only the system trust store is used. + properties: + name: + description: |- + name is the metadata.name of the referenced ConfigMap. + Must be a valid DNS subdomain name (RFC 1123): at most 253 + characters, only lowercase alphanumeric characters, '-' or + '.', starting and ending with an alphanumeric character. + maxLength: 253 + minLength: 1 + type: string + x-kubernetes-validations: + - message: 'name must be a valid DNS subdomain name: contain + no more than 253 characters, contain only lowercase alphanumeric + characters, ''-'' or ''.'', and start and end with an + alphanumeric character' + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - name + type: object + type: object + x-kubernetes-validations: + - message: at least one of httpProxy or httpsProxy must be specified + rule: has(self.httpProxy) || has(self.httpsProxy) + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-OKD.crd.yaml similarity index 99% rename from operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles.crd.yaml rename to operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-OKD.crd.yaml index ee5f83e6c58..a52fee052dc 100644 --- a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles.crd.yaml +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-OKD.crd.yaml @@ -6,6 +6,7 @@ metadata: api.openshift.io/merged-by-featuregates: "true" include.release.openshift.io/ibm-cloud-managed: "true" include.release.openshift.io/self-managed-high-availability: "true" + release.openshift.io/feature-set: OKD name: consoles.operator.openshift.io spec: group: operator.openshift.io diff --git a/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-SelfManagedHA-CustomNoUpgrade.crd.yaml b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-SelfManagedHA-CustomNoUpgrade.crd.yaml new file mode 100644 index 00000000000..2526ca14e21 --- /dev/null +++ b/operator/v1/zz_generated.crd-manifests/0000_50_console_01_consoles-SelfManagedHA-CustomNoUpgrade.crd.yaml @@ -0,0 +1,1187 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/merged-by-featuregates: "true" + include.release.openshift.io/self-managed-high-availability: "true" + release.openshift.io/feature-set: CustomNoUpgrade + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + authProxy: + description: |- + authProxy configures proxy settings for outbound connections made by + Console's OIDC login clients, including discovery, JWKS retrieval, + code exchange, and token refresh. When set, it replaces the cluster-wide + proxy (proxy.config.openshift.io/cluster) entirely for these connections; + individual fields are not inherited from the cluster-wide configuration. + At least one of httpProxy or httpsProxy must be specified. + When omitted, the cluster-wide proxy is used if configured; otherwise no + proxy is used. Other Console clients retain their existing proxy settings. + minProperties: 1 + properties: + httpProxy: + description: |- + httpProxy is the URL of the proxy for HTTP requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpProxy must be a valid URL + rule: isURL(self) + - message: httpProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + httpsProxy: + description: |- + httpsProxy is the URL of the proxy for HTTPS requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpsProxy must be a valid URL + rule: isURL(self) + - message: httpsProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpsProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpsProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpsProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpsProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + noProxy: + description: |- + noProxy is a list of hostnames and/or CIDRs and/or IPs for which + the proxy should not be used. Must contain at least one entry + when set. Each entry must be between 1 and 253 characters long + and at most 64 entries are allowed. Duplicate + entries are not permitted. Entries that are not valid hostnames, + CIDRs, or IPs are silently ignored. Cluster-internal defaults + (.cluster.local, .svc, 127.0.0.1, localhost) are always appended + automatically and do not need to be included. + items: + maxLength: 253 + minLength: 1 + type: string + maxItems: 64 + minItems: 1 + type: array + x-kubernetes-list-type: set + trustedCA: + description: |- + trustedCA is a reference to a ConfigMap in the openshift-config + namespace containing a CA certificate bundle under the key + "ca-bundle.crt". This bundle is appended to the system trust store + used by Console's OIDC login clients for proxy TLS connections. + When omitted, only the system trust store is used. + properties: + name: + description: |- + name is the metadata.name of the referenced ConfigMap. + Must be a valid DNS subdomain name (RFC 1123): at most 253 + characters, only lowercase alphanumeric characters, '-' or + '.', starting and ending with an alphanumeric character. + maxLength: 253 + minLength: 1 + type: string + x-kubernetes-validations: + - message: 'name must be a valid DNS subdomain name: contain + no more than 253 characters, contain only lowercase alphanumeric + characters, ''-'' or ''.'', and start and end with an + alphanumeric character' + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - name + type: object + type: object + x-kubernetes-validations: + - message: at least one of httpProxy or httpsProxy must be specified + rule: has(self.httpProxy) || has(self.httpsProxy) + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.deepcopy.go b/operator/v1/zz_generated.deepcopy.go index 2d410274511..0b1589d578d 100644 --- a/operator/v1/zz_generated.deepcopy.go +++ b/operator/v1/zz_generated.deepcopy.go @@ -1055,6 +1055,22 @@ func (in *Console) DeepCopyObject() runtime.Object { return nil } +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *ConsoleConfigMapReference) DeepCopyInto(out *ConsoleConfigMapReference) { + *out = *in + return +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ConsoleConfigMapReference. +func (in *ConsoleConfigMapReference) DeepCopy() *ConsoleConfigMapReference { + if in == nil { + return nil + } + out := new(ConsoleConfigMapReference) + in.DeepCopyInto(out) + return out +} + // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *ConsoleConfigRoute) DeepCopyInto(out *ConsoleConfigRoute) { *out = *in @@ -1166,10 +1182,33 @@ func (in *ConsoleProviders) DeepCopy() *ConsoleProviders { return out } +// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. +func (in *ConsoleProxyConfig) DeepCopyInto(out *ConsoleProxyConfig) { + *out = *in + if in.NoProxy != nil { + in, out := &in.NoProxy, &out.NoProxy + *out = make([]string, len(*in)) + copy(*out, *in) + } + out.TrustedCA = in.TrustedCA + return +} + +// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ConsoleProxyConfig. +func (in *ConsoleProxyConfig) DeepCopy() *ConsoleProxyConfig { + if in == nil { + return nil + } + out := new(ConsoleProxyConfig) + in.DeepCopyInto(out) + return out +} + // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. func (in *ConsoleSpec) DeepCopyInto(out *ConsoleSpec) { *out = *in in.OperatorSpec.DeepCopyInto(&out.OperatorSpec) + in.AuthProxy.DeepCopyInto(&out.AuthProxy) in.Customization.DeepCopyInto(&out.Customization) in.Providers.DeepCopyInto(&out.Providers) out.Route = in.Route diff --git a/operator/v1/zz_generated.featuregated-crd-manifests.yaml b/operator/v1/zz_generated.featuregated-crd-manifests.yaml index 7dd0b8f1b63..be86b221578 100644 --- a/operator/v1/zz_generated.featuregated-crd-manifests.yaml +++ b/operator/v1/zz_generated.featuregated-crd-manifests.yaml @@ -114,7 +114,8 @@ consoles.operator.openshift.io: CRDName: consoles.operator.openshift.io Capability: "" Category: "" - FeatureGates: [] + FeatureGates: + - AuthenticationComponentProxyExternalOIDC FilenameOperatorName: console FilenameOperatorOrdering: "01" FilenameRunLevel: "0000_50" diff --git a/operator/v1/zz_generated.featuregated-crd-manifests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDC.yaml b/operator/v1/zz_generated.featuregated-crd-manifests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDC.yaml new file mode 100644 index 00000000000..be33bc6fa44 --- /dev/null +++ b/operator/v1/zz_generated.featuregated-crd-manifests/consoles.operator.openshift.io/AuthenticationComponentProxyExternalOIDC.yaml @@ -0,0 +1,1188 @@ +apiVersion: apiextensions.k8s.io/v1 +kind: CustomResourceDefinition +metadata: + annotations: + api-approved.openshift.io: https://github.com/openshift/api/pull/486 + api.openshift.io/filename-cvo-runlevel: "0000_50" + api.openshift.io/filename-operator: console + api.openshift.io/filename-ordering: "01" + feature-gate.release.openshift.io/AuthenticationComponentProxyExternalOIDC: "true" + name: consoles.operator.openshift.io +spec: + group: operator.openshift.io + names: + kind: Console + listKind: ConsoleList + plural: consoles + singular: console + scope: Cluster + versions: + - name: v1 + schema: + openAPIV3Schema: + description: |- + Console provides a means to configure an operator to manage the console. + + Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). + properties: + apiVersion: + description: |- + APIVersion defines the versioned schema of this representation of an object. + Servers should convert recognized schemas to the latest internal value, and + may reject unrecognized values. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources + type: string + kind: + description: |- + Kind is a string value representing the REST resource this object represents. + Servers may infer this from the endpoint the client submits requests to. + Cannot be updated. + In CamelCase. + More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds + type: string + metadata: + type: object + spec: + description: ConsoleSpec is the specification of the desired behavior + of the Console. + properties: + authProxy: + description: |- + authProxy configures proxy settings for outbound connections made by + Console's OIDC login clients, including discovery, JWKS retrieval, + code exchange, and token refresh. When set, it replaces the cluster-wide + proxy (proxy.config.openshift.io/cluster) entirely for these connections; + individual fields are not inherited from the cluster-wide configuration. + At least one of httpProxy or httpsProxy must be specified. + When omitted, the cluster-wide proxy is used if configured; otherwise no + proxy is used. Other Console clients retain their existing proxy settings. + minProperties: 1 + properties: + httpProxy: + description: |- + httpProxy is the URL of the proxy for HTTP requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpProxy must be a valid URL + rule: isURL(self) + - message: httpProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + httpsProxy: + description: |- + httpsProxy is the URL of the proxy for HTTPS requests. + Must be a valid URL with http or https scheme, a non-empty + hostname, and no path, query parameters, or fragment. + Userinfo (e.g. user:password@host) is allowed for proxy + authentication. Maximum length is 2048 characters. + maxLength: 2048 + minLength: 1 + type: string + x-kubernetes-validations: + - message: httpsProxy must be a valid URL + rule: isURL(self) + - message: httpsProxy must use http or https scheme + rule: '!isURL(self) || url(self).getScheme() in [''http'', ''https'']' + - message: httpsProxy must contain a hostname + rule: '!isURL(self) || size(url(self).getHostname()) > 0' + - message: httpsProxy must not contain a path + rule: '!isURL(self) || url(self).getEscapedPath() == '''' || + url(self).getEscapedPath() == ''/''' + - message: httpsProxy must not contain query parameters + rule: '!isURL(self) || url(self).getQuery().size() == 0' + - message: httpsProxy must not contain a fragment + rule: '!self.matches(''.*#.*'')' + noProxy: + description: |- + noProxy is a list of hostnames and/or CIDRs and/or IPs for which + the proxy should not be used. Must contain at least one entry + when set. Each entry must be between 1 and 253 characters long + and at most 64 entries are allowed. Duplicate + entries are not permitted. Entries that are not valid hostnames, + CIDRs, or IPs are silently ignored. Cluster-internal defaults + (.cluster.local, .svc, 127.0.0.1, localhost) are always appended + automatically and do not need to be included. + items: + maxLength: 253 + minLength: 1 + type: string + maxItems: 64 + minItems: 1 + type: array + x-kubernetes-list-type: set + trustedCA: + description: |- + trustedCA is a reference to a ConfigMap in the openshift-config + namespace containing a CA certificate bundle under the key + "ca-bundle.crt". This bundle is appended to the system trust store + used by Console's OIDC login clients for proxy TLS connections. + When omitted, only the system trust store is used. + properties: + name: + description: |- + name is the metadata.name of the referenced ConfigMap. + Must be a valid DNS subdomain name (RFC 1123): at most 253 + characters, only lowercase alphanumeric characters, '-' or + '.', starting and ending with an alphanumeric character. + maxLength: 253 + minLength: 1 + type: string + x-kubernetes-validations: + - message: 'name must be a valid DNS subdomain name: contain + no more than 253 characters, contain only lowercase alphanumeric + characters, ''-'' or ''.'', and start and end with an + alphanumeric character' + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - name + type: object + type: object + x-kubernetes-validations: + - message: at least one of httpProxy or httpsProxy must be specified + rule: has(self.httpProxy) || has(self.httpsProxy) + customization: + description: |- + customization is used to optionally provide a small set of + customization options to the web console. + properties: + addPage: + description: addPage allows customizing actions on the Add page + in developer perspective. + properties: + disabledActions: + description: |- + disabledActions is a list of actions that are not shown to users. + Each action in the list is represented by its ID. + items: + type: string + minItems: 1 + type: array + type: object + brand: + description: |- + brand is the default branding of the web console which can be overridden by + providing the brand field. There is a limited set of specific brand options. + This field controls elements of the console such as the logo. + Invalid value will prevent a console rollout. + enum: + - openshift + - okd + - online + - ocp + - dedicated + - azure + - OpenShift + - OKD + - Online + - OCP + - Dedicated + - Azure + - ROSA + type: string + capabilities: + description: |- + capabilities defines an array of capabilities that can be interacted with in the console UI. + Each capability defines a visual state that can be interacted with the console to render in the UI. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + Each of the available capabilities may appear only once in the list. + items: + description: Capabilities contains set of UI capabilities and + their state in the console UI. + properties: + name: + description: |- + name is the unique name of a capability. + Available capabilities are LightspeedButton, GettingStartedBanner, and GuidedTour. + enum: + - LightspeedButton + - GettingStartedBanner + - GuidedTour + type: string + visibility: + description: visibility defines the visibility state of + the capability. + properties: + state: + description: |- + state defines if the capability is enabled or disabled in the console UI. + Enabling the capability in the console UI is represented by the "Enabled" value. + Disabling the capability in the console UI is represented by the "Disabled" value. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + required: + - name + - visibility + type: object + maxItems: 3 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map + customLogoFile: + description: |- + customLogoFile replaces the default OpenShift logo in the masthead and about dialog. It is a reference to a + Only one of customLogoFile or logos can be set at a time. + ConfigMap in the openshift-config namespace. This can be created with a command like + 'oc create configmap custom-logo --from-file=/path/to/file -n openshift-config'. + Image size must be less than 1 MB due to constraints on the ConfigMap size. + The ConfigMap key should include a file extension so that the console serves the file + with the correct MIME type. + The recommended file format for the logo is SVG, but other file formats are allowed if supported by the browser. + Deprecated: Use logos instead. + properties: + key: + description: key allows pointing to a specific key/value inside + of the configmap. This is useful for logical file references. + type: string + name: + type: string + type: object + customProductName: + description: |- + customProductName is the name that will be displayed in page titles, logo alt text, and the about dialog + instead of the normal OpenShift product name. + type: string + developerCatalog: + description: developerCatalog allows to configure the shown developer + catalog categories (filters) and types (sub-catalogs). + properties: + categories: + description: categories which are shown in the developer catalog. + items: + description: DeveloperConsoleCatalogCategory for the developer + console catalog. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display label. + It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + subcategories: + description: subcategories defines a list of child categories. + items: + description: DeveloperConsoleCatalogCategoryMeta are + the key identifiers of a developer catalog category. + properties: + id: + description: |- + id is an identifier used in the URL to enable deep linking in console. + ID is required and must have 1-32 URL safe (A-Z, a-z, 0-9, - and _) characters. + maxLength: 32 + minLength: 1 + pattern: ^[A-Za-z0-9-_]+$ + type: string + label: + description: label defines a category display + label. It is required and must have 1-64 characters. + maxLength: 64 + minLength: 1 + type: string + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + tags: + description: |- + tags is a list of strings that will match the category. A selected category + show all items which has at least one overlapping tag between category and item. + items: + type: string + type: array + required: + - id + - label + type: object + type: array + types: + description: |- + types allows enabling or disabling of sub-catalog types that user can see in the Developer catalog. + When omitted, all the sub-catalog types will be shown. + properties: + disabled: + description: |- + disabled is a list of developer catalog types (sub-catalogs IDs) that are not shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is empty or all the available sub-catalog types are added, then the complete developer catalog should be hidden. + items: + type: string + type: array + x-kubernetes-list-type: set + enabled: + description: |- + enabled is a list of developer catalog types (sub-catalogs IDs) that will be shown to users. + Types (sub-catalogs) are added via console plugins, the available types (sub-catalog IDs) are available + in the console on the cluster configuration page, or when editing the YAML in the console. + Example: "Devfile", "HelmChart", "BuilderImage" + If the list is non-empty, a new type will not be shown to the user until it is added to list. + If the list is empty the complete developer catalog will be shown. + items: + type: string + type: array + x-kubernetes-list-type: set + state: + default: Enabled + description: state defines if a list of catalog types + should be enabled or disabled. + enum: + - Enabled + - Disabled + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: enabled is forbidden when state is not Enabled + rule: 'self.state == ''Enabled'' ? true : !has(self.enabled)' + - message: disabled is forbidden when state is not Disabled + rule: 'self.state == ''Disabled'' ? true : !has(self.disabled)' + type: object + documentationBaseURL: + description: |- + documentationBaseURL links to external documentation are shown in various sections + of the web console. Providing documentationBaseURL will override the default + documentation URL. + Invalid value will prevent a console rollout. + pattern: ^$|^((https):\/\/?)