c1e2f7390c
The external-dns → in-cluster bind migration needs external-dns to present the exact TSIG key that the in-cluster bind-externaldns primary accepts on allow-update. The operator generates that key into Secret externaldns-key-tsig in bind-internal; reflecting it removes the manual eyaml→Vault key sync. - Add spec.secretTemplate.annotations to BindTSIGKey externaldns-key with the emberstack reflector hints (reflection-allowed, allowed/auto-namespaces externaldns, auto-enabled) so the operator stamps them onto the managed Secret. - Regenerate schemas/bind.unkin.net/bindtsigkey_v1alpha1.json from the live CRD (deployed bind-operator v0.2.4 already exposes secretTemplate) to add the secretTemplate property.
131 lines
3.1 KiB
JSON
131 lines
3.1 KiB
JSON
{
|
|
"$schema": "http://json-schema.org/draft-07/schema#",
|
|
"properties": {
|
|
"apiVersion": {
|
|
"type": "string"
|
|
},
|
|
"kind": {
|
|
"type": "string"
|
|
},
|
|
"metadata": {
|
|
"type": "object"
|
|
},
|
|
"spec": {
|
|
"properties": {
|
|
"algorithm": {
|
|
"default": "hmac-sha256",
|
|
"enum": [
|
|
"hmac-sha256",
|
|
"hmac-sha512",
|
|
"hmac-sha384",
|
|
"hmac-sha224",
|
|
"hmac-sha1",
|
|
"hmac-md5"
|
|
],
|
|
"type": "string"
|
|
},
|
|
"clusterRef": {
|
|
"type": "string"
|
|
},
|
|
"importExisting": {
|
|
"type": "boolean"
|
|
},
|
|
"keyName": {
|
|
"type": "string"
|
|
},
|
|
"secretName": {
|
|
"type": "string"
|
|
},
|
|
"secretTemplate": {
|
|
"properties": {
|
|
"annotations": {
|
|
"additionalProperties": {
|
|
"type": "string"
|
|
},
|
|
"type": "object"
|
|
},
|
|
"labels": {
|
|
"additionalProperties": {
|
|
"type": "string"
|
|
},
|
|
"type": "object"
|
|
}
|
|
},
|
|
"type": "object"
|
|
}
|
|
},
|
|
"type": "object"
|
|
},
|
|
"status": {
|
|
"properties": {
|
|
"conditions": {
|
|
"items": {
|
|
"properties": {
|
|
"lastTransitionTime": {
|
|
"format": "date-time",
|
|
"type": "string"
|
|
},
|
|
"message": {
|
|
"maxLength": 32768,
|
|
"type": "string"
|
|
},
|
|
"observedGeneration": {
|
|
"format": "int64",
|
|
"minimum": 0,
|
|
"type": "integer"
|
|
},
|
|
"reason": {
|
|
"maxLength": 1024,
|
|
"minLength": 1,
|
|
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
|
"type": "string"
|
|
},
|
|
"status": {
|
|
"enum": [
|
|
"True",
|
|
"False",
|
|
"Unknown"
|
|
],
|
|
"type": "string"
|
|
},
|
|
"type": {
|
|
"maxLength": 316,
|
|
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
|
"type": "string"
|
|
}
|
|
},
|
|
"required": [
|
|
"lastTransitionTime",
|
|
"message",
|
|
"reason",
|
|
"status",
|
|
"type"
|
|
],
|
|
"type": "object"
|
|
},
|
|
"type": "array",
|
|
"x-kubernetes-list-map-keys": [
|
|
"type"
|
|
],
|
|
"x-kubernetes-list-type": "map"
|
|
},
|
|
"keyName": {
|
|
"type": "string"
|
|
},
|
|
"observedGeneration": {
|
|
"format": "int64",
|
|
"type": "integer"
|
|
},
|
|
"ready": {
|
|
"type": "boolean"
|
|
},
|
|
"secretName": {
|
|
"type": "string"
|
|
}
|
|
},
|
|
"type": "object"
|
|
}
|
|
},
|
|
"type": "object"
|
|
}
|