Documentation
¶
Overview ¶
Generated by *go generate* - DO NOT EDIT
Copyright 2026. projectsveltos.io. All rights reserved.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Generated by *go generate* - DO NOT EDIT
Copyright 2026. projectsveltos.io. All rights reserved.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Generated by *go generate* - DO NOT EDIT
Copyright 2026. projectsveltos.io. All rights reserved.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Generated by *go generate* - DO NOT EDIT
Copyright 2026. projectsveltos.io. All rights reserved.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Generated by *go generate* - DO NOT EDIT
Copyright 2026. projectsveltos.io. All rights reserved.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Generated by *go generate* - DO NOT EDIT
Copyright 2026. projectsveltos.io. All rights reserved.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ClusterConfigurationCRD = []byte(`---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.21.0
name: clusterconfigurations.config.projectsveltos.io
spec:
group: config.projectsveltos.io
names:
kind: ClusterConfiguration
listKind: ClusterConfigurationList
plural: clusterconfigurations
singular: clusterconfiguration
scope: Namespaced
versions:
- name: v1beta1
schema:
openAPIV3Schema:
description: ClusterConfiguration is the Schema for the clusterconfigurations
API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
status:
description: ClusterConfigurationStatus defines the observed state of
ClusterConfiguration
properties:
clusterProfileResources:
description: |-
ClusterProfileResources is the list of resources currently deployed in a Cluster due
to ClusterProfiles
items:
description: |-
ClusterProfileResource keeps info on all of the resources deployed in this Cluster
due to a given ClusterProfile
properties:
Features:
description: |-
Features contains the list of policies deployed in the Cluster because
of a given feature
items:
properties:
charts:
description: Charts is a list of helm charts deployed
in the Cluster.
items:
properties:
appVersion:
description: AppVersion is the version of the app
deployed in the Cluster.
type: string
chartVersion:
description: ChartVersion is the version of the
helm chart deployed in the Cluster.
type: string
icon:
description: The URL to an icon file.
type: string
lastAppliedTime:
description: LastAppliedTime identifies when this
resource was last applied to the cluster.
format: date-time
type: string
namespace:
description: Namespace where chart is deployed in
the Cluster.
type: string
releaseName:
description: ReleaseName name of the release deployed
in the Cluster.
minLength: 1
type: string
repoURL:
description: |-
RepoURL URL of the repo containing the helm chart deployed
in the Cluster.
minLength: 1
type: string
required:
- chartVersion
- lastAppliedTime
- releaseName
- repoURL
type: object
type: array
featureID:
description: FeatureID is an indentifier of the feature
whose status is reported
enum:
- Resources
- Helm
- Kustomize
type: string
resources:
description: Resources is a list of resources deployed
in the Cluster.
items:
properties:
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources is deployed
into the management cluster (local) or the managed cluster (remote)
enum:
- Local
- Remote
type: string
group:
description: Group of the resource deployed in the
Cluster.
type: string
kind:
description: Kind of the resource deployed in the
Cluster.
minLength: 1
type: string
lastAppliedTime:
description: LastAppliedTime identifies when this
resource was last applied to the cluster.
format: date-time
type: string
name:
description: Name of the resource deployed in the
Cluster.
minLength: 1
type: string
namespace:
description: |-
Namespace of the resource deployed in the Cluster.
Empty for resources scoped at cluster level.
type: string
version:
description: Version of the resource deployed in
the Cluster.
minLength: 1
type: string
required:
- group
- kind
- name
- version
type: object
type: array
required:
- featureID
type: object
type: array
clusterProfileName:
description: ProfileName is the name of the ClusterProfile matching
the Cluster.
type: string
required:
- clusterProfileName
type: object
type: array
profileResources:
description: |-
ProfileResources is the list of resources currently deployed in a Cluster due
to Profiles
items:
description: |-
ProfileResource keeps info on all of the resources deployed in this Cluster
due to a given Profile
properties:
Features:
description: |-
Features contains the list of policies deployed in the Cluster because
of a given feature
items:
properties:
charts:
description: Charts is a list of helm charts deployed
in the Cluster.
items:
properties:
appVersion:
description: AppVersion is the version of the app
deployed in the Cluster.
type: string
chartVersion:
description: ChartVersion is the version of the
helm chart deployed in the Cluster.
type: string
icon:
description: The URL to an icon file.
type: string
lastAppliedTime:
description: LastAppliedTime identifies when this
resource was last applied to the cluster.
format: date-time
type: string
namespace:
description: Namespace where chart is deployed in
the Cluster.
type: string
releaseName:
description: ReleaseName name of the release deployed
in the Cluster.
minLength: 1
type: string
repoURL:
description: |-
RepoURL URL of the repo containing the helm chart deployed
in the Cluster.
minLength: 1
type: string
required:
- chartVersion
- lastAppliedTime
- releaseName
- repoURL
type: object
type: array
featureID:
description: FeatureID is an indentifier of the feature
whose status is reported
enum:
- Resources
- Helm
- Kustomize
type: string
resources:
description: Resources is a list of resources deployed
in the Cluster.
items:
properties:
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources is deployed
into the management cluster (local) or the managed cluster (remote)
enum:
- Local
- Remote
type: string
group:
description: Group of the resource deployed in the
Cluster.
type: string
kind:
description: Kind of the resource deployed in the
Cluster.
minLength: 1
type: string
lastAppliedTime:
description: LastAppliedTime identifies when this
resource was last applied to the cluster.
format: date-time
type: string
name:
description: Name of the resource deployed in the
Cluster.
minLength: 1
type: string
namespace:
description: |-
Namespace of the resource deployed in the Cluster.
Empty for resources scoped at cluster level.
type: string
version:
description: Version of the resource deployed in
the Cluster.
minLength: 1
type: string
required:
- group
- kind
- name
- version
type: object
type: array
required:
- featureID
type: object
type: array
profileName:
description: ProfileName is the name of the Profile matching
the Cluster.
type: string
required:
- profileName
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
`)
var ClusterConfigurationFile = "../../config/crd/bases/config.projectsveltos.io_clusterconfigurations.yaml"
var ClusterProfileCRD = []byte(`---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.21.0
name: clusterprofiles.config.projectsveltos.io
spec:
group: config.projectsveltos.io
names:
kind: ClusterProfile
listKind: ClusterProfileList
plural: clusterprofiles
singular: clusterprofile
scope: Cluster
versions:
- name: v1beta1
schema:
openAPIV3Schema:
description: ClusterProfile is the Schema for the clusterprofiles API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
properties:
clusterRefs:
description: ClusterRefs identifies clusters to associate to.
items:
description: ObjectReference contains enough information to let
you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
clusterSelector:
description: ClusterSelector identifies clusters to associate to.
properties:
matchExpressions:
description: matchExpressions is a list of label selector requirements.
The requirements are ANDed.
items:
description: |-
A label selector requirement is a selector that contains values, a key, and an operator that
relates the key and values.
properties:
key:
description: key is the label key that the selector applies
to.
type: string
operator:
description: |-
operator represents a key's relationship to a set of values.
Valid operators are In, NotIn, Exists and DoesNotExist.
type: string
values:
description: |-
values is an array of string values. If the operator is In or NotIn,
the values array must be non-empty. If the operator is Exists or DoesNotExist,
the values array must be empty. This array is replaced during a strategic
merge patch.
items:
type: string
type: array
x-kubernetes-list-type: atomic
required:
- key
- operator
type: object
type: array
x-kubernetes-list-type: atomic
matchLabels:
additionalProperties:
type: string
description: |-
matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
map is equivalent to an element of matchExpressions, whose key field is "key", the
operator is "In", and the values array contains only "value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
continueOnConflict:
default: false
description: |-
By default (when ContinueOnConflict is unset or set to false), Sveltos stops deployment after
encountering the first conflict (e.g., another ClusterProfile already deployed the resource).
If set to true, Sveltos will attempt to deploy remaining resources in the ClusterProfile even
if conflicts are detected for previous resources.
type: boolean
continueOnError:
default: false
description: |-
By default (when ContinueOnError is unset or set to false), Sveltos stops deployment after
encountering the first error.
If set to true, Sveltos will attempt to deploy remaining resources in the ClusterProfile even
if errors are detected for previous resources.
type: boolean
dependsOn:
description: |-
DependsOn specifies a list of other profiles that this instance depends on.
A ClusterProfile can only depend on other ClusterProfiles, and a Profile can
only depend on other Profiles.
The add-ons and applications defined in this instance will not be deployed
until all add-ons and applications in the profiles listed as dependencies are deployed.
items:
type: string
type: array
driftExclusions:
description: |-
DriftExclusions is a list of configuration drift exclusions to be applied when syncMode is
set to ContinuousWithDriftDetection. Each exclusion specifies JSON6902 paths to ignore
when evaluating drift, optionally targeting specific resources and features.
items:
properties:
paths:
description: Paths is a slice of JSON6902 paths to exclude from
configuration drift evaluation.
items:
type: string
type: array
target:
description: Target points to the resources that the paths refers
to.
properties:
annotationSelector:
description: |-
AnnotationSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource annotations.
type: string
group:
description: |-
Group is the API group to select resources from.
Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
kind:
description: |-
Kind of the API Group to select resources from.
Together with Group and Version it is capable of unambiguously
identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
labelSelector:
description: |-
LabelSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource labels.
type: string
name:
description: Name to match resources with.
type: string
namespace:
description: Namespace to select resources from.
type: string
version:
description: |-
Version of the API Group to select resources from.
Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
type: object
required:
- paths
type: object
type: array
x-kubernetes-list-type: atomic
extraAnnotations:
additionalProperties:
type: string
description: |-
ExtraAnnotations: These annotations will be added by Sveltos to all Kubernetes resources
deployed in a managed cluster based on this ClusterProfile/Profile instance.
**Important:** If a resource deployed by Sveltos already has a annotation with a key present in
` + "`" + `ExtraAnnotations` + "`" + `, the value from ` + "`" + `ExtraAnnotations` + "`" + ` will override the existing value.
(Deprecated use Patches instead)
type: object
extraLabels:
additionalProperties:
type: string
description: |-
ExtraLabels: These labels will be added by Sveltos to all Kubernetes resources deployed in
a managed cluster based on this ClusterProfile/Profile instance.
**Important:** If a resource deployed by Sveltos already has a label with a key present in
` + "`" + `ExtraLabels` + "`" + `, the value from ` + "`" + `ExtraLabels` + "`" + ` will override the existing value.
(Deprecated use Patches instead)
type: object
helmCharts:
description: Helm charts is a list of helm charts that need to be
deployed
items:
properties:
chartName:
description: |-
ChartName is the chart name
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
Must be defined otherwise.
type: string
chartVersion:
description: |-
ChartVersion is the chart version
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
It is ignored if RepositoryURL references a Flux Source.
Must be defined otherwise.
type: string
helmChartAction:
default: Install
description: HelmChartAction is the action that will be taken
on the helm chart
enum:
- Install
- Uninstall
type: string
options:
description: Options allows to set flags which are used during
installation.
properties:
atomic:
default: false
description: |-
if set, the installation process deletes the installation/upgrades on failure.
The --wait flag will be set automatically if --atomic is used
Default to false
type: boolean
dependencyUpdate:
default: false
description: |-
update dependencies if they are missing before installing the chart
Default to false
type: boolean
description:
description: Description is the description of an helm operation
type: string
disableHooks:
default: false
description: |-
prevent hooks from running during install/upgrade/uninstall
Default to false
type: boolean
disableOpenAPIValidation:
default: false
description: |-
if set, the installation process will not validate rendered templates against the Kubernetes OpenAPI Schema
Default to false
type: boolean
enableClientCache:
default: false
description: EnableClientCache is a flag to enable Helm
client cache. If it is not specified, it will be set to
false.
type: boolean
installOptions:
description: HelmInstallOptions are options specific to
helm install
properties:
createNamespace:
default: true
description: Create the release namespace if not present.
Defaults to true
type: boolean
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on install
Default to false
type: boolean
recoverAfterConsecutiveFailures:
default: 5
description: |-
RecoverAfterConsecutiveFailures is the number of consecutive install failures for this
chart after which Sveltos uninstalls any existing release under this name before
retrying, to clear potentially stale Helm release history that would otherwise keep
blocking every subsequent install attempt. This only ever runs when there is no
currently deployed release to protect: a release that is deployed, or mid-upgrade, or
failed while already existing, is always retried through helm upgrade instead, never
through this. It only applies to a release that was never successfully installed, or
was already cleanly uninstalled.
Default to 5
type: integer
replace:
default: true
description: Replaces if set indicates to replace an
older release with this one
type: boolean
takeOwnership:
default: false
description: |-
if set, install will ignore the check for helm annotations
and take ownership of the existing resources
type: boolean
type: object
labels:
additionalProperties:
type: string
description: Labels that would be added to release metadata.
type: object
passCredentialsAll:
description: PassCredentialsAll is the flag to pass credentials
to all domains
type: boolean
postRenderStrategy:
description: |-
PostRenderStrategy controls whether Helm hooks are included when Patches/PatchesFrom
are applied as a post-renderer during this chart's install/upgrade. Only relevant
when Patches or PatchesFrom is set on the Spec; ignored otherwise. Defaults to
Helm's own default (combined) when unset.
enum:
- combined
- separate
- nohooks
type: string
runTests:
default: false
description: |-
RunTests if set to true, Sveltos will run helm test after each successful install or upgrade
operation. The tests are the test hooks defined in the chart (annotated with
"helm.sh/hook: test"). If any test fails the deployment is considered failed and the
error is surfaced in the ClusterSummary status, providing operational gating.
Has no effect in DryRun mode.
Default to false
type: boolean
skipCRDs:
default: false
description: |-
SkipCRDs controls whether CRDs should be installed during install/upgrade operation.
By default, CRDs are installed if not already present.
type: boolean
skipSchemaValidation:
default: false
description: SkipSchemaValidation determines if JSON schema
validation is disabled.
type: boolean
timeout:
description: time to wait for any individual Kubernetes
operation (like Jobs for hooks) (default 5m0s)
type: string
uninstallOptions:
description: HelmUninstallOptions are options specific to
helm uninstall
properties:
deletionPropagation:
description: DeletionPropagation
enum:
- orphan
- foreground
- background
type: string
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on uninstall
Default to false
type: boolean
keepHistory:
description: |-
When uninstall a chart with this flag, Helm removes the resources associated with the chart,
but it keeps the release information. This allows to see details about the uninstalled release
using the helm history command.
type: boolean
type: object
upgradeOptions:
description: HelmUpgradeOptions are options specific to
helm upgrade
properties:
cleanupOnFail:
default: false
description: CleanupOnFail will, if true, cause the
upgrade to delete newly-created resources on a failed
update.
type: boolean
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on upgrade
Default to false
type: boolean
force:
default: false
description: |-
Force will, if set to ` + "`" + `true` + "`" + `, ignore certain warnings and perform the upgrade anyway.
This should be used with caution.
type: boolean
maxHistory:
default: 2
description: |-
MaxHistory limits the maximum number of revisions saved per release
Default to 2
type: integer
recreate:
default: false
description: |-
Recreate will (if true) recreate pods after a rollback.
Deprecated: This field is no longer supported
type: boolean
resetThenReuseValues:
default: false
description: ResetThenReuseValues will reset the values
to the chart's built-ins then merge with user's last
supplied values.
type: boolean
resetValues:
default: false
description: ResetValues will reset the values to the
chart's built-ins rather than merging with existing.
type: boolean
reuseValues:
default: false
description: |-
ReuseValues copies values from the current release to a new release if the
new release does not have any values. If the request already has values,
or if there are no values in the current release, this does nothing.
This is skipped if the ResetValues flag is set, in which case the
request values are not altered.
type: boolean
subNotes:
default: false
description: SubNotes determines whether sub-notes are
rendered in the chart.
type: boolean
takeOwnership:
default: false
description: |-
if set, upgrade will ignore the check for helm annotations
and take ownership of the existing resources
type: boolean
upgradeCRDs:
default: false
description: |-
UpgradeCRDs upgrade CRDs from the Helm Chart's crds directory
By default, CRDs are not applied during Helm upgrade action by Helm
https://helm.sh/docs/chart_best_practices/custom_resource_definitions/
type: boolean
type: object
wait:
default: false
description: |-
if set, will wait until all Pods, PVCs, Services, and minimum number of Pods of a Deployment, StatefulSet, or ReplicaSet
are in a ready state before marking the release as successful. It will wait for as long as --timeout
Default to false
type: boolean
waitForJobs:
default: false
description: |-
if set and --wait enabled, will wait until all Jobs have been completed before marking the release as successful.
It will wait for as long as --timeout
Default to false
type: boolean
type: object
provenanceVerification:
description: |-
ProvenanceVerification configures Helm GPG .prov file verification for HTTP chart repositories.
Ignored for OCI and Flux-sourced charts.
properties:
keyringSecretRef:
description: |-
KeyringSecretRef references a Secret in the management cluster containing the GPG keyring.
The Secret must have a key named "keyring.gpg".
If Namespace is omitted, the cluster's namespace is used.
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
required:
- keyringSecretRef
type: object
registryCredentialsConfig:
description: |-
RegistryCredentialsConfig is an optional configuration for credentials,
including information to connect to private registries.
properties:
ca:
description: |-
CASecretRef references a secret containing the TLS CA certificate
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
key: ca.crt
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
credentials:
description: |-
CredentialsSecretRef references a secret containing credentials
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
insecureSkipTLSVerify:
description: InsecureSkipTLSVerify controls server certificate
verification.
type: boolean
key:
description: |-
Key specifies the key within the CredentialsSecretRef containing the data
If not specified, it defaults to the only key in the secret if there's just one.
type: string
plainHTTP:
description: PlainHTTP indicates to use insecure HTTP connections
for the chart download
type: boolean
type: object
releaseName:
description: ReleaseName is the chart release
minLength: 1
type: string
releaseNamespace:
description: ReleaseNamespace is the namespace release will
be installed
minLength: 1
type: string
repositoryName:
description: |-
RepositoryName is the name helm chart repository
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
It is ignored if RepositoryURL references a Flux Source.
Must be defined otherwise.
type: string
repositoryURL:
description: |-
RepositoryURL is the URL helm chart repository
It can point to a traditional HTTP-based repository or an OCI registry.
Examples:
- HTTP Repository: https://charts.example.com/stable
- OCI Registry: oci://registry.example.com/namespace/charts
- GitHub Pages: https://<username>.github.io/<repository>/
- Any other valid URL where Helm charts are hosted.
