Documentation
¶
Overview ¶
Package v1alpha1 contains API Schema definitions for the opmodel.dev v1alpha1 API group. +kubebuilder:object:generate=true +groupName=opmodel.dev
Index ¶
- Constants
- Variables
- type FailureCounters
- type HistoryEntry
- type Inventory
- type InventoryEntry
- type ModuleInstance
- func (in *ModuleInstance) DeepCopy() *ModuleInstance
- func (in *ModuleInstance) DeepCopyInto(out *ModuleInstance)
- func (in *ModuleInstance) DeepCopyObject() runtime.Object
- func (in *ModuleInstance) GetConditions() []metav1.Condition
- func (in *ModuleInstance) SetConditions(conditions []metav1.Condition)
- type ModuleInstanceList
- type ModuleInstanceSpec
- type ModuleInstanceStatus
- type ModulePackage
- type ModulePackageList
- type ModulePackageSpec
- type ModulePackageStatus
- type ModuleReference
- type OwnerType
- type Platform
- type PlatformList
- type PlatformSpec
- type PlatformStatus
- type ProviderReference
- type RawValues
- type RegistryEntrySource
- type ResolvedRegistryEntry
- type RolloutSpec
- type SourceReference
- type SourceStatus
- type Subscription
- type TransformerRegistration
- func (in *TransformerRegistration) DeepCopy() *TransformerRegistration
- func (in *TransformerRegistration) DeepCopyInto(out *TransformerRegistration)
- func (in *TransformerRegistration) DeepCopyObject() runtime.Object
- func (in *TransformerRegistration) GetConditions() []metav1.Condition
- func (in *TransformerRegistration) SetConditions(conditions []metav1.Condition)
- type TransformerRegistrationList
- type TransformerRegistrationSpec
- type TransformerRegistrationStatus
Constants ¶
const ( // SkewPolicyWarn renders against the platform's build and reports the // skew. The default. SkewPolicyWarn = "Warn" // SkewPolicyRefuse refuses the render before evaluation. SkewPolicyRefuse = "Refuse" )
Skew policy values for PlatformSpec.SkewPolicy.
const AnnotationForceDeleteOrphan = "opm.dev/force-delete-orphan"
AnnotationForceDeleteOrphan is the release annotation that, when set to "true", releases a finalizer stuck in the DeletionSAMissing stall by skipping prune and orphaning the managed inventory. Any value other than the literal string "true" is treated as absent.
Variables ¶
var ( // GroupVersion is group version used to register these objects. GroupVersion = schema.GroupVersion{Group: "opmodel.dev", Version: "v1alpha1"} // SchemeBuilder is used to add go types to the GroupVersionKind scheme. // Uses the apimachinery builder directly rather than the deprecated // sigs.k8s.io/controller-runtime/pkg/scheme.Builder convenience wrapper // (deprecated in controller-runtime v0.24.0). SchemeBuilder = runtime.NewSchemeBuilder(addToGroupVersion) // AddToScheme adds the types in this group-version to the given scheme. AddToScheme = SchemeBuilder.AddToScheme )
Functions ¶
This section is empty.
Types ¶
type FailureCounters ¶
type FailureCounters struct {
// +optional
Reconcile int64 `json:"reconcile,omitempty"`
// +optional
Apply int64 `json:"apply,omitempty"`
// +optional
Prune int64 `json:"prune,omitempty"`
// +optional
Drift int64 `json:"drift,omitempty"`
}
FailureCounters tracks bounded reconcile failure counts by action.
func (*FailureCounters) DeepCopy ¶
func (in *FailureCounters) DeepCopy() *FailureCounters
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new FailureCounters.
func (*FailureCounters) DeepCopyInto ¶
func (in *FailureCounters) DeepCopyInto(out *FailureCounters)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type HistoryEntry ¶
type HistoryEntry struct {
// +optional
Sequence int64 `json:"sequence,omitempty"`
// +optional
Action string `json:"action,omitempty"`
// +optional
Phase string `json:"phase,omitempty"`
// +optional
StartedAt *metav1.Time `json:"startedAt,omitempty"`
// +optional
FinishedAt *metav1.Time `json:"finishedAt,omitempty"`
// +optional
SourceDigest string `json:"sourceDigest,omitempty"`
// +optional
ConfigDigest string `json:"configDigest,omitempty"`
// +optional
RenderDigest string `json:"renderDigest,omitempty"`
// +optional
InventoryDigest string `json:"inventoryDigest,omitempty"`
// +optional
InventoryCount int64 `json:"inventoryCount,omitempty"`
// +optional
Message string `json:"message,omitempty"`
}
HistoryEntry captures a compact reconcile history record.
func (*HistoryEntry) DeepCopy ¶
func (in *HistoryEntry) DeepCopy() *HistoryEntry
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new HistoryEntry.
func (*HistoryEntry) DeepCopyInto ¶
func (in *HistoryEntry) DeepCopyInto(out *HistoryEntry)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Inventory ¶
type Inventory struct {
// +optional
Revision int64 `json:"revision,omitempty"`
// +optional
Digest string `json:"digest,omitempty"`
// +optional
Count int64 `json:"count,omitempty"`
// +optional
Entries []InventoryEntry `json:"entries,omitempty"`
}
Inventory stores the current set of owned resources.
