diff --git a/core/go.mod b/core/go.mod index fa99fd92..fba831b8 100644 --- a/core/go.mod +++ b/core/go.mod @@ -49,9 +49,9 @@ require ( golang.org/x/crypto v0.55.0 google.golang.org/grpc v1.83.2 google.golang.org/protobuf v1.36.12 - k8s.io/api v0.36.4 - k8s.io/apimachinery v0.36.4 - k8s.io/client-go v0.36.4 + k8s.io/api v0.37.0 + k8s.io/apimachinery v0.37.0 + k8s.io/client-go v0.37.0 sigs.k8s.io/controller-runtime v0.24.1 sigs.k8s.io/yaml v1.6.0 ) @@ -201,7 +201,7 @@ require ( k8s.io/apiextensions-apiserver v0.36.2 // indirect k8s.io/klog/v2 v2.140.0 // indirect k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad // indirect - k8s.io/streaming v0.36.4 // indirect + k8s.io/streaming v0.37.0 // indirect k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect sigs.k8s.io/randfill v1.0.0 // indirect diff --git a/core/go.sum b/core/go.sum index 376055cd..abf42d3c 100644 --- a/core/go.sum +++ b/core/go.sum @@ -460,20 +460,20 @@ gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -k8s.io/api v0.36.4 h1:RxrvqCL6vgH5/+UnTeu1IIFqYmGfy0hnyrod1rn35Oo= -k8s.io/api v0.36.4/go.mod h1:S2B3orCFBDhrgyWbLeuKcT2QdHIpQesBkCYSlWtwUOw= +k8s.io/api v0.37.0 h1:Z//Vj9N7RA/yS2sDmxyeo7h+RR4zbUrd2vrd3Z0TbB4= +k8s.io/api v0.37.0/go.mod h1:LKXgcJWMc+f4OLbP5SFR8rulEg07zZhpi/zMULiBImk= k8s.io/apiextensions-apiserver v0.36.2 h1:3O5gqOj/dt2XWWbpMe+TXWpE9yU6pjM/tXxtHHJT/K4= k8s.io/apiextensions-apiserver v0.36.2/go.mod h1:cL1tBWe8XSaP1H30iWKGo7hf6iAUUUJPEU70dskmAnA= -k8s.io/apimachinery v0.36.4 h1:PT2UzkupGuAx/+xT5XjiMJ1WGpY3fn9/hdAvjweRet4= -k8s.io/apimachinery v0.36.4/go.mod h1:p2I2dipt7JHG+quVwQ1d02d28O4GdDi77RByQ13MTpk= -k8s.io/client-go v0.36.4 h1:MDvfDNvMSt0Br94SK8neviVlwL9qifw9B26hJCpD1K0= -k8s.io/client-go v0.36.4/go.mod h1:pNK4WKELbwlEDvtbE8l22lEZL5THYF61H5EealokZmA= +k8s.io/apimachinery v0.37.0 h1:Np2AbDtf8x6RDHiD8T9LbKJ9gaegeVNa8yNm5FuGKm0= +k8s.io/apimachinery v0.37.0/go.mod h1:RN3nhprFSCxOi5Selxd7oMTXOe/c+ZbcE7Im+TS2zkE= +k8s.io/client-go v0.37.0 h1:nsN31fy8wBySuZ+QRnKmrjRSQLOG2rvoGN0tKd12zhQ= +k8s.io/client-go v0.37.0/go.mod h1:FcGqw+Ll/gNQiq+nPGY1Oyt9y7SgDh1d3MW3RFDEbn0= k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc= k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0= k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad h1:oXImqH8mQNk7PmvzKhmN3ddJoY6OnyM225MXwGHPm0A= k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad/go.mod h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I= -k8s.io/streaming v0.36.4 h1:RS5YlhrdBN2pKGVjgygGntdu6SNdsduyjGWGe3cX0vo= -k8s.io/streaming v0.36.4/go.mod h1:tJ6S2bZa2HxIBauguBbCWSCYyd93Grfz1+z3tcOvlDE= +k8s.io/streaming v0.37.0 h1:iPBUZLZiKt5bV+lxJurASMOV07VuBhNpiwJt2//AWrM= +k8s.io/streaming v0.37.0/go.mod h1:APlJR26ZWRcVy5bIEj0QRrKUXROtBHPcxl2NT7EAzPU= k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 h1:jVkFFVfXdXP74B/zbO3hM3hpSFD0xvhQ5U686DPurkE= k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3/go.mod h1:M2s5JB1lIYP3jzZdorPLHXIPJzt9vv2muW5a6L9DtNM= sigs.k8s.io/controller-runtime v0.24.1 h1:miPEwrmirImAvgME1L9qebGHrOnGJoVmVdtOU9fRfo4= diff --git a/operator/config/crd/bases/klio.cnpg.io_pluginconfigurations.yaml b/operator/config/crd/bases/klio.cnpg.io_pluginconfigurations.yaml index 830fbbc1..87f7a846 100644 --- a/operator/config/crd/bases/klio.cnpg.io_pluginconfigurations.yaml +++ b/operator/config/crd/bases/klio.cnpg.io_pluginconfigurations.yaml @@ -128,7 +128,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -398,6 +400,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -511,6 +518,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -593,6 +605,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -650,6 +669,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -805,6 +829,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -862,6 +893,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1315,6 +1351,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -1372,6 +1415,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1511,10 +1559,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume + should be mounted. type: string mountPropagation: description: |- diff --git a/operator/config/crd/bases/klio.cnpg.io_servers.yaml b/operator/config/crd/bases/klio.cnpg.io_servers.yaml index 2242fec1..6274b0fd 100644 --- a/operator/config/crd/bases/klio.cnpg.io_servers.yaml +++ b/operator/config/crd/bases/klio.cnpg.io_servers.yaml @@ -107,8 +107,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -151,7 +151,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -1316,7 +1315,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1591,6 +1592,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1705,6 +1711,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1787,6 +1798,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -1845,6 +1863,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2002,6 +2025,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2060,6 +2090,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2515,6 +2550,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2573,6 +2615,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2714,10 +2761,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: + bindMountOptions: + description: |- + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set mountPath: - description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -2929,7 +2987,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3201,6 +3261,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3315,6 +3380,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3393,6 +3463,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3451,6 +3528,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3596,6 +3678,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3654,6 +3743,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4078,6 +4172,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -4136,6 +4237,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4286,10 +4392,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: + bindMountOptions: + description: |- + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set mountPath: - description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -4361,6 +4478,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4431,7 +4605,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4538,7 +4711,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4813,6 +4988,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4927,6 +5107,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5009,6 +5194,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5067,6 +5259,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5224,6 +5421,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5282,6 +5486,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5737,6 +5946,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5795,6 +6011,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5936,10 +6157,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: + bindMountOptions: + description: |- + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set mountPath: - description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -6093,6 +6325,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6437,11 +6671,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -7061,6 +7292,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -7094,6 +7332,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7181,6 +7426,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -7249,6 +7501,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7267,6 +7526,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7360,8 +7631,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7406,7 +7677,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7975,6 +8245,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -8075,6 +8352,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8115,6 +8399,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8214,6 +8505,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8321,6 +8619,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -8380,6 +8685,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8427,6 +8739,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8633,6 +8952,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8666,6 +8992,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8796,8 +9129,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8840,7 +9173,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9001,8 +9333,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -9045,7 +9377,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9409,6 +9740,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -9442,6 +9780,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9529,6 +9874,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -9599,6 +9951,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9617,6 +9976,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -9710,8 +10081,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -9756,7 +10127,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -10321,6 +10691,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -10421,6 +10798,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -10462,6 +10846,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -10563,6 +10954,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -10670,6 +11068,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -10730,6 +11135,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -10779,6 +11191,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -10986,6 +11405,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -11019,6 +11445,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -11350,6 +11783,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -11383,6 +11823,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -11470,6 +11917,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -11540,6 +11994,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -11558,6 +12019,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -11651,8 +12124,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -11697,7 +12170,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -12262,6 +12734,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -12362,6 +12841,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -12403,6 +12889,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -12504,6 +12997,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -12611,6 +13111,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -12671,6 +13178,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -12720,6 +13234,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -12927,6 +13448,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -12960,6 +13488,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -13096,8 +13631,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -13140,7 +13675,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -13504,6 +14038,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -13537,6 +14078,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -13624,6 +14172,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -13694,6 +14249,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -13712,6 +14274,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -13805,8 +14379,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -13851,7 +14425,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -14416,6 +14989,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -14516,6 +15096,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -14557,6 +15144,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -14658,6 +15252,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -14765,6 +15366,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -14825,6 +15433,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -14874,6 +15489,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15081,6 +15703,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -15114,6 +15743,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -15445,6 +16081,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -15478,6 +16121,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -15565,6 +16215,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -15635,6 +16292,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15653,6 +16317,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -15746,8 +16422,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -15792,7 +16468,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -16357,6 +17032,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -16457,6 +17139,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16498,6 +17187,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -16599,6 +17295,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16706,6 +17409,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -16766,6 +17476,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -16815,6 +17532,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -17022,6 +17746,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -17055,6 +17786,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/operator/dist/chart/crds/pluginconfiguration-crd.yaml b/operator/dist/chart/crds/pluginconfiguration-crd.yaml index 3b2e1408..b7303d7d 100644 --- a/operator/dist/chart/crds/pluginconfiguration-crd.yaml +++ b/operator/dist/chart/crds/pluginconfiguration-crd.yaml @@ -127,7 +127,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -397,6 +399,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -510,6 +517,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -592,6 +604,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -649,6 +668,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -804,6 +828,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -861,6 +892,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1314,6 +1350,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -1371,6 +1414,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1510,10 +1558,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume + should be mounted. type: string mountPropagation: description: |- diff --git a/operator/dist/chart/crds/server-crd.yaml b/operator/dist/chart/crds/server-crd.yaml index 627c8976..3aadb6d7 100644 --- a/operator/dist/chart/crds/server-crd.yaml +++ b/operator/dist/chart/crds/server-crd.yaml @@ -106,8 +106,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -150,7 +150,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -1315,7 +1314,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1590,6 +1591,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1704,6 +1710,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1786,6 +1797,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -1844,6 +1862,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2001,6 +2024,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2059,6 +2089,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2514,6 +2549,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2572,6 +2614,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2713,10 +2760,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: + bindMountOptions: + description: |- + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set mountPath: - description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -2928,7 +2986,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3200,6 +3260,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3314,6 +3379,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3392,6 +3462,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3450,6 +3527,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3595,6 +3677,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3653,6 +3742,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4077,6 +4171,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -4135,6 +4236,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4285,10 +4391,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: + bindMountOptions: + description: |- + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set mountPath: - description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -4360,6 +4477,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4430,7 +4604,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4537,7 +4710,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4812,6 +4987,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4926,6 +5106,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5008,6 +5193,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5066,6 +5258,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5223,6 +5420,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5281,6 +5485,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5736,6 +5945,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5794,6 +6010,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5935,10 +6156,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: + bindMountOptions: + description: |- + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set mountPath: - description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -6092,6 +6324,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6436,11 +6670,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -7060,6 +7291,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -7093,6 +7331,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7180,6 +7425,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -7248,6 +7500,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7266,6 +7525,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7359,8 +7630,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7405,7 +7676,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7974,6 +8244,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -8074,6 +8351,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8114,6 +8398,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8213,6 +8504,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8320,6 +8618,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -8379,6 +8684,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8426,6 +8738,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8632,6 +8951,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8665,6 +8991,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8795,8 +9128,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8839,7 +9172,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9000,8 +9332,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -9044,7 +9376,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9408,6 +9739,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -9441,6 +9779,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9528,6 +9873,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -9598,6 +9950,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9616,6 +9975,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -9709,8 +10080,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -9755,7 +10126,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -10320,6 +10690,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -10420,6 +10797,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -10461,6 +10845,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -10562,6 +10953,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -10669,6 +11067,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -10729,6 +11134,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -10778,6 +11190,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -10985,6 +11404,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -11018,6 +11444,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -11349,6 +11782,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -11382,6 +11822,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -11469,6 +11916,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -11539,6 +11993,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -11557,6 +12018,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -11650,8 +12123,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -11696,7 +12169,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -12261,6 +12733,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -12361,6 +12840,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -12402,6 +12888,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -12503,6 +12996,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -12610,6 +13110,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -12670,6 +13177,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -12719,6 +13233,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -12926,6 +13447,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -12959,6 +13487,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -13095,8 +13630,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -13139,7 +13674,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -13503,6 +14037,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -13536,6 +14077,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -13623,6 +14171,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -13693,6 +14248,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -13711,6 +14273,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -13804,8 +14378,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -13850,7 +14424,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -14415,6 +14988,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -14515,6 +15095,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -14556,6 +15143,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -14657,6 +15251,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -14764,6 +15365,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -14824,6 +15432,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -14873,6 +15488,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15080,6 +15702,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -15113,6 +15742,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -15444,6 +16080,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -15477,6 +16120,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -15564,6 +16214,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -15634,6 +16291,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15652,6 +16316,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -15745,8 +16421,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -15791,7 +16467,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -16356,6 +17031,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -16456,6 +17138,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16497,6 +17186,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -16598,6 +17294,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16705,6 +17408,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -16765,6 +17475,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -16814,6 +17531,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -17021,6 +17745,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -17054,6 +17785,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/operator/go.mod b/operator/go.mod index e0c1e0fd..ffe6466b 100644 --- a/operator/go.mod +++ b/operator/go.mod @@ -31,9 +31,9 @@ require ( go.opentelemetry.io/otel/sdk/metric v1.46.0 golang.org/x/sync v0.22.0 google.golang.org/grpc v1.83.2 - k8s.io/api v0.36.4 - k8s.io/apimachinery v0.36.4 - k8s.io/client-go v0.36.4 + k8s.io/api v0.37.0 + k8s.io/apimachinery v0.37.0 + k8s.io/client-go v0.37.0 sigs.k8s.io/controller-runtime v0.24.1 sigs.k8s.io/e2e-framework v0.7.0 sigs.k8s.io/yaml v1.6.0 @@ -189,7 +189,7 @@ require ( k8s.io/component-base v0.36.2 // indirect k8s.io/klog/v2 v2.140.0 // indirect k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad // indirect - k8s.io/streaming v0.36.4 // indirect + k8s.io/streaming v0.37.0 // indirect k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 // indirect sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 // indirect sigs.k8s.io/gateway-api v1.6.0 // indirect diff --git a/operator/go.sum b/operator/go.sum index f326faea..8a8a149c 100644 --- a/operator/go.sum +++ b/operator/go.sum @@ -431,24 +431,24 @@ gopkg.in/inf.v0 v0.9.1/go.mod h1:cWUDdTG/fYaXco+Dcufb5Vnc6Gp2YChqWtbxRZE0mXw= gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -k8s.io/api v0.36.4 h1:RxrvqCL6vgH5/+UnTeu1IIFqYmGfy0hnyrod1rn35Oo= -k8s.io/api v0.36.4/go.mod h1:S2B3orCFBDhrgyWbLeuKcT2QdHIpQesBkCYSlWtwUOw= +k8s.io/api v0.37.0 h1:Z//Vj9N7RA/yS2sDmxyeo7h+RR4zbUrd2vrd3Z0TbB4= +k8s.io/api v0.37.0/go.mod h1:LKXgcJWMc+f4OLbP5SFR8rulEg07zZhpi/zMULiBImk= k8s.io/apiextensions-apiserver v0.36.2 h1:3O5gqOj/dt2XWWbpMe+TXWpE9yU6pjM/tXxtHHJT/K4= k8s.io/apiextensions-apiserver v0.36.2/go.mod h1:cL1tBWe8XSaP1H30iWKGo7hf6iAUUUJPEU70dskmAnA= -k8s.io/apimachinery v0.36.4 h1:PT2UzkupGuAx/+xT5XjiMJ1WGpY3fn9/hdAvjweRet4= -k8s.io/apimachinery v0.36.4/go.mod h1:p2I2dipt7JHG+quVwQ1d02d28O4GdDi77RByQ13MTpk= +k8s.io/apimachinery v0.37.0 h1:Np2AbDtf8x6RDHiD8T9LbKJ9gaegeVNa8yNm5FuGKm0= +k8s.io/apimachinery v0.37.0/go.mod h1:RN3nhprFSCxOi5Selxd7oMTXOe/c+ZbcE7Im+TS2zkE= k8s.io/apiserver v0.36.2 h1:6vMnkmHZPeBloNkHUhmZYq7Ylv8WIB8xjyEl+eSt26E= k8s.io/apiserver v0.36.2/go.mod h1:9PoQ2ikCytrZyZg11mGhLEF5m8Rgsb5FJmYJ4Wvnl1k= -k8s.io/client-go v0.36.4 h1:MDvfDNvMSt0Br94SK8neviVlwL9qifw9B26hJCpD1K0= -k8s.io/client-go v0.36.4/go.mod h1:pNK4WKELbwlEDvtbE8l22lEZL5THYF61H5EealokZmA= +k8s.io/client-go v0.37.0 h1:nsN31fy8wBySuZ+QRnKmrjRSQLOG2rvoGN0tKd12zhQ= +k8s.io/client-go v0.37.0/go.mod h1:FcGqw+Ll/gNQiq+nPGY1Oyt9y7SgDh1d3MW3RFDEbn0= k8s.io/component-base v0.36.2 h1:Z0VH80O7Ng0HDZnZj3WRR3urEGa0kTwmO8CwEwjVK1w= k8s.io/component-base v0.36.2/go.mod h1:mGfFOA7Gwpdm1VW2cwSQYbiDIlz8GD2WGwH88QSeCyA= k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc= k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0= k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad h1:oXImqH8mQNk7PmvzKhmN3ddJoY6OnyM225MXwGHPm0A= k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad/go.mod h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I= -k8s.io/streaming v0.36.4 h1:RS5YlhrdBN2pKGVjgygGntdu6SNdsduyjGWGe3cX0vo= -k8s.io/streaming v0.36.4/go.mod h1:tJ6S2bZa2HxIBauguBbCWSCYyd93Grfz1+z3tcOvlDE= +k8s.io/streaming v0.37.0 h1:iPBUZLZiKt5bV+lxJurASMOV07VuBhNpiwJt2//AWrM= +k8s.io/streaming v0.37.0/go.mod h1:APlJR26ZWRcVy5bIEj0QRrKUXROtBHPcxl2NT7EAzPU= k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 h1:jVkFFVfXdXP74B/zbO3hM3hpSFD0xvhQ5U686DPurkE= k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3/go.mod h1:M2s5JB1lIYP3jzZdorPLHXIPJzt9vv2muW5a6L9DtNM= sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.34.0 h1:hSfpvjjTQXQY2Fol2CS0QHMNs/WI1MOSGzCm1KhM5ec=