[^\s()<>]+(?:\([\w\d]+\)|([^[:punct:]\s]|\/?))\/$ + type: string + logos: + description: |- + logos is used to replace the OpenShift Masthead and Favicon logos in the console UI with custom logos. + logos is an optional field that allows a list of logos. + Only one of logos or customLogoFile can be set at a time. + If logos is set, customLogoFile must be unset. + When specified, there must be at least one entry and no more than 2 entries. + Each type must appear only once in the list. + items: + description: Logo defines a configuration based on theme modes + for the console UI logo. + properties: + themes: + description: |- + themes specifies the themes for the console UI logo. + themes is a required field that allows a list of themes. Each item in the themes list must have a unique mode and a source field. + Each mode determines whether the logo is for the dark or light mode of the console UI. + If a theme is not specified, the default OpenShift logo will be displayed for that theme. + There must be at least one entry and no more than 2 entries. + items: + description: Theme defines a theme mode for the console + UI. + properties: + mode: + description: |- + mode is used to specify what theme mode a logo will apply to in the console UI. + mode is a required field that allows values of Dark and Light. + When set to Dark, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Dark mode. + When set to Light, the logo file referenced in the 'file' field will be used when an end-user of the console UI enables the Light mode. + enum: + - Dark + - Light + type: string + source: + description: |- + source is used by the console to locate the specified file containing a custom logo. + source is a required field that references a ConfigMap name and key that contains the custom logo file in the openshift-config namespace. + You can create it with a command like: + - 'oc create configmap custom-logos-config --namespace=openshift-config --from-file=/path/to/file' + The ConfigMap key must include the file extension so that the console serves the file with the correct MIME type. + The recommended file format for the Masthead and Favicon logos is SVG, but other file formats are allowed if supported by the browser. + The logo image size must be less than 1 MB due to constraints on the ConfigMap size. + For more information, see the documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/web_console/customizing-web-console#customizing-web-console + properties: + configMap: + description: |- + configMap specifies the ConfigMap sourcing details such as the name of the ConfigMap and the key for the file. + The ConfigMap must exist in the openshift-config namespace. + Required when from is "ConfigMap", and forbidden otherwise. + properties: + key: + description: |- + key is the logo key inside the referenced ConfigMap. + Must consist only of alphanumeric characters, dashes (-), underscores (_), and periods (.). + Must be at most 253 characters in length. + Must end in a valid file extension. + A valid file extension must consist of a period followed by 2 to 5 alpha characters. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: The ConfigMap key must consist + only of alphanumeric characters, dashes + (-), underscores (_), and periods (.). + rule: self.matches('^[a-zA-Z0-9._-]+$') + - message: The ConfigMap key must end with + a valid file extension (2 to 5 letters). + rule: self.matches('.*\\.[a-zA-Z]{2,5}$') + name: + description: |- + name is the name of the ConfigMap. + name is a required field. + Must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character. + Must be at most 253 characters in length. + maxLength: 253 + type: string + x-kubernetes-validations: + - message: a lowercase RFC 1123 subdomain + must consist of lower case alphanumeric + characters, '-' or '.', and must start + and end with an alphanumeric character. + rule: '!format.dns1123Subdomain().validate(self).hasValue()' + required: + - key + - name + type: object + from: + description: |- + from is a required field to specify the source type of the file reference. + Allowed values are ConfigMap. + When set to ConfigMap, the file will be sourced from a ConfigMap in the openshift-config namespace. The configMap field must be set when from is set to ConfigMap. + enum: + - ConfigMap + type: string + required: + - from + type: object + x-kubernetes-validations: + - message: configMap is required when from is 'ConfigMap', + and forbidden otherwise. + rule: 'has(self.from) && self.from == ''ConfigMap'' + ? has(self.configMap) : !has(self.configMap)' + required: + - mode + - source + type: object + maxItems: 2 + minItems: 1 + type: array + x-kubernetes-list-map-keys: + - mode + x-kubernetes-list-type: map + type: + description: |- + type specifies the type of the logo for the console UI. It determines whether the logo is for the masthead or favicon. + type is a required field that allows values of Masthead and Favicon. + When set to "Masthead", the logo will be used in the masthead and about modal of the console UI. + When set to "Favicon", the logo will be used as the favicon of the console UI. + enum: + - Masthead + - Favicon + type: string + required: + - themes + - type + type: object + maxItems: 2 + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + perspectives: + description: perspectives allows enabling/disabling of perspective(s) + that user can see in the Perspective switcher dropdown. + items: + description: Perspective defines a perspective that cluster + admins want to show/hide in the perspective switcher dropdown + properties: + id: + description: |- + id defines the id of the perspective. + Example: "dev", "admin". + The available perspective ids can be found in the code snippet section next to the yaml editor. + Incorrect or unknown ids will be ignored. + type: string + pinnedResources: + description: |- + pinnedResources defines the list of default pinned resources that users will see on the perspective navigation if they have not customized these pinned resources themselves. + The list of available Kubernetes resources could be read via `kubectl api-resources`. + The console will also provide a configuration UI and a YAML snippet that will list the available resources that can be pinned to the navigation. + Incorrect or unknown resources will be ignored. + items: + description: PinnedResourceReference includes the group, + version and type of resource + properties: + group: + description: |- + group is the API Group of the Resource. + Enter empty string for the core group. + This value should consist of only lowercase alphanumeric characters, hyphens and periods. + Example: "", "apps", "build.openshift.io", etc. + pattern: ^$|^[a-z0-9]([-a-z0-9]*[a-z0-9])?