Alternatively, it can be a Flux source reference:
<flux source kind>://<flux source namespace>/<flux source name>/<path>
Where:
- <flux source kind> is the type of Flux source (gitrepository, ocirepository, bucket).
- <flux source namespace> and <flux source name> are the namespace and name of the Flux Source in the management cluster.
- <path> is the path within the source repository where the Helm charts are located.
For instance:
gitrepository://flux-system/flux-system/charts/projectsveltos
Assuming there is a Flux GitRepository named 'flux-system' in the 'flux-system' namespace
syncing 'https://github.com/projectsveltos/helm-charts.git/', and the Helm charts are
located in the 'charts/projectsveltos' directory of that repository.
minLength: 1
type: string
signatureVerification:
description: |-
SignatureVerification configures Cosign-based signature verification for OCI Helm charts.
Ignored when RepositoryURL does not start with "oci://".
properties:
matchOIDCIdentity:
description: |-
MatchOIDCIdentity lists OIDC identity matchers for keyless verification.
At least one matcher must be satisfied. Required when Provider is Keyless.
items:
description: OIDCIdentityMatcher specifies the expected
OIDC issuer and subject for keyless Cosign verification.
properties:
issuer:
description: Issuer is the OIDC issuer URL or regex.
minLength: 1
type: string
subject:
description: Subject is the OIDC subject or regex,
typically the workload identity or GitHub Actions
workflow URL.
minLength: 1
type: string
required:
- issuer
- subject
type: object
type: array
provider:
description: Provider specifies how to obtain the verification
key or certificate.
enum:
- PublicKey
- Keyless
type: string
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing the Cosign public key.
The Secret must have a key named "cosign.pub" holding a PEM-encoded public key.
Required when Provider is PublicKey.
If Namespace is omitted, the cluster's namespace is used.
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
required:
- provider
type: object
values:
description: |-
Values field allows to define configuration for the Helm release.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
valuesFrom:
description: |-
ValuesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to store configuration for the Helm release.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
required:
- releaseName
- releaseNamespace
- repositoryURL
type: object
x-kubernetes-validations:
- message: ChartName must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.chartName)
>= 1 : true'
- message: ChartName must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.chartName)
>= 1 : true'
- message: ChartVersion must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.chartVersion)
>= 1 : true'
- message: ChartVersion must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.chartVersion)
>= 1 : true'
- message: RepositoryName must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.repositoryName)
>= 1 : true'
- message: RepositoryName must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.repositoryName)
>= 1 : true'
type: array
x-kubernetes-list-type: atomic
kustomizationRefs:
description: |-
Kustomization refs is a list of kustomization paths. Kustomization will
be run on those paths and the outcome will be deployed.
items:
properties:
components:
description: |-
Components is a list of paths to Kustomize components. These paths are relative to the
` + "`" + `Path` + "`" + ` field and are included in the Kustomize build to provide reusable configuration logic.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
type: string
type: array
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
NOTE: DeploymentType Local cannot be used when the matching cluster is the management cluster itself.
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
KustomizationRef when an update is rejected with an error that only a delete+recreate
can resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this KustomizationRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- flux GitRepository;OCIRepository;Bucket
- ConfigMap/Secret
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
path:
description: |-
Path to the directory containing the kustomization.yaml file, or the
set of plain YAMLs a kustomization.yaml should be generated for.
Defaults to 'None', which translates to the root path of the SourceRef.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching the Kustomize directory content from an HTTP/HTTPS
endpoint or an OCI registry, without requiring a Flux GitRepository/OCIRepository/Bucket
or a ConfigMap/Secret.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the remote source serving the Kustomize directory content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint serving a gzipped tarball
(.tar.gz) of the Kustomize directory
"oci://" — OCI registry artifact whose layers are extracted
the same way, preserving the directory tree
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this KustomizationRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
targetNamespace:
description: |-
TargetNamespace sets or overrides the namespace in the
kustomization.yaml file.
maxLength: 63
minLength: 1
type: string
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different KustomizationRef
within the same ClusterProfile or Profile.
When two KustomizationRef attempt to deploy the same resource, the KustomizationRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
values:
additionalProperties:
type: string
description: |-
Values is a map[string]string type that allows to define a set of key-value pairs.
These key-value pairs can optionally leverage Go templates for further processing.
With Sveltos, you can define key-value pairs where the values can be Go templates.
These templates have access to management cluster information during deployment. This allows
to do more than just replace placeholders. Variables can be used to dynamically
construct values based on other resources or variables within the Kustomize output.
For example, imagine you have a Region key with a template value like:
'{{ index .Cluster.metadata.labels "region" }}'.
This template retrieves the region label from the cluster instance metadata.
Finally, Sveltos uses these processed values to fill placeholders in the Kustomize output.
The output itself can also contain templates, like:
region: '{{ default "west" .Region }}'.
This way, the final output from Kustomize will have the region set dynamically based on
the actual region retrieved earlier.
type: object
valuesFrom:
description: |-
ValuesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to define key-value pairs. These key-value pairs can optionally leverage
Go templates for further processing.
With Sveltos, you can define key-value pairs where the values can be Go templates.
These templates have access to management cluster information during deployment. This allows
to do more than just replace placeholders. Variables can be used to dynamically
construct values based on other resources or variables within the Kustomize output.
For example, imagine you have a Region key with a template value like:
'{{ index .Cluster.metadata.labels "region" }}'.
This template retrieves the region label from the cluster instance metadata.
Finally, Sveltos uses these processed values to fill placeholders in the Kustomize output.
The output itself can also contain templates, like:
region: '{{ default "west" .Region }}'.
This way, the final output from Kustomize will have the region set dynamically based on
the actual region retrieved earlier.
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but not both
rule: has(self.remoteURL) != has(self.kind)
type: array
x-kubernetes-list-type: atomic
maxConsecutiveFailures:
description: |-
The maximum number of consecutive deployment failures that Sveltos will permit.
After this many consecutive failures, the deployment will be considered failed, and Sveltos will stop retrying.
This setting applies only to feature deployments, not resource removal.
This field is optional. If not set, Sveltos default behavior is to keep retrying.
type: integer
maxUpdate:
anyOf:
- type: integer
- type: string
description: |-
The maximum number of clusters that can be updated concurrently.
Value can be an absolute number (ex: 5) or a percentage of desired cluster (ex: 10%).
Defaults to 100%.
Example: when this is set to 30%, when list of add-ons/applications in ClusterProfile
changes, only 30% of matching clusters will be updated in parallel. Only when updates
in those cluster succeed, other matching clusters are updated.
pattern: ^((100|[0-9]{1,2})%|[0-9]+)$
x-kubernetes-int-or-string: true
patches:
description: |-
Define additional Kustomize inline Patches applied for all resources on this profile
Within the Patch Spec you can use templating
items:
description: |-
Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should
be applied to.
properties:
patch:
description: |-
Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with
an array of operation objects.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
target:
description: Target points to the resources that the patch document
should be applied to.
properties:
annotationSelector:
description: |-
AnnotationSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource annotations.
type: string
group:
description: |-
Group is the API group to select resources from.
Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
kind:
description: |-
Kind of the API Group to select resources from.
Together with Group and Version it is capable of unambiguously
identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
labelSelector:
description: |-
LabelSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource labels.
type: string
name:
description: Name to match resources with.
type: string
namespace:
description: Namespace to select resources from.
type: string
version:
description: |-
Version of the API Group to select resources from.
Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
type: object
required:
- patch
type: object
type: array
x-kubernetes-list-type: atomic
patchesFrom:
description: |-
PatchesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to store additional Kustomize inline Patches applied for all resources on this profile
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
x-kubernetes-list-type: atomic
policyRefs:
description: |-
PolicyRefs references all the ConfigMaps/Secrets/Flux Sources containing kubernetes resources
that need to be deployed in the matching managed clusters.
The values contained in those resources can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
PolicyRef when an update is rejected with an error that only a delete+recreate can
resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this PolicyRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
- flux GitRepository;OCIRepository;Bucket
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other PolicyRefs.
type: boolean
path:
description: |-
Path to the directory containing the YAML files.
Defaults to 'None', which translates to the root path of the SourceRef.
Used only for GitRepository;OCIRepository;Bucket
This value can be static or leverage Go templates for dynamic customization.
When expressed as a template, it is filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching content from an HTTP/HTTPS endpoint or an OCI registry.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
template:
description: |-
Template indicates that the fetched content is a Go template that
must be instantiated using cluster fields and templateResourceRefs values
before deployment. Equivalent to the projectsveltos.io/template annotation
on a ConfigMap or Secret.
type: boolean
url:
description: |-
URL is the remote source serving raw YAML/JSON content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint returning a raw YAML/JSON
document, a gzip-compressed document, an
uncompressed tar, or a gzip-compressed tar of
.yaml/.yml/.json files
"oci://" — OCI registry artifact whose layers are accepted
in the same shapes: raw YAML/JSON, gzip-compressed
YAML/JSON, uncompressed tar, or gzip-compressed tar
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this PolicyRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different PolicyRefs
within the same ClusterProfile or Profile.
When two PolicyRefs attempt to deploy the same resource, the PolicyRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but not both
rule: has(self.remoteURL) != has(self.kind)
type: array
x-kubernetes-list-type: atomic
postDeleteChecks:
description: |-
PostDeleteChecks is a slice of checks to run against the managed cluster
*after* Sveltos has deleted all resources.
This ensures that the environment has reached the desired clean state.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for the
rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based on
current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
preDeleteChecks:
description: |-
PreDeleteChecks is a slice of checks to run against the managed cluster
*before* Sveltos starts deleting resources.
If any of these fail, the deletion process is halted.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for the
rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based on
current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
preDeployChecks:
description: |-
PreDeployChecks is a slice of checks to run against the managed cluster
*before* Sveltos starts deploying resources.
Each check can use Lua scripts or CEL expressions to validate the cluster state.
If any check fails, the deployment of the associated feature is halted.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for the
rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based on
current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
reloader:
default: false
description: |-
Reloader indicates whether Deployment/StatefulSet/DaemonSet instances deployed
by Sveltos and part of this ClusterProfile need to be restarted via rolling upgrade
when a ConfigMap/Secret instance mounted as volume is modified.
When set to true, when any mounted ConfigMap/Secret is modified, Sveltos automatically
starts a rolling upgrade for Deployment/StatefulSet/DaemonSet instances mounting it.
type: boolean
setRefs:
description: |-
SetRefs identifies referenced (cluster)Sets.
- ClusterProfile can reference ClusterSet;
- Profile can reference Set;
items:
type: string
type: array
stopMatchingBehavior:
default: WithdrawPolicies
description: |-
StopMatchingBehavior indicates what behavior should be when a Cluster stop matching
the ClusterProfile. By default all deployed Helm charts and Kubernetes resources will
be withdrawn from Cluster. Setting StopMatchingBehavior to LeavePolicies will instead
leave ClusterProfile deployed policies in the Cluster.
enum:
- WithdrawPolicies
- LeavePolicies
type: string
syncMode:
default: Continuous
description: |-
SyncMode specifies how features are synced in a matching workload cluster.
- OneTime means, first time a workload cluster matches the ClusterProfile,
features will be deployed in such cluster. Any subsequent feature configuration
change won't be applied into the matching workload clusters;
- Continuous mode ensures that the first time a workload cluster matches a ClusterProfile,
the specified features are deployed. Subsequent changes to the feature configuration are also
automatically applied to all matching workload clusters.
_ SyncModeContinuousWithDriftDetection operates similarly to Continuous mode, but also monitors
matching managed clusters for configuration drift. If drift is detected, a reconciliation is
triggered to ensure the managed cluster's configuration aligns with the ClusterProfile.
- DryRun means no change will be propagated to any matching cluster. A report
instead will be generated summarizing what would happen in any matching cluster
because of the changes made to ClusterProfile while in DryRun mode.
enum:
- OneTime
- Continuous
- ContinuousWithDriftDetection
- DryRun
type: string
templateResourceRefs:
description: |-
TemplateResourceRefs is a list of resource to collect from the management cluster.
Those resources' values will be used to instantiate templates
items:
properties:
identifier:
description: |-
Identifier is how the resource will be referred to in the
template
type: string
ignoreStatusChanges:
default: false
description: |-
IgnoreStatusChanges indicates whether changes to the status of the referenced
resource should be ignored. If set to true, only changes to the spec or
metadata (generation change) will trigger a reconciliation.
type: boolean
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other TemplateResourceRefs.
type: boolean
resource:
description: |-
Resource references a Kubernetes instance in the management
cluster to fetch and use during template instantiation.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
Name and namespace can be expressed as a template and instantiate using any cluster field.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
watchFields:
description: |-
WatchFields is an optional list of dot-separated field paths to include
when computing the hash for this resource (e.g. "status.readyReplicas",
"metadata.labels"). When non-empty, only the listed fields are hashed and
IgnoreStatusChanges is ignored. Use this when you need to react to a
specific field without being sensitive to every other change on the object.
items:
type: string
type: array
required:
- identifier
- resource
type: object
type: array
x-kubernetes-list-map-keys:
- identifier
x-kubernetes-list-type: map
tier:
default: 100
description: |-
Tier controls the order of deployment for ClusterProfile or Profile resources targeting
the same cluster resources.
Imagine two configurations (ClusterProfiles or Profiles) trying to deploy the same resource (a Kubernetes
resource or an helm chart). By default, the first one to reach the cluster "wins" and deploys it.
Tier allows you to override this. When conflicts arise, the ClusterProfile or Profile with the **lowest**
Tier value takes priority and deploys the resource.
Higher Tier values represent lower priority. The default Tier value is 100.
Using Tiers provides finer control over resource deployment within your cluster, particularly useful
when multiple configurations manage the same resources.
format: int32
minimum: 1
type: integer
validateHealths:
description: |-
ValidateHealths is a slice of checks to run against the managed cluster
*after* resources are deployed to validate that the state of the
add-ons/applications is healthy.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for the
rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based on
current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
type: object
status:
description: Status defines the observed state of ClusterProfile/Profile
properties:
dependenciesHash:
description: |-
DependenciesHash is a hash representing the set of clusters where this ClusterProfile
must be deployed, based on the combined configuration of its dependencies.
format: byte
type: string
failedClusters:
description: |-
FailedClusters contains information about clusters for which
a ClusterSummary could not be created or updated.
items:
description: |-
FailedCluster describes an error encountered while trying to
manage resources for a specific matching cluster.
properties:
clusterRef:
description: ClusterRef is a reference to the cluster where
the failure occurred.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
failureMessage:
description: |-
FailureMessage is a human-readable explanation of why the
ClusterSummary creation/update failed.
type: string
lastFailureTime:
description: LastFailureTime is the time the error occurred.
format: date-time
type: string
required:
- clusterRef
- failureMessage
type: object
type: array
matchingClusters:
description: |-
MatchingClusterRefs reference all the clusters currently matching
ClusterProfile ClusterSelector
items:
description: ObjectReference contains enough information to let
you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
reconciliationSuspended:
description: |-
ReconciliationSuspended indicates whether the reconciliation loop for this
ClusterSummary is currently paused due to an external action (e.g., a user annotation).
When true, the status will not be updated unless the pause is lifted.
type: boolean
suspensionReason:
description: SuspensionReason provides a brief explanation of why
the reconciliation is suspended.
type: string
updatedClusters:
description: |-
UpdatedClusters contains information all the cluster currently matching
ClusterProfile ClusterSelector and already updated to latest ClusterProfile
Spec
properties:
clusters:
description: |-
Clusters reference all the clusters currently matching
ClusterProfile ClusterSelector and already updated/being updated
to ClusterProfile Spec
items:
description: ObjectReference contains enough information to
let you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
hash:
description: |-
Hash represents of a unique value for ClusterProfile Spec at
a fixed point in time
format: byte
type: string
type: object
updatingClusters:
description: |-
UpdatingClusters reference all the cluster currently matching
ClusterProfile ClusterSelector and being updated
properties:
clusters:
description: |-
Clusters reference all the clusters currently matching
ClusterProfile ClusterSelector and already updated/being updated
to ClusterProfile Spec
items:
description: ObjectReference contains enough information to
let you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
hash:
description: |-
Hash represents of a unique value for ClusterProfile Spec at
a fixed point in time
format: byte
type: string
type: object
type: object
type: object
served: true
storage: true
subresources:
status: {}
`)
var ClusterProfileFile = "../../config/crd/bases/config.projectsveltos.io_clusterprofiles.yaml"
var ClusterPromotionCRD = []byte(`---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.21.0
name: clusterpromotions.config.projectsveltos.io
spec:
group: config.projectsveltos.io
names:
kind: ClusterPromotion
listKind: ClusterPromotionList
plural: clusterpromotions
singular: clusterpromotion
scope: Cluster
versions:
- name: v1beta1
schema:
openAPIV3Schema:
description: ClusterPromotion is the Schema for the ClusterPromotions API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: spec defines the desired state of ClusterPromotion
properties:
preserveClusterProfilesOnDelete:
description: |-
PreserveClusterProfilesOnDelete, if true, prevents the controller from deleting
the associated ClusterProfiles when this ClusterPromotion is deleted.
The ClusterProfiles will remain, and will need to be manually cleaned up.
type: boolean
profileSpec:
description: |-
ProfileSpec contains the common configuration for the Sveltos ClusterProfiles
that will be created at each stage.
properties:
continueOnConflict:
default: false
description: |-
By default (when ContinueOnConflict is unset or set to false), Sveltos stops deployment after
encountering the first conflict (e.g., another ClusterProfile already deployed the resource).
If set to true, Sveltos will attempt to deploy remaining resources in the ClusterProfile even
if conflicts are detected for previous resources.
type: boolean
continueOnError:
default: false
description: |-
By default (when ContinueOnError is unset or set to false), Sveltos stops deployment after
encountering the first error.
If set to true, Sveltos will attempt to deploy remaining resources in the ClusterProfile even
if errors are detected for previous resources.
type: boolean
dependsOn:
description: |-
DependsOn specifies a list of other profiles that this instance depends on.
A ClusterProfile can only depend on other ClusterProfiles, and a Profile can
only depend on other Profiles.
The add-ons and applications defined in this instance will not be deployed
until all add-ons and applications in the profiles listed as dependencies are deployed.
items:
type: string
type: array
driftExclusions:
description: |-
DriftExclusions is a list of configuration drift exclusions to be applied when syncMode is
set to ContinuousWithDriftDetection. Each exclusion specifies JSON6902 paths to ignore
when evaluating drift, optionally targeting specific resources and features.
items:
properties:
paths:
description: Paths is a slice of JSON6902 paths to exclude
from configuration drift evaluation.
items:
type: string
type: array
target:
description: Target points to the resources that the paths
refers to.
properties:
annotationSelector:
description: |-
AnnotationSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource annotations.
type: string
group:
description: |-
Group is the API group to select resources from.
Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
kind:
description: |-
Kind of the API Group to select resources from.
Together with Group and Version it is capable of unambiguously
identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
labelSelector:
description: |-
LabelSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource labels.
type: string
name:
description: Name to match resources with.
type: string
namespace:
description: Namespace to select resources from.
type: string
version:
description: |-
Version of the API Group to select resources from.
Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
type: object
required:
- paths
type: object
type: array
x-kubernetes-list-type: atomic
helmCharts:
description: Helm charts is a list of helm charts that need to
be deployed
items:
properties:
chartName:
description: |-
ChartName is the chart name
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
Must be defined otherwise.
type: string
chartVersion:
description: |-
ChartVersion is the chart version
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
It is ignored if RepositoryURL references a Flux Source.
Must be defined otherwise.
type: string
helmChartAction:
default: Install
description: HelmChartAction is the action that will be
taken on the helm chart
enum:
- Install
- Uninstall
type: string
options:
description: Options allows to set flags which are used
during installation.
properties:
atomic:
default: false
description: |-
if set, the installation process deletes the installation/upgrades on failure.
The --wait flag will be set automatically if --atomic is used
Default to false
type: boolean
dependencyUpdate:
default: false
description: |-
update dependencies if they are missing before installing the chart
Default to false
type: boolean
description:
description: Description is the description of an helm
operation
type: string
disableHooks:
default: false
description: |-
prevent hooks from running during install/upgrade/uninstall
Default to false
type: boolean
disableOpenAPIValidation:
default: false
description: |-
if set, the installation process will not validate rendered templates against the Kubernetes OpenAPI Schema
Default to false
type: boolean
enableClientCache:
default: false
description: EnableClientCache is a flag to enable Helm
client cache. If it is not specified, it will be set
to false.
type: boolean
installOptions:
description: HelmInstallOptions are options specific
to helm install
properties:
createNamespace:
default: true
description: Create the release namespace if not
present. Defaults to true
type: boolean
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on install
Default to false
type: boolean
recoverAfterConsecutiveFailures:
default: 5
description: |-
RecoverAfterConsecutiveFailures is the number of consecutive install failures for this
chart after which Sveltos uninstalls any existing release under this name before
retrying, to clear potentially stale Helm release history that would otherwise keep
blocking every subsequent install attempt. This only ever runs when there is no
currently deployed release to protect: a release that is deployed, or mid-upgrade, or
failed while already existing, is always retried through helm upgrade instead, never
through this. It only applies to a release that was never successfully installed, or
was already cleanly uninstalled.
Default to 5
type: integer
replace:
default: true
description: Replaces if set indicates to replace
an older release with this one
type: boolean
takeOwnership:
default: false
description: |-
if set, install will ignore the check for helm annotations
and take ownership of the existing resources
type: boolean
type: object
labels:
additionalProperties:
type: string
description: Labels that would be added to release metadata.
type: object
passCredentialsAll:
description: PassCredentialsAll is the flag to pass
credentials to all domains
type: boolean
postRenderStrategy:
description: |-
PostRenderStrategy controls whether Helm hooks are included when Patches/PatchesFrom
are applied as a post-renderer during this chart's install/upgrade. Only relevant
when Patches or PatchesFrom is set on the Spec; ignored otherwise. Defaults to
Helm's own default (combined) when unset.
enum:
- combined
- separate
- nohooks
type: string
runTests:
default: false
description: |-
RunTests if set to true, Sveltos will run helm test after each successful install or upgrade
operation. The tests are the test hooks defined in the chart (annotated with
"helm.sh/hook: test"). If any test fails the deployment is considered failed and the
error is surfaced in the ClusterSummary status, providing operational gating.
Has no effect in DryRun mode.
Default to false
type: boolean
skipCRDs:
default: false
description: |-
SkipCRDs controls whether CRDs should be installed during install/upgrade operation.
By default, CRDs are installed if not already present.
type: boolean
skipSchemaValidation:
default: false
description: SkipSchemaValidation determines if JSON
schema validation is disabled.
type: boolean
timeout:
description: time to wait for any individual Kubernetes
operation (like Jobs for hooks) (default 5m0s)
type: string
uninstallOptions:
description: HelmUninstallOptions are options specific
to helm uninstall
properties:
deletionPropagation:
description: DeletionPropagation
enum:
- orphan
- foreground
- background
type: string
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on uninstall
Default to false
type: boolean
keepHistory:
description: |-
When uninstall a chart with this flag, Helm removes the resources associated with the chart,
but it keeps the release information. This allows to see details about the uninstalled release
using the helm history command.
type: boolean
type: object
upgradeOptions:
description: HelmUpgradeOptions are options specific
to helm upgrade
properties:
cleanupOnFail:
default: false
description: CleanupOnFail will, if true, cause
the upgrade to delete newly-created resources
on a failed update.
type: boolean
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on upgrade
Default to false
type: boolean
force:
default: false
description: |-
Force will, if set to ` + "`" + `true` + "`" + `, ignore certain warnings and perform the upgrade anyway.
This should be used with caution.
type: boolean
maxHistory:
default: 2
description: |-
MaxHistory limits the maximum number of revisions saved per release
Default to 2
type: integer
recreate:
default: false
description: |-
Recreate will (if true) recreate pods after a rollback.
Deprecated: This field is no longer supported
type: boolean
resetThenReuseValues:
default: false
description: ResetThenReuseValues will reset the
values to the chart's built-ins then merge with
user's last supplied values.
type: boolean
resetValues:
default: false
description: ResetValues will reset the values to
the chart's built-ins rather than merging with
existing.
type: boolean
reuseValues:
default: false
description: |-
ReuseValues copies values from the current release to a new release if the
new release does not have any values. If the request already has values,
or if there are no values in the current release, this does nothing.
This is skipped if the ResetValues flag is set, in which case the
request values are not altered.
type: boolean
subNotes:
default: false
description: SubNotes determines whether sub-notes
are rendered in the chart.
type: boolean
takeOwnership:
default: false
description: |-
if set, upgrade will ignore the check for helm annotations
and take ownership of the existing resources
type: boolean
upgradeCRDs:
default: false
description: |-
UpgradeCRDs upgrade CRDs from the Helm Chart's crds directory
By default, CRDs are not applied during Helm upgrade action by Helm
https://helm.sh/docs/chart_best_practices/custom_resource_definitions/
type: boolean
type: object
wait:
default: false
description: |-
if set, will wait until all Pods, PVCs, Services, and minimum number of Pods of a Deployment, StatefulSet, or ReplicaSet
are in a ready state before marking the release as successful. It will wait for as long as --timeout
Default to false
type: boolean
waitForJobs:
default: false
description: |-
if set and --wait enabled, will wait until all Jobs have been completed before marking the release as successful.
It will wait for as long as --timeout
Default to false
type: boolean
type: object
provenanceVerification:
description: |-
ProvenanceVerification configures Helm GPG .prov file verification for HTTP chart repositories.
Ignored for OCI and Flux-sourced charts.
properties:
keyringSecretRef:
description: |-
KeyringSecretRef references a Secret in the management cluster containing the GPG keyring.
The Secret must have a key named "keyring.gpg".
If Namespace is omitted, the cluster's namespace is used.
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
required:
- keyringSecretRef
type: object
registryCredentialsConfig:
description: |-
RegistryCredentialsConfig is an optional configuration for credentials,
including information to connect to private registries.
properties:
ca:
description: |-
CASecretRef references a secret containing the TLS CA certificate
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
key: ca.crt
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
credentials:
description: |-
CredentialsSecretRef references a secret containing credentials
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
insecureSkipTLSVerify:
description: InsecureSkipTLSVerify controls server certificate
verification.
type: boolean
key:
description: |-
Key specifies the key within the CredentialsSecretRef containing the data
If not specified, it defaults to the only key in the secret if there's just one.
type: string
plainHTTP:
description: PlainHTTP indicates to use insecure HTTP
connections for the chart download
type: boolean
type: object
releaseName:
description: ReleaseName is the chart release
minLength: 1
type: string
releaseNamespace:
description: ReleaseNamespace is the namespace release will
be installed
minLength: 1
type: string
repositoryName:
description: |-
RepositoryName is the name helm chart repository
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
It is ignored if RepositoryURL references a Flux Source.
Must be defined otherwise.
type: string
repositoryURL:
description: |-
RepositoryURL is the URL helm chart repository
It can point to a traditional HTTP-based repository or an OCI registry.
Examples:
- HTTP Repository: https://charts.example.com/stable
- OCI Registry: oci://registry.example.com/namespace/charts
- GitHub Pages: https://<username>.github.io/<repository>/
- Any other valid URL where Helm charts are hosted.
Alternatively, it can be a Flux source reference:
<flux source kind>://<flux source namespace>/<flux source name>/<path>
Where:
- <flux source kind> is the type of Flux source (gitrepository, ocirepository, bucket).
- <flux source namespace> and <flux source name> are the namespace and name of the Flux Source in the management cluster.
- <path> is the path within the source repository where the Helm charts are located.
For instance:
gitrepository://flux-system/flux-system/charts/projectsveltos
Assuming there is a Flux GitRepository named 'flux-system' in the 'flux-system' namespace
syncing 'https://github.com/projectsveltos/helm-charts.git/', and the Helm charts are
located in the 'charts/projectsveltos' directory of that repository.
minLength: 1
type: string
signatureVerification:
description: |-
SignatureVerification configures Cosign-based signature verification for OCI Helm charts.
Ignored when RepositoryURL does not start with "oci://".
properties:
matchOIDCIdentity:
description: |-
MatchOIDCIdentity lists OIDC identity matchers for keyless verification.
At least one matcher must be satisfied. Required when Provider is Keyless.
items:
description: OIDCIdentityMatcher specifies the expected
OIDC issuer and subject for keyless Cosign verification.
properties:
issuer:
description: Issuer is the OIDC issuer URL or
regex.
minLength: 1
type: string
subject:
description: Subject is the OIDC subject or regex,
typically the workload identity or GitHub Actions
workflow URL.
minLength: 1
type: string
required:
- issuer
- subject
type: object
type: array
provider:
description: Provider specifies how to obtain the verification
key or certificate.
enum:
- PublicKey
- Keyless
type: string
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing the Cosign public key.
The Secret must have a key named "cosign.pub" holding a PEM-encoded public key.
Required when Provider is PublicKey.
If Namespace is omitted, the cluster's namespace is used.
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
required:
- provider
type: object
values:
description: |-
Values field allows to define configuration for the Helm release.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
valuesFrom:
description: |-
ValuesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to store configuration for the Helm release.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
required:
- releaseName
- releaseNamespace
- repositoryURL
type: object
x-kubernetes-validations:
- message: ChartName must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.chartName)
>= 1 : true'
- message: ChartName must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.chartName)
>= 1 : true'
- message: ChartVersion must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.chartVersion)
>= 1 : true'
- message: ChartVersion must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.chartVersion)
>= 1 : true'
- message: RepositoryName must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.repositoryName)
>= 1 : true'
- message: RepositoryName must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.repositoryName)
>= 1 : true'
type: array
x-kubernetes-list-type: atomic
kustomizationRefs:
description: |-
Kustomization refs is a list of kustomization paths. Kustomization will
be run on those paths and the outcome will be deployed.
items:
properties:
components:
description: |-
Components is a list of paths to Kustomize components. These paths are relative to the
` + "`" + `Path` + "`" + ` field and are included in the Kustomize build to provide reusable configuration logic.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
type: string
type: array
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
NOTE: DeploymentType Local cannot be used when the matching cluster is the management cluster itself.
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
KustomizationRef when an update is rejected with an error that only a delete+recreate
can resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this KustomizationRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- flux GitRepository;OCIRepository;Bucket
- ConfigMap/Secret
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
path:
description: |-
Path to the directory containing the kustomization.yaml file, or the
set of plain YAMLs a kustomization.yaml should be generated for.
Defaults to 'None', which translates to the root path of the SourceRef.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching the Kustomize directory content from an HTTP/HTTPS
endpoint or an OCI registry, without requiring a Flux GitRepository/OCIRepository/Bucket
or a ConfigMap/Secret.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the remote source serving the Kustomize directory content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint serving a gzipped tarball
(.tar.gz) of the Kustomize directory
"oci://" — OCI registry artifact whose layers are extracted
the same way, preserving the directory tree
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this KustomizationRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
targetNamespace:
description: |-
TargetNamespace sets or overrides the namespace in the
kustomization.yaml file.
maxLength: 63
minLength: 1
type: string
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different KustomizationRef
within the same ClusterProfile or Profile.
When two KustomizationRef attempt to deploy the same resource, the KustomizationRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
values:
additionalProperties:
type: string
description: |-
Values is a map[string]string type that allows to define a set of key-value pairs.
These key-value pairs can optionally leverage Go templates for further processing.
With Sveltos, you can define key-value pairs where the values can be Go templates.
These templates have access to management cluster information during deployment. This allows
to do more than just replace placeholders. Variables can be used to dynamically
construct values based on other resources or variables within the Kustomize output.
For example, imagine you have a Region key with a template value like:
'{{ index .Cluster.metadata.labels "region" }}'.
This template retrieves the region label from the cluster instance metadata.
Finally, Sveltos uses these processed values to fill placeholders in the Kustomize output.
The output itself can also contain templates, like:
region: '{{ default "west" .Region }}'.
This way, the final output from Kustomize will have the region set dynamically based on
the actual region retrieved earlier.
type: object
valuesFrom:
description: |-
ValuesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to define key-value pairs. These key-value pairs can optionally leverage
Go templates for further processing.
With Sveltos, you can define key-value pairs where the values can be Go templates.
These templates have access to management cluster information during deployment. This allows
to do more than just replace placeholders. Variables can be used to dynamically
construct values based on other resources or variables within the Kustomize output.
For example, imagine you have a Region key with a template value like:
'{{ index .Cluster.metadata.labels "region" }}'.
This template retrieves the region label from the cluster instance metadata.
Finally, Sveltos uses these processed values to fill placeholders in the Kustomize output.
The output itself can also contain templates, like:
region: '{{ default "west" .Region }}'.
This way, the final output from Kustomize will have the region set dynamically based on
the actual region retrieved earlier.
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but not both
rule: has(self.remoteURL) != has(self.kind)
type: array
x-kubernetes-list-type: atomic
maxConsecutiveFailures:
description: |-
The maximum number of consecutive deployment failures that Sveltos will permit.
After this many consecutive failures, the deployment will be considered failed, and Sveltos will stop retrying.
This setting applies only to feature deployments, not resource removal.
This field is optional. If not set, Sveltos default behavior is to keep retrying.
type: integer
maxUpdate:
anyOf:
- type: integer
- type: string
description: |-
The maximum number of clusters that can be updated concurrently.
Value can be an absolute number (ex: 5) or a percentage of desired cluster (ex: 10%).
Defaults to 100%.
Example: when this is set to 30%, when list of add-ons/applications in ClusterProfile
changes, only 30% of matching clusters will be updated in parallel. Only when updates
in those cluster succeed, other matching clusters are updated.
pattern: ^((100|[0-9]{1,2})%|[0-9]+)$
x-kubernetes-int-or-string: true
patches:
description: |-
Define additional Kustomize inline Patches applied for all resources on this profile
Within the Patch Spec you can use templating
items:
description: |-
Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should
be applied to.
properties:
patch:
description: |-
Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with
an array of operation objects.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
target:
description: Target points to the resources that the patch
document should be applied to.
properties:
annotationSelector:
description: |-
AnnotationSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource annotations.
type: string
group:
description: |-
Group is the API group to select resources from.
Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
kind:
description: |-
Kind of the API Group to select resources from.
Together with Group and Version it is capable of unambiguously
identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
labelSelector:
description: |-
LabelSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource labels.
type: string
name:
description: Name to match resources with.
type: string
namespace:
description: Namespace to select resources from.
type: string
version:
description: |-
Version of the API Group to select resources from.
Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
type: object
required:
- patch
type: object
type: array
x-kubernetes-list-type: atomic
patchesFrom:
description: |-
PatchesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to store additional Kustomize inline Patches applied for all resources on this profile
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
x-kubernetes-list-type: atomic
policyRefs:
description: |-
PolicyRefs references all the ConfigMaps/Secrets/Flux Sources containing kubernetes resources
that need to be deployed in the matching managed clusters.
The values contained in those resources can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
PolicyRef when an update is rejected with an error that only a delete+recreate can
resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this PolicyRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
- flux GitRepository;OCIRepository;Bucket
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other PolicyRefs.
type: boolean
path:
description: |-
Path to the directory containing the YAML files.
Defaults to 'None', which translates to the root path of the SourceRef.
Used only for GitRepository;OCIRepository;Bucket
This value can be static or leverage Go templates for dynamic customization.
When expressed as a template, it is filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching content from an HTTP/HTTPS endpoint or an OCI registry.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
template:
description: |-
Template indicates that the fetched content is a Go template that
must be instantiated using cluster fields and templateResourceRefs values
before deployment. Equivalent to the projectsveltos.io/template annotation
on a ConfigMap or Secret.
type: boolean
url:
description: |-
URL is the remote source serving raw YAML/JSON content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint returning a raw YAML/JSON
document, a gzip-compressed document, an
uncompressed tar, or a gzip-compressed tar of
.yaml/.yml/.json files
"oci://" — OCI registry artifact whose layers are accepted
in the same shapes: raw YAML/JSON, gzip-compressed
YAML/JSON, uncompressed tar, or gzip-compressed tar
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this PolicyRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different PolicyRefs
within the same ClusterProfile or Profile.
When two PolicyRefs attempt to deploy the same resource, the PolicyRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but not both
rule: has(self.remoteURL) != has(self.kind)
type: array
x-kubernetes-list-type: atomic
postDeleteChecks:
description: |-
PostDeleteChecks is a slice of checks to run against the managed cluster
*after* Sveltos has deleted all resources.
This ensures that the environment has reached the desired clean state.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in
EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for
the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based
on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
preDeleteChecks:
description: |-
PreDeleteChecks is a slice of checks to run against the managed cluster
*before* Sveltos starts deleting resources.
If any of these fail, the deletion process is halted.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in
EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for
the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based
on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
preDeployChecks:
description: |-
PreDeployChecks is a slice of checks to run against the managed cluster
*before* Sveltos starts deploying resources.
Each check can use Lua scripts or CEL expressions to validate the cluster state.
