mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
fix(k8-operator): common types support
This commit is contained in:
@@ -261,7 +261,7 @@ func (in *InfisicalDynamicSecret) DeepCopyInto(out *InfisicalDynamicSecret) {
|
|||||||
*out = *in
|
*out = *in
|
||||||
out.TypeMeta = in.TypeMeta
|
out.TypeMeta = in.TypeMeta
|
||||||
in.ObjectMeta.DeepCopyInto(&out.ObjectMeta)
|
in.ObjectMeta.DeepCopyInto(&out.ObjectMeta)
|
||||||
out.Spec = in.Spec
|
in.Spec.DeepCopyInto(&out.Spec)
|
||||||
in.Status.DeepCopyInto(&out.Status)
|
in.Status.DeepCopyInto(&out.Status)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -335,7 +335,7 @@ func (in *InfisicalDynamicSecretList) DeepCopyObject() runtime.Object {
|
|||||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||||
func (in *InfisicalDynamicSecretSpec) DeepCopyInto(out *InfisicalDynamicSecretSpec) {
|
func (in *InfisicalDynamicSecretSpec) DeepCopyInto(out *InfisicalDynamicSecretSpec) {
|
||||||
*out = *in
|
*out = *in
|
||||||
out.ManagedSecretReference = in.ManagedSecretReference
|
in.ManagedSecretReference.DeepCopyInto(&out.ManagedSecretReference)
|
||||||
out.Authentication = in.Authentication
|
out.Authentication = in.Authentication
|
||||||
out.DynamicSecret = in.DynamicSecret
|
out.DynamicSecret = in.DynamicSecret
|
||||||
out.TLS = in.TLS
|
out.TLS = in.TLS
|
||||||
|
|||||||
@@ -152,6 +152,20 @@ spec:
|
|||||||
description: 'The Kubernetes Secret type (experimental feature).
|
description: 'The Kubernetes Secret type (experimental feature).
|
||||||
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
|
||||||
type: string
|
type: string
|
||||||
|
template:
|
||||||
|
description: The template to transform the secret data
|
||||||
|
properties:
|
||||||
|
data:
|
||||||
|
additionalProperties:
|
||||||
|
type: string
|
||||||
|
description: The template key values
|
||||||
|
type: object
|
||||||
|
includeAllSecrets:
|
||||||
|
description: This injects all retrieved secrets into the top
|
||||||
|
level of your template. Secrets defined in the template
|
||||||
|
will take precedence over the injected ones.
|
||||||
|
type: boolean
|
||||||
|
type: object
|
||||||
required:
|
required:
|
||||||
- secretName
|
- secretName
|
||||||
- secretNamespace
|
- secretNamespace
|
||||||
|
|||||||
@@ -90,7 +90,6 @@ spec:
|
|||||||
- serviceAccountRef
|
- serviceAccountRef
|
||||||
type: object
|
type: object
|
||||||
universalAuth:
|
universalAuth:
|
||||||
description: PushSecretUniversalAuth defines universal authentication
|
|
||||||
properties:
|
properties:
|
||||||
credentialsRef:
|
credentialsRef:
|
||||||
properties:
|
properties:
|
||||||
@@ -191,239 +190,74 @@ spec:
|
|||||||
`json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\"
|
`json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\"
|
||||||
protobuf:\"bytes,1,rep,name=conditions\"` \n // other fields }"
|
protobuf:\"bytes,1,rep,name=conditions\"` \n // other fields }"
|
||||||
properties:
|
properties:
|
||||||
awsIamAuth:
|
lastTransitionTime:
|
||||||
properties:
|
description: lastTransitionTime is the last time the condition
|
||||||
identityId:
|
transitioned from one status to another. This should be when
|
||||||
type: string
|
the underlying condition changed. If that is not known, then
|
||||||
required:
|
using the time when the API field changed is acceptable.
|
||||||
- identityId
|
format: date-time
|
||||||
type: object
|
|
||||||
azureAuth:
|
|
||||||
properties:
|
|
||||||
identityId:
|
|
||||||
type: string
|
|
||||||
resource:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- identityId
|
|
||||||
type: object
|
|
||||||
gcpIamAuth:
|
|
||||||
properties:
|
|
||||||
identityId:
|
|
||||||
type: string
|
|
||||||
serviceAccountKeyFilePath:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- identityId
|
|
||||||
- serviceAccountKeyFilePath
|
|
||||||
type: object
|
|
||||||
gcpIdTokenAuth:
|
|
||||||
properties:
|
|
||||||
identityId:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- identityId
|
|
||||||
type: object
|
|
||||||
kubernetesAuth:
|
|
||||||
description: Rest of your types should be defined similarly...