(.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ + type: string + resource: + description: |- + resource is the type that is being referenced. + It is normally the plural form of the resource kind in lowercase. + This value should consist of only lowercase alphanumeric characters and hyphens. + Example: "deployments", "deploymentconfigs", "pods", etc. + pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ + type: string + version: + description: |- + version is the API Version of the Resource. + This value should consist of only lowercase alphanumeric characters. + Example: "v1", "v1beta1", etc. + pattern: ^[a-z0-9]+$ + type: string + required: + - group + - resource + - version + type: object + maxItems: 100 + type: array + visibility: + description: visibility defines the state of perspective + along with access review checks if needed for that perspective. + properties: + accessReview: + description: accessReview defines required and missing + access review checks. + minProperties: 1 + properties: + missing: + description: missing defines a list of permission + checks. The perspective will only be shown when + at least one check fails. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the required access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + required: + description: required defines a list of permission + checks. The perspective will only be shown when + all checks are successful. When omitted, the access + review is skipped and the perspective will not + be shown unless it is required to do so based + on the configuration of the missing access review + list. + items: + description: ResourceAttributes includes the authorization + attributes available for resource requests to + the Authorizer interface + properties: + fieldSelector: + description: fieldSelector describes the limitation + on access based on field. It can only limit + access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a field selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + FieldSelectorRequirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the field selector + key that the requirement applies + to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists, DoesNotExist. + The list of operators may grow in the future. + type: string + values: + description: |- + values is an array of string values. + If the operator is In or NotIn, the values array must be non-empty. + If the operator is Exists or DoesNotExist, the values array must be empty. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + group: + description: group is the API Group of the + Resource. "*" means all. + type: string + labelSelector: + description: labelSelector describes the limitation + on access based on labels. It can only + limit access, not broaden it. + properties: + rawSelector: + description: |- + rawSelector is the serialization of a field selector that would be included in a query parameter. + Webhook implementations are encouraged to ignore rawSelector. + The kube-apiserver's *SubjectAccessReview will parse the rawSelector as long as the requirements are not present. + type: string + requirements: + description: |- + requirements is the parsed interpretation of a label selector. + All requirements must be met for a resource instance to match the selector. + Webhook implementations should handle requirements, but how to handle them is up to the webhook. + Since requirements can only limit the request, it is safe to authorize as unlimited request if the requirements + are not understood. + items: + description: |- + A label selector requirement is a selector that contains values, a key, and an operator that + relates the key and values. + properties: + key: + description: key is the label key + that the selector applies to. + type: string + operator: + description: |- + operator represents a key's relationship to a set of values. + Valid operators are In, NotIn, Exists and DoesNotExist. + type: string + values: + description: |- + values is an array of string values. If the operator is In or NotIn, + the values array must be non-empty. If the operator is Exists or DoesNotExist, + the values array must be empty. This array is replaced during a strategic + merge patch. + items: + type: string + type: array + x-kubernetes-list-type: atomic + required: + - key + - operator + type: object + type: array + x-kubernetes-list-type: atomic + type: object + name: + description: name is the name of the resource + being requested for a "get" or deleted for + a "delete". "" (empty) means all. + type: string + namespace: + description: |- + namespace is the namespace of the action being requested. Currently, there is no distinction between no namespace and all namespaces + "" (empty) is defaulted for LocalSubjectAccessReviews + "" (empty) is empty for cluster-scoped resources + "" (empty) means "all" for namespace scoped resources from a SubjectAccessReview or SelfSubjectAccessReview + type: string + resource: + description: resource is one of the existing + resource types. "*" means all. + type: string + subresource: + description: subresource is one of the existing + resource types. "" means none. + type: string + verb: + description: 'verb is a kubernetes resource + API verb, like: get, list, watch, create, + update, delete, proxy. "*" means all.' + type: string + version: + description: version is the API Version of + the Resource. "*" means all. + type: string + type: object + type: array + type: object + state: + description: state defines the perspective is enabled + or disabled or access review check is required. + enum: + - Enabled + - Disabled + - AccessReview + type: string + required: + - state + type: object + x-kubernetes-validations: + - message: accessReview configuration is required when state + is AccessReview, and forbidden otherwise + rule: 'self.state == ''AccessReview'' ? has(self.accessReview) + : !has(self.accessReview)' + required: + - id + - visibility + type: object + x-kubernetes-validations: + - message: pinnedResources is allowed only for dev and forbidden + for other perspectives + rule: 'has(self.id) && self.id != ''dev''? !has(self.pinnedResources) + : true' + type: array + x-kubernetes-list-map-keys: + - id + x-kubernetes-list-type: map + projectAccess: + description: |- + projectAccess allows customizing the available list of ClusterRoles in the Developer perspective + Project access page which can be used by a project admin to specify roles to other users and + restrict access within the project. If set, the list will replace the default ClusterRole options. + properties: + availableClusterRoles: + description: |- + availableClusterRoles is the list of ClusterRole names that are assignable to users + through the project access tab. + items: + type: string + type: array + type: object + quickStarts: + description: quickStarts allows customization of available ConsoleQuickStart + resources in console. + properties: + disabled: + description: disabled is a list of ConsoleQuickStart resource + names that are not shown to users. + items: + type: string + type: array + type: object + type: object + x-kubernetes-validations: + - message: Only one of logos or customLogoFile can be set. + rule: '!(has(self.logos) && has(self.customLogoFile))' + ingress: + description: |- + ingress allows to configure the alternative ingress for the console. + This field is intended for clusters without ingress capability, + where access to routes is not possible. + properties: + clientDownloadsURL: + description: |- + clientDownloadsURL is a URL to be used as the address to download client binaries. + If not specified, the downloads route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: client downloads url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: client downloads url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + consoleURL: + description: |- + consoleURL is a URL to be used as the base console address. + If not specified, the console route hostname will be used. + This field is required for clusters without ingress capability, + where access to routes is not possible. + Make sure that appropriate ingress is set up at this URL. + The console operator will monitor the URL and may go degraded + if it's unreachable for an extended period. + Must use the HTTPS scheme. + maxLength: 1024 + type: string + x-kubernetes-validations: + - message: console url must be a valid absolute URL + rule: size(self) == 0 || isURL(self) + - message: console url scheme must be https + rule: size(self) == 0 || url(self).getScheme() == 'https' + type: object + logLevel: + default: Normal + description: |- + logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for their operands. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + managementState: + description: managementState indicates whether and how the operator + should manage the component + pattern: ^(Managed|Unmanaged|Force|Removed)$ + type: string + observedConfig: + description: |- + observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because + it is an input to the level for the operator + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + operatorLogLevel: + default: Normal + description: |- + operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a + simple way to manage coarse grained logging choices that operators have to interpret for themselves. + + Valid values are: "Normal", "Debug", "Trace", "TraceAll". + Defaults to "Normal". + enum: + - "" + - Normal + - Debug + - Trace + - TraceAll + type: string + plugins: + description: plugins defines a list of enabled console plugin names. + items: + type: string + type: array + providers: + description: providers contains configuration for using specific service + providers. + properties: + statuspage: + description: statuspage contains ID for statuspage.io page that + provides status info about. + properties: + pageID: + description: pageID is the unique ID assigned by Statuspage + for your page. This must be a public page. + type: string + type: object + type: object + route: + description: |- + route contains hostname and secret reference that contains the serving certificate. + If a custom route is specified, a new route will be created with the + provided hostname, under which console will be available. + In case of custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. + The default console route will be maintained to reserve the default hostname + for console if the custom route is removed. + If not specified, default route will be used. + DEPRECATED + properties: + hostname: + description: hostname is the desired custom domain under which + console will be available. + type: string + secret: + description: |- + secret points to secret in the openshift-config namespace that contains custom + certificate and key and needs to be created manually by the cluster admin. + Referenced Secret is required to contain following key value pairs: + - "tls.crt" - to specifies custom certificate + - "tls.key" - to specifies private key of the custom certificate + If the custom hostname uses the default routing suffix of the cluster, + the Secret specification for a serving certificate will not be needed. + properties: + name: + description: name is the metadata.name of the referenced secret + type: string + required: + - name + type: object + type: object + unsupportedConfigOverrides: + description: |- + unsupportedConfigOverrides overrides the final configuration that was computed by the operator. + Red Hat does not support the use of this field. + Misuse of this field could lead to unexpected behavior or conflict with other configuration options. + Seek guidance from the Red Hat support before using this field. + Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster. + nullable: true + type: object + x-kubernetes-preserve-unknown-fields: true + type: object + status: + description: ConsoleStatus defines the observed status of the Console. + properties: + conditions: + description: conditions is a list of conditions and their status + items: + description: OperatorCondition is just the standard condition fields. + properties: + lastTransitionTime: + description: |- + lastTransitionTime is the last