If any check fails, the deployment of the associated feature is halted.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in
EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for
the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based
on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
reloader:
default: false
description: |-
Reloader indicates whether Deployment/StatefulSet/DaemonSet instances deployed
by Sveltos and part of this ClusterProfile need to be restarted via rolling upgrade
when a ConfigMap/Secret instance mounted as volume is modified.
When set to true, when any mounted ConfigMap/Secret is modified, Sveltos automatically
starts a rolling upgrade for Deployment/StatefulSet/DaemonSet instances mounting it.
type: boolean
stopMatchingBehavior:
default: WithdrawPolicies
description: |-
StopMatchingBehavior indicates what behavior should be when a Cluster stop matching
the ClusterProfile. By default all deployed Helm charts and Kubernetes resources will
be withdrawn from Cluster. Setting StopMatchingBehavior to LeavePolicies will instead
leave ClusterProfile deployed policies in the Cluster.
enum:
- WithdrawPolicies
- LeavePolicies
type: string
syncMode:
default: Continuous
description: |-
SyncMode specifies how features are synced in a matching workload cluster.
- OneTime means, first time a workload cluster matches the ClusterProfile,
features will be deployed in such cluster. Any subsequent feature configuration
change won't be applied into the matching workload clusters;
- Continuous mode ensures that the first time a workload cluster matches a ClusterProfile,
the specified features are deployed. Subsequent changes to the feature configuration are also
automatically applied to all matching workload clusters.
_ SyncModeContinuousWithDriftDetection operates similarly to Continuous mode, but also monitors
matching managed clusters for configuration drift. If drift is detected, a reconciliation is
triggered to ensure the managed cluster's configuration aligns with the ClusterProfile.
- DryRun means no change will be propagated to any matching cluster. A report
instead will be generated summarizing what would happen in any matching cluster
because of the changes made to ClusterProfile while in DryRun mode.
enum:
- OneTime
- Continuous
- ContinuousWithDriftDetection
- DryRun
type: string
templateResourceRefs:
description: |-
TemplateResourceRefs is a list of resource to collect from the management cluster.
Those resources' values will be used to instantiate templates
items:
properties:
identifier:
description: |-
Identifier is how the resource will be referred to in the
template
type: string
ignoreStatusChanges:
default: false
description: |-
IgnoreStatusChanges indicates whether changes to the status of the referenced
resource should be ignored. If set to true, only changes to the spec or
metadata (generation change) will trigger a reconciliation.
type: boolean
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other TemplateResourceRefs.
type: boolean
resource:
description: |-
Resource references a Kubernetes instance in the management
cluster to fetch and use during template instantiation.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
Name and namespace can be expressed as a template and instantiate using any cluster field.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
watchFields:
description: |-
WatchFields is an optional list of dot-separated field paths to include
when computing the hash for this resource (e.g. "status.readyReplicas",
"metadata.labels"). When non-empty, only the listed fields are hashed and
IgnoreStatusChanges is ignored. Use this when you need to react to a
specific field without being sensitive to every other change on the object.
items:
type: string
type: array
required:
- identifier
- resource
type: object
type: array
x-kubernetes-list-map-keys:
- identifier
x-kubernetes-list-type: map
tier:
default: 100
description: |-
Tier controls the order of deployment for ClusterProfile or Profile resources targeting
the same cluster resources.
Imagine two configurations (ClusterProfiles or Profiles) trying to deploy the same resource (a Kubernetes
resource or an helm chart). By default, the first one to reach the cluster "wins" and deploys it.
Tier allows you to override this. When conflicts arise, the ClusterProfile or Profile with the **lowest**
Tier value takes priority and deploys the resource.
Higher Tier values represent lower priority. The default Tier value is 100.
Using Tiers provides finer control over resource deployment within your cluster, particularly useful
when multiple configurations manage the same resources.
format: int32
minimum: 1
type: integer
validateHealths:
description: |-
ValidateHealths is a slice of checks to run against the managed cluster
*after* resources are deployed to validate that the state of the
add-ons/applications is healthy.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in
EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for
the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based
on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
type: object
stages:
description: |-
Stages is a list of environments in the promotion pipeline.
The pipeline will progress through these stages in the order they are defined.
items:
description: Stage defines a single step in the promotion pipeline
properties:
clusterSelector:
description: ClusterSelector specifies which clusters this stage's
resources will be deployed to.
properties:
matchExpressions:
description: matchExpressions is a list of label selector
requirements. The requirements are ANDed.
items:
description: |-
A label selector requirement is a selector that contains values, a key, and an operator that
relates the key and values.
properties:
key:
description: key is the label key that the selector
applies to.
type: string
operator:
description: |-
operator represents a key's relationship to a set of values.
Valid operators are In, NotIn, Exists and DoesNotExist.
type: string
values:
description: |-
values is an array of string values. If the operator is In or NotIn,
the values array must be non-empty. If the operator is Exists or DoesNotExist,
the values array must be empty. This array is replaced during a strategic
merge patch.
items:
type: string
type: array
x-kubernetes-list-type: atomic
required:
- key
- operator
type: object
type: array
x-kubernetes-list-type: atomic
matchLabels:
additionalProperties:
type: string
description: |-
matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
map is equivalent to an element of matchExpressions, whose key field is "key", the
operator is "In", and the values array contains only "value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
name:
description: Name of the stage, e.g., "qa", "staging", "production".
type: string
trigger:
description: |-
Trigger for promoting to the next stage in the pipeline.
This field is only applicable to stages that are not the last stage.
properties:
auto:
description: |-
Auto is an automatic trigger. When set, promotion occurs automatically
based on defined conditions.
properties:
delay:
description: |-
Delay is an optional time duration to wait after the WaitForStatus condition
is met before proceeding with the promotion.
type: string
postDelayHealthChecks:
description: |-
PostDelayHealthChecks is a slice of health checks Sveltos will run after the delay
period has elapsed.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule
used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier
for the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported
kinds are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources
based on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison
operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query
expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace
to reference a secret resource.
type: string
namespace:
description: namespace defines the space
within which the secret name must be
unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script
or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script)
&& !has(self.evaluateCEL))'
type: array
preHealthCheckDeployment:
description: |-
PreHealthCheckDeployment is a slice of resources Sveltos will deploy after the Delay
period has elapsed and before running PostDelayHealthChecks.
This can be used, for example, to deploy a Job that performs validation tasks.
The PostDelayHealthChecks can then validate the successful completion of these resources (e.g., a Job).
items:
properties:
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
PolicyRef when an update is rejected with an error that only a delete+recreate can
resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this PolicyRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
- flux GitRepository;OCIRepository;Bucket
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other PolicyRefs.
type: boolean
path:
description: |-
Path to the directory containing the YAML files.
Defaults to 'None', which translates to the root path of the SourceRef.
Used only for GitRepository;OCIRepository;Bucket
This value can be static or leverage Go templates for dynamic customization.
When expressed as a template, it is filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching content from an HTTP/HTTPS endpoint or an OCI registry.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace
to reference a secret resource.
type: string
namespace:
description: namespace defines the space
within which the secret name must be
unique.
type: string
type: object
x-kubernetes-map-type: atomic
template:
description: |-
Template indicates that the fetched content is a Go template that
must be instantiated using cluster fields and templateResourceRefs values
before deployment. Equivalent to the projectsveltos.io/template annotation
on a ConfigMap or Secret.
type: boolean
url:
description: |-
URL is the remote source serving raw YAML/JSON content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint returning a raw YAML/JSON
document, a gzip-compressed document, an
uncompressed tar, or a gzip-compressed tar of
.yaml/.yml/.json files
"oci://" — OCI registry artifact whose layers are accepted
in the same shapes: raw YAML/JSON, gzip-compressed
YAML/JSON, uncompressed tar, or gzip-compressed tar
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this PolicyRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different PolicyRefs
within the same ClusterProfile or Profile.
When two PolicyRefs attempt to deploy the same resource, the PolicyRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but
not both
rule: has(self.remoteURL) != has(self.kind)
type: array
promotionWindow:
description: |-
PromotionWindow defines the recurring time window during which the
automatic promotion is permitted. The controller evaluates this window
*only after* the Delay (if defined) has elapsed and all PostDelayHealthChecks
have passed. The controller will then wait until the window defined by From/To
is open before proceeding.
properties:
from:
description: |-
From is a cron expression defining the recurring time(s) when the promotion
window opens. The promotion will be blocked until the time defined by 'From'
is reached.
minLength: 1
type: string
to:
description: |-
To is a cron expression defining the recurring time(s) when the promotion
window closes. If the promotion process is not complete when 'To' is reached,
the controller should pause and wait for the next 'From' time.
minLength: 1
type: string
required:
- from
- to
type: object
type: object
manual:
description: Manual is a manual trigger. When set, promotion
requires a human signal.
properties:
approved:
description: |-
Approved, when set to true, signals to the controller that
promotion to the next stage is approved.
type: boolean
automaticReset:
default: true
description: |-
AutomaticReset, when set to true, instructs the controller to automatically
reset the 'Approved' field to nil/false after successfully promoting
to the next stage. This prevents unintended immediate advancement
past the next manual stage. Defaults to true.
type: boolean
delay:
description: |-
Delay is an optional time duration to wait after the WaitForStatus condition
is met before proceeding with the promotion.
type: string
postDelayHealthChecks:
description: |-
PostDelayHealthChecks is a slice of health checks Sveltos will run after the delay
period has elapsed.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule
used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier
for the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported
kinds are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources
based on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison
operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query
expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace
to reference a secret resource.
type: string
namespace:
description: namespace defines the space
within which the secret name must be
unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script
or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script)
&& !has(self.evaluateCEL))'
type: array
preHealthCheckDeployment:
description: |-
PreHealthCheckDeployment is a slice of resources Sveltos will deploy after the Delay
period has elapsed and before running PostDelayHealthChecks.
This can be used, for example, to deploy a Job that performs validation tasks.
The PostDelayHealthChecks can then validate the successful completion of these resources (e.g., a Job).
items:
properties:
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
PolicyRef when an update is rejected with an error that only a delete+recreate can
resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this PolicyRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
- flux GitRepository;OCIRepository;Bucket
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other PolicyRefs.
type: boolean
path:
description: |-
Path to the directory containing the YAML files.
Defaults to 'None', which translates to the root path of the SourceRef.
Used only for GitRepository;OCIRepository;Bucket
This value can be static or leverage Go templates for dynamic customization.
When expressed as a template, it is filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching content from an HTTP/HTTPS endpoint or an OCI registry.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace
to reference a secret resource.
type: string
namespace:
description: namespace defines the space
within which the secret name must be
unique.
type: string
type: object
x-kubernetes-map-type: atomic
template:
description: |-
Template indicates that the fetched content is a Go template that
must be instantiated using cluster fields and templateResourceRefs values
before deployment. Equivalent to the projectsveltos.io/template annotation
on a ConfigMap or Secret.
type: boolean
url:
description: |-
URL is the remote source serving raw YAML/JSON content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint returning a raw YAML/JSON
document, a gzip-compressed document, an
uncompressed tar, or a gzip-compressed tar of
.yaml/.yml/.json files
"oci://" — OCI registry artifact whose layers are accepted
in the same shapes: raw YAML/JSON, gzip-compressed
YAML/JSON, uncompressed tar, or gzip-compressed tar
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this PolicyRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different PolicyRefs
within the same ClusterProfile or Profile.
When two PolicyRefs attempt to deploy the same resource, the PolicyRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but
not both
rule: has(self.remoteURL) != has(self.kind)
type: array
type: object
type: object
x-kubernetes-validations:
- message: A trigger must have either a 'manual' or 'auto' field,
but not both.
rule: has(self.manual) != has(self.auto)
required:
- name
type: object
minItems: 1
type: array
x-kubernetes-list-map-keys:
- name
x-kubernetes-list-type: map
required:
- stages
type: object
status:
description: status defines the observed state of ClusterPromotion
properties:
currentStageName:
description: |2-
If the pipeline is currently running, this is the name of the stage
being processed. If the pipeline is paused or completed, this is the name
of the last stage that reached a target state.
type: string
lastPromotionTime:
description: LastPromotionTime is the time the entire promotion process
was successfully completed.
format: date-time
type: string
profileSpecHash:
description: |-
ProfileSpecHash represents a unique value for the entire ProfileSpec configuration
at a fixed point in time. This is used to detect configuration changes.
format: byte
type: string
stages:
description: |-
Stages tracks the status of each configured promotion stage
(e.g., "qa", "staging", "production").
items:
description: StageStatus defines the status for a given stage in
a progressive deployment.
properties:
currentStatusDescription:
description: |-
CurrentStatusDescription provides a high-level description of where the stage is
in its progression (e.g., "Waiting for cluster profiles to be created",
"Waiting for all clusters to be Provisioned", "Running post-deployment health checks").
This helps users understand the current blocking state.
type: string
failureMessage:
description: FailureMessage reports a detailed error message
if a failure occurred.
type: string
lastStatusCheckTime:
description: |-
LastStatusCheckTime is the time the ClusterPromotion controller last checked the
statuses of the matching clusters and their provisioned state.
This is updated frequently while waiting for provisioning to complete.
format: date-time
type: string
lastSuccessfulAppliedTime:
description: |-
LastSuccessfulAppliedTime is the time this stage was fully and successfully deployed.
This means all clusters matching the stage have reported a 'Provisioned' status.
format: date-time
type: string
lastUpdateReconciledTime:
description: |-
LastUpdateReconciledTime is the time the ClusterPromotion controller most recently
created or updated the corresponding ClusterProfile resource for this stage.
This indicates when the desired state was last applied to the system.
format: date-time
type: string
name:
description: Name of the stage, e.g., "qa", "staging", "production".
type: string
required:
- name
type: object
type: array
stagesHash:
description: |-
StagesHash represents a unique value for the entire list of Stages.
This hash changes if any stage is added, removed, or if the ordering
or configuration (ClusterSelector, Trigger) of any stage changes.
format: byte
type: string
type: object
required:
- spec
type: object
served: true
storage: true
subresources:
status: {}
`)
var ClusterPromotionFile = "../../config/crd/bases/config.projectsveltos.io_clusterpromotions.yaml"
var ClusterReportCRD = []byte(`---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.21.0
name: clusterreports.config.projectsveltos.io
spec:
group: config.projectsveltos.io
names:
kind: ClusterReport
listKind: ClusterReportList
plural: clusterreports
singular: clusterreport
scope: Namespaced
versions:
- name: v1beta1
schema:
openAPIV3Schema:
description: ClusterReport is the Schema for the clusterreports API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: ClusterReportSpec defines the desired state of ClusterReport
properties:
clusterName:
description: |-
ClusterName is the name of the CAPI Cluster this ClusterReport
is for.
type: string
clusterNamespace:
description: |-
ClusterNamespace is the namespace of the CAPI Cluster this
ClusterReport is for.
type: string
required:
- clusterName
- clusterNamespace
type: object
status:
description: ClusterReportStatus defines the observed state of ClusterReport
properties:
helmResourceReports:
description: |-
HelmResourceReports contains report on helm resources (when in pull mode, helm template resources are
deployed directly)
items:
properties:
action:
description: Action represent the type of operation on the Kubernetes
resource.
enum:
- No Action
- Create
- Update
- Delete
- Conflict
- Error
type: string
message:
description: |-
Message is for any message that needs to added to better
explain the action.
type: string
resource:
description: Resource contains information about Kubernetes
Resource
properties:
group:
description: Group of the resource deployed in the Cluster.
type: string
ignoreForConfigurationDrift:
default: false
description: |-
IgnoreForConfigurationDrift indicates to not track resource
for configuration drift detection.
This field has a meaning only when mode is ContinuousWithDriftDetection
type: boolean
kind:
description: Kind of the resource deployed in the Cluster.
minLength: 1
type: string
lastAppliedTime:
description: LastAppliedTime identifies when this resource
was last applied to the cluster.
format: date-time
type: string
name:
description: Name of the resource deployed in the Cluster.
minLength: 1
type: string
namespace:
description: |-
Namespace of the resource deployed in the Cluster.
Empty for resources scoped at cluster level.
type: string
version:
description: Version of the resource deployed in the Cluster.
minLength: 1
type: string
required:
- group
- kind
- name
- version
type: object
required:
- resource
type: object
type: array
kustomizeResourceReports:
description: |-
KustomizeResourceReports contains report on Kubernetes resources
deployed because of KustomizationRefs
items:
properties:
action:
description: Action represent the type of operation on the Kubernetes
resource.
enum:
- No Action
- Create
- Update
- Delete
- Conflict
- Error
type: string
message:
description: |-
Message is for any message that needs to added to better
explain the action.
type: string
resource:
description: Resource contains information about Kubernetes
Resource
properties:
group:
description: Group of the resource deployed in the Cluster.
type: string
ignoreForConfigurationDrift:
default: false
description: |-
IgnoreForConfigurationDrift indicates to not track resource
for configuration drift detection.
This field has a meaning only when mode is ContinuousWithDriftDetection
type: boolean
kind:
description: Kind of the resource deployed in the Cluster.
minLength: 1
type: string
lastAppliedTime:
description: LastAppliedTime identifies when this resource
was last applied to the cluster.
format: date-time
type: string
name:
description: Name of the resource deployed in the Cluster.
minLength: 1
type: string
namespace:
description: |-
Namespace of the resource deployed in the Cluster.
Empty for resources scoped at cluster level.
type: string
version:
description: Version of the resource deployed in the Cluster.
minLength: 1
type: string
required:
- group
- kind
- name
- version
type: object
required:
- resource
type: object
type: array
releaseReports:
description: ReleaseReports contains report on helm releases
items:
properties:
action:
description: Action represent the type of operation on the Helm
Chart
enum:
- No Action
- Install
- Upgrade
- Delete
- Conflict
- Update Values
type: string
chartName:
description: ReleaseName of the release deployed in the CAPI
Cluster.
minLength: 1
type: string
chartVersion:
description: |-
ChartVersion is the version of the helm chart deployed
in the CAPI Cluster.
type: string
message:
description: |-
Message is for any message that needs to added to better
explain the action.
type: string
releaseNamespace:
description: Namespace where release is deployed in the CAPI
Cluster.
minLength: 1
type: string
required:
- chartName
- chartVersion
- releaseNamespace
type: object
type: array
resourceReports:
description: |-
ResourceReports contains report on Kubernetes resources
deployed because of PolicyRefs
items:
properties:
action:
description: Action represent the type of operation on the Kubernetes
resource.
enum:
- No Action
- Create
- Update
- Delete
- Conflict
- Error
type: string
message:
description: |-
Message is for any message that needs to added to better
explain the action.
type: string
resource:
description: Resource contains information about Kubernetes
Resource
properties:
group:
description: Group of the resource deployed in the Cluster.
type: string
ignoreForConfigurationDrift:
default: false
description: |-
IgnoreForConfigurationDrift indicates to not track resource
for configuration drift detection.