|
|
||||||
properties:
|
|
||||||
identityId:
|
|
||||||
type: string
|
|
||||||
serviceAccountRef:
|
|
||||||
properties:
|
|
||||||
name:
|
|
||||||
type: string
|
|
||||||
namespace:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- name
|
|
||||||
- namespace
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- identityId
|
|
||||||
- serviceAccountRef
|
|
||||||
type: object
|
|
||||||
universalAuth:
|
|
||||||
description: PushSecretUniversalAuth defines universal authentication
|
|
||||||
properties:
|
|
||||||
credentialsRef:
|
|
||||||
properties:
|
|
||||||
secretName:
|
|
||||||
description: The name of the Kubernetes Secret
|
|
||||||
type: string
|
|
||||||
secretNamespace:
|
|
||||||
description:
|
|
||||||
The name space where the Kubernetes Secret
|
|
||||||
is located
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- secretName
|
|
||||||
- secretNamespace
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- credentialsRef
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
deletionPolicy:
|
|
||||||
type: string
|
|
||||||
destination:
|
|
||||||
properties:
|
|
||||||
EnvironmentSlug:
|
|
||||||
type: string
|
type: string
|
||||||
projectId:
|
message:
|
||||||
|
description: message is a human readable message indicating
|
||||||
|
details about the transition. This may be an empty string.
|
||||||
|
maxLength: 32768
|
||||||
type: string
|
type: string
|
||||||
secretsPath:
|
observedGeneration:
|
||||||
|
description: observedGeneration represents the .metadata.generation
|
||||||
|
that the condition was set based upon. For instance, if .metadata.generation
|
||||||
|
is currently 12, but the .status.conditions[x].observedGeneration
|
||||||
|
is 9, the condition is out of date with respect to the current
|
||||||
|
state of the instance.
|
||||||
|
format: int64
|
||||||
|
minimum: 0
|
||||||
|
type: integer
|
||||||
|
reason:
|
||||||
|
description: reason contains a programmatic identifier indicating
|
||||||
|
the reason for the condition's last transition. Producers
|
||||||
|
of specific condition types may define expected values and
|
||||||
|
meanings for this field, and whether the values are considered
|
||||||
|
a guaranteed API. The value should be a CamelCase string.
|
||||||
|
This field may not be empty.
|
||||||
|
maxLength: 1024
|
||||||
|
minLength: 1
|
||||||
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
||||||
|
type: string
|
||||||
|
status:
|
||||||
|
description: status of the condition, one of True, False, Unknown.
|
||||||
|
enum:
|
||||||
|
- "True"
|
||||||
|
- "False"
|
||||||
|
- Unknown
|
||||||
|
type: string
|
||||||
|
type:
|
||||||
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
||||||
|
--- Many .condition.type values are consistent across resources
|
||||||
|
like Available, but because arbitrary conditions can be useful
|
||||||
|
(see .node.status.conditions), the ability to deconflict is
|
||||||
|
important. The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
|
||||||
|
maxLength: 316
|
||||||
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
||||||
type: string
|
type: string
|
||||||
required:
|
required:
|
||||||
- EnvironmentSlug
|
- lastTransitionTime
|
||||||
- projectId
|
- message
|
||||||
- secretsPath
|
- reason
|
||||||
|
- status
|
||||||
|
- type
|
||||||
type: object
|
type: object
|
||||||
hostAPI:
|
type: array
|
||||||
description: Infisical host to pull secrets from
|
managedSecrets:
|
||||||
|
additionalProperties:
|
||||||
type: string
|
type: string
|
||||||
push:
|
description: managed secrets is a map where the key is the ID, and
|
||||||
properties:
|
the value is the secret key (string[id], string[key] )
|
||||||
secret:
|
type: object
|
||||||
properties:
|
required:
|
||||||
secretName:
|
- conditions
|
||||||
description: The name of the Kubernetes Secret
|
- managedSecrets
|
||||||
type: string
|
type: object
|
||||||
secretNamespace:
|
type: object
|
||||||
description:
|
served: true
|
||||||
The name space where the Kubernetes Secret is
|
storage: true
|
||||||
located
|
subresources:
|
||||||
type: string
|
status: {}
|
||||||
required:
|
|
||||||
- secretName
|
|
||||||
- secretNamespace
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- secret
|
|
||||||
type: object
|
|
||||||
resyncInterval:
|
|
||||||
type: string
|
|
||||||
tls:
|
|
||||||
properties:
|
|
||||||
caRef:
|
|
||||||
description: Reference to secret containing CA cert
|
|
||||||
properties:
|
|
||||||
key:
|
|
||||||
description:
|
|
||||||
The name of the secret property with the CA certificate
|
|
||||||
value
|
|
||||||
type: string
|
|
||||||
secretName:
|
|
||||||
description: The name of the Kubernetes Secret
|
|
||||||
type: string
|
|
||||||
secretNamespace:
|
|
||||||
description:
|
|
||||||
The namespace where the Kubernetes Secret is
|
|
||||||
located
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- key
|
|
||||||
- secretName
|
|
||||||
- secretNamespace
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
updatePolicy:
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- destination
|
|
||||||
- push
|
|
||||||
- resyncInterval
|
|
||||||
type: object
|
|
||||||
status:
|
|
||||||
description: InfisicalPushSecretStatus defines the observed state of InfisicalPushSecret
|
|
||||||
properties:
|
|
||||||
conditions:
|
|
||||||
items:
|
|
||||||
description:
|
|
||||||
"Condition contains details for one aspect of the current
|
|
||||||
state of this API Resource. --- This struct is intended for direct
|
|
||||||
use as an array at the field path .status.conditions. For example,
|
|
||||||
\n type FooStatus struct{ // Represents the observations of a
|
|
||||||
foo's current state. // Known .status.conditions.type are: \"Available\",
|
|
||||||
\"Progressing\", and \"Degraded\" // +patchMergeKey=type // +patchStrategy=merge
|
|
||||||
// +listType=map // +listMapKey=type Conditions []metav1.Condition
|
|
||||||
`json:\"conditions,omitempty\" patchStrategy:\"merge\" patchMergeKey:\"type\"
|
|
||||||
protobuf:\"bytes,1,rep,name=conditions\"` \n // other fields }"
|
|
||||||
properties:
|
|
||||||
lastTransitionTime:
|
|
||||||
description:
|
|
||||||
lastTransitionTime is the last time the condition
|
|
||||||
transitioned from one status to another. This should be when
|
|
||||||
the underlying condition changed. If that is not known, then
|
|
||||||
using the time when the API field changed is acceptable.
|
|
||||||
format: date-time
|
|
||||||
type: string
|
|
||||||
message:
|
|
||||||
description:
|
|
||||||
message is a human readable message indicating
|
|
||||||
details about the transition. This may be an empty string.
|
|
||||||
maxLength: 32768
|
|
||||||
type: string
|
|
||||||
observedGeneration:
|
|
||||||
description:
|
|
||||||
observedGeneration represents the .metadata.generation
|
|
||||||
that the condition was set based upon. For instance, if .metadata.generation
|
|
||||||
is currently 12, but the .status.conditions[x].observedGeneration
|
|
||||||
is 9, the condition is out of date with respect to the current
|
|
||||||
state of the instance.
|
|
||||||
format: int64
|
|
||||||
minimum: 0
|
|
||||||
type: integer
|
|
||||||
reason:
|
|
||||||
description:
|
|
||||||
reason contains a programmatic identifier indicating
|
|
||||||
the reason for the condition's last transition. Producers
|
|
||||||
of specific condition types may define expected values and
|
|
||||||
meanings for this field, and whether the values are considered
|
|
||||||
a guaranteed API. The value should be a CamelCase string.
|
|
||||||
This field may not be empty.
|
|
||||||
maxLength: 1024
|
|
||||||
minLength: 1
|
|
||||||
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
|
||||||
type: string
|
|
||||||
status:
|
|
||||||
description: status of the condition, one of True, False, Unknown.
|
|
||||||
enum:
|
|
||||||
- "True"
|
|
||||||
- "False"
|
|
||||||
- Unknown
|
|
||||||
type: string
|
|
||||||
type:
|
|
||||||
description:
|
|
||||||
type of condition in CamelCase or in foo.example.com/CamelCase.
|
|
||||||
--- Many .condition.type values are consistent across resources
|
|
||||||
like Available, but because arbitrary conditions can be useful
|
|
||||||
(see .node.status.conditions), the ability to deconflict is
|
|
||||||
important. The regex it matches is (dns1123SubdomainFmt/)?(qualifiedNameFmt)
|
|
||||||
maxLength: 316
|
|
||||||
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
|
||||||
type: string
|
|
||||||
required:
|
|
||||||
- lastTransitionTime
|
|
||||||
- message
|
|
||||||
- reason
|
|
||||||
- status
|
|
||||||
- type
|
|
||||||
type: object
|
|
||||||
type: array
|
|
||||||
managedSecrets:
|
|
||||||
additionalProperties:
|
|
||||||
type: string
|
|
||||||
description:
|
|
||||||
managed secrets is a map where the key is the ID, and
|
|
||||||
the value is the secret key (string[id], string[key] )
|
|
||||||
type: object
|
|
||||||
required:
|
|
||||||
- conditions
|
|
||||||
- managedSecrets
|
|
||||||
type: object
|
|
||||||
type: object
|
|
||||||
served: true
|
|
||||||
storage: true
|
|
||||||
subresources:
|
|
||||||
status: {}
|
|
||||||
|
|||||||
Reference in New Issue
Block a user