func (*Inventory) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Inventory.
func (*Inventory) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type InventoryEntry ¶
type InventoryEntry struct {
// +optional
Group string `json:"group,omitempty"`
Kind string `json:"kind"`
// +optional
Namespace string `json:"namespace,omitempty"`
Name string `json:"name"`
// +optional
Version string `json:"v,omitempty"`
// +optional
Component string `json:"component,omitempty"`
}
InventoryEntry identifies one owned Kubernetes resource.
func (*InventoryEntry) DeepCopy ¶
func (in *InventoryEntry) DeepCopy() *InventoryEntry
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InventoryEntry.
func (*InventoryEntry) DeepCopyInto ¶
func (in *InventoryEntry) DeepCopyInto(out *InventoryEntry)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ModuleInstance ¶
type ModuleInstance struct {
metav1.TypeMeta `json:",inline"`
// metadata is a standard object metadata
// +optional
metav1.ObjectMeta `json:"metadata,omitzero"`
// spec defines the desired state of ModuleInstance
// +required
Spec ModuleInstanceSpec `json:"spec"`
// status defines the observed state of ModuleInstance
// +optional
Status ModuleInstanceStatus `json:"status,omitzero"`
}
ModuleInstance is the Schema for the moduleinstances API
func (*ModuleInstance) DeepCopy ¶
func (in *ModuleInstance) DeepCopy() *ModuleInstance
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleInstance.
func (*ModuleInstance) DeepCopyInto ¶
func (in *ModuleInstance) DeepCopyInto(out *ModuleInstance)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*ModuleInstance) DeepCopyObject ¶
func (in *ModuleInstance) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*ModuleInstance) GetConditions ¶
func (in *ModuleInstance) GetConditions() []metav1.Condition
GetConditions returns the status conditions of the ModuleInstance.
func (*ModuleInstance) SetConditions ¶
func (in *ModuleInstance) SetConditions(conditions []metav1.Condition)
SetConditions sets the status conditions on the ModuleInstance.
type ModuleInstanceList ¶
type ModuleInstanceList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitzero"`
Items []ModuleInstance `json:"items"`
}
ModuleInstanceList contains a list of ModuleInstance
func (*ModuleInstanceList) DeepCopy ¶
func (in *ModuleInstanceList) DeepCopy() *ModuleInstanceList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleInstanceList.
func (*ModuleInstanceList) DeepCopyInto ¶
func (in *ModuleInstanceList) DeepCopyInto(out *ModuleInstanceList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*ModuleInstanceList) DeepCopyObject ¶
func (in *ModuleInstanceList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type ModuleInstanceSpec ¶
type ModuleInstanceSpec struct {
// +optional
Suspend bool `json:"suspend,omitempty"`
// Owner identifies which actor manages this instance. An absent, empty, or
// "operator" value means operator-managed: the controller reconciles
// normally. Only an explicit "cli" makes the operator skip the instance
// (no render/apply/prune, no finalizer) and record a single
// ManagedExternally acknowledgement. There is no CRD default; the
// reconciler carries the operator-managed default semantics.
// +kubebuilder:validation:Enum=cli;operator
// +optional
Owner OwnerType `json:"owner,omitempty"`
// Module identifies the CUE module to evaluate from the OCI registry.
Module ModuleReference `json:"module"`
// Values contains arbitrary release input values.
// +optional
Values *RawValues `json:"values,omitempty"`
// +optional
Prune bool `json:"prune,omitempty"`
// +optional
ServiceAccountName string `json:"serviceAccountName,omitempty"`
// +optional
Rollout *RolloutSpec `json:"rollout,omitempty"`
}
ModuleInstanceSpec defines the desired state of ModuleInstance
func (*ModuleInstanceSpec) DeepCopy ¶
func (in *ModuleInstanceSpec) DeepCopy() *ModuleInstanceSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleInstanceSpec.
func (*ModuleInstanceSpec) DeepCopyInto ¶
func (in *ModuleInstanceSpec) DeepCopyInto(out *ModuleInstanceSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ModuleInstanceStatus ¶
type ModuleInstanceStatus struct {
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// InstanceUUID is the globally-unique identity of the rendered ModuleInstance,
// read from the `module-instance.opmodel.dev/uuid` label on rendered resources.
// Populated on the first successful render; consumed by the prune ownership
// guard (including the deletion path where a fresh render is not available).
// +optional
InstanceUUID string `json:"instanceUUID,omitempty"`
// conditions represent the current state of the ModuleInstance resource.
// Each condition has a unique type and reflects the status of a specific aspect of the resource.
//
// Standard condition types include:
// - "Available": the resource is fully functional
// - "Progressing": the resource is being created or updated
// - "Degraded": the resource failed to reach or maintain its desired state
//
// The status of each condition is one of True, False, or Unknown.
