Documentation
¶
Overview ¶
Package v1alpha1 contains API Schema definitions for the db v1alpha1 API group +kubebuilder:object:generate=true +groupName=db.atlasgo.io
Index ¶
- Constants
- Variables
- func LevelIndex(l SecurityLevel) int
- func VersionFromContext(ctx context.Context) string
- func WithVersionContext(ctx context.Context, version string) context.Context
- type AtlasDriftCheck
- func (in *AtlasDriftCheck) DeepCopy() *AtlasDriftCheck
- func (in *AtlasDriftCheck) DeepCopyInto(out *AtlasDriftCheck)
- func (in *AtlasDriftCheck) DeepCopyObject() runtime.Object
- func (c *AtlasDriftCheck) SetCheckFailed(reason, message string, permanent bool)
- func (c *AtlasDriftCheck) SetChecked(rep *atlasexec.MigrateDrift)
- func (c *AtlasDriftCheck) SetDrifted(rep *atlasexec.MigrateDrift, action DriftAction)
- func (c *AtlasDriftCheck) SetSuspended()
- func (c *AtlasDriftCheck) SetTargetNotReady(message string)
- type AtlasDriftCheckList
- type AtlasDriftCheckSpec
- type AtlasDriftCheckStatus
- type AtlasMigration
- func (in *AtlasMigration) DeepCopy() *AtlasMigration
- func (in *AtlasMigration) DeepCopyInto(out *AtlasMigration)
- func (in *AtlasMigration) DeepCopyObject() runtime.Object
- func (m *AtlasMigration) GetPrewarmDevDB() *bool
- func (m *AtlasMigration) IncrementFailed()
- func (m *AtlasMigration) IsExceedBackoffLimit() bool
- func (m *AtlasMigration) IsHashModified(hash string) bool
- func (m *AtlasMigration) IsReady() bool
- func (m *AtlasMigration) IsReconciling() bool
- func (m *AtlasMigration) NamespacedName() types.NamespacedName
- func (m *AtlasMigration) ResetFailed()
- func (m *AtlasMigration) SetNotReady(reason, message string)
- func (m *AtlasMigration) SetReady(status AtlasMigrationStatus)
- func (m *AtlasMigration) SetReconciling(message string)
- type AtlasMigrationList
- type AtlasMigrationSpec
- type AtlasMigrationStatus
- type AtlasSchema
- func (in *AtlasSchema) DeepCopy() *AtlasSchema
- func (in *AtlasSchema) DeepCopyInto(out *AtlasSchema)
- func (in *AtlasSchema) DeepCopyObject() runtime.Object
- func (s *AtlasSchema) GetPrewarmDevDB() *bool
- func (sc *AtlasSchema) IncrementFailed()
- func (sc *AtlasSchema) IsExceedBackoffLimit() bool
- func (sc *AtlasSchema) IsHashModified(hash string) bool
- func (m *AtlasSchema) IsReady() bool
- func (s *AtlasSchema) NamespacedName() types.NamespacedName
- func (sc *AtlasSchema) ResetFailed()
- func (sc *AtlasSchema) SetNotReady(reason, msg string)
- func (sc *AtlasSchema) SetReady(status AtlasSchemaStatus, report any)
- func (sc *AtlasSchema) SetReconciling(message string)
- type AtlasSchemaList
- type AtlasSchemaSpec
- type AtlasSchemaStatus
- type AtlasSecurityReport
- type AtlasSecurityReportList
- type AtlasSecurityScan
- func (s *AtlasSecurityScan) BackoffLimit() int
- func (in *AtlasSecurityScan) DeepCopy() *AtlasSecurityScan
- func (in *AtlasSecurityScan) DeepCopyInto(out *AtlasSecurityScan)
- func (in *AtlasSecurityScan) DeepCopyObject() runtime.Object
- func (s *AtlasSecurityScan) IsReady() bool
- func (s *AtlasSecurityScan) IsStalled(reason string) bool
- func (s *AtlasSecurityScan) IsSuspended() bool
- func (s *AtlasSecurityScan) MinSeverity() SecurityLevel
- func (s *AtlasSecurityScan) SetCompliant(status metav1.ConditionStatus, reason, message string)
- func (s *AtlasSecurityScan) SetFirstVisit()
- func (s *AtlasSecurityScan) SetIdle()
- func (s *AtlasSecurityScan) SetRetrying(reason, message string)
- func (s *AtlasSecurityScan) SetScanned(message string)
- func (s *AtlasSecurityScan) SetScanning()
- func (s *AtlasSecurityScan) SetStalled(reason, message string)
- func (s *AtlasSecurityScan) SetSuspended()
- func (s *AtlasSecurityScan) WasSuspended() bool
- type AtlasSecurityScanList
- type AtlasSecurityScanSpec
- type AtlasSecurityScanStatus
- type CheckConfig
- type Cloud
- type CloudV0
- type ConcurrentIndex
- type Credentials
- type DeploymentFlow
- type DevDB
- type DevDBMetadata
- type Diff
- type Dir
- type DriftAction
- type DriftCheckTarget
- type DriftOnError
- type DriftPolicy
- type DriftSummary
- type Driver
- type GradedPolicy
- type IgnoredVulnerability
- type LevelCount
- type Lint
- type LintReview
- type MigrateExecOrder
- type MigrationPolicy
- type ObservedTrigger
- type Policy
- type ProjectConfigSpec
- func (in *ProjectConfigSpec) DeepCopy() *ProjectConfigSpec
- func (in *ProjectConfigSpec) DeepCopyInto(out *ProjectConfigSpec)
- func (s ProjectConfigSpec) GetConfig(ctx context.Context, r client.Reader, ns string) (*hclwrite.File, error)
- func (s ProjectConfigSpec) GetVars(ctx context.Context, r client.Reader, ns string) (atlasexec.Vars2, error)
- type ProtectFlows
- type Remote
- type ReportedVulnerability
- type ScanAttempt
- type ScanPolicy
- type ScanResult
- type ScanSummary
- type ScanTrigger
- type ScanTriggerKind
- type ScanTriggerRef
- type Schema
- type Secret
- type SecurityLevel
- type SecurityReport
- type SkipChanges
- type TargetSpec
- type TokenFrom
- type TransactionMode
- type ValueFrom
- type Variable
- type Waiver
Constants ¶
const ( SchemaTypeAtlas = "atlas" SchemaTypeFile = "file" )
Schema reader types (URL schemes).
const ( // ReasonReconciling represents for the reconciliation is in progress. ReasonReconciling = "Reconciling" // ReasonGettingDevDB represents the reason for getting the dev database. ReasonGettingDevDB = "GettingDevDB" // ReasonWhoAmI represents the reason for getting the current user via Atlas CLI ReasonWhoAmI = "WhoAmI" // ReasonApplyingMigration represents the reason for applied a schema/migration resource successfully. ReasonApplied = "Applied" // ReasonApprovalPending represents the reason for the approval is pending. ReasonApprovalPending = "ApprovalPending" // ReasonCreatingAtlasClient represents the reason for creating an Atlas client. ReasonCreatingAtlasClient = "CreatingAtlasClient" // ReasonCreatingWorkingDir represents the reason for creating a working directory. ReasonCreatingWorkingDir = "CreatingWorkingDir" // ReasonLogin represents the reason for logging in to Atlas. ReasonLogin = "Login" // ReasonReadingMigrationData represents the reason for getting the data of an AtlasMigration resource. ReasonReadingMigrationData = "ReadingMigrationData" // ReasonMigrating represents the reason for migrating a database. ReasonMigrating = "Migrating" // ReasonStoringDirState represents the reason for storing the state of an AtlasMigration resource. ReasonStoringDirState = "StoringDirState" // ReasonDriftDetected represents the reason for the pre-apply drift check blocking a migration. ReasonDriftDetected = "DriftDetected" // ReasonChecked represents the reason for a completed drift check. ReasonChecked = "Checked" // ReasonNoDrift represents the reason for a drift check that found no drift. ReasonNoDrift = "NoDrift" // ReasonCheckFailed represents the reason for a drift check that could not be completed. ReasonCheckFailed = "CheckFailed" // ReasonTargetNotFound represents the reason for a missing target resource. ReasonTargetNotFound = "TargetNotFound" // ReasonTargetNotReady represents the reason for a target resource that is mid-apply. ReasonTargetNotReady = "TargetNotReady" // ReasonSuspended represents the reason for a suspended resource. ReasonSuspended = "Suspended" // ReasonNoMigrationHistory represents the reason for a database with no applied migrations. ReasonNoMigrationHistory = "NoMigrationHistory" // Reasons of the AtlasSecurityScan conditions. Their messages are fixed text: // CLI and driver output never reaches a condition or an Event. ReasonScanning = "Scanning" ReasonScanned = "Scanned" ReasonRetrying = "Retrying" ReasonScanFailed = "ScanFailed" ReasonLoginFailed = "LoginFailed" ReasonCLIError = "CLIError" ReasonReadingInputs = "ReadingInputs" ReasonStoringReport = "StoringReport" ReasonBackoffLimitExceeded = "BackoffLimitExceeded" ReasonInvalidSchedule = "InvalidSchedule" ReasonInvalidTimeZone = "InvalidTimeZone" ReasonInvalidTarget = "InvalidTarget" ReasonNotScanned = "NotScanned" ReasonNoThreshold = "NoThreshold" ReasonWithinPolicy = "WithinPolicy" ReasonPolicyViolated = "PolicyViolated" ReasonReportStale = "ReportStale" // Event-only reasons of the AtlasSecurityScan controller. EventTriggerNotFound = "TriggerNotFound" EventMissedSchedule = "MissedSchedule" EventScanWarning = "ScanWarning" EventResumed = "Resumed" )
const ( // AnnotationScanRequestedAt requests a scan. Any new value triggers one scan; the value // is echoed to status.lastHandledScanRequest when that scan completes successfully. AnnotationScanRequestedAt = "db.atlasgo.io/scan-requested-at" )
Variables ¶
var ( // GroupVersion is group version used to register these objects GroupVersion = schema.GroupVersion{Group: "db.atlasgo.io", Version: "v1alpha1"} // SchemeBuilder is used to add go types to the GroupVersionKind scheme SchemeBuilder = &scheme.Builder{GroupVersion: GroupVersion} // AddToScheme adds the types in this group-version to the given scheme. AddToScheme = SchemeBuilder.AddToScheme )
Functions ¶
func LevelIndex ¶ added in v0.8.0
func LevelIndex(l SecurityLevel) int
LevelIndex ranks a level, lowest first, and -1 for an unknown one.
func VersionFromContext ¶ added in v0.3.7
VersionFromContext returns the version from the given context.
