--- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.22.0 name: postgresqldatabases.database.ayatori.ddupan.top spec: group: database.ayatori.ddupan.top names: kind: PostgreSQLDatabase listKind: PostgreSQLDatabaseList plural: postgresqldatabases singular: postgresqldatabase scope: Cluster versions: - additionalPrinterColumns: - jsonPath: .spec.instanceRef.name name: Instance type: string - jsonPath: .spec.database name: Database type: string - jsonPath: .status.conditions[?(@.type=='Ready')].status name: Ready type: string name: v1alpha1 schema: openAPIV3Schema: properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: PostgreSQLDatabaseSpec 是一库、一个 login owner 及凭据的独立资源声明。 properties: credentialRef: description: |- CredentialReference 定位已有 OpenBao KV v2 凭据,不包含任何秘密值。 只由资源管理员在导入时填写;controller 必须检查部署允许的 mount/path 范围。 properties: mount: maxLength: 253 minLength: 1 type: string path: description: Path 是 mount 内的逻辑路径,不含 KV v2 的 data/ API 前缀。 maxLength: 1024 minLength: 1 type: string required: - mount - path type: object database: description: PostgreSQLIdentifier 是第一版受管 database 与 login role 使用的名称。 maxLength: 63 pattern: ^[a-z][a-z0-9_]{0,62}$ type: string instanceRef: description: InstanceReference 仅引用同 API group 的集群级 PostgreSQLInstance。 properties: name: description: ObjectName 定位集群级资源,不携带 namespace 或隐式跨 API group 引用。 maxLength: 253 minLength: 1 pattern: ^[a-z0-9]([-a-z0-9.]*[a-z0-9])?$ type: string required: - name type: object loginRole: description: PostgreSQLIdentifier 是第一版受管 database 与 login role 使用的名称。 maxLength: 63 pattern: ^[a-z][a-z0-9_]{0,62}$ type: string reclaimPolicy: default: Retain description: ReclaimPolicy 控制资源释放后的处置,只有资源管理者可以修改。 enum: - Retain - Delete type: string source: description: Source 明确区分创建与只读导入,不从后端同名对象推断。 enum: - Provision - Import type: string tenantRef: description: TenantRef 由 controller 先写入;Released 时仍保留旧身份。 properties: name: description: ObjectName 定位集群级资源,不携带 namespace 或隐式跨 API group 引用。 maxLength: 253 minLength: 1 pattern: ^[a-z0-9]([-a-z0-9.]*[a-z0-9])?$ type: string namespace: maxLength: 63 minLength: 1 pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$ type: string uid: description: |- UID is a type that holds unique ID values, including UUIDs. Because we don't ONLY use UUIDs, this is an alias to string. Being a type captures intent and helps make sure that UIDs and names do not get conflated. maxLength: 128 minLength: 1 type: string required: - name - namespace - uid type: object required: - database - instanceRef - loginRole - source type: object x-kubernetes-validations: - message: only imported databases require an existing credentialRef rule: (self.source == 'Import') == has(self.credentialRef) status: properties: conditions: items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array x-kubernetes-list-map-keys: - type x-kubernetes-list-type: map instanceUID: description: InstanceUID 记录观察时的实例身份,不把同名新实例视为原目标。 type: string observedGeneration: format: int64 type: integer phase: description: Phase 暂不冻结供应子阶段枚举;它不是操作授权或绑定的替代记录。 type: string type: object required: - spec type: object x-kubernetes-validations: - message: managed database target cannot change after observation or binding starts rule: '!(has(oldSelf.spec.tenantRef) || (has(oldSelf.status) && has(oldSelf.status.instanceUID))) || (self.spec.instanceRef == oldSelf.spec.instanceRef && self.spec.database == oldSelf.spec.database && self.spec.loginRole == oldSelf.spec.loginRole && self.spec.source == oldSelf.spec.source && has(self.spec.credentialRef) == has(oldSelf.spec.credentialRef) && (!has(oldSelf.spec.credentialRef) || self.spec.credentialRef == oldSelf.spec.credentialRef))' served: true storage: true subresources: status: {}