v1alpha1

package
v0.8.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 21 Imported by: 0

Documentation

Overview

Package v1alpha1 contains API Schema definitions for the db v1alpha1 API group +kubebuilder:object:generate=true +groupName=db.atlasgo.io

Index

Constants

View Source
const (
	SchemaTypeAtlas = "atlas"
	SchemaTypeFile  = "file"
)

Schema reader types (URL schemes).

View Source
const (
	// ReasonReconciling represents for the reconciliation is in progress.
	ReasonReconciling = "Reconciling"
	// ReasonGettingDevDB represents the reason for getting the dev database.
	ReasonGettingDevDB = "GettingDevDB"
	// ReasonWhoAmI represents the reason for getting the current user via Atlas CLI
	ReasonWhoAmI = "WhoAmI"
	// ReasonApplyingMigration represents the reason for applied a schema/migration resource successfully.
	ReasonApplied = "Applied"
	// ReasonApprovalPending represents the reason for the approval is pending.
	ReasonApprovalPending = "ApprovalPending"
	// ReasonCreatingAtlasClient represents the reason for creating an Atlas client.
	ReasonCreatingAtlasClient = "CreatingAtlasClient"
	// ReasonCreatingWorkingDir represents the reason for creating a working directory.
	ReasonCreatingWorkingDir = "CreatingWorkingDir"
	// ReasonLogin represents the reason for logging in to Atlas.
	ReasonLogin = "Login"
	// ReasonReadingMigrationData represents the reason for getting the data of an AtlasMigration resource.
	ReasonReadingMigrationData = "ReadingMigrationData"
	// ReasonMigrating represents the reason for migrating a database.
	ReasonMigrating = "Migrating"
	// ReasonStoringDirState represents the reason for storing the state of an AtlasMigration resource.
	ReasonStoringDirState = "StoringDirState"
	// ReasonDriftDetected represents the reason for the pre-apply drift check blocking a migration.
	ReasonDriftDetected = "DriftDetected"
	// ReasonChecked represents the reason for a completed drift check.
	ReasonChecked = "Checked"
	// ReasonNoDrift represents the reason for a drift check that found no drift.
	ReasonNoDrift = "NoDrift"
	// ReasonCheckFailed represents the reason for a drift check that could not be completed.
	ReasonCheckFailed = "CheckFailed"
	// ReasonTargetNotFound represents the reason for a missing target resource.
	ReasonTargetNotFound = "TargetNotFound"
	// ReasonTargetNotReady represents the reason for a target resource that is mid-apply.
	ReasonTargetNotReady = "TargetNotReady"
	// ReasonSuspended represents the reason for a suspended resource.
	ReasonSuspended = "Suspended"
	// ReasonNoMigrationHistory represents the reason for a database with no applied migrations.
	ReasonNoMigrationHistory = "NoMigrationHistory"
	// Reasons of the AtlasSecurityScan conditions. Their messages are fixed text:
	// CLI and driver output never reaches a condition or an Event.
	ReasonScanning             = "Scanning"
	ReasonScanned              = "Scanned"
	ReasonRetrying             = "Retrying"
	ReasonScanFailed           = "ScanFailed"
	ReasonLoginFailed          = "LoginFailed"
	ReasonCLIError             = "CLIError"
	ReasonReadingInputs        = "ReadingInputs"
	ReasonStoringReport        = "StoringReport"
	ReasonBackoffLimitExceeded = "BackoffLimitExceeded"
	ReasonInvalidSchedule      = "InvalidSchedule"
	ReasonInvalidTimeZone      = "InvalidTimeZone"
	ReasonInvalidTarget        = "InvalidTarget"
	ReasonNotScanned           = "NotScanned"
	ReasonNoThreshold          = "NoThreshold"
	ReasonWithinPolicy         = "WithinPolicy"
	ReasonPolicyViolated       = "PolicyViolated"
	ReasonReportStale          = "ReportStale"
	// Event-only reasons of the AtlasSecurityScan controller.
	EventTriggerNotFound = "TriggerNotFound"
	EventMissedSchedule  = "MissedSchedule"
	EventScanWarning     = "ScanWarning"
	EventResumed         = "Resumed"
)
View Source
const (
	// AnnotationScanRequestedAt requests a scan. Any new value triggers one scan; the value
	// is echoed to status.lastHandledScanRequest when that scan completes successfully.
	AnnotationScanRequestedAt = "db.atlasgo.io/scan-requested-at"
)

Variables

View Source
var (
	// GroupVersion is group version used to register these objects
	GroupVersion = schema.GroupVersion{Group: "db.atlasgo.io", Version: "v1alpha1"}

	// SchemeBuilder is used to add go types to the GroupVersionKind scheme
	SchemeBuilder = &scheme.Builder{GroupVersion: GroupVersion}

	// AddToScheme adds the types in this group-version to the given scheme.
	AddToScheme = SchemeBuilder.AddToScheme
)

Functions

func LevelIndex added in v0.8.0

func LevelIndex(l SecurityLevel) int

LevelIndex ranks a level, lowest first, and -1 for an unknown one.

func VersionFromContext added in v0.3.7

func VersionFromContext(ctx context.Context) string

VersionFromContext returns the version from the given context.

func WithVersionContext added in v0.3.7

func WithVersionContext(ctx context.Context, version string) context.Context

WithVersionContext returns a new context with the given verison.

Types

type AtlasDriftCheck added in v0.8.0

type AtlasDriftCheck struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	// Defines the desired state of AtlasDriftCheck.
	Spec AtlasDriftCheckSpec `json:"spec,omitempty"`
	// Reports the observed state of AtlasDriftCheck.
	//+kubebuilder:default={"observedGeneration":-1}
	Status AtlasDriftCheckStatus `json:"status,omitempty"`
}

+kubebuilder:object:root=true +kubebuilder:subresource:status

AtlasDriftCheck periodically checks an AtlasMigration database for drift and reports the result in its status. It does not change the database or report the DDL needed to fix the drift. +kubebuilder:printcolumn:name="Target",type=string,JSONPath=`.spec.targetRef.name` +kubebuilder:printcolumn:name="Drifted",type=string,JSONPath=`.status.conditions[?(@.type=="Drifted")].status` +kubebuilder:printcolumn:name="Version",type=string,JSONPath=`.status.version` +kubebuilder:printcolumn:name="Objects",type=integer,JSONPath=`.status.summary.total` +kubebuilder:printcolumn:name="Ready",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].status` +kubebuilder:printcolumn:name="Suspended",type=boolean,JSONPath=`.spec.suspend` +kubebuilder:printcolumn:name="Last Check",type=date,JSONPath=`.status.lastCheckTime` +kubebuilder:printcolumn:name="Age",type=date,JSONPath=`.metadata.creationTimestamp` +kubebuilder:printcolumn:name="Fingerprint",type=string,JSONPath=`.status.fingerprint`,priority=1 +kubebuilder:printcolumn:name="Mode",type=string,JSONPath=`.status.mode`,priority=1

func (*AtlasDriftCheck) DeepCopy added in v0.8.0

func (in *AtlasDriftCheck) DeepCopy() *AtlasDriftCheck

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasDriftCheck.

func (*AtlasDriftCheck) DeepCopyInto added in v0.8.0

func (in *AtlasDriftCheck) DeepCopyInto(out *AtlasDriftCheck)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasDriftCheck) DeepCopyObject added in v0.8.0

func (in *AtlasDriftCheck) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*AtlasDriftCheck) SetCheckFailed added in v0.8.0

func (c *AtlasDriftCheck) SetCheckFailed(reason, message string, permanent bool)

SetCheckFailed records a check that could not be completed. A permanent failure stalls the resource; a transient one keeps it reconciling. Either way the result of the last completed check is kept, and the Drifted condition becomes Unknown because it is no longer being observed.

func (*AtlasDriftCheck) SetChecked added in v0.8.0

func (c *AtlasDriftCheck) SetChecked(rep *atlasexec.MigrateDrift)

SetChecked records a completed check that found no drift.

func (*AtlasDriftCheck) SetDrifted added in v0.8.0

func (c *AtlasDriftCheck) SetDrifted(rep *atlasexec.MigrateDrift, action DriftAction)

SetDrifted records a completed check that found drift. The action decides whether the drift also marks the check not ready.

func (*AtlasDriftCheck) SetSuspended added in v0.8.0

func (c *AtlasDriftCheck) SetSuspended()

SetSuspended records that the checks are suspended.

func (*AtlasDriftCheck) SetTargetNotReady added in v0.8.0

func (c *AtlasDriftCheck) SetTargetNotReady(message string)

SetTargetNotReady records that the check was skipped because the target is mid-apply. It touches the Reconciling condition only, so the result of the last completed check stays visible.

type AtlasDriftCheckList added in v0.8.0

type AtlasDriftCheckList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`

	Items []AtlasDriftCheck `json:"items"`
}

+kubebuilder:object:root=true

AtlasDriftCheckList contains a list of AtlasDriftCheck

func (*AtlasDriftCheckList) DeepCopy added in v0.8.0

func (in *AtlasDriftCheckList) DeepCopy() *AtlasDriftCheckList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasDriftCheckList.