time the condition transitioned from one status to another. + This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. + format: date-time + type: string + message: + type: string + reason: + type: string + status: + description: status of the condition, one of True, False, Unknown. + enum: + - "True" + - "False" + - Unknown + type: string + type: + description: type of condition in CamelCase or in foo.example.com/CamelCase. + maxLength: 316 + pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ + type: string + required: + - lastTransitionTime + - status + - type + type: object + type: array + x-kubernetes-list-map-keys: + - type + x-kubernetes-list-type: map + generations: + description: generations are used to determine when an item needs + to be reconciled or has changed in a way that needs a reaction. + items: + description: GenerationStatus keeps track of the generation for + a given resource so that decisions about forced updates can be + made. + properties: + group: + description: group is the group of the thing you're tracking + type: string + hash: + description: hash is an optional field set for resources without + generation that are content sensitive like secrets and configmaps + type: string + lastGeneration: + description: lastGeneration is the last generation of the workload + controller involved + format: int64 + type: integer + name: + description: name is the name of the thing you're tracking + type: string + namespace: + description: namespace is where the thing you're tracking is + type: string + resource: + description: resource is the resource type of the thing you're + tracking + type: string + required: + - group + - name + - namespace + - resource + type: object + type: array + x-kubernetes-list-map-keys: + - group + - resource + - namespace + - name + x-kubernetes-list-type: map + latestAvailableRevision: + description: latestAvailableRevision is the deploymentID of the most + recent deployment + format: int32 + type: integer + x-kubernetes-validations: + - message: must only increase + rule: self >= oldSelf + observedGeneration: + description: observedGeneration is the last generation change you've + dealt with + format: int64 + type: integer + readyReplicas: + description: readyReplicas indicates how many replicas are ready and + at the desired state + format: int32 + type: integer + version: + description: version is the level this availability applies to + type: string + type: object + required: + - spec + type: object + served: true + storage: true + subresources: + status: {} diff --git a/operator/v1/zz_generated.model_name.go b/operator/v1/zz_generated.model_name.go index 13ab0c5f6f2..0e04439a002 100644 --- a/operator/v1/zz_generated.model_name.go +++ b/operator/v1/zz_generated.model_name.go @@ -240,6 +240,11 @@ func (in Console) OpenAPIModelName() string { return "com.github.openshift.api.operator.v1.Console" } +// OpenAPIModelName returns the OpenAPI model name for this type. +func (in ConsoleConfigMapReference) OpenAPIModelName() string { + return "com.github.openshift.api.operator.v1.ConsoleConfigMapReference" +} + // OpenAPIModelName returns the OpenAPI model name for this type. func (in ConsoleConfigRoute) OpenAPIModelName() string { return "com.github.openshift.api.operator.v1.ConsoleConfigRoute" @@ -260,6 +265,11 @@ func (in ConsoleProviders) OpenAPIModelName() string { return "com.github.openshift.api.operator.v1.ConsoleProviders" } +// OpenAPIModelName returns the OpenAPI model name for this type. +func (in ConsoleProxyConfig) OpenAPIModelName() string { + return "com.github.openshift.api.operator.v1.ConsoleProxyConfig" +} + // OpenAPIModelName returns the OpenAPI model name for this type. func (in ConsoleSpec) OpenAPIModelName() string { return "com.github.openshift.api.operator.v1.ConsoleSpec" diff --git a/operator/v1/zz_generated.swagger_doc_generated.go b/operator/v1/zz_generated.swagger_doc_generated.go index 891d75adc29..2ddcc7b6c2c 100644 --- a/operator/v1/zz_generated.swagger_doc_generated.go +++ b/operator/v1/zz_generated.swagger_doc_generated.go @@ -277,6 +277,15 @@ func (Console) SwaggerDoc() map[string]string { return map_Console } +var map_ConsoleConfigMapReference = map[string]string{ + "": "ConsoleConfigMapReference references a ConfigMap in the openshift-config namespace.", + "name": "name is the metadata.name of the referenced ConfigMap. Must be a valid DNS subdomain name (RFC 1123): at most 253 characters, only lowercase alphanumeric characters, '-' or '.', starting and ending with an alphanumeric character.", +} + +func (ConsoleConfigMapReference) SwaggerDoc() map[string]string { + return map_ConsoleConfigMapReference +} + var map_ConsoleConfigRoute = map[string]string{ "": "ConsoleConfigRoute holds information on external route access to console. DEPRECATED", "hostname": "hostname is the desired custom domain under which console will be available.", @@ -324,8 +333,21 @@ func (ConsoleProviders) SwaggerDoc() map[string]string { return map_ConsoleProviders } +var map_ConsoleProxyConfig = map[string]string{ + "": "ConsoleProxyConfig holds proxy configuration scoped to Console's OIDC login clients. At least one of httpProxy or httpsProxy must be specified.", + "httpProxy": "httpProxy is the URL of the proxy for HTTP requests. Must be a valid URL with http or https scheme, a non-empty hostname, and no path, query parameters, or fragment. Userinfo (e.g. user:password@host) is allowed for proxy authentication. Maximum length is 2048 characters.", + "httpsProxy": "httpsProxy is the URL of the proxy for HTTPS requests. Must be a valid URL with http or https scheme, a non-empty hostname, and no path, query parameters, or fragment. Userinfo (e.g. user:password@host) is allowed for proxy authentication. Maximum length is 2048 characters.", + "noProxy": "noProxy is a list of hostnames and/or CIDRs and/or IPs for which the proxy should not be used. Must contain at least one entry when set. Each entry must be between 1 and 253 characters long and at most 64 entries are allowed. Duplicate entries are not permitted. Entries that are not valid hostnames, CIDRs, or IPs are silently ignored. Cluster-internal defaults (.cluster.local, .svc, 127.0.0.1, localhost) are always appended automatically and do not need to be included.", + "trustedCA": "trustedCA is a reference to a ConfigMap in the openshift-config namespace containing a CA certificate bundle under the key \"ca-bundle.crt\". This bundle is appended to the system trust store used by Console's OIDC login clients for proxy