v1alpha1

package
v1.0.0-alpha.21 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package v1alpha1 contains API Schema definitions for the opmodel.dev v1alpha1 API group. +kubebuilder:object:generate=true +groupName=opmodel.dev

Index

Constants

View Source
const (
	// SkewPolicyWarn renders against the platform's build and reports the
	// skew. The default.
	SkewPolicyWarn = "Warn"

	// SkewPolicyRefuse refuses the render before evaluation.
	SkewPolicyRefuse = "Refuse"
)

Skew policy values for PlatformSpec.SkewPolicy.

View Source
const AnnotationForceDeleteOrphan = "opm.dev/force-delete-orphan"

AnnotationForceDeleteOrphan is the release annotation that, when set to "true", releases a finalizer stuck in the DeletionSAMissing stall by skipping prune and orphaning the managed inventory. Any value other than the literal string "true" is treated as absent.

Variables

View Source
var (
	// GroupVersion is group version used to register these objects.
	GroupVersion = schema.GroupVersion{Group: "opmodel.dev", Version: "v1alpha1"}

	// SchemeBuilder is used to add go types to the GroupVersionKind scheme.
	// Uses the apimachinery builder directly rather than the deprecated
	// sigs.k8s.io/controller-runtime/pkg/scheme.Builder convenience wrapper
	// (deprecated in controller-runtime v0.24.0).
	SchemeBuilder = runtime.NewSchemeBuilder(addToGroupVersion)

	// AddToScheme adds the types in this group-version to the given scheme.
	AddToScheme = SchemeBuilder.AddToScheme
)

Functions

This section is empty.

Types

type FailureCounters

type FailureCounters struct {
	// +optional
	Reconcile int64 `json:"reconcile,omitempty"`

	// +optional
	Apply int64 `json:"apply,omitempty"`

	// +optional
	Prune int64 `json:"prune,omitempty"`

	// +optional
	Drift int64 `json:"drift,omitempty"`
}

FailureCounters tracks bounded reconcile failure counts by action.

func (*FailureCounters) DeepCopy

func (in *FailureCounters) DeepCopy() *FailureCounters

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new FailureCounters.

func (*FailureCounters) DeepCopyInto

func (in *FailureCounters) DeepCopyInto(out *FailureCounters)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type HistoryEntry

type HistoryEntry struct {
	// +optional
	Sequence int64 `json:"sequence,omitempty"`

	// +optional
	Action string `json:"action,omitempty"`

	// +optional
	Phase string `json:"phase,omitempty"`

	// +optional
	StartedAt *metav1.Time `json:"startedAt,omitempty"`

	// +optional
	FinishedAt *metav1.Time `json:"finishedAt,omitempty"`

	// +optional
	SourceDigest string `json:"sourceDigest,omitempty"`

	// +optional
	ConfigDigest string `json:"configDigest,omitempty"`

	// +optional
	RenderDigest string `json:"renderDigest,omitempty"`

	// +optional
	InventoryDigest string `json:"inventoryDigest,omitempty"`

	// +optional
	InventoryCount int64 `json:"inventoryCount,omitempty"`

	// +optional
	Message string `json:"message,omitempty"`
}

HistoryEntry captures a compact reconcile history record.

func (*HistoryEntry) DeepCopy

func (in *HistoryEntry) DeepCopy() *HistoryEntry

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new HistoryEntry.

func (*HistoryEntry) DeepCopyInto

func (in *HistoryEntry) DeepCopyInto(out *HistoryEntry)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Inventory

type Inventory struct {
	// +optional
	Revision int64 `json:"revision,omitempty"`

	// +optional
	Digest string `json:"digest,omitempty"`

	// +optional
	Count int64 `json:"count,omitempty"`

	// +optional
	Entries []InventoryEntry `json:"entries,omitempty"`
}

Inventory stores the current set of owned resources.

func (*Inventory) DeepCopy

func (in *Inventory) DeepCopy() *Inventory

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Inventory.

func (*Inventory) DeepCopyInto

func (in *Inventory) DeepCopyInto(out *Inventory)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type InventoryEntry

type InventoryEntry struct {
	// +optional
	Group string `json:"group,omitempty"`

	Kind string `json:"kind"`

	// +optional
	Namespace string `json:"namespace,omitempty"`

	Name string `json:"name"`

	// +optional
	Version string `json:"v,omitempty"`

	// +optional
	Component string `json:"component,omitempty"`
}

InventoryEntry identifies one owned Kubernetes resource.

func (*InventoryEntry) DeepCopy

func (in *InventoryEntry) DeepCopy() *InventoryEntry

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InventoryEntry.

func (*InventoryEntry) DeepCopyInto

func (in *InventoryEntry) DeepCopyInto(out *InventoryEntry)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ModuleInstance

type ModuleInstance struct {
	metav1.TypeMeta `json:",inline"`

	// metadata is a standard object metadata
	// +optional
	metav1.ObjectMeta `json:"metadata,omitzero"`