func (*AtlasDriftCheckList) DeepCopyInto added in v0.8.0

func (in *AtlasDriftCheckList) DeepCopyInto(out *AtlasDriftCheckList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasDriftCheckList) DeepCopyObject added in v0.8.0

func (in *AtlasDriftCheckList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type AtlasDriftCheckSpec added in v0.8.0

type AtlasDriftCheckSpec struct {
	// The AtlasMigration to check for drift.
	TargetRef DriftCheckTarget `json:"targetRef"`
	// How often to check for drift. The minimum is 1m because each check uses
	// the same database lock as migrations, and more frequent checks may conflict
	// with deployments.
	// +kubebuilder:default="5m"
	// +kubebuilder:validation:XValidation:rule="duration(self) >= duration('1m')",message="interval must be at least 1m"
	Interval metav1.Duration `json:"interval,omitempty"`
	// Maximum time allowed for one drift check.
	// +kubebuilder:default="5m"
	Timeout metav1.Duration `json:"timeout,omitempty"`
	// Stops drift checks without deleting the resource.
	// +optional
	Suspend bool `json:"suspend,omitempty"`
	// How to handle detected drift. Report records the drift in the Drifted
	// condition. Fail also sets Ready=False and Stalled=True, so GitOps tools can
	// treat the check as degraded.
	// +kubebuilder:default=Report
	OnDrift DriftAction `json:"onDrift,omitempty"`
	// Database objects to ignore, such as "public.audit_*" or
	// "*[type=extension]". If empty, uses the exclude list from the target's
	// spec.policy.drift.
	// +optional
	Exclude []string `json:"exclude,omitempty"`
}

AtlasDriftCheckSpec defines the desired state of AtlasDriftCheck

func (*AtlasDriftCheckSpec) DeepCopy added in v0.8.0

func (in *AtlasDriftCheckSpec) DeepCopy() *AtlasDriftCheckSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasDriftCheckSpec.

func (*AtlasDriftCheckSpec) DeepCopyInto added in v0.8.0

func (in *AtlasDriftCheckSpec) DeepCopyInto(out *AtlasDriftCheckSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type AtlasDriftCheckStatus added in v0.8.0

type AtlasDriftCheckStatus struct {
	// Generation last processed by the controller.
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`
	// Conditions represent the latest available observations of an object's state.
	// +optional
	Conditions []metav1.Condition `json:"conditions,omitempty"`
	// Applied migration version used to resolve the expected state.
	// +optional
	Version string `json:"version,omitempty"`
	// Identifies the current drift. It changes when the drift changes and is
	// empty when there is no drift.
	// +optional
	Fingerprint string `json:"fingerprint,omitempty"`
	// How the expected state was resolved, "registry" or "local".
	// +optional
	Mode string `json:"mode,omitempty"`
	// Counts drifted objects. It is empty when there is no drift.
	// +optional
	Summary *DriftSummary `json:"summary,omitempty"`
	// Time when the last drift check completed.
	// +optional
	LastCheckTime *metav1.Time `json:"lastCheckTime,omitempty"`
}

AtlasDriftCheckStatus defines the observed state of AtlasDriftCheck

func (*AtlasDriftCheckStatus) DeepCopy added in v0.8.0

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasDriftCheckStatus.

func (*AtlasDriftCheckStatus) DeepCopyInto added in v0.8.0

func (in *AtlasDriftCheckStatus) DeepCopyInto(out *AtlasDriftCheckStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type AtlasMigration added in v0.1.7

type AtlasMigration struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	Spec AtlasMigrationSpec `json:"spec,omitempty"`
	//+kubebuilder:default={"observedGeneration":-1}
	Status AtlasMigrationStatus `json:"status,omitempty"`
}

+kubebuilder:object:root=true +kubebuilder:subresource:status

AtlasMigration is the Schema for the atlasmigrations API +kubebuilder:printcolumn:name="Ready",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].status` +kubebuilder:printcolumn:name="Reason",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].reason`

func (*AtlasMigration) DeepCopy added in v0.1.7

func (in *AtlasMigration) DeepCopy() *AtlasMigration

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasMigration.

func (*AtlasMigration) DeepCopyInto added in v0.1.7

func (in *AtlasMigration) DeepCopyInto(out *AtlasMigration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasMigration) DeepCopyObject added in v0.1.7

func (in *AtlasMigration) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*AtlasMigration) GetPrewarmDevDB added in v0.8.0

func (m *AtlasMigration) GetPrewarmDevDB() *bool

GetPrewarmDevDB returns the per-resource dev DB prewarm override, if set.

func (*AtlasMigration) IncrementFailed added in v0.7.3

func (m *AtlasMigration) IncrementFailed()

IncrementFailed increments the failed count.

func (*AtlasMigration) IsExceedBackoffLimit added in v0.7.3

func (m *AtlasMigration) IsExceedBackoffLimit() bool

IsExceedBackoffLimit returns true if the failed count exceeds the backoff limit.

func (*AtlasMigration) IsHashModified added in v0.1.8

func (m *AtlasMigration) IsHashModified(hash string) bool

IsHashModified returns true if the hash is different from the observed hash.

func (*AtlasMigration) IsReady added in v0.1.8

func (m *AtlasMigration) IsReady() bool

IsReady returns true if the ready condition is true.

func (*AtlasMigration) IsReconciling added in v0.7.52

func (m *AtlasMigration) IsReconciling() bool

IsReconciling returns true if the reconciling condition is true, i.e. an apply is in flight.

func (*AtlasMigration) NamespacedName added in v0.1.7

func (m *AtlasMigration) NamespacedName() types.NamespacedName

NamespacedName returns the namespaced name of the object.

func (*AtlasMigration) ResetFailed added in v0.7.3

func (m *AtlasMigration) ResetFailed()

ResetFailed resets the failed count.

func (*AtlasMigration) SetNotReady added in v0.1.8

func (m *AtlasMigration) SetNotReady(reason, message string)

SetNotReady sets the ready condition to false.

func (*AtlasMigration) SetReady added in v0.1.8

func (m *AtlasMigration) SetReady(status AtlasMigrationStatus)

SetReady sets the ready condition to true.

func (*AtlasMigration) SetReconciling added in v0.7.3

func (m *AtlasMigration) SetReconciling(message string)

SetReconciling sets the ready condition to false with the reason "Reconciling".

type AtlasMigrationList added in v0.1.7

type AtlasMigrationList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`

	Items []AtlasMigration `json:"items"`
}

+kubebuilder:object:root=true

AtlasMigrationList contains a list of AtlasMigration

func (*AtlasMigrationList) DeepCopy added in v0.1.7

func (in *AtlasMigrationList) DeepCopy() *AtlasMigrationList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasMigrationList.

func (*AtlasMigrationList) DeepCopyInto added in v0.1.7

func (in *AtlasMigrationList) DeepCopyInto(out *AtlasMigrationList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasMigrationList) DeepCopyObject added in v0.1.7

func (in *AtlasMigrationList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type AtlasMigrationSpec added in v0.1.7

type AtlasMigrationSpec struct {
	TargetSpec        `json:",inline"`
	ProjectConfigSpec `json:",inline"`
	// EnvName sets the environment name used for reporting runs to Atlas Cloud.
	EnvName string `json:"envName,omitempty"`
	// Cloud defines the Atlas Cloud configuration.
	Cloud CloudV0 `json:"cloud,omitempty"`
	// Dir defines the directory to use for migrations as a configmap key reference.
	Dir Dir `json:"dir"`
	// DevURL is the URL of the database to use for normalization and calculations.
	// If not specified, the operator will spin up a temporary database container to use for these operations.
	// +optional
	DevURL string `json:"devURL"`
	// DevURLFrom is a reference to a secret containing the URL of the database to use for normalization and calculations.
	// +optional
	DevURLFrom Secret `json:"devURLFrom,omitempty"`
	// DevDB configures the dev database pod used for normalization and calculations.
	// If spec is omitted, a default pod spec is created based on the target database driver.
	// When a custom pod spec is provided, devURL must be defined as well.
	// +optional
	DevDB *DevDB `json:"devDB,omitempty"`
	// PrewarmDevDB controls whether the automatically managed dev DB should be kept warm after reconciliation.
	// If not specified, the operator-wide default is used.
	// +optional
	PrewarmDevDB *bool `json:"prewarmDevDB,omitempty"`
	// RevisionsSchema defines the schema that revisions table resides in
	RevisionsSchema string `json:"revisionsSchema,omitempty"`
	// BaselineVersion defines the baseline version of the database on the first migration.
	Baseline string `json:"baseline,omitempty"`
	// ExecOrder controls how Atlas computes and executes pending migration files to the database.
	// +kubebuilder:default=linear
	ExecOrder MigrateExecOrder `json:"execOrder,omitempty"`
	// ProtectedFlows defines the protected flows of a deployment.
	ProtectedFlows *ProtectFlows `json:"protectedFlows,omitempty"`
	// Policy defines the policies to apply when migrating the database.
	// +optional
	Policy *MigrationPolicy `json:"policy,omitempty"`
	// BackoffLimit is the number of retries on error.
	// +kubebuilder:default=20
	BackoffLimit int `json:"backoffLimit,omitempty"`
}

AtlasMigrationSpec defines the desired state of AtlasMigration

func (*AtlasMigrationSpec) DeepCopy added in v0.1.7

func (in *AtlasMigrationSpec) DeepCopy() *AtlasMigrationSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasMigrationSpec.

