9c81320df8
The operator-generated TSIG Secret previously carried only the managed-by
label, so it could not be mirrored to another namespace by emberstack
reflector (which requires reflection-allowed annotations on the source).
Add spec.secretTemplate.{annotations,labels}, applied both when the Secret
is first generated and reconciled onto the existing Secret when the CR
changes (imported secrets are left untouched so we don't fight their
external manager). This lets the external-dns TSIG key be managed in
bind-internal and reflected into the externaldns namespace.
189 lines
8.0 KiB
YAML
189 lines
8.0 KiB
YAML
---
|
|
apiVersion: apiextensions.k8s.io/v1
|
|
kind: CustomResourceDefinition
|
|
metadata:
|
|
annotations:
|
|
controller-gen.kubebuilder.io/version: v0.17.3
|
|
name: bindtsigkeys.bind.unkin.net
|
|
spec:
|
|
group: bind.unkin.net
|
|
names:
|
|
kind: BindTSIGKey
|
|
listKind: BindTSIGKeyList
|
|
plural: bindtsigkeys
|
|
shortNames:
|
|
- btk
|
|
singular: bindtsigkey
|
|
scope: Namespaced
|
|
versions:
|
|
- additionalPrinterColumns:
|
|
- jsonPath: .spec.algorithm
|
|
name: Algorithm
|
|
type: string
|
|
- jsonPath: .status.secretName
|
|
name: Secret
|
|
type: string
|
|
- jsonPath: .status.ready
|
|
name: Ready
|
|
type: boolean
|
|
name: v1alpha1
|
|
schema:
|
|
openAPIV3Schema:
|
|
description: |-
|
|
BindTSIGKey is a TSIG key backing zone transfers, dynamic updates and view
|
|
matching. The key material lives in a Kubernetes Secret, never in the CR.
|
|
properties:
|
|
apiVersion:
|
|
description: |-
|
|
APIVersion defines the versioned schema of this representation of an object.
|
|
Servers should convert recognized schemas to the latest internal value, and
|
|
may reject unrecognized values.
|
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
kind:
|
|
description: |-
|
|
Kind is a string value representing the REST resource this object represents.
|
|
Servers may infer this from the endpoint the client submits requests to.
|
|
Cannot be updated.
|
|
In CamelCase.
|
|
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
type: object
|
|
spec:
|
|
description: |-
|
|
BindTSIGKeySpec defines a TSIG key. If no existing key material is imported,
|
|
the operator generates a random key and stores it in a Secret.
|
|
properties:
|
|
algorithm:
|
|
default: hmac-sha256
|
|
description: Algorithm is the HMAC algorithm. Defaults to hmac-sha256.
|
|
enum:
|
|
- hmac-sha256
|
|
- hmac-sha512
|
|
- hmac-sha384
|
|
- hmac-sha224
|
|
- hmac-sha1
|
|
- hmac-md5
|
|
type: string
|
|
clusterRef:
|
|
description: |-
|
|
ClusterRef names the BindCluster this key is included in. When empty the
|
|
key is shared with every cluster in the namespace (useful when multiple
|
|
clusters share one namespace).
|
|
type: string
|
|
importExisting:
|
|
description: |-
|
|
ImportExisting, when true, means the referenced Secret already contains a
|
|
`secret` key and the operator will not generate new material.
|
|
type: boolean
|
|
keyName:
|
|
description: |-
|
|
KeyName is the TSIG key name emitted into named.conf. Defaults to the
|
|
object name.
|
|
type: string
|
|
secretName:
|
|
description: |-
|
|
SecretName is the Secret the key material is written to (or read from when
|
|
ImportExisting is set). Defaults to "<name>-tsig".
|
|
type: string
|
|
secretTemplate:
|
|
description: |-
|
|
SecretTemplate customizes metadata written onto the managed key Secret.
|
|
Useful, for example, to let secret-reflection tooling mirror the key into
|
|
another namespace. Operator-managed labels are always preserved.
|
|
properties:
|
|
annotations:
|
|
additionalProperties:
|
|
type: string
|
|
description: Annotations to set on the Secret.
|
|
type: object
|
|
labels:
|
|
additionalProperties:
|
|
type: string
|
|
description: Labels to set on the Secret.
|
|
type: object
|
|
type: object
|
|
type: object
|
|
status:
|
|
description: BindTSIGKeyStatus reports observed TSIG key state.
|
|
properties:
|
|
conditions:
|
|
items:
|
|
description: Condition contains details for one aspect of the current
|
|
state of this API Resource.
|
|
properties:
|
|
lastTransitionTime:
|
|
description: |-
|
|
lastTransitionTime is the last time the condition transitioned from one status to another.
|
|
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
|
|
format: date-time
|
|
type: string
|
|
message:
|
|
description: |-
|
|
message is a human readable message indicating details about the transition.
|
|
This may be an empty string.
|
|
maxLength: 32768
|
|
type: string
|
|
observedGeneration:
|
|
description: |-
|
|
observedGeneration represents the .metadata.generation that the condition was set based upon.
|
|
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
|
|
with respect to the current state of the instance.
|
|
format: int64
|
|
minimum: 0
|
|
type: integer
|
|
reason:
|
|
description: |-
|
|
reason contains a programmatic identifier indicating the reason for the condition's last transition.
|
|
Producers of specific condition types may define expected values and meanings for this field,
|
|
and whether the values are considered a guaranteed API.
|
|
The value should be a CamelCase string.
|
|
This field may not be empty.
|
|
maxLength: 1024
|
|
minLength: 1
|
|
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
|
|
type: string
|
|
status:
|
|
description: status of the condition, one of True, False, Unknown.
|
|
enum:
|
|
- "True"
|
|
- "False"
|
|
- Unknown
|
|
type: string
|
|
type:
|
|
description: type of condition in CamelCase or in foo.example.com/CamelCase.
|
|
maxLength: 316
|
|
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
|
|
type: string
|
|
required:
|
|
- lastTransitionTime
|
|
- message
|
|
- reason
|
|
- status
|
|
- type
|
|
type: object
|
|
type: array
|
|
x-kubernetes-list-map-keys:
|
|
- type
|
|
x-kubernetes-list-type: map
|
|
keyName:
|
|
description: KeyName as used in named.conf.
|
|
type: string
|
|
observedGeneration:
|
|
description: ObservedGeneration is the last reconciled generation.
|
|
format: int64
|
|
type: integer
|
|
ready:
|
|
description: Ready is true once the key Secret exists.
|
|
type: boolean
|
|
secretName:
|
|
description: SecretName holds the generated/managed key material.
|
|
type: string
|
|
type: object
|
|
type: object
|
|
served: true
|
|
storage: true
|
|
subresources:
|
|
status: {}
|