	// spec defines the desired state of ModuleInstance
	// +required
	Spec ModuleInstanceSpec `json:"spec"`

	// status defines the observed state of ModuleInstance
	// +optional
	Status ModuleInstanceStatus `json:"status,omitzero"`
}

ModuleInstance is the Schema for the moduleinstances API

func (*ModuleInstance) DeepCopy

func (in *ModuleInstance) DeepCopy() *ModuleInstance

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleInstance.

func (*ModuleInstance) DeepCopyInto

func (in *ModuleInstance) DeepCopyInto(out *ModuleInstance)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*ModuleInstance) DeepCopyObject

func (in *ModuleInstance) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*ModuleInstance) GetConditions

func (in *ModuleInstance) GetConditions() []metav1.Condition

GetConditions returns the status conditions of the ModuleInstance.

func (*ModuleInstance) SetConditions

func (in *ModuleInstance) SetConditions(conditions []metav1.Condition)

SetConditions sets the status conditions on the ModuleInstance.

type ModuleInstanceList

type ModuleInstanceList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitzero"`
	Items           []ModuleInstance `json:"items"`
}

ModuleInstanceList contains a list of ModuleInstance

func (*ModuleInstanceList) DeepCopy

func (in *ModuleInstanceList) DeepCopy() *ModuleInstanceList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleInstanceList.

func (*ModuleInstanceList) DeepCopyInto

func (in *ModuleInstanceList) DeepCopyInto(out *ModuleInstanceList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*ModuleInstanceList) DeepCopyObject

func (in *ModuleInstanceList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type ModuleInstanceSpec

type ModuleInstanceSpec struct {
	// +optional
	Suspend bool `json:"suspend,omitempty"`

	// Owner identifies which actor manages this instance. An absent, empty, or
	// "operator" value means operator-managed: the controller reconciles
	// normally. Only an explicit "cli" makes the operator skip the instance
	// (no render/apply/prune, no finalizer) and record a single
	// ManagedExternally acknowledgement. There is no CRD default; the
	// reconciler carries the operator-managed default semantics.
	// +kubebuilder:validation:Enum=cli;operator
	// +optional
	Owner OwnerType `json:"owner,omitempty"`

	// Module identifies the CUE module to evaluate from the OCI registry.
	Module ModuleReference `json:"module"`

	// Values contains arbitrary release input values.
	// +optional
	Values *RawValues `json:"values,omitempty"`

	// +optional
	Prune bool `json:"prune,omitempty"`

	// +optional
	ServiceAccountName string `json:"serviceAccountName,omitempty"`

	// +optional
	Rollout *RolloutSpec `json:"rollout,omitempty"`
}

ModuleInstanceSpec defines the desired state of ModuleInstance

func (*ModuleInstanceSpec) DeepCopy

func (in *ModuleInstanceSpec) DeepCopy() *ModuleInstanceSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleInstanceSpec.

func (*ModuleInstanceSpec) DeepCopyInto

func (in *ModuleInstanceSpec) DeepCopyInto(out *ModuleInstanceSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ModuleInstanceStatus

type ModuleInstanceStatus struct {
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`

	// InstanceUUID is the globally-unique identity of the rendered ModuleInstance,
	// read from the `module-instance.opmodel.dev/uuid` label on rendered resources.
	// Populated on the first successful render; consumed by the prune ownership
	// guard (including the deletion path where a fresh render is not available).
	// +optional
	InstanceUUID string `json:"instanceUUID,omitempty"`

	// conditions represent the current state of the ModuleInstance resource.
	// Each condition has a unique type and reflects the status of a specific aspect of the resource.
	//
	// Standard condition types include:
	// - "Available": the resource is fully functional
	// - "Progressing": the resource is being created or updated
	// - "Degraded": the resource failed to reach or maintain its desired state
	//
	// The status of each condition is one of True, False, or Unknown.
	// +listType=map
	// +listMapKey=type
	// +optional
	Conditions []metav1.Condition `json:"conditions,omitempty"`

	// +optional
	LastAttemptedAction string `json:"lastAttemptedAction,omitempty"`

	// +optional
	LastAttemptedAt *metav1.Time `json:"lastAttemptedAt,omitempty"`

	// +optional
	LastAttemptedDuration *metav1.Duration `json:"lastAttemptedDuration,omitempty"`

	// +optional
	LastAttemptedSourceDigest string `json:"lastAttemptedSourceDigest,omitempty"`

	// +optional
	LastAttemptedConfigDigest string `json:"lastAttemptedConfigDigest,omitempty"`

	// +optional
	LastAttemptedRenderDigest string `json:"lastAttemptedRenderDigest,omitempty"`

	// +optional
	LastAppliedAt *metav1.Time `json:"lastAppliedAt,omitempty"`

	// +optional
	LastAppliedSourceDigest string `json:"lastAppliedSourceDigest,omitempty"`

