v1alpha1

package
v0.1.0-latest-stable Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package v1alpha1 contains API Schema definitions for the operator v1alpha1 API group +kubebuilder:object:generate=true +groupName=operator.dpu.nvidia.com

Index

Constants

View Source
const (
	// DPUAgentIdentityTemplatesValidCondition reports that the templates parse and produce
	// serial-dependent probe values. SPIFFE ID format and trust-domain semantics are validated
	// later when the templates are rendered with real DPU and DPUDevice data.
	DPUAgentIdentityTemplatesValidCondition conditions.ConditionType = "DPUAgentIdentityTemplatesValid"
	PreUpgradeValidationReadyCondition      conditions.ConditionType = "PreUpgradeValidationReady"
	ImagePullSecretsReconciledCondition     conditions.ConditionType = "ImagePullSecretsReconciled"
	SystemComponentsReconciledCondition     conditions.ConditionType = "SystemComponentsReconciled"
	SystemComponentsReadyCondition          conditions.ConditionType = "SystemComponentsReady"
	CATrustBundleReadyCondition             conditions.ConditionType = "CATrustBundleReady"
)
View Source
const (
	// DefaultCATrustBundleConfigMapName is the default name of the ConfigMap that the DPF Operator
	// maintains with the public DPF CA certificate(s) in Self-Signed CA case.
	DefaultCATrustBundleConfigMapName = "dpf-ca-trust-bundle"
	// CATrustBundleKey is the data key in the CA trust bundle ConfigMap. A single key holding one or
	// more concatenated PEM certificates is the most portable form for both API readers and volume
	// mounts (e.g. tools that scan for *.crt files).
	CATrustBundleKey = "ca.crt"
	// CATrustBundleHashKey tracks the effective CA set by a stable hash.
	CATrustBundleHashKey = "bundle-hash"
)
View Source
const DefaultDPUAgentSPIFFEIDTemplate = "spiffe://{{ .TrustDomain }}/dpu/{{ .SerialNumber }}/process/dpu-agent"

DefaultDPUAgentSPIFFEIDTemplate is the default for both DPU Agent identity templates. This default is applied during reconciliation because the generated CRD is shipped as a Helm template, which would evaluate a kubebuilder default containing Go template delimiters.

View Source
const (
	// DefaultDPUNodeOOBBridgeName is the default out-of-band bridge name on host-trusted worker nodes.
	DefaultDPUNodeOOBBridgeName = "br-dpu"
)
View Source
const DefaultDPUServiceSPIFFEIDTemplate = "spiffe://{{ .TrustDomain }}/dpu/{{ .SerialNumber }}/service/{{ .Namespace }}/{{ .ServiceID }}"

DefaultDPUServiceSPIFFEIDTemplate is the default for both DPUService identity templates. Applied during reconciliation for the same reason as DefaultDPUAgentSPIFFEIDTemplate.

View Source
const OpenTelemetryCollectorCASecretKey = "ca.crt"

OpenTelemetryCollectorCASecretKey is the default Secret data key that holds the PEM-encoded CA certificate bundle referenced by a CASecretRef when the reference does not specify a key.

Variables

View Source
var (
	DPFOperatorConfigFinalizer = "dpu.nvidia.com/dpfoperatorconfig"
	// DPFComponentLabelKey is added on all objects created by the DPF Operator.
	DPFComponentLabelKey = "dpu.nvidia.com/component"
)
View Source
var (
	DPFOperatorConfigKind             = "DPFOperatorConfig"
	DPFOperatorConfigGroupVersionKind = GroupVersion.WithKind(DPFOperatorConfigKind)
)
View Source
var (
	// GroupVersion is group version used to register these objects
	GroupVersion = schema.GroupVersion{Group: "operator.dpu.nvidia.com", Version: "v1alpha1"}

	// SchemeBuilder is used to add go types to the GroupVersionKind scheme
	SchemeBuilder = &scheme.Builder{GroupVersion: GroupVersion}

	// AddToScheme adds the types in this group-version to the given scheme.
	AddToScheme = SchemeBuilder.AddToScheme
)

Functions

This section is empty.

Types

type BFBRegistryConfiguration

type BFBRegistryConfiguration struct {
	// Disable ensures the BFB Registry is not deployed when set to true.
	// +optional
	Disable *bool `json:"disable,omitempty"`

	// Port is the port on which the BFB Registry will listen
	// +optional
	Port *int `json:"port,omitempty"`
}

func (*BFBRegistryConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new BFBRegistryConfiguration.

func (*BFBRegistryConfiguration) DeepCopyInto

func (in *BFBRegistryConfiguration) DeepCopyInto(out *BFBRegistryConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*BFBRegistryConfiguration) Disabled

func (c *BFBRegistryConfiguration) Disabled() bool

func (*BFBRegistryConfiguration) Name

func (c *BFBRegistryConfiguration) Name() string

type BaseComponentConfig

type BaseComponentConfig struct {
	// Disable ensures the component is not deployed when set to true.
	// +optional
	Disable *bool `json:"disable,omitempty"`
}

BaseComponentConfig provides common configuration fields that can be embedded by all component configurations to reduce code duplication.

func (*BaseComponentConfig) DeepCopy

func (in *BaseComponentConfig) DeepCopy() *BaseComponentConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new BaseComponentConfig.

func (*BaseComponentConfig) DeepCopyInto

func (in *BaseComponentConfig) DeepCopyInto(out *BaseComponentConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*BaseComponentConfig) Disabled

func (b *BaseComponentConfig) Disabled() bool

Disabled returns whether the component is disabled

type BaseControllerConfig

type BaseControllerConfig struct {
	// Replicas is the number of replicas for the controller deployment.
	// Used for High Availability via leader election.
	// +kubebuilder:validation:Minimum=1
	// +kubebuilder:validation:Maximum=3
	// +kubebuilder:default=2
	// +optional
	Replicas *int32 `json:"replicas,omitempty"`
}

BaseControllerConfig provides common configuration fields that can be embedded by all controller configurations to reduce code duplication.

func (*BaseControllerConfig) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new BaseControllerConfig.

func (*BaseControllerConfig) DeepCopyInto

func (in *BaseControllerConfig) DeepCopyInto(out *BaseControllerConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*BaseControllerConfig) SetReplicas

func (b *BaseControllerConfig) SetReplicas(replicas *int32)

SetReplicas sets the desired replica count for the controller deployment.

type CNIInstallerConfiguration

type CNIInstallerConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Installer contains the configuration for the CNI-Installer component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Installer *DefaultOverridesConfiguration `json:"installer,omitempty"`
}

func (*CNIInstallerConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CNIInstallerConfiguration.

func (*CNIInstallerConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*CNIInstallerConfiguration) GetImages

func (c *CNIInstallerConfiguration) GetImages() map[ContainerName]*string

GetImages returns a map of container names to their images

func (*CNIInstallerConfiguration) GetResources

func (*CNIInstallerConfiguration) Name

type ComponentConfigurable

type ComponentConfigurable interface {
	Name() string
	Disabled() bool
}

ComponentConfigurable defines the shared config for all components deployed by the DPF Operator. +kubebuilder:object:generate=false

type ComponentName

type ComponentName string
var (
	ProvisioningControllerName          ComponentName = "provisioning-controller"
	DPUServiceControllerName            ComponentName = "dpuservice-controller"
	ServiceSetControllerName            ComponentName = "servicechainset-controller"
	ServiceChainSetCRDsName             ComponentName = "servicechainset-rbac-and-crds"
	DPUDetectorName                     ComponentName = "dpudetector"
	FlannelName                         ComponentName = "flannel"
	MultusName                          ComponentName = "multus"
	SRIOVDevicePluginName               ComponentName = "sriov-device-plugin"
	OVSCNIName                          ComponentName = "ovs-cni"
	NVIPAMControllerName                ComponentName = "nvidia-k8s-ipam"
	NVIPAMNodeName                      ComponentName = "nvidia-k8s-ipam-node"
	SFCControllerName                   ComponentName = "sfc-controller"
	KamajiClusterManagerName            ComponentName = "kamaji-cluster-manager"
	StaticClusterManagerName            ComponentName = "static-cluster-manager"
	BFBRegistryName                     ComponentName = "bfb-registry"
	CNIInstallerName                    ComponentName = "cni-installer"
	NodeSRIOVDevicePluginControllerName ComponentName = "nodesriovdeviceplugin-controller"
	KubeStateMetricsName                ComponentName = "kube-state-metrics"
	KubeStateMetricsRBACName            ComponentName = "kube-state-metrics-rbac"
	DPUMonitoringName                   ComponentName = "dpu-monitoring"
	NodeProblemDetectorName             ComponentName = "node-problem-detector"
	OpenTelemetryCollectorName          ComponentName = "opentelemetry-collector"
	PLDMUnpackContainerName             ComponentName = "pldmunpack"
	KataContainersName                  ComponentName = "kata-containers"
	SPIFFECSIDriverName                 ComponentName = "spiffe-csi-driver"
	VaultKMSName                        ComponentName = "vault-kms"
	SpireAgentRBACName                  ComponentName = "spire-agent-rbac"
	CoreDNSName                         ComponentName = "coredns"
	CoreDNSRBACName                     ComponentName = "coredns-rbac"
)

func (ComponentName) String

func (c ComponentName) String() string

func (ComponentName) WithContainer

func (c ComponentName) WithContainer(cName ContainerName) string

type ConfigMapKeyRef

type ConfigMapKeyRef struct {
	// Name is the name of the ConfigMap.
	// +kubebuilder:validation:MinLength=1
	// +required
	Name string `json:"name,omitempty"`

	// Key is the key within the ConfigMap data to select.
	// +kubebuilder:validation:MinLength=1
	// +required
	Key string `json:"key,omitempty"`
}

ConfigMapKeyRef selects a single key from a ConfigMap living in the same namespace as the DPFOperatorConfig.

func (*ConfigMapKeyRef) DeepCopy

func (in *ConfigMapKeyRef) DeepCopy() *ConfigMapKeyRef

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ConfigMapKeyRef.

func (*ConfigMapKeyRef) DeepCopyInto

func (in *ConfigMapKeyRef) DeepCopyInto(out *ConfigMapKeyRef)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ContainerName

type ContainerName string
var (
	// ControllerManagerContainer is the default name of the scaffolded controller-runtime manager container.
	ControllerManagerContainer ContainerName = "manager"
	// DPUDetectorContainer is the default name of the DPU Detector container.
	DPUDetectorContainer ContainerName = "dpu-detector"
	// FlannelContainerDaemon is the name of the flannel daemon container.
	FlannelContainerDaemon ContainerName = "daemon"
	// FlannelContainerCNI is the name of the flannel CNI container.
	FlannelContainerCNI ContainerName = "cni"
	// NVIPAMContainerController is the name of the NVIPAM controller container.
	NVIPAMContainerController ContainerName = "controller"
	// NVIPAMContainerNode is the name of the NVIPAM node container.
	NVIPAMContainerNode ContainerName = "node"
	// MultusContainer is the default name of the scaffolded MultusContainer CNI container.
	MultusContainer ContainerName = "kube-multus"
	// SRIOVDevicePluginContainer is the default name of the scaffolded SR-IOV Device Plugin container.
	SRIOVDevicePluginContainer ContainerName = "kube-sriovdp"
	// SRIOVDevicePluginConfigInitContainer is the name of the SR-IOV Device Plugin init container
	// that resolves which config the plugin consumes.
	SRIOVDevicePluginConfigInitContainer ContainerName = "config-init"
	// OVSCNI is the default name of the scaffolded OVS CNI
	OVSCNI ContainerName = "ovs-cni-plugin"
	// CNIInstallerContainer is the default name of the scaffolded CNI Installer container.
	CNIInstallerContainer ContainerName = "cni-installer"
	// KubeStateMetricsContainer is the default name of the kube-state-metrics container.
	KubeStateMetricsContainer ContainerName = "kube-state-metrics"
	// NodeProblemDetectorContainer is the default name of the node-problem-detector container.
	NodeProblemDetectorContainer ContainerName = "node-problem-detector"
	// OpenTelemetryCollectorContainer is the default name of the opentelemetry-collector container.
	OpenTelemetryCollectorContainer ContainerName = "opentelemetry-collector"
	// KataDeployContainer is the default name of the kata-deploy container.
	KataDeployContainer ContainerName = "kata-deploy"
	// VaultKMSContainer is the default name of the Vault KMS plugin container.
	VaultKMSContainer ContainerName = "vault-kms"
	// CoreDNSContainer is the default name of the host cluster CoreDNS container.
	CoreDNSContainer ContainerName = "coredns"
)

Container names for the helm path provider in internal/operator/inventory/helm_paths_provider.go.

func (ContainerName) String

func (c ContainerName) String() string

type CoreDNSConfiguration

type CoreDNSConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Deployment contains the configuration for the CoreDNS deployment.
	// It contains the image for the CoreDNS container and its resource requirements.
	// +optional
	Deployment *CoreDNSDeployment `json:"deployment,omitempty"`

	// UpstreamNameservers is passed to the CoreDNS forward plugin for names outside the cluster domain.
	// It accepts the same space-separated nameserver or resolv.conf path syntax as the CoreDNS chart.
	// +kubebuilder:validation:MinLength=1
	// +optional
	UpstreamNameservers string `json:"upstreamNameservers,omitempty"`
}

CoreDNSConfiguration is the configuration for CoreDNS serving DPU clusters.

func (*CoreDNSConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CoreDNSConfiguration.

