Files
irsa-manager/docs/api.md
T

4.7 KiB

API Reference

Packages

irsa.kkb0318.github.io/v1alpha1

Package v1alpha1 contains API Schema definitions for the irsa v1alpha1 API group

Resource Types

Auth

Auth holds the authentication configuration details.

Appears in:

Field Description Default Validation
secretRef SecretRef SecretRef specifies the reference to the Kubernetes secret containing authentication details.

Discovery

Discovery holds the configuration for IdP Discovery, which is crucial for locating the OIDC provider in a self-hosted environment.

Appears in:

Field Description Default Validation
s3 S3Discovery S3 specifies the AWS S3 bucket details where the OIDC provider's discovery information is hosted.

IRSA

IRSA is the Schema for the irsas API

Field Description Default Validation
apiVersion string irsa.kkb0318.github.io/v1alpha1
kind string IRSA
metadata ObjectMeta Refer to Kubernetes API documentation for fields of metadata.
spec IRSASpec

IRSAServiceAccount

IRSAServiceAccount represents the details of the Kubernetes service account

Appears in:

Field Description Default Validation
name string Name represents the name of the Kubernetes service account
namespaces string array Namespaces represents the list of namespaces where the service account is used

IRSASetup

IRSASetup represents a configuration for setting up IAM Roles for Service Accounts (IRSA) in a Kubernetes cluster.

Field Description Default Validation
apiVersion string irsa.kkb0318.github.io/v1alpha1
kind string IRSASetup
metadata ObjectMeta Refer to Kubernetes API documentation for fields of metadata.
spec IRSASetupSpec

IRSASetupSpec

IRSASetupSpec defines the desired state of IRSASetup

Appears in:

Field Description Default Validation
cleanup boolean Cleanup, when enabled, allows the IRSASetup to perform garbage collection
of resources that are no longer needed or managed.
mode string Mode specifies the mode of operation. Can be either "selfhosted" or "eks".
discovery Discovery Discovery configures the IdP Discovery process, essential for setting up IRSA by locating
the OIDC provider information.
auth Auth Auth contains authentication configuration details.

IRSASpec

IRSASpec defines the desired state of IRSA

Appears in:

Field Description Default Validation
serviceAccount IRSAServiceAccount ServiceAccount represents the Kubernetes service account associated with the IRSA
iamRole IamRole IamRole represents the IAM role details associated with the IRSA
iamPolicies string array IamPolicies represents the list of IAM policies to be attached to the IAM role

IamRole

IamRole represents the IAM role configuration

Appears in:

Field Description Default Validation
name string Name represents the name of the IAM role

S3Discovery

S3Discovery contains the specifics of the S3 bucket used for hosting OIDC provider discovery information.

Appears in:

Field Description Default Validation
region string Region denotes the AWS region where the S3 bucket is located.
bucketName string BucketName is the name of the S3 bucket that hosts the OIDC discovery information.

SecretRef

SecretRef contains the reference to a Kubernetes secret.

Appears in:

Field Description Default Validation
name string Name specifies the name of the secret.
namespace string Namespace specifies the namespace of the secret.