func (*AtlasMigrationSpec) DeepCopyInto added in v0.1.7

func (in *AtlasMigrationSpec) DeepCopyInto(out *AtlasMigrationSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type AtlasMigrationStatus added in v0.1.7

type AtlasMigrationStatus struct {
	// ObservedGeneration is the generation last processed by the controller.
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`
	// Conditions represent the latest available observations of an object's state.
	// +optional
	Conditions []metav1.Condition `json:"conditions,omitempty"`
	// LastAppliedVersion is the version of the most recent successful versioned migration.
	// +optional
	LastAppliedVersion string `json:"lastAppliedVersion,omitempty"`
	// LastDeploymentURL is the Deployment URL of the most recent successful versioned migration.
	// +optional
	LastDeploymentURL string `json:"lastDeploymentUrl,omitempty"`
	// ApprovalURL is the URL to approve the migration.
	// +optional
	ApprovalURL string `json:"approvalUrl,omitempty"`
	// ObservedHash is the hash of the most recent successful versioned migration.
	// +optional
	ObservedHash string `json:"observed_hash"`
	// LastApplied is the unix timestamp of the most recent successful versioned migration.
	// +optional
	LastApplied int64 `json:"lastApplied"`
	// Failed is the number of times the migration has failed.
	// +optional
	// +kubebuilder:default=0
	Failed int `json:"failed"`
}

AtlasMigrationStatus defines the observed state of AtlasMigration

func (*AtlasMigrationStatus) DeepCopy added in v0.1.7

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasMigrationStatus.

func (*AtlasMigrationStatus) DeepCopyInto added in v0.1.7

func (in *AtlasMigrationStatus) DeepCopyInto(out *AtlasMigrationStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type AtlasSchema

type AtlasSchema struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	Spec AtlasSchemaSpec `json:"spec,omitempty"`
	//+kubebuilder:default={"observedGeneration":-1}
	Status AtlasSchemaStatus `json:"status,omitempty"`
}

+kubebuilder:object:root=true +kubebuilder:subresource:status

AtlasSchema is the Schema for the atlasschemas API +kubebuilder:printcolumn:name="Ready",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].status` +kubebuilder:printcolumn:name="Reason",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].reason`

func (*AtlasSchema) DeepCopy

func (in *AtlasSchema) DeepCopy() *AtlasSchema

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSchema.

func (*AtlasSchema) DeepCopyInto

func (in *AtlasSchema) DeepCopyInto(out *AtlasSchema)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasSchema) DeepCopyObject

func (in *AtlasSchema) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*AtlasSchema) GetPrewarmDevDB added in v0.8.0

func (s *AtlasSchema) GetPrewarmDevDB() *bool

GetPrewarmDevDB returns the per-resource dev DB prewarm override, if set.

func (*AtlasSchema) IncrementFailed added in v0.7.3

func (sc *AtlasSchema) IncrementFailed()

IncrementFailed increments the failed count.

func (*AtlasSchema) IsExceedBackoffLimit added in v0.7.3

func (sc *AtlasSchema) IsExceedBackoffLimit() bool

IsExceedBackoffLimit returns true if the failed count exceeds the backoff limit.

func (*AtlasSchema) IsHashModified added in v0.3.1

func (sc *AtlasSchema) IsHashModified(hash string) bool

IsHashModified returns true if the hash is different from the observed hash.

func (*AtlasSchema) IsReady added in v0.3.1

func (m *AtlasSchema) IsReady() bool

IsReady returns true if the ready condition is true.

func (*AtlasSchema) NamespacedName added in v0.1.7

func (s *AtlasSchema) NamespacedName() types.NamespacedName

NamespacedName returns the namespaced name of the object.

func (*AtlasSchema) ResetFailed added in v0.7.3

func (sc *AtlasSchema) ResetFailed()

ResetFailed resets the failed count.

func (*AtlasSchema) SetNotReady added in v0.3.1

func (sc *AtlasSchema) SetNotReady(reason, msg string)

SetNotReady sets the Ready condition to false with the given reason and message.

func (*AtlasSchema) SetReady added in v0.3.1

func (sc *AtlasSchema) SetReady(status AtlasSchemaStatus, report any)

SetReady sets the Ready condition to true

func (*AtlasSchema) SetReconciling added in v0.7.3

func (sc *AtlasSchema) SetReconciling(message string)

SetReconciling sets the ready condition to false with the reason "Reconciling".

type AtlasSchemaList

type AtlasSchemaList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`

	Items []AtlasSchema `json:"items"`
}

+kubebuilder:object:root=true

AtlasSchemaList contains a list of AtlasSchema

func (*AtlasSchemaList) DeepCopy

func (in *AtlasSchemaList) DeepCopy() *AtlasSchemaList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSchemaList.

func (*AtlasSchemaList) DeepCopyInto

func (in *AtlasSchemaList) DeepCopyInto(out *AtlasSchemaList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasSchemaList) DeepCopyObject

func (in *AtlasSchemaList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type AtlasSchemaSpec

type AtlasSchemaSpec struct {
	TargetSpec        `json:",inline"`
	ProjectConfigSpec `json:",inline"`
	// Desired Schema of the target.
	Schema Schema `json:"schema,omitempty"`
	// Cloud defines the Atlas Cloud configuration.
	Cloud Cloud `json:"cloud,omitempty"`
	// +optional
	// DevURL is the URL of the database to use for normalization and calculations.
	// If not specified, the operator will spin up a temporary database container to use for these operations.
	DevURL string `json:"devURL"`
	// DevURLFrom is a reference to a secret containing the URL of the database to use for normalization and calculations.
	// +optional
	DevURLFrom Secret `json:"devURLFrom,omitempty"`
	// DevDB configures the dev database pod used for normalization and calculations.
	// If spec is omitted, a default pod spec is created based on the target database driver.
	// When a custom pod spec is provided, devURL must be defined as well.
	// +optional
	DevDB *DevDB `json:"devDB,omitempty"`
	// PrewarmDevDB controls whether the automatically managed dev DB should be kept warm after reconciliation.
	// If not specified, the operator-wide default is used.
	// +optional
	PrewarmDevDB *bool `json:"prewarmDevDB,omitempty"`
	// Exclude a list of glob patterns used to filter existing resources being taken into account.
	Exclude []string `json:"exclude,omitempty"`
	// TxMode defines the transaction mode to use when applying the schema.
	// +kubebuilder:default=file
	TxMode TransactionMode `json:"txMode,omitempty"`
	// Policy defines the policies to apply when managing the schema change lifecycle.
	Policy *Policy `json:"policy,omitempty"`
	// The names of the schemas (named databases) on the target database to be managed.
	Schemas []string `json:"schemas,omitempty"`
	// BackoffLimit is the number of retries on error.
	// +kubebuilder:default=20
	BackoffLimit int `json:"backoffLimit,omitempty"`
}

AtlasSchemaSpec defines the desired state of AtlasSchema

func (*AtlasSchemaSpec) DeepCopy

func (in *AtlasSchemaSpec) DeepCopy() *AtlasSchemaSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSchemaSpec.

func (*AtlasSchemaSpec) DeepCopyInto

func (in *AtlasSchemaSpec) DeepCopyInto(out *AtlasSchemaSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type AtlasSchemaStatus

type AtlasSchemaStatus struct {
	// ObservedGeneration is the generation last processed by the controller.
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`
	// Conditions represent the latest available observations of an object's state.
	// +optional
	Conditions []metav1.Condition `json:"conditions,omitempty"`
	// ObservedHash is the hash of the most recently applied schema.
	// +optional
	ObservedHash string `json:"observed_hash"`
	// LastApplied is the unix timestamp of the most recent successful schema apply operation.
	// +optional
	LastApplied int64 `json:"last_applied"`
	// PlanURL is the URL of the schema plan to apply.
	// +optional
	PlanURL string `json:"planURL"`
	// PlanLink is the link to the schema plan on the Atlas Cloud.
	// +optional
	PlanLink string `json:"planLink"`
	// Failed is the number of times the schema has failed to apply.
	// +optional
	// +kubebuilder:default=0
	Failed int `json:"failed"`
}

AtlasSchemaStatus defines the observed state of AtlasSchema

func (*AtlasSchemaStatus) DeepCopy

func (in *AtlasSchemaStatus) DeepCopy() *AtlasSchemaStatus

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSchemaStatus.

func (*AtlasSchemaStatus) DeepCopyInto

func (in *AtlasSchemaStatus) DeepCopyInto(out *AtlasSchemaStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type AtlasSecurityReport added in v0.8.0

type AtlasSecurityReport struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`
	// +required
	Report SecurityReport `json:"report,omitempty"`
}

+kubebuilder:object:root=true

AtlasSecurityReport holds the findings of the most recent successful scan of an AtlasSecurityScan. It is owned by the scan, replaced on every successful scan, and readable by its own RBAC rather than by everyone who can read the scan. +kubebuilder:printcolumn:name="Findings",type=integer,JSONPath=`.report.summary.total` +kubebuilder:printcolumn:name="Highest",type=string,JSONPath=`.report.summary.highestLevel` +kubebuilder:printcolumn:name="Scanned",type=date,JSONPath=`.report.completionTime` +kubebuilder:printcolumn:name="Age",type=date,JSONPath=`.metadata.creationTimestamp`

func (*AtlasSecurityReport) DeepCopy added in v0.8.0

func (in *AtlasSecurityReport) DeepCopy() *AtlasSecurityReport

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityReport.