	// +optional
	LastAppliedConfigDigest string `json:"lastAppliedConfigDigest,omitempty"`

	// +optional
	LastAppliedRenderDigest string `json:"lastAppliedRenderDigest,omitempty"`

	// +optional
	FailureCounters *FailureCounters `json:"failureCounters,omitempty"`

	// +optional
	Inventory *Inventory `json:"inventory,omitempty"`

	// RequiredContracts lists every contract FQN this instance's components
	// declare, sorted and deduplicated, as the last successful render
	// reported them. It is the instance side of the removal guard
	// (0015:D3, D16): a TransformerRegistration counts its
	// dependents by intersecting this with its own spec.provides, so a
	// provider cannot be deleted, or shrink its provides, out from under
	// the instances still demanding what it serves.
	//
	// Derived, never authored. The contracts are read off the synthesized
	// instance's components, which is the same keyspace the render's
	// matching compares, so nothing a module author writes into spec can
	// raise or lower the count. A reconcile that does not render — a failed
	// render, a suspended instance, a CLI-owned one — leaves the previous
	// value: a stale entry over-reports demand and blocks a deletion that
	// could have proceeded, which is the safe direction for a guard.
	// +listType=atomic
	// +optional
	RequiredContracts []string `json:"requiredContracts,omitempty"`

	// +optional
	History []HistoryEntry `json:"history,omitempty"`

	// NextRetryAt indicates when the controller will next attempt reconciliation
	// after a transient or stalled failure. Nil when the resource is healthy or no-op.
	// +optional
	NextRetryAt *metav1.Time `json:"nextRetryAt,omitempty"`
}

ModuleInstanceStatus defines the observed state of ModuleInstance.

func (*ModuleInstanceStatus) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleInstanceStatus.

func (*ModuleInstanceStatus) DeepCopyInto

func (in *ModuleInstanceStatus) DeepCopyInto(out *ModuleInstanceStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ModulePackage

type ModulePackage struct {
	metav1.TypeMeta `json:",inline"`

	// metadata is a standard object metadata
	// +optional
	metav1.ObjectMeta `json:"metadata,omitzero"`

	// spec defines the desired state of ModulePackage
	// +required
	Spec ModulePackageSpec `json:"spec"`

	// status defines the observed state of ModulePackage
	// +optional
	Status ModulePackageStatus `json:"status,omitzero"`
}

ModulePackage is the Schema for the modulepackages API.

func (*ModulePackage) DeepCopy

func (in *ModulePackage) DeepCopy() *ModulePackage

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModulePackage.

func (*ModulePackage) DeepCopyInto

func (in *ModulePackage) DeepCopyInto(out *ModulePackage)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*ModulePackage) DeepCopyObject

func (in *ModulePackage) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*ModulePackage) GetConditions

func (in *ModulePackage) GetConditions() []metav1.Condition

GetConditions returns the status conditions of the ModulePackage.

func (*ModulePackage) SetConditions

func (in *ModulePackage) SetConditions(conditions []metav1.Condition)

SetConditions sets the status conditions on the ModulePackage.

type ModulePackageList

type ModulePackageList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitzero"`
	Items           []ModulePackage `json:"items"`
}

ModulePackageList contains a list of ModulePackage.

func (*ModulePackageList) DeepCopy

func (in *ModulePackageList) DeepCopy() *ModulePackageList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModulePackageList.

func (*ModulePackageList) DeepCopyInto

func (in *ModulePackageList) DeepCopyInto(out *ModulePackageList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*ModulePackageList) DeepCopyObject

func (in *ModulePackageList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type ModulePackageSpec

type ModulePackageSpec struct {
	// SourceRef references a Flux source (OCIRepository, GitRepository, or Bucket)
	// that provides the artifact containing the CUE package.
	SourceRef SourceReference `json:"sourceRef"`

	// Path is the directory within the artifact containing instance.cue.
	// Example: "releases/prod/minecraft".
	// +kubebuilder:validation:MinLength=1
	Path string `json:"path"`

	// Interval at which the reconciler re-evaluates the package to detect drift
	// and re-apply. Also the requeue interval after transient failures.
	// +optional
	Interval metav1.Duration `json:"interval,omitempty"`

	// DependsOn references other ModulePackage CRs that must be Ready=True before
	// this ModulePackage is reconciled. References are same-namespace only.
	// +optional
	DependsOn []fluxmeta.NamespacedObjectReference `json:"dependsOn,omitempty"`

	// Prune enables deletion of stale resources on reconcile and of all owned
	// resources on ModulePackage deletion.
	// +optional
	Prune bool `json:"prune,omitempty"`

	// Suspend halts reconciliation when true.
	// +optional
	Suspend bool `json:"suspend,omitempty"`

	// ServiceAccountName is the name of the ServiceAccount used to impersonate
	// during apply and prune. Empty means use the controller's identity.
	// +optional
	ServiceAccountName string `json:"serviceAccountName,omitempty"`

