-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathcrds.yaml
More file actions
711 lines (703 loc) · 35.1 KB
/
Copy pathcrds.yaml
File metadata and controls
711 lines (703 loc) · 35.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: authenticationclasses.authentication.stackable.tech
spec:
group: authentication.stackable.tech
names:
categories: []
kind: AuthenticationClass
plural: authenticationclasses
shortNames: []
singular: authenticationclass
scope: Cluster
versions:
- additionalPrinterColumns: []
name: v1alpha1
schema:
openAPIV3Schema:
description: Auto-generated derived type for AuthenticationClassSpec via `CustomResource`
properties:
spec:
description: |-
The Stackable Platform uses the AuthenticationClass as a central mechanism to handle user
authentication across supported products.
The authentication mechanism needs to be configured only in the AuthenticationClass which is
then referenced in the product. Multiple different authentication providers are supported.
Learn more in the [authentication concept documentation][1] and the
[Authentication with OpenLDAP tutorial][2].
[1]: https://docs.stackable.tech/home/26.3/concepts/authentication
[2]: https://docs.stackable.tech/home/26.3/tutorials/authentication_with_openldap
properties:
provider:
description: Provider used for authentication like LDAP or Kerberos.
oneOf:
- required:
- static
- required:
- ldap
- required:
- oidc
- required:
- tls
- required:
- kerberos
properties:
kerberos:
description: |-
The [Kerberos provider](https://docs.stackable.tech/home/26.3/concepts/authentication#_kerberos).
The Kerberos AuthenticationClass is used when users should authenticate themselves via
Kerberos.
properties:
kerberosSecretClass:
description: Mandatory SecretClass used to obtain keytabs.
type: string
required:
- kerberosSecretClass
type: object
ldap:
description: |-
The [LDAP provider](https://docs.stackable.tech/home/26.3/concepts/authentication#_ldap).
There is also the ["Authentication with LDAP" tutorial](https://docs.stackable.tech/home/26.3/tutorials/authentication_with_openldap)
where you can learn to configure Superset and Trino with OpenLDAP.
properties:
bindCredentials:
description: In case you need a special account for searching the LDAP server you can specify it here.
nullable: true
properties:
scope:
description: |-
[Scope](https://docs.stackable.tech/home/26.3/secret-operator/scope) of the
[SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass).
nullable: true
properties:
listenerVolumes:
default: []
description: |-
The listener volume scope allows Node and Service scopes to be inferred from the applicable listeners.
This must correspond to Volume names in the Pod that mount Listeners.
items:
type: string
type: array
node:
default: false
description: |-
The node scope is resolved to the name of the Kubernetes Node object that the Pod is running on.
This will typically be the DNS name of the node.
type: boolean
pod:
default: false
description: |-
The pod scope is resolved to the name of the Kubernetes Pod.
This allows the secret to differentiate between StatefulSet replicas.
type: boolean
services:
default: []
description: |-
The service scope allows Pod objects to specify custom scopes.
This should typically correspond to Service objects that the Pod participates in.
items:
type: string
type: array
type: object
secretClass:
description: '[SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass) containing the LDAP bind credentials.'
type: string
required:
- secretClass
type: object
hostname:
description: 'Host of the LDAP server, for example: `my.ldap.server` or `127.0.0.1`.'
type: string
ldapFieldNames:
default:
email: mail
givenName: givenName
group: memberof
surname: sn
uid: uid
description: The name of the LDAP object fields.
properties:
email:
default: mail
description: The name of the email field
type: string
givenName:
default: givenName
description: The name of the firstname field
type: string
group:
default: memberof
description: The name of the group field
type: string
surname:
default: sn
description: The name of the lastname field
type: string
uid:
default: uid
description: The name of the username field
type: string
type: object
port:
description: Port of the LDAP server. If TLS is used defaults to 636 otherwise to 389.
format: uint16
maximum: 65535.0
minimum: 0.0
nullable: true
type: integer
searchBase:
default: ''
description: 'LDAP search base, for example: `ou=users,dc=example,dc=org`.'
type: string
searchFilter:
default: ''
description: 'LDAP query to filter users, for example: `(memberOf=cn=myTeam,ou=teams,dc=example,dc=org)`.'
type: string
tls:
description: Use a TLS connection. If not specified no TLS will be used.
nullable: true
properties:
verification:
description: The verification method used to verify the certificates of the server and/or the client.
oneOf:
- required:
- none
- required:
- server
properties:
none:
description: Use TLS but don't verify certificates.
type: object
server:
description: Use TLS and a CA certificate to verify the server.
properties:
caCert:
description: CA cert to verify the server.
oneOf:
- required:
- webPki
- required:
- secretClass
properties:
secretClass:
description: |-
Name of the [SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass) which will provide the CA certificate.
Note that a SecretClass does not need to have a key but can also work with just a CA certificate,
so if you got provided with a CA cert but don't have access to the key you can still use this method.
type: string
webPki:
description: |-
Use TLS and the CA certificates trusted by the common web browsers to verify the server.
This can be useful when you e.g. use public AWS S3 or other public available services.
type: object
type: object
required:
- caCert
type: object
type: object
required:
- verification
type: object
required:
- hostname
type: object
oidc:
description: The OIDC provider can be used to configure OpenID Connect.
properties:
hostname:
description: Host of the identity provider, e.g. `my.keycloak.corp` or `127.0.0.1`.
type: string
port:
description: |-
Port of the identity provider. If TLS is used defaults to 443,
otherwise to 80.
format: uint16
maximum: 65535.0
minimum: 0.0
nullable: true
type: integer
principalClaim:
description: |-
If a product extracts some sort of "effective user" that is represented by a
string internally, this config determines with claim is used to extract that
string. It is desirable to use `sub` in here (or some other stable identifier),
but in many cases you might need to use `preferred_username` (e.g. in case of Keycloak)
or a different claim instead.
Please note that some products hard-coded the claim in their implementation,
so some product operators might error out if the product hardcodes a different
claim than configured here.
We don't provide any default value, as there is no correct way of doing it
that works in all setups. Most demos will probably use `preferred_username`,
although `sub` being more desirable, but technically impossible with the current
behavior of the products.
type: string
providerHint:
description: |-
This is a hint about which identity provider is used by the
AuthenticationClass. Operators *can* opt to use this
value to enable known quirks around OIDC / OAuth authentication.
Not providing a hint means there is no hint and OIDC should be used as it is
intended to be used (via the `.well-known` discovery).
enum:
- Keycloak
- null
nullable: true
type: string
rootPath:
default: /
description: Root HTTP path of the identity provider. Defaults to `/`.
type: string
scopes:
description: |-
Scopes to request from your identity provider. It is recommended to
request the `openid`, `email`, and `profile` scopes.
items:
type: string
type: array
tls:
description: Use a TLS connection. If not specified no TLS will be used.
nullable: true
properties:
verification:
description: The verification method used to verify the certificates of the server and/or the client.
oneOf:
- required:
- none
- required:
- server
properties:
none:
description: Use TLS but don't verify certificates.
type: object
server:
description: Use TLS and a CA certificate to verify the server.
properties:
caCert:
description: CA cert to verify the server.
oneOf:
- required:
- webPki
- required:
- secretClass
properties:
secretClass:
description: |-
Name of the [SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass) which will provide the CA certificate.
Note that a SecretClass does not need to have a key but can also work with just a CA certificate,
so if you got provided with a CA cert but don't have access to the key you can still use this method.
type: string
webPki:
description: |-
Use TLS and the CA certificates trusted by the common web browsers to verify the server.
This can be useful when you e.g. use public AWS S3 or other public available services.
type: object
type: object
required:
- caCert
type: object
type: object
required:
- verification
type: object
required:
- hostname
- principalClaim
- scopes
type: object
static:
description: |-
The [static provider](https://https://docs.stackable.tech/home/26.3/concepts/authentication#_static)
is used to configure a static set of users, identified by username and password.
properties:
userCredentialsSecret:
description: |-
Secret providing the usernames and passwords.
The Secret must contain an entry for every user, with the key being the username and the value the password in plain text.
It must be located in the same namespace as the product using it.
properties:
name:
description: Name of the Secret.
type: string
required:
- name
type: object
required:
- userCredentialsSecret
type: object
tls:
description: |-
The [TLS provider](https://docs.stackable.tech/home/26.3/concepts/authentication#_tls).
The TLS AuthenticationClass is used when users should authenticate themselves with a
TLS certificate.
properties:
clientCertSecretClass:
description: |-
See [ADR017: TLS authentication](https://docs.stackable.tech/home/26.3/contributor/adr/adr017-tls_authentication).
If `client_cert_secret_class` is not set, the TLS settings may also be used for client authentication.
If `client_cert_secret_class` is set, the [SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass)
will be used to provision client certificates.
nullable: true
type: string
type: object
type: object
required:
- provider
type: object
required:
- spec
title: AuthenticationClass
type: object
served: true
storage: true
subresources: {}
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: s3connections.s3.stackable.tech
spec:
group: s3.stackable.tech
names:
categories: []
kind: S3Connection
plural: s3connections
shortNames: []
singular: s3connection
scope: Namespaced
versions:
- additionalPrinterColumns: []
name: v1alpha1
schema:
openAPIV3Schema:
description: Auto-generated derived type for ConnectionSpec via `CustomResource`
properties:
spec:
description: |-
S3 connection definition as a resource.
Learn more on the [S3 concept documentation](https://docs.stackable.tech/home/26.3/concepts/s3).
properties:
accessStyle:
default: VirtualHosted
description: |-
Which access style to use.
Defaults to virtual hosted-style as most of the data products out there.
Have a look at the [AWS documentation](https://docs.aws.amazon.com/AmazonS3/latest/userguide/VirtualHosting.html).
enum:
- Path
- VirtualHosted
type: string
credentials:
description: |-
If the S3 uses authentication you have to specify you S3 credentials.
In the most cases a [SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass)
providing `accessKey` and `secretKey` is sufficient.
nullable: true
properties:
scope:
description: |-
[Scope](https://docs.stackable.tech/home/26.3/secret-operator/scope) of the
[SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass).
nullable: true
properties:
listenerVolumes:
default: []
description: |-
The listener volume scope allows Node and Service scopes to be inferred from the applicable listeners.
This must correspond to Volume names in the Pod that mount Listeners.
items:
type: string
type: array
node:
default: false
description: |-
The node scope is resolved to the name of the Kubernetes Node object that the Pod is running on.
This will typically be the DNS name of the node.
type: boolean
pod:
default: false
description: |-
The pod scope is resolved to the name of the Kubernetes Pod.
This allows the secret to differentiate between StatefulSet replicas.
type: boolean
services:
default: []
description: |-
The service scope allows Pod objects to specify custom scopes.
This should typically correspond to Service objects that the Pod participates in.
items:
type: string
type: array
type: object
secretClass:
description: '[SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass) containing the LDAP bind credentials.'
type: string
required:
- secretClass
type: object
host:
description: 'Host of the S3 server without any protocol or port. For example: `west1.my-cloud.com`.'
type: string
port:
description: |-
Port the S3 server listens on.
If not specified the product will determine the port to use.
format: uint16
maximum: 65535.0
minimum: 0.0
nullable: true
type: integer
region:
default:
name: us-east-1
description: |-
Bucket region used for signing headers (sigv4).
This defaults to `us-east-1` which is compatible with other implementations such as Minio.
WARNING: Some products use the Hadoop S3 implementation which falls back to us-east-2.
properties:
name:
default: us-east-1
type: string
type: object
tls:
description: Use a TLS connection. If not specified no TLS will be used.
nullable: true
properties:
verification:
description: The verification method used to verify the certificates of the server and/or the client.
oneOf:
- required:
- none
- required:
- server
properties:
none:
description: Use TLS but don't verify certificates.
type: object
server:
description: Use TLS and a CA certificate to verify the server.
properties:
caCert:
description: CA cert to verify the server.
oneOf:
- required:
- webPki
- required:
- secretClass
properties:
secretClass:
description: |-
Name of the [SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass) which will provide the CA certificate.
Note that a SecretClass does not need to have a key but can also work with just a CA certificate,
so if you got provided with a CA cert but don't have access to the key you can still use this method.
type: string
webPki:
description: |-
Use TLS and the CA certificates trusted by the common web browsers to verify the server.
This can be useful when you e.g. use public AWS S3 or other public available services.
type: object
type: object
required:
- caCert
type: object
type: object
required:
- verification
type: object
required:
- host
type: object
required:
- spec
title: S3Connection
type: object
served: true
storage: true
subresources: {}
---
apiVersion: apiextensions.k8s.io/v1
kind: CustomResourceDefinition
metadata:
name: s3buckets.s3.stackable.tech
spec:
group: s3.stackable.tech
names:
categories: []
kind: S3Bucket
plural: s3buckets
shortNames: []
singular: s3bucket
scope: Namespaced
versions:
- additionalPrinterColumns: []
name: v1alpha1
schema:
openAPIV3Schema:
description: Auto-generated derived type for BucketSpec via `CustomResource`
properties:
spec:
description: |-
S3 bucket specification containing the bucket name and an inlined or referenced connection specification.
Learn more on the [S3 concept documentation](https://docs.stackable.tech/home/26.3/concepts/s3).
properties:
bucketName:
description: The name of the S3 bucket.
type: string
connection:
description: The definition of an S3 connection, either inline or as a reference.
oneOf:
- required:
- inline
- required:
- reference
properties:
inline:
description: |-
S3 connection definition as a resource.
Learn more on the [S3 concept documentation](https://docs.stackable.tech/home/26.3/concepts/s3).
properties:
accessStyle:
default: VirtualHosted
description: |-
Which access style to use.
Defaults to virtual hosted-style as most of the data products out there.
Have a look at the [AWS documentation](https://docs.aws.amazon.com/AmazonS3/latest/userguide/VirtualHosting.html).
enum:
- Path
- VirtualHosted
type: string
credentials:
description: |-
If the S3 uses authentication you have to specify you S3 credentials.
In the most cases a [SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass)
providing `accessKey` and `secretKey` is sufficient.
nullable: true
properties:
scope:
description: |-
[Scope](https://docs.stackable.tech/home/26.3/secret-operator/scope) of the
[SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass).
nullable: true
properties:
listenerVolumes:
default: []
description: |-
The listener volume scope allows Node and Service scopes to be inferred from the applicable listeners.
This must correspond to Volume names in the Pod that mount Listeners.
items:
type: string
type: array
node:
default: false
description: |-
The node scope is resolved to the name of the Kubernetes Node object that the Pod is running on.
This will typically be the DNS name of the node.
type: boolean
pod:
default: false
description: |-
The pod scope is resolved to the name of the Kubernetes Pod.
This allows the secret to differentiate between StatefulSet replicas.
type: boolean
services:
default: []
description: |-
The service scope allows Pod objects to specify custom scopes.
This should typically correspond to Service objects that the Pod participates in.
items:
type: string
type: array
type: object
secretClass:
description: '[SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass) containing the LDAP bind credentials.'
type: string
required:
- secretClass
type: object
host:
description: 'Host of the S3 server without any protocol or port. For example: `west1.my-cloud.com`.'
type: string
port:
description: |-
Port the S3 server listens on.
If not specified the product will determine the port to use.
format: uint16
maximum: 65535.0
minimum: 0.0
nullable: true
type: integer
region:
default:
name: us-east-1
description: |-
Bucket region used for signing headers (sigv4).
This defaults to `us-east-1` which is compatible with other implementations such as Minio.
WARNING: Some products use the Hadoop S3 implementation which falls back to us-east-2.
properties:
name:
default: us-east-1
type: string
type: object
tls:
description: Use a TLS connection. If not specified no TLS will be used.
nullable: true
properties:
verification:
description: The verification method used to verify the certificates of the server and/or the client.
oneOf:
- required:
- none
- required:
- server
properties:
none:
description: Use TLS but don't verify certificates.
type: object
server:
description: Use TLS and a CA certificate to verify the server.
properties:
caCert:
description: CA cert to verify the server.
oneOf:
- required:
- webPki
- required:
- secretClass
properties:
secretClass:
description: |-
Name of the [SecretClass](https://docs.stackable.tech/home/26.3/secret-operator/secretclass) which will provide the CA certificate.
Note that a SecretClass does not need to have a key but can also work with just a CA certificate,
so if you got provided with a CA cert but don't have access to the key you can still use this method.
type: string
webPki:
description: |-
Use TLS and the CA certificates trusted by the common web browsers to verify the server.
This can be useful when you e.g. use public AWS S3 or other public available services.
type: object
type: object
required:
- caCert
type: object
type: object
required:
- verification
type: object
required:
- host
type: object
reference:
type: string
type: object
required:
- bucketName
- connection
type: object
required:
- spec
title: S3Bucket
type: object
served: true
storage: true
subresources: {}