func (*AtlasSecurityReport) DeepCopyInto added in v0.8.0

func (in *AtlasSecurityReport) DeepCopyInto(out *AtlasSecurityReport)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasSecurityReport) DeepCopyObject added in v0.8.0

func (in *AtlasSecurityReport) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type AtlasSecurityReportList added in v0.8.0

type AtlasSecurityReportList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`

	Items []AtlasSecurityReport `json:"items"`
}

+kubebuilder:object:root=true

AtlasSecurityReportList contains a list of AtlasSecurityReport

func (*AtlasSecurityReportList) DeepCopy added in v0.8.0

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityReportList.

func (*AtlasSecurityReportList) DeepCopyInto added in v0.8.0

func (in *AtlasSecurityReportList) DeepCopyInto(out *AtlasSecurityReportList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasSecurityReportList) DeepCopyObject added in v0.8.0

func (in *AtlasSecurityReportList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type AtlasSecurityScan added in v0.8.0

type AtlasSecurityScan struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	// +required
	Spec AtlasSecurityScanSpec `json:"spec,omitempty"`
	//+kubebuilder:default={"observedGeneration":-1}
	Status AtlasSecurityScanStatus `json:"status,omitempty"`
}

+kubebuilder:object:root=true +kubebuilder:subresource:status

AtlasSecurityScan scans a database with `atlas security scan` on a schedule and after the referenced AtlasSchema/AtlasMigration resources apply changes to it. +kubebuilder:printcolumn:name="Ready",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].status` +kubebuilder:printcolumn:name="Reason",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].reason` +kubebuilder:printcolumn:name="Compliant",type=string,JSONPath=`.status.conditions[?(@.type=="Compliant")].status` +kubebuilder:printcolumn:name="Findings",type=integer,JSONPath=`.status.summary.total` +kubebuilder:printcolumn:name="Highest",type=string,JSONPath=`.status.summary.highestLevel` +kubebuilder:printcolumn:name="Last Scan",type=date,JSONPath=`.status.lastSuccessfulTime` +kubebuilder:printcolumn:name="Next Scan",type=string,JSONPath=`.status.nextScheduleTime` +kubebuilder:printcolumn:name="Age",type=date,JSONPath=`.metadata.creationTimestamp` +kubebuilder:printcolumn:name="Trigger",type=string,JSONPath=`.status.lastScan.trigger`,priority=1 +kubebuilder:printcolumn:name="Schedule",type=string,JSONPath=`.spec.schedule`,priority=1 +kubebuilder:printcolumn:name="Suspended",type=boolean,JSONPath=`.spec.suspend`,priority=1

func (*AtlasSecurityScan) BackoffLimit added in v0.8.0

func (s *AtlasSecurityScan) BackoffLimit() int

BackoffLimit returns the retry limit, 0 for unlimited. Admission defaults an unset limit to 20; the fallback covers objects that did not go through it.

func (*AtlasSecurityScan) DeepCopy added in v0.8.0

func (in *AtlasSecurityScan) DeepCopy() *AtlasSecurityScan

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityScan.

func (*AtlasSecurityScan) DeepCopyInto added in v0.8.0

func (in *AtlasSecurityScan) DeepCopyInto(out *AtlasSecurityScan)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasSecurityScan) DeepCopyObject added in v0.8.0

func (in *AtlasSecurityScan) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*AtlasSecurityScan) IsReady added in v0.8.0

func (s *AtlasSecurityScan) IsReady() bool

IsReady returns true if the ready condition is true.

func (*AtlasSecurityScan) IsStalled added in v0.8.0

func (s *AtlasSecurityScan) IsStalled(reason string) bool

IsStalled reports whether the resource stalled for the given reason, or for any reason when none is given.

func (*AtlasSecurityScan) IsSuspended added in v0.8.0

func (s *AtlasSecurityScan) IsSuspended() bool

IsSuspended reports whether scanning is paused.

func (*AtlasSecurityScan) MinSeverity added in v0.8.0

func (s *AtlasSecurityScan) MinSeverity() SecurityLevel

MinSeverity is the lowest level the scan reports. It is always set, so the severity the report is graded with is the one the CLI ran with.

func (*AtlasSecurityScan) SetCompliant added in v0.8.0

func (s *AtlasSecurityScan) SetCompliant(status metav1.ConditionStatus, reason, message string)

SetCompliant records the policy verdict.

func (*AtlasSecurityScan) SetFirstVisit added in v0.8.0

func (s *AtlasSecurityScan) SetFirstVisit()

SetFirstVisit writes the initial conditions. Nothing is known yet.

func (*AtlasSecurityScan) SetIdle added in v0.8.0

func (s *AtlasSecurityScan) SetIdle()

SetIdle restores the ready state when nothing is pending and the resource is not stalled, which implies a success exists for the current generation. It also clears the failures of a retry whose cause has meanwhile disappeared.

func (*AtlasSecurityScan) SetRetrying added in v0.8.0

func (s *AtlasSecurityScan) SetRetrying(reason, message string)

SetRetrying records a failed attempt that will be retried with a backoff. It deliberately leaves Stalled false: a transient failure is not a stall.

func (*AtlasSecurityScan) SetScanned added in v0.8.0

func (s *AtlasSecurityScan) SetScanned(message string)

SetScanned records a successful scan: the controller did its job and the result reflects the current spec.

func (*AtlasSecurityScan) SetScanning added in v0.8.0

func (s *AtlasSecurityScan) SetScanning()

SetScanning marks the resource as converging on its spec while a scan runs. Ready moves to Unknown only until the first success; afterwards the last result stands while a Spec-triggered re-scan runs.

func (*AtlasSecurityScan) SetStalled added in v0.8.0

func (s *AtlasSecurityScan) SetStalled(reason, message string)

SetStalled records a failure that retrying cannot fix, or exhausted retries.

func (*AtlasSecurityScan) SetSuspended added in v0.8.0

func (s *AtlasSecurityScan) SetSuspended()

SetSuspended pauses the resource. Ready and Compliant keep their last values.

func (*AtlasSecurityScan) WasSuspended added in v0.8.0

func (s *AtlasSecurityScan) WasSuspended() bool

WasSuspended reports whether the last pass left the resource suspended.

type AtlasSecurityScanList added in v0.8.0

type AtlasSecurityScanList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`

	Items []AtlasSecurityScan `json:"items"`
}

+kubebuilder:object:root=true

AtlasSecurityScanList contains a list of AtlasSecurityScan

func (*AtlasSecurityScanList) DeepCopy added in v0.8.0

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityScanList.

func (*AtlasSecurityScanList) DeepCopyInto added in v0.8.0

func (in *AtlasSecurityScanList) DeepCopyInto(out *AtlasSecurityScanList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*AtlasSecurityScanList) DeepCopyObject added in v0.8.0

func (in *AtlasSecurityScanList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type AtlasSecurityScanSpec added in v0.8.0

type AtlasSecurityScanSpec struct {
	TargetSpec        `json:",inline"`
	ProjectConfigSpec `json:",inline"`
	// Cloud defines the Atlas Cloud configuration. The Security Graph requires Atlas Pro.
	// +optional
	Cloud Cloud `json:"cloud,omitempty"`
	// Schedule is a cron expression (5 fields, or @hourly/@daily/@weekly/@monthly/@yearly) evaluated in TimeZone.
	// +optional
	// +kubebuilder:validation:MinLength=1
	Schedule string `json:"schedule,omitempty"`
	// TimeZone is the IANA name of the zone the schedule is evaluated in. Defaults to UTC.
	// +optional
	// +kubebuilder:default="UTC"
	// +kubebuilder:validation:MinLength=1
	TimeZone string `json:"timeZone,omitempty"`
	// Triggers are resources in this namespace whose applies cause a scan.
	// +optional
	// +listType=map
	// +listMapKey=kind
	// +listMapKey=name
	// +kubebuilder:validation:MaxItems=32
	Triggers []ScanTriggerRef `json:"triggers,omitempty"`
	// Suspend pauses scanning. Everything that becomes due while suspended is covered by one scan on resume.
	// +optional
	Suspend *bool `json:"suspend,omitempty"`
	// Policy controls which findings are reported and which make the database non-compliant.
	// +optional
	Policy *ScanPolicy `json:"policy,omitempty"`
	// BackoffLimit is the number of retries of a failed scan before the resource stalls. 0 means unlimited.
	// +kubebuilder:default=20
	// +kubebuilder:validation:Minimum=0
	BackoffLimit *int `json:"backoffLimit,omitempty"`
}