	// Rollout configures apply behavior.
	// +optional
	Rollout *RolloutSpec `json:"rollout,omitempty"`
}

ModulePackageSpec defines the desired state of ModulePackage. A ModulePackage points to a Flux source artifact containing a CUE package. The controller fetches the artifact, navigates to spec.path, loads instance.cue, and renders it when it evaluates to #ModuleInstance; any other kind is rejected as unsupported.

func (*ModulePackageSpec) DeepCopy

func (in *ModulePackageSpec) DeepCopy() *ModulePackageSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModulePackageSpec.

func (*ModulePackageSpec) DeepCopyInto

func (in *ModulePackageSpec) DeepCopyInto(out *ModulePackageSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ModulePackageStatus

type ModulePackageStatus struct {
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`

	// conditions represent the current state of the ModulePackage resource.
	// +listType=map
	// +listMapKey=type
	// +optional
	Conditions []metav1.Condition `json:"conditions,omitempty"`

	// Source is the resolved Flux source artifact metadata.
	// +optional
	Source *SourceStatus `json:"source,omitempty"`

	// +optional
	LastAttemptedAction string `json:"lastAttemptedAction,omitempty"`

	// +optional
	LastAttemptedAt *metav1.Time `json:"lastAttemptedAt,omitempty"`

	// +optional
	LastAttemptedDuration *metav1.Duration `json:"lastAttemptedDuration,omitempty"`

	// +optional
	LastAttemptedSourceDigest string `json:"lastAttemptedSourceDigest,omitempty"`

	// +optional
	LastAttemptedConfigDigest string `json:"lastAttemptedConfigDigest,omitempty"`

	// +optional
	LastAttemptedRenderDigest string `json:"lastAttemptedRenderDigest,omitempty"`

	// +optional
	LastAppliedAt *metav1.Time `json:"lastAppliedAt,omitempty"`

	// +optional
	LastAppliedSourceDigest string `json:"lastAppliedSourceDigest,omitempty"`

	// +optional
	LastAppliedConfigDigest string `json:"lastAppliedConfigDigest,omitempty"`

	// +optional
	LastAppliedRenderDigest string `json:"lastAppliedRenderDigest,omitempty"`

	// +optional
	FailureCounters *FailureCounters `json:"failureCounters,omitempty"`

	// +optional
	Inventory *Inventory `json:"inventory,omitempty"`

	// +optional
	History []HistoryEntry `json:"history,omitempty"`

	// NextRetryAt indicates when the controller will next attempt reconciliation
	// after a transient or stalled failure.
	// +optional
	NextRetryAt *metav1.Time `json:"nextRetryAt,omitempty"`
}

ModulePackageStatus defines the observed state of ModulePackage.

func (*ModulePackageStatus) DeepCopy

func (in *ModulePackageStatus) DeepCopy() *ModulePackageStatus

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModulePackageStatus.

func (*ModulePackageStatus) DeepCopyInto

func (in *ModulePackageStatus) DeepCopyInto(out *ModulePackageStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ModuleReference

type ModuleReference struct {
	// Path is the CUE module import path.
	// Example: "opmodel.dev/modules/cert_manager@v0"
	// +kubebuilder:validation:MinLength=1
	Path string `json:"path"`

	// Version is the pinned module version to resolve from the registry.
	// Example: "v0.2.1"
	// +kubebuilder:validation:MinLength=1
	Version string `json:"version"`
}

ModuleReference identifies the CUE module to evaluate from an OCI registry.

func (*ModuleReference) DeepCopy

func (in *ModuleReference) DeepCopy() *ModuleReference

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleReference.

func (*ModuleReference) DeepCopyInto

func (in *ModuleReference) DeepCopyInto(out *ModuleReference)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type OwnerType

type OwnerType string

OwnerType identifies which actor manages a ModuleInstance.

const (
	// OwnerCLI marks an instance as managed externally by the OPM CLI. The
	// operator stays hands-off: it renders, applies, prunes nothing, adds no
	// finalizer, and only records a ManagedExternally acknowledgement.
	OwnerCLI OwnerType = "cli"
	// OwnerOperator marks an instance as managed by the operator (the default
	// semantics). The reconciler also treats an absent or empty owner this way.
	OwnerOperator OwnerType = "operator"
)

type Platform added in v0.7.0

type Platform struct {
	metav1.TypeMeta `json:",inline"`

	// metadata is a standard object metadata
	// +optional
	metav1.ObjectMeta `json:"metadata,omitzero"`

	// spec defines the desired state of Platform
	// +required
	Spec PlatformSpec `json:"spec"`

	// status defines the observed state of Platform
	// +optional
	Status PlatformStatus `json:"status,omitzero"`
}

Platform is the Schema for the platforms API. It is a cluster-scoped singleton (the only permitted name is "cluster") whose spec projects the core #Platform author surface.

func (*Platform) DeepCopy added in v0.7.0

func (in *Platform) DeepCopy() *Platform

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Platform.