Types ¶
type AtlasDriftCheck ¶ added in v0.8.0
type AtlasDriftCheck struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
// Defines the desired state of AtlasDriftCheck.
Spec AtlasDriftCheckSpec `json:"spec,omitempty"`
// Reports the observed state of AtlasDriftCheck.
//+kubebuilder:default={"observedGeneration":-1}
Status AtlasDriftCheckStatus `json:"status,omitempty"`
}
+kubebuilder:object:root=true +kubebuilder:subresource:status
AtlasDriftCheck periodically checks an AtlasMigration database for drift and reports the result in its status. It does not change the database or report the DDL needed to fix the drift. +kubebuilder:printcolumn:name="Target",type=string,JSONPath=`.spec.targetRef.name` +kubebuilder:printcolumn:name="Drifted",type=string,JSONPath=`.status.conditions[?(@.type=="Drifted")].status` +kubebuilder:printcolumn:name="Version",type=string,JSONPath=`.status.version` +kubebuilder:printcolumn:name="Objects",type=integer,JSONPath=`.status.summary.total` +kubebuilder:printcolumn:name="Ready",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].status` +kubebuilder:printcolumn:name="Suspended",type=boolean,JSONPath=`.spec.suspend` +kubebuilder:printcolumn:name="Last Check",type=date,JSONPath=`.status.lastCheckTime` +kubebuilder:printcolumn:name="Age",type=date,JSONPath=`.metadata.creationTimestamp` +kubebuilder:printcolumn:name="Fingerprint",type=string,JSONPath=`.status.fingerprint`,priority=1 +kubebuilder:printcolumn:name="Mode",type=string,JSONPath=`.status.mode`,priority=1
func (*AtlasDriftCheck) DeepCopy ¶ added in v0.8.0
func (in *AtlasDriftCheck) DeepCopy() *AtlasDriftCheck
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasDriftCheck.
func (*AtlasDriftCheck) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasDriftCheck) DeepCopyInto(out *AtlasDriftCheck)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasDriftCheck) DeepCopyObject ¶ added in v0.8.0
func (in *AtlasDriftCheck) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*AtlasDriftCheck) SetCheckFailed ¶ added in v0.8.0
func (c *AtlasDriftCheck) SetCheckFailed(reason, message string, permanent bool)
SetCheckFailed records a check that could not be completed. A permanent failure stalls the resource; a transient one keeps it reconciling. Either way the result of the last completed check is kept, and the Drifted condition becomes Unknown because it is no longer being observed.
func (*AtlasDriftCheck) SetChecked ¶ added in v0.8.0
func (c *AtlasDriftCheck) SetChecked(rep *atlasexec.MigrateDrift)
SetChecked records a completed check that found no drift.
func (*AtlasDriftCheck) SetDrifted ¶ added in v0.8.0
func (c *AtlasDriftCheck) SetDrifted(rep *atlasexec.MigrateDrift, action DriftAction)
SetDrifted records a completed check that found drift. The action decides whether the drift also marks the check not ready.
func (*AtlasDriftCheck) SetSuspended ¶ added in v0.8.0
func (c *AtlasDriftCheck) SetSuspended()
SetSuspended records that the checks are suspended.
func (*AtlasDriftCheck) SetTargetNotReady ¶ added in v0.8.0
func (c *AtlasDriftCheck) SetTargetNotReady(message string)
SetTargetNotReady records that the check was skipped because the target is mid-apply. It touches the Reconciling condition only, so the result of the last completed check stays visible.
type AtlasDriftCheckList ¶ added in v0.8.0
type AtlasDriftCheckList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []AtlasDriftCheck `json:"items"`
}
+kubebuilder:object:root=true
AtlasDriftCheckList contains a list of AtlasDriftCheck
func (*AtlasDriftCheckList) DeepCopy ¶ added in v0.8.0
func (in *AtlasDriftCheckList) DeepCopy() *AtlasDriftCheckList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasDriftCheckList.
func (*AtlasDriftCheckList) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasDriftCheckList) DeepCopyInto(out *AtlasDriftCheckList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasDriftCheckList) DeepCopyObject ¶ added in v0.8.0
func (in *AtlasDriftCheckList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type AtlasDriftCheckSpec ¶ added in v0.8.0
type AtlasDriftCheckSpec struct {
// The AtlasMigration to check for drift.
TargetRef DriftCheckTarget `json:"targetRef"`
// How often to check for drift. The minimum is 1m because each check uses
// the same database lock as migrations, and more frequent checks may conflict
// with deployments.
// +kubebuilder:default="5m"
// +kubebuilder:validation:XValidation:rule="duration(self) >= duration('1m')",message="interval must be at least 1m"
Interval metav1.Duration `json:"interval,omitempty"`
// Maximum time allowed for one drift check.
// +kubebuilder:default="5m"
Timeout metav1.Duration `json:"timeout,omitempty"`
// Stops drift checks without deleting the resource.
// +optional
Suspend bool `json:"suspend,omitempty"`
// How to handle detected drift. Report records the drift in the Drifted
// condition. Fail also sets Ready=False and Stalled=True, so GitOps tools can
// treat the check as degraded.
// +kubebuilder:default=Report
OnDrift DriftAction `json:"onDrift,omitempty"`
// Database objects to ignore, such as "public.audit_*" or
// "*[type=extension]". If empty, uses the exclude list from the target's
// spec.policy.drift.
// +optional
Exclude []string `json:"exclude,omitempty"`
}
AtlasDriftCheckSpec defines the desired state of AtlasDriftCheck
func (*AtlasDriftCheckSpec) DeepCopy ¶ added in v0.8.0
func (in *AtlasDriftCheckSpec) DeepCopy() *AtlasDriftCheckSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasDriftCheckSpec.
func (*AtlasDriftCheckSpec) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasDriftCheckSpec) DeepCopyInto(out *AtlasDriftCheckSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type AtlasDriftCheckStatus ¶ added in v0.8.0
type AtlasDriftCheckStatus struct {
// Generation last processed by the controller.
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// Conditions represent the latest available observations of an object's state.
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
// Applied migration version used to resolve the expected state.
// +optional
Version string `json:"version,omitempty"`
// Identifies the current drift. It changes when the drift changes and is
// empty when there is no drift.
// +optional
Fingerprint string `json:"fingerprint,omitempty"`
// How the expected state was resolved, "registry" or "local".
// +optional
Mode string `json:"mode,omitempty"`
// Counts drifted objects. It is empty when there is no drift.
// +optional
Summary *DriftSummary `json:"summary,omitempty"`
// Time when the last drift check completed.
// +optional
LastCheckTime *metav1.Time `json:"lastCheckTime,omitempty"`
}
AtlasDriftCheckStatus defines the observed state of AtlasDriftCheck
func (*AtlasDriftCheckStatus) DeepCopy ¶ added in v0.8.0
func (in *AtlasDriftCheckStatus) DeepCopy() *AtlasDriftCheckStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasDriftCheckStatus.
func (*AtlasDriftCheckStatus) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasDriftCheckStatus) DeepCopyInto(out *AtlasDriftCheckStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type AtlasMigration ¶ added in v0.1.7
type AtlasMigration struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec AtlasMigrationSpec `json:"spec,omitempty"`
//+kubebuilder:default={"observedGeneration":-1}
Status AtlasMigrationStatus `json:"status,omitempty"`
}
+kubebuilder:object:root=true +kubebuilder:subresource:status
AtlasMigration is the Schema for the atlasmigrations API +kubebuilder:printcolumn:name="Ready",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].status` +kubebuilder:printcolumn:name="Reason",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].reason`
func (*AtlasMigration) DeepCopy ¶ added in v0.1.7
func (in *AtlasMigration) DeepCopy() *AtlasMigration
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasMigration.
func (*AtlasMigration) DeepCopyInto ¶ added in v0.1.7
func (in *AtlasMigration) DeepCopyInto(out *AtlasMigration)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasMigration) DeepCopyObject ¶ added in v0.1.7
func (in *AtlasMigration) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*AtlasMigration) GetPrewarmDevDB ¶ added in v0.8.0
func (m *AtlasMigration) GetPrewarmDevDB() *bool
GetPrewarmDevDB returns the per-resource dev DB prewarm override, if set.
func (*AtlasMigration) IncrementFailed ¶ added in v0.7.3
func (m *AtlasMigration) IncrementFailed()
IncrementFailed increments the failed count.
func (*AtlasMigration) IsExceedBackoffLimit ¶ added in v0.7.3
func (m *AtlasMigration) IsExceedBackoffLimit() bool
IsExceedBackoffLimit returns true if the failed count exceeds the backoff limit.
func (*AtlasMigration) IsHashModified ¶ added in v0.1.8
func (m *AtlasMigration) IsHashModified(hash string) bool
IsHashModified returns true if the hash is different from the observed hash.
func (*AtlasMigration) IsReady ¶ added in v0.1.8
func (m *AtlasMigration) IsReady() bool
IsReady returns true if the ready condition is true.
func (*AtlasMigration) IsReconciling ¶ added in v0.7.52
func (m *AtlasMigration) IsReconciling() bool
IsReconciling returns true if the reconciling condition is true, i.e. an apply is in flight.
func (*AtlasMigration) NamespacedName ¶ added in v0.1.7
func (m *AtlasMigration) NamespacedName() types.NamespacedName
NamespacedName returns the namespaced name of the object.
func (*AtlasMigration) ResetFailed ¶ added in v0.7.3
func (m *AtlasMigration) ResetFailed()
ResetFailed resets the failed count.
func (*AtlasMigration) SetNotReady ¶ added in v0.1.8
func (m *AtlasMigration) SetNotReady(reason, message string)
SetNotReady sets the ready condition to false.
func (*AtlasMigration) SetReady ¶ added in v0.1.8
func (m *AtlasMigration) SetReady(status AtlasMigrationStatus)
SetReady sets the ready condition to true.
func (*AtlasMigration) SetReconciling ¶ added in v0.7.3
func (m *AtlasMigration) SetReconciling(message string)
SetReconciling sets the ready condition to false with the reason "Reconciling".
type AtlasMigrationList ¶ added in v0.1.7
type AtlasMigrationList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []AtlasMigration `json:"items"`
}
+kubebuilder:object:root=true
AtlasMigrationList contains a list of AtlasMigration
func (*AtlasMigrationList) DeepCopy ¶ added in v0.1.7
func (in *AtlasMigrationList) DeepCopy() *AtlasMigrationList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasMigrationList.
func (*AtlasMigrationList) DeepCopyInto ¶ added in v0.1.7
func (in *AtlasMigrationList) DeepCopyInto(out *AtlasMigrationList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasMigrationList) DeepCopyObject ¶ added in v0.1.7
func (in *AtlasMigrationList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type AtlasMigrationSpec ¶ added in v0.1.7
type AtlasMigrationSpec struct {
TargetSpec `json:",inline"`
ProjectConfigSpec `json:",inline"`
// EnvName sets the environment name used for reporting runs to Atlas Cloud.
EnvName string `json:"envName,omitempty"`
// Cloud defines the Atlas Cloud configuration.
Cloud CloudV0 `json:"cloud,omitempty"`
// Dir defines the directory to use for migrations as a configmap key reference.
Dir Dir `json:"dir"`
// DevURL is the URL of the database to use for normalization and calculations.
// If not specified, the operator will spin up a temporary database container to use for these operations.
// +optional
DevURL string `json:"devURL"`
// DevURLFrom is a reference to a secret containing the URL of the database to use for normalization and calculations.
// +optional
DevURLFrom Secret `json:"devURLFrom,omitempty"`
// DevDB configures the dev database pod used for normalization and calculations.
// If spec is omitted, a default pod spec is created based on the target database driver.
// When a custom pod spec is provided, devURL must be defined as well.
// +optional
DevDB *DevDB `json:"devDB,omitempty"`
// PrewarmDevDB controls whether the automatically managed dev DB should be kept warm after reconciliation.
// If not specified, the operator-wide default is used.
// +optional
PrewarmDevDB *bool `json:"prewarmDevDB,omitempty"`
// RevisionsSchema defines the schema that revisions table resides in
RevisionsSchema string `json:"revisionsSchema,omitempty"`
// BaselineVersion defines the baseline version of the database on the first migration.
Baseline string `json:"baseline,omitempty"`
// ExecOrder controls how Atlas computes and executes pending migration files to the database.
// +kubebuilder:default=linear
ExecOrder MigrateExecOrder `json:"execOrder,omitempty"`
// ProtectedFlows defines the protected flows of a deployment.
ProtectedFlows *ProtectFlows `json:"protectedFlows,omitempty"`
// Policy defines the policies to apply when migrating the database.
// +optional
Policy *MigrationPolicy `json:"policy,omitempty"`
// BackoffLimit is the number of retries on error.
// +kubebuilder:default=20
BackoffLimit int `json:"backoffLimit,omitempty"`
}
AtlasMigrationSpec defines the desired state of AtlasMigration
func (*AtlasMigrationSpec) DeepCopy ¶ added in v0.1.7
func (in *AtlasMigrationSpec) DeepCopy() *AtlasMigrationSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasMigrationSpec.
func (*AtlasMigrationSpec) DeepCopyInto ¶ added in v0.1.7
func (in *AtlasMigrationSpec) DeepCopyInto(out *AtlasMigrationSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type AtlasMigrationStatus ¶ added in v0.1.7
type AtlasMigrationStatus struct {
// ObservedGeneration is the generation last processed by the controller.
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// Conditions represent the latest available observations of an object's state.
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
// LastAppliedVersion is the version of the most recent successful versioned migration.
// +optional
LastAppliedVersion string `json:"lastAppliedVersion,omitempty"`
// LastDeploymentURL is the Deployment URL of the most recent successful versioned migration.
// +optional
LastDeploymentURL string `json:"lastDeploymentUrl,omitempty"`
// ApprovalURL is the URL to approve the migration.
// +optional
ApprovalURL string `json:"approvalUrl,omitempty"`
// ObservedHash is the hash of the most recent successful versioned migration.
// +optional
ObservedHash string `json:"observed_hash"`
// LastApplied is the unix timestamp of the most recent successful versioned migration.
// +optional
LastApplied int64 `json:"lastApplied"`
// Failed is the number of times the migration has failed.
// +optional
// +kubebuilder:default=0
Failed int `json:"failed"`
}
AtlasMigrationStatus defines the observed state of AtlasMigration
func (*AtlasMigrationStatus) DeepCopy ¶ added in v0.1.7
func (in *AtlasMigrationStatus) DeepCopy() *AtlasMigrationStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasMigrationStatus.
func (*AtlasMigrationStatus) DeepCopyInto ¶ added in v0.1.7
func (in *AtlasMigrationStatus) DeepCopyInto(out *AtlasMigrationStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type AtlasSchema ¶
type AtlasSchema struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
Spec AtlasSchemaSpec `json:"spec,omitempty"`
//+kubebuilder:default={"observedGeneration":-1}
Status AtlasSchemaStatus `json:"status,omitempty"`
}
+kubebuilder:object:root=true +kubebuilder:subresource:status
AtlasSchema is the Schema for the atlasschemas API +kubebuilder:printcolumn:name="Ready",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].status` +kubebuilder:printcolumn:name="Reason",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].reason`
func (*AtlasSchema) DeepCopy ¶
func (in *AtlasSchema) DeepCopy() *AtlasSchema
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSchema.
func (*AtlasSchema) DeepCopyInto ¶
func (in *AtlasSchema) DeepCopyInto(out *AtlasSchema)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasSchema) DeepCopyObject ¶
func (in *AtlasSchema) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*AtlasSchema) GetPrewarmDevDB ¶ added in v0.8.0
func (s *AtlasSchema) GetPrewarmDevDB() *bool
GetPrewarmDevDB returns the per-resource dev DB prewarm override, if set.
func (*AtlasSchema) IncrementFailed ¶ added in v0.7.3
func (sc *AtlasSchema) IncrementFailed()
IncrementFailed increments the failed count.
func (*AtlasSchema) IsExceedBackoffLimit ¶ added in v0.7.3
func (sc *AtlasSchema) IsExceedBackoffLimit() bool
IsExceedBackoffLimit returns true if the failed count exceeds the backoff limit.
func (*AtlasSchema) IsHashModified ¶ added in v0.3.1
func (sc *AtlasSchema) IsHashModified(hash string) bool
IsHashModified returns true if the hash is different from the observed hash.
func (*AtlasSchema) IsReady ¶ added in v0.3.1
func (m *AtlasSchema) IsReady() bool
IsReady returns true if the ready condition is true.
func (*AtlasSchema) NamespacedName ¶ added in v0.1.7
func (s *AtlasSchema) NamespacedName() types.NamespacedName
NamespacedName returns the namespaced name of the object.
func (*AtlasSchema) ResetFailed ¶ added in v0.7.3
func (sc *AtlasSchema) ResetFailed()
ResetFailed resets the failed count.
func (*AtlasSchema) SetNotReady ¶ added in v0.3.1
func (sc *AtlasSchema) SetNotReady(reason, msg string)
SetNotReady sets the Ready condition to false with the given reason and message.
func (*AtlasSchema) SetReady ¶ added in v0.3.1
func (sc *AtlasSchema) SetReady(status AtlasSchemaStatus, report any)
SetReady sets the Ready condition to true
func (*AtlasSchema) SetReconciling ¶ added in v0.7.3
func (sc *AtlasSchema) SetReconciling(message string)
SetReconciling sets the ready condition to false with the reason "Reconciling".
type AtlasSchemaList ¶
type AtlasSchemaList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []AtlasSchema `json:"items"`
}
+kubebuilder:object:root=true
AtlasSchemaList contains a list of AtlasSchema
func (*AtlasSchemaList) DeepCopy ¶
func (in *AtlasSchemaList) DeepCopy() *AtlasSchemaList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSchemaList.
func (*AtlasSchemaList) DeepCopyInto ¶
func (in *AtlasSchemaList) DeepCopyInto(out *AtlasSchemaList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasSchemaList) DeepCopyObject ¶
func (in *AtlasSchemaList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type AtlasSchemaSpec ¶
type AtlasSchemaSpec struct {
TargetSpec `json:",inline"`
ProjectConfigSpec `json:",inline"`
// Desired Schema of the target.
Schema Schema `json:"schema,omitempty"`
// Cloud defines the Atlas Cloud configuration.
Cloud Cloud `json:"cloud,omitempty"`
// +optional
// DevURL is the URL of the database to use for normalization and calculations.
// If not specified, the operator will spin up a temporary database container to use for these operations.
DevURL string `json:"devURL"`
// DevURLFrom is a reference to a secret containing the URL of the database to use for normalization and calculations.
// +optional
DevURLFrom Secret `json:"devURLFrom,omitempty"`
// DevDB configures the dev database pod used for normalization and calculations.
// If spec is omitted, a default pod spec is created based on the target database driver.
// When a custom pod spec is provided, devURL must be defined as well.
// +optional
DevDB *DevDB `json:"devDB,omitempty"`
// PrewarmDevDB controls whether the automatically managed dev DB should be kept warm after reconciliation.
// If not specified, the operator-wide default is used.
// +optional
PrewarmDevDB *bool `json:"prewarmDevDB,omitempty"`
// Exclude a list of glob patterns used to filter existing resources being taken into account.
Exclude []string `json:"exclude,omitempty"`
// TxMode defines the transaction mode to use when applying the schema.
// +kubebuilder:default=file
TxMode TransactionMode `json:"txMode,omitempty"`
// Policy defines the policies to apply when managing the schema change lifecycle.
Policy *Policy `json:"policy,omitempty"`
// The names of the schemas (named databases) on the target database to be managed.
Schemas []string `json:"schemas,omitempty"`
// BackoffLimit is the number of retries on error.
// +kubebuilder:default=20
BackoffLimit int `json:"backoffLimit,omitempty"`
}
AtlasSchemaSpec defines the desired state of AtlasSchema
func (*AtlasSchemaSpec) DeepCopy ¶
func (in *AtlasSchemaSpec) DeepCopy() *AtlasSchemaSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSchemaSpec.
func (*AtlasSchemaSpec) DeepCopyInto ¶
func (in *AtlasSchemaSpec) DeepCopyInto(out *AtlasSchemaSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type AtlasSchemaStatus ¶
type AtlasSchemaStatus struct {
// ObservedGeneration is the generation last processed by the controller.
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// Conditions represent the latest available observations of an object's state.
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
// ObservedHash is the hash of the most recently applied schema.
// +optional
ObservedHash string `json:"observed_hash"`
// LastApplied is the unix timestamp of the most recent successful schema apply operation.
// +optional
LastApplied int64 `json:"last_applied"`
// PlanURL is the URL of the schema plan to apply.
// +optional
PlanURL string `json:"planURL"`
// PlanLink is the link to the schema plan on the Atlas Cloud.
// +optional
PlanLink string `json:"planLink"`
// Failed is the number of times the schema has failed to apply.
// +optional
// +kubebuilder:default=0
Failed int `json:"failed"`
}
AtlasSchemaStatus defines the observed state of AtlasSchema
func (*AtlasSchemaStatus) DeepCopy ¶
func (in *AtlasSchemaStatus) DeepCopy() *AtlasSchemaStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSchemaStatus.
func (*AtlasSchemaStatus) DeepCopyInto ¶
func (in *AtlasSchemaStatus) DeepCopyInto(out *AtlasSchemaStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type AtlasSecurityReport ¶ added in v0.8.0
type AtlasSecurityReport struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
// +required
Report SecurityReport `json:"report,omitempty"`
}
+kubebuilder:object:root=true
AtlasSecurityReport holds the findings of the most recent successful scan of an AtlasSecurityScan. It is owned by the scan, replaced on every successful scan, and readable by its own RBAC rather than by everyone who can read the scan. +kubebuilder:printcolumn:name="Findings",type=integer,JSONPath=`.report.summary.total` +kubebuilder:printcolumn:name="Highest",type=string,JSONPath=`.report.summary.highestLevel` +kubebuilder:printcolumn:name="Scanned",type=date,JSONPath=`.report.completionTime` +kubebuilder:printcolumn:name="Age",type=date,JSONPath=`.metadata.creationTimestamp`
func (*AtlasSecurityReport) DeepCopy ¶ added in v0.8.0
func (in *AtlasSecurityReport) DeepCopy() *AtlasSecurityReport
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityReport.
func (*AtlasSecurityReport) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasSecurityReport) DeepCopyInto(out *AtlasSecurityReport)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasSecurityReport) DeepCopyObject ¶ added in v0.8.0
func (in *AtlasSecurityReport) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type AtlasSecurityReportList ¶ added in v0.8.0
type AtlasSecurityReportList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []AtlasSecurityReport `json:"items"`
}
+kubebuilder:object:root=true
AtlasSecurityReportList contains a list of AtlasSecurityReport
func (*AtlasSecurityReportList) DeepCopy ¶ added in v0.8.0
func (in *AtlasSecurityReportList) DeepCopy() *AtlasSecurityReportList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityReportList.
func (*AtlasSecurityReportList) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasSecurityReportList) DeepCopyInto(out *AtlasSecurityReportList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasSecurityReportList) DeepCopyObject ¶ added in v0.8.0
func (in *AtlasSecurityReportList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type AtlasSecurityScan ¶ added in v0.8.0
type AtlasSecurityScan struct {
metav1.TypeMeta `json:",inline"`
metav1.ObjectMeta `json:"metadata,omitempty"`
// +required
Spec AtlasSecurityScanSpec `json:"spec,omitempty"`
//+kubebuilder:default={"observedGeneration":-1}
Status AtlasSecurityScanStatus `json:"status,omitempty"`
}
+kubebuilder:object:root=true +kubebuilder:subresource:status
AtlasSecurityScan scans a database with `atlas security scan` on a schedule and after the referenced AtlasSchema/AtlasMigration resources apply changes to it. +kubebuilder:printcolumn:name="Ready",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].status` +kubebuilder:printcolumn:name="Reason",type=string,JSONPath=`.status.conditions[?(@.type=="Ready")].reason` +kubebuilder:printcolumn:name="Compliant",type=string,JSONPath=`.status.conditions[?(@.type=="Compliant")].status` +kubebuilder:printcolumn:name="Findings",type=integer,JSONPath=`.status.summary.total` +kubebuilder:printcolumn:name="Highest",type=string,JSONPath=`.status.summary.highestLevel` +kubebuilder:printcolumn:name="Last Scan",type=date,JSONPath=`.status.lastSuccessfulTime` +kubebuilder:printcolumn:name="Next Scan",type=string,JSONPath=`.status.nextScheduleTime` +kubebuilder:printcolumn:name="Age",type=date,JSONPath=`.metadata.creationTimestamp` +kubebuilder:printcolumn:name="Trigger",type=string,JSONPath=`.status.lastScan.trigger`,priority=1 +kubebuilder:printcolumn:name="Schedule",type=string,JSONPath=`.spec.schedule`,priority=1 +kubebuilder:printcolumn:name="Suspended",type=boolean,JSONPath=`.spec.suspend`,priority=1
func (*AtlasSecurityScan) BackoffLimit ¶ added in v0.8.0
func (s *AtlasSecurityScan) BackoffLimit() int
BackoffLimit returns the retry limit, 0 for unlimited. Admission defaults an unset limit to 20; the fallback covers objects that did not go through it.
func (*AtlasSecurityScan) DeepCopy ¶ added in v0.8.0
func (in *AtlasSecurityScan) DeepCopy() *AtlasSecurityScan
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityScan.
func (*AtlasSecurityScan) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasSecurityScan) DeepCopyInto(out *AtlasSecurityScan)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasSecurityScan) DeepCopyObject ¶ added in v0.8.0
func (in *AtlasSecurityScan) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*AtlasSecurityScan) IsReady ¶ added in v0.8.0
func (s *AtlasSecurityScan) IsReady() bool
IsReady returns true if the ready condition is true.
func (*AtlasSecurityScan) IsStalled ¶ added in v0.8.0
func (s *AtlasSecurityScan) IsStalled(reason string) bool
IsStalled reports whether the resource stalled for the given reason, or for any reason when none is given.
func (*AtlasSecurityScan) IsSuspended ¶ added in v0.8.0
func (s *AtlasSecurityScan) IsSuspended() bool
IsSuspended reports whether scanning is paused.
func (*AtlasSecurityScan) MinSeverity ¶ added in v0.8.0
func (s *AtlasSecurityScan) MinSeverity() SecurityLevel
MinSeverity is the lowest level the scan reports. It is always set, so the severity the report is graded with is the one the CLI ran with.
func (*AtlasSecurityScan) SetCompliant ¶ added in v0.8.0
func (s *AtlasSecurityScan) SetCompliant(status metav1.ConditionStatus, reason, message string)
SetCompliant records the policy verdict.
func (*AtlasSecurityScan) SetFirstVisit ¶ added in v0.8.0
func (s *AtlasSecurityScan) SetFirstVisit()
SetFirstVisit writes the initial conditions. Nothing is known yet.
func (*AtlasSecurityScan) SetIdle ¶ added in v0.8.0
func (s *AtlasSecurityScan) SetIdle()
SetIdle restores the ready state when nothing is pending and the resource is not stalled, which implies a success exists for the current generation. It also clears the failures of a retry whose cause has meanwhile disappeared.
func (*AtlasSecurityScan) SetRetrying ¶ added in v0.8.0
func (s *AtlasSecurityScan) SetRetrying(reason, message string)
SetRetrying records a failed attempt that will be retried with a backoff. It deliberately leaves Stalled false: a transient failure is not a stall.
func (*AtlasSecurityScan) SetScanned ¶ added in v0.8.0
func (s *AtlasSecurityScan) SetScanned(message string)
SetScanned records a successful scan: the controller did its job and the result reflects the current spec.
func (*AtlasSecurityScan) SetScanning ¶ added in v0.8.0
func (s *AtlasSecurityScan) SetScanning()
SetScanning marks the resource as converging on its spec while a scan runs. Ready moves to Unknown only until the first success; afterwards the last result stands while a Spec-triggered re-scan runs.
func (*AtlasSecurityScan) SetStalled ¶ added in v0.8.0
func (s *AtlasSecurityScan) SetStalled(reason, message string)
SetStalled records a failure that retrying cannot fix, or exhausted retries.
func (*AtlasSecurityScan) SetSuspended ¶ added in v0.8.0
func (s *AtlasSecurityScan) SetSuspended()
SetSuspended pauses the resource. Ready and Compliant keep their last values.
func (*AtlasSecurityScan) WasSuspended ¶ added in v0.8.0
func (s *AtlasSecurityScan) WasSuspended() bool
WasSuspended reports whether the last pass left the resource suspended.
type AtlasSecurityScanList ¶ added in v0.8.0
type AtlasSecurityScanList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitempty"`
Items []AtlasSecurityScan `json:"items"`
}
+kubebuilder:object:root=true
AtlasSecurityScanList contains a list of AtlasSecurityScan
func (*AtlasSecurityScanList) DeepCopy ¶ added in v0.8.0
func (in *AtlasSecurityScanList) DeepCopy() *AtlasSecurityScanList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityScanList.
func (*AtlasSecurityScanList) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasSecurityScanList) DeepCopyInto(out *AtlasSecurityScanList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*AtlasSecurityScanList) DeepCopyObject ¶ added in v0.8.0
func (in *AtlasSecurityScanList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type AtlasSecurityScanSpec ¶ added in v0.8.0
type AtlasSecurityScanSpec struct {
TargetSpec `json:",inline"`
ProjectConfigSpec `json:",inline"`
// Cloud defines the Atlas Cloud configuration. The Security Graph requires Atlas Pro.
// +optional
Cloud Cloud `json:"cloud,omitempty"`
// Schedule is a cron expression (5 fields, or @hourly/@daily/@weekly/@monthly/@yearly) evaluated in TimeZone.
// +optional
// +kubebuilder:validation:MinLength=1
Schedule string `json:"schedule,omitempty"`
// TimeZone is the IANA name of the zone the schedule is evaluated in. Defaults to UTC.
// +optional
// +kubebuilder:default="UTC"
// +kubebuilder:validation:MinLength=1
TimeZone string `json:"timeZone,omitempty"`
// Triggers are resources in this namespace whose applies cause a scan.
// +optional
// +listType=map
// +listMapKey=kind
// +listMapKey=name
// +kubebuilder:validation:MaxItems=32
Triggers []ScanTriggerRef `json:"triggers,omitempty"`
// Suspend pauses scanning. Everything that becomes due while suspended is covered by one scan on resume.
// +optional
Suspend *bool `json:"suspend,omitempty"`
// Policy controls which findings are reported and which make the database non-compliant.
// +optional
Policy *ScanPolicy `json:"policy,omitempty"`
// BackoffLimit is the number of retries of a failed scan before the resource stalls. 0 means unlimited.
// +kubebuilder:default=20
// +kubebuilder:validation:Minimum=0
BackoffLimit *int `json:"backoffLimit,omitempty"`
}
AtlasSecurityScanSpec defines the desired state of AtlasSecurityScan. +kubebuilder:validation:XValidation:rule="(has(self.schedule) && self.schedule != ”) || (has(self.triggers) && size(self.triggers) > 0)",message="at least one of spec.schedule or spec.triggers must be set" +kubebuilder:validation:XValidation:rule="!has(self.schedule) || !(self.schedule.startsWith('TZ=') || self.schedule.startsWith('CRON_TZ='))",message="use spec.timeZone instead of a TZ=/CRON_TZ= prefix" +kubebuilder:validation:XValidation:rule="!has(self.schedule) || !self.schedule.startsWith('@every')",message="@every is interval-based and drifts; use a cron expression or @hourly/@daily/@weekly/@monthly/@yearly" +kubebuilder:validation:XValidation:rule="!has(self.timeZone) || self.timeZone != 'Local'",message="timeZone must be an IANA zone name" +kubebuilder:validation:XValidation:rule="!has(self.cloud) || !has(self.cloud.repo)",message="cloud.repo is not used by security scans"
func (*AtlasSecurityScanSpec) DeepCopy ¶ added in v0.8.0
func (in *AtlasSecurityScanSpec) DeepCopy() *AtlasSecurityScanSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityScanSpec.
func (*AtlasSecurityScanSpec) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasSecurityScanSpec) DeepCopyInto(out *AtlasSecurityScanSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type AtlasSecurityScanStatus ¶ added in v0.8.0
type AtlasSecurityScanStatus struct {
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// +optional
// +listType=map
// +listMapKey=type
Conditions []metav1.Condition `json:"conditions,omitempty"`
// LastScan describes the most recent attempt, whether it succeeded or failed.
// +optional
LastScan *ScanAttempt `json:"lastScan,omitempty"`
// LastSuccessfulTime is when the most recent successful scan completed. Summary, report and the
// Compliant condition describe that scan.
// +optional
LastSuccessfulTime *metav1.Time `json:"lastSuccessfulTime,omitempty"`
// LastScheduleTime is the latest schedule slot a successful scan covered. A scan that is still
// running when a slot passes covers it, so this can be later than the start of that scan.
// +optional
LastScheduleTime *metav1.Time `json:"lastScheduleTime,omitempty"`
// NextScheduleTime is the slot after LastScheduleTime. Omitted while suspended,
// on an invalid spec, or without a schedule. It advances only when a scan
// succeeds, so it stays at a missed slot until the catch-up completes.
// +optional
NextScheduleTime *metav1.Time `json:"nextScheduleTime,omitempty"`
// LastHandledScanRequest is the scan-requested-at annotation value whose scan completed successfully.
// +optional
LastHandledScanRequest string `json:"lastHandledScanRequest,omitempty"`
// Triggers holds the revision of each trigger observed when the last successful scan started.
// +optional
// +listType=map
// +listMapKey=kind
// +listMapKey=name
Triggers []ObservedTrigger `json:"triggers,omitempty"`
// ActiveWaivers lists the waiver ids that were in force when the last successful scan started.
// +optional
// +listType=set
ActiveWaivers []string `json:"activeWaivers,omitempty"`
// Summary of the last successful scan.
// +optional
Summary *ScanSummary `json:"summary,omitempty"`
// ReportRef names the AtlasSecurityReport holding the findings of the last successful scan.
// +optional
ReportRef *corev1.LocalObjectReference `json:"reportRef,omitempty"`
// Failed is the number of consecutive failed attempts since the last success.
// +optional
// +kubebuilder:default=0
Failed int `json:"failed"`
}
AtlasSecurityScanStatus defines the observed state of AtlasSecurityScan.
func (*AtlasSecurityScanStatus) DeepCopy ¶ added in v0.8.0
func (in *AtlasSecurityScanStatus) DeepCopy() *AtlasSecurityScanStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new AtlasSecurityScanStatus.
func (*AtlasSecurityScanStatus) DeepCopyInto ¶ added in v0.8.0
func (in *AtlasSecurityScanStatus) DeepCopyInto(out *AtlasSecurityScanStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type CheckConfig ¶
type CheckConfig struct {
Error bool `json:"error,omitempty"`
}
CheckConfig defines the configuration of a linting check.
func (*CheckConfig) DeepCopy ¶
func (in *CheckConfig) DeepCopy() *CheckConfig
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CheckConfig.
func (*CheckConfig) DeepCopyInto ¶
func (in *CheckConfig) DeepCopyInto(out *CheckConfig)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Cloud ¶ added in v0.1.7
type Cloud struct {
// TokenFrom defines the reference to the secret key that contains the Atlas Cloud Token.
TokenFrom TokenFrom `json:"tokenFrom,omitempty"`
// Repo is the name of repository on the Atlas Cloud.
Repo string `json:"repo,omitempty"`
}
Cloud defines the Atlas Cloud configuration.
func (*Cloud) DeepCopy ¶ added in v0.1.7
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Cloud.
func (*Cloud) DeepCopyInto ¶ added in v0.1.7
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type CloudV0 ¶ added in v0.6.0
type CloudV0 struct {
URL string `json:"url,omitempty"`
TokenFrom TokenFrom `json:"tokenFrom,omitempty"`
Project string `json:"project,omitempty"`
}
func (*CloudV0) DeepCopy ¶ added in v0.6.0
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CloudV0.
func (*CloudV0) DeepCopyInto ¶ added in v0.6.0
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ConcurrentIndex ¶ added in v0.4.3
type ConcurrentIndex struct {
// +optional
Create bool `json:"create,omitempty"`
// +optional
Drop bool `json:"drop,omitempty"`
}
func (*ConcurrentIndex) DeepCopy ¶ added in v0.4.3
func (in *ConcurrentIndex) DeepCopy() *ConcurrentIndex
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ConcurrentIndex.
func (*ConcurrentIndex) DeepCopyInto ¶ added in v0.4.3
func (in *ConcurrentIndex) DeepCopyInto(out *ConcurrentIndex)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Credentials ¶ added in v0.2.2
type Credentials struct {
Scheme string `json:"scheme,omitempty"`
User string `json:"user,omitempty"`
UserFrom Secret `json:"userFrom,omitempty"`
Password string `json:"password,omitempty"`
PasswordFrom Secret `json:"passwordFrom,omitempty"`
Host string `json:"host,omitempty"`
HostFrom Secret `json:"hostFrom,omitempty"`
Port int `json:"port,omitempty"`
Database string `json:"database,omitempty"`
Parameters map[string]string `json:"parameters,omitempty"`
}
Credentials defines the credentials to use when connecting to the database.
func (*Credentials) DeepCopy ¶ added in v0.2.2
func (in *Credentials) DeepCopy() *Credentials
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Credentials.
func (*Credentials) DeepCopyInto ¶ added in v0.2.2
func (in *Credentials) DeepCopyInto(out *Credentials)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type DeploymentFlow ¶ added in v0.5.0
type DeploymentFlow struct {
// Allow allows the flow to be executed.