// +listType=map
// +listMapKey=type
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
// +optional
LastAttemptedAction string `json:"lastAttemptedAction,omitempty"`
// +optional
LastAttemptedAt *metav1.Time `json:"lastAttemptedAt,omitempty"`
// +optional
LastAttemptedDuration *metav1.Duration `json:"lastAttemptedDuration,omitempty"`
// +optional
LastAttemptedSourceDigest string `json:"lastAttemptedSourceDigest,omitempty"`
// +optional
LastAttemptedConfigDigest string `json:"lastAttemptedConfigDigest,omitempty"`
// +optional
LastAttemptedRenderDigest string `json:"lastAttemptedRenderDigest,omitempty"`
// +optional
LastAppliedAt *metav1.Time `json:"lastAppliedAt,omitempty"`
// +optional
LastAppliedSourceDigest string `json:"lastAppliedSourceDigest,omitempty"`
// +optional
LastAppliedConfigDigest string `json:"lastAppliedConfigDigest,omitempty"`
// +optional
LastAppliedRenderDigest string `json:"lastAppliedRenderDigest,omitempty"`
// +optional
FailureCounters *FailureCounters `json:"failureCounters,omitempty"`
// +optional
Inventory *Inventory `json:"inventory,omitempty"`
// RequiredContracts lists every contract FQN this instance's components
// declare, sorted and deduplicated, as the last successful render
// reported them. It is the instance side of the removal guard
// (0015:D3, D16): a TransformerRegistration counts its
// dependents by intersecting this with its own spec.provides, so a
// provider cannot be deleted, or shrink its provides, out from under
// the instances still demanding what it serves.
//
// Derived, never authored. The contracts are read off the synthesized
// instance's components, which is the same keyspace the render's
// matching compares, so nothing a module author writes into spec can
// raise or lower the count. A reconcile that does not render — a failed
// render, a suspended instance, a CLI-owned one — leaves the previous
// value: a stale entry over-reports demand and blocks a deletion that
// could have proceeded, which is the safe direction for a guard.
// +listType=atomic
// +optional
RequiredContracts []string `json:"requiredContracts,omitempty"`
// +optional
History []HistoryEntry `json:"history,omitempty"`
// NextRetryAt indicates when the controller will next attempt reconciliation
// after a transient or stalled failure. Nil when the resource is healthy or no-op.
// +optional
NextRetryAt *metav1.Time `json:"nextRetryAt,omitempty"`
}
ModuleInstanceStatus defines the observed state of ModuleInstance.
func (*ModuleInstanceStatus) DeepCopy ¶
func (in *ModuleInstanceStatus) DeepCopy() *ModuleInstanceStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleInstanceStatus.
func (*ModuleInstanceStatus) DeepCopyInto ¶
func (in *ModuleInstanceStatus) DeepCopyInto(out *ModuleInstanceStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ModulePackage ¶
type ModulePackage struct {
metav1.TypeMeta `json:",inline"`
// metadata is a standard object metadata
// +optional
metav1.ObjectMeta `json:"metadata,omitzero"`
// spec defines the desired state of ModulePackage
// +required
Spec ModulePackageSpec `json:"spec"`
// status defines the observed state of ModulePackage
// +optional
Status ModulePackageStatus `json:"status,omitzero"`
}
ModulePackage is the Schema for the modulepackages API.
func (*ModulePackage) DeepCopy ¶
func (in *ModulePackage) DeepCopy() *ModulePackage
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModulePackage.
func (*ModulePackage) DeepCopyInto ¶
func (in *ModulePackage) DeepCopyInto(out *ModulePackage)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*ModulePackage) DeepCopyObject ¶
func (in *ModulePackage) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*ModulePackage) GetConditions ¶
func (in *ModulePackage) GetConditions() []metav1.Condition
GetConditions returns the status conditions of the ModulePackage.
func (*ModulePackage) SetConditions ¶
func (in *ModulePackage) SetConditions(conditions []metav1.Condition)
SetConditions sets the status conditions on the ModulePackage.
type ModulePackageList ¶
type ModulePackageList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitzero"`
Items []ModulePackage `json:"items"`
}
ModulePackageList contains a list of ModulePackage.
func (*ModulePackageList) DeepCopy ¶
func (in *ModulePackageList) DeepCopy() *ModulePackageList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModulePackageList.
func (*ModulePackageList) DeepCopyInto ¶
func (in *ModulePackageList) DeepCopyInto(out *ModulePackageList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*ModulePackageList) DeepCopyObject ¶
func (in *ModulePackageList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type ModulePackageSpec ¶
type ModulePackageSpec struct {
// SourceRef references a Flux source (OCIRepository, GitRepository, or Bucket)
// that provides the artifact containing the CUE package.
SourceRef SourceReference `json:"sourceRef"`
// Path is the directory within the artifact containing instance.cue.
// Example: "releases/prod/minecraft".
// +kubebuilder:validation:MinLength=1
Path string `json:"path"`
// Interval at which the reconciler re-evaluates the package to detect drift
// and re-apply. Also the requeue interval after transient failures.
// +optional
Interval metav1.Duration `json:"interval,omitempty"`
// DependsOn references other ModulePackage CRs that must be Ready=True before
// this ModulePackage is reconciled. References are same-namespace only.