This field has a meaning only when mode is ContinuousWithDriftDetection
type: boolean
kind:
description: Kind of the resource deployed in the Cluster.
minLength: 1
type: string
lastAppliedTime:
description: LastAppliedTime identifies when this resource
was last applied to the cluster.
format: date-time
type: string
name:
description: Name of the resource deployed in the Cluster.
minLength: 1
type: string
namespace:
description: |-
Namespace of the resource deployed in the Cluster.
Empty for resources scoped at cluster level.
type: string
version:
description: Version of the resource deployed in the Cluster.
minLength: 1
type: string
required:
- group
- kind
- name
- version
type: object
required:
- resource
type: object
type: array
type: object
type: object
served: true
storage: true
subresources:
status: {}
`)
var ClusterReportFile = "../../config/crd/bases/config.projectsveltos.io_clusterreports.yaml"
var ClusterSummaryCRD = []byte(`---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.21.0
name: clustersummaries.config.projectsveltos.io
spec:
group: config.projectsveltos.io
names:
kind: ClusterSummary
listKind: ClusterSummaryList
plural: clustersummaries
singular: clustersummary
scope: Namespaced
versions:
- additionalPrinterColumns:
- description: Time duration since creation of ClusterSummary
jsonPath: .metadata.creationTimestamp
name: Age
type: date
- description: Indicates whether HelmCharts are all provisioned
jsonPath: .status.featureSummaries[?(@.featureID=="Helm")].status
name: HelmCharts
priority: 2
type: string
- description: Indicates whether KustomizeRefs are all provisioned
jsonPath: .status.featureSummaries[?(@.featureID=="Kustomize")].status
name: KustomizeRefs
priority: 2
type: string
- description: Indicates whether PolicyRefs are all provisioned
jsonPath: .status.featureSummaries[?(@.featureID=="Resources")].status
name: PolicyRefs
priority: 2
type: string
name: v1beta1
schema:
openAPIV3Schema:
description: ClusterSummary is the Schema for the clustersummaries API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: ClusterSummarySpec defines the desired state of ClusterSummary
properties:
clusterName:
description: ClusterName is the name of the workload Cluster this
ClusterSummary is for.
type: string
clusterNamespace:
description: |-
ClusterNamespace is the namespace of the workload Cluster this
ClusterSummary is for.
type: string
clusterProfileSpec:
description: |-
ClusterProfileSpec represent the configuration that will be applied to
the workload cluster.
properties:
clusterRefs:
description: ClusterRefs identifies clusters to associate to.
items:
description: ObjectReference contains enough information to
let you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
clusterSelector:
description: ClusterSelector identifies clusters to associate
to.
properties:
matchExpressions:
description: matchExpressions is a list of label selector
requirements. The requirements are ANDed.
items:
description: |-
A label selector requirement is a selector that contains values, a key, and an operator that
relates the key and values.
properties:
key:
description: key is the label key that the selector
applies to.
type: string
operator:
description: |-
operator represents a key's relationship to a set of values.
Valid operators are In, NotIn, Exists and DoesNotExist.
type: string
values:
description: |-
values is an array of string values. If the operator is In or NotIn,
the values array must be non-empty. If the operator is Exists or DoesNotExist,
the values array must be empty. This array is replaced during a strategic
merge patch.
items:
type: string
type: array
x-kubernetes-list-type: atomic
required:
- key
- operator
type: object
type: array
x-kubernetes-list-type: atomic
matchLabels:
additionalProperties:
type: string
description: |-
matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
map is equivalent to an element of matchExpressions, whose key field is "key", the
operator is "In", and the values array contains only "value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
continueOnConflict:
default: false
description: |-
By default (when ContinueOnConflict is unset or set to false), Sveltos stops deployment after
encountering the first conflict (e.g., another ClusterProfile already deployed the resource).
If set to true, Sveltos will attempt to deploy remaining resources in the ClusterProfile even
if conflicts are detected for previous resources.
type: boolean
continueOnError:
default: false
description: |-
By default (when ContinueOnError is unset or set to false), Sveltos stops deployment after
encountering the first error.
If set to true, Sveltos will attempt to deploy remaining resources in the ClusterProfile even
if errors are detected for previous resources.
type: boolean
dependsOn:
description: |-
DependsOn specifies a list of other profiles that this instance depends on.
A ClusterProfile can only depend on other ClusterProfiles, and a Profile can
only depend on other Profiles.
The add-ons and applications defined in this instance will not be deployed
until all add-ons and applications in the profiles listed as dependencies are deployed.
items:
type: string
type: array
driftExclusions:
description: |-
DriftExclusions is a list of configuration drift exclusions to be applied when syncMode is
set to ContinuousWithDriftDetection. Each exclusion specifies JSON6902 paths to ignore
when evaluating drift, optionally targeting specific resources and features.
items:
properties:
paths:
description: Paths is a slice of JSON6902 paths to exclude
from configuration drift evaluation.
items:
type: string
type: array
target:
description: Target points to the resources that the paths
refers to.
properties:
annotationSelector:
description: |-
AnnotationSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource annotations.
type: string
group:
description: |-
Group is the API group to select resources from.
Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
kind:
description: |-
Kind of the API Group to select resources from.
Together with Group and Version it is capable of unambiguously
identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
labelSelector:
description: |-
LabelSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource labels.
type: string
name:
description: Name to match resources with.
type: string
namespace:
description: Namespace to select resources from.
type: string
version:
description: |-
Version of the API Group to select resources from.
Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
type: object
required:
- paths
type: object
type: array
x-kubernetes-list-type: atomic
extraAnnotations:
additionalProperties:
type: string
description: |-
ExtraAnnotations: These annotations will be added by Sveltos to all Kubernetes resources
deployed in a managed cluster based on this ClusterProfile/Profile instance.
**Important:** If a resource deployed by Sveltos already has a annotation with a key present in
` + "`" + `ExtraAnnotations` + "`" + `, the value from ` + "`" + `ExtraAnnotations` + "`" + ` will override the existing value.
(Deprecated use Patches instead)
type: object
extraLabels:
additionalProperties:
type: string
description: |-
ExtraLabels: These labels will be added by Sveltos to all Kubernetes resources deployed in
a managed cluster based on this ClusterProfile/Profile instance.
**Important:** If a resource deployed by Sveltos already has a label with a key present in
` + "`" + `ExtraLabels` + "`" + `, the value from ` + "`" + `ExtraLabels` + "`" + ` will override the existing value.
(Deprecated use Patches instead)
type: object
helmCharts:
description: Helm charts is a list of helm charts that need to
be deployed
items:
properties:
chartName:
description: |-
ChartName is the chart name
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
Must be defined otherwise.
type: string
chartVersion:
description: |-
ChartVersion is the chart version
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
It is ignored if RepositoryURL references a Flux Source.
Must be defined otherwise.
type: string
helmChartAction:
default: Install
description: HelmChartAction is the action that will be
taken on the helm chart
enum:
- Install
- Uninstall
type: string
options:
description: Options allows to set flags which are used
during installation.
properties:
atomic:
default: false
description: |-
if set, the installation process deletes the installation/upgrades on failure.
The --wait flag will be set automatically if --atomic is used
Default to false
type: boolean
dependencyUpdate:
default: false
description: |-
update dependencies if they are missing before installing the chart
Default to false
type: boolean
description:
description: Description is the description of an helm
operation
type: string
disableHooks:
default: false
description: |-
prevent hooks from running during install/upgrade/uninstall
Default to false
type: boolean
disableOpenAPIValidation:
default: false
description: |-
if set, the installation process will not validate rendered templates against the Kubernetes OpenAPI Schema
Default to false
type: boolean
enableClientCache:
default: false
description: EnableClientCache is a flag to enable Helm
client cache. If it is not specified, it will be set
to false.
type: boolean
installOptions:
description: HelmInstallOptions are options specific
to helm install
properties:
createNamespace:
default: true
description: Create the release namespace if not
present. Defaults to true
type: boolean
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on install
Default to false
type: boolean
recoverAfterConsecutiveFailures:
default: 5
description: |-
RecoverAfterConsecutiveFailures is the number of consecutive install failures for this
chart after which Sveltos uninstalls any existing release under this name before
retrying, to clear potentially stale Helm release history that would otherwise keep
blocking every subsequent install attempt. This only ever runs when there is no
currently deployed release to protect: a release that is deployed, or mid-upgrade, or
failed while already existing, is always retried through helm upgrade instead, never
through this. It only applies to a release that was never successfully installed, or
was already cleanly uninstalled.
Default to 5
type: integer
replace:
default: true
description: Replaces if set indicates to replace
an older release with this one
type: boolean
takeOwnership:
default: false
description: |-
if set, install will ignore the check for helm annotations
and take ownership of the existing resources
type: boolean
type: object
labels:
additionalProperties:
type: string
description: Labels that would be added to release metadata.
type: object
passCredentialsAll:
description: PassCredentialsAll is the flag to pass
credentials to all domains
type: boolean
postRenderStrategy:
description: |-
PostRenderStrategy controls whether Helm hooks are included when Patches/PatchesFrom
are applied as a post-renderer during this chart's install/upgrade. Only relevant
when Patches or PatchesFrom is set on the Spec; ignored otherwise. Defaults to
Helm's own default (combined) when unset.
enum:
- combined
- separate
- nohooks
type: string
runTests:
default: false
description: |-
RunTests if set to true, Sveltos will run helm test after each successful install or upgrade
operation. The tests are the test hooks defined in the chart (annotated with
"helm.sh/hook: test"). If any test fails the deployment is considered failed and the
error is surfaced in the ClusterSummary status, providing operational gating.
Has no effect in DryRun mode.
Default to false
type: boolean
skipCRDs:
default: false
description: |-
SkipCRDs controls whether CRDs should be installed during install/upgrade operation.
By default, CRDs are installed if not already present.
type: boolean
skipSchemaValidation:
default: false
description: SkipSchemaValidation determines if JSON
schema validation is disabled.
type: boolean
timeout:
description: time to wait for any individual Kubernetes
operation (like Jobs for hooks) (default 5m0s)
type: string
uninstallOptions:
description: HelmUninstallOptions are options specific
to helm uninstall
properties:
deletionPropagation:
description: DeletionPropagation
enum:
- orphan
- foreground
- background
type: string
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on uninstall
Default to false
type: boolean
keepHistory:
description: |-
When uninstall a chart with this flag, Helm removes the resources associated with the chart,
but it keeps the release information. This allows to see details about the uninstalled release
using the helm history command.
type: boolean
type: object
upgradeOptions:
description: HelmUpgradeOptions are options specific
to helm upgrade
properties:
cleanupOnFail:
default: false
description: CleanupOnFail will, if true, cause
the upgrade to delete newly-created resources
on a failed update.
type: boolean
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on upgrade
Default to false
type: boolean
force:
default: false
description: |-
Force will, if set to ` + "`" + `true` + "`" + `, ignore certain warnings and perform the upgrade anyway.
This should be used with caution.
type: boolean
maxHistory:
default: 2
description: |-
MaxHistory limits the maximum number of revisions saved per release
Default to 2
type: integer
recreate:
default: false
description: |-
Recreate will (if true) recreate pods after a rollback.
Deprecated: This field is no longer supported
type: boolean
resetThenReuseValues:
default: false
description: ResetThenReuseValues will reset the
values to the chart's built-ins then merge with
user's last supplied values.
type: boolean
resetValues:
default: false
description: ResetValues will reset the values to
the chart's built-ins rather than merging with
existing.
type: boolean
reuseValues:
default: false
description: |-
ReuseValues copies values from the current release to a new release if the
new release does not have any values. If the request already has values,
or if there are no values in the current release, this does nothing.
This is skipped if the ResetValues flag is set, in which case the
request values are not altered.
type: boolean
subNotes:
default: false
description: SubNotes determines whether sub-notes
are rendered in the chart.
type: boolean
takeOwnership:
default: false
description: |-
if set, upgrade will ignore the check for helm annotations
and take ownership of the existing resources
type: boolean
upgradeCRDs:
default: false
description: |-
UpgradeCRDs upgrade CRDs from the Helm Chart's crds directory
By default, CRDs are not applied during Helm upgrade action by Helm
https://helm.sh/docs/chart_best_practices/custom_resource_definitions/
type: boolean
type: object
wait:
default: false
description: |-
if set, will wait until all Pods, PVCs, Services, and minimum number of Pods of a Deployment, StatefulSet, or ReplicaSet
are in a ready state before marking the release as successful. It will wait for as long as --timeout
Default to false
type: boolean
waitForJobs:
default: false
description: |-
if set and --wait enabled, will wait until all Jobs have been completed before marking the release as successful.
It will wait for as long as --timeout
Default to false
type: boolean
type: object
provenanceVerification:
description: |-
ProvenanceVerification configures Helm GPG .prov file verification for HTTP chart repositories.
Ignored for OCI and Flux-sourced charts.
properties:
keyringSecretRef:
description: |-
KeyringSecretRef references a Secret in the management cluster containing the GPG keyring.
The Secret must have a key named "keyring.gpg".
If Namespace is omitted, the cluster's namespace is used.
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
required:
- keyringSecretRef
type: object
registryCredentialsConfig:
description: |-
RegistryCredentialsConfig is an optional configuration for credentials,
including information to connect to private registries.
properties:
ca:
description: |-
CASecretRef references a secret containing the TLS CA certificate
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
key: ca.crt
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
credentials:
description: |-
CredentialsSecretRef references a secret containing credentials
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
insecureSkipTLSVerify:
description: InsecureSkipTLSVerify controls server certificate
verification.
type: boolean
key:
description: |-
Key specifies the key within the CredentialsSecretRef containing the data
If not specified, it defaults to the only key in the secret if there's just one.
type: string
plainHTTP:
description: PlainHTTP indicates to use insecure HTTP
connections for the chart download
type: boolean
type: object
releaseName:
description: ReleaseName is the chart release
minLength: 1
type: string
releaseNamespace:
description: ReleaseNamespace is the namespace release will
be installed
minLength: 1
type: string
repositoryName:
description: |-
RepositoryName is the name helm chart repository
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
It is ignored if RepositoryURL references a Flux Source.
Must be defined otherwise.
type: string
repositoryURL:
description: |-
RepositoryURL is the URL helm chart repository
It can point to a traditional HTTP-based repository or an OCI registry.
Examples:
- HTTP Repository: https://charts.example.com/stable
- OCI Registry: oci://registry.example.com/namespace/charts
- GitHub Pages: https://<username>.github.io/<repository>/
- Any other valid URL where Helm charts are hosted.
Alternatively, it can be a Flux source reference:
<flux source kind>://<flux source namespace>/<flux source name>/<path>
Where:
- <flux source kind> is the type of Flux source (gitrepository, ocirepository, bucket).
- <flux source namespace> and <flux source name> are the namespace and name of the Flux Source in the management cluster.
- <path> is the path within the source repository where the Helm charts are located.
For instance:
gitrepository://flux-system/flux-system/charts/projectsveltos
Assuming there is a Flux GitRepository named 'flux-system' in the 'flux-system' namespace
syncing 'https://github.com/projectsveltos/helm-charts.git/', and the Helm charts are
located in the 'charts/projectsveltos' directory of that repository.
minLength: 1
type: string
signatureVerification:
description: |-
SignatureVerification configures Cosign-based signature verification for OCI Helm charts.
Ignored when RepositoryURL does not start with "oci://".
properties:
matchOIDCIdentity:
description: |-
MatchOIDCIdentity lists OIDC identity matchers for keyless verification.
At least one matcher must be satisfied. Required when Provider is Keyless.
items:
description: OIDCIdentityMatcher specifies the expected
OIDC issuer and subject for keyless Cosign verification.
properties:
issuer:
description: Issuer is the OIDC issuer URL or
regex.
minLength: 1
type: string
subject:
description: Subject is the OIDC subject or regex,
typically the workload identity or GitHub Actions
workflow URL.
minLength: 1
type: string
required:
- issuer
- subject
type: object
type: array
provider:
description: Provider specifies how to obtain the verification
key or certificate.
enum:
- PublicKey
- Keyless
type: string
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing the Cosign public key.
The Secret must have a key named "cosign.pub" holding a PEM-encoded public key.
Required when Provider is PublicKey.
If Namespace is omitted, the cluster's namespace is used.
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
required:
- provider
type: object
values:
description: |-
Values field allows to define configuration for the Helm release.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
valuesFrom:
description: |-
ValuesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to store configuration for the Helm release.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
required:
- releaseName
- releaseNamespace
- repositoryURL
type: object
x-kubernetes-validations:
- message: ChartName must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.chartName)
>= 1 : true'
- message: ChartName must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.chartName)
>= 1 : true'
- message: ChartVersion must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.chartVersion)
>= 1 : true'
- message: ChartVersion must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.chartVersion)
>= 1 : true'
- message: RepositoryName must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.repositoryName)
>= 1 : true'
- message: RepositoryName must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.repositoryName)
>= 1 : true'
type: array
x-kubernetes-list-type: atomic
kustomizationRefs:
description: |-
Kustomization refs is a list of kustomization paths. Kustomization will
be run on those paths and the outcome will be deployed.
items:
properties:
components:
description: |-
Components is a list of paths to Kustomize components. These paths are relative to the
` + "`" + `Path` + "`" + ` field and are included in the Kustomize build to provide reusable configuration logic.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
type: string
type: array
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
NOTE: DeploymentType Local cannot be used when the matching cluster is the management cluster itself.
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
KustomizationRef when an update is rejected with an error that only a delete+recreate
can resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this KustomizationRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- flux GitRepository;OCIRepository;Bucket
- ConfigMap/Secret
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
path:
description: |-
Path to the directory containing the kustomization.yaml file, or the
set of plain YAMLs a kustomization.yaml should be generated for.
Defaults to 'None', which translates to the root path of the SourceRef.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching the Kustomize directory content from an HTTP/HTTPS
endpoint or an OCI registry, without requiring a Flux GitRepository/OCIRepository/Bucket
or a ConfigMap/Secret.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the remote source serving the Kustomize directory content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint serving a gzipped tarball
(.tar.gz) of the Kustomize directory
"oci://" — OCI registry artifact whose layers are extracted
the same way, preserving the directory tree
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this KustomizationRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
targetNamespace:
description: |-
TargetNamespace sets or overrides the namespace in the
kustomization.yaml file.
maxLength: 63
minLength: 1
type: string
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different KustomizationRef
within the same ClusterProfile or Profile.
When two KustomizationRef attempt to deploy the same resource, the KustomizationRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
values:
additionalProperties:
type: string
description: |-
Values is a map[string]string type that allows to define a set of key-value pairs.
These key-value pairs can optionally leverage Go templates for further processing.
With Sveltos, you can define key-value pairs where the values can be Go templates.
These templates have access to management cluster information during deployment. This allows
to do more than just replace placeholders. Variables can be used to dynamically
construct values based on other resources or variables within the Kustomize output.
For example, imagine you have a Region key with a template value like:
'{{ index .Cluster.metadata.labels "region" }}'.
This template retrieves the region label from the cluster instance metadata.
Finally, Sveltos uses these processed values to fill placeholders in the Kustomize output.
The output itself can also contain templates, like:
region: '{{ default "west" .Region }}'.
This way, the final output from Kustomize will have the region set dynamically based on
the actual region retrieved earlier.
type: object
valuesFrom:
description: |-
ValuesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to define key-value pairs. These key-value pairs can optionally leverage
Go templates for further processing.
With Sveltos, you can define key-value pairs where the values can be Go templates.
These templates have access to management cluster information during deployment. This allows
to do more than just replace placeholders. Variables can be used to dynamically
construct values based on other resources or variables within the Kustomize output.
For example, imagine you have a Region key with a template value like:
'{{ index .Cluster.metadata.labels "region" }}'.
This template retrieves the region label from the cluster instance metadata.
Finally, Sveltos uses these processed values to fill placeholders in the Kustomize output.
The output itself can also contain templates, like:
region: '{{ default "west" .Region }}'.
This way, the final output from Kustomize will have the region set dynamically based on
the actual region retrieved earlier.
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but not both
rule: has(self.remoteURL) != has(self.kind)
type: array
x-kubernetes-list-type: atomic
maxConsecutiveFailures:
description: |-
The maximum number of consecutive deployment failures that Sveltos will permit.
After this many consecutive failures, the deployment will be considered failed, and Sveltos will stop retrying.
This setting applies only to feature deployments, not resource removal.
This field is optional. If not set, Sveltos default behavior is to keep retrying.
type: integer
maxUpdate:
anyOf:
- type: integer
- type: string
description: |-
The maximum number of clusters that can be updated concurrently.
Value can be an absolute number (ex: 5) or a percentage of desired cluster (ex: 10%).
Defaults to 100%.
Example: when this is set to 30%, when list of add-ons/applications in ClusterProfile
changes, only 30% of matching clusters will be updated in parallel. Only when updates
in those cluster succeed, other matching clusters are updated.
pattern: ^((100|[0-9]{1,2})%|[0-9]+)$
x-kubernetes-int-or-string: true
patches:
description: |-
Define additional Kustomize inline Patches applied for all resources on this profile
Within the Patch Spec you can use templating
items:
description: |-
Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should
be applied to.
properties:
patch:
description: |-
Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with
an array of operation objects.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
target:
description: Target points to the resources that the patch
document should be applied to.
properties:
annotationSelector:
description: |-
AnnotationSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource annotations.
type: string
group:
description: |-
Group is the API group to select resources from.
Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
kind:
description: |-
Kind of the API Group to select resources from.
Together with Group and Version it is capable of unambiguously
identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
labelSelector:
description: |-
LabelSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource labels.
type: string
name:
description: Name to match resources with.
type: string
namespace:
description: Namespace to select resources from.
type: string
version:
description: |-
Version of the API Group to select resources from.
Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
type: object
required:
- patch
type: object
type: array
x-kubernetes-list-type: atomic
patchesFrom:
description: |-
PatchesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to store additional Kustomize inline Patches applied for all resources on this profile
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
x-kubernetes-list-type: atomic
policyRefs:
description: |-
PolicyRefs references all the ConfigMaps/Secrets/Flux Sources containing kubernetes resources
that need to be deployed in the matching managed clusters.
The values contained in those resources can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
PolicyRef when an update is rejected with an error that only a delete+recreate can
resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this PolicyRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
- flux GitRepository;OCIRepository;Bucket
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other PolicyRefs.
type: boolean
path:
description: |-
Path to the directory containing the YAML files.
Defaults to 'None', which translates to the root path of the SourceRef.
Used only for GitRepository;OCIRepository;Bucket
This value can be static or leverage Go templates for dynamic customization.
When expressed as a template, it is filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching content from an HTTP/HTTPS endpoint or an OCI registry.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
template:
description: |-
Template indicates that the fetched content is a Go template that
must be instantiated using cluster fields and templateResourceRefs values
before deployment. Equivalent to the projectsveltos.io/template annotation
on a ConfigMap or Secret.
type: boolean
url:
description: |-
URL is the remote source serving raw YAML/JSON content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint returning a raw YAML/JSON
document, a gzip-compressed document, an
uncompressed tar, or a gzip-compressed tar of
.yaml/.yml/.json files
"oci://" — OCI registry artifact whose layers are accepted
in the same shapes: raw YAML/JSON, gzip-compressed
YAML/JSON, uncompressed tar, or gzip-compressed tar
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this PolicyRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different PolicyRefs
within the same ClusterProfile or Profile.
When two PolicyRefs attempt to deploy the same resource, the PolicyRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but not both
rule: has(self.remoteURL) != has(self.kind)
type: array
x-kubernetes-list-type: atomic
postDeleteChecks:
description: |-
PostDeleteChecks is a slice of checks to run against the managed cluster
*after* Sveltos has deleted all resources.
This ensures that the environment has reached the desired clean state.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in
EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for
the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based
on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
preDeleteChecks:
description: |-
PreDeleteChecks is a slice of checks to run against the managed cluster
*before* Sveltos starts deleting resources.
If any of these fail, the deletion process is halted.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in
EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for
the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based
on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
preDeployChecks:
description: |-
PreDeployChecks is a slice of checks to run against the managed cluster
*before* Sveltos starts deploying resources.
Each check can use Lua scripts or CEL expressions to validate the cluster state.
If any check fails, the deployment of the associated feature is halted.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in
EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for
the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based
on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
reloader:
default: false
description: |-
Reloader indicates whether Deployment/StatefulSet/DaemonSet instances deployed
by Sveltos and part of this ClusterProfile need to be restarted via rolling upgrade
when a ConfigMap/Secret instance mounted as volume is modified.
When set to true, when any mounted ConfigMap/Secret is modified, Sveltos automatically
starts a rolling upgrade for Deployment/StatefulSet/DaemonSet instances mounting it.
type: boolean
setRefs:
description: |-
SetRefs identifies referenced (cluster)Sets.
- ClusterProfile can reference ClusterSet;
- Profile can reference Set;
items:
type: string
type: array
stopMatchingBehavior:
default: WithdrawPolicies
description: |-
StopMatchingBehavior indicates what behavior should be when a Cluster stop matching
the ClusterProfile. By default all deployed Helm charts and Kubernetes resources will
be withdrawn from Cluster. Setting StopMatchingBehavior to LeavePolicies will instead
leave ClusterProfile deployed policies in the Cluster.
enum:
- WithdrawPolicies
- LeavePolicies
type: string
syncMode:
default: Continuous
description: |-
SyncMode specifies how features are synced in a matching workload cluster.
- OneTime means, first time a workload cluster matches the ClusterProfile,
features will be deployed in such cluster. Any subsequent feature configuration
change won't be applied into the matching workload clusters;
- Continuous mode ensures that the first time a workload cluster matches a ClusterProfile,
the specified features are deployed. Subsequent changes to the feature configuration are also
automatically applied to all matching workload clusters.
_ SyncModeContinuousWithDriftDetection operates similarly to Continuous mode, but also monitors
matching managed clusters for configuration drift. If drift is detected, a reconciliation is
triggered to ensure the managed cluster's configuration aligns with the ClusterProfile.
- DryRun means no change will be propagated to any matching cluster. A report
instead will be generated summarizing what would happen in any matching cluster
because of the changes made to ClusterProfile while in DryRun mode.
enum:
- OneTime
- Continuous
- ContinuousWithDriftDetection
- DryRun
type: string
templateResourceRefs:
description: |-
TemplateResourceRefs is a list of resource to collect from the management cluster.
Those resources' values will be used to instantiate templates
items:
properties:
identifier:
description: |-
Identifier is how the resource will be referred to in the
template
type: string
ignoreStatusChanges:
default: false
description: |-
IgnoreStatusChanges indicates whether changes to the status of the referenced
resource should be ignored. If set to true, only changes to the spec or
metadata (generation change) will trigger a reconciliation.
type: boolean
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other TemplateResourceRefs.
type: boolean
resource:
description: |-
Resource references a Kubernetes instance in the management
cluster to fetch and use during template instantiation.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
Name and namespace can be expressed as a template and instantiate using any cluster field.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
watchFields:
description: |-
WatchFields is an optional list of dot-separated field paths to include
when computing the hash for this resource (e.g. "status.readyReplicas",
"metadata.labels"). When non-empty, only the listed fields are hashed and
IgnoreStatusChanges is ignored. Use this when you need to react to a
specific field without being sensitive to every other change on the object.
items:
type: string
type: array
required:
- identifier
- resource
type: object
type: array
x-kubernetes-list-map-keys:
- identifier
x-kubernetes-list-type: map
tier:
default: 100
description: |-
Tier controls the order of deployment for ClusterProfile or Profile resources targeting
the same cluster resources.
Imagine two configurations (ClusterProfiles or Profiles) trying to deploy the same resource (a Kubernetes
resource or an helm chart). By default, the first one to reach the cluster "wins" and deploys it.
Tier allows you to override this. When conflicts arise, the ClusterProfile or Profile with the **lowest**
Tier value takes priority and deploys the resource.
Higher Tier values represent lower priority. The default Tier value is 100.
Using Tiers provides finer control over resource deployment within your cluster, particularly useful
when multiple configurations manage the same resources.
format: int32
minimum: 1
type: integer
validateHealths:
description: |-
ValidateHealths is a slice of checks to run against the managed cluster
*after* resources are deployed to validate that the state of the
add-ons/applications is healthy.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in
EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for
the rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based
on current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to
reference a secret resource.
type: string
namespace:
description: namespace defines the space within
which the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
type: object
clusterType:
description: ClusterType is the type of Cluster
type: string
required:
- clusterName
- clusterNamespace
- clusterType
type: object
status:
description: ClusterSummaryStatus defines the observed state of ClusterSummary
properties:
dependencies:
description: |-
Dependencies is a summary reporting the status of the dependencies
for the associated ClusterProfile
type: string
deployedGVKs:
description: |-
DeployedGVKs reports the list of GVKs deployed by ClusterSummary
in a managed cluster
items:
properties:
deployedGroupVersionKind:
description: |-
DeployedGroupVersionKind contains all GroupVersionKinds deployed in either
the workload cluster or the management cluster because of this feature.
Each element has format kind.version.group
items:
type: string
type: array
featureID:
description: FeatureID is an identifier of the feature whose
status is reported
enum:
- Resources
- Helm
- Kustomize
type: string
required:
- featureID
type: object
type: array
x-kubernetes-list-map-keys:
- featureID
x-kubernetes-list-type: map
failureMessage:
description: |-
FailureMessage reports any error encountered during the reconciliation of the ClusterSummary
instance itself, *excluding* errors related to the deployment of individual features.
type: string
featureSummaries:
description: |-
FeatureSummaries reports the status of each workload cluster feature
directly managed by ClusterProfile.
items:
description: |-
FeatureSummary contains a summary of the state of a workload
cluster feature.
properties:
consecutiveFailures:
description: The number of consecutive deployment failures.
type: integer
deployedGroupVersionKind:
description: |-
DeployedGroupVersionKind contains all GroupVersionKinds deployed in either
the workload cluster or the management cluster because of this feature.
Each element has format kind.version.group
Deprecated: Replaced by FeatureDeploymentInfo field instead
items:
type: string
type: array
failureMessage:
description: FailureMessage provides more information about
the error.
type: string
failureReason:
description: FailureReason indicates the type of error that
occurred.
type: string
featureID:
description: FeatureID is an indentifier of the feature whose
status is reported
enum:
- Resources
- Helm
- Kustomize
type: string
hash:
description: |-
Hash represents of a unique value for a feature at a fixed point in
time
format: byte
type: string
lastAppliedTime:
description: LastAppliedTime is the time feature was last reconciled
format: date-time
type: string
resourceSummaryDeployed:
description: |-
ResourceSummaryDeployed tracks whether a ResourceSummary was deployed
to the managed cluster for drift detection. nil means unknown (upgrade
scenario); true means currently deployed; false means removed.
type: boolean
status:
description: Status represents the state of the feature in the
workload cluster
enum:
- Provisioning
- Provisioned
- Failed
- FailedNonRetriable
- Removing
- Removed
- AgentRemoving
type: string
required:
- featureID
type: object
type: array
x-kubernetes-list-map-keys:
- featureID
x-kubernetes-list-type: map
helmReleaseSummaries:
description: |-
HelmReleaseSummaries reports the status of each helm chart
directly managed by ClusterProfile.
items:
properties:
chartName:
description: |-
ChartName, RepositoryName, RepoURL, and ChartVersion mirror the fully resolved
(post-template) HelmChart entry that produced this release, captured at deploy time.
Never set for Flux-source-backed charts (Flux owns version resolution there).
type: string
chartVersion:
type: string
conflictMessage:
description: |-
Status indicates whether ClusterSummary can manage the helm
chart or there is a conflict
type: string
credentialsSecretRef:
description: |-
CredentialsSecretRef is the resolved secret reference (if any) used to authenticate
against RepoURL, captured at deploy time. Only the reference is stored, never secret
contents.
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which the
secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
failureMessage:
description: FailureMessage provides the specific error from
the Helm engine for this release
type: string
lastCheckedTime:
description: LastCheckedTime is when LatestVersion/LatestPatchVersion
were last evaluated.
format: date-time
type: string
latestPatchVersion:
description: |-
LatestPatchVersion is the highest published version sharing ChartVersion's
major.minor, if greater than ChartVersion. Distinguishes "a same-minor patch bump is
available" from "a newer minor/major line exists" (LatestVersion).
type: string
latestVersion:
description: |-
LatestVersion is the highest version currently published upstream for this chart, if
greater than ChartVersion. Populated by a periodic background check, independent of
the reconcile loop. Detection only: Sveltos never mutates ChartVersion based on this.
type: string
needsRedeploy:
description: |-
NeedsRedeploy is set to true when drift-detection reports that a resource deployed by
this chart changed out of band. Only meaningful when SyncMode is ContinuousWithDriftDetection.
When true, this chart is upgraded on the next reconciliation regardless of whether its
desired values/version changed; cleared once the upgrade succeeds.
type: boolean
patchesHash:
description: PatchesHash represents of a unique value for the
patches section
format: byte
type: string
releaseName:
description: ReleaseName is the chart release
minLength: 1
type: string
releaseNamespace:
description: ReleaseNamespace is the namespace release will
be installed
minLength: 1
type: string
repoURL:
type: string
repositoryName:
type: string
status:
description: |-
Status indicates whether ClusterSummary can manage the helm
chart or there is a conflict
enum:
- Managing
- Conflict
type: string
valuesHash:
description: ValuesHash represents of a unique value for the
values section
format: byte
type: string
required:
- releaseName
- releaseNamespace
- status
type: object
type: array
x-kubernetes-list-type: atomic
nextReconcileTime:
description: |-
NextReconcileTime is the earliest time when this resource should be reconciled again.
Controller skips reconciliation if current time is before this timestamp.
If not set, reconciliations will happen as usual.
format: date-time
type: string
reconciliationSuspended:
description: |-
ReconciliationSuspended indicates whether the reconciliation loop for this
ClusterSummary is currently paused due to an external action (e.g., a user annotation).
When true, the status will not be updated unless the pause is lifted.
type: boolean
suspensionReason:
description: SuspensionReason provides a brief explanation of why
the reconciliation is suspended.
type: string
type: object
type: object
served: true
storage: true
subresources:
status: {}
`)
var ClusterSummaryFile = "../../config/crd/bases/config.projectsveltos.io_clustersummaries.yaml"
var ProfileCRD = []byte(`---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.21.0
name: profiles.config.projectsveltos.io
spec:
group: config.projectsveltos.io
names:
kind: Profile
listKind: ProfileList
plural: profiles
singular: profile
scope: Namespaced
versions:
- name: v1beta1
schema:
openAPIV3Schema:
description: Profile is the Schema for the profiles API
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
properties:
clusterRefs:
description: ClusterRefs identifies clusters to associate to.
items:
description: ObjectReference contains enough information to let
you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
clusterSelector:
description: ClusterSelector identifies clusters to associate to.
properties:
matchExpressions:
description: matchExpressions is a list of label selector requirements.
The requirements are ANDed.
items:
description: |-
A label selector requirement is a selector that contains values, a key, and an operator that
relates the key and values.
properties:
key:
description: key is the label key that the selector applies
to.
type: string
operator:
description: |-
operator represents a key's relationship to a set of values.
Valid operators are In, NotIn, Exists and DoesNotExist.
type: string
values:
description: |-
values is an array of string values. If the operator is In or NotIn,
the values array must be non-empty. If the operator is Exists or DoesNotExist,
the values array must be empty. This array is replaced during a strategic
merge patch.
items:
type: string
type: array
x-kubernetes-list-type: atomic
required:
- key
- operator
type: object
type: array
x-kubernetes-list-type: atomic
matchLabels:
additionalProperties:
type: string
description: |-
matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
map is equivalent to an element of matchExpressions, whose key field is "key", the
operator is "In", and the values array contains only "value". The requirements are ANDed.
type: object
type: object
x-kubernetes-map-type: atomic
continueOnConflict:
default: false
description: |-
By default (when ContinueOnConflict is unset or set to false), Sveltos stops deployment after
encountering the first conflict (e.g., another ClusterProfile already deployed the resource).
If set to true, Sveltos will attempt to deploy remaining resources in the ClusterProfile even
if conflicts are detected for previous resources.
type: boolean
continueOnError:
default: false
description: |-
By default (when ContinueOnError is unset or set to false), Sveltos stops deployment after
encountering the first error.
If set to true, Sveltos will attempt to deploy remaining resources in the ClusterProfile even
if errors are detected for previous resources.
type: boolean
dependsOn:
description: |-
DependsOn specifies a list of other profiles that this instance depends on.
A ClusterProfile can only depend on other ClusterProfiles, and a Profile can
only depend on other Profiles.
