--- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.17.3 name: bucketaccesses.ceph.unkin.net spec: group: ceph.unkin.net names: kind: BucketAccess listKind: BucketAccessList plural: bucketaccesses shortNames: - ba singular: bucketaccess scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.bucketRef name: Bucket type: string - jsonPath: .spec.level name: Level type: string - jsonPath: .status.uid name: UID type: string - jsonPath: .status.phase name: Phase type: string name: v1alpha1 schema: openAPIV3Schema: description: |- BucketAccess grants an RGW user read-only, read-write or full access to a Bucket via the bucket's S3 policy. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: |- BucketAccessSpec grants an RGW user a level of access to a Bucket by maintaining a statement in the bucket's S3 policy. If UserRef is empty the operator provisions a dedicated user for this grant and writes its keys into a Secret; otherwise it grants an existing ObjectStoreUser. properties: actions: description: |- Actions optionally overrides the S3 actions granted by Level. When set, exactly these actions are granted, on the bucket and its (optionally prefixed) objects. Ignored when RawStatements is set. items: type: string type: array bucketRef: description: BucketRef names the Bucket (in this namespace) to grant access to. type: string conditions: description: |- Conditions optionally restricts when the grant applies (e.g. source IPs, TLS required). Ignored when RawStatements is set. properties: secureTransportOnly: description: |- SecureTransportOnly requires the request to use TLS, via the S3 aws:SecureTransport condition. type: boolean sourceIPs: description: |- SourceIPs restricts the grant to requests from these CIDRs (or single addresses), via the S3 aws:SourceIp condition. items: type: string type: array type: object level: description: Level is the access level to grant. enum: - read-only - read-write - full type: string paths: description: |- Paths optionally scopes object-level access to these key prefixes within the bucket; each becomes the resource "/*". Empty grants the whole bucket. The bucket-level ListBucket action always applies to the whole bucket. Ignored when RawStatements is set. items: type: string type: array rawStatements: description: |- RawStatements is an escape hatch for arbitrary S3 policy statements, merged into the bucket policy for this grant's principal. When set, Level, Actions, Paths and Conditions on this object are ignored; the operator only fills in the Principal (this grant's user) when a statement omits one. items: description: |- PolicyStatement is a raw S3 bucket-policy statement, exposed for grants that need control beyond Level/Actions/Paths/Conditions. properties: actions: description: Actions are the S3 actions the statement covers (e.g. s3:GetObject). items: type: string type: array conditions: additionalProperties: additionalProperties: items: type: string type: array type: object description: |- Conditions is the raw S3 condition block: operator -> condition key -> values, e.g. {"IpAddress": {"aws:SourceIp": ["10.0.0.0/8"]}}. type: object effect: default: Allow description: Effect is Allow or Deny. Defaults to Allow. enum: - Allow - Deny type: string resources: description: |- Resources are S3 resource ARNs, or bucket-relative key prefixes when they do not start with "arn:". Empty means the whole bucket and its objects. items: type: string type: array sid: description: Sid is an optional statement id. The operator derives one when empty. type: string required: - actions type: object type: array retainOnDelete: description: |- RetainOnDelete keeps the dedicated RGW user (created when UserRef is empty) instead of deleting it when this BucketAccess is removed. Ignored when UserRef is set (that user is never managed here). Defaults to false. type: boolean secretName: description: |- SecretName is the Secret the operator writes credentials into for the dedicated user it creates (UserRef empty). Defaults to "-rgw". type: string uid: description: |- UID overrides the id of the dedicated user created when UserRef is empty. Defaults to "-". Ignored when UserRef is set. type: string userRef: description: |- UserRef optionally names an existing ObjectStoreUser (in this namespace) to grant. When set, the operator does not create or delete a user and SecretName is ignored (that user already owns its own credential Secret). type: string required: - bucketRef - level type: object status: description: BucketAccessStatus reports observed grant state. properties: bound: description: Bound reports whether the grant is reflected in the bucket policy. type: boolean conditions: items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array x-kubernetes-list-map-keys: - type x-kubernetes-list-type: map observedGeneration: format: int64 type: integer phase: description: Phase is a coarse lifecycle summary (Pending/Ready/Error). type: string secretName: description: SecretName is the Secret holding the dedicated user's credentials, if any. type: string uid: description: UID is the RGW user id that was granted access. type: string type: object type: object served: true storage: true subresources: status: {}