TLS connections. When omitted, only the system trust store is used.", +} + +func (ConsoleProxyConfig) SwaggerDoc() map[string]string { + return map_ConsoleProxyConfig +} + var map_ConsoleSpec = map[string]string{ "": "ConsoleSpec is the specification of the desired behavior of the Console.", + "authProxy": "authProxy configures proxy settings for outbound connections made by Console's OIDC login clients, including discovery, JWKS retrieval, code exchange, and token refresh. When set, it replaces the cluster-wide proxy (proxy.config.openshift.io/cluster) entirely for these connections; individual fields are not inherited from the cluster-wide configuration. At least one of httpProxy or httpsProxy must be specified. When omitted, the cluster-wide proxy is used if configured; otherwise no proxy is used. Other Console clients retain their existing proxy settings.", "customization": "customization is used to optionally provide a small set of customization options to the web console.", "providers": "providers contains configuration for using specific service providers.", "route": "route contains hostname and secret reference that contains the serving certificate. If a custom route is specified, a new route will be created with the provided hostname, under which console will be available. In case of custom hostname uses the default routing suffix of the cluster, the Secret specification for a serving certificate will not be needed. In case of custom hostname points to an arbitrary domain, manual DNS configurations steps are necessary. The default console route will be maintained to reserve the default hostname for console if the custom route is removed. If not specified, default route will be used. DEPRECATED", diff --git a/payload-manifests/featuregates/featureGate-4-10-Hypershift-Default.yaml b/payload-manifests/featuregates/featureGate-4-10-Hypershift-Default.yaml index d99a35ff03f..676beb887f0 100644 --- a/payload-manifests/featuregates/featureGate-4-10-Hypershift-Default.yaml +++ b/payload-manifests/featuregates/featureGate-4-10-Hypershift-Default.yaml @@ -26,6 +26,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-4-10-Hypershift-DevPreviewNoUpgrade.yaml b/payload-manifests/featuregates/featureGate-4-10-Hypershift-DevPreviewNoUpgrade.yaml index 310647a4773..96d66edb23d 100644 --- a/payload-manifests/featuregates/featureGate-4-10-Hypershift-DevPreviewNoUpgrade.yaml +++ b/payload-manifests/featuregates/featureGate-4-10-Hypershift-DevPreviewNoUpgrade.yaml @@ -108,6 +108,9 @@ { "name": "AdditionalStorageConfig" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-4-10-Hypershift-OKD.yaml b/payload-manifests/featuregates/featureGate-4-10-Hypershift-OKD.yaml index b4aecd8327b..a5f457e1e36 100644 --- a/payload-manifests/featuregates/featureGate-4-10-Hypershift-OKD.yaml +++ b/payload-manifests/featuregates/featureGate-4-10-Hypershift-OKD.yaml @@ -28,6 +28,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-4-10-Hypershift-TechPreviewNoUpgrade.yaml b/payload-manifests/featuregates/featureGate-4-10-Hypershift-TechPreviewNoUpgrade.yaml index 7e4882ca9ac..ae69841cf99 100644 --- a/payload-manifests/featuregates/featureGate-4-10-Hypershift-TechPreviewNoUpgrade.yaml +++ b/payload-manifests/featuregates/featureGate-4-10-Hypershift-TechPreviewNoUpgrade.yaml @@ -141,6 +141,9 @@ { "name": "AdditionalStorageConfig" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-4-SelfManagedHA-Default.yaml b/payload-manifests/featuregates/featureGate-4-SelfManagedHA-Default.yaml index d1c737843a1..2bb41045075 100644 --- a/payload-manifests/featuregates/featureGate-4-SelfManagedHA-Default.yaml +++ b/payload-manifests/featuregates/featureGate-4-SelfManagedHA-Default.yaml @@ -26,6 +26,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-4-SelfManagedHA-DevPreviewNoUpgrade.yaml b/payload-manifests/featuregates/featureGate-4-SelfManagedHA-DevPreviewNoUpgrade.yaml index d9565d65dd9..139a59984ad 100644 --- a/payload-manifests/featuregates/featureGate-4-SelfManagedHA-DevPreviewNoUpgrade.yaml +++ b/payload-manifests/featuregates/featureGate-4-SelfManagedHA-DevPreviewNoUpgrade.yaml @@ -78,6 +78,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-4-SelfManagedHA-OKD.yaml b/payload-manifests/featuregates/featureGate-4-SelfManagedHA-OKD.yaml index 53bbc1d725f..903eb12d305 100644 --- a/payload-manifests/featuregates/featureGate-4-SelfManagedHA-OKD.yaml +++ b/payload-manifests/featuregates/featureGate-4-SelfManagedHA-OKD.yaml @@ -28,6 +28,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-4-SelfManagedHA-TechPreviewNoUpgrade.yaml b/payload-manifests/featuregates/featureGate-4-SelfManagedHA-TechPreviewNoUpgrade.yaml index 66dfa3501ab..490da5f8e4c 100644 --- a/payload-manifests/featuregates/featureGate-4-SelfManagedHA-TechPreviewNoUpgrade.yaml +++ b/payload-manifests/featuregates/featureGate-4-SelfManagedHA-TechPreviewNoUpgrade.yaml @@ -120,6 +120,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-Default.yaml b/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-Default.yaml index e4c9366c1ab..584ea1b2f5f 100644 --- a/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-Default.yaml +++ b/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-Default.yaml @@ -26,6 +26,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-DevPreviewNoUpgrade.yaml b/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-DevPreviewNoUpgrade.yaml index 2bc7c070b11..6cc250942b1 100644 --- a/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-DevPreviewNoUpgrade.yaml +++ b/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-DevPreviewNoUpgrade.yaml @@ -75,6 +75,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-OKD.yaml b/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-OKD.yaml index 53ed8ce90f7..40b29877ed0 100644 --- a/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-OKD.yaml +++ b/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-OKD.yaml @@ -28,6 +28,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" }, diff --git a/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-TechPreviewNoUpgrade.yaml b/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-TechPreviewNoUpgrade.yaml index 19e343c9124..5c9890b4483 100644 --- a/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-TechPreviewNoUpgrade.yaml +++ b/payload-manifests/featuregates/featureGate-5-10-SelfManagedHA-TechPreviewNoUpgrade.yaml @@ -117,6 +117,9 @@ { "name": "AuthenticationComponentProxy" }, + { + "name": "AuthenticationComponentProxyExternalOIDC" + }, { "name": "AutomatedEtcdBackup" },