The add-ons and applications defined in this instance will not be deployed
until all add-ons and applications in the profiles listed as dependencies are deployed.
items:
type: string
type: array
driftExclusions:
description: |-
DriftExclusions is a list of configuration drift exclusions to be applied when syncMode is
set to ContinuousWithDriftDetection. Each exclusion specifies JSON6902 paths to ignore
when evaluating drift, optionally targeting specific resources and features.
items:
properties:
paths:
description: Paths is a slice of JSON6902 paths to exclude from
configuration drift evaluation.
items:
type: string
type: array
target:
description: Target points to the resources that the paths refers
to.
properties:
annotationSelector:
description: |-
AnnotationSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource annotations.
type: string
group:
description: |-
Group is the API group to select resources from.
Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
kind:
description: |-
Kind of the API Group to select resources from.
Together with Group and Version it is capable of unambiguously
identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
labelSelector:
description: |-
LabelSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource labels.
type: string
name:
description: Name to match resources with.
type: string
namespace:
description: Namespace to select resources from.
type: string
version:
description: |-
Version of the API Group to select resources from.
Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
type: object
required:
- paths
type: object
type: array
x-kubernetes-list-type: atomic
extraAnnotations:
additionalProperties:
type: string
description: |-
ExtraAnnotations: These annotations will be added by Sveltos to all Kubernetes resources
deployed in a managed cluster based on this ClusterProfile/Profile instance.
**Important:** If a resource deployed by Sveltos already has a annotation with a key present in
` + "`" + `ExtraAnnotations` + "`" + `, the value from ` + "`" + `ExtraAnnotations` + "`" + ` will override the existing value.
(Deprecated use Patches instead)
type: object
extraLabels:
additionalProperties:
type: string
description: |-
ExtraLabels: These labels will be added by Sveltos to all Kubernetes resources deployed in
a managed cluster based on this ClusterProfile/Profile instance.
**Important:** If a resource deployed by Sveltos already has a label with a key present in
` + "`" + `ExtraLabels` + "`" + `, the value from ` + "`" + `ExtraLabels` + "`" + ` will override the existing value.
(Deprecated use Patches instead)
type: object
helmCharts:
description: Helm charts is a list of helm charts that need to be
deployed
items:
properties:
chartName:
description: |-
ChartName is the chart name
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
Must be defined otherwise.
type: string
chartVersion:
description: |-
ChartVersion is the chart version
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
It is ignored if RepositoryURL references a Flux Source.
Must be defined otherwise.
type: string
helmChartAction:
default: Install
description: HelmChartAction is the action that will be taken
on the helm chart
enum:
- Install
- Uninstall
type: string
options:
description: Options allows to set flags which are used during
installation.
properties:
atomic:
default: false
description: |-
if set, the installation process deletes the installation/upgrades on failure.
The --wait flag will be set automatically if --atomic is used
Default to false
type: boolean
dependencyUpdate:
default: false
description: |-
update dependencies if they are missing before installing the chart
Default to false
type: boolean
description:
description: Description is the description of an helm operation
type: string
disableHooks:
default: false
description: |-
prevent hooks from running during install/upgrade/uninstall
Default to false
type: boolean
disableOpenAPIValidation:
default: false
description: |-
if set, the installation process will not validate rendered templates against the Kubernetes OpenAPI Schema
Default to false
type: boolean
enableClientCache:
default: false
description: EnableClientCache is a flag to enable Helm
client cache. If it is not specified, it will be set to
false.
type: boolean
installOptions:
description: HelmInstallOptions are options specific to
helm install
properties:
createNamespace:
default: true
description: Create the release namespace if not present.
Defaults to true
type: boolean
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on install
Default to false
type: boolean
recoverAfterConsecutiveFailures:
default: 5
description: |-
RecoverAfterConsecutiveFailures is the number of consecutive install failures for this
chart after which Sveltos uninstalls any existing release under this name before
retrying, to clear potentially stale Helm release history that would otherwise keep
blocking every subsequent install attempt. This only ever runs when there is no
currently deployed release to protect: a release that is deployed, or mid-upgrade, or
failed while already existing, is always retried through helm upgrade instead, never
through this. It only applies to a release that was never successfully installed, or
was already cleanly uninstalled.
Default to 5
type: integer
replace:
default: true
description: Replaces if set indicates to replace an
older release with this one
type: boolean
takeOwnership:
default: false
description: |-
if set, install will ignore the check for helm annotations
and take ownership of the existing resources
type: boolean
type: object
labels:
additionalProperties:
type: string
description: Labels that would be added to release metadata.
type: object
passCredentialsAll:
description: PassCredentialsAll is the flag to pass credentials
to all domains
type: boolean
postRenderStrategy:
description: |-
PostRenderStrategy controls whether Helm hooks are included when Patches/PatchesFrom
are applied as a post-renderer during this chart's install/upgrade. Only relevant
when Patches or PatchesFrom is set on the Spec; ignored otherwise. Defaults to
Helm's own default (combined) when unset.
enum:
- combined
- separate
- nohooks
type: string
runTests:
default: false
description: |-
RunTests if set to true, Sveltos will run helm test after each successful install or upgrade
operation. The tests are the test hooks defined in the chart (annotated with
"helm.sh/hook: test"). If any test fails the deployment is considered failed and the
error is surfaced in the ClusterSummary status, providing operational gating.
Has no effect in DryRun mode.
Default to false
type: boolean
skipCRDs:
default: false
description: |-
SkipCRDs controls whether CRDs should be installed during install/upgrade operation.
By default, CRDs are installed if not already present.
type: boolean
skipSchemaValidation:
default: false
description: SkipSchemaValidation determines if JSON schema
validation is disabled.
type: boolean
timeout:
description: time to wait for any individual Kubernetes
operation (like Jobs for hooks) (default 5m0s)
type: string
uninstallOptions:
description: HelmUninstallOptions are options specific to
helm uninstall
properties:
deletionPropagation:
description: DeletionPropagation
enum:
- orphan
- foreground
- background
type: string
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on uninstall
Default to false
type: boolean
keepHistory:
description: |-
When uninstall a chart with this flag, Helm removes the resources associated with the chart,
but it keeps the release information. This allows to see details about the uninstalled release
using the helm history command.
type: boolean
type: object
upgradeOptions:
description: HelmUpgradeOptions are options specific to
helm upgrade
properties:
cleanupOnFail:
default: false
description: CleanupOnFail will, if true, cause the
upgrade to delete newly-created resources on a failed
update.
type: boolean
disableHooks:
default: false
description: |-
prevent hooks from running during install. If set to true, overrides
DisableHooks in HelmOptions. Use this one when you want to selective
disable hooks on upgrade
Default to false
type: boolean
force:
default: false
description: |-
Force will, if set to ` + "`" + `true` + "`" + `, ignore certain warnings and perform the upgrade anyway.
This should be used with caution.
type: boolean
maxHistory:
default: 2
description: |-
MaxHistory limits the maximum number of revisions saved per release
Default to 2
type: integer
recreate:
default: false
description: |-
Recreate will (if true) recreate pods after a rollback.
Deprecated: This field is no longer supported
type: boolean
resetThenReuseValues:
default: false
description: ResetThenReuseValues will reset the values
to the chart's built-ins then merge with user's last
supplied values.
type: boolean
resetValues:
default: false
description: ResetValues will reset the values to the
chart's built-ins rather than merging with existing.
type: boolean
reuseValues:
default: false
description: |-
ReuseValues copies values from the current release to a new release if the
new release does not have any values. If the request already has values,
or if there are no values in the current release, this does nothing.
This is skipped if the ResetValues flag is set, in which case the
request values are not altered.
type: boolean
subNotes:
default: false
description: SubNotes determines whether sub-notes are
rendered in the chart.
type: boolean
takeOwnership:
default: false
description: |-
if set, upgrade will ignore the check for helm annotations
and take ownership of the existing resources
type: boolean
upgradeCRDs:
default: false
description: |-
UpgradeCRDs upgrade CRDs from the Helm Chart's crds directory
By default, CRDs are not applied during Helm upgrade action by Helm
https://helm.sh/docs/chart_best_practices/custom_resource_definitions/
type: boolean
type: object
wait:
default: false
description: |-
if set, will wait until all Pods, PVCs, Services, and minimum number of Pods of a Deployment, StatefulSet, or ReplicaSet
are in a ready state before marking the release as successful. It will wait for as long as --timeout
Default to false
type: boolean
waitForJobs:
default: false
description: |-
if set and --wait enabled, will wait until all Jobs have been completed before marking the release as successful.
It will wait for as long as --timeout
Default to false
type: boolean
type: object
provenanceVerification:
description: |-
ProvenanceVerification configures Helm GPG .prov file verification for HTTP chart repositories.
Ignored for OCI and Flux-sourced charts.
properties:
keyringSecretRef:
description: |-
KeyringSecretRef references a Secret in the management cluster containing the GPG keyring.
The Secret must have a key named "keyring.gpg".
If Namespace is omitted, the cluster's namespace is used.
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
required:
- keyringSecretRef
type: object
registryCredentialsConfig:
description: |-
RegistryCredentialsConfig is an optional configuration for credentials,
including information to connect to private registries.
properties:
ca:
description: |-
CASecretRef references a secret containing the TLS CA certificate
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
key: ca.crt
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
credentials:
description: |-
CredentialsSecretRef references a secret containing credentials
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
insecureSkipTLSVerify:
description: InsecureSkipTLSVerify controls server certificate
verification.
type: boolean
key:
description: |-
Key specifies the key within the CredentialsSecretRef containing the data
If not specified, it defaults to the only key in the secret if there's just one.
type: string
plainHTTP:
description: PlainHTTP indicates to use insecure HTTP connections
for the chart download
type: boolean
type: object
releaseName:
description: ReleaseName is the chart release
minLength: 1
type: string
releaseNamespace:
description: ReleaseNamespace is the namespace release will
be installed
minLength: 1
type: string
repositoryName:
description: |-
RepositoryName is the name helm chart repository
This field is used only when RepositoryURL points to a traditional HTTP or OCI repository.
It is ignored if RepositoryURL references a Flux Source.
Must be defined otherwise.
type: string
repositoryURL:
description: |-
RepositoryURL is the URL helm chart repository
It can point to a traditional HTTP-based repository or an OCI registry.
Examples:
- HTTP Repository: https://charts.example.com/stable
- OCI Registry: oci://registry.example.com/namespace/charts
- GitHub Pages: https://<username>.github.io/<repository>/
- Any other valid URL where Helm charts are hosted.
Alternatively, it can be a Flux source reference:
<flux source kind>://<flux source namespace>/<flux source name>/<path>
Where:
- <flux source kind> is the type of Flux source (gitrepository, ocirepository, bucket).
- <flux source namespace> and <flux source name> are the namespace and name of the Flux Source in the management cluster.
- <path> is the path within the source repository where the Helm charts are located.
For instance:
gitrepository://flux-system/flux-system/charts/projectsveltos
Assuming there is a Flux GitRepository named 'flux-system' in the 'flux-system' namespace
syncing 'https://github.com/projectsveltos/helm-charts.git/', and the Helm charts are
located in the 'charts/projectsveltos' directory of that repository.
minLength: 1
type: string
signatureVerification:
description: |-
SignatureVerification configures Cosign-based signature verification for OCI Helm charts.
Ignored when RepositoryURL does not start with "oci://".
properties:
matchOIDCIdentity:
description: |-
MatchOIDCIdentity lists OIDC identity matchers for keyless verification.
At least one matcher must be satisfied. Required when Provider is Keyless.
items:
description: OIDCIdentityMatcher specifies the expected
OIDC issuer and subject for keyless Cosign verification.
properties:
issuer:
description: Issuer is the OIDC issuer URL or regex.
minLength: 1
type: string
subject:
description: Subject is the OIDC subject or regex,
typically the workload identity or GitHub Actions
workflow URL.
minLength: 1
type: string
required:
- issuer
- subject
type: object
type: array
provider:
description: Provider specifies how to obtain the verification
key or certificate.
enum:
- PublicKey
- Keyless
type: string
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing the Cosign public key.
The Secret must have a key named "cosign.pub" holding a PEM-encoded public key.
Required when Provider is PublicKey.
If Namespace is omitted, the cluster's namespace is used.
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
required:
- provider
type: object
values:
description: |-
Values field allows to define configuration for the Helm release.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
valuesFrom:
description: |-
ValuesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to store configuration for the Helm release.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
required:
- releaseName
- releaseNamespace
- repositoryURL
type: object
x-kubernetes-validations:
- message: ChartName must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.chartName)
>= 1 : true'
- message: ChartName must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.chartName)
>= 1 : true'
- message: ChartVersion must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.chartVersion)
>= 1 : true'
- message: ChartVersion must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.chartVersion)
>= 1 : true'
- message: RepositoryName must be defined
rule: 'self.repositoryURL.startsWith(''http'') ? size(self.repositoryName)
>= 1 : true'
- message: RepositoryName must be defined
rule: 'self.repositoryURL.startsWith(''oci'') ? size(self.repositoryName)
>= 1 : true'
type: array
x-kubernetes-list-type: atomic
kustomizationRefs:
description: |-
Kustomization refs is a list of kustomization paths. Kustomization will
be run on those paths and the outcome will be deployed.
items:
properties:
components:
description: |-
Components is a list of paths to Kustomize components. These paths are relative to the
` + "`" + `Path` + "`" + ` field and are included in the Kustomize build to provide reusable configuration logic.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
type: string
type: array
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
NOTE: DeploymentType Local cannot be used when the matching cluster is the management cluster itself.
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
KustomizationRef when an update is rejected with an error that only a delete+recreate
can resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this KustomizationRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- flux GitRepository;OCIRepository;Bucket
- ConfigMap/Secret
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
path:
description: |-
Path to the directory containing the kustomization.yaml file, or the
set of plain YAMLs a kustomization.yaml should be generated for.
Defaults to 'None', which translates to the root path of the SourceRef.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching the Kustomize directory content from an HTTP/HTTPS
endpoint or an OCI registry, without requiring a Flux GitRepository/OCIRepository/Bucket
or a ConfigMap/Secret.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the remote source serving the Kustomize directory content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint serving a gzipped tarball
(.tar.gz) of the Kustomize directory
"oci://" — OCI registry artifact whose layers are extracted
the same way, preserving the directory tree
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this KustomizationRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
targetNamespace:
description: |-
TargetNamespace sets or overrides the namespace in the
kustomization.yaml file.
maxLength: 63
minLength: 1
type: string
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different KustomizationRef
within the same ClusterProfile or Profile.
When two KustomizationRef attempt to deploy the same resource, the KustomizationRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
values:
additionalProperties:
type: string
description: |-
Values is a map[string]string type that allows to define a set of key-value pairs.
These key-value pairs can optionally leverage Go templates for further processing.
With Sveltos, you can define key-value pairs where the values can be Go templates.
These templates have access to management cluster information during deployment. This allows
to do more than just replace placeholders. Variables can be used to dynamically
construct values based on other resources or variables within the Kustomize output.
For example, imagine you have a Region key with a template value like:
'{{ index .Cluster.metadata.labels "region" }}'.
This template retrieves the region label from the cluster instance metadata.
Finally, Sveltos uses these processed values to fill placeholders in the Kustomize output.
The output itself can also contain templates, like:
region: '{{ default "west" .Region }}'.
This way, the final output from Kustomize will have the region set dynamically based on
the actual region retrieved earlier.
type: object
valuesFrom:
description: |-
ValuesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to define key-value pairs. These key-value pairs can optionally leverage
Go templates for further processing.
With Sveltos, you can define key-value pairs where the values can be Go templates.
These templates have access to management cluster information during deployment. This allows
to do more than just replace placeholders. Variables can be used to dynamically
construct values based on other resources or variables within the Kustomize output.
For example, imagine you have a Region key with a template value like:
'{{ index .Cluster.metadata.labels "region" }}'.
This template retrieves the region label from the cluster instance metadata.
Finally, Sveltos uses these processed values to fill placeholders in the Kustomize output.
The output itself can also contain templates, like:
region: '{{ default "west" .Region }}'.
This way, the final output from Kustomize will have the region set dynamically based on
the actual region retrieved earlier.
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but not both
rule: has(self.remoteURL) != has(self.kind)
type: array
x-kubernetes-list-type: atomic
maxConsecutiveFailures:
description: |-
The maximum number of consecutive deployment failures that Sveltos will permit.
After this many consecutive failures, the deployment will be considered failed, and Sveltos will stop retrying.
This setting applies only to feature deployments, not resource removal.
This field is optional. If not set, Sveltos default behavior is to keep retrying.
type: integer
maxUpdate:
anyOf:
- type: integer
- type: string
description: |-
The maximum number of clusters that can be updated concurrently.
Value can be an absolute number (ex: 5) or a percentage of desired cluster (ex: 10%).
Defaults to 100%.
Example: when this is set to 30%, when list of add-ons/applications in ClusterProfile
changes, only 30% of matching clusters will be updated in parallel. Only when updates
in those cluster succeed, other matching clusters are updated.
pattern: ^((100|[0-9]{1,2})%|[0-9]+)$
x-kubernetes-int-or-string: true
patches:
description: |-
Define additional Kustomize inline Patches applied for all resources on this profile
Within the Patch Spec you can use templating
items:
description: |-
Patch contains an inline StrategicMerge or JSON6902 patch, and the target the patch should
be applied to.
properties:
patch:
description: |-
Patch contains an inline StrategicMerge patch or an inline JSON6902 patch with
an array of operation objects.
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
target:
description: Target points to the resources that the patch document
should be applied to.
properties:
annotationSelector:
description: |-
AnnotationSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource annotations.
type: string
group:
description: |-
Group is the API group to select resources from.
Together with Version and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
kind:
description: |-
Kind of the API Group to select resources from.
Together with Group and Version it is capable of unambiguously
identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
labelSelector:
description: |-
LabelSelector is a string that follows the label selection expression
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/#api
It matches with the resource labels.
type: string
name:
description: Name to match resources with.
type: string
namespace:
description: Namespace to select resources from.
type: string
version:
description: |-
Version of the API Group to select resources from.
Together with Group and Kind it is capable of unambiguously identifying and/or selecting resources.
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/api-machinery/api-group.md
type: string
type: object
required:
- patch
type: object
type: array
x-kubernetes-list-type: atomic
patchesFrom:
description: |-
PatchesFrom can reference ConfigMap/Secret instances. Within the ConfigMap or Secret data,
it is possible to store additional Kustomize inline Patches applied for all resources on this profile
These values can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
enum:
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. The Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other ValueFroms.
type: boolean
required:
- kind
- name
type: object
type: array
x-kubernetes-list-type: atomic
policyRefs:
description: |-
PolicyRefs references all the ConfigMaps/Secrets/Flux Sources containing kubernetes resources
that need to be deployed in the matching managed clusters.
