Allow Dev CRDs Schema¶
Note
This is auto-generated documentation from a JSON schema that is under construction, this will improve over time.
Return to the root config schema
https://raw.githubusercontent.com/elastisys/compliantkubernetes-apps/main/config/schemas/config.yaml#/properties/gatekeeper/properties/allowUserCRDs
Configure access to Custom Resource Definitions for application developers.
Abstract | Extensible | Status | Identifiable | Custom Properties | Additional Properties | Access Restrictions | Defined In |
---|---|---|---|---|---|---|---|
Can be instantiated | No | Unknown status | No | Forbidden | Forbidden | none | config/schemas/config.yaml* |
TYPE:
object
(Allow Dev CRDs)
PROPERTIES:
Property | Type | Required | Nullable | Defined by |
---|---|---|---|---|
enabled | boolean |
Optional | cannot be null | Welkin Apps Config |
enforcement | string |
Optional | cannot be null | Welkin Apps Config |
adminConfUser | string |
Optional | cannot be null | Welkin Apps Config |
extraCRDs | array |
Optional | cannot be null | Welkin Apps Config |
extraServiceAccounts | array |
Optional | cannot be null | Welkin Apps Config |
enabled¶
enabled
-
is optional
-
Type:
boolean
(Dev CRDs Enabled) -
cannot be null
-
defined in: Welkin Apps Config
TYPE:
boolean
(Dev CRDs Enabled)
enforcement¶
enforcement
-
is optional
-
Type:
string
(Dev CRDs Enforcement) -
cannot be null
-
defined in: Welkin Apps Config
TYPE:
string
(Dev CRDs Enforcement)
CONSTRAINTS:
enum: the value of this property must be equal to one of the following values:
Value | Explanation |
---|---|
"deny" |
Deny actions violating the constraint. |
"warn" |
Warn actions violating the constraint. |
"dryrun" |
Dryrun actions violating the constraint. |
DEFAULTS:
The default value is:
"deny"
adminConfUser¶
Configure the admin config user of the /etc/kubernetes/admin.conf
found on the control plane nodes.
This is necessary if Kubespray is used for managing the cluster.
adminConfUser
-
is optional
-
Type:
string
(Dev CRDs Admin Config User) -
cannot be null
-
defined in: Welkin Apps Config
TYPE:
string
(Dev CRDs Admin Config User)
DEFAULTS:
The default value is:
"kubernetes-admin"
extraCRDs¶
Configure extra CRDs to allow for application developers.
extraCRDs
-
is optional
-
Type:
object[]
(Dev CRDs Extra CRDs) -
cannot be null
-
defined in: Welkin Apps Config
TYPE:
object[]
(Dev CRDs Extra CRDs)
extraServiceAccounts¶
Configure extra service accounts to allow access to configured CRDs.
extraServiceAccounts
-
is optional
-
Type:
object[]
(Dev CRDs Extra Service Account) -
cannot be null
-
defined in: Welkin Apps Config
TYPE:
object[]
(Dev CRDs Extra Service Account)
EXAMPLES:
- namespace: example-namespace
name: example-controller
Return to the root config schema
Generated Sun Nov 17 03:51:36 UTC 2024 from elastisys/compliantkubernetes-apps@main