// +optional
DependsOn []fluxmeta.NamespacedObjectReference `json:"dependsOn,omitempty"`
// Prune enables deletion of stale resources on reconcile and of all owned
// resources on ModulePackage deletion.
// +optional
Prune bool `json:"prune,omitempty"`
// Suspend halts reconciliation when true.
// +optional
Suspend bool `json:"suspend,omitempty"`
// ServiceAccountName is the name of the ServiceAccount used to impersonate
// during apply and prune. Empty means use the controller's identity.
// +optional
ServiceAccountName string `json:"serviceAccountName,omitempty"`
// Rollout configures apply behavior.
// +optional
Rollout *RolloutSpec `json:"rollout,omitempty"`
}
ModulePackageSpec defines the desired state of ModulePackage. A ModulePackage points to a Flux source artifact containing a CUE package. The controller fetches the artifact, navigates to spec.path, loads instance.cue, and renders it when it evaluates to #ModuleInstance; any other kind is rejected as unsupported.
func (*ModulePackageSpec) DeepCopy ¶
func (in *ModulePackageSpec) DeepCopy() *ModulePackageSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModulePackageSpec.
func (*ModulePackageSpec) DeepCopyInto ¶
func (in *ModulePackageSpec) DeepCopyInto(out *ModulePackageSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ModulePackageStatus ¶
type ModulePackageStatus struct {
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// conditions represent the current state of the ModulePackage resource.
// +listType=map
// +listMapKey=type
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
// Source is the resolved Flux source artifact metadata.
// +optional
Source *SourceStatus `json:"source,omitempty"`
// +optional
LastAttemptedAction string `json:"lastAttemptedAction,omitempty"`
// +optional
LastAttemptedAt *metav1.Time `json:"lastAttemptedAt,omitempty"`
// +optional
LastAttemptedDuration *metav1.Duration `json:"lastAttemptedDuration,omitempty"`
// +optional
LastAttemptedSourceDigest string `json:"lastAttemptedSourceDigest,omitempty"`
// +optional
LastAttemptedConfigDigest string `json:"lastAttemptedConfigDigest,omitempty"`
// +optional
LastAttemptedRenderDigest string `json:"lastAttemptedRenderDigest,omitempty"`
// +optional
LastAppliedAt *metav1.Time `json:"lastAppliedAt,omitempty"`
// +optional
LastAppliedSourceDigest string `json:"lastAppliedSourceDigest,omitempty"`
// +optional
LastAppliedConfigDigest string `json:"lastAppliedConfigDigest,omitempty"`
// +optional
LastAppliedRenderDigest string `json:"lastAppliedRenderDigest,omitempty"`
// +optional
FailureCounters *FailureCounters `json:"failureCounters,omitempty"`
// +optional
Inventory *Inventory `json:"inventory,omitempty"`
// +optional
History []HistoryEntry `json:"history,omitempty"`
// NextRetryAt indicates when the controller will next attempt reconciliation
// after a transient or stalled failure.
// +optional
NextRetryAt *metav1.Time `json:"nextRetryAt,omitempty"`
}
ModulePackageStatus defines the observed state of ModulePackage.
func (*ModulePackageStatus) DeepCopy ¶
func (in *ModulePackageStatus) DeepCopy() *ModulePackageStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModulePackageStatus.
func (*ModulePackageStatus) DeepCopyInto ¶
func (in *ModulePackageStatus) DeepCopyInto(out *ModulePackageStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ModuleReference ¶
type ModuleReference struct {
// Path is the CUE module import path.
// Example: "opmodel.dev/modules/cert_manager@v0"
// +kubebuilder:validation:MinLength=1
Path string `json:"path"`
// Version is the pinned module version to resolve from the registry.
// Example: "v0.2.1"
// +kubebuilder:validation:MinLength=1
Version string `json:"version"`
}
ModuleReference identifies the CUE module to evaluate from an OCI registry.
func (*ModuleReference) DeepCopy ¶
func (in *ModuleReference) DeepCopy() *ModuleReference
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ModuleReference.
func (*ModuleReference) DeepCopyInto ¶
func (in *ModuleReference) DeepCopyInto(out *ModuleReference)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type OwnerType ¶
type OwnerType string
OwnerType identifies which actor manages a ModuleInstance.
const ( // OwnerCLI marks an instance as managed externally by the OPM CLI. The // operator stays hands-off: it renders, applies, prunes nothing, adds no // finalizer, and only records a ManagedExternally acknowledgement. OwnerCLI OwnerType = "cli" // OwnerOperator marks an instance as managed by the operator (the default // semantics). The reconciler also treats an absent or empty owner this way. OwnerOperator OwnerType = "operator" )
type Platform ¶ added in v0.7.0
type Platform struct {
metav1.TypeMeta `json:",inline"`
// metadata is a standard object metadata
// +optional
metav1.ObjectMeta `json:"metadata,omitzero"`
// spec defines the desired state of Platform
// +required
Spec PlatformSpec `json:"spec"`
// status defines the observed state of Platform
// +optional
Status PlatformStatus `json:"status,omitzero"`
}
Platform is the Schema for the platforms API. It is a cluster-scoped singleton (the only permitted name is "cluster") whose spec projects the core #Platform author surface.
func (*Platform) DeepCopy ¶ added in v0.7.0
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Platform.
func (*Platform) DeepCopyInto ¶ added in v0.7.0
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*Platform) DeepCopyObject ¶ added in v0.7.0
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*Platform) GetConditions ¶ added in v0.7.0
GetConditions returns the status conditions of the Platform.
func (*Platform) SetConditions ¶ added in v0.7.0
SetConditions sets the status conditions on the Platform.
type PlatformList ¶ added in v0.7.0
type PlatformList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitzero"`
Items []Platform `json:"items"`
}
PlatformList contains a list of Platform.
func (*PlatformList) DeepCopy ¶ added in v0.7.0
func (in *PlatformList) DeepCopy() *PlatformList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PlatformList.
func (*PlatformList) DeepCopyInto ¶ added in v0.7.0
func (in *PlatformList) DeepCopyInto(out *PlatformList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*PlatformList) DeepCopyObject ¶ added in v0.7.0
func (in *PlatformList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type PlatformSpec ¶ added in v0.7.0
type PlatformSpec struct {
// Type is the informational discriminator for the platform (core
// #Platform.type). It does not affect matching; it labels the platform
// flavor for operators and downstream tooling.
// +kubebuilder:validation:MinLength=1
// +required
Type string `json:"type"`
// Registry is the set of catalog subscriptions keyed by major-suffixed
// catalog CUE module path (e.g. "opmodel.dev/catalogs/opm@v2"), projecting
// core #Platform.#registry. The key's major must agree with the major of
// the subscribed version (0010:D14).
// +optional
Registry map[string]Subscription `json:"registry,omitempty"`
// SkewPolicy is the operator's response to catalog version skew: a
// module whose cue.mod requires a newer build of an OPM-namespace path
// (core or a catalog) than the platform pins (0019:D7/D18).
// "Warn" (the default when unset) renders against the platform's build
// and reports the skew as a RenderWarning event on the workload; "Refuse"
// refuses the render before evaluation and the workload reports
// Ready=False with reason SkewRefused, naming the path and both versions.
// The policy is not part of the generated platform module; it is recorded
// beside it, so changing the field alone bumps the generation, regenerates
// and re-enqueues the workloads.
// +kubebuilder:validation:Enum=Warn;Refuse
// +optional
SkewPolicy *string `json:"skewPolicy,omitempty"`
}
PlatformSpec defines the desired state of Platform. It is a near-1:1 projection of the core #Platform author surface: an informational type discriminator plus a path-keyed registry of catalog subscriptions. The operator generates a platform CUE module from it on its own disk (a cue.mod pinning every subscribed catalog and a platform.cue carrying each catalog by import) and builds that module; the CR stays the API and the module is derived state (0019:D6).
func (*PlatformSpec) DeepCopy ¶ added in v0.7.0
func (in *PlatformSpec) DeepCopy() *PlatformSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PlatformSpec.
func (*PlatformSpec) DeepCopyInto ¶ added in v0.7.0
func (in *PlatformSpec) DeepCopyInto(out *PlatformSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type PlatformStatus ¶ added in v0.7.0
type PlatformStatus struct {
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// packageIdentity identifies the generated platform package by the two
// inputs it is a function of (0015:D13): this CR's
// generation and the sorted set of active claims' catalog coordinates.
// The same inputs always produce the same value and any change to either
// produces a different one.
//
// This, not status.active on a TransformerRegistration, is the
// authoritative answer to what a render is building against. The claim
// reconciler writes the verdict on the claim and this reconciler folds
// the verdict into the package, so the two are eventually consistent: an
// observer can see a claim active for a moment before a package
// containing its catalog exists. Generation is level-computed, so the
// next regeneration catches up; until it lands, an active claim is a
// promise about the next package, not a statement about the current one.
// +optional
PackageIdentity string `json:"packageIdentity,omitempty"`
// registry is the resolved union of the registry the platform is
// running: the subscriptions spec.registry authored plus the catalogs
// active TransformerRegistrations contributed, each entry recording
// which. It makes the effective set enumerable from the Platform rather
// than only by listing every claim, and it is rewritten on every
// generation, so it follows the active set in both directions.
// +listType=map
// +listMapKey=catalog
// +optional
Registry []ResolvedRegistryEntry `json:"registry,omitempty"`
// conditions represent the current state of the Platform resource. The
// PlatformReconciler summarizes module generation on the Ready condition:
// Ready=True (reason Generated) when the generated platform module built
// and its contract inventory was accepted, Ready=False with reason
// BuildFailed (a pinned build does not exist, a key disagrees with its
// imported catalog, the module did not build, or its contract inventory
// could not be read; the message names the dependency, the entry or the
// field), GenerateFailed (the module could not be written to the
// operator's disk), OverSubscribedContracts (the module built, but a
// provider-fulfilled contract is provided by more than one enabled
// registry entry, counted per entry so two majors of one catalog are
// two, and whether or not its defining catalog is enabled; the platform
// cannot route it, and the message names each contract, its defining
// catalog when one is enabled and the providing registry entries) or
// ComparablePredicates (the module built, but two enabled transformers
// have comparable match predicates over a shared catalog-fulfilled
// contract, so both would render every component the narrower matches;
// the message names each pair and the contracts it shares). A refused
// module is not recorded: the last good package keeps serving renders.