The values contained in those resources can be static or leverage Go templates for dynamic customization.
When expressed as templates, the values are filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
items:
properties:
deploymentType:
default: Remote
description: |-
DeploymentType indicates whether resources need to be deployed
into the management cluster (local) or the managed cluster (remote)
enum:
- Local
- Remote
type: string
force:
default: false
description: |-
Force indicates whether Sveltos should delete and recreate a resource defined in this
PolicyRef when an update is rejected with an error that only a delete+recreate can
resolve (eg an invalid combination of fields, or a field enforced as immutable).
By default, such errors are surfaced instead of recreating the resource.
This applies to every resource produced by this PolicyRef. To force just one
resource, regardless of this field's value, annotate that resource with
projectsveltos.io/forceRecreate instead.
type: boolean
kind:
description: |-
Kind of the resource. Supported kinds are:
- ConfigMap/Secret
- flux GitRepository;OCIRepository;Bucket
Required when RemoteURL is not set.
enum:
- GitRepository
- OCIRepository
- Bucket
- ConfigMap
- Secret
type: string
name:
description: |-
Name of the referenced resource.
Name can be expressed as a template and instantiate using any cluster field.
Required when RemoteURL is not set.
type: string
namespace:
description: |-
Namespace of the referenced resource.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
For Profile namespace must be left empty. Profile namespace will be used.
Namespace can be expressed as a template and instantiate using any cluster field.
Not used when RemoteURL is set.
type: string
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other PolicyRefs.
type: boolean
path:
description: |-
Path to the directory containing the YAML files.
Defaults to 'None', which translates to the root path of the SourceRef.
Used only for GitRepository;OCIRepository;Bucket
This value can be static or leverage Go templates for dynamic customization.
When expressed as a template, it is filled in using information from
resources within the management cluster before deployment (Cluster and TemplateResourceRefs)
type: string
remoteURL:
description: |-
RemoteURL configures fetching content from an HTTP/HTTPS endpoint or an OCI registry.
When set, Kind/Name/Namespace must be omitted.
properties:
insecureSkipTLSVerify:
default: false
description: |-
InsecureSkipTLSVerify controls server certificate verification.
Ignored if the referenced SecretRef provides a "caFile".
type: boolean
interval:
description: |-
Interval defines how often Sveltos re-fetches the source to detect changes.
Defaults to 5 minutes.
type: string
plainHTTP:
default: false
description: |-
PlainHTTP indicates to use insecure HTTP connections when URL uses the
"oci://" scheme. Ignored for "http://"/"https://" URLs.
type: boolean
secretRef:
description: |-
SecretRef references a Secret in the management cluster containing optional
credentials for fetching the source. Both Name and Namespace must be set,
allowing the Secret to live in any namespace (e.g. projectsveltos) so that
a single Secret can be shared across clusters without replication.
Supported Secret keys:
"token" — Bearer token (Authorization: Bearer <token>)
"username"+"password" — HTTP Basic Auth or OCI registry basic auth
"caFile" — PEM-encoded CA certificate for TLS verification
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
template:
description: |-
Template indicates that the fetched content is a Go template that
must be instantiated using cluster fields and templateResourceRefs values
before deployment. Equivalent to the projectsveltos.io/template annotation
on a ConfigMap or Secret.
type: boolean
url:
description: |-
URL is the remote source serving raw YAML/JSON content.
Sveltos fetches the content on every reconciliation and redeploys if the
content hash has changed.
Supported schemes:
"http://" or "https://" — HTTP/HTTPS endpoint returning a raw YAML/JSON
document, a gzip-compressed document, an
uncompressed tar, or a gzip-compressed tar of
.yaml/.yml/.json files
"oci://" — OCI registry artifact whose layers are accepted
in the same shapes: raw YAML/JSON, gzip-compressed
YAML/JSON, uncompressed tar, or gzip-compressed tar
pattern: ^(https?|oci)://
type: string
required:
- url
type: object
skipNamespaceCreation:
default: false
description: |-
SkipNamespaceCreation indicates whether Sveltos should skip creating the namespace
for namespaced resources defined in this PolicyRef.
This field is ignored for cluster-scoped resources.
By default, Sveltos attempts to get or create the target namespace if it does not exist.
Setting this to true avoids those calls, which is necessary when Sveltos lacks
permissions to manage namespaces at the cluster level.
type: boolean
tier:
default: 100
description: |-
Tier controls the order of deployment for resources coming from different PolicyRefs
within the same ClusterProfile or Profile.
When two PolicyRefs attempt to deploy the same resource, the PolicyRef with the lowest
Tier value takes priority and deploys/updates the resource.
This priority mechanism is only checked after the parent ClusterProfile has won
the primary conflict resolution against other ClusterProfiles.
Higher Tier values represent lower priority. The default Tier value is 100.
format: int32
minimum: 1
type: integer
type: object
x-kubernetes-validations:
- message: either remoteURL or kind must be set, but not both
rule: has(self.remoteURL) != has(self.kind)
type: array
x-kubernetes-list-type: atomic
postDeleteChecks:
description: |-
PostDeleteChecks is a slice of checks to run against the managed cluster
*after* Sveltos has deleted all resources.
This ensures that the environment has reached the desired clean state.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for the
rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based on
current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
preDeleteChecks:
description: |-
PreDeleteChecks is a slice of checks to run against the managed cluster
*before* Sveltos starts deleting resources.
If any of these fail, the deletion process is halted.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for the
rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based on
current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
preDeployChecks:
description: |-
PreDeployChecks is a slice of checks to run against the managed cluster
*before* Sveltos starts deploying resources.
Each check can use Lua scripts or CEL expressions to validate the cluster state.
If any check fails, the deployment of the associated feature is halted.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for the
rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based on
current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
reloader:
default: false
description: |-
Reloader indicates whether Deployment/StatefulSet/DaemonSet instances deployed
by Sveltos and part of this ClusterProfile need to be restarted via rolling upgrade
when a ConfigMap/Secret instance mounted as volume is modified.
When set to true, when any mounted ConfigMap/Secret is modified, Sveltos automatically
starts a rolling upgrade for Deployment/StatefulSet/DaemonSet instances mounting it.
type: boolean
setRefs:
description: |-
SetRefs identifies referenced (cluster)Sets.
- ClusterProfile can reference ClusterSet;
- Profile can reference Set;
items:
type: string
type: array
stopMatchingBehavior:
default: WithdrawPolicies
description: |-
StopMatchingBehavior indicates what behavior should be when a Cluster stop matching
the ClusterProfile. By default all deployed Helm charts and Kubernetes resources will
be withdrawn from Cluster. Setting StopMatchingBehavior to LeavePolicies will instead
leave ClusterProfile deployed policies in the Cluster.
enum:
- WithdrawPolicies
- LeavePolicies
type: string
syncMode:
default: Continuous
description: |-
SyncMode specifies how features are synced in a matching workload cluster.
- OneTime means, first time a workload cluster matches the ClusterProfile,
features will be deployed in such cluster. Any subsequent feature configuration
change won't be applied into the matching workload clusters;
- Continuous mode ensures that the first time a workload cluster matches a ClusterProfile,
the specified features are deployed. Subsequent changes to the feature configuration are also
automatically applied to all matching workload clusters.
_ SyncModeContinuousWithDriftDetection operates similarly to Continuous mode, but also monitors
matching managed clusters for configuration drift. If drift is detected, a reconciliation is
triggered to ensure the managed cluster's configuration aligns with the ClusterProfile.
- DryRun means no change will be propagated to any matching cluster. A report
instead will be generated summarizing what would happen in any matching cluster
because of the changes made to ClusterProfile while in DryRun mode.
enum:
- OneTime
- Continuous
- ContinuousWithDriftDetection
- DryRun
type: string
templateResourceRefs:
description: |-
TemplateResourceRefs is a list of resource to collect from the management cluster.
Those resources' values will be used to instantiate templates
items:
properties:
identifier:
description: |-
Identifier is how the resource will be referred to in the
template
type: string
ignoreStatusChanges:
default: false
description: |-
IgnoreStatusChanges indicates whether changes to the status of the referenced
resource should be ignored. If set to true, only changes to the spec or
metadata (generation change) will trigger a reconciliation.
type: boolean
optional:
default: false
description: |-
Optional indicates that the referenced resource is not mandatory.
If set to true and the resource is not found, the error will be ignored,
and Sveltos will continue processing other TemplateResourceRefs.
type: boolean
resource:
description: |-
Resource references a Kubernetes instance in the management
cluster to fetch and use during template instantiation.
For ClusterProfile namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
Name and namespace can be expressed as a template and instantiate using any cluster field.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
watchFields:
description: |-
WatchFields is an optional list of dot-separated field paths to include
when computing the hash for this resource (e.g. "status.readyReplicas",
"metadata.labels"). When non-empty, only the listed fields are hashed and
IgnoreStatusChanges is ignored. Use this when you need to react to a
specific field without being sensitive to every other change on the object.
items:
type: string
type: array
required:
- identifier
- resource
type: object
type: array
x-kubernetes-list-map-keys:
- identifier
x-kubernetes-list-type: map
tier:
default: 100
description: |-
Tier controls the order of deployment for ClusterProfile or Profile resources targeting
the same cluster resources.
Imagine two configurations (ClusterProfiles or Profiles) trying to deploy the same resource (a Kubernetes
resource or an helm chart). By default, the first one to reach the cluster "wins" and deploys it.
Tier allows you to override this. When conflicts arise, the ClusterProfile or Profile with the **lowest**
Tier value takes priority and deploys the resource.
Higher Tier values represent lower priority. The default Tier value is 100.
Using Tiers provides finer control over resource deployment within your cluster, particularly useful
when multiple configurations manage the same resources.
format: int32
minimum: 1
type: integer
validateHealths:
description: |-
ValidateHealths is a slice of checks to run against the managed cluster
*after* resources are deployed to validate that the state of the
add-ons/applications is healthy.
Each check can select resources and validate them using Lua scripts or CEL expressions.
items:
properties:
evaluateCEL:
description: |-
EvaluateCEL contains a list of named CEL (Common Expression Language) rules.
Each rule will be evaluated in order against each object selected based on
the criteria defined above. Each rule's expression must return a boolean value
indicating whether the object is a match.
Evaluation stops at the first rule that returns true; subsequent
rules will not be evaluated.
items:
description: CELRule defines a named CEL rule used in EvaluateCEL.
properties:
name:
description: Name is a human-readable identifier for the
rule.
type: string
rule:
description: |-
Rule is the CEL (Common Expression Language) expression to evaluate.
It must return a bool
type: string
required:
- name
- rule
type: object
type: array
featureID:
description: |-
FeatureID is an identifier of the feature (Helm/Kustomize/Resources)
This field indicates when to run this check.
For instance:
- if set to Helm this check will be run after all helm
charts specified in the ClusterProfile are deployed.
- if set to Resources this check will be run after the content
of all the ConfigMaps/Secrets referenced by ClusterProfile in the
PolicyRef sections is deployed
enum:
- Resources
- Helm
- Kustomize
type: string
group:
description: |-
Group of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
jobCheck:
description: |-
JobCheck runs a Job in the managed cluster and uses its Complete/Failed
outcome as the check result. Mutually exclusive with Script and EvaluateCEL.
properties:
jobRef:
description: |-
JobRef references the Secret/ConfigMap containing the Job manifest to
deploy in the managed Cluster as this check.
properties:
kind:
description: 'Kind of the resource. Supported kinds
are: Secrets and ConfigMaps.'
enum:
- Secret
- ConfigMap
type: string
name:
description: Name of the referenced resource.
minLength: 1
type: string
namespace:
description: |-
Namespace of the referenced resource.
Namespace can be left empty. In such a case, namespace will
be implicit set to cluster's namespace.
type: string
required:
- kind
- name
- namespace
type: object
timeout:
description: |-
Timeout is how long to wait for the Job to reach Complete or Failed
before treating the check as failed. Defaults to 5 minutes when unset.
type: string
required:
- jobRef
type: object
kind:
description: |-
Kind of the resource to fetch in the managed Cluster.
Leave empty for metric-only checks.
type: string
labelFilters:
description: LabelFilters allows to filter resources based on
current labels.
items:
properties:
key:
description: Key is the label key
type: string
operation:
description: Operation is the comparison operation
enum:
- Equal
- Different
- Has
- DoesNotHave
type: string
value:
description: Value is the label value
type: string
required:
- key
- operation
type: object
type: array
metricQueries:
description: |-
MetricQueries lists the PromQL instant queries to execute against
MetricSource. Results are injected into the evaluation script as a
"metrics" map keyed by each query's Name field, value is the scalar
float result. Scripts access results via metrics["<name>"].
items:
description: |-
MetricQuery binds a PromQL instant-query result to a name the evaluation
script can reference via the metrics table (e.g. metrics["errorRate"]).
properties:
name:
description: |-
Name is the key under which the scalar result is available in the script.
Must be unique within the ValidateHealth entry.
minLength: 1
type: string
query:
description: Query is a PromQL instant-query expression.
minLength: 1
type: string
required:
- name
- query
type: object
type: array
metricSource:
description: |-
MetricSource identifies the Prometheus-compatible endpoint to query.
Required when MetricQueries is set.
properties:
path:
description: |-
Path is the HTTP path for Prometheus instant queries.
Defaults to /api/v1/query when empty.
type: string
secretRef:
description: |-
SecretRef optionally references a Secret on the managed cluster containing
credentials to authenticate against the endpoint.
The Secret namespace and name must both be specified.
Supported keys: "token" (bearer token), "username" and "password" (basic auth).
properties:
name:
description: name is unique within a namespace to reference
a secret resource.
type: string
namespace:
description: namespace defines the space within which
the secret name must be unique.
type: string
type: object
x-kubernetes-map-type: atomic
url:
description: |-
URL is the base HTTP(S) address of the Prometheus-compatible endpoint
(e.g. http://prometheus.monitoring.svc:9090).
minLength: 1
type: string
required:
- url
type: object
name:
description: Name is the name of this check
type: string
namespace:
description: |-
Namespace of the resource to fetch in the managed Cluster.
Empty for resources scoped at cluster level.
type: string
script:
description: |-
Script is a text containing a lua script.
Must return struct with field "health"
representing whether object is a match (true or false)
type: string
version:
description: |-
Version of the resource to fetch in the managed Cluster.
Required when Kind is set. Leave empty for metric-only checks.
type: string
required:
- featureID
- name
type: object
x-kubernetes-validations:
- message: jobCheck cannot be set together with script or evaluateCEL
rule: '!has(self.jobCheck) || (!has(self.script) && !has(self.evaluateCEL))'
type: array
x-kubernetes-list-type: atomic
type: object
status:
description: Status defines the observed state of ClusterProfile/Profile
properties:
dependenciesHash:
description: |-
DependenciesHash is a hash representing the set of clusters where this ClusterProfile
must be deployed, based on the combined configuration of its dependencies.
format: byte
type: string
failedClusters:
description: |-
FailedClusters contains information about clusters for which
a ClusterSummary could not be created or updated.
items:
description: |-
FailedCluster describes an error encountered while trying to
manage resources for a specific matching cluster.
properties:
clusterRef:
description: ClusterRef is a reference to the cluster where
the failure occurred.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
failureMessage:
description: |-
FailureMessage is a human-readable explanation of why the
ClusterSummary creation/update failed.
type: string
lastFailureTime:
description: LastFailureTime is the time the error occurred.
format: date-time
type: string
required:
- clusterRef
- failureMessage
type: object
type: array
matchingClusters:
description: |-
MatchingClusterRefs reference all the clusters currently matching
ClusterProfile ClusterSelector
items:
description: ObjectReference contains enough information to let
you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
reconciliationSuspended:
description: |-
ReconciliationSuspended indicates whether the reconciliation loop for this
ClusterSummary is currently paused due to an external action (e.g., a user annotation).
When true, the status will not be updated unless the pause is lifted.
type: boolean
suspensionReason:
description: SuspensionReason provides a brief explanation of why
the reconciliation is suspended.
type: string
updatedClusters:
description: |-
UpdatedClusters contains information all the cluster currently matching
ClusterProfile ClusterSelector and already updated to latest ClusterProfile
Spec
properties:
clusters:
description: |-
Clusters reference all the clusters currently matching
ClusterProfile ClusterSelector and already updated/being updated
to ClusterProfile Spec
items:
description: ObjectReference contains enough information to
let you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
hash:
description: |-
Hash represents of a unique value for ClusterProfile Spec at
a fixed point in time
format: byte
type: string
type: object
updatingClusters:
description: |-
UpdatingClusters reference all the cluster currently matching
ClusterProfile ClusterSelector and being updated
properties:
clusters:
description: |-
Clusters reference all the clusters currently matching
ClusterProfile ClusterSelector and already updated/being updated
to ClusterProfile Spec
items:
description: ObjectReference contains enough information to
let you inspect or modify the referred object.
properties:
apiVersion:
description: API version of the referent.
type: string
fieldPath:
description: |-
If referring to a piece of an object instead of an entire object, this string
should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2].
For example, if the object reference is to a container within a pod, this would take on a value like:
"spec.containers{name}" (where "name" refers to the name of the container that triggered
the event) or if no container name is specified "spec.containers[2]" (container with
index 2 in this pod). This syntax is chosen only to have some well-defined way of
referencing a part of an object.
type: string
kind:
description: |-
Kind of the referent.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: |-
Name of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
namespace:
description: |-
Namespace of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/
type: string
resourceVersion:
description: |-
Specific resourceVersion to which this reference is made, if any.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
uid:
description: |-
UID of the referent.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids
type: string
type: object
x-kubernetes-map-type: atomic
type: array
hash:
description: |-
Hash represents of a unique value for ClusterProfile Spec at
a fixed point in time
format: byte
type: string
type: object
type: object
type: object
served: true
storage: true
subresources:
status: {}
`)
var ProfileFile = "../../config/crd/bases/config.projectsveltos.io_profiles.yaml"
Functions ¶
func GetClusterConfigurationCRDYAML ¶
func GetClusterConfigurationCRDYAML() []byte
func GetClusterProfileCRDYAML ¶
func GetClusterProfileCRDYAML() []byte
func GetClusterPromotionCRDYAML ¶
func GetClusterPromotionCRDYAML() []byte
func GetClusterReportCRDYAML ¶
func GetClusterReportCRDYAML() []byte
func GetClusterSummaryCRDYAML ¶
func GetClusterSummaryCRDYAML() []byte
func GetProfileCRDYAML ¶
func GetProfileCRDYAML() []byte
Types ¶
This section is empty.