4.7 KiB
API Reference
Packages
irsa.kkb0318.github.io/v1alpha1
Package v1alpha1 contains API Schema definitions for the irsa v1alpha1 API group
Resource Types
Auth
Auth holds the authentication configuration details.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
secretRef SecretRef |
SecretRef specifies the reference to the Kubernetes secret containing authentication details. |
Discovery
Discovery holds the configuration for IdP Discovery, which is crucial for locating the OIDC provider in a self-hosted environment.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
s3 S3Discovery |
S3 specifies the AWS S3 bucket details where the OIDC provider's discovery information is hosted. |
IRSA
IRSA is the Schema for the irsas API
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
irsa.kkb0318.github.io/v1alpha1 |
||
kind string |
IRSA |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec IRSASpec |
IRSAServiceAccount
IRSAServiceAccount represents the details of the Kubernetes service account
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
Name represents the name of the Kubernetes service account | ||
namespaces string array |
Namespaces represents the list of namespaces where the service account is used |
IRSASetup
IRSASetup represents a configuration for setting up IAM Roles for Service Accounts (IRSA) in a Kubernetes cluster.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
irsa.kkb0318.github.io/v1alpha1 |
||
kind string |
IRSASetup |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec IRSASetupSpec |
IRSASetupSpec
IRSASetupSpec defines the desired state of IRSASetup
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
cleanup boolean |
Cleanup, when enabled, allows the IRSASetup to perform garbage collection of resources that are no longer needed or managed. |
||
mode string |
Mode specifies the mode of operation. Can be either "selfhosted" or "eks". | ||
discovery Discovery |
Discovery configures the IdP Discovery process, essential for setting up IRSA by locating the OIDC provider information. |
||
auth Auth |
Auth contains authentication configuration details. |
IRSASpec
IRSASpec defines the desired state of IRSA
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
serviceAccount IRSAServiceAccount |
ServiceAccount represents the Kubernetes service account associated with the IRSA | ||
iamRole IamRole |
IamRole represents the IAM role details associated with the IRSA | ||
iamPolicies string array |
IamPolicies represents the list of IAM policies to be attached to the IAM role |
IamRole
IamRole represents the IAM role configuration
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
Name represents the name of the IAM role |
S3Discovery
S3Discovery contains the specifics of the S3 bucket used for hosting OIDC provider discovery information.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
region string |
Region denotes the AWS region where the S3 bucket is located. | ||
bucketName string |
BucketName is the name of the S3 bucket that hosts the OIDC discovery information. |
SecretRef
SecretRef contains the reference to a Kubernetes secret.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
Name specifies the name of the secret. | ||
namespace string |
Namespace specifies the namespace of the secret. |