//
// The ContractsFulfilled condition is a separate, non-gating report on
// the package renders are consuming, written whenever one is recorded:
// False with reason UnfulfilledContracts when the package defines
// provider-fulfilled contracts nothing on the platform implements (the
// message names each and its defining catalog), True with reason
// ContractsFulfilled when every defined contract has a provider, and True
// with reason NoContractsDefined when the enabled catalogs list no
// contract at all, so nothing was verified. It never moves Ready.
// +listType=map
// +listMapKey=type
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
// operatorVersion is the version of the operator that last patched this
// Platform's status, stamped on every reconcile regardless of outcome
// (0006:D24). The CLI reads it as the version-skew ceiling;
// absence means no operator has reconciled the Platform (solo cluster).
// +optional
OperatorVersion string `json:"operatorVersion,omitempty"`
}
func (*PlatformStatus) DeepCopy ¶ added in v0.7.0
func (in *PlatformStatus) DeepCopy() *PlatformStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new PlatformStatus.
func (*PlatformStatus) DeepCopyInto ¶ added in v0.7.0
func (in *PlatformStatus) DeepCopyInto(out *PlatformStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type ProviderReference ¶
type ProviderReference struct {
// Namespace of the claiming ModuleInstance.
// +kubebuilder:validation:MinLength=1
// +required
Namespace string `json:"namespace"`
// Name of the claiming ModuleInstance.
// +kubebuilder:validation:MinLength=1
// +required
Name string `json:"name"`
}
ProviderReference identifies the ModuleInstance that claimed a provider catalog, by namespace and name.
Flux's meta.NamespacedObjectReference is the shape this would otherwise reuse, but it does not fit verbatim: its Namespace is +optional, acting as a LocalObjectReference when absent. A TransformerRegistration is cluster-scoped, so it has no namespace of its own to fall back to and an omitted namespace would name nothing findable. Both fields are required here. The operator stamps them from the rendering instance rather than accepting them from a module author (0015:D11).
func (*ProviderReference) DeepCopy ¶
func (in *ProviderReference) DeepCopy() *ProviderReference
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ProviderReference.
func (*ProviderReference) DeepCopyInto ¶
func (in *ProviderReference) DeepCopyInto(out *ProviderReference)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type RawValues ¶
type RawValues struct {
apiextensionsv1.JSON `json:",inline"`
}
RawValues stores arbitrary CUE/JSON-compatible values.
func (*RawValues) DeepCopy ¶
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new RawValues.
func (*RawValues) DeepCopyInto ¶
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type RegistryEntrySource ¶
type RegistryEntrySource string
PlatformStatus defines the observed state of Platform. RegistryEntrySource names how a catalog reached the platform's resolved registry: the two paths transformers take to a platform (0015:D3). +kubebuilder:validation:Enum=Subscription;Registration
const ( // RegistryEntrySubscription is a catalog the Platform CR's spec.registry // authored: a platform admin subscribed to it deliberately. RegistryEntrySubscription RegistryEntrySource = "Subscription" // RegistryEntryRegistration is a catalog an accepted-and-active // TransformerRegistration contributed: a provider module registered it // and the operator judged the claim. RegistryEntryRegistration RegistryEntrySource = "Registration" )
type ResolvedRegistryEntry ¶
type ResolvedRegistryEntry struct {
// catalog is the major-suffixed CUE module path of the catalog.
// +kubebuilder:validation:MinLength=1
// +required
Catalog string `json:"catalog"`
// version is the bare SemVer build the generated platform module pins
// the catalog at.
// +kubebuilder:validation:MinLength=1
// +required
Version string `json:"version"`
// enabled reports whether the catalog's transformers register. A
// disabled subscription is still pinned and imported by the generated
// module, so it belongs in the resolved registry, but it contributes no
// transformer; reading the list without this field would overstate what
// the platform runs. Every catalog an active claim contributed is
// enabled.
// +optional
Enabled bool `json:"enabled,omitzero"`
// source records which of the two transformer paths put the catalog
// here, so an operator can tell an authored subscription from one a
// provider registered.
// +required
Source RegistryEntrySource `json:"source"`
}
ResolvedRegistryEntry is one catalog of the registry the platform is actually running, resolved from both of its sources. A catalog is one registry key, so an authored subscription and a claim naming the same catalog resolve to a single entry sourced Subscription: the admin's pin and enable decision is the deliberate one.
func (*ResolvedRegistryEntry) DeepCopy ¶
func (in *ResolvedRegistryEntry) DeepCopy() *ResolvedRegistryEntry
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ResolvedRegistryEntry.
func (*ResolvedRegistryEntry) DeepCopyInto ¶
func (in *ResolvedRegistryEntry) DeepCopyInto(out *ResolvedRegistryEntry)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type RolloutSpec ¶
type RolloutSpec struct {
// Strategy controls how apply operations are performed.
// +kubebuilder:validation:Enum=Apply
// +optional
Strategy string `json:"strategy,omitempty"`
// ForceConflicts enables SSA force ownership when desired.
// +optional
ForceConflicts bool `json:"forceConflicts,omitempty"`
}
RolloutSpec configures apply behavior for a release.
func (*RolloutSpec) DeepCopy ¶
func (in *RolloutSpec) DeepCopy() *RolloutSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new RolloutSpec.
func (*RolloutSpec) DeepCopyInto ¶
func (in *RolloutSpec) DeepCopyInto(out *RolloutSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type SourceReference ¶
type SourceReference = fluxmeta.NamespacedObjectKindReference
SourceReference points to a Flux source object. Used by Release; ModuleInstance uses CUE-native module resolution instead.
type SourceStatus ¶
type SourceStatus struct {
// Ref is the resolved source reference.
// +optional
Ref *SourceReference `json:"ref,omitempty"`
// ArtifactRevision is the revision reported by the source artifact.
// +optional
ArtifactRevision string `json:"artifactRevision,omitempty"`
// ArtifactDigest is the digest reported by the source artifact.
// +optional
ArtifactDigest string `json:"artifactDigest,omitempty"`
// ArtifactURL is the fetch URL reported by the source artifact.
// +optional
ArtifactURL string `json:"artifactURL,omitempty"`
}
SourceStatus describes the resolved source artifact used by a reconcile.
func (*SourceStatus) DeepCopy ¶
func (in *SourceStatus) DeepCopy() *SourceStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SourceStatus.
func (*SourceStatus) DeepCopyInto ¶
func (in *SourceStatus) DeepCopyInto(out *SourceStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type Subscription ¶ added in v0.7.0
type Subscription struct {
// Enable toggles the subscription. A pointer so that an omitted value
// defers to the schema default (true) rather than serializing as an
// explicit false. A disabled subscription is still pinned and imported by
// the generated module, with enable set to false on its entry.
// +optional
Enable *bool `json:"enable,omitempty"`
// Version names exactly one published catalog build as a bare SemVer
// string (e.g. "2.0.0-alpha.3") — the platform module IS the resolution
// (0010:D14); there is no range or allow/deny vocabulary. The
// version's major must agree with the subscription key's `@vN` suffix.
// The operator uses it twice: as the generated cue.mod pin and as the
// entry's stamped expected version, which unifies with the imported
// catalog's own version so wrong bytes fail the build naming the entry
// (0019:D13).
// CRD-required is safe against the stored pre-reshape singleton: API
// server validation ratcheting keeps status-subresource patches working
// against a stored object lacking the field (measured in
// test/integration/crdvalidation).
// +kubebuilder:validation:MinLength=1
// +required
Version string `json:"version"`
}
Subscription is a single catalog registry subscription. It becomes one #registry entry of the generated platform module, carrying the catalog by import.
func (*Subscription) DeepCopy ¶ added in v0.7.0
func (in *Subscription) DeepCopy() *Subscription
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Subscription.
func (*Subscription) DeepCopyInto ¶ added in v0.7.0
func (in *Subscription) DeepCopyInto(out *Subscription)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type TransformerRegistration ¶
type TransformerRegistration struct {
metav1.TypeMeta `json:",inline"`
// metadata is a standard object metadata
// +optional
metav1.ObjectMeta `json:"metadata,omitzero"`
// spec defines the desired state of TransformerRegistration
// +required
Spec TransformerRegistrationSpec `json:"spec"`
// status defines the observed state of TransformerRegistration
// +optional
Status TransformerRegistrationStatus `json:"status,omitzero"`
}
TransformerRegistration is the Schema for the transformerregistrations API. It is the cluster-scoped claim a provider module ships among its rendered resources, the second path by which transformers reach a platform (0015:D3); the first is a subscription in Platform.spec.registry.
metadata.name is the dot-joined "<namespace>.<name>" of the claiming instance (0015:D12). A namespace cannot contain a dot, so the join is collision-free and two instances of one provider module produce two distinct claims, the second refused at acceptance naming the claimant, rather than contending for one object.
Creating one requires platform-admin RBAC. The operator ships that role unbound (config/rbac/transformerregistration_admin_role.yaml) and ships no tenant-facing role granting create, so a module applied under an impersonated tenant ServiceAccount cannot register a transformer unless a cluster administrator deliberately bound it.
func (*TransformerRegistration) DeepCopy ¶
func (in *TransformerRegistration) DeepCopy() *TransformerRegistration
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TransformerRegistration.
func (*TransformerRegistration) DeepCopyInto ¶
func (in *TransformerRegistration) DeepCopyInto(out *TransformerRegistration)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*TransformerRegistration) DeepCopyObject ¶
func (in *TransformerRegistration) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
func (*TransformerRegistration) GetConditions ¶
func (in *TransformerRegistration) GetConditions() []metav1.Condition
GetConditions returns the status conditions of the TransformerRegistration.