func (*CoreDNSConfiguration) DeepCopyInto

func (in *CoreDNSConfiguration) DeepCopyInto(out *CoreDNSConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*CoreDNSConfiguration) GetImages

func (c *CoreDNSConfiguration) GetImages() map[ContainerName]*string

GetImages returns a map of container names to their images.

func (*CoreDNSConfiguration) GetResources

GetResources returns a map of container names to their resource requirements.

func (*CoreDNSConfiguration) Name

func (c *CoreDNSConfiguration) Name() string

type CoreDNSDeployment

type CoreDNSDeployment struct {
	ImageComponentConfig    `json:",inline"`
	ResourceComponentConfig `json:",inline"`
}

CoreDNSDeployment contains the configuration for the CoreDNS deployment container.

func (*CoreDNSDeployment) DeepCopy

func (in *CoreDNSDeployment) DeepCopy() *CoreDNSDeployment

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CoreDNSDeployment.

func (*CoreDNSDeployment) DeepCopyInto

func (in *CoreDNSDeployment) DeepCopyInto(out *CoreDNSDeployment)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DPFOperatorConfig

type DPFOperatorConfig struct {
	metav1.TypeMeta   `json:",inline"`
	metav1.ObjectMeta `json:"metadata,omitempty"`

	Spec   DPFOperatorConfigSpec   `json:"spec,omitempty"`
	Status DPFOperatorConfigStatus `json:"status,omitempty"`
}

DPFOperatorConfig is the Schema for the dpfoperatorconfigs API

func (*DPFOperatorConfig) ComponentConfigs

func (c *DPFOperatorConfig) ComponentConfigs() []ComponentConfigurable

func (*DPFOperatorConfig) DeepCopy

func (in *DPFOperatorConfig) DeepCopy() *DPFOperatorConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DPFOperatorConfig.

func (*DPFOperatorConfig) DeepCopyInto

func (in *DPFOperatorConfig) DeepCopyInto(out *DPFOperatorConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*DPFOperatorConfig) DeepCopyObject

func (in *DPFOperatorConfig) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*DPFOperatorConfig) GetArgoCDNamespace

func (c *DPFOperatorConfig) GetArgoCDNamespace() string

GetArgoCDNamespace returns the namespace where ArgoCD is deployed. Falls back to the DPFOperatorConfig's own namespace if not explicitly configured.

func (*DPFOperatorConfig) GetCATrustBundleConfigMapName

func (c *DPFOperatorConfig) GetCATrustBundleConfigMapName() string

GetCATrustBundleConfigMapName returns the name of the ConfigMap that holds the public provisioning CA certificate(s). Consumers should call this helper to discover the trust bundle name instead of hardcoding it. For now it always returns a fixed default name; a configurable override on the DPFOperatorConfig API is planned for a follow-up task.

func (*DPFOperatorConfig) GetConditions

func (c *DPFOperatorConfig) GetConditions() []metav1.Condition

func (*DPFOperatorConfig) IsNewConfig

func (c *DPFOperatorConfig) IsNewConfig() bool

func (*DPFOperatorConfig) MonitoringEnabled

func (c *DPFOperatorConfig) MonitoringEnabled() bool

func (*DPFOperatorConfig) SetConditions

func (c *DPFOperatorConfig) SetConditions(conditions []metav1.Condition)

func (*DPFOperatorConfig) UpgradeInProgress

func (c *DPFOperatorConfig) UpgradeInProgress() bool

UpgradeInProgress reports whether the deployed version differs from the version being deployed. It compares the versions in the status and not the version of the binary reading the config: components deployed by the DPF Operator still run the previous release during an upgrade.

type DPFOperatorConfigList

type DPFOperatorConfigList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitempty"`
	Items           []DPFOperatorConfig `json:"items"`
}

DPFOperatorConfigList contains a list of DPFOperatorConfig

func (*DPFOperatorConfigList) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DPFOperatorConfigList.

func (*DPFOperatorConfigList) DeepCopyInto

func (in *DPFOperatorConfigList) DeepCopyInto(out *DPFOperatorConfigList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*DPFOperatorConfigList) DeepCopyObject

func (in *DPFOperatorConfigList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type DPFOperatorConfigSpec

type DPFOperatorConfigSpec struct {
	// +optional
	Overrides *Overrides `json:"overrides,omitempty"`

	// +kubebuilder:default={controlPlaneMTU: 1500}
	// +optional
	Networking *Networking `json:"networking,omitempty"`
	// Monitoring is the configuration for monitoring resources.
	// +optional
	Monitoring *MonitoringConfiguration `json:"monitoring,omitempty"`

	// Security groups configuration for security-related components managed by the DPF Operator.
	// +optional
	Security *SecurityConfiguration `json:"security,omitempty"`

	// List of secret names which are used to pull images for DPF system components and DPUServices.
	// These secrets must be in the same namespace as the DPF Operator Config and should be created before the config is created.
	// System reconciliation will not proceed until these secrets are available.
	// +optional
	ImagePullSecrets []string `json:"imagePullSecrets,omitempty"`

	// DeploymentMode selects zero-trust vs host-trusted deployment alignment.
	// Required: operators must set this explicitly; provisioning controllers propagate this to DPU.status.deploymentMode.
	// +required
	DeploymentMode DeploymentMode `json:"deploymentMode"`

	// DPUServiceController is the configuration for the DPUServiceController
	// +optional
	DPUServiceController *DPUServiceControllerConfiguration `json:"dpuServiceController,omitempty"`
	// ProvisioningController is the configuration for the ProvisioningController
	ProvisioningController *ProvisioningControllerConfiguration `json:"provisioningController"`
	// ServiceSetController is the configuration for the ServiceSetController
	// +optional
	ServiceSetController *ServiceSetControllerConfiguration `json:"serviceSetController,omitempty"`
	// DPUDetector is the configuration for the DPUDetector.
	// +optional
	DPUDetector *DPUDetectorConfiguration `json:"dpuDetector,omitempty"`
	// Multus is the configuration for Multus
	// +optional
	Multus *MultusConfiguration `json:"multus,omitempty"`
	// SRIOVDevicePlugin is the configuration for the SRIOVDevicePlugin
	// +optional
	SRIOVDevicePlugin *SRIOVDevicePluginConfiguration `json:"sriovDevicePlugin,omitempty"`
	// Flannel is the configuration for Flannel
	// +optional
	Flannel *FlannelConfiguration `json:"flannel,omitempty"`
	// OVSCNI is the configuration for OVSCNI
	//
	// Deprecated: OVS CNI is installed by CNIInstaller. Remove in 27.1.
	// +optional
	OVSCNI *OVSCNIConfiguration `json:"ovsCNI,omitempty"`
	// NVIPAM is the configuration for NVIPAM
	// +optional
	NVIPAM *NVIPAMConfiguration `json:"nvipam,omitempty"`
	// CNIInstaller is the configuration for the cni-installer
	// +optional
	CNIInstaller *CNIInstallerConfiguration `json:"cniInstaller,omitempty"`
	// CoreDNS is the configuration for CoreDNS serving Kamaji DPU clusters with a Keepalived endpoint.
	// +optional
	CoreDNS *CoreDNSConfiguration `json:"coreDNS,omitempty"`
	// SFCController is the configuration for the SFCController
	// +optional
	SFCController *SFCControllerConfiguration `json:"sfcController,omitempty"`
	// KamajiClusterManager is the configuration for the kamaji-cluster-manager
	// +optional
	KamajiClusterManager *KamajiClusterManagerConfiguration `json:"kamajiClusterManager,omitempty"`
	// StaticClusterManager is the configuration for the static-cluster-manager
	// +optional
	StaticClusterManager *StaticClusterManagerConfiguration `json:"staticClusterManager,omitempty"`
	// NodeSRIOVDevicePluginController is the configuration for the NodeSRIOVDevicePlugin controller.
	// This controller manages per-node SRIOV device plugin pods based on DPU configurations.
	// The controller is disabled by default.
	// +optional
	NodeSRIOVDevicePluginController *NodeSRIOVDevicePluginControllerConfiguration `json:"nodeSRIOVDevicePluginController,omitempty"`
}

DPFOperatorConfigSpec defines the desired state of DPFOperatorConfig +kubebuilder:validation:XValidation:rule="!has(self.deploymentMode) || self.deploymentMode != 'zero-trust' || (has(self.provisioningController.installInterface) && has(self.provisioningController.installInterface.installViaRedfish))",message="deploymentMode zero-trust requires provisioningController.installInterface.installViaRedfish" +kubebuilder:validation:XValidation:rule="!has(self.deploymentMode) || self.deploymentMode != 'host-trusted' || !has(self.provisioningController.installInterface) || !has(self.provisioningController.installInterface.installViaRedfish)",message="deploymentMode host-trusted does not support provisioningController.installInterface.installViaRedfish" +kubebuilder:validation:XValidation:rule="!has(self.deploymentMode) || self.deploymentMode == 'host-trusted' || !has(self.networking.dpuNodeOOBBridgeName) || self.networking.dpuNodeOOBBridgeName == 'br-dpu'",message="dpuNodeOOBBridgeName is only configurable in host-trusted mode" +kubebuilder:validation:XValidation:rule="!has(self.deploymentMode) || self.deploymentMode != 'zero-trust' || !has(self.networking) || !has(self.networking.controlPlaneMTU) || self.networking.controlPlaneMTU <= 1500",message="controlPlaneMTU must not exceed 1500 in zero-trust mode because DPU OOB interfaces do not support jumbo frames" +kubebuilder:validation:XValidation:rule="!has(oldSelf.deploymentMode) || (has(self.deploymentMode) && self.deploymentMode == oldSelf.deploymentMode)",message="deploymentMode is immutable after creation: it cannot be changed once set, because already provisioned DPUs keep the trust boundary they were provisioned under. Switch the cluster to another deploymentMode by deleting and recreating DPFOperatorConfig (DR escape hatch); existing DPUs require re-provisioning." +kubebuilder:validation:XValidation:rule="!has(self.security) || !has(self.security.spiffe) || self.deploymentMode == 'zero-trust'",message="spiffe configuration requires deploymentMode=zero-trust" +kubebuilder:validation:XValidation:rule="!has(oldSelf.security) || !has(oldSelf.security.spiffe) || (has(self.security) && has(self.security.spiffe))",message="spec.security.spiffe cannot be removed once set; SPIFFE-mode DPUs depend on this configuration. Disable SPIFFE for the cluster by deleting and recreating DPFOperatorConfig (DR escape hatch); existing SPIFFE-mode DPUs require re-provisioning." +kubebuilder:validation:XValidation:rule="!has(self.kamajiClusterManager) || !has(self.kamajiClusterManager.etcdEncryptionAtRest) || self.kamajiClusterManager.etcdEncryptionAtRest.provider != 'vaultKMS' || (has(self.security) && has(self.security.vaultKMS) && (!has(self.security.vaultKMS.disable) || self.security.vaultKMS.disable == false))",message="kamajiClusterManager.etcdEncryptionAtRest.provider vaultKMS requires spec.security.vaultKMS to be enabled"

func (*DPFOperatorConfigSpec) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DPFOperatorConfigSpec.

func (*DPFOperatorConfigSpec) DeepCopyInto

func (in *DPFOperatorConfigSpec) DeepCopyInto(out *DPFOperatorConfigSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DPFOperatorConfigStatus

type DPFOperatorConfigStatus struct {
	// Conditions exposes the current state of the OperatorConfig.
	// +optional
	Conditions []metav1.Condition `json:"conditions,omitempty"`

	// ObservedGeneration records the Generation observed on the object the last time it was patched.
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`

	// Version is the version of the DPF Operator that is currently deployed.
	// +optional
	Version *string `json:"version,omitempty"`

	// TargetVersion is the version of the DPF Operator that is being deployed. It differs from
	// Version while an upgrade is in progress.
	// +optional
	TargetVersion *string `json:"targetVersion,omitempty"`
}

DPFOperatorConfigStatus defines the observed state of DPFOperatorConfig

func (*DPFOperatorConfigStatus) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DPFOperatorConfigStatus.

func (*DPFOperatorConfigStatus) DeepCopyInto

func (in *DPFOperatorConfigStatus) DeepCopyInto(out *DPFOperatorConfigStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DPUDetectorConfiguration

type DPUDetectorConfiguration struct {
	BaseComponentConfig `json:",inline"`

	// Image overrides the container image used by the DPUDetector Container.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `daemon` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// Daemon contains the configuration for the DPU Detector component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Daemon *DefaultOverridesConfiguration `json:"daemon,omitempty"`
}

func (*DPUDetectorConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DPUDetectorConfiguration.

func (*DPUDetectorConfiguration) DeepCopyInto

func (in *DPUDetectorConfiguration) DeepCopyInto(out *DPUDetectorConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*DPUDetectorConfiguration) GetImage deprecated

func (c *DPUDetectorConfiguration) GetImage() *string

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*DPUDetectorConfiguration) GetImages

func (c *DPUDetectorConfiguration) GetImages() map[ContainerName]*string

GetImages returns a map of container names to their images

func (*DPUDetectorConfiguration) GetResources

func (*DPUDetectorConfiguration) Name

func (c *DPUDetectorConfiguration) Name() string

type DPUServiceControllerConfiguration

type DPUServiceControllerConfiguration struct {
	BaseComponentConfig  `json:",inline"`
	BaseControllerConfig `json:",inline"`

	// Image overrides the container image used by the DPUService controller.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `controller` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// Controller contains the configuration for the DPU Service controller component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Controller *DefaultOverridesConfiguration `json:"controller,omitempty"`

	// DisableDPUReadyTaints is a full taint kill-switch for the DPUReady controller.
	// When set to true, no taint managed by this controller (NoSchedule for critical
	// DPUServices, or NoExecute for HostNetworkReady) is added, removed, or otherwise
	// touched on host worker nodes.
	// +optional
	DisableDPUReadyTaints *bool `json:"disableDPUReadyTaints,omitempty"`

	// DisableHostNetworkReadyNoExecuteTaints disables NoExecute taints on host worker nodes
	// based on HostNetworkReady. When unset or true, the feature is disabled (safe default).
	// Set to false to enable NoExecute tainting when HostNetworkReady != True.
	// +optional
	DisableHostNetworkReadyNoExecuteTaints *bool `json:"disableHostNetworkReadyNoExecuteTaints,omitempty"`
}

func (*DPUServiceControllerConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DPUServiceControllerConfiguration.

func (*DPUServiceControllerConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*DPUServiceControllerConfiguration) GetImage deprecated

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*DPUServiceControllerConfiguration) GetImages

GetImages returns a map of container names to their images

func (*DPUServiceControllerConfiguration) GetResources

func (*DPUServiceControllerConfiguration) Name

type DefaultOverridesConfiguration

type DefaultOverridesConfiguration struct {
	ImageComponentConfig    `json:",inline"`
	ResourceComponentConfig `json:",inline"`
}

func (*DefaultOverridesConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new DefaultOverridesConfiguration.

func (*DefaultOverridesConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type DeploymentMode

type DeploymentMode string

DeploymentMode describes the cluster deployment model for DPU provisioning (zero-trust vs host-trusted). +kubebuilder:validation:Enum=zero-trust;host-trusted

const (
	// DeploymentModeZeroTrust requires provisioningController.installInterface.installViaRedfish
	DeploymentModeZeroTrust DeploymentMode = "zero-trust"
	// DeploymentModeHostTrusted allows provisioningController.installInterface.installViaHostAgent, or installViaGNOI
	DeploymentModeHostTrusted DeploymentMode = "host-trusted"
)

type DeprecatedImageComponentConfigurable deprecated

type DeprecatedImageComponentConfigurable interface {
	// GetImage returns a string with one or more images to be configured for the components.
	// This is a comma-delimited string if the component has more than one image to be configured.
	GetImage() *string
}

DeprecatedImageComponentConfigurable is the shared config for helm components.

Deprecated: new components should use the ImageComponentConfigurable instead.

+kubebuilder:object:generate=false

type EtcdEncryptionAtRestConfiguration

type EtcdEncryptionAtRestConfiguration struct {
	// Provider selects the encryption-at-rest provider.
	// +required
	Provider EtcdEncryptionAtRestProvider `json:"provider,omitempty"`

	// StaticKey configures the staticKey provider. It is required when provider is staticKey and
	// must not be set otherwise.
	// +optional
	StaticKey *StaticKeyConfiguration `json:"staticKey,omitempty"`
}

EtcdEncryptionAtRestConfiguration is the per-cluster encryption-at-rest selector for Kamaji clusters. +kubebuilder:validation:XValidation:rule="self.provider != 'staticKey' || has(self.staticKey)",message="staticKey is required when provider is staticKey" +kubebuilder:validation:XValidation:rule="self.provider != 'vaultKMS' || !has(self.staticKey)",message="staticKey must not be set when provider is vaultKMS"

func (*EtcdEncryptionAtRestConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new EtcdEncryptionAtRestConfiguration.

func (*EtcdEncryptionAtRestConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type EtcdEncryptionAtRestProvider

type EtcdEncryptionAtRestProvider string

EtcdEncryptionAtRestProvider selects the etcd encryption-at-rest provider. +kubebuilder:validation:Enum=staticKey;vaultKMS

const (
	// EtcdEncryptionProviderStaticKey encrypts etcd data with an AES-GCM key rendered inline into the encryption config.
	EtcdEncryptionProviderStaticKey EtcdEncryptionAtRestProvider = "staticKey"
	// EtcdEncryptionProviderVaultKMS encrypts etcd data via the KMS v2 plugin served by the vaultKMS component.
	EtcdEncryptionProviderVaultKMS EtcdEncryptionAtRestProvider = "vaultKMS"
)

type FlannelCNI

type FlannelCNI struct {
	ImageComponentConfig `json:",inline"`
}

func (*FlannelCNI) DeepCopy

func (in *FlannelCNI) DeepCopy() *FlannelCNI

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new FlannelCNI.

func (*FlannelCNI) DeepCopyInto

func (in *FlannelCNI) DeepCopyInto(out *FlannelCNI)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type FlannelConfiguration

type FlannelConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// CNI is the configuration for the Flannel CNI component.
	// It contains the image for the CNI init container.
	// Note: The resources for the CNI container are not configurable.
	// +optional
	CNI *FlannelCNI `json:"cni,omitempty"`

	// Daemon is the configuration for the Flannel Daemon component.
	// It contains the image for the Flannel Daemon container and its resource requirements.
	// +optional
	Daemon *FlannelDaemon `json:"daemon,omitempty"`

	// Images overrides the container images used by flannel
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new fields `cni` and `daemon` instead.
	// +optional
	Images *FlannelImages `json:"image,omitempty"`

	// PodCIDR is the pod cidr for flannel.
	// +optional
	PodCIDR *string `json:"podCIDR,omitempty"`
}

func (*FlannelConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new FlannelConfiguration.

func (*FlannelConfiguration) DeepCopyInto

func (in *FlannelConfiguration) DeepCopyInto(out *FlannelConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*FlannelConfiguration) GetImage

func (c *FlannelConfiguration) GetImage() *string

GetImage returns a comma-delimited list of the Flannel images with a specified order. KubeFlannel is first and FlannelCNi is second.

func (*FlannelConfiguration) GetImages

func (c *FlannelConfiguration) GetImages() map[ContainerName]*string

GetImages returns a map of container names to their images

func (*FlannelConfiguration) GetResources

func (*FlannelConfiguration) Name

func (c *FlannelConfiguration) Name() string

type FlannelDaemon

type FlannelDaemon struct {
	ImageComponentConfig    `json:",inline"`
	ResourceComponentConfig `json:",inline"`
}

func (*FlannelDaemon) DeepCopy

func (in *FlannelDaemon) DeepCopy() *FlannelDaemon

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new FlannelDaemon.

func (*FlannelDaemon) DeepCopyInto

func (in *FlannelDaemon) DeepCopyInto(out *FlannelDaemon)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type FlannelImages

type FlannelImages struct {
	// FlannelCNI must be set if FlannelImages is set.
	// +kubebuilder:validation:MinLength=1
	// +required
	FlannelCNI string `json:"flannelCNI,omitempty"`
	// KubeFlannel must be set if FlannelImages is set.
	// +kubebuilder:validation:MinLength=1
	// +required
	KubeFlannel string `json:"kubeFlannel,omitempty"`
}

func (*FlannelImages) DeepCopy

func (in *FlannelImages) DeepCopy() *FlannelImages

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new FlannelImages.

func (*FlannelImages) DeepCopyInto

func (in *FlannelImages) DeepCopyInto(out *FlannelImages)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type HelmChart

type HelmChart *string

HelmChart is a reference to a helm chart. +kubebuilder:validation:Pattern=`^(oci://|https://).+$`

type HelmComponentConfig

type HelmComponentConfig struct {
	// HelmChart overrides the helm chart used by the ServiceSet controller.
	// The URL must begin with either 'oci://' or 'https://', ensuring it points to a valid
	// OCI registry or a web-based repository.
	// +optional
	HelmChart HelmChart `json:"helmChart,omitempty"`
}

func (*HelmComponentConfig) DeepCopy

func (in *HelmComponentConfig) DeepCopy() *HelmComponentConfig

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new HelmComponentConfig.

func (*HelmComponentConfig) DeepCopyInto

func (in *HelmComponentConfig) DeepCopyInto(out *HelmComponentConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*HelmComponentConfig) GetHelmChart

func (b *HelmComponentConfig) GetHelmChart() *string

type HelmComponentConfigurable

type HelmComponentConfigurable interface {
	GetHelmChart() *string
}

HelmComponentConfigurable is the shared config for helm components.

+kubebuilder:object:generate=false

type Image

Image is a reference to a container image. +kubebuilder:validation:Pattern= `^((?:(?:(?:[a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9-]*[a-zA-Z0-9])(?:\.(?:[a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9-]*[a-zA-Z0-9]))*|\[(?:[a-fA-F0-9:]+)\])(?::[0-9]+)?/)?[a-z0-9]+(?:(?:[._]|__|[-]+)[a-z0-9]+)*(?:/[a-z0-9]+(?:(?:[._]|__|[-]+)[a-z0-9]+)*)*)(?::([\w][\w.-]{0,127}))?(?:@([A-Za-z][A-Za-z0-9]*(?:[-_+.][A-Za-z][A-Za-z0-9]*)*[:][[:xdigit:]]{32,}))?$`

type ImageComponentConfig

type ImageComponentConfig struct {
	// +optional
	Image Image `json:"image,omitempty"`
}

ImageComponentConfig provides common configuration fields that can be embedded by all component configurations to reduce code duplication.

func (*ImageComponentConfig) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ImageComponentConfig.

func (*ImageComponentConfig) DeepCopyInto

func (in *ImageComponentConfig) DeepCopyInto(out *ImageComponentConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*ImageComponentConfig) GetImage

func (b *ImageComponentConfig) GetImage() *string

GetImage returns the image override for the component

type ImageComponentConfigurable

type ImageComponentConfigurable interface {
	// GetImages returns a map of container names to their images.
	GetImages() map[ContainerName]*string
}

ImageComponentConfigurable defines configuration for overriding the images of a component’s containers. Specified at the pod container level. +kubebuilder:object:generate=false

type InstallViaGNOI

type InstallViaGNOI struct{}

InstallViaGNOI is the interface used to install the BFB via GNOI

func (*InstallViaGNOI) DeepCopy

func (in *InstallViaGNOI) DeepCopy() *InstallViaGNOI

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InstallViaGNOI.

func (*InstallViaGNOI) DeepCopyInto

func (in *InstallViaGNOI) DeepCopyInto(out *InstallViaGNOI)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type InstallViaHostAgent

type InstallViaHostAgent struct{}

InstallViaHostAgent is the interface used to install the BFB

func (*InstallViaHostAgent) DeepCopy

func (in *InstallViaHostAgent) DeepCopy() *InstallViaHostAgent

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InstallViaHostAgent.

func (*InstallViaHostAgent) DeepCopyInto

func (in *InstallViaHostAgent) DeepCopyInto(out *InstallViaHostAgent)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type InstallViaRedfish

type InstallViaRedfish struct {
	// BFBRegistryAddress is the address of the BFB Registry
	//
	// Deprecated: Use RegistryConfiguration instead.
	// +kubebuilder:validation:MinLength=1
	BFBRegistryAddress string `json:"bfbRegistryAddress,omitempty"`
	// BFBRegistry is the configuration for the BFB Registry
	//
	// Deprecated: Use RegistryConfiguration instead.
	// +optional
	BFBRegistry *BFBRegistryConfiguration `json:"bfbRegistry,omitempty"`
	// SkipDPUNodeDiscovery is a flag to skip the DPU node discovery.
	// +optional
	// +kubebuilder:default=true
	SkipDPUNodeDiscovery *bool `json:"skipDPUNodeDiscovery,omitempty"`
	// DiscoveredDPUDeviceBMCFactoryResetPolicy is the BMC factory reset policy DPUDiscovery
	// sets on the DPUDevices it creates. It is applied at creation time only: changing it
	// does not affect DPUDevices that already exist, and it is not consulted when a
	// DPUDevice is reconciled. When unset, the discovery controller uses OnInitialization.
	// +kubebuilder:validation:Enum=OnInitialization;Never
	// +optional
	DiscoveredDPUDeviceBMCFactoryResetPolicy provisioningv1.BMCFactoryResetPolicy `json:"discoveredDPUDeviceBMCFactoryResetPolicy,omitempty"`
}

InstallViaRedfish is the interface used to install the BFB via Redfish

func (*InstallViaRedfish) DeepCopy

func (in *InstallViaRedfish) DeepCopy() *InstallViaRedfish

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InstallViaRedfish.

func (*InstallViaRedfish) DeepCopyInto

func (in *InstallViaRedfish) DeepCopyInto(out *InstallViaRedfish)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type KamajiClusterManagerConfiguration

type KamajiClusterManagerConfiguration struct {
	BaseComponentConfig  `json:",inline"`
	BaseControllerConfig `json:",inline"`

	// Image overrides the container image used by the Kamaji Cluster Manager.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `controller` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// Controller contains the configuration for the Kamaji Cluster Manager component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Controller *DefaultOverridesConfiguration `json:"controller,omitempty"`

	// EtcdEncryptionAtRest configures encryption at rest for the etcd datastore of
	// Kamaji-managed DPU clusters. The provider selection is applied only when a
	// Kamaji cluster is first created and is not changed for existing clusters.
	// +optional
	EtcdEncryptionAtRest *EtcdEncryptionAtRestConfiguration `json:"etcdEncryptionAtRest,omitempty"`
}

func (*KamajiClusterManagerConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new KamajiClusterManagerConfiguration.

func (*KamajiClusterManagerConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*KamajiClusterManagerConfiguration) GetImage deprecated

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*KamajiClusterManagerConfiguration) GetImages

GetImages returns a map of container names to their images

func (*KamajiClusterManagerConfiguration) GetResources

func (*KamajiClusterManagerConfiguration) Name

type KataContainersConfiguration

type KataContainersConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Daemon contains the configuration for the kata-deploy component.
	// It contains the image for the kata-deploy container.
	// +optional
	Daemon *ImageComponentConfig `json:"daemon,omitempty"`

	// NodeSelector restricts which nodes kata-deploy runs on.
	// This is passed as the Helm chart's nodeSelector value.
	// +optional
	NodeSelector map[string]string `json:"nodeSelector,omitempty"`

	// Shims selects which Kata hypervisor shims to enable.
	// Defaults to ["qemu"] if empty.
	// +optional
	// +kubebuilder:validation:items:Enum=qemu
	Shims []KataShim `json:"shims,omitempty"`

	// ContainerdConfigFileName overrides the containerd config file name
	// on the target nodes. Defaults to "config-mlnx.toml".
	// +optional
	ContainerdConfigFileName string `json:"containerdConfigFileName,omitempty"`
}

func (*KataContainersConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new KataContainersConfiguration.

func (*KataContainersConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*KataContainersConfiguration) GetImages

func (c *KataContainersConfiguration) GetImages() map[ContainerName]*string

func (*KataContainersConfiguration) Name

type KataShim

type KataShim string

KataShim identifies a Kata hypervisor shim variant. Values must match the shim keys in the kata-deploy Helm chart's `shims.<name>.enabled` values. Only arm64-compatible shims are supported. +kubebuilder:validation:Enum=qemu

const (
	// KataShimQEMU is the QEMU hypervisor shim.
	KataShimQEMU KataShim = "qemu"
)

type KubeStateMetricsConfiguration

type KubeStateMetricsConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Daemon contains the configuration for the kube-state-metrics component.
	// It contains the image for kube-state-metrics and its resource requirements.
	// +optional
	Daemon *DefaultOverridesConfiguration `json:"daemon,omitempty"`
}

func (*KubeStateMetricsConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new KubeStateMetricsConfiguration.

func (*KubeStateMetricsConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*KubeStateMetricsConfiguration) GetImages

GetImages returns a map of container names to their images

func (*KubeStateMetricsConfiguration) GetResources

func (*KubeStateMetricsConfiguration) Name

type MonitoringConfiguration

type MonitoringConfiguration struct {
	// Disable controls whether monitoring resources are installed.
	// When enabled (default), the controller:
	// - Creates ServiceMonitors for Kamaji clusters to scrape control-plane metrics.
	// - Deploys kube-state-metrics as a DPUService to expose metrics for custom resources.
	// - Deploys node-problem-detector as a DaemonSet on DPU nodes to detect and report node-level problems.
	// - Deploys opentelemetry-collector as a DaemonSet on DPU nodes to collect and forward logs.
	// +optional
	Disable *bool `json:"disable,omitempty"`

	// KubeStateMetrics is the configuration for kube-state-metrics
	// +optional
	KubeStateMetrics *KubeStateMetricsConfiguration `json:"kubeStateMetrics,omitempty"`

	// NodeProblemDetector is the configuration for node-problem-detector
	// +optional
	NodeProblemDetector *NodeProblemDetectorConfiguration `json:"nodeProblemDetector,omitempty"`

	// OpenTelemetryCollector is the configuration for opentelemetry-collector
	// +optional
	OpenTelemetryCollector *OpenTelemetryCollectorConfiguration `json:"openTelemetryCollector,omitempty"`
}

MonitoringConfiguration defines the configuration for monitoring resources.

func (*MonitoringConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MonitoringConfiguration.

func (*MonitoringConfiguration) DeepCopyInto

func (in *MonitoringConfiguration) DeepCopyInto(out *MonitoringConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type MultusConfiguration

type MultusConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Image overrides the container image used by the Multus Container.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `cni` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// CNI contains the configuration for the Multus CNI component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	CNI *DefaultOverridesConfiguration `json:"cni,omitempty"`
}

func (*MultusConfiguration) DeepCopy

func (in *MultusConfiguration) DeepCopy() *MultusConfiguration

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MultusConfiguration.

func (*MultusConfiguration) DeepCopyInto

func (in *MultusConfiguration) DeepCopyInto(out *MultusConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*MultusConfiguration) GetImage deprecated

func (c *MultusConfiguration) GetImage() *string

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*MultusConfiguration) GetImages

func (c *MultusConfiguration) GetImages() map[ContainerName]*string

GetImages returns a map of container names to their images

func (*MultusConfiguration) GetResources

func (*MultusConfiguration) Name

func (c *MultusConfiguration) Name() string

type NVIPAMConfiguration

type NVIPAMConfiguration struct {
	BaseComponentConfig  `json:",inline"`
	HelmComponentConfig  `json:",inline"`
	BaseControllerConfig `json:",inline"`

	// Image overrides the container image used by the NVIPAM controller.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `controller` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// Controller contains the configuration for the NVIPAM controller component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Controller *NVIPAMController `json:"controller,omitempty"`

	// Node contains the configuration for the NVIPAM node component.
	// It contains the image for the node and its resource requirements.
	Node *NVIPAMNode `json:"node,omitempty"`
}

func (*NVIPAMConfiguration) DeepCopy

func (in *NVIPAMConfiguration) DeepCopy() *NVIPAMConfiguration

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new NVIPAMConfiguration.

func (*NVIPAMConfiguration) DeepCopyInto

func (in *NVIPAMConfiguration) DeepCopyInto(out *NVIPAMConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*NVIPAMConfiguration) GetImage deprecated

func (c *NVIPAMConfiguration) GetImage() *string

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*NVIPAMConfiguration) GetImages

func (c *NVIPAMConfiguration) GetImages() map[ContainerName]*string

func (*NVIPAMConfiguration) GetResources

func (*NVIPAMConfiguration) Name

func (c *NVIPAMConfiguration) Name() string

type NVIPAMController

type NVIPAMController struct {
	ImageComponentConfig    `json:",inline"`
	ResourceComponentConfig `json:",inline"`
}

func (*NVIPAMController) DeepCopy

func (in *NVIPAMController) DeepCopy() *NVIPAMController

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new NVIPAMController.

func (*NVIPAMController) DeepCopyInto

func (in *NVIPAMController) DeepCopyInto(out *NVIPAMController)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type NVIPAMNode

type NVIPAMNode struct {
	ImageComponentConfig    `json:",inline"`
	ResourceComponentConfig `json:",inline"`
}

func (*NVIPAMNode) DeepCopy

func (in *NVIPAMNode) DeepCopy() *NVIPAMNode

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new NVIPAMNode.

func (*NVIPAMNode) DeepCopyInto

func (in *NVIPAMNode) DeepCopyInto(out *NVIPAMNode)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Networking

type Networking struct {
	// ControlPlaneMTU is the MTU value to be set on the management network.
	// In zero-trust mode this value is applied to the DPU OOB interface (oob_net0), which does not
	// support jumbo frames; it must not exceed 1500 when deploymentMode is zero-trust.
	// The default is 1500.
	// +kubebuilder:validation:Minimum=1280
	// +kubebuilder:validation:Maximum=9216
	// +kubebuilder:default=1500
	// +optional
	ControlPlaneMTU *int `json:"controlPlaneMTU,omitempty"`

	// HighSpeedMTU is the MTU value to be set on the high-speed interface.
	// The default is 1500.
	// +kubebuilder:validation:Minimum=1280
	// +kubebuilder:validation:Maximum=9216
	// +kubebuilder:default=1500
	// +optional
	HighSpeedMTU *int `json:"highSpeedMTU,omitempty"`

	// DPUNodeOOBBridgeName is the name of the Linux bridge on the host used for
	// out-of-band DPU management traffic. If not specified, defaults to "br-dpu".
	// This setting applies only to host-trusted deployments.
	// +kubebuilder:default="br-dpu"
	// +kubebuilder:validation:Pattern=`^[a-z][a-z0-9-]*$`
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=15
	// +optional
	DPUNodeOOBBridgeName *string `json:"dpuNodeOOBBridgeName,omitempty"`
}

Networking defines the networking configuration for the system components.

func (*Networking) DeepCopy

func (in *Networking) DeepCopy() *Networking

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Networking.

func (*Networking) DeepCopyInto

func (in *Networking) DeepCopyInto(out *Networking)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*Networking) GetDPUNodeOOBBridgeName

func (n *Networking) GetDPUNodeOOBBridgeName() string

GetDPUNodeOOBBridgeName returns the configured OOB bridge name, defaulting to br-dpu.

type NodeProblemDetectorConfiguration

type NodeProblemDetectorConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Daemon contains the configuration for the node-problem-detector component.
	// It contains the image for node-problem-detector and its resource requirements.
	// +optional
	Daemon *DefaultOverridesConfiguration `json:"daemon,omitempty"`
}

func (*NodeProblemDetectorConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new NodeProblemDetectorConfiguration.

func (*NodeProblemDetectorConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*NodeProblemDetectorConfiguration) GetImages

GetImages returns a map of container names to their images

func (*NodeProblemDetectorConfiguration) GetResources

func (*NodeProblemDetectorConfiguration) Name

type NodeSRIOVDevicePluginControllerConfiguration

type NodeSRIOVDevicePluginControllerConfiguration struct {
	BaseComponentConfig  `json:",inline"`
	BaseControllerConfig `json:",inline"`

	// Controller contains the configuration for the NodeSRIOVDevicePlugin controller component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Controller *DefaultOverridesConfiguration `json:"controller,omitempty"`

	// DevicePlugin contains the configuration for the SRIOV device plugin pods
	// managed by this controller.
	// +optional
	DevicePlugin *NodeSRIOVDevicePluginSettings `json:"devicePlugin,omitempty"`
}

NodeSRIOVDevicePluginControllerConfiguration is the configuration for the NodeSRIOVDevicePlugin controller. This controller manages per-node SRIOV device plugin pods based on DPU configurations. The controller is disabled by default.

func (*NodeSRIOVDevicePluginControllerConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new NodeSRIOVDevicePluginControllerConfiguration.

func (*NodeSRIOVDevicePluginControllerConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*NodeSRIOVDevicePluginControllerConfiguration) GetImages

GetImages returns a map of container names to their images

func (*NodeSRIOVDevicePluginControllerConfiguration) GetResources

func (*NodeSRIOVDevicePluginControllerConfiguration) Name

type NodeSRIOVDevicePluginSettings

type NodeSRIOVDevicePluginSettings struct {
	// Image overrides the container image for the SRIOV device plugin.
	// +optional
	Image Image `json:"image,omitempty"`

	// InitImage overrides the container image for the init container
	// that generates device plugin configuration.
	// +optional
	InitImage Image `json:"initImage,omitempty"`

	// DefaultResourcePrefix is the default resource prefix for the SRIOV device plugin resources.
	// Defaults to "nvidia.com".
	// +kubebuilder:validation:Pattern=`^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$`
	// +optional
	DefaultResourcePrefix *string `json:"defaultResourcePrefix,omitempty"`
}

NodeSRIOVDevicePluginSettings contains configuration for the SRIOV device plugin pods managed by the NodeSRIOVDevicePlugin controller.

func (*NodeSRIOVDevicePluginSettings) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new NodeSRIOVDevicePluginSettings.

func (*NodeSRIOVDevicePluginSettings) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type OVSCNIConfiguration

type OVSCNIConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Image overrides the container image used by the OVS CNI.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `cni` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// CNI contains the configuration for the OVS CNI component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	CNI *DefaultOverridesConfiguration `json:"cni,omitempty"`
}

func (*OVSCNIConfiguration) DeepCopy

func (in *OVSCNIConfiguration) DeepCopy() *OVSCNIConfiguration

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OVSCNIConfiguration.

func (*OVSCNIConfiguration) DeepCopyInto

func (in *OVSCNIConfiguration) DeepCopyInto(out *OVSCNIConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*OVSCNIConfiguration) GetImage deprecated

func (c *OVSCNIConfiguration) GetImage() *string

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*OVSCNIConfiguration) GetImages

func (c *OVSCNIConfiguration) GetImages() map[ContainerName]*string

GetImages returns a map of container names to their images

func (*OVSCNIConfiguration) GetResources

func (*OVSCNIConfiguration) Name

func (c *OVSCNIConfiguration) Name() string

type OpenTelemetryCollectorCASecretReference

type OpenTelemetryCollectorCASecretReference struct {
	// Name is the name of the Secret holding the CA certificate bundle.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=253
	// +required
	Name string `json:"name,omitempty"`

	// Namespace is the namespace of the Secret holding the CA certificate bundle.
	// If unset, the DPFOperatorConfig namespace is used.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=63
	// +optional
	Namespace *string `json:"namespace,omitempty"`

	// Key is the Secret data key that holds the PEM-encoded CA certificate bundle.
	// If unset, "ca.crt" is used, matching the key that cert-manager writes.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=253
	// +optional
	Key *string `json:"key,omitempty"`
}

OpenTelemetryCollectorCASecretReference references a Secret that contains the PEM-encoded CA certificate bundle used to verify the endpoint's TLS certificate.

func (*OpenTelemetryCollectorCASecretReference) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenTelemetryCollectorCASecretReference.

func (*OpenTelemetryCollectorCASecretReference) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type OpenTelemetryCollectorConfiguration

type OpenTelemetryCollectorConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Daemon contains the configuration for the opentelemetry-collector component.
	// It contains the image for opentelemetry-collector and its resource requirements.
	// +optional
	Daemon *DefaultOverridesConfiguration `json:"daemon,omitempty"`

	// Logging contains the configuration for the opentelemetry-collector logging component.
	// If not specified, logging will not be streamed.
	// +optional
	Logging *OpenTelemetryCollectorLoggingConfiguration `json:"logging,omitempty"`

	// Metrics contains the configuration for the opentelemetry-collector metrics component.
	// If not specified, metrics will not be streamed from DPU clusters.
	// +optional
	Metrics *OpenTelemetryCollectorMetricsConfiguration `json:"metrics,omitempty"`
}

func (*OpenTelemetryCollectorConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenTelemetryCollectorConfiguration.

func (*OpenTelemetryCollectorConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*OpenTelemetryCollectorConfiguration) GetImages

GetImages returns a map of container names to their images

func (*OpenTelemetryCollectorConfiguration) GetResources

func (*OpenTelemetryCollectorConfiguration) Name

type OpenTelemetryCollectorLoggingConfiguration

type OpenTelemetryCollectorLoggingConfiguration struct {
	// Endpoint is the OTLP endpoint where the DPU cluster opentelemetry-collector sends data to.
	// This could be the management cluster's opentelemetry-collector endpoint.
	// If not specified, nothing will be forwarded from DPU clusters.
	// For the http transport the endpoint must include the scheme, e.g. "https://host:4318".
	// For the grpc transport the endpoint is "host:4317", optionally prefixed with a
	// scheme ("https://host:4317") to enforce TLS.
	// +required
	Endpoint string `json:"endpoint,omitempty"`

	// Transport is the OTLP transport used to export data to the endpoint.
	// +kubebuilder:validation:Enum=http;grpc
	// +optional
	Transport *OpenTelemetryCollectorTransport `json:"transport,omitempty"`

	// CASecretRef references a Secret that contains the PEM-encoded CA certificate bundle
	// (under the "ca.crt" key) used to verify the endpoint's TLS certificate. Set it when the
	// endpoint serves a certificate issued by a private CA. The Secret may live in any namespace,
	// for example alongside the endpoint's cert-manager Certificate; if its namespace is empty,
	// the DPFOperatorConfig namespace is used.
	// If not specified, TLS endpoints are verified against the system CA pool.
	// Changes to the Secret content are applied on the next reconciliation of the DPFOperatorConfig.
	// +optional
	CASecretRef *OpenTelemetryCollectorCASecretReference `json:"caSecretRef,omitempty"`
}

OpenTelemetryCollectorLoggingConfiguration configures where and how the DPU cluster opentelemetry-collector exports its data. +kubebuilder:validation:XValidation:rule="!has(self.caSecretRef) || !self.endpoint.startsWith('http://')",message="caSecretRef cannot be used with a plaintext http:// endpoint"

func (*OpenTelemetryCollectorLoggingConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenTelemetryCollectorLoggingConfiguration.

func (*OpenTelemetryCollectorLoggingConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type OpenTelemetryCollectorMetricsConfiguration

type OpenTelemetryCollectorMetricsConfiguration struct {
	// Endpoint is the OTLP endpoint where the DPU cluster opentelemetry-collector sends metrics to.
	// This could be the management cluster's opentelemetry-collector endpoint.
	// If not specified, metrics will not be forwarded from DPU clusters.
	// For the http transport the endpoint must include the scheme, e.g. "https://host:4318".
	// For the grpc transport the endpoint is "host:4317", optionally prefixed with a
	// scheme ("https://host:4317") to enforce TLS.
	// +required
	Endpoint string `json:"endpoint,omitempty"`

	// Transport is the OTLP transport used to export data to the endpoint.
	// +kubebuilder:validation:Enum=http;grpc
	// +optional
	Transport *OpenTelemetryCollectorTransport `json:"transport,omitempty"`

	// CASecretRef references a Secret that contains the PEM-encoded CA certificate bundle
	// (under the "ca.crt" key) used to verify the endpoint's TLS certificate. Set it when the
	// endpoint serves a certificate issued by a private CA. The Secret may live in any namespace,
	// for example alongside the endpoint's cert-manager Certificate; if its namespace is empty,
	// the DPFOperatorConfig namespace is used.
	// If not specified, TLS endpoints are verified against the system CA pool.
	// Changes to the Secret content are applied on the next reconciliation of the DPFOperatorConfig.
	// +optional
	CASecretRef *OpenTelemetryCollectorCASecretReference `json:"caSecretRef,omitempty"`
}

OpenTelemetryCollectorMetricsConfiguration configures where and how the DPU cluster opentelemetry-collector exports its metrics. +kubebuilder:validation:XValidation:rule="!has(self.caSecretRef) || !self.endpoint.startsWith('http://')",message="caSecretRef cannot be used with a plaintext http:// endpoint"

func (*OpenTelemetryCollectorMetricsConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new OpenTelemetryCollectorMetricsConfiguration.

func (*OpenTelemetryCollectorMetricsConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type OpenTelemetryCollectorTransport

type OpenTelemetryCollectorTransport string

OpenTelemetryCollectorTransport is the OTLP transport used to export data to the endpoint.

const (
	// OpenTelemetryCollectorTransportHTTP exports data via OTLP/HTTP.
	OpenTelemetryCollectorTransportHTTP OpenTelemetryCollectorTransport = "http"
	// OpenTelemetryCollectorTransportGRPC exports data via OTLP/gRPC.
	OpenTelemetryCollectorTransportGRPC OpenTelemetryCollectorTransport = "grpc"
)

type Overrides

type Overrides struct {
	// Paused disables all reconciliation of the DPFOperatorConfig when set to true.
	// +optional
	Paused *bool `json:"paused,omitempty"`

	// DPUCNIBinPath is the path at which the CNI binaries will be installed to on the DPU.
	// This is /opt/cni/bin by default.
	// This setting does not change where kubelet is configured to use the CNI from.
	// +optional
	DPUCNIBinPath *string `json:"dpuCNIBinPath,omitempty"`

	// DPUCNIConfigPath is the path to which the CNI config files will be installed on the DPU.
	// This is /etc/cni/net.d by default.
	// This setting does not change where kubelet is configured to read the CNI config from.
	// +optional
	DPUCNIConfigPath *string `json:"dpuCNIPath,omitempty"`

	// DPUOpenvSwitchPath is the path at which the openvSwitch run directory can be found on the DPU.
	// This is /var/run/openvswitch by default.
	// This setting does not change where components are installed. Installation location fixed in the BFB.
	// +optional
	DPUOpenvSwitchRunPath *string `json:"dpuOpenvSwitchRunPath,omitempty"`

	// DPUOpenvSwitchBinPath is the path at which the openvSwitch bin directory can be found on the DPU node.
	// This is /usr/bin/ by default.
	// This setting does not change where components are installed. Installation location fixed in the BFB.
	// +optional
	DPUOpenvSwitchBinPath *string `json:"dpuOpenvSwitchBinPath,omitempty"`

	// DPUOpenvSwitchSystemSharedLibPath is the path at which the system lib used by OVS components can be found on the DPU.
	// This is /lib by default.
	// This setting does not change where components are installed. Installation location fixed in the BFB.
	// +optional
	DPUOpenvSwitchSystemSharedLibPath *string `json:"dpuOpenvSwitchSystemSharedPath,omitempty"`

	// FlannelSkipCNIConfigInstallation controls whether Flannel should skip CNI config installation.
	// This is true by default, meaning Flannel does not manage its own CNI configuration.
	// Set to false if you want Flannel to install a CNI configuration.
	// +optional
	FlannelSkipCNIConfigInstallation *bool `json:"flannelSkipCNIConfigInstallation,omitempty"`

	// DPUOpenvSwitchSystemSharedLib64Path is the path at which the system lib64 used by OVS components can be found on the DPU.
	// If this field is not set, no lib64 volume mount will be configured in the SFC Controller component.
	// This setting does not change where components are installed. Installation location fixed in the BFB.
	// +optional
	// +kubebuilder:validation:MinLength=1
	DPUOpenvSwitchSystemSharedLib64Path *string `json:"dpuOpenvSwitchSystemSharedLib64Path,omitempty"`

	// DPULinkerCachePath is the path on the DPU at which the prebuilt dynamic-linker cache
	// file can be found. When set, this file is mounted read-only into the SFC Controller
	// container so that host OVS binaries can resolve shared libraries using the DPU's
	// linker configuration. If not set, no linker cache mount is added.
	// This setting does not change where components are installed. Installation location fixed in the BFB.
	// +optional
	// +kubebuilder:validation:MinLength=1
	DPULinkerCachePath *string `json:"dpuLinkerCachePath,omitempty"`

	// DPUOptLibraryPath is the path on the DPU at which an additional library directory
	// can be found. When set, this directory is mounted read-only into the SFC Controller
	// container. Useful on distributions that install vendor libraries outside the standard
	// paths (e.g. /usr/opt on RHCOS BFB). If not set, no additional library directory is mounted.
	// This setting does not change where components are installed. Installation location fixed in the BFB.
	// +optional
	// +kubebuilder:validation:MinLength=1
	DPUOptLibraryPath *string `json:"dpuOptLibraryPath,omitempty"`

	// KubernetesAPIServerVIP is the VIP the Kubernetes API server is accessible at.
	// This setting enables specific underlying components deployed directly or indirectly by the DPF Operator to reach
	// the Kubernetes API Server when the ClusterIP Kubernetes Service is not functional.
	// If set, it should be set to an IP to ensure that components work even if DNS is not available in the cluster.
	// +optional
	KubernetesAPIServerVIP *string `json:"kubernetesAPIServerVIP,omitempty"`

	// KubernetesAPIServerPort is the port the Kubernetes API server is accessible at.
	// This setting is usually used together with the kubernetesAPIServerVIP setting. It enables specific underlying
	// components deployed directly or indirectly by the DPF Operator to reach the Kubernetes API Server when the
	// ClusterIP Kubernetes Service is not functional.
	// +optional
	KubernetesAPIServerPort *int `json:"kubernetesAPIServerPort,omitempty"`

	// ArgoCDNamespace is the namespace where ArgoCD is deployed.
	// AppProjects and cluster secrets required by DPF will be created in this namespace.
	// Defaults to the namespace of the DPFOperatorConfig.
	// +optional
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=63
	ArgoCDNamespace *string `json:"argoCDNamespace,omitempty"`

	// ProvisioningIssuerCASecretName overrides the CA secret used by the provisioning Issuer during
	// controlled CA rotation workflows. When unset, the default issuer secret is used.
	// +optional
	// +kubebuilder:validation:MinLength=1
	ProvisioningIssuerCASecretName *string `json:"provisioningIssuerCASecretName,omitempty"`
}

Overrides exposes a set of fields which impact the recommended behavior of the DPF Operator. These fields should only be set for advanced use cases. The fields here have no stability guarantees.

func (*Overrides) DeepCopy

func (in *Overrides) DeepCopy() *Overrides

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Overrides.

func (*Overrides) DeepCopyInto

func (in *Overrides) DeepCopyInto(out *Overrides)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ProvisioningControllerConfiguration

type ProvisioningControllerConfiguration struct {
	BaseComponentConfig  `json:",inline"`
	BaseControllerConfig `json:",inline"`

	// Image overrides the container image used by the Provisioning controller.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `controller` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// Controller contains the configuration for the Provisioning controller component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Controller *DefaultOverridesConfiguration `json:"controller,omitempty"`

	// BFCFGTemplateConfigMap is the name of a configMap containing a template for the BF.cfg file used by the DPU controller.
	// By default the provisioning controller use a hardcoded BF.cfg e.g. https://github.com/NVIDIA/doca-platform/blob/release-v24.10/internal/provisioning/controllers/dpu/bfcfg/bf.cfg.template
	// Note: Replacing the bf.cfg is an advanced use case. The default bf.cfg is designed for most use cases.
	//
	// Deprecated: BFCFGTemplateConfigMap is deprecated and will be removed in a future release.
	// Use enableDynamicBFCFGTemplates instead for custom bf.cfg templates.
	// +optional
	BFCFGTemplateConfigMap *string `json:"bfCFGTemplateConfigMap,omitempty"`

	// EnableDynamicBFCFGTemplates enables runtime discovery of bf.cfg templates via ConfigMaps.
	// When enabled, the provisioning controller discovers ConfigMaps by matching labels for BFB
	// name/namespace and DPUCluster name/namespace. Mutually exclusive with bfCFGTemplateConfigMap.
	// +optional
	EnableDynamicBFCFGTemplates bool `json:"enableDynamicBFCFGTemplates,omitempty"`

	// BFBPersistentVolumeClaimName is the name of the PersistentVolumeClaim used by dpf-provisioning-controller
	// If not provided, the controller will use local host storage (hostPath)
	// +optional
	BFBPersistentVolumeClaimName *string `json:"bfbPVCName,omitempty"`

	// DMSTimeout is the max time in seconds within which a DMS API must respond, 0 is unlimited
	// +kubebuilder:validation:Minimum=1
	// +optional
	DMSTimeout *int `json:"dmsTimeout,omitempty"`

	// CustomCASecretName indicates the name of the Kubernetes secret object
	// which containing the custom CA certificate
	// +optional
	CustomCASecretName *string `json:"customCASecretName,omitempty"`

	// InstallInterface is the interface through which the BFB is installed
	// +optional
	InstallInterface *ProvisioningInstallInterface `json:"installInterface,omitempty"`

	// Registry is the configuration for the BFB Registry
	// +optional
	Registry *RegistryConfiguration `json:"registry,omitempty"`

	// MaxDPUParallelInstallations specifies the maximum number of DPUs that can be provisioned concurrently.
	// A DPU is removed from the concurrent provisioning count as soon as it finishes the "OS Installing" phase and
	// enters the "Rebooting" phase of its provisioning lifecycle.
	// +kubebuilder:default=50
	// +kubebuilder:validation:Minimum=1
	// +optional
	MaxDPUParallelInstallations *int32 `json:"maxDPUParallelInstallations,omitempty"`

	// MultiDPUOperationsSyncWaitTime is the wait time between DPUs sync operations on the same node.
	// It would take effect only on DPUNode objects which contain more than one DPU.
	// +kubebuilder:default="30s"
	// +kubebuilder:validation:Type=string
	// +kubebuilder:validation:Pattern=`^([0-9]+(h|m|s|ms|us|µs|ns))+$`
	// +kubebuilder:validation:Format=duration
	// +optional
	MultiDPUOperationsSyncWaitTime *metav1.Duration `json:"multiDPUOperationsSyncWaitTime,omitempty"`

	// MaxUnavailableDPUNodes is the maximum number of DPUNodes that are unavailable during the node effect period.
	// It is also used as the maximum number of unavailable DPUs when controlling DPUSet rolling-update deletion.
	// +kubebuilder:default=50
	// +kubebuilder:validation:Minimum=1
	// +optional
	MaxUnavailableDPUNodes *int32 `json:"maxUnavailableDPUNodes,omitempty"`

	// OSInstallRetries is the maximum number of retryable OS installation attempts in zero-trust mode
	// before the DPU transitions to Error. Attempts are counted in-process and reset on controller restart.
	// When unset, the provisioning controller defaults to 2.
	// +kubebuilder:validation:Minimum=1
	// +optional
	OSInstallRetries int32 `json:"osInstallRetries,omitempty"`

	// OSInstallTimeout is the maximum time allowed for OS installation.
	// If the installation exceeds this timeout, the DPU will transition to an error state.
	// When unset, the provisioning controller defaults to 60m.
	// +kubebuilder:validation:Type=string
	// +kubebuilder:validation:Pattern=`^([0-9]+(h|m|s|ms|us|µs|ns))+$`
	// +kubebuilder:validation:Format=duration
	// +optional
	OSInstallTimeout *metav1.Duration `json:"osInstallTimeout,omitempty"`

	// NodeJoinTokenTTL is the lifetime of the kubeadm bootstrap token created for
	// a DPU node to join its DPUCluster. When unset, the provisioning controller
	// defaults to 3h.
	// +kubebuilder:validation:Type=string
	// +kubebuilder:validation:Pattern=`^([0-9]+(h|m|s|ms|us|µs|ns))+$`
	// +kubebuilder:validation:Format=duration
	// +kubebuilder:validation:XValidation:rule="self == null || duration(self) > duration('0s')",message="must be greater than zero"
	// +optional
	NodeJoinTokenTTL *metav1.Duration `json:"nodeJoinTokenTTL,omitempty"`

	// FirmwareUpdateTimeout is the maximum time allowed for BF4 firmware update in zero-trust mode.
	// If the update exceeds this timeout, the DPU will transition to an error state.
	// When unset, the provisioning controller defaults to 45m.
	// +kubebuilder:validation:Type=string
	// +kubebuilder:validation:Pattern=`^([0-9]+(h|m|s|ms|us|µs|ns))+$`
	// +kubebuilder:validation:Format=duration
	// +optional
	FirmwareUpdateTimeout *metav1.Duration `json:"firmwareUpdateTimeout,omitempty"`

	// PreInstallAgentRegistrationTimeout is how long Initializing waits for the in-band dpu-agent
	// to set preInstall.agentReported on a recreated DPU CR (reprovision). When the timeout elapses,
	// provisioning continues without agent-assisted pre-install for this cycle.
	// +kubebuilder:default="30s"
	// +kubebuilder:validation:Type=string
	// +kubebuilder:validation:Pattern=`^([0-9]+(h|m|s|ms|us|µs|ns))+$`
	// +kubebuilder:validation:Format=duration
	// +optional
	PreInstallAgentRegistrationTimeout *metav1.Duration `json:"preInstallAgentRegistrationTimeout,omitempty"`

	// NodeEffectRemovalTimeout is the maximum time allowed for the Node Effect Removal phase.
	// If the DPUNodeMaintenance CR still has requestors after this timeout, the DPU will transition to an error state.
	// When unset, the provisioning controller defaults to 0s (timeout disabled).
	// +kubebuilder:validation:Type=string
	// +kubebuilder:validation:Pattern=`^([0-9]+(h|m|s|ms|us|µs|ns))+$`
	// +kubebuilder:validation:Format=duration
	// +optional
	NodeEffectRemovalTimeout *metav1.Duration `json:"nodeEffectRemovalTimeout,omitempty"`

	// HostAgentDNSPolicy sets the DNS policy for the hostagent pod.
	// Valid values are 'ClusterFirstWithHostNet', 'ClusterFirst', 'Default' or 'None'.
	// Defaults to 'ClusterFirstWithHostNet'.
	// +kubebuilder:validation:Enum=ClusterFirstWithHostNet;ClusterFirst;Default;None
	// +optional
	HostAgentDNSPolicy *corev1.DNSPolicy `json:"hostAgentDNSPolicy,omitempty"`

	// BMCServerCertRenewBefore is how long before expiry DPF rotates the DPU BMC mTLS
	// server certificate.
	// When unset, the provisioning controller defaults to 720h (30 days).
	// +kubebuilder:validation:Type=string
	// +kubebuilder:validation:Pattern=`^([0-9]+(h|m|s|ms|us|µs|ns))+$`
	// +kubebuilder:validation:Format=duration
	// +optional
	BMCServerCertRenewBefore *metav1.Duration `json:"bmcServerCertRenewBefore,omitempty"`
}

func (*ProvisioningControllerConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ProvisioningControllerConfiguration.

func (*ProvisioningControllerConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*ProvisioningControllerConfiguration) GetImage deprecated

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*ProvisioningControllerConfiguration) GetImages

GetImages returns a map of container names to their images

func (*ProvisioningControllerConfiguration) GetResources

func (*ProvisioningControllerConfiguration) Name

type ProvisioningInstallInterface

type ProvisioningInstallInterface struct {
	// InstallViaGNOI is the interface used to install the BFB via GNOI
	//
	// Deprecated: Use InstallViaHostAgent instead.
	// +optional
	InstallViaGNOI *InstallViaGNOI `json:"installViaGNOI,omitempty"`
	// InstallViaHostAgent is the interface used to install the BFB via HostAgent
	// +optional
	InstallViaHostAgent *InstallViaHostAgent `json:"installViaHostAgent,omitempty"`
	// InstallViaRedfish is the interface used to install the BFB via Redfish
	// +optional
	InstallViaRedfish *InstallViaRedfish `json:"installViaRedfish,omitempty"`
}

ProvisioningInstallInterface is the interface used to install the BFB +kubebuilder:validation:XValidation:rule="((has(self.installViaHostAgent) || has(self.installViaGNOI)) && !has(self.installViaRedfish)) || (!has(self.installViaHostAgent) && !has(self.installViaGNOI) && has(self.installViaRedfish))",message="exactly one of installViaHostAgent, installViaGNOI or installViaRedfish must be set"

func (*ProvisioningInstallInterface) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ProvisioningInstallInterface.

func (*ProvisioningInstallInterface) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type RegistryConfiguration

type RegistryConfiguration struct {
	// Address is the address used to access the BFB Registry. The address must start with "http://" or "https://".
	// By default, the BFB Registry can be accessed via its Service.
	// For non-kubernetes environments, this must be set due to the lack of kubelet on worker nodes.
	// For zero-trust environments, this must be set so that the BFB Registry can be accessed from DPU BMC.
	// +kubebuilder:validation:Pattern="^https?://"
	// +optional
	// Deprecated: Address is deprecated and will be removed in a future release.
	Address *string `json:"address,omitempty"`

	// Port is the port on which the registry instances will listen
	// +kubebuilder:validation:Minimum=1
	// +kubebuilder:validation:Maximum=65535
	// +optional
	// Deprecated: Address is deprecated and will be removed in a future release.
	Port *int `json:"port,omitempty"`

	// LoadBalancerAddress is the address of the load balancer for the BFB Registry which the hostagent/redfish use to fetch the BFB and generated bf.cfg.
	// To enable the load balancer, you need to deploy your own load balancer controller and configure the LoadBalancerAddress field.
	// Then check the bfb-registry nodeport service and make your load balancer controller to distribute the requests to the bfb-registry nodeport.
	// +kubebuilder:validation:Pattern="^https?://"
	// +optional
	LoadBalancerAddress *string `json:"loadBalancerAddress,omitempty"`
}

func (*RegistryConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new RegistryConfiguration.

func (*RegistryConfiguration) DeepCopyInto

func (in *RegistryConfiguration) DeepCopyInto(out *RegistryConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ResourceComponentConfig

type ResourceComponentConfig struct {
	// Resources defines the memory and CPU resource requests and limits for the component.
	// This field is optional, and if not set, the component will use the default resource.
	// +optional
	Resources *ResourceRequirements `json:"resources,omitempty"`
}

ResourceComponentConfig defines the resource requirements for a container.

func (*ResourceComponentConfig) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ResourceComponentConfig.

func (*ResourceComponentConfig) DeepCopyInto

func (in *ResourceComponentConfig) DeepCopyInto(out *ResourceComponentConfig)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*ResourceComponentConfig) GetResource

GetResource converts the ResourceComponentConfig to a Kubernetes ResourceRequirements. Returns nil if no resource configuration is specified. Only CPU and Memory resources are supported.

type ResourceRequirements

type ResourceRequirements struct {
	// Requests defines the resource requests for the component.
	Requests *Resources `json:"requests,omitempty"`

	// Limits defines the resource limits for the component.
	Limits *Resources `json:"limits,omitempty"`
}

func (*ResourceRequirements) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ResourceRequirements.

func (*ResourceRequirements) DeepCopyInto

func (in *ResourceRequirements) DeepCopyInto(out *ResourceRequirements)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Resources

type Resources struct {
	// CPU is the amount of CPU requested by the component.
	// +optional
	CPU *resource.Quantity `json:"cpu,omitempty"`

	// Memory is the amount of Memory requested by the component.
	// +optional
	Memory *resource.Quantity `json:"memory,omitempty"`
}

func (*Resources) DeepCopy

func (in *Resources) DeepCopy() *Resources

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Resources.

func (*Resources) DeepCopyInto

func (in *Resources) DeepCopyInto(out *Resources)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ResourcesComponentConfigurable

type ResourcesComponentConfigurable interface {
	// GetResources returns a map of container names to their resource requirements.
	GetResources() map[ContainerName]*corev1.ResourceRequirements
}

ResourcesComponentConfigurable defines configuration for overriding the resources of a component’s containers. Specified at the pod container level. +kubebuilder:object:generate=false

type SFCControllerConfiguration

type SFCControllerConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Image overrides the container image used by the SFC controller.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `controller` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// Controller contains the configuration for the SFC controller component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Controller *DefaultOverridesConfiguration `json:"controller,omitempty"`

	// SecureFlowDeletionTimeout controls the timeout for which the API server is unreachable after which all the flows
	// are deleted to prevent unintended packet leaks. It has effect when is greater than zero.
	// Value must be in units accepted by Go time.ParseDuration https://golang.org/pkg/time/#ParseDuration.
	// +optional
	SecureFlowDeletionTimeout *metav1.Duration `json:"secureFlowDeletionTimeout,omitempty"`
}

SFCControllerConfiguration intentionally does not embed BaseControllerConfig: HA is achieved via per-node sharding (DaemonSet + node-local cache + per-node reconcilers); each pod exclusively owns its node's state, which makes leader election unnecessary.

func (*SFCControllerConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SFCControllerConfiguration.

func (*SFCControllerConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*SFCControllerConfiguration) GetImage deprecated

func (c *SFCControllerConfiguration) GetImage() *string

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*SFCControllerConfiguration) GetImages

func (c *SFCControllerConfiguration) GetImages() map[ContainerName]*string

GetImages returns a map of container names to their images

func (*SFCControllerConfiguration) GetResources

func (*SFCControllerConfiguration) Name

type SPIFFEConfiguration

type SPIFFEConfiguration struct {
	// SPIREServerAddress is the address of the pre-installed SPIRE Server in host:port form
	// (e.g. "spire-server.spire-system.svc:8081").
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=263
	// +required
	SPIREServerAddress string `json:"spireServerAddress,omitempty"`

	// SPIRETrustDomain is the SPIRE-internal trust domain (e.g. "cs.internal") embedded in the
	// DPU Agent SVID URI.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=253
	// +kubebuilder:validation:Pattern=`^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$`
	// +required
	SPIRETrustDomain string `json:"spireTrustDomain,omitempty"`

	// DPUAgentSPIFFEIDTemplate renders the local SPIFFE workload identity registered with SPIRE.
	// It uses Go text/template syntax and receives TrustDomain, normalized SerialNumber, DPUMeta,
	// DPUSpec, DPUDeviceMeta, and DPUDeviceSpec. Metadata labels and annotations can be accessed
	// with the built-in index function.
	// The rendered identity must use SPIRETrustDomain and depend on the DPU serial.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=2048
	// +optional
	DPUAgentSPIFFEIDTemplate string `json:"dpuAgentSPIFFEIDTemplate,omitempty"`

	// DPUAgentExchangedSPIFFEIDTemplate renders the post-exchange SPIFFE ID subject. It receives
	// the same Go template data as DPUAgentSPIFFEIDTemplate.
	// The rendered identity may use a different trust domain and must depend on the DPU serial.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=2048
	// +optional
	DPUAgentExchangedSPIFFEIDTemplate string `json:"dpuAgentExchangedSPIFFEIDTemplate,omitempty"`