func (*Platform) DeepCopyInto added in v0.7.0

func (in *Platform) DeepCopyInto(out *Platform)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*Platform) DeepCopyObject added in v0.7.0

func (in *Platform) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*Platform) GetConditions added in v0.7.0

func (in *Platform) GetConditions() []metav1.Condition

GetConditions returns the status conditions of the Platform.

func (*Platform) SetConditions added in v0.7.0

func (in *Platform) SetConditions(conditions []metav1.Condition)

SetConditions sets the status conditions on the Platform.

type PlatformList added in v0.7.0

type PlatformList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitzero"`
	Items           []Platform `json:"items"`
}

PlatformList contains a list of Platform.

func (*PlatformList) DeepCopy added in v0.7.0

func (in *PlatformList) DeepCopy() *PlatformList

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PlatformList.

func (*PlatformList) DeepCopyInto added in v0.7.0

func (in *PlatformList) DeepCopyInto(out *PlatformList)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*PlatformList) DeepCopyObject added in v0.7.0

func (in *PlatformList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type PlatformSpec added in v0.7.0

type PlatformSpec struct {
	// Type is the informational discriminator for the platform (core
	// #Platform.type). It does not affect matching; it labels the platform
	// flavor for operators and downstream tooling.
	// +kubebuilder:validation:MinLength=1
	// +required
	Type string `json:"type"`

	// Registry is the set of catalog subscriptions keyed by major-suffixed
	// catalog CUE module path (e.g. "opmodel.dev/catalogs/opm@v2"), projecting
	// core #Platform.#registry. The key's major must agree with the major of
	// the subscribed version (0010:D14).
	// +optional
	Registry map[string]Subscription `json:"registry,omitempty"`

	// SkewPolicy is the operator's response to catalog version skew: a
	// module whose cue.mod requires a newer build of an OPM-namespace path
	// (core or a catalog) than the platform pins (0019:D7/D18).
	// "Warn" (the default when unset) renders against the platform's build
	// and reports the skew as a RenderWarning event on the workload; "Refuse"
	// refuses the render before evaluation and the workload reports
	// Ready=False with reason SkewRefused, naming the path and both versions.
	// The policy is not part of the generated platform module; it is recorded
	// beside it, so changing the field alone bumps the generation, regenerates
	// and re-enqueues the workloads.
	// +kubebuilder:validation:Enum=Warn;Refuse
	// +optional
	SkewPolicy *string `json:"skewPolicy,omitempty"`
}

PlatformSpec defines the desired state of Platform. It is a near-1:1 projection of the core #Platform author surface: an informational type discriminator plus a path-keyed registry of catalog subscriptions. The operator generates a platform CUE module from it on its own disk (a cue.mod pinning every subscribed catalog and a platform.cue carrying each catalog by import) and builds that module; the CR stays the API and the module is derived state (0019:D6).

func (*PlatformSpec) DeepCopy added in v0.7.0

func (in *PlatformSpec) DeepCopy() *PlatformSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PlatformSpec.

func (*PlatformSpec) DeepCopyInto added in v0.7.0

func (in *PlatformSpec) DeepCopyInto(out *PlatformSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type PlatformStatus added in v0.7.0

type PlatformStatus struct {
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`

	// packageIdentity identifies the generated platform package by the two
	// inputs it is a function of (0015:D13): this CR's
	// generation and the sorted set of active claims' catalog coordinates.
	// The same inputs always produce the same value and any change to either
	// produces a different one.
	//
	// This, not status.active on a TransformerRegistration, is the
	// authoritative answer to what a render is building against. The claim
	// reconciler writes the verdict on the claim and this reconciler folds
	// the verdict into the package, so the two are eventually consistent: an
	// observer can see a claim active for a moment before a package
	// containing its catalog exists. Generation is level-computed, so the
	// next regeneration catches up; until it lands, an active claim is a
	// promise about the next package, not a statement about the current one.
	// +optional
	PackageIdentity string `json:"packageIdentity,omitempty"`

	// registry is the resolved union of the registry the platform is
	// running: the subscriptions spec.registry authored plus the catalogs
	// active TransformerRegistrations contributed, each entry recording
	// which. It makes the effective set enumerable from the Platform rather
	// than only by listing every claim, and it is rewritten on every
	// generation, so it follows the active set in both directions.
	// +listType=map
	// +listMapKey=catalog
	// +optional
	Registry []ResolvedRegistryEntry `json:"registry,omitempty"`

	// conditions represent the current state of the Platform resource. The
	// PlatformReconciler summarizes module generation on the Ready condition:
	// Ready=True (reason Generated) when the generated platform module built
	// and its contract inventory was accepted, Ready=False with reason
	// BuildFailed (a pinned build does not exist, a key disagrees with its
	// imported catalog, the module did not build, or its contract inventory
	// could not be read; the message names the dependency, the entry or the
	// field), GenerateFailed (the module could not be written to the
	// operator's disk), OverSubscribedContracts (the module built, but a
	// provider-fulfilled contract is provided by more than one enabled
	// registry entry, counted per entry so two majors of one catalog are
	// two, and whether or not its defining catalog is enabled; the platform
	// cannot route it, and the message names each contract, its defining
	// catalog when one is enabled and the providing registry entries) or
	// ComparablePredicates (the module built, but two enabled transformers
	// have comparable match predicates over a shared catalog-fulfilled
	// contract, so both would render every component the narrower matches;
	// the message names each pair and the contracts it shares). A refused
	// module is not recorded: the last good package keeps serving renders.
	//
	// The ContractsFulfilled condition is a separate, non-gating report on
	// the package renders are consuming, written whenever one is recorded:
	// False with reason UnfulfilledContracts when the package defines
	// provider-fulfilled contracts nothing on the platform implements (the
	// message names each and its defining catalog), True with reason
	// ContractsFulfilled when every defined contract has a provider, and True
	// with reason NoContractsDefined when the enabled catalogs list no
	// contract at all, so nothing was verified. It never moves Ready.
	// +listType=map
	// +listMapKey=type
	// +optional
	Conditions []metav1.Condition `json:"conditions,omitempty"`

	// operatorVersion is the version of the operator that last patched this
	// Platform's status, stamped on every reconcile regardless of outcome
	// (0006:D24). The CLI reads it as the version-skew ceiling;
	// absence means no operator has reconciled the Platform (solo cluster).
	// +optional
	OperatorVersion string `json:"operatorVersion,omitempty"`
}

func (*PlatformStatus) DeepCopy added in v0.7.0

func (in *PlatformStatus) DeepCopy() *PlatformStatus

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PlatformStatus.

func (*PlatformStatus) DeepCopyInto added in v0.7.0

func (in *PlatformStatus) DeepCopyInto(out *PlatformStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type ProviderReference

type ProviderReference struct {
	// Namespace of the claiming ModuleInstance.
	// +kubebuilder:validation:MinLength=1
	// +required
	Namespace string `json:"namespace"`

	// Name of the claiming ModuleInstance.
	// +kubebuilder:validation:MinLength=1
	// +required
	Name string `json:"name"`
}

ProviderReference identifies the ModuleInstance that claimed a provider catalog, by namespace and name.

Flux's meta.NamespacedObjectReference is the shape this would otherwise reuse, but it does not fit verbatim: its Namespace is +optional, acting as a LocalObjectReference when absent. A TransformerRegistration is cluster-scoped, so it has no namespace of its own to fall back to and an omitted namespace would name nothing findable. Both fields are required here. The operator stamps them from the rendering instance rather than accepting them from a module author (0015:D11).

func (*ProviderReference) DeepCopy

func (in *ProviderReference) DeepCopy() *ProviderReference

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ProviderReference.

func (*ProviderReference) DeepCopyInto

func (in *ProviderReference) DeepCopyInto(out *ProviderReference)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type RawValues

type RawValues struct {
	apiextensionsv1.JSON `json:",inline"`
}

RawValues stores arbitrary CUE/JSON-compatible values.

func (*RawValues) DeepCopy

func (in *RawValues) DeepCopy() *RawValues

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new RawValues.

func (*RawValues) DeepCopyInto

func (in *RawValues) DeepCopyInto(out *RawValues)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type RegistryEntrySource

type RegistryEntrySource string

PlatformStatus defines the observed state of Platform. RegistryEntrySource names how a catalog reached the platform's resolved registry: the two paths transformers take to a platform (0015:D3). +kubebuilder:validation:Enum=Subscription;Registration

const (
	// RegistryEntrySubscription is a catalog the Platform CR's spec.registry
	// authored: a platform admin subscribed to it deliberately.
	RegistryEntrySubscription RegistryEntrySource = "Subscription"

	// RegistryEntryRegistration is a catalog an accepted-and-active
	// TransformerRegistration contributed: a provider module registered it
	// and the operator judged the claim.
	RegistryEntryRegistration RegistryEntrySource = "Registration"
)

type ResolvedRegistryEntry

type ResolvedRegistryEntry struct {
	// catalog is the major-suffixed CUE module path of the catalog.
	// +kubebuilder:validation:MinLength=1
	// +required
	Catalog string `json:"catalog"`

	// version is the bare SemVer build the generated platform module pins
	// the catalog at.
	// +kubebuilder:validation:MinLength=1
	// +required
	Version string `json:"version"`

	// enabled reports whether the catalog's transformers register. A
	// disabled subscription is still pinned and imported by the generated
	// module, so it belongs in the resolved registry, but it contributes no
	// transformer; reading the list without this field would overstate what
	// the platform runs. Every catalog an active claim contributed is
	// enabled.
	// +optional
	Enabled bool `json:"enabled,omitzero"`

	// source records which of the two transformer paths put the catalog
	// here, so an operator can tell an authored subscription from one a
	// provider registered.
	// +required
	Source RegistryEntrySource `json:"source"`
}