func (*TransformerRegistration) SetConditions ¶
func (in *TransformerRegistration) SetConditions(conditions []metav1.Condition)
SetConditions sets the status conditions on the TransformerRegistration.
type TransformerRegistrationList ¶
type TransformerRegistrationList struct {
metav1.TypeMeta `json:",inline"`
metav1.ListMeta `json:"metadata,omitzero"`
Items []TransformerRegistration `json:"items"`
}
TransformerRegistrationList contains a list of TransformerRegistration.
func (*TransformerRegistrationList) DeepCopy ¶
func (in *TransformerRegistrationList) DeepCopy() *TransformerRegistrationList
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TransformerRegistrationList.
func (*TransformerRegistrationList) DeepCopyInto ¶
func (in *TransformerRegistrationList) DeepCopyInto(out *TransformerRegistrationList)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (*TransformerRegistrationList) DeepCopyObject ¶
func (in *TransformerRegistrationList) DeepCopyObject() runtime.Object
DeepCopyObject is an autogenerated deepcopy function, copying the receiver, creating a new runtime.Object.
type TransformerRegistrationSpec ¶
type TransformerRegistrationSpec struct {
// Catalog is the provider catalog's major-suffixed CUE module path
// (e.g. "opmodel.dev/catalogs/k8up@v1"). It names a catalog, never a
// module: a catalog is what carries transformers, so a claim naming a
// module names nothing that could implement a contract. Acceptance
// refuses a non-catalog artifact structurally (0015:D10).
// +kubebuilder:validation:MinLength=1
// +required
Catalog string `json:"catalog"`
// Version is the released build of the named catalog, a bare SemVer
// string (e.g. "1.0.0"). It pins the claim to one build, which is what
// lets acceptance re-derive Provides from the artifact this names.
// +kubebuilder:validation:MinLength=1
// +required
Version string `json:"version"`
// Provides lists every provider-fulfilled contract FQN the named catalog
// claims to implement.
//
// Required but MAY be empty. A provider catalog implementing no
// provider-fulfilled contract is a claim acceptance refuses on its merits,
// naming the catalog it re-derived from, not a malformed object. The CRD
// is the wrong place to encode a rule the reconciler states better.
// +required
Provides []string `json:"provides"`
// ProviderRef identifies the ModuleInstance that rendered this claim. It
// is stamped from the rendering instance and never authored, so a module
// cannot claim to be another provider (0015:D11).
// +required
ProviderRef ProviderReference `json:"providerRef"`
}
TransformerRegistrationSpec defines a provider module's claim that its catalog implements platform contracts (0015:D3).
Every field is required at the CRD level, deliberately duplicating the catalog-side contract rather than trusting it. CUE reports a missing required field as an incomplete value, not an error: measured 2026-09-14 at cue v0.17.1, a component omitting `catalog` passes `cue vet ./...` and fails only under `cue export`. A claim can therefore reach the cluster with a field absent, so the API server validates it on its own terms.
func (*TransformerRegistrationSpec) DeepCopy ¶
func (in *TransformerRegistrationSpec) DeepCopy() *TransformerRegistrationSpec
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TransformerRegistrationSpec.
func (*TransformerRegistrationSpec) DeepCopyInto ¶
func (in *TransformerRegistrationSpec) DeepCopyInto(out *TransformerRegistrationSpec)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
type TransformerRegistrationStatus ¶
type TransformerRegistrationStatus struct {
// observedGeneration is the .metadata.generation this claim was last
// reconciled for, whether or not that reconcile reached a verdict: a claim
// waiting on the platform or on its provider's inventory records the
// generation it observed rather than reading as un-reconciled. A claim
// whose generation is ahead of this has been edited since, so whatever
// conditions report is stale.
// +optional
ObservedGeneration int64 `json:"observedGeneration,omitempty"`
// conditions represent the current state of the TransformerRegistration
// resource.
// +listType=map
// +listMapKey=type
// +optional
Conditions []metav1.Condition `json:"conditions,omitempty"`
// accepted reports whether the claim passed acceptance: the catalog
// resolved, its Provides re-derived equal, and no other instance holds
// the same provider.
// +optional
Accepted bool `json:"accepted,omitzero"`
// active reports whether an accepted claim's provider is serving. An
// accepted claim stays inactive until its ModulePackage is Ready.
// +optional
Active bool `json:"active,omitzero"`
}
TransformerRegistrationStatus defines the observed state of a TransformerRegistration.
Acceptance and activation are separate states (0015:D3): a stored claim is not yet judged, accepted but inactive, or active. The acceptance reconciler writes conditions, accepted and observedGeneration; active stays false until an accepted claim's provider is serving.
func (*TransformerRegistrationStatus) DeepCopy ¶
func (in *TransformerRegistrationStatus) DeepCopy() *TransformerRegistrationStatus
DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TransformerRegistrationStatus.
func (*TransformerRegistrationStatus) DeepCopyInto ¶
func (in *TransformerRegistrationStatus) DeepCopyInto(out *TransformerRegistrationStatus)
DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.