// +kubebuilder:default=false
Allow bool `json:"allow,omitempty"`
// AutoApprove allows the flow to be automatically approved.
// +kubebuilder:default=false
AutoApprove bool `json:"autoApprove,omitempty"`
}
DeploymentFlow defines the flow of a deployment.
func (*DeploymentFlow) DeepCopy ¶ added in v0.5.0
func (in *DeploymentFlow) DeepCopy() *DeploymentFlow
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DeploymentFlow.
func (*DeploymentFlow) DeepCopyInto ¶ added in v0.5.0
func (in *DeploymentFlow) DeepCopyInto(out *DeploymentFlow)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type DevDB ¶ added in v0.7.11
type DevDB struct {
// Metadata contains labels and annotations applied when creating the dev database pod template.
// Operator-managed labels and the atlasgo.io/conntmpl annotation take precedence.
// +optional
Metadata *DevDBMetadata `json:"metadata,omitempty"`
// Spec overrides the automatically generated pod spec. When set, devURL is required.
// +optional
Spec *corev1.PodSpec `json:"spec,omitempty"`
}
func (*DevDB) DeepCopy ¶ added in v0.7.11
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DevDB.
func (*DevDB) DeepCopyInto ¶ added in v0.7.11
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type DevDBMetadata ¶ added in v0.7.52
type DevDBMetadata struct {
// Labels are additional labels for the pod template. They do not affect the Deployment selector.
// +optional
Labels map[string]string `json:"labels,omitempty"`
// Annotations are additional annotations for the pod template.
// +optional
Annotations map[string]string `json:"annotations,omitempty"`
}
DevDBMetadata defines additional metadata for dev database pods.
func (*DevDBMetadata) DeepCopy ¶ added in v0.7.52
func (in *DevDBMetadata) DeepCopy() *DevDBMetadata
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DevDBMetadata.
func (*DevDBMetadata) DeepCopyInto ¶ added in v0.7.52
func (in *DevDBMetadata) DeepCopyInto(out *DevDBMetadata)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Diff ¶
type Diff struct {
ConcurrentIndex *ConcurrentIndex `json:"concurrent_index,omitempty"`
Skip *SkipChanges `json:"skip,omitempty"`
}
Diff defines the diff policies to apply when planning schema changes.
func (*Diff) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Diff.
func (*Diff) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Dir ¶ added in v0.1.7
type Dir struct {
// ConfigMapRef defines the configmap to use for migrations
ConfigMapRef *corev1.LocalObjectReference `json:"configMapRef,omitempty"`
// Remote defines the Atlas Cloud migration directory.
Remote Remote `json:"remote,omitempty"`
// Local defines the local migration directory.
Local map[string]string `json:"local,omitempty"`
}
Dir defines the place where migrations are stored.
func (*Dir) DeepCopy ¶ added in v0.1.7
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Dir.
func (*Dir) DeepCopyInto ¶ added in v0.1.7
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type DriftAction ¶ added in v0.8.0
type DriftAction string
DriftAction controls how the check reports detected drift. +kubebuilder:validation:Enum=Report;Fail
const ( // DriftActionReport reports the drift on the Drifted condition only. DriftActionReport DriftAction = "Report" // DriftActionFail also marks the check not ready and stalled. DriftActionFail DriftAction = "Fail" )
DriftAction values.
type DriftCheckTarget ¶ added in v0.8.0
type DriftCheckTarget struct {
// Name of the AtlasMigration in the same namespace.
// +kubebuilder:validation:MinLength=1
Name string `json:"name"`
}
DriftCheckTarget references the resource to check.
func (*DriftCheckTarget) DeepCopy ¶ added in v0.8.0
func (in *DriftCheckTarget) DeepCopy() *DriftCheckTarget
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DriftCheckTarget.
func (*DriftCheckTarget) DeepCopyInto ¶ added in v0.8.0
func (in *DriftCheckTarget) DeepCopyInto(out *DriftCheckTarget)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type DriftOnError ¶ added in v0.7.52
type DriftOnError string
DriftOnError controls what the drift check does when it finds drift. +kubebuilder:validation:Enum=FAIL;CONTINUE
const ( // DriftOnErrorFail stops the migration when drift is found. DriftOnErrorFail DriftOnError = "FAIL" // DriftOnErrorContinue applies the migration anyway and records the // drift in the Atlas Registry deployment log. DriftOnErrorContinue DriftOnError = "CONTINUE" )
DriftOnError values.
type DriftPolicy ¶ added in v0.7.52
type DriftPolicy struct {
// OnError controls what happens when drift is found (default: FAIL).
// FAIL stops the migration and reports the drift on the Ready condition.
// CONTINUE applies it anyway and records the drift only in the Atlas
// +optional
OnError DriftOnError `json:"onError,omitempty"`
// Exclude lists glob patterns of database objects to ignore, e.g. "public.audit_*"
// or "*[type=extension]". It replaces the env-level exclude list.
// The revisions table is always excluded.
// +optional
Exclude []string `json:"exclude,omitempty"`
}
DriftPolicy configures the pre-apply drift check. It adds a check "migrate_apply" { drift { ... } } block to the generated atlas.hcl.
func (*DriftPolicy) AsBlock ¶ added in v0.7.52
func (d *DriftPolicy) AsBlock() *hclwrite.Block
AsBlock returns the check "migrate_apply" block for this policy.
func (*DriftPolicy) DeepCopy ¶ added in v0.7.52
func (in *DriftPolicy) DeepCopy() *DriftPolicy
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DriftPolicy.
func (*DriftPolicy) DeepCopyInto ¶ added in v0.7.52
func (in *DriftPolicy) DeepCopyInto(out *DriftPolicy)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type DriftSummary ¶ added in v0.8.0
type DriftSummary struct {
// Total number of drifted objects.
Total int `json:"total"`
// Number of objects found only in the database.
// +optional
Extra int `json:"extra,omitempty"`
// Number of objects found only in the expected state.
// +optional
Missing int `json:"missing,omitempty"`
// Number of objects that exist in both states but differ.
// +optional
Modified int `json:"modified,omitempty"`
// Drifted objects by type, e.g. {"table": 2, "role": 1}.
// +optional
Types map[string]int `json:"types,omitempty"`
}
DriftSummary counts the drifted objects by kind and by object type.
func (*DriftSummary) DeepCopy ¶ added in v0.8.0
func (in *DriftSummary) DeepCopy() *DriftSummary
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DriftSummary.
func (*DriftSummary) DeepCopyInto ¶ added in v0.8.0
func (in *DriftSummary) DeepCopyInto(out *DriftSummary)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Driver ¶ added in v0.6.0
type Driver string
Driver defines the database driver.
const ( DriverClickHouse Driver = "clickhouse" DriverCockroachDB Driver = "crdb" DriverDatabricks Driver = "databricks" DriverDSQL Driver = "dsql" DriverMariaDB Driver = "mariadb" DriverMySQL Driver = "mysql" DriverOracle Driver = "oracle" DriverPostgres Driver = "postgres" DriverRedshift Driver = "redshift" DriverSnowflake Driver = "snowflake" DriverSpanner Driver = "spanner" DriverSQLite Driver = "sqlite" DriverSQLServer Driver = "sqlserver" DriverYSQL Driver = "ysql" )
func DriverBySchema ¶ added in v0.5.0
DriverBySchema returns the driver from the given schema. it remove the schema modifier if present. e.g. mysql+unix -> mysql it also handles aliases. e.g. mariadb -> mysql
func (Driver) SchemaBound ¶ added in v0.6.0
SchemaBound returns true if the driver requires a schema.
type GradedPolicy ¶ added in v0.8.0
type GradedPolicy struct {
MinSeverity SecurityLevel `json:"minSeverity"`
FailOn *SecurityLevel `json:"failOn,omitempty"`
}
GradedPolicy is the policy a report was graded with (waivers appear on the findings they apply to).
func (*GradedPolicy) DeepCopy ¶ added in v0.8.0
func (in *GradedPolicy) DeepCopy() *GradedPolicy
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new GradedPolicy.
func (*GradedPolicy) DeepCopyInto ¶ added in v0.8.0
func (in *GradedPolicy) DeepCopyInto(out *GradedPolicy)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type IgnoredVulnerability ¶ added in v0.8.0
type IgnoredVulnerability struct {
// ID of the vulnerability, e.g. CVE-2024-10977.
// +kubebuilder:validation:Pattern=`^[A-Za-z0-9][A-Za-z0-9._-]{2,63}$`
ID string `json:"id"`
Waiver `json:",inline"`
}
IgnoredVulnerability is a waiver for one vulnerability.
func (*IgnoredVulnerability) DeepCopy ¶ added in v0.8.0
func (in *IgnoredVulnerability) DeepCopy() *IgnoredVulnerability
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new IgnoredVulnerability.
func (*IgnoredVulnerability) DeepCopyInto ¶ added in v0.8.0
func (in *IgnoredVulnerability) DeepCopyInto(out *IgnoredVulnerability)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type LevelCount ¶ added in v0.8.0
type LevelCount struct {
Level SecurityLevel `json:"level"`
Count int32 `json:"count"`
}
LevelCount is the number of non-waived findings at one level.
func (*LevelCount) DeepCopy ¶ added in v0.8.0
func (in *LevelCount) DeepCopy() *LevelCount
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new LevelCount.
func (*LevelCount) DeepCopyInto ¶ added in v0.8.0
func (in *LevelCount) DeepCopyInto(out *LevelCount)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Lint ¶
type Lint struct {
Destructive *CheckConfig `json:"destructive,omitempty"`
// Review defines the review policy to apply after linting the schema changes (default: "ERROR").
// Atlas Cloud login is required.
Review LintReview `json:"review,omitempty"`
}
Lint defines the linting policies to apply before applying the schema.
func (*Lint) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Lint.
func (*Lint) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type LintReview ¶ added in v0.6.0
type LintReview string
LintReview defines the review policies to apply after linting the schema. +kubebuilder:validation:Enum=ALWAYS;WARNING;ERROR
const ( LintReviewAlways LintReview = "ALWAYS" LintReviewWarning LintReview = "WARNING" LintReviewError LintReview = "ERROR" )
LintReview values.
type MigrateExecOrder ¶ added in v0.3.7
type MigrateExecOrder string
ExecOrder controls how Atlas computes and executes pending migration files to the database. +kubebuilder:validation:Enum=linear;linear-skip;non-linear
type MigrationPolicy ¶ added in v0.7.52
type MigrationPolicy struct {
// Drift enables the pre-apply drift check
// Before applying pending migrations, Atlas compares the database with the
// state the Atlas Registry holds for the current version. The migration
// directory must be on the registry: set spec.dir.remote, or migration.repo.name
// in spec.config. See https://atlasgo.io/versioned/drift-detection.
// +optional
Drift *DriftPolicy `json:"drift,omitempty"`
}
MigrationPolicy defines the policies to apply when migrating the database.
func (*MigrationPolicy) DeepCopy ¶ added in v0.7.52
func (in *MigrationPolicy) DeepCopy() *MigrationPolicy
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MigrationPolicy.
func (*MigrationPolicy) DeepCopyInto ¶ added in v0.7.52
func (in *MigrationPolicy) DeepCopyInto(out *MigrationPolicy)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*MigrationPolicy) HasDrift ¶ added in v0.7.52
func (p *MigrationPolicy) HasDrift() bool
HasDrift reports whether the policy enables the pre-apply drift check.
type ObservedTrigger ¶ added in v0.8.0
type ObservedTrigger struct {
Kind ScanTriggerKind `json:"kind"`
Name string `json:"name"`
UID types.UID `json:"uid"`
Revision string `json:"revision"`
}
ObservedTrigger is the revision of a trigger when a scan started.
func (*ObservedTrigger) DeepCopy ¶ added in v0.8.0
func (in *ObservedTrigger) DeepCopy() *ObservedTrigger
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ObservedTrigger.
func (*ObservedTrigger) DeepCopyInto ¶ added in v0.8.0
func (in *ObservedTrigger) DeepCopyInto(out *ObservedTrigger)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Policy ¶
Policy defines the policies to apply when managing the schema change lifecycle.
func (*Policy) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Policy.
func (*Policy) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*Policy) HasLintDestructive ¶ added in v0.7.1
func (*Policy) HasLintReview ¶ added in v0.7.1
type ProjectConfigSpec ¶ added in v0.7.0
type ProjectConfigSpec struct {
// Config defines the project configuration.
// Should be a valid YAML string.
Config string `json:"config,omitempty"`
// ConfigFrom defines the reference to the secret key that contains the project configuration.
ConfigFrom Secret `json:"configFrom,omitempty"`
// EnvName defines the environment name that defined in the project configuration.
// If not defined, the default environment "k8s" will be used.
EnvName string `json:"envName,omitempty"`
// Vars defines the input variables for the project configuration.
Vars []Variable `json:"vars,omitempty"`
}
ProjectConfigSpec defines the project configuration.
func (*ProjectConfigSpec) DeepCopy ¶ added in v0.7.0
func (in *ProjectConfigSpec) DeepCopy() *ProjectConfigSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ProjectConfigSpec.
func (*ProjectConfigSpec) DeepCopyInto ¶ added in v0.7.0
func (in *ProjectConfigSpec) DeepCopyInto(out *ProjectConfigSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ProtectFlows ¶ added in v0.5.0
type ProtectFlows struct {
MigrateDown *DeploymentFlow `json:"migrateDown,omitempty"`
}
ProtectedFlows defines the protected flows of a deployment.
func (*ProtectFlows) DeepCopy ¶ added in v0.5.0
func (in *ProtectFlows) DeepCopy() *ProtectFlows
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ProtectFlows.
func (*ProtectFlows) DeepCopyInto ¶ added in v0.5.0
func (in *ProtectFlows) DeepCopyInto(out *ProtectFlows)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Remote ¶ added in v0.1.7
Remote defines the Atlas Cloud directory migration.
func (*Remote) DeepCopy ¶ added in v0.1.7
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Remote.
func (*Remote) DeepCopyInto ¶ added in v0.1.7
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ReportedVulnerability ¶ added in v0.8.0
type ReportedVulnerability struct {
ID string `json:"id"`
Extension string `json:"extension"`
Version string `json:"version,omitempty"`
Level SecurityLevel `json:"level"`
CVSSSeverity string `json:"cvssSeverity,omitempty"`
Title string `json:"title,omitempty"`
Description string `json:"description,omitempty"`
Suggestion string `json:"suggestion,omitempty"`
// Waiver is set when the finding is ignored by the policy.
// +optional
Waiver *Waiver `json:"waiver,omitempty"`
}
ReportedVulnerability is one finding of a scan.
func (*ReportedVulnerability) DeepCopy ¶ added in v0.8.0
func (in *ReportedVulnerability) DeepCopy() *ReportedVulnerability
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ReportedVulnerability.
func (*ReportedVulnerability) DeepCopyInto ¶ added in v0.8.0
func (in *ReportedVulnerability) DeepCopyInto(out *ReportedVulnerability)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ScanAttempt ¶ added in v0.8.0
type ScanAttempt struct {
Trigger ScanTrigger `json:"trigger"`
TriggeredBy string `json:"triggeredBy,omitempty"`
StartTime metav1.Time `json:"startTime"`
CompletionTime *metav1.Time `json:"completionTime,omitempty"`
Result ScanResult `json:"result,omitempty"`
// Message is a fixed description of a failure class, never CLI or driver output.
Message string `json:"message,omitempty"`
// InputsHash identifies what was observed when the attempt started. A stalled
// resource makes one finished attempt per distinct hash.
InputsHash string `json:"inputsHash,omitempty"`
}
ScanAttempt describes one scan attempt.
func (*ScanAttempt) DeepCopy ¶ added in v0.8.0
func (in *ScanAttempt) DeepCopy() *ScanAttempt
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ScanAttempt.
func (*ScanAttempt) DeepCopyInto ¶ added in v0.8.0
func (in *ScanAttempt) DeepCopyInto(out *ScanAttempt)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ScanPolicy ¶ added in v0.8.0
type ScanPolicy struct {
// MinSeverity is the lowest level that is reported (--min-severity).
// +kubebuilder:default=NORMAL
MinSeverity SecurityLevel `json:"minSeverity,omitempty"`
// FailOn is the lowest level at which a non-waived finding makes Compliant=False. Unset: report only.
// +optional
FailOn *SecurityLevel `json:"failOn,omitempty"`
// Ignore lists vulnerabilities that do not count toward the policy. They remain in the report, marked waived.
// +optional
// +listType=map
// +listMapKey=id
// +kubebuilder:validation:MaxItems=256
Ignore []IgnoredVulnerability `json:"ignore,omitempty"`
}
ScanPolicy grades the findings of a scan. +kubebuilder:validation:XValidation:rule="!has(self.failOn) || !has(self.minSeverity) || {'NORMAL':0,'ELEVATED':1,'HIGH':2,'CRITICAL':3}[self.failOn] >= {'NORMAL':0,'ELEVATED':1,'HIGH':2,'CRITICAL':3}[self.minSeverity]",message="failOn must be at or above minSeverity"
func (*ScanPolicy) DeepCopy ¶ added in v0.8.0
func (in *ScanPolicy) DeepCopy() *ScanPolicy
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ScanPolicy.
func (*ScanPolicy) DeepCopyInto ¶ added in v0.8.0
func (in *ScanPolicy) DeepCopyInto(out *ScanPolicy)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ScanResult ¶ added in v0.8.0
type ScanResult string
ScanResult is the outcome of a scan attempt. +kubebuilder:validation:Enum=Succeeded;Failed
const ( ScanSucceeded ScanResult = "Succeeded" ScanFailed ScanResult = "Failed" )
ScanResult values.
type ScanSummary ¶ added in v0.8.0
type ScanSummary struct {
Driver string `json:"driver,omitempty"`
Extensions int32 `json:"extensions"`
Total int32 `json:"total"`
Waived int32 `json:"waived"`
// +optional
HighestLevel SecurityLevel `json:"highestLevel,omitempty"`
// +listType=map
// +listMapKey=level
Levels []LevelCount `json:"levels"`
}
ScanSummary counts the findings of a scan. Levels always lists all four, so metric series never disappear.
func (*ScanSummary) DeepCopy ¶ added in v0.8.0
func (in *ScanSummary) DeepCopy() *ScanSummary
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ScanSummary.
func (*ScanSummary) DeepCopyInto ¶ added in v0.8.0
func (in *ScanSummary) DeepCopyInto(out *ScanSummary)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ScanTrigger ¶ added in v0.8.0
type ScanTrigger string
ScanTrigger says why a scan ran. +kubebuilder:validation:Enum=Spec;Manual;Apply;Schedule;Policy
const ( TriggerSpec ScanTrigger = "Spec" TriggerManual ScanTrigger = "Manual" TriggerApply ScanTrigger = "Apply" TriggerSchedule ScanTrigger = "Schedule" TriggerPolicy ScanTrigger = "Policy" )
ScanTrigger values, in precedence order: one scan satisfies everything pending, and the label names the highest-precedence cause.
type ScanTriggerKind ¶ added in v0.8.0
type ScanTriggerKind string
ScanTriggerKind is a kind whose applies can trigger a scan. +kubebuilder:validation:Enum=AtlasSchema;AtlasMigration
const ( TriggerKindSchema ScanTriggerKind = "AtlasSchema" TriggerKindMigration ScanTriggerKind = "AtlasMigration" )
ScanTriggerKind values.
type ScanTriggerRef ¶ added in v0.8.0
type ScanTriggerRef struct {
Kind ScanTriggerKind `json:"kind"`
// +kubebuilder:validation:MinLength=1
// +kubebuilder:validation:MaxLength=253
Name string `json:"name"`
}
ScanTriggerRef references an AtlasSchema or AtlasMigration in the same namespace.
func (*ScanTriggerRef) DeepCopy ¶ added in v0.8.0
func (in *ScanTriggerRef) DeepCopy() *ScanTriggerRef
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ScanTriggerRef.
func (*ScanTriggerRef) DeepCopyInto ¶ added in v0.8.0
func (in *ScanTriggerRef) DeepCopyInto(out *ScanTriggerRef)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Schema ¶
type Schema struct {
SQL string `json:"sql,omitempty"`
HCL string `json:"hcl,omitempty"`
URL string `json:"url,omitempty"`
ConfigMapKeyRef *corev1.ConfigMapKeySelector `json:"configMapKeyRef,omitempty"`
}
Schema defines the desired state of the target database schema in plain SQL or HCL.
func (*Schema) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Schema.
func (*Schema) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Secret ¶ added in v0.3.3
type Secret struct {
// SecretKeyRef defines the secret key reference to use for the user.
SecretKeyRef *corev1.SecretKeySelector `json:"secretKeyRef,omitempty"`
}
Secret defines a secret key reference.
func (*Secret) DeepCopy ¶ added in v0.3.3
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Secret.
func (*Secret) DeepCopyInto ¶ added in v0.3.3
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type SecurityLevel ¶ added in v0.8.0
type SecurityLevel string
SecurityLevel is a Security Graph grade. Uppercase mirrors the CLI flags and atlas.hcl deliberately. +kubebuilder:validation:Enum=NORMAL;ELEVATED;HIGH;CRITICAL
const ( SecurityLevelNormal SecurityLevel = "NORMAL" SecurityLevelElevated SecurityLevel = "ELEVATED" SecurityLevelHigh SecurityLevel = "HIGH" SecurityLevelCritical SecurityLevel = "CRITICAL" )
SecurityLevel values.
func SecurityLevels ¶ added in v0.8.0
func SecurityLevels() []SecurityLevel
SecurityLevels returns the levels lowest first, as a copy the caller may modify.
type SecurityReport ¶ added in v0.8.0
type SecurityReport struct {
StartTime metav1.Time `json:"startTime"`
CompletionTime metav1.Time `json:"completionTime"`
Trigger ScanTrigger `json:"trigger"`
// ServerVersion of the database. The engine type is Summary.Driver, which the
// scan carries too, so it reads without access to the report.
ServerVersion string `json:"serverVersion,omitempty"`
Policy GradedPolicy `json:"policy"`
Summary ScanSummary `json:"summary"`
// Extensions installed in the database, by name.
// +listType=set
Extensions []string `json:"extensions,omitempty"`
// +listType=map
// +listMapKey=id
// +listMapKey=extension
Vulnerabilities []ReportedVulnerability `json:"vulnerabilities,omitempty"`
}
SecurityReport is the graded result of one scan.
func (*SecurityReport) DeepCopy ¶ added in v0.8.0
func (in *SecurityReport) DeepCopy() *SecurityReport
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecurityReport.
func (*SecurityReport) DeepCopyInto ¶ added in v0.8.0
func (in *SecurityReport) DeepCopyInto(out *SecurityReport)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type SkipChanges ¶
type SkipChanges struct {
// +optional
AddSchema bool `json:"add_schema,omitempty"`
// +optional
DropSchema bool `json:"drop_schema,omitempty"`
// +optional
ModifySchema bool `json:"modify_schema,omitempty"`
// +optional
AddTable bool `json:"add_table,omitempty"`
// +optional
DropTable bool `json:"drop_table,omitempty"`
// +optional
ModifyTable bool `json:"modify_table,omitempty"`
// +optional
AddColumn bool `json:"add_column,omitempty"`
// +optional
DropColumn bool `json:"drop_column,omitempty"`
// +optional
ModifyColumn bool `json:"modify_column,omitempty"`
// +optional
AddIndex bool `json:"add_index,omitempty"`
// +optional
DropIndex bool `json:"drop_index,omitempty"`
// +optional
ModifyIndex bool `json:"modify_index,omitempty"`
// +optional
AddForeignKey bool `json:"add_foreign_key,omitempty"`
// +optional
DropForeignKey bool `json:"drop_foreign_key,omitempty"`
// +optional
ModifyForeignKey bool `json:"modify_foreign_key,omitempty"`
}
SkipChanges represents the skip changes policy.
func (*SkipChanges) DeepCopy ¶
func (in *SkipChanges) DeepCopy() *SkipChanges
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SkipChanges.
func (*SkipChanges) DeepCopyInto ¶
func (in *SkipChanges) DeepCopyInto(out *SkipChanges)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type TargetSpec ¶ added in v0.3.1
type TargetSpec struct {
// URL of the target database schema.
URL string `json:"url,omitempty"`
// URLs may be defined as a secret key reference.
URLFrom Secret `json:"urlFrom,omitempty"`
// Credentials defines the credentials to use when connecting to the database.
// Used instead of URL or URLFrom.
Credentials Credentials `json:"credentials,omitempty"`
}
TargetSpec defines the target database to manage.
func (TargetSpec) DatabaseURL ¶ added in v0.3.1
DatabaseURL returns the database url.
func (*TargetSpec) DeepCopy ¶ added in v0.3.1
func (in *TargetSpec) DeepCopy() *TargetSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TargetSpec.
func (*TargetSpec) DeepCopyInto ¶ added in v0.3.1
func (in *TargetSpec) DeepCopyInto(out *TargetSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type TokenFrom ¶ added in v0.1.7
type TokenFrom struct {
// SecretKeyRef references to the key of a secret in the same namespace.
SecretKeyRef *corev1.SecretKeySelector `json:"secretKeyRef,omitempty"`
}
TokenFrom defines a reference to a secret key that contains the Atlas Cloud Token
func (*TokenFrom) DeepCopy ¶ added in v0.1.7
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TokenFrom.
func (*TokenFrom) DeepCopyInto ¶ added in v0.1.7
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type TransactionMode ¶ added in v0.4.3
type TransactionMode string
TransactionMode +kubebuilder:validation:Enum=file;all;none
type ValueFrom ¶ added in v0.7.0
type ValueFrom struct {
// SecretKeyRef defines the secret key reference to use for the value.
SecretKeyRef *corev1.SecretKeySelector `json:"secretKeyRef,omitempty"`
// ConfigMapKeyRef defines the configmap key reference to use for the value.
ConfigMapKeyRef *corev1.ConfigMapKeySelector `json:"configMapKeyRef,omitempty"`
}
ValueFrom defines the reference to the secret key that contains the value.
func (*ValueFrom) DeepCopy ¶ added in v0.7.0
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ValueFrom.
func (*ValueFrom) DeepCopyInto ¶ added in v0.7.0
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Variable ¶ added in v0.7.0
type Variable struct {
Key string `json:"key,omitempty"`
Value string `json:"value,omitempty"`
ValueFrom ValueFrom `json:"valueFrom,omitempty"`
}
Variables defines the reference of secret/configmap to the input variables for the project configuration.
func (*Variable) DeepCopy ¶ added in v0.7.0
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Variable.
func (*Variable) DeepCopyInto ¶ added in v0.7.0
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Waiver ¶ added in v0.8.0
type Waiver struct {
// Reason documents why the vulnerability is waived.
// +kubebuilder:validation:MinLength=1
// +kubebuilder:validation:MaxLength=1024
Reason string `json:"reason"`
// ExpirationTime is when the waiver stops applying. A scan runs when it passes.
// +optional
ExpirationTime *metav1.Time `json:"expirationTime,omitempty"`
}
Waiver documents why and until when a vulnerability is ignored.
func (*Waiver) DeepCopy ¶ added in v0.8.0
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Waiver.
func (*Waiver) DeepCopyInto ¶ added in v0.8.0
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.