	// DPUServiceSPIFFEIDTemplate renders the identity registered with SPIRE for a DPUService that
	// opts in through its own spec.security.spiffe. It receives TrustDomain, normalized
	// SerialNumber, Namespace and ServiceID, plus DPUMeta, DPUSpec, DPUServiceMeta and
	// DPUServiceSpec.
	// The rendered identity must use SPIRETrustDomain and depend on the namespace, the service ID
	// and the DPU serial, which together identify one DPUService workload. Dropping any of them
	// hands a single SVID to distinct workloads, and nothing detects that later: SPIRE keys
	// entries on the identity, the parent and the selectors, so two DPUServices differing only in
	// namespace produce two entries carrying the same identity. A label cannot stand in for the
	// namespace, since nothing ties one to the other.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=2048
	// +optional
	DPUServiceSPIFFEIDTemplate string `json:"dpuServiceSPIFFEIDTemplate,omitempty"`

	// DPUServiceExchangedSPIFFEIDTemplate renders the post-exchange DPUService subject. It
	// receives the same template data as DPUServiceSPIFFEIDTemplate and may use a different trust
	// domain.
	// DPF renders and validates it so the identity layout is declared in one place, but does not
	// consume it: unlike the DPU Agent, a DPUService identity is never presented back to DPF.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=2048
	// +optional
	DPUServiceExchangedSPIFFEIDTemplate string `json:"dpuServiceExchangedSPIFFEIDTemplate,omitempty"`

	// KubeAPIAudience is the audience claim the DPU Agent's JWT-SVID must carry; it must match an
	// entry in the kube-apiserver AuthenticationConfiguration.audiences[] (owned out-of-band).
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=512
	// +required
	KubeAPIAudience string `json:"kubeAPIAudience,omitempty"`

	// tokenExchangeEndpoint exchanges the SPIRE JWT-SVID before the DSX SPIFFE Helper writes it.
	// When omitted, the DSX SPIFFE Helper writes the SPIRE JWT-SVID directly.
	// The returned token's audience must match kubeAPIAudience, or the kube-apiserver rejects the
	// DPU Agent. Only https: the JWT-SVID is sent here as a bearer credential.
	// +kubebuilder:validation:Pattern=`^https://[^[:space:]"\\]+$`
	// +kubebuilder:validation:MaxLength=2048
	// +optional
	TokenExchangeEndpoint *string `json:"tokenExchangeEndpoint,omitempty"`

	// SPIREOIDCURL is the OIDC discovery (issuer) URL of the pre-installed SPIRE Server.
	// The matching kube-apiserver AuthenticationConfiguration.jwt[].issuer value is applied out-of-band.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=2048
	// +required
	SPIREOIDCURL string `json:"spireOIDCURL,omitempty"`

	// spireControllerManagerClassName selects the SPIRE controller-manager instance that renders
	// DPF ClusterStaticEntries.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=253
	// +required
	SPIREControllerManagerClassName string `json:"spireControllerManagerClassName,omitempty"`

	// trustBundle references a ConfigMap holding the initial SPIRE trust bundle.
	// +required
	TrustBundle SPIFFETrustBundleConfigMapReference `json:"trustBundle,omitzero"`
}

SPIFFEConfiguration is the per-cluster SPIFFE bootstrap parameter set

+kubebuilder:validation:XValidation:rule="self.spireServerAddress.matches('^[A-Za-z0-9]([A-Za-z0-9-]*[A-Za-z0-9])?([.][A-Za-z0-9]([A-Za-z0-9-]*[A-Za-z0-9])?)*:[1-9][0-9]{0,4}$')",message="spireServerAddress must be host:port with a valid DNS-1123 host (e.g. spire-server.spire-system.svc:8081)" +kubebuilder:validation:XValidation:rule="!self.spireServerAddress.contains(':') || (int(self.spireServerAddress.split(':')[1]) >= 1 && int(self.spireServerAddress.split(':')[1]) <= 65535)",message="spireServerAddress port must be in 1-65535"

func (*SPIFFEConfiguration) DeepCopy

func (in *SPIFFEConfiguration) DeepCopy() *SPIFFEConfiguration

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SPIFFEConfiguration.

func (*SPIFFEConfiguration) DeepCopyInto

func (in *SPIFFEConfiguration) DeepCopyInto(out *SPIFFEConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SPIFFETrustBundleConfigMapReference

type SPIFFETrustBundleConfigMapReference struct {
	// Name is the name of the ConfigMap holding the SPIRE trust bundle.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=253
	// +required
	Name string `json:"name,omitempty"`

	// Namespace is the namespace of the ConfigMap holding the SPIRE trust bundle.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=63
	// +required
	Namespace string `json:"namespace,omitempty"`

	// Format selects data["bundle.pem"] or data["bundle.spiffe"] and the matching SPIRE Agent parser.
	// +kubebuilder:validation:Enum=pem;spiffe
	// +kubebuilder:default=pem
	// +optional
	Format SPIFFETrustBundleFormat `json:"format,omitempty"`
}

SPIFFETrustBundleConfigMapReference references a ConfigMap containing the initial SPIRE trust bundle.

func (*SPIFFETrustBundleConfigMapReference) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SPIFFETrustBundleConfigMapReference.

func (*SPIFFETrustBundleConfigMapReference) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SPIFFETrustBundleFormat

type SPIFFETrustBundleFormat string

SPIFFETrustBundleFormat is a SPIRE Agent initial trust bundle format.

const (
	SPIFFETrustBundleFormatPEM    SPIFFETrustBundleFormat = "pem"
	SPIFFETrustBundleFormatSPIFFE SPIFFETrustBundleFormat = "spiffe"
)

type SRIOVDevicePluginConfiguration

type SRIOVDevicePluginConfiguration struct {
	BaseComponentConfig `json:",inline"`
	HelmComponentConfig `json:",inline"`

	// Image overrides the container image used by the SRIOV Device Plugin container.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `deviceplugin` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// DevicePlugin contains the configuration for the SRIOV Device Plugin component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	DevicePlugin *DefaultOverridesConfiguration `json:"deviceplugin,omitempty"`

	// ConfigInit contains the configuration for the SR-IOV Device Plugin config-init container.
	// It contains the image for the init container and its resource requirements.
	// +optional
	ConfigInit *DefaultOverridesConfiguration `json:"configInit,omitempty"`
}

func (*SRIOVDevicePluginConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SRIOVDevicePluginConfiguration.

func (*SRIOVDevicePluginConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*SRIOVDevicePluginConfiguration) GetImage deprecated

func (c *SRIOVDevicePluginConfiguration) GetImage() *string

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*SRIOVDevicePluginConfiguration) GetImages

GetImages returns a map of container names to their images

func (*SRIOVDevicePluginConfiguration) GetResources

func (*SRIOVDevicePluginConfiguration) Name

type SecretKeyRef

type SecretKeyRef struct {
	// Name is the name of the Secret.
	// +kubebuilder:validation:MinLength=1
	// +required
	Name string `json:"name,omitempty"`

	// Key is the key within the Secret data to select.
	// +kubebuilder:validation:MinLength=1
	// +required
	Key string `json:"key,omitempty"`
}

SecretKeyRef selects a single key from a Secret living in the same namespace as the DPFOperatorConfig.

func (*SecretKeyRef) DeepCopy

func (in *SecretKeyRef) DeepCopy() *SecretKeyRef

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecretKeyRef.

func (*SecretKeyRef) DeepCopyInto

func (in *SecretKeyRef) DeepCopyInto(out *SecretKeyRef)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SecurityConfiguration

type SecurityConfiguration struct {
	// PrivilegedPodEnforcement controls whether privileged pods are rejected
	// unless explicitly allowed by the workload API. The DPUService controller
	// currently implements this by applying the PrivilegedPodEnforcement
	// ValidatingAdmissionPolicy to DPUService workloads.
	//
	// Setting it to false does not fully opt out of enforcement: the policy and its
	// binding are kept, but the binding is switched from Deny to Audit, so privileged
	// pods are no longer denied and are only recorded in the audit log. The allowlist
	// is kept populated so the audit log only flags pods that would otherwise be
	// denied.
	//
	// The objects are intentionally not deleted to avoid a Kubernetes paramRef
	// informer bug (https://github.com/kubernetes/kubernetes/issues/133827).
	//
	// Defaults to true.
	// +kubebuilder:default=true
	// +optional
	PrivilegedPodEnforcement *bool `json:"privilegedPodEnforcement,omitempty"`

	// Kata is the configuration for Kata Containers.
	// Kata Containers provides VM-based isolation for untrusted workloads on DPU nodes.
	// This component is disabled by default; set disable to false to enable.
	// +optional
	Kata *KataContainersConfiguration `json:"kata,omitempty"`

	// spiffe configures the SPIFFE-based DPU Agent identity flow. Edits are accepted post-bootstrap
	// but do NOT retro-apply to already-provisioned DPUs.
	// +optional
	SPIFFE *SPIFFEConfiguration `json:"spiffe,omitempty"`

	// VaultKMS is the configuration for the standalone Vault/OpenBao KMS plugin component.
	// It is deployed as a DaemonSet on control-plane nodes and is disabled by default.
	// The plugin is used for encryption at rest for DPUClusters.
	// +optional
	VaultKMS *VaultKMSConfiguration `json:"vaultKMS,omitempty"`
}

SecurityConfiguration groups configuration for security-related configurations managed by the DPF Operator.

func (*SecurityConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SecurityConfiguration.

func (*SecurityConfiguration) DeepCopyInto

func (in *SecurityConfiguration) DeepCopyInto(out *SecurityConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*SecurityConfiguration) PrivilegedPodEnforcementEnabled

func (s *SecurityConfiguration) PrivilegedPodEnforcementEnabled() bool

PrivilegedPodEnforcementEnabled reports whether privileged pod enforcement is enabled. Returns true when Security is nil, PrivilegedPodEnforcement is nil, or it is true.

type ServiceSetControllerConfiguration

type ServiceSetControllerConfiguration struct {
	BaseComponentConfig  `json:",inline"`
	BaseControllerConfig `json:",inline"`
	HelmComponentConfig  `json:",inline"`

	// Image overrides the container image used by the ServiceChainSet Controller.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `controller` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// Controller contains the configuration for the ServiceChainSet controller component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Controller *DefaultOverridesConfiguration `json:"controller,omitempty"`
}

func (*ServiceSetControllerConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ServiceSetControllerConfiguration.

func (*ServiceSetControllerConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*ServiceSetControllerConfiguration) GetImage deprecated

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*ServiceSetControllerConfiguration) GetImages

GetImages returns a map of container names to their images

func (*ServiceSetControllerConfiguration) GetResources

func (*ServiceSetControllerConfiguration) Name

type StaticClusterManagerConfiguration

type StaticClusterManagerConfiguration struct {
	BaseComponentConfig  `json:",inline"`
	BaseControllerConfig `json:",inline"`

	// Image overrides the container image used by the Static Cluster Manager.
	//
	// Deprecated: This field is deprecated and will be removed with v27.1.0.
	// Use the new field `controller` instead.
	// +optional
	Image Image `json:"image,omitempty"`

	// Controller contains the configuration for the Static Cluster Manager controller component.
	// It contains the image for the controller and its resource requirements.
	// +optional
	Controller *DefaultOverridesConfiguration `json:"controller,omitempty"`
}

func (*StaticClusterManagerConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new StaticClusterManagerConfiguration.

func (*StaticClusterManagerConfiguration) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*StaticClusterManagerConfiguration) GetImage deprecated

Deprecated: This method is deprecated and will be removed with v27.1.0. Use GetImages instead.

func (*StaticClusterManagerConfiguration) GetImages

GetImages returns a map of container names to their images

func (*StaticClusterManagerConfiguration) GetResources

func (*StaticClusterManagerConfiguration) Name

type StaticKeyConfiguration

type StaticKeyConfiguration struct {
	// KeySecretRef selects the AES-GCM key from a Secret in the DPFOperatorConfig namespace.
	// The referenced Secret value must be base64-encoded AES key text whose decoded length is 16,
	// 24, or 32 bytes. For Kubernetes manifests, use stringData.key with the output of
	// `openssl rand -base64 32`. For External Secrets, configure the external value or template so
	// the resulting Kubernetes Secret data decodes to that base64 text, not to raw key bytes.
	// The referenced key is used as the desired static key source. Changing the referenced
	// Secret value triggers automatic rotation for existing staticKey-encrypted Kamaji clusters.
	// The per-cluster rendered encryption configuration must be backed up together with the
	// cluster etcd backup because Kubernetes encrypted data references encryption config key names.
	// +required
	KeySecretRef SecretKeyRef `json:"keySecretRef,omitzero"`

	// AutomaticRotationDisabled disables automatic staticKey rotation for existing Kamaji clusters.
	// In-flight rotations stop at the next stable checkpoint; encryption at rest remains enabled.
	// +optional
	AutomaticRotationDisabled *bool `json:"automaticRotationDisabled,omitempty"`
}

StaticKeyConfiguration configures the staticKey encryption-at-rest provider.

func (*StaticKeyConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new StaticKeyConfiguration.

func (*StaticKeyConfiguration) DeepCopyInto

func (in *StaticKeyConfiguration) DeepCopyInto(out *StaticKeyConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type VaultKMSAppRoleAuth

type VaultKMSAppRoleAuth struct {
	// SecretName is the name of the Secret holding the AppRole role ID and secret ID.
	// +kubebuilder:validation:MinLength=1
	// +required
	SecretName string `json:"secretName,omitempty"`

	// AuthEngineMountPath optionally overrides the Vault auth engine mount path. It is not the transit mount.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=512
	// +optional
	AuthEngineMountPath *string `json:"authEngineMountPath,omitempty"`

	// RoleIDKey is the Secret data key holding the AppRole role ID.
	// +kubebuilder:validation:MinLength=1
	// +required
	RoleIDKey string `json:"roleIDKey,omitempty"`

	// SecretIDKey is the Secret data key holding the AppRole secret ID.
	// +kubebuilder:validation:MinLength=1
	// +required
	SecretIDKey string `json:"secretIDKey,omitempty"`
}

VaultKMSAppRoleAuth configures the AppRole auth method using a single merged Secret.

func (*VaultKMSAppRoleAuth) DeepCopy

func (in *VaultKMSAppRoleAuth) DeepCopy() *VaultKMSAppRoleAuth

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSAppRoleAuth.

func (*VaultKMSAppRoleAuth) DeepCopyInto

func (in *VaultKMSAppRoleAuth) DeepCopyInto(out *VaultKMSAppRoleAuth)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type VaultKMSAuth

type VaultKMSAuth struct {
	// Method selects the Vault auth method.
	// +required
	Method VaultKMSAuthMethod `json:"method,omitempty"`

	// Token configures token auth.
	// +optional
	Token *VaultKMSTokenAuth `json:"token,omitempty"`

	// AppRole configures AppRole auth.
	// +optional
	AppRole *VaultKMSAppRoleAuth `json:"appRole,omitempty"`

	// Userpass configures userpass auth.
	// +optional
	Userpass *VaultKMSUserpassAuth `json:"userpass,omitempty"`

	// Kubernetes configures Kubernetes auth.
	// +optional
	Kubernetes *VaultKMSKubernetesAuth `json:"kubernetes,omitempty"`

	// JWT configures JWT auth.
	// +optional
	JWT *VaultKMSJWTAuth `json:"jwt,omitempty"`
}

VaultKMSAuth configures the Vault/OpenBao auth method. Exactly one auth block matching method must be set. +kubebuilder:validation:XValidation:rule="self.method != 'token' || has(self.token)",message="token is required when method is token" +kubebuilder:validation:XValidation:rule="self.method == 'token' || !has(self.token)",message="token must only be set when method is token" +kubebuilder:validation:XValidation:rule="self.method != 'approle' || has(self.appRole)",message="appRole is required when method is approle" +kubebuilder:validation:XValidation:rule="self.method == 'approle' || !has(self.appRole)",message="appRole must only be set when method is approle" +kubebuilder:validation:XValidation:rule="self.method != 'userpass' || has(self.userpass)",message="userpass is required when method is userpass" +kubebuilder:validation:XValidation:rule="self.method == 'userpass' || !has(self.userpass)",message="userpass must only be set when method is userpass" +kubebuilder:validation:XValidation:rule="self.method != 'kubernetes' || has(self.kubernetes)",message="kubernetes is required when method is kubernetes" +kubebuilder:validation:XValidation:rule="self.method == 'kubernetes' || !has(self.kubernetes)",message="kubernetes must only be set when method is kubernetes" +kubebuilder:validation:XValidation:rule="self.method != 'jwt' || has(self.jwt)",message="jwt is required when method is jwt" +kubebuilder:validation:XValidation:rule="self.method == 'jwt' || !has(self.jwt)",message="jwt must only be set when method is jwt"

func (*VaultKMSAuth) DeepCopy

func (in *VaultKMSAuth) DeepCopy() *VaultKMSAuth

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSAuth.

func (*VaultKMSAuth) DeepCopyInto

func (in *VaultKMSAuth) DeepCopyInto(out *VaultKMSAuth)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type VaultKMSAuthMethod

type VaultKMSAuthMethod string

VaultKMSAuthMethod selects the Vault/OpenBao auth method used by the KMS plugin. +kubebuilder:validation:Enum=token;approle;userpass;kubernetes;jwt

const (
	// VaultKMSAuthMethodToken authenticates using a Vault token.
	VaultKMSAuthMethodToken VaultKMSAuthMethod = "token"
	// VaultKMSAuthMethodAppRole authenticates using the AppRole auth method.
	VaultKMSAuthMethodAppRole VaultKMSAuthMethod = "approle"
	// VaultKMSAuthMethodUserpass authenticates using the userpass auth method.
	VaultKMSAuthMethodUserpass VaultKMSAuthMethod = "userpass"
	// VaultKMSAuthMethodKubernetes authenticates using the Kubernetes auth method.
	VaultKMSAuthMethodKubernetes VaultKMSAuthMethod = "kubernetes"
	// VaultKMSAuthMethodJWT authenticates using the JWT auth method.
	VaultKMSAuthMethodJWT VaultKMSAuthMethod = "jwt"
)

type VaultKMSConfiguration

type VaultKMSConfiguration struct {
	BaseComponentConfig `json:",inline"`

	// Daemon contains the image and resource overrides for the KMS plugin DaemonSet.
	// +optional
	Daemon *DefaultOverridesConfiguration `json:"daemon,omitempty"`

	// TLS configures TLS settings used to connect to Vault/OpenBao.
	// +optional
	TLS *VaultKMSTLS `json:"tls,omitempty"`

	// Auth configures how the plugin authenticates to Vault/OpenBao.
	// +required
	Auth VaultKMSAuth `json:"auth,omitzero"`

	// TokenCheckIntervalSeconds optionally overrides how often the plugin checks and renews the current Vault token, in seconds.
	// This is an advanced setting. The plugin default should work for most environments.
	// Must be at least 5 seconds.
	// +kubebuilder:validation:Minimum=5
	// +optional
	TokenCheckIntervalSeconds *int32 `json:"tokenCheckIntervalSeconds,omitempty"`

	// LoginTimeoutSeconds optionally overrides the maximum time for one Vault token check cycle, including authentication, in seconds.
	// This is an advanced setting. The plugin default should work for most environments.
	// Must be at least 1 second.
	// +kubebuilder:validation:Minimum=1
	// +optional
	LoginTimeoutSeconds *int32 `json:"loginTimeoutSeconds,omitempty"`

	// Address is the Vault/OpenBao server address.
	// WARNING: Changing this field does not automatically rotate the encryption key or
	// re-encrypt existing DPU cluster secrets. Do not change it while active DPU clusters
	// depend on this KMS plugin unless the new endpoint provides access to the key material
	// used by the previous endpoint. Otherwise, those clusters will be unable to decrypt
	// their existing secrets, causing an outage.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=2048
	// +kubebuilder:validation:Pattern=`^https://.+$`
	// +required
	Address string `json:"address,omitempty"`

	// Transit configures the Vault Transit secrets engine used for encrypt/decrypt.
	// WARNING: Changing this field does not automatically rotate the encryption key or
	// re-encrypt existing DPU cluster secrets. Do not change it while active DPU clusters
	// depend on this KMS plugin unless the new Transit configuration provides access to all
	// key material used by the previous configuration. Otherwise, those clusters will be
	// unable to decrypt their existing secrets, causing an outage.
	// +required
	Transit VaultKMSTransit `json:"transit,omitzero"`

	// Namespace optionally configures the Vault/OpenBao namespace used for requests.
	// This is a Vault/OpenBao namespace, not a Kubernetes namespace.
	// WARNING: Changing this field does not automatically rotate the encryption key or
	// re-encrypt existing DPU cluster secrets. Do not change it while active DPU clusters
	// depend on this KMS plugin unless the new namespace provides access to the key material
	// used by the previous namespace. Otherwise, those clusters will be unable to decrypt
	// their existing secrets, causing an outage.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=512
	// +optional
	Namespace *string `json:"namespace,omitempty"`
}

VaultKMSConfiguration configures the standalone Vault/OpenBao KMS plugin component. The component is deployed as a DaemonSet on control-plane nodes and is disabled by default. The plugin is used for encryption at rest for DPUClusters.

func (*VaultKMSConfiguration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSConfiguration.

func (*VaultKMSConfiguration) DeepCopyInto

func (in *VaultKMSConfiguration) DeepCopyInto(out *VaultKMSConfiguration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*VaultKMSConfiguration) GetImages

func (c *VaultKMSConfiguration) GetImages() map[ContainerName]*string

GetImages returns a map of container names to their images.

func (*VaultKMSConfiguration) GetResources

GetResources returns a map of container names to their resource requirements.

func (*VaultKMSConfiguration) Name

func (c *VaultKMSConfiguration) Name() string

type VaultKMSJWTAuth

type VaultKMSJWTAuth struct {
	// Role is the Vault JWT auth role name.
	// +kubebuilder:validation:MinLength=1
	// +required
	Role string `json:"role,omitempty"`

	// JWTSecretRef selects the JWT presented to Vault from a Secret in the DPFOperatorConfig namespace.
	// +required
	JWTSecretRef SecretKeyRef `json:"jwtSecretRef,omitzero"`

	// AuthEngineMountPath optionally overrides the Vault auth engine mount path. It is not the transit mount.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=512
	// +optional
	AuthEngineMountPath *string `json:"authEngineMountPath,omitempty"`
}

VaultKMSJWTAuth configures the JWT auth method.

func (*VaultKMSJWTAuth) DeepCopy

func (in *VaultKMSJWTAuth) DeepCopy() *VaultKMSJWTAuth

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSJWTAuth.

func (*VaultKMSJWTAuth) DeepCopyInto

func (in *VaultKMSJWTAuth) DeepCopyInto(out *VaultKMSJWTAuth)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type VaultKMSKubernetesAuth

type VaultKMSKubernetesAuth struct {
	// Role is the Vault Kubernetes auth role name (not a Kubernetes RBAC role).
	// +kubebuilder:validation:MinLength=1
	// +required
	Role string `json:"role,omitempty"`

	// Audience optionally sets the audience for the projected Kubernetes service account token.
	// Use this when the Vault Kubernetes auth role is configured with bound audiences.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=512
	// +optional
	Audience *string `json:"audience,omitempty"`

	// AuthEngineMountPath optionally overrides the Vault auth engine mount path. It is not the transit mount.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=512
	// +optional
	AuthEngineMountPath *string `json:"authEngineMountPath,omitempty"`
}

VaultKMSKubernetesAuth configures the Kubernetes auth method.

func (*VaultKMSKubernetesAuth) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSKubernetesAuth.

func (*VaultKMSKubernetesAuth) DeepCopyInto

func (in *VaultKMSKubernetesAuth) DeepCopyInto(out *VaultKMSKubernetesAuth)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type VaultKMSTLS

type VaultKMSTLS struct {
	// CACertConfigMapRef selects a CA bundle key from a ConfigMap used to verify the
	// Vault/OpenBao server certificate. It is mounted as a file.
	// +optional
	CACertConfigMapRef *ConfigMapKeyRef `json:"caConfigMapRef,omitempty"`
}

VaultKMSTLS configures TLS settings for the connection to Vault/OpenBao.

func (*VaultKMSTLS) DeepCopy

func (in *VaultKMSTLS) DeepCopy() *VaultKMSTLS

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSTLS.

func (*VaultKMSTLS) DeepCopyInto

func (in *VaultKMSTLS) DeepCopyInto(out *VaultKMSTLS)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type VaultKMSTokenAuth

type VaultKMSTokenAuth struct {
	// TokenSecretRef selects the Vault token from a Secret in the DPFOperatorConfig namespace.
	// +required
	TokenSecretRef SecretKeyRef `json:"tokenSecretRef,omitzero"`
}

VaultKMSTokenAuth configures the token auth method.

func (*VaultKMSTokenAuth) DeepCopy

func (in *VaultKMSTokenAuth) DeepCopy() *VaultKMSTokenAuth

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSTokenAuth.

func (*VaultKMSTokenAuth) DeepCopyInto

func (in *VaultKMSTokenAuth) DeepCopyInto(out *VaultKMSTokenAuth)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type VaultKMSTransit

type VaultKMSTransit struct {
	// KeyName is the Transit key used for encrypt and decrypt operations.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:Pattern=`^\w(([\w-.]+)?\w)?$`
	// +required
	KeyName string `json:"keyName,omitempty"`

	// Mount is the Transit secrets engine mount path. Defaults to "transit".
	// +kubebuilder:default="transit"
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=512
	// +kubebuilder:validation:Pattern=`^/?[^/\s][^\s]*$`
	// +optional
	Mount *string `json:"mount,omitempty"`
}

VaultKMSTransit configures the Vault Transit secrets engine.

func (*VaultKMSTransit) DeepCopy

func (in *VaultKMSTransit) DeepCopy() *VaultKMSTransit

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSTransit.

func (*VaultKMSTransit) DeepCopyInto

func (in *VaultKMSTransit) DeepCopyInto(out *VaultKMSTransit)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type VaultKMSUserpassAuth

type VaultKMSUserpassAuth struct {
	// SecretName is the name of the Secret holding the username and password.
	// +kubebuilder:validation:MinLength=1
	// +required
	SecretName string `json:"secretName,omitempty"`

	// AuthEngineMountPath optionally overrides the Vault auth engine mount path. It is not the transit mount.
	// +kubebuilder:validation:MinLength=1
	// +kubebuilder:validation:MaxLength=512
	// +optional
	AuthEngineMountPath *string `json:"authEngineMountPath,omitempty"`

	// UsernameKey is the Secret data key holding the username.
	// +kubebuilder:validation:MinLength=1
	// +required
	UsernameKey string `json:"usernameKey,omitempty"`

	// PasswordKey is the Secret data key holding the password.
	// +kubebuilder:validation:MinLength=1
	// +required
	PasswordKey string `json:"passwordKey,omitempty"`
}

VaultKMSUserpassAuth configures the userpass auth method using a single merged Secret.

func (*VaultKMSUserpassAuth) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new VaultKMSUserpassAuth.

func (*VaultKMSUserpassAuth) DeepCopyInto

func (in *VaultKMSUserpassAuth) DeepCopyInto(out *VaultKMSUserpassAuth)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL