-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathkilo.squat.ai_clustermeshes.yaml
More file actions
224 lines (224 loc) · 10.3 KB
/
Copy pathkilo.squat.ai_clustermeshes.yaml
File metadata and controls
224 lines (224 loc) · 10.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
annotations:
controller-gen.kubebuilder.io/version: v0.20.1
name: clustermeshes.kilo.squat.ai
spec:
group: kilo.squat.ai
names:
kind: ClusterMesh
listKind: ClusterMeshList
plural: clustermeshes
shortNames:
- cm
singular: clustermesh
scope: Namespaced
versions:
- additionalPrinterColumns:
- jsonPath: .status.conditions[?(@.type=='Ready')].status
name: Ready
type: string
- jsonPath: .metadata.creationTimestamp
name: Age
type: date
name: v1alpha1
schema:
openAPIV3Schema:
description: ClusterMesh is the Schema for the clustermeshes API.
properties:
apiVersion:
description: |-
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: |-
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
type: object
spec:
description: spec defines the desired state of ClusterMesh.
properties:
clusters:
description: Clusters is the list of clusters to connect in this mesh.
items:
description: ClusterEntry describes a single cluster participating
in the mesh.
properties:
allowedNetworks:
description: |-
AllowedNetworks is the flat list of every CIDR this cluster contributes
to the mesh: pod CIDRs, the WireGuard (kilo0) CIDR, the service CIDR,
host-network ranges, external subnets, and so on. There is no typed
distinction between them — both validation and Peer construction treat
every entry uniformly. A node is eligible when its PodCIDR is a subset
of some entry and its kilo.squat.ai/wireguard-ip host IP falls within
some entry; entries that have no per-node representative (e.g. the
service CIDR or host-network ranges) are advertised via the anchor Peer.
Multiple entries support dual-stack (IPv4 + IPv6).
items:
type: string
minItems: 1
type: array
kubeconfigSecretRef:
description: |-
KubeconfigSecretRef references a Secret containing the kubeconfig
for this cluster. Required for non-local clusters.
properties:
key:
description: Key within the Secret data.
type: string
name:
description: Name of the Secret.
type: string
required:
- key
- name
type: object
local:
description: |-
Local indicates this is the cluster where the controller runs.
Exactly one cluster in the mesh must be marked as local.
No kubeconfigSecretRef is needed for the local cluster.
type: boolean
name:
description: |-
Name is a unique identifier for this cluster within the mesh.
Used as label value and status key. Must be a valid DNS-1123 label.
maxLength: 63
pattern: ^[a-z0-9]([a-z0-9\-]{0,61}[a-z0-9])?$
type: string
persistentKeepalive:
description: |-
PersistentKeepalive is the interval in seconds at which WireGuard
sends keepalive packets to peers in this cluster. Set to a non-zero
value (e.g. 25) for clusters behind NAT so that the stateful NAT
mapping is refreshed before it expires, enabling bidirectional traffic
even when the cluster has no directly-routable public IP.
0 disables persistent keepalive (default).
maximum: 65535
minimum: 0
type: integer
wireguardPort:
default: 51820
description: |-
WireguardPort is the UDP port of Kilo's WireGuard endpoint on each node in
this cluster. Used as a fallback when the operator synthesises the
endpoint from Node.Status.Addresses (i.e. neither
kilo.squat.ai/clustermesh-endpoint nor kilo.squat.ai/force-endpoint is set
on a node). Defaults to 51820.
maximum: 65535
minimum: 1
type: integer
required:
- allowedNetworks
- name
type: object
minItems: 2
type: array
required:
- clusters
type: object
status:
description: status defines the observed state of ClusterMesh.
properties:
clusters:
description: Clusters contains per-cluster status information.
items:
description: ClusterStatus holds the observed state for a single
cluster in the mesh.
properties:
name:
description: Name matches ClusterEntry.Name.
type: string
registeredPeers:
description: RegisteredPeers is the number of Peer objects created
for this cluster's nodes.
type: integer
skippedNodes:
description: SkippedNodes is the number of nodes that failed
validation and were not peered.
type: integer
required:
- name
- registeredPeers
- skippedNodes
type: object
type: array
conditions:
description: Conditions represent the latest available observations.
items:
description: Condition contains details for one aspect of the current
state of this API Resource.
properties:
lastTransitionTime:
description: |-
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format: date-time
type: string
message:
description: |-
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength: 32768
type: string
observedGeneration:
description: |-
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format: int64
minimum: 0
type: integer
reason:
description: |-
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
type: string
status:
description: status of the condition, one of True, False, Unknown.
enum:
- "True"
- "False"
- Unknown
type: string
type:
description: type of condition in CamelCase or in foo.example.com/CamelCase.
maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
type: string
required:
- lastTransitionTime
- message
- reason
- status
- type
type: object
type: array
x-kubernetes-list-map-keys:
- type
x-kubernetes-list-type: map
type: object
required:
- spec
type: object
served: true
storage: true
subresources:
status: {}