ResolvedRegistryEntry is one catalog of the registry the platform is actually running, resolved from both of its sources. A catalog is one registry key, so an authored subscription and a claim naming the same catalog resolve to a single entry sourced Subscription: the admin's pin and enable decision is the deliberate one.

func (*ResolvedRegistryEntry) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ResolvedRegistryEntry.

func (*ResolvedRegistryEntry) DeepCopyInto

func (in *ResolvedRegistryEntry) DeepCopyInto(out *ResolvedRegistryEntry)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type RolloutSpec

type RolloutSpec struct {
	// Strategy controls how apply operations are performed.
	// +kubebuilder:validation:Enum=Apply
	// +optional
	Strategy string `json:"strategy,omitempty"`

	// ForceConflicts enables SSA force ownership when desired.
	// +optional
	ForceConflicts bool `json:"forceConflicts,omitempty"`
}

RolloutSpec configures apply behavior for a release.

func (*RolloutSpec) DeepCopy

func (in *RolloutSpec) DeepCopy() *RolloutSpec

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new RolloutSpec.

func (*RolloutSpec) DeepCopyInto

func (in *RolloutSpec) DeepCopyInto(out *RolloutSpec)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type SourceReference

type SourceReference = fluxmeta.NamespacedObjectKindReference

SourceReference points to a Flux source object. Used by Release; ModuleInstance uses CUE-native module resolution instead.

type SourceStatus

type SourceStatus struct {
	// Ref is the resolved source reference.
	// +optional
	Ref *SourceReference `json:"ref,omitempty"`

	// ArtifactRevision is the revision reported by the source artifact.
	// +optional
	ArtifactRevision string `json:"artifactRevision,omitempty"`

	// ArtifactDigest is the digest reported by the source artifact.
	// +optional
	ArtifactDigest string `json:"artifactDigest,omitempty"`

	// ArtifactURL is the fetch URL reported by the source artifact.
	// +optional
	ArtifactURL string `json:"artifactURL,omitempty"`
}

SourceStatus describes the resolved source artifact used by a reconcile.

func (*SourceStatus) DeepCopy

func (in *SourceStatus) DeepCopy() *SourceStatus

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SourceStatus.

func (*SourceStatus) DeepCopyInto

func (in *SourceStatus) DeepCopyInto(out *SourceStatus)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type Subscription added in v0.7.0

type Subscription struct {
	// Enable toggles the subscription. A pointer so that an omitted value
	// defers to the schema default (true) rather than serializing as an
	// explicit false. A disabled subscription is still pinned and imported by
	// the generated module, with enable set to false on its entry.
	// +optional
	Enable *bool `json:"enable,omitempty"`

	// Version names exactly one published catalog build as a bare SemVer
	// string (e.g. "2.0.0-alpha.3") — the platform module IS the resolution
	// (0010:D14); there is no range or allow/deny vocabulary. The
	// version's major must agree with the subscription key's `@vN` suffix.
	// The operator uses it twice: as the generated cue.mod pin and as the
	// entry's stamped expected version, which unifies with the imported
	// catalog's own version so wrong bytes fail the build naming the entry
	// (0019:D13).
	// CRD-required is safe against the stored pre-reshape singleton: API
	// server validation ratcheting keeps status-subresource patches working
	// against a stored object lacking the field (measured in
	// test/integration/crdvalidation).
	// +kubebuilder:validation:MinLength=1
	// +required
	Version string `json:"version"`
}

Subscription is a single catalog registry subscription. It becomes one #registry entry of the generated platform module, carrying the catalog by import.

func (*Subscription) DeepCopy added in v0.7.0

func (in *Subscription) DeepCopy() *Subscription

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Subscription.

func (*Subscription) DeepCopyInto added in v0.7.0

func (in *Subscription) DeepCopyInto(out *Subscription)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type TransformerRegistration

type TransformerRegistration struct {
	metav1.TypeMeta `json:",inline"`

	// metadata is a standard object metadata
	// +optional
	metav1.ObjectMeta `json:"metadata,omitzero"`

	// spec defines the desired state of TransformerRegistration
	// +required
	Spec TransformerRegistrationSpec `json:"spec"`

	// status defines the observed state of TransformerRegistration
	// +optional
	Status TransformerRegistrationStatus `json:"status,omitzero"`
}

TransformerRegistration is the Schema for the transformerregistrations API. It is the cluster-scoped claim a provider module ships among its rendered resources, the second path by which transformers reach a platform (0015:D3); the first is a subscription in Platform.spec.registry.

metadata.name is the dot-joined "<namespace>.<name>" of the claiming instance (0015:D12). A namespace cannot contain a dot, so the join is collision-free and two instances of one provider module produce two distinct claims, the second refused at acceptance naming the claimant, rather than contending for one object.

Creating one requires platform-admin RBAC. The operator ships that role unbound (config/rbac/transformerregistration_admin_role.yaml) and ships no tenant-facing role granting create, so a module applied under an impersonated tenant ServiceAccount cannot register a transformer unless a cluster administrator deliberately bound it.

func (*TransformerRegistration) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TransformerRegistration.

func (*TransformerRegistration) DeepCopyInto

func (in *TransformerRegistration) DeepCopyInto(out *TransformerRegistration)

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*TransformerRegistration) DeepCopyObject

func (in *TransformerRegistration) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

func (*TransformerRegistration) GetConditions

func (in *TransformerRegistration) GetConditions() []metav1.Condition

GetConditions returns the status conditions of the TransformerRegistration.

func (*TransformerRegistration) SetConditions

func (in *TransformerRegistration) SetConditions(conditions []metav1.Condition)

SetConditions sets the status conditions on the TransformerRegistration.

type TransformerRegistrationList

type TransformerRegistrationList struct {
	metav1.TypeMeta `json:",inline"`
	metav1.ListMeta `json:"metadata,omitzero"`
	Items           []TransformerRegistration `json:"items"`
}

TransformerRegistrationList contains a list of TransformerRegistration.

func (*TransformerRegistrationList) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TransformerRegistrationList.

func (*TransformerRegistrationList) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

func (*TransformerRegistrationList) DeepCopyObject

func (in *TransformerRegistrationList) DeepCopyObject() runtime.Object

DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.

type TransformerRegistrationSpec

type TransformerRegistrationSpec struct {
	// Catalog is the provider catalog's major-suffixed CUE module path
	// (e.g. "opmodel.dev/catalogs/k8up@v1"). It names a catalog, never a
	// module: a catalog is what carries transformers, so a claim naming a
	// module names nothing that could implement a contract. Acceptance
	// refuses a non-catalog artifact structurally (0015:D10).
	// +kubebuilder:validation:MinLength=1
	// +required
	Catalog string `json:"catalog"`

	// Version is the released build of the named catalog, a bare SemVer
	// string (e.g. "1.0.0"). It pins the claim to one build, which is what
	// lets acceptance re-derive Provides from the artifact this names.
	// +kubebuilder:validation:MinLength=1
	// +required
	Version string `json:"version"`

	// Provides lists every provider-fulfilled contract FQN the named catalog
	// claims to implement.
	//
	// Required but MAY be empty. A provider catalog implementing no
	// provider-fulfilled contract is a claim acceptance refuses on its merits,
	// naming the catalog it re-derived from, not a malformed object. The CRD
	// is the wrong place to encode a rule the reconciler states better.
	// +required
	Provides []string `json:"provides"`

	// ProviderRef identifies the ModuleInstance that rendered this claim. It
	// is stamped from the rendering instance and never authored, so a module
	// cannot claim to be another provider (0015:D11).
	// +required
	ProviderRef ProviderReference `json:"providerRef"`
}

TransformerRegistrationSpec defines a provider module's claim that its catalog implements platform contracts (0015:D3).

Every field is required at the CRD level, deliberately duplicating the catalog-side contract rather than trusting it. CUE reports a missing required field as an incomplete value, not an error: measured 2026-09-14 at cue v0.17.1, a component omitting `catalog` passes `cue vet ./...` and fails only under `cue export`. A claim can therefore reach the cluster with a field absent, so the API server validates it on its own terms.

func (*TransformerRegistrationSpec) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TransformerRegistrationSpec.

func (*TransformerRegistrationSpec) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

type TransformerRegistrationStatus

type TransformerRegistrationStatus struct {
	// observedGeneration is the .metadata.generation this claim was last
	// reconciled for, whether or not that reconcile reached a verdict: a claim
	// waiting on the platform or on its provider's inventory records the
	// generation it observed rather than reading as un-reconciled. A claim
	// whose generation is ahead of this has been edited since, so whatever
	// conditions report is stale.
	// +optional
	ObservedGeneration int64 `json:"observedGeneration,omitempty"`

	// conditions represent the current state of the TransformerRegistration
	// resource.
	// +listType=map
	// +listMapKey=type
	// +optional
	Conditions []metav1.Condition `json:"conditions,omitempty"`

	// accepted reports whether the claim passed acceptance: the catalog
	// resolved, its Provides re-derived equal, and no other instance holds
	// the same provider.
	// +optional
	Accepted bool `json:"accepted,omitzero"`

	// active reports whether an accepted claim's provider is serving. An
	// accepted claim stays inactive until its ModulePackage is Ready.
	// +optional
	Active bool `json:"active,omitzero"`
}

TransformerRegistrationStatus defines the observed state of a TransformerRegistration.

Acceptance and activation are separate states (0015:D3): a stored claim is not yet judged, accepted but inactive, or active. The acceptance reconciler writes conditions, accepted and observedGeneration; active stays false until an accepted claim's provider is serving.

func (*TransformerRegistrationStatus) DeepCopy

DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TransformerRegistrationStatus.

func (*TransformerRegistrationStatus) DeepCopyInto

DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL