--- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.21.0 name: postgresqltenants.database.ddupan.top spec: group: database.ddupan.top names: kind: PostgreSQLTenant listKind: PostgreSQLTenantList plural: postgresqltenants shortNames: - pgtenant singular: postgresqltenant scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.instanceRef name: Instance type: string - jsonPath: .status.database name: Database type: string - jsonPath: .status.phase name: Phase type: string - jsonPath: .status.credential.secretRef.name name: Secret type: string - jsonPath: .status.conditions[?(@.type=="Ready")].status name: Ready type: string - jsonPath: .metadata.creationTimestamp name: Age type: date name: v1alpha1 schema: openAPIV3Schema: description: PostgreSQLTenant is the Schema for the postgresqltenants API. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: PostgreSQLTenantSpec defines one application database and its login owner. properties: credential: description: Credential configures projection of the application credential. properties: secretName: description: |- SecretName is the target Kubernetes Secret in the Tenant namespace. It semantically defaults to --postgresql. maxLength: 253 pattern: ^[a-z0-9]([-a-z0-9.]*[a-z0-9])?$ type: string type: object database: description: Database is the database to create. It semantically defaults to metadata.name. pattern: ^[a-z][a-z0-9_]{0,62}$ type: string deletionPolicy: default: Retain description: DeletionPolicy controls cleanup when this object is deleted. enum: - Retain - Delete type: string extensions: description: |- Extensions is the set to install from the referenced Instance allowlist. Once provisioned, this set may only grow. items: type: string type: array x-kubernetes-list-type: set instanceRef: description: InstanceRef names the cluster-scoped PostgreSQLInstance to use. maxLength: 253 minLength: 1 pattern: ^[a-z0-9]([-a-z0-9.]*[a-z0-9])?$ type: string loginRole: description: |- LoginRole is both the database owner and application login. It semantically defaults to metadata.name. pattern: ^[a-z][a-z0-9_]{0,62}$ type: string required: - instanceRef type: object status: description: PostgreSQLTenantStatus defines the observed state of PostgreSQLTenant. properties: conditions: description: Conditions contains the current Ready condition and any future auxiliary conditions. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array x-kubernetes-list-map-keys: - type x-kubernetes-list-type: map credential: description: Credential identifies the projected Secret and the non-authenticated OpenBao API URL. properties: openBaoURL: description: |- OpenBaoURL is the complete KV v2 data API URL for non-Kubernetes consumers. It contains no token or credential value. type: string secretRef: description: SecretRef identifies the target Secret in the Tenant namespace. properties: name: description: Name is the Secret name. type: string type: object type: object database: description: Database is the effective database name after applying semantic defaults. type: string databaseOID: description: DatabaseOID is the observed PostgreSQL object identifier for diagnostics. format: int32 type: integer loginRole: description: LoginRole is the effective owner/login role after applying semantic defaults. type: string observedGeneration: description: ObservedGeneration is the most recent generation for which reconciliation reached a conclusion. format: int64 type: integer phase: description: |- Phase is the authoritative checkpoint of the controller workflow. External state is still read back before and after every operation. enum: - Pending - Planned - CredentialCreated - RoleCreated - DatabaseCreated - ExternalSecretCreated - CredentialProjected - Ready - Deleting type: string type: object required: - metadata - spec type: object x-kubernetes-validations: - message: instanceRef and metadata.name are too long to derive the ExternalSecret name rule: size(self.spec.instanceRef) + size(self.metadata.name) <= 241 served: true storage: true subresources: status: {}