AtlasSecurityScanSpec defines the desired state of AtlasSecurityScan. +kubebuilder:validation:XValidation:rule="(has(self.schedule) && self.schedule != ”) || (has(self.triggers) && size(self.triggers) > 0)",message="at least one of spec.schedule or spec.triggers must be set" +kubebuilder:validation:XValidation:rule="!has(self.schedule) || !(self.schedule.startsWith('TZ=') || self.schedule.startsWith('CRON_TZ='))",message="use spec.timeZone instead of a TZ=/CRON_TZ= prefix" +kubebuilder:validation:XValidation:rule="!has(self.schedule) || !self.schedule.startsWith('@every')",message="@every is interval-based and drifts; use a cron expression or @hourly/@daily/@weekly/@monthly/@yearly" +kubebuilder:validation:XValidation:rule="!has(self.timeZone) || self.timeZone != 'Local'",message="timeZone must be an IANA zone name" +kubebuilder:validation:XValidation:rule="!has(self.cloud) || !has(self.cloud.repo)",message="cloud.repo is not used by security scans"

func (*AtlasSecurityScanSpec) DeepCopy added in v0.8.0

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityScanSpec.

func (*AtlasSecurityScanSpec) DeepCopyInto added in v0.8.0

func (in *AtlasSecurityScanSpec) DeepCopyInto(out *AtlasSecurityScanSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type AtlasSecurityScanStatus added in v0.8.0

type AtlasSecurityScanStatus struct {
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`
	// +optional
	// +listType=map
	// +listMapKey=type
	Conditions []metav1.Condition `json:"conditions,omitempty"`
	// LastScan describes the most recent attempt, whether it succeeded or failed.
	// +optional
	LastScan *ScanAttempt `json:"lastScan,omitempty"`
	// LastSuccessfulTime is when the most recent successful scan completed. Summary, report and the
	// Compliant condition describe that scan.
	// +optional
	LastSuccessfulTime *metav1.Time `json:"lastSuccessfulTime,omitempty"`
	// LastScheduleTime is the latest schedule slot a successful scan covered. A scan that is still
	// running when a slot passes covers it, so this can be later than the start of that scan.
	// +optional
	LastScheduleTime *metav1.Time `json:"lastScheduleTime,omitempty"`
	// NextScheduleTime is the slot after LastScheduleTime. Omitted while suspended,
	// on an invalid spec, or without a schedule. It advances only when a scan
	// succeeds, so it stays at a missed slot until the catch-up completes.
	// +optional
	NextScheduleTime *metav1.Time `json:"nextScheduleTime,omitempty"`
	// LastHandledScanRequest is the scan-requested-at annotation value whose scan completed successfully.
	// +optional
	LastHandledScanRequest string `json:"lastHandledScanRequest,omitempty"`
	// Triggers holds the revision of each trigger observed when the last successful scan started.
	// +optional
	// +listType=map
	// +listMapKey=kind
	// +listMapKey=name
	Triggers []ObservedTrigger `json:"triggers,omitempty"`
	// ActiveWaivers lists the waiver ids that were in force when the last successful scan started.
	// +optional
	// +listType=set
	ActiveWaivers []string `json:"activeWaivers,omitempty"`
	// Summary of the last successful scan.
	// +optional
	Summary *ScanSummary `json:"summary,omitempty"`
	// ReportRef names the AtlasSecurityReport holding the findings of the last successful scan.
	// +optional
	ReportRef *corev1.LocalObjectReference `json:"reportRef,omitempty"`
	// Failed is the number of consecutive failed attempts since the last success.
	// +optional
	// +kubebuilder:default=0
	Failed int `json:"failed"`
}

AtlasSecurityScanStatus defines the observed state of AtlasSecurityScan.

func (*AtlasSecurityScanStatus) DeepCopy added in v0.8.0

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityScanStatus.

func (*AtlasSecurityScanStatus) DeepCopyInto added in v0.8.0

func (in *AtlasSecurityScanStatus) DeepCopyInto(out *AtlasSecurityScanStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type CheckConfig

type CheckConfig struct {
	Error bool `json:"error,omitempty"`
}

CheckConfig defines the configuration of a linting check.

func (*CheckConfig) DeepCopy

func (in *CheckConfig) DeepCopy() *CheckConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CheckConfig.

func (*CheckConfig) DeepCopyInto

func (in *CheckConfig) DeepCopyInto(out *CheckConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Cloud added in v0.1.7

type Cloud struct {
	// TokenFrom defines the reference to the secret key that contains the Atlas Cloud Token.
	TokenFrom TokenFrom `json:"tokenFrom,omitempty"`
	// Repo is the name of repository on the Atlas Cloud.
	Repo string `json:"repo,omitempty"`
}

Cloud defines the Atlas Cloud configuration.

func (*Cloud) DeepCopy added in v0.1.7

func (in *Cloud) DeepCopy() *Cloud

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Cloud.

func (*Cloud) DeepCopyInto added in v0.1.7

func (in *Cloud) DeepCopyInto(out *Cloud)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type CloudV0 added in v0.6.0

type CloudV0 struct {
	URL       string    `json:"url,omitempty"`
	TokenFrom TokenFrom `json:"tokenFrom,omitempty"`
	Project   string    `json:"project,omitempty"`
}

func (*CloudV0) DeepCopy added in v0.6.0

func (in *CloudV0) DeepCopy() *CloudV0

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CloudV0.

func (*CloudV0) DeepCopyInto added in v0.6.0

func (in *CloudV0) DeepCopyInto(out *CloudV0)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ConcurrentIndex added in v0.4.3

type ConcurrentIndex struct {
	// +optional
	Create bool `json:"create,omitempty"`
	// +optional
	Drop bool `json:"drop,omitempty"`
}

func (*ConcurrentIndex) DeepCopy added in v0.4.3

func (in *ConcurrentIndex) DeepCopy() *ConcurrentIndex

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ConcurrentIndex.

func (*ConcurrentIndex) DeepCopyInto added in v0.4.3

func (in *ConcurrentIndex) DeepCopyInto(out *ConcurrentIndex)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Credentials added in v0.2.2

type Credentials struct {
	Scheme       string            `json:"scheme,omitempty"`
	User         string            `json:"user,omitempty"`
	UserFrom     Secret            `json:"userFrom,omitempty"`
	Password     string            `json:"password,omitempty"`
	PasswordFrom Secret            `json:"passwordFrom,omitempty"`
	Host         string            `json:"host,omitempty"`
	HostFrom     Secret            `json:"hostFrom,omitempty"`
	Port         int               `json:"port,omitempty"`
	Database     string            `json:"database,omitempty"`
	Parameters   map[string]string `json:"parameters,omitempty"`
}

Credentials defines the credentials to use when connecting to the database.

func (*Credentials) DeepCopy added in v0.2.2

func (in *Credentials) DeepCopy() *Credentials

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Credentials.

func (*Credentials) DeepCopyInto added in v0.2.2

func (in *Credentials) DeepCopyInto(out *Credentials)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*Credentials) URL added in v0.2.2

func (c *Credentials) URL() (*url.URL, error)

URL returns the URL for the database.

type DeploymentFlow added in v0.5.0

type DeploymentFlow struct {
	// Allow allows the flow to be executed.
	// +kubebuilder:default=false
	Allow bool `json:"allow,omitempty"`
	// AutoApprove allows the flow to be automatically approved.
	// +kubebuilder:default=false
	AutoApprove bool `json:"autoApprove,omitempty"`
}

DeploymentFlow defines the flow of a deployment.

func (*DeploymentFlow) DeepCopy added in v0.5.0

func (in *DeploymentFlow) DeepCopy() *DeploymentFlow

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DeploymentFlow.

func (*DeploymentFlow) DeepCopyInto added in v0.5.0

func (in *DeploymentFlow) DeepCopyInto(out *DeploymentFlow)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DevDB added in v0.7.11

type DevDB struct {
	// Metadata contains labels and annotations applied when creating the dev database pod template.
	// Operator-managed labels and the atlasgo.io/conntmpl annotation take precedence.
	// +optional
	Metadata *DevDBMetadata `json:"metadata,omitempty"`
	// Spec overrides the automatically generated pod spec. When set, devURL is required.
	// +optional
	Spec *corev1.PodSpec `json:"spec,omitempty"`
}

func (*DevDB) DeepCopy added in v0.7.11

func (in *DevDB) DeepCopy() *DevDB

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DevDB.

func (*DevDB) DeepCopyInto added in v0.7.11

func (in *DevDB) DeepCopyInto(out *DevDB)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DevDBMetadata added in v0.7.52

type DevDBMetadata struct {
	// Labels are additional labels for the pod template. They do not affect the Deployment selector.
	// +optional
	Labels map[string]string `json:"labels,omitempty"`
	// Annotations are additional annotations for the pod template.
	// +optional
	Annotations map[string]string `json:"annotations,omitempty"`
}

DevDBMetadata defines additional metadata for dev database pods.

func (*DevDBMetadata) DeepCopy added in v0.7.52

func (in *DevDBMetadata) DeepCopy() *DevDBMetadata

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DevDBMetadata.

func (*DevDBMetadata) DeepCopyInto added in v0.7.52

func (in *DevDBMetadata) DeepCopyInto(out *DevDBMetadata)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Diff

type Diff struct {
	ConcurrentIndex *ConcurrentIndex `json:"concurrent_index,omitempty"`
	Skip            *SkipChanges     `json:"skip,omitempty"`
}

Diff defines the diff policies to apply when planning schema changes.

func (Diff) AsBlock added in v0.7.0

func (d Diff) AsBlock() *hclwrite.Block

AsBlock returns the HCL block representation of the diff.

func (*Diff) DeepCopy

func (in *Diff) DeepCopy() *Diff

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Diff.

func (*Diff) DeepCopyInto

func (in *Diff) DeepCopyInto(out *Diff)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Dir added in v0.1.7

type Dir struct {
	// ConfigMapRef defines the configmap to use for migrations
	ConfigMapRef *corev1.LocalObjectReference `json:"configMapRef,omitempty"`
	// Remote defines the Atlas Cloud migration directory.
	Remote Remote `json:"remote,omitempty"`
	// Local defines the local migration directory.
	Local map[string]string `json:"local,omitempty"`
}

Dir defines the place where migrations are stored.

func (*Dir) DeepCopy added in v0.1.7

func (in *Dir) DeepCopy() *Dir

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Dir.

func (*Dir) DeepCopyInto added in v0.1.7

func (in *Dir) DeepCopyInto(out *Dir)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DriftAction added in v0.8.0

type DriftAction string

DriftAction controls how the check reports detected drift. +kubebuilder:validation:Enum=Report;Fail

const (
	// DriftActionReport reports the drift on the Drifted condition only.
	DriftActionReport DriftAction = "Report"
	// DriftActionFail also marks the check not ready and stalled.
	DriftActionFail DriftAction = "Fail"
)

DriftAction values.

type DriftCheckTarget added in v0.8.0

type DriftCheckTarget struct {
	// Name of the AtlasMigration in the same namespace.
	// +kubebuilder:validation:MinLength=1
	Name string `json:"name"`
}

DriftCheckTarget references the resource to check.

func (*DriftCheckTarget) DeepCopy added in v0.8.0

func (in *DriftCheckTarget) DeepCopy() *DriftCheckTarget

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DriftCheckTarget.

func (*DriftCheckTarget) DeepCopyInto added in v0.8.0

func (in *DriftCheckTarget) DeepCopyInto(out *DriftCheckTarget)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DriftOnError added in v0.7.52

type DriftOnError string

DriftOnError controls what the drift check does when it finds drift. +kubebuilder:validation:Enum=FAIL;CONTINUE

const (
	// DriftOnErrorFail stops the migration when drift is found.
	DriftOnErrorFail DriftOnError = "FAIL"
	// DriftOnErrorContinue applies the migration anyway and records the
	// drift in the Atlas Registry deployment log.
	DriftOnErrorContinue DriftOnError = "CONTINUE"
)

DriftOnError values.

type DriftPolicy added in v0.7.52

type DriftPolicy struct {
	// OnError controls what happens when drift is found (default: FAIL).
	// FAIL stops the migration and reports the drift on the Ready condition.
	// CONTINUE applies it anyway and records the drift only in the Atlas
	// +optional
	OnError DriftOnError `json:"onError,omitempty"`
	// Exclude lists glob patterns of database objects to ignore, e.g. "public.audit_*"
	// or "*[type=extension]". It replaces the env-level exclude list.
	// The revisions table is always excluded.
	// +optional
	Exclude []string `json:"exclude,omitempty"`
}

DriftPolicy configures the pre-apply drift check. It adds a check "migrate_apply" { drift { ... } } block to the generated atlas.hcl.

func (*DriftPolicy) AsBlock added in v0.7.52

func (d *DriftPolicy) AsBlock() *hclwrite.Block

AsBlock returns the check "migrate_apply" block for this policy.

func (*DriftPolicy) DeepCopy added in v0.7.52

func (in *DriftPolicy) DeepCopy() *DriftPolicy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DriftPolicy.

func (*DriftPolicy) DeepCopyInto added in v0.7.52

func (in *DriftPolicy) DeepCopyInto(out *DriftPolicy)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DriftSummary added in v0.8.0

type DriftSummary struct {
	// Total number of drifted objects.
	Total int `json:"total"`
	// Number of objects found only in the database.
	// +optional
	Extra int `json:"extra,omitempty"`
	// Number of objects found only in the expected state.
	// +optional
	Missing int `json:"missing,omitempty"`
	// Number of objects that exist in both states but differ.
	// +optional
	Modified int `json:"modified,omitempty"`
	// Drifted objects by type, e.g. {"table": 2, "role": 1}.
	// +optional
	Types map[string]int `json:"types,omitempty"`
}

DriftSummary counts the drifted objects by kind and by object type.

func (*DriftSummary) DeepCopy added in v0.8.0

func (in *DriftSummary) DeepCopy() *DriftSummary

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DriftSummary.

func (*DriftSummary) DeepCopyInto added in v0.8.0

func (in *DriftSummary) DeepCopyInto(out *DriftSummary)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Driver added in v0.6.0

type Driver string

Driver defines the database driver.

const (
	DriverClickHouse  Driver = "clickhouse"
	DriverCockroachDB Driver = "crdb"
	DriverDatabricks  Driver = "databricks"
	DriverDSQL        Driver = "dsql"
	DriverMariaDB     Driver = "mariadb"
	DriverMySQL       Driver = "mysql"
	DriverOracle      Driver = "oracle"
	DriverPostgres    Driver = "postgres"
	DriverRedshift    Driver = "redshift"
	DriverSnowflake   Driver = "snowflake"
	DriverSpanner     Driver = "spanner"
	DriverSQLite      Driver = "sqlite"
	DriverSQLServer   Driver = "sqlserver"
	DriverYSQL        Driver = "ysql"
)

func DriverBySchema added in v0.5.0

func DriverBySchema(schema string) (Driver, error)

DriverBySchema returns the driver from the given schema. it remove the schema modifier if present. e.g. mysql+unix -> mysql it also handles aliases. e.g. mariadb -> mysql

func (Driver) SchemaBound added in v0.6.0

func (d Driver) SchemaBound(u url.URL) (bool, error)

SchemaBound returns true if the driver requires a schema.

func (Driver) String added in v0.6.0

func (d Driver) String() string

String returns the string representation of the driver.

type GradedPolicy added in v0.8.0

type GradedPolicy struct {
	MinSeverity SecurityLevel  `json:"minSeverity"`
	FailOn      *SecurityLevel `json:"failOn,omitempty"`
}

GradedPolicy is the policy a report was graded with (waivers appear on the findings they apply to).

func (*GradedPolicy) DeepCopy added in v0.8.0

func (in *GradedPolicy) DeepCopy() *GradedPolicy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new GradedPolicy.

func (*GradedPolicy) DeepCopyInto added in v0.8.0

func (in *GradedPolicy) DeepCopyInto(out *GradedPolicy)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type IgnoredVulnerability added in v0.8.0

type IgnoredVulnerability struct {
	// ID of the vulnerability, e.g. CVE-2024-10977.
	// +kubebuilder:validation:Pattern=`^[A-Za-z0-9][A-Za-z0-9._-]{2,63}$`
	ID     string `json:"id"`
	Waiver `json:",inline"`
}

IgnoredVulnerability is a waiver for one vulnerability.

func (*IgnoredVulnerability) DeepCopy added in v0.8.0

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new IgnoredVulnerability.

func (*IgnoredVulnerability) DeepCopyInto added in v0.8.0

func (in *IgnoredVulnerability) DeepCopyInto(out *IgnoredVulnerability)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type LevelCount added in v0.8.0

type LevelCount struct {
	Level SecurityLevel `json:"level"`
	Count int32         `json:"count"`
}

LevelCount is the number of non-waived findings at one level.

func (*LevelCount) DeepCopy added in v0.8.0

func (in *LevelCount) DeepCopy() *LevelCount

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new LevelCount.

func (*LevelCount) DeepCopyInto added in v0.8.0

func (in *LevelCount) DeepCopyInto(out *LevelCount)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Lint

type Lint struct {
	Destructive *CheckConfig `json:"destructive,omitempty"`
	// Review defines the review policy to apply after linting the schema changes (default: "ERROR").
	// Atlas Cloud login is required.
	Review LintReview `json:"review,omitempty"`
}

Lint defines the linting policies to apply before applying the schema.

func (*Lint) DeepCopy

func (in *Lint) DeepCopy() *Lint

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Lint.

func (*Lint) DeepCopyInto

func (in *Lint) DeepCopyInto(out *Lint)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type LintReview added in v0.6.0

type LintReview string

LintReview defines the review policies to apply after linting the schema. +kubebuilder:validation:Enum=ALWAYS;WARNING;ERROR

const (
	LintReviewAlways  LintReview = "ALWAYS"
	LintReviewWarning LintReview = "WARNING"
	LintReviewError   LintReview = "ERROR"
)

LintReview values.

type MigrateExecOrder added in v0.3.7

type MigrateExecOrder string

ExecOrder controls how Atlas computes and executes pending migration files to the database. +kubebuilder:validation:Enum=linear;linear-skip;non-linear

type MigrationPolicy added in v0.7.52

type MigrationPolicy struct {
	// Drift enables the pre-apply drift check
	// Before applying pending migrations, Atlas compares the database with the
	// state the Atlas Registry holds for the current version. The migration
	// directory must be on the registry: set spec.dir.remote, or migration.repo.name
	// in spec.config. See https://atlasgo.io/versioned/drift-detection.
	// +optional
	Drift *DriftPolicy `json:"drift,omitempty"`
}

MigrationPolicy defines the policies to apply when migrating the database.

func (*MigrationPolicy) DeepCopy added in v0.7.52

func (in *MigrationPolicy) DeepCopy() *MigrationPolicy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MigrationPolicy.

func (*MigrationPolicy) DeepCopyInto added in v0.7.52

func (in *MigrationPolicy) DeepCopyInto(out *MigrationPolicy)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*MigrationPolicy) HasDrift added in v0.7.52

func (p *MigrationPolicy) HasDrift() bool

HasDrift reports whether the policy enables the pre-apply drift check.

type ObservedTrigger added in v0.8.0

type ObservedTrigger struct {
	Kind     ScanTriggerKind `json:"kind"`
	Name     string          `json:"name"`
	UID      types.UID       `json:"uid"`
	Revision string          `json:"revision"`
}

ObservedTrigger is the revision of a trigger when a scan started.

func (*ObservedTrigger) DeepCopy added in v0.8.0

func (in *ObservedTrigger) DeepCopy() *ObservedTrigger

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ObservedTrigger.

func (*ObservedTrigger) DeepCopyInto added in v0.8.0

func (in *ObservedTrigger) DeepCopyInto(out *ObservedTrigger)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Policy

type Policy struct {
	Lint *Lint `json:"lint,omitempty"`
	Diff *Diff `json:"diff,omitempty"`
}

Policy defines the policies to apply when managing the schema change lifecycle.

func (*Policy) DeepCopy

func (in *Policy) DeepCopy() *Policy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Policy.

func (*Policy) DeepCopyInto

func (in *Policy) DeepCopyInto(out *Policy)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*Policy) HasDiff added in v0.7.1

func (p *Policy) HasDiff() bool

func (*Policy) HasLint added in v0.7.1

func (p *Policy) HasLint() bool

func (*Policy) HasLintDestructive added in v0.7.1

func (p *Policy) HasLintDestructive() bool

func (*Policy) HasLintReview added in v0.7.1

func (p *Policy) HasLintReview() bool

type ProjectConfigSpec added in v0.7.0

type ProjectConfigSpec struct {
	// Config defines the project configuration.
	// Should be a valid YAML string.
	Config string `json:"config,omitempty"`
	// ConfigFrom defines the reference to the secret key that contains the project configuration.
	ConfigFrom Secret `json:"configFrom,omitempty"`
	// EnvName defines the environment name that defined in the project configuration.
	// If not defined, the default environment "k8s" will be used.
	EnvName string `json:"envName,omitempty"`
	// Vars defines the input variables for the project configuration.
	Vars []Variable `json:"vars,omitempty"`
}

ProjectConfigSpec defines the project configuration.

func (*ProjectConfigSpec) DeepCopy added in v0.7.0

func (in *ProjectConfigSpec) DeepCopy() *ProjectConfigSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ProjectConfigSpec.

func (*ProjectConfigSpec) DeepCopyInto added in v0.7.0

func (in *ProjectConfigSpec) DeepCopyInto(out *ProjectConfigSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (ProjectConfigSpec) GetConfig added in v0.7.0

func (s ProjectConfigSpec) GetConfig(ctx context.Context, r client.Reader, ns string) (*hclwrite.File, error)

GetConfig returns the project configuration. The configuration is resolved from the secret reference.

func (ProjectConfigSpec) GetVars added in v0.7.0

GetVars returns the input variables for the project configuration. The variables are resolved from the secret or configmap reference.

type ProtectFlows added in v0.5.0

type ProtectFlows struct {
	MigrateDown *DeploymentFlow `json:"migrateDown,omitempty"`
}

ProtectedFlows defines the protected flows of a deployment.

func (*ProtectFlows) DeepCopy added in v0.5.0

func (in *ProtectFlows) DeepCopy() *ProtectFlows

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ProtectFlows.

func (*ProtectFlows) DeepCopyInto added in v0.5.0

func (in *ProtectFlows) DeepCopyInto(out *ProtectFlows)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Remote added in v0.1.7

type Remote struct {
	Name string `json:"name,omitempty"`
	Tag  string `json:"tag,omitempty"`
}

Remote defines the Atlas Cloud directory migration.

func (*Remote) DeepCopy added in v0.1.7

func (in *Remote) DeepCopy() *Remote

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Remote.

func (*Remote) DeepCopyInto added in v0.1.7

func (in *Remote) DeepCopyInto(out *Remote)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ReportedVulnerability added in v0.8.0

type ReportedVulnerability struct {
	ID           string        `json:"id"`
	Extension    string        `json:"extension"`
	Version      string        `json:"version,omitempty"`
	Level        SecurityLevel `json:"level"`
	CVSSSeverity string        `json:"cvssSeverity,omitempty"`
	Title        string        `json:"title,omitempty"`
	Description  string        `json:"description,omitempty"`
	Suggestion   string        `json:"suggestion,omitempty"`
	// Waiver is set when the finding is ignored by the policy.
	// +optional
	Waiver *Waiver `json:"waiver,omitempty"`
}

ReportedVulnerability is one finding of a scan.

func (*ReportedVulnerability) DeepCopy added in v0.8.0

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ReportedVulnerability.

func (*ReportedVulnerability) DeepCopyInto added in v0.8.0

func (in *ReportedVulnerability) DeepCopyInto(out *ReportedVulnerability)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ScanAttempt added in v0.8.0

type ScanAttempt struct {
	Trigger        ScanTrigger  `json:"trigger"`
	TriggeredBy    string       `json:"triggeredBy,omitempty"`
	StartTime      metav1.Time  `json:"startTime"`
	CompletionTime *metav1.Time `json:"completionTime,omitempty"`
	Result         ScanResult   `json:"result,omitempty"`
	// Message is a fixed description of a failure class, never CLI or driver output.
	Message string `json:"message,omitempty"`
	// InputsHash identifies what was observed when the attempt started. A stalled
	// resource makes one finished attempt per distinct hash.
	InputsHash string `json:"inputsHash,omitempty"`
}

ScanAttempt describes one scan attempt.

func (*ScanAttempt) DeepCopy added in v0.8.0

func (in *ScanAttempt) DeepCopy() *ScanAttempt

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ScanAttempt.

func (*ScanAttempt) DeepCopyInto added in v0.8.0

func (in *ScanAttempt) DeepCopyInto(out *ScanAttempt)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ScanPolicy added in v0.8.0

type ScanPolicy struct {
	// MinSeverity is the lowest level that is reported (--min-severity).
	// +kubebuilder:default=NORMAL
	MinSeverity SecurityLevel `json:"minSeverity,omitempty"`
	// FailOn is the lowest level at which a non-waived finding makes Compliant=False. Unset: report only.
	// +optional
	FailOn *SecurityLevel `json:"failOn,omitempty"`
	// Ignore lists vulnerabilities that do not count toward the policy. They remain in the report, marked waived.
	// +optional
	// +listType=map
	// +listMapKey=id
	// +kubebuilder:validation:MaxItems=256
	Ignore []IgnoredVulnerability `json:"ignore,omitempty"`
}

ScanPolicy grades the findings of a scan. +kubebuilder:validation:XValidation:rule="!has(self.failOn) || !has(self.minSeverity) || {'NORMAL':0,'ELEVATED':1,'HIGH':2,'CRITICAL':3}[self.failOn] >= {'NORMAL':0,'ELEVATED':1,'HIGH':2,'CRITICAL':3}[self.minSeverity]",message="failOn must be at or above minSeverity"

func (*ScanPolicy) DeepCopy added in v0.8.0

func (in *ScanPolicy) DeepCopy() *ScanPolicy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ScanPolicy.

func (*ScanPolicy) DeepCopyInto added in v0.8.0

func (in *ScanPolicy) DeepCopyInto(out *ScanPolicy)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ScanResult added in v0.8.0

type ScanResult string

ScanResult is the outcome of a scan attempt. +kubebuilder:validation:Enum=Succeeded;Failed

const (
	ScanSucceeded ScanResult = "Succeeded"
	ScanFailed    ScanResult = "Failed"
)

ScanResult values.

type ScanSummary added in v0.8.0

type ScanSummary struct {
	Driver     string `json:"driver,omitempty"`
	Extensions int32  `json:"extensions"`
	Total      int32  `json:"total"`
	Waived     int32  `json:"waived"`
	// +optional
	HighestLevel SecurityLevel `json:"highestLevel,omitempty"`
	// +listType=map
	// +listMapKey=level
	Levels []LevelCount `json:"levels"`
}

ScanSummary counts the findings of a scan. Levels always lists all four, so metric series never disappear.

func (*ScanSummary) DeepCopy added in v0.8.0

func (in *ScanSummary) DeepCopy() *ScanSummary

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ScanSummary.

func (*ScanSummary) DeepCopyInto added in v0.8.0

func (in *ScanSummary) DeepCopyInto(out *ScanSummary)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ScanTrigger added in v0.8.0

type ScanTrigger string

ScanTrigger says why a scan ran. +kubebuilder:validation:Enum=Spec;Manual;Apply;Schedule;Policy

const (
	TriggerSpec     ScanTrigger = "Spec"
	TriggerManual   ScanTrigger = "Manual"
	TriggerApply    ScanTrigger = "Apply"
	TriggerSchedule ScanTrigger = "Schedule"
	TriggerPolicy   ScanTrigger = "Policy"
)

ScanTrigger values, in precedence order: one scan satisfies everything pending, and the label names the highest-precedence cause.

type ScanTriggerKind added in v0.8.0

type ScanTriggerKind string

ScanTriggerKind is a kind whose applies can trigger a scan. +kubebuilder:validation:Enum=AtlasSchema;AtlasMigration

const (
	TriggerKindSchema    ScanTriggerKind = "AtlasSchema"
	TriggerKindMigration ScanTriggerKind = "AtlasMigration"
)

ScanTriggerKind values.

type ScanTriggerRef added in v0.8.0

type ScanTriggerRef struct {
	Kind ScanTriggerKind `json:"kind"`
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=253
	Name string `json:"name"`
}

ScanTriggerRef references an AtlasSchema or AtlasMigration in the same namespace.

func (*ScanTriggerRef) DeepCopy added in v0.8.0

func (in *ScanTriggerRef) DeepCopy() *ScanTriggerRef

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ScanTriggerRef.

func (*ScanTriggerRef) DeepCopyInto added in v0.8.0

func (in *ScanTriggerRef) DeepCopyInto(out *ScanTriggerRef)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Schema

type Schema struct {
	SQL string `json:"sql,omitempty"`
	HCL string `json:"hcl,omitempty"`
	URL string `json:"url,omitempty"`

	ConfigMapKeyRef *corev1.ConfigMapKeySelector `json:"configMapKeyRef,omitempty"`
}

Schema defines the desired state of the target database schema in plain SQL or HCL.

func (*Schema) DeepCopy

func (in *Schema) DeepCopy() *Schema

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Schema.

func (*Schema) DeepCopyInto

func (in *Schema) DeepCopyInto(out *Schema)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (Schema) DesiredState added in v0.6.0

func (s Schema) DesiredState(ctx context.Context, r client.Reader, ns string) (*url.URL, []byte, error)

Desired returns the desired schema of the AtlasSchema.

type Secret added in v0.3.3

type Secret struct {
	// SecretKeyRef defines the secret key reference to use for the user.
	SecretKeyRef *corev1.SecretKeySelector `json:"secretKeyRef,omitempty"`
}

Secret defines a secret key reference.

func (*Secret) DeepCopy added in v0.3.3

func (in *Secret) DeepCopy() *Secret

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Secret.

func (*Secret) DeepCopyInto added in v0.3.3

func (in *Secret) DeepCopyInto(out *Secret)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SecurityLevel added in v0.8.0

type SecurityLevel string

SecurityLevel is a Security Graph grade. Uppercase mirrors the CLI flags and atlas.hcl deliberately. +kubebuilder:validation:Enum=NORMAL;ELEVATED;HIGH;CRITICAL

const (
	SecurityLevelNormal   SecurityLevel = "NORMAL"
	SecurityLevelElevated SecurityLevel = "ELEVATED"
	SecurityLevelHigh     SecurityLevel = "HIGH"
	SecurityLevelCritical SecurityLevel = "CRITICAL"
)

SecurityLevel values.

func SecurityLevels added in v0.8.0

func SecurityLevels() []SecurityLevel

SecurityLevels returns the levels lowest first, as a copy the caller may modify.

type SecurityReport added in v0.8.0

type SecurityReport struct {
	StartTime      metav1.Time `json:"startTime"`
	CompletionTime metav1.Time `json:"completionTime"`
	Trigger        ScanTrigger `json:"trigger"`
	// ServerVersion of the database. The engine type is Summary.Driver, which the
	// scan carries too, so it reads without access to the report.
	ServerVersion string       `json:"serverVersion,omitempty"`
	Policy        GradedPolicy `json:"policy"`
	Summary       ScanSummary  `json:"summary"`
	// Extensions installed in the database, by name.
	// +listType=set
	Extensions []string `json:"extensions,omitempty"`
	// +listType=map
	// +listMapKey=id
	// +listMapKey=extension
	Vulnerabilities []ReportedVulnerability `json:"vulnerabilities,omitempty"`
}

SecurityReport is the graded result of one scan.

func (*SecurityReport) DeepCopy added in v0.8.0

func (in *SecurityReport) DeepCopy() *SecurityReport

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecurityReport.

func (*SecurityReport) DeepCopyInto added in v0.8.0

func (in *SecurityReport) DeepCopyInto(out *SecurityReport)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SkipChanges

type SkipChanges struct {
	// +optional
	AddSchema bool `json:"add_schema,omitempty"`
	// +optional
	DropSchema bool `json:"drop_schema,omitempty"`
	// +optional
	ModifySchema bool `json:"modify_schema,omitempty"`
	// +optional
	AddTable bool `json:"add_table,omitempty"`
	// +optional
	DropTable bool `json:"drop_table,omitempty"`
	// +optional
	ModifyTable bool `json:"modify_table,omitempty"`
	// +optional
	AddColumn bool `json:"add_column,omitempty"`
	// +optional
	DropColumn bool `json:"drop_column,omitempty"`
	// +optional
	ModifyColumn bool `json:"modify_column,omitempty"`
	// +optional
	AddIndex bool `json:"add_index,omitempty"`
	// +optional
	DropIndex bool `json:"drop_index,omitempty"`
	// +optional
	ModifyIndex bool `json:"modify_index,omitempty"`
	// +optional
	AddForeignKey bool `json:"add_foreign_key,omitempty"`
	// +optional
	DropForeignKey bool `json:"drop_foreign_key,omitempty"`
	// +optional
	ModifyForeignKey bool `json:"modify_foreign_key,omitempty"`
}

SkipChanges represents the skip changes policy.

func (*SkipChanges) DeepCopy

func (in *SkipChanges) DeepCopy() *SkipChanges

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SkipChanges.

func (*SkipChanges) DeepCopyInto

func (in *SkipChanges) DeepCopyInto(out *SkipChanges)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type TargetSpec added in v0.3.1

type TargetSpec struct {
	// URL of the target database schema.
	URL string `json:"url,omitempty"`
	// URLs may be defined as a secret key reference.
	URLFrom Secret `json:"urlFrom,omitempty"`
	// Credentials defines the credentials to use when connecting to the database.
	// Used instead of URL or URLFrom.
	Credentials Credentials `json:"credentials,omitempty"`
}

TargetSpec defines the target database to manage.

func (TargetSpec) DatabaseURL added in v0.3.1

func (s TargetSpec) DatabaseURL(ctx context.Context, r client.Reader, ns string) (*url.URL, error)

DatabaseURL returns the database url.

func (*TargetSpec) DeepCopy added in v0.3.1

func (in *TargetSpec) DeepCopy() *TargetSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TargetSpec.

func (*TargetSpec) DeepCopyInto added in v0.3.1

func (in *TargetSpec) DeepCopyInto(out *TargetSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type TokenFrom added in v0.1.7

type TokenFrom struct {
	// SecretKeyRef references to the key of a secret in the same namespace.
	SecretKeyRef *corev1.SecretKeySelector `json:"secretKeyRef,omitempty"`
}

TokenFrom defines a reference to a secret key that contains the Atlas Cloud Token

func (*TokenFrom) DeepCopy added in v0.1.7

func (in *TokenFrom) DeepCopy() *TokenFrom

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TokenFrom.

func (*TokenFrom) DeepCopyInto added in v0.1.7

func (in *TokenFrom) DeepCopyInto(out *TokenFrom)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type TransactionMode added in v0.4.3

type TransactionMode string

TransactionMode +kubebuilder:validation:Enum=file;all;none

type ValueFrom added in v0.7.0

type ValueFrom struct {
	// SecretKeyRef defines the secret key reference to use for the value.
	SecretKeyRef *corev1.SecretKeySelector `json:"secretKeyRef,omitempty"`
	// ConfigMapKeyRef defines the configmap key reference to use for the value.
	ConfigMapKeyRef *corev1.ConfigMapKeySelector `json:"configMapKeyRef,omitempty"`
}

ValueFrom defines the reference to the secret key that contains the value.

func (*ValueFrom) DeepCopy added in v0.7.0

func (in *ValueFrom) DeepCopy() *ValueFrom

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ValueFrom.

func (*ValueFrom) DeepCopyInto added in v0.7.0

func (in *ValueFrom) DeepCopyInto(out *ValueFrom)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Variable added in v0.7.0

type Variable struct {
	Key       string    `json:"key,omitempty"`
	Value     string    `json:"value,omitempty"`
	ValueFrom ValueFrom `json:"valueFrom,omitempty"`
}

Variables defines the reference of secret/configmap to the input variables for the project configuration.

func (*Variable) DeepCopy added in v0.7.0

func (in *Variable) DeepCopy() *Variable

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Variable.

func (*Variable) DeepCopyInto added in v0.7.0

func (in *Variable) DeepCopyInto(out *Variable)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Waiver added in v0.8.0

type Waiver struct {
	// Reason documents why the vulnerability is waived.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=1024
	Reason string `json:"reason"`
	// ExpirationTime is when the waiver stops applying. A scan runs when it passes.
	// +optional
	ExpirationTime *metav1.Time `json:"expirationTime,omitempty"`
}

Waiver documents why and until when a vulnerability is ignored.

func (*Waiver) DeepCopy added in v0.8.0

func (in *Waiver) DeepCopy() *Waiver

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Waiver.

func (*Waiver) DeepCopyInto added in v0.8.0

func (in *Waiver) DeepCopyInto(out *Waiver)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL