From 544ee37bad4d7eecfb31754c6ae0701f63ec5b85 Mon Sep 17 00:00:00 2001 From: Nikola Jokic Date: Wed, 23 Sep 2026 15:36:46 +0200 Subject: [PATCH] Bump go and go dependencies and modify deprecated Requeue to RequeueAfter (#4678) --- .github/workflows/go.yaml | 5 +- Dockerfile | 2 +- Makefile | 71 +- ...rwind.dev_horizontalrunnerautoscalers.yaml | 2 +- ...ions.summerwind.dev_runnerdeployments.yaml | 419 +++++++++- ...ions.summerwind.dev_runnerreplicasets.yaml | 419 +++++++++- .../crds/actions.summerwind.dev_runners.yaml | 419 +++++++++- .../actions.summerwind.dev_runnersets.yaml | 428 +++++++++- ...tions.github.com_autoscalinglisteners.yaml | 380 ++++++++- ...ions.github.com_autoscalingrunnersets.yaml | 748 ++++++++++++++++- .../actions.github.com_ephemeralrunners.yaml | 377 ++++++++- ...ctions.github.com_ephemeralrunnersets.yaml | 377 ++++++++- ...tions.github.com_autoscalinglisteners.yaml | 380 ++++++++- ...ions.github.com_autoscalingrunnersets.yaml | 748 ++++++++++++++++- .../actions.github.com_ephemeralrunners.yaml | 377 ++++++++- ...ctions.github.com_ephemeralrunnersets.yaml | 377 ++++++++- .../tests/template_test.go | 20 +- .../tests/template_test.go | 2 +- ...tions.github.com_autoscalinglisteners.yaml | 380 ++++++++- ...ions.github.com_autoscalingrunnersets.yaml | 748 ++++++++++++++++- .../actions.github.com_ephemeralrunners.yaml | 377 ++++++++- ...ctions.github.com_ephemeralrunnersets.yaml | 377 ++++++++- ...rwind.dev_horizontalrunnerautoscalers.yaml | 2 +- ...ions.summerwind.dev_runnerdeployments.yaml | 419 +++++++++- ...ions.summerwind.dev_runnerreplicasets.yaml | 419 +++++++++- .../bases/actions.summerwind.dev_runners.yaml | 419 +++++++++- .../actions.summerwind.dev_runnersets.yaml | 428 +++++++++- .../autoscalinglistener_controller.go | 175 ++-- .../autoscalinglistener_proxy_cleanup_test.go | 6 +- .../autoscalinglistener_requeue_bench_test.go | 756 ++++++++++++++++++ .../ephemeralrunner_controller.go | 10 +- .../ephemeralrunnerset_controller.go | 9 +- .../actions.summerwind.net/utils_test.go | 2 +- go.mod | 236 +++--- go.sum | 537 ++++++++----- test/e2e/e2e_test.go | 4 +- 36 files changed, 9838 insertions(+), 1017 deletions(-) create mode 100644 controllers/actions.github.com/autoscalinglistener_requeue_bench_test.go diff --git a/.github/workflows/go.yaml b/.github/workflows/go.yaml index 155c4a75..fde1be3b 100644 --- a/.github/workflows/go.yaml +++ b/.github/workflows/go.yaml @@ -51,7 +51,7 @@ jobs: uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a with: only-new-issues: true - version: v2.11.2 + version: v2.13.2 generate: runs-on: ubuntu-latest @@ -91,9 +91,8 @@ jobs: run: git diff --exit-code - name: Setup envtest run: | - go install sigs.k8s.io/controller-runtime/tools/setup-envtest@$(go list -m -f '{{ .Version }}' sigs.k8s.io/controller-runtime | awk -F'[v.]' '{printf "release-%d.%d", $2, $3}') ENVTEST_K8S_VERSION=$(go list -m -f '{{ .Version }}' k8s.io/api | awk -F'[v.]' '{printf "1.%d", $3}') - echo "KUBEBUILDER_ASSETS=$(setup-envtest use ${ENVTEST_K8S_VERSION} -p path)" >> $GITHUB_ENV + echo "KUBEBUILDER_ASSETS=$(go tool sigs.k8s.io/controller-runtime/tools/setup-envtest use ${ENVTEST_K8S_VERSION} -p path)" >> $GITHUB_ENV - name: Run go tests run: | go test -short `go list ./... | grep -v ./test_e2e_arc` diff --git a/Dockerfile b/Dockerfile index c7c255a3..613a21b5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # Build the manager binary -FROM --platform=$BUILDPLATFORM golang:1.26.3 AS builder +FROM --platform=$BUILDPLATFORM golang:1.27.1 AS builder WORKDIR /workspace diff --git a/Makefile b/Makefile index 7eabff83..30b88f8a 100644 --- a/Makefile +++ b/Makefile @@ -36,11 +36,14 @@ TOOLS_PATH=$(PWD)/.tools OS_NAME := $(shell uname -s | tr A-Z a-z) -# ENVTEST_VERSION is the version of controller-runtime release branch to fetch the envtest setup script -ENVTEST_VERSION ?= $(shell go list -m -f "{{ .Version }}" sigs.k8s.io/controller-runtime | awk -F'[v.]' '{printf "release-%d.%d", $$2, $$3}') # ENVTEST_K8S_VERSION is the version of Kubernetes to use for setting up ENVTEST binaries ENVTEST_K8S_VERSION ?= $(shell go list -m -f "{{ .Version }}" k8s.io/api | awk -F'[v.]' '{printf "1.%d", $$3}') -ENVTEST ?= $(GOBIN)/setup-envtest + +# Tools are declared as `tool` directives in go.mod and executed with `go tool`, +# so their versions are pinned and updated alongside the rest of the dependencies. +CONTROLLER_GEN ?= go tool sigs.k8s.io/controller-tools/cmd/controller-gen +ENVTEST ?= go tool sigs.k8s.io/controller-runtime/tools/setup-envtest +YQ ?= go tool github.com/mikefarah/yq/v4 # default list of platforms for which multiarch image is built ifeq (${PLATFORMS}, ) @@ -62,7 +65,7 @@ endif all: manager lint: - docker run --rm -v $(PWD):/app -w /app golangci/golangci-lint:v2.11.2 golangci-lint run + docker run --rm -v $(PWD):/app -w /app golangci/golangci-lint:v2.13.2 golangci-lint run GO_TEST_ARGS ?= -short @@ -110,7 +113,7 @@ deploy: manifests # Generate manifests e.g. CRD, RBAC etc. manifests: manifests-gen-crds chart-crds -manifests-gen-crds: controller-gen yq +manifests-gen-crds: $(CONTROLLER_GEN) $(CRD_OPTIONS) rbac:roleName=manager-role webhook paths="./..." output:crd:artifacts:config=config/crd/bases make manifests-gen-crds-fix DELETE_KEY=x-kubernetes-list-type make manifests-gen-crds-fix DELETE_KEY=x-kubernetes-list-map-keys @@ -195,7 +198,7 @@ vet: go vet ./... # Generate code -generate: controller-gen +generate: $(CONTROLLER_GEN) object:headerFile=./hack/boilerplate.go.txt paths="./..." # Run shellcheck on runner scripts @@ -302,7 +305,8 @@ gha-e2e: github-release: release ghr ${VERSION} release/ -# Find or download controller-gen +# controller-gen is provided by the `sigs.k8s.io/controller-tools/cmd/controller-gen` +# tool directive in go.mod, and is invoked through `$(CONTROLLER_GEN)`. # # Note that controller-gen newer than 0.4.1 is needed for https://github.com/kubernetes-sigs/controller-tools/issues/444#issuecomment-680168439 # Otherwise we get errors like the below: @@ -310,39 +314,6 @@ github-release: release # # Note that controller-gen newer than 0.8.1 is needed due to https://github.com/kubernetes-sigs/controller-tools/issues/448 # Otherwise ObjectMeta embedded in Spec results in empty on the storage. -controller-gen: -ifeq (, $(shell which controller-gen)) -ifeq (, $(wildcard $(GOBIN)/controller-gen)) - @{ \ - set -e ;\ - CONTROLLER_GEN_TMP_DIR=$$(mktemp -d) ;\ - cd $$CONTROLLER_GEN_TMP_DIR ;\ - go mod init tmp ;\ - go install sigs.k8s.io/controller-tools/cmd/controller-gen@v0.20.1 ;\ - rm -rf $$CONTROLLER_GEN_TMP_DIR ;\ - } -endif -CONTROLLER_GEN=$(GOBIN)/controller-gen -else -CONTROLLER_GEN=$(shell which controller-gen) -endif - -# find or download yq -# download yq if necessary -# Use always go-version to get consistent line wraps etc. -yq: -ifeq (, $(wildcard $(GOBIN)/yq)) - echo "Downloading yq" - @{ \ - set -e ;\ - YQ_TMP_DIR=$$(mktemp -d) ;\ - cd $$YQ_TMP_DIR ;\ - go mod init tmp ;\ - go install github.com/mikefarah/yq/v4@v4.25.3 ;\ - rm -rf $$YQ_TMP_DIR ;\ - } -endif -YQ=$(GOBIN)/yq # find or download shellcheck # download shellcheck if necessary @@ -363,26 +334,8 @@ ifeq (, $(wildcard $(TOOLS_PATH)/shellcheck)) endif SHELLCHECK=$(TOOLS_PATH)/shellcheck -# find or download envtest -envtest: -ifeq (, $(shell which setup-envtest)) -ifeq (, $(wildcard $(GOBIN)/setup-envtest)) - @{ \ - set -e ;\ - ENVTEST_TMP_DIR=$$(mktemp -d) ;\ - cd $$ENVTEST_TMP_DIR ;\ - go mod init tmp ;\ - go install sigs.k8s.io/controller-runtime/tools/setup-envtest@$(ENVTEST_VERSION) ;\ - rm -rf $$ENVTEST_TMP_DIR ;\ - } -endif -ENVTEST=$(GOBIN)/setup-envtest -else -ENVTEST=$(shell which setup-envtest) -endif - .PHONY: setup-envtest -setup-envtest: envtest +setup-envtest: @echo "Setting up envtest binaries for Kubernetes version $(ENVTEST_K8S_VERSION)..." @$(ENVTEST) use $(ENVTEST_K8S_VERSION) --bin-dir $(GOBIN) -p path || { \ echo "Error: Failed to set up envtest binaries for version $(ENVTEST_K8S_VERSION)."; \ diff --git a/charts/actions-runner-controller/crds/actions.summerwind.dev_horizontalrunnerautoscalers.yaml b/charts/actions-runner-controller/crds/actions.summerwind.dev_horizontalrunnerautoscalers.yaml index beb4a089..069dab97 100644 --- a/charts/actions-runner-controller/crds/actions.summerwind.dev_horizontalrunnerautoscalers.yaml +++ b/charts/actions-runner-controller/crds/actions.summerwind.dev_horizontalrunnerautoscalers.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: horizontalrunnerautoscalers.actions.summerwind.dev spec: group: actions.summerwind.dev diff --git a/charts/actions-runner-controller/crds/actions.summerwind.dev_runnerdeployments.yaml b/charts/actions-runner-controller/crds/actions.summerwind.dev_runnerdeployments.yaml index 4a2804f9..6e69f846 100644 --- a/charts/actions-runner-controller/crds/actions.summerwind.dev_runnerdeployments.yaml +++ b/charts/actions-runner-controller/crds/actions.summerwind.dev_runnerdeployments.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: runnerdeployments.actions.summerwind.dev spec: group: actions.summerwind.dev @@ -1095,7 +1095,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1350,6 +1352,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1456,6 +1463,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1534,6 +1546,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1588,6 +1607,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1740,6 +1764,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1794,6 +1825,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2232,6 +2268,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2286,6 +2329,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2419,10 +2467,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2568,7 +2626,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2701,10 +2761,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2850,7 +2920,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3086,7 +3158,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3337,6 +3411,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3443,6 +3522,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3517,6 +3601,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3571,6 +3662,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3711,6 +3807,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3765,6 +3868,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4172,6 +4280,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4226,6 +4341,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4368,10 +4488,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4557,7 +4687,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4812,6 +4944,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4918,6 +5055,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4996,6 +5138,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5050,6 +5199,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5202,6 +5356,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5256,6 +5417,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5694,6 +5860,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5748,6 +5921,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5881,10 +6059,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -6127,11 +6315,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6325,7 +6510,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -6580,6 +6767,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6686,6 +6878,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6764,6 +6961,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -6818,6 +7022,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6970,6 +7179,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7024,6 +7240,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7462,6 +7683,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7516,6 +7744,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7649,10 +7882,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -7937,10 +8180,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -8208,6 +8461,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -8240,6 +8500,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8323,6 +8590,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -8376,6 +8650,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8394,6 +8675,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -8504,8 +8797,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8548,7 +8841,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9095,6 +9387,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -9190,6 +9489,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9228,6 +9534,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9304,6 +9617,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9410,6 +9730,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -9467,6 +9794,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9512,6 +9846,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9712,6 +10053,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -9744,6 +10092,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/actions-runner-controller/crds/actions.summerwind.dev_runnerreplicasets.yaml b/charts/actions-runner-controller/crds/actions.summerwind.dev_runnerreplicasets.yaml index b029730c..f399e5a5 100644 --- a/charts/actions-runner-controller/crds/actions.summerwind.dev_runnerreplicasets.yaml +++ b/charts/actions-runner-controller/crds/actions.summerwind.dev_runnerreplicasets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: runnerreplicasets.actions.summerwind.dev spec: group: actions.summerwind.dev @@ -1078,7 +1078,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1333,6 +1335,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1439,6 +1446,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1517,6 +1529,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1571,6 +1590,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1723,6 +1747,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1777,6 +1808,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2215,6 +2251,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2269,6 +2312,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2402,10 +2450,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2551,7 +2609,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2684,10 +2744,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2833,7 +2903,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3069,7 +3141,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3320,6 +3394,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3426,6 +3505,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3500,6 +3584,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3554,6 +3645,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3694,6 +3790,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3748,6 +3851,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4155,6 +4263,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4209,6 +4324,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4351,10 +4471,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4540,7 +4670,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4795,6 +4927,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4901,6 +5038,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4979,6 +5121,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5033,6 +5182,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5185,6 +5339,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5239,6 +5400,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5677,6 +5843,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5731,6 +5904,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5864,10 +6042,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -6110,11 +6298,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6308,7 +6493,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -6563,6 +6750,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6669,6 +6861,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6747,6 +6944,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -6801,6 +7005,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6953,6 +7162,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7007,6 +7223,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7445,6 +7666,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7499,6 +7727,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7632,10 +7865,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -7920,10 +8163,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -8191,6 +8444,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -8223,6 +8483,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8306,6 +8573,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -8359,6 +8633,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8377,6 +8658,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -8487,8 +8780,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8531,7 +8824,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9078,6 +9370,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -9173,6 +9472,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9211,6 +9517,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9287,6 +9600,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9393,6 +9713,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -9450,6 +9777,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9495,6 +9829,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9695,6 +10036,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -9727,6 +10075,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/actions-runner-controller/crds/actions.summerwind.dev_runners.yaml b/charts/actions-runner-controller/crds/actions.summerwind.dev_runners.yaml index 938f1813..5f9d8a29 100644 --- a/charts/actions-runner-controller/crds/actions.summerwind.dev_runners.yaml +++ b/charts/actions-runner-controller/crds/actions.summerwind.dev_runners.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: runners.actions.summerwind.dev spec: group: actions.summerwind.dev @@ -1010,7 +1010,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1265,6 +1267,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1371,6 +1378,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1449,6 +1461,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1503,6 +1522,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1655,6 +1679,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1709,6 +1740,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2147,6 +2183,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2201,6 +2244,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2334,10 +2382,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2483,7 +2541,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2616,10 +2676,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2765,7 +2835,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3001,7 +3073,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3252,6 +3326,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3358,6 +3437,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3432,6 +3516,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3486,6 +3577,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3626,6 +3722,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3680,6 +3783,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4087,6 +4195,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4141,6 +4256,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4283,10 +4403,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4472,7 +4602,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4727,6 +4859,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4833,6 +4970,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4911,6 +5053,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4965,6 +5114,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5117,6 +5271,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5171,6 +5332,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5609,6 +5775,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5663,6 +5836,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5796,10 +5974,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -6042,11 +6230,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6240,7 +6425,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -6495,6 +6682,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6601,6 +6793,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6679,6 +6876,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -6733,6 +6937,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6885,6 +7094,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -6939,6 +7155,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7377,6 +7598,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7431,6 +7659,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7564,10 +7797,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -7852,10 +8095,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -8123,6 +8376,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -8155,6 +8415,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8238,6 +8505,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -8291,6 +8565,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8309,6 +8590,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -8419,8 +8712,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8463,7 +8756,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9010,6 +9302,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -9105,6 +9404,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9143,6 +9449,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9219,6 +9532,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9325,6 +9645,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -9382,6 +9709,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9427,6 +9761,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9627,6 +9968,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -9659,6 +10007,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/actions-runner-controller/crds/actions.summerwind.dev_runnersets.yaml b/charts/actions-runner-controller/crds/actions.summerwind.dev_runnersets.yaml index a510d0bd..b6637fb4 100644 --- a/charts/actions-runner-controller/crds/actions.summerwind.dev_runnersets.yaml +++ b/charts/actions-runner-controller/crds/actions.summerwind.dev_runnersets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: runnersets.actions.summerwind.dev spec: group: actions.summerwind.dev @@ -1232,7 +1232,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1487,6 +1489,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1593,6 +1600,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1671,6 +1683,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1725,6 +1744,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1877,6 +1901,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1931,6 +1962,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2369,6 +2405,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2423,6 +2466,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2556,10 +2604,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2767,7 +2825,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3018,6 +3078,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3124,6 +3189,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3198,6 +3268,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3252,6 +3329,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3392,6 +3474,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3446,6 +3535,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3853,6 +3947,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3907,6 +4008,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4049,10 +4155,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4124,6 +4240,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4194,7 +4367,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4298,7 +4470,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4553,6 +4727,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4659,6 +4838,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4737,6 +4921,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4791,6 +4982,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4943,6 +5139,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4997,6 +5200,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5435,6 +5643,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5489,6 +5704,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5622,10 +5842,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5779,6 +6009,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6117,11 +6349,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6720,6 +6949,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6752,6 +6988,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6835,6 +7078,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6888,6 +7138,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6906,6 +7163,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7016,8 +7285,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7060,7 +7329,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7607,6 +7875,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7702,6 +7977,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7740,6 +8022,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7816,6 +8105,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7922,6 +8218,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7979,6 +8282,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8024,6 +8334,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8224,6 +8541,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8256,6 +8580,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8458,8 +8789,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8502,7 +8833,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -8721,6 +9051,56 @@ spec: currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using. When unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim type: string + healthStatus: + description: |- + healthStatus contains the latest controller-reported health information + for the volume bound to this claim. + properties: + healthConditions: + description: |- + conditions is the set of adverse conditions reported by + the CSI controller plugin. An empty list means no adverse condition. + At most 16 conditions may be reported. + items: + description: VolumeHealthCondition represents an adverse health condition reported for a volume. + properties: + message: + description: |- + message is a human-readable description. + Maximum permitted length of a message is 1024 bytes. + type: string + reason: + description: |- + reason is a brief CamelCase machine-parseable reason. + Together with status it forms the unique identity of a condition entry. + Maximum permitted length of a reason is 256 bytes. + type: string + status: + description: |- + status is the machine-parseable health category. + Possible values: + - "Inaccessible": the volume cannot be accessed. + - "DataLoss": data loss has been detected on the volume. + - "Degraded": the volume is functioning with reduced capability. + enum: + - DataLoss + - Degraded + - Inaccessible + type: string + required: + - reason + - status + type: object + type: array + x-kubernetes-list-map-keys: + - status + - reason + x-kubernetes-list-type: map + lastTransitionTime: + description: lastTransitionTime is when the current set of conditions first appeared. + format: date-time + type: string + type: object modifyVolumeStatus: description: |- ModifyVolumeStatus represents the status object of ControllerModifyVolume operation. diff --git a/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_autoscalinglisteners.yaml b/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_autoscalinglisteners.yaml index c9f7bb27..79e336b4 100644 --- a/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_autoscalinglisteners.yaml +++ b/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_autoscalinglisteners.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: autoscalinglisteners.actions.github.com spec: group: actions.github.com @@ -85,7 +85,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1304,7 +1306,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1579,6 +1583,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1693,6 +1702,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1775,6 +1789,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -1833,6 +1854,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1990,6 +2016,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2048,6 +2081,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2503,6 +2541,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2561,6 +2606,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2702,10 +2752,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -2917,7 +2978,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3189,6 +3252,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3303,6 +3371,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3381,6 +3454,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3439,6 +3519,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3584,6 +3669,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3642,6 +3734,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4066,6 +4163,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -4124,6 +4228,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4274,10 +4383,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -4349,6 +4469,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4419,7 +4596,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4526,7 +4702,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4801,6 +4979,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4915,6 +5098,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4997,6 +5185,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5055,6 +5250,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5212,6 +5412,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5270,6 +5477,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5725,6 +5937,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5783,6 +6002,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5924,10 +6148,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -6081,6 +6316,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6425,11 +6662,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -7049,6 +7283,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -7082,6 +7323,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7169,6 +7417,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -7237,6 +7492,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7255,6 +7517,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7365,8 +7639,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7411,7 +7685,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7980,6 +8253,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -8080,6 +8360,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8120,6 +8407,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8219,6 +8513,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8326,6 +8627,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -8385,6 +8693,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8432,6 +8747,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8638,6 +8960,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8671,6 +9000,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_autoscalingrunnersets.yaml b/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_autoscalingrunnersets.yaml index 17128cf1..ffdc6068 100644 --- a/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_autoscalingrunnersets.yaml +++ b/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_autoscalingrunnersets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: autoscalingrunnersets.actions.github.com spec: group: actions.github.com @@ -110,7 +110,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1217,7 +1219,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1472,6 +1476,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1578,6 +1587,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1656,6 +1670,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1710,6 +1731,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1862,6 +1888,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1916,6 +1949,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2357,6 +2395,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2411,6 +2456,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2544,10 +2594,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2755,7 +2815,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3006,6 +3068,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3112,6 +3179,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3186,6 +3258,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3240,6 +3319,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3380,6 +3464,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3434,6 +3525,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3844,6 +3940,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3898,6 +4001,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4040,10 +4148,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4115,6 +4233,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4185,7 +4360,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4289,7 +4463,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4544,6 +4720,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4650,6 +4831,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4728,6 +4914,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4782,6 +4975,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4934,6 +5132,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4988,6 +5193,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5429,6 +5639,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5483,6 +5700,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5616,10 +5838,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5773,6 +6005,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6114,11 +6348,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6717,6 +6948,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6749,6 +6987,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6832,6 +7077,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6885,6 +7137,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6903,6 +7162,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7013,8 +7284,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7057,7 +7328,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7604,6 +7874,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7699,6 +7976,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7737,6 +8021,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7813,6 +8104,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7919,6 +8217,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7976,6 +8281,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8021,6 +8333,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8221,6 +8540,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8253,6 +8579,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9368,7 +9701,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -9623,6 +9958,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -9729,6 +10069,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -9807,6 +10152,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -9861,6 +10213,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10013,6 +10370,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -10067,6 +10431,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10505,6 +10874,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -10559,6 +10935,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10692,10 +11073,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -10903,7 +11294,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -11154,6 +11547,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11260,6 +11658,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11334,6 +11737,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -11388,6 +11798,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11528,6 +11943,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -11582,6 +12004,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11989,6 +12416,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -12043,6 +12477,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12185,10 +12624,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -12260,6 +12709,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -12330,7 +12836,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -12434,7 +12939,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -12689,6 +13196,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12795,6 +13307,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12873,6 +13390,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -12927,6 +13451,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13079,6 +13608,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -13133,6 +13669,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13571,6 +14112,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -13625,6 +14173,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13758,10 +14311,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -13915,6 +14478,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -14253,11 +14818,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -14856,6 +15418,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -14888,6 +15457,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -14971,6 +15547,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -15024,6 +15607,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15042,6 +15632,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -15152,8 +15754,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -15196,7 +15798,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -15743,6 +16344,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -15838,6 +16446,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15876,6 +16491,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -15952,6 +16574,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16058,6 +16687,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -16115,6 +16751,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -16160,6 +16803,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16360,6 +17010,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -16392,6 +17049,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_ephemeralrunners.yaml b/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_ephemeralrunners.yaml index e6d671a1..7ae231e4 100644 --- a/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_ephemeralrunners.yaml +++ b/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_ephemeralrunners.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: ephemeralrunners.actions.github.com spec: group: actions.github.com @@ -95,7 +95,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1120,7 +1122,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1375,6 +1379,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1481,6 +1490,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1559,6 +1573,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1613,6 +1634,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1765,6 +1791,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1819,6 +1852,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2257,6 +2295,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2311,6 +2356,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2444,10 +2494,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2655,7 +2715,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2906,6 +2968,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3012,6 +3079,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3086,6 +3158,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3140,6 +3219,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3280,6 +3364,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3334,6 +3425,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3741,6 +3837,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3795,6 +3898,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3937,10 +4045,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4012,6 +4130,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4082,7 +4257,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4186,7 +4360,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4441,6 +4617,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4547,6 +4728,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4625,6 +4811,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4679,6 +4872,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4831,6 +5029,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4885,6 +5090,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5323,6 +5533,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5377,6 +5594,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5510,10 +5732,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5667,6 +5899,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6008,11 +6242,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6611,6 +6842,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6643,6 +6881,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6726,6 +6971,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6779,6 +7031,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6797,6 +7056,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -6907,8 +7178,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -6951,7 +7222,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7498,6 +7768,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7593,6 +7870,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7631,6 +7915,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7707,6 +7998,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7813,6 +8111,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7870,6 +8175,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7915,6 +8227,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8115,6 +8434,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8147,6 +8473,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_ephemeralrunnersets.yaml b/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_ephemeralrunnersets.yaml index 03702649..539817bb 100644 --- a/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_ephemeralrunnersets.yaml +++ b/charts/gha-runner-scale-set-controller-experimental/crds/actions.github.com_ephemeralrunnersets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: ephemeralrunnersets.actions.github.com spec: group: actions.github.com @@ -97,7 +97,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1122,7 +1124,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1377,6 +1381,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1483,6 +1492,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1561,6 +1575,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1615,6 +1636,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1767,6 +1793,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1821,6 +1854,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2259,6 +2297,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2313,6 +2358,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2446,10 +2496,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2657,7 +2717,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2908,6 +2970,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3014,6 +3081,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3088,6 +3160,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3142,6 +3221,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3282,6 +3366,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3336,6 +3427,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3743,6 +3839,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3797,6 +3900,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3939,10 +4047,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4014,6 +4132,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4084,7 +4259,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4188,7 +4362,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4443,6 +4619,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4549,6 +4730,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4627,6 +4813,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4681,6 +4874,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4833,6 +5031,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4887,6 +5092,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5325,6 +5535,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5379,6 +5596,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5512,10 +5734,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5669,6 +5901,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6010,11 +6244,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6613,6 +6844,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6645,6 +6883,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6728,6 +6973,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6781,6 +7033,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6799,6 +7058,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -6909,8 +7180,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -6953,7 +7224,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7500,6 +7770,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7595,6 +7872,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7633,6 +7917,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7709,6 +8000,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7815,6 +8113,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7872,6 +8177,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7917,6 +8229,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8117,6 +8436,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8149,6 +8475,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/gha-runner-scale-set-controller/crds/actions.github.com_autoscalinglisteners.yaml b/charts/gha-runner-scale-set-controller/crds/actions.github.com_autoscalinglisteners.yaml index c9f7bb27..79e336b4 100644 --- a/charts/gha-runner-scale-set-controller/crds/actions.github.com_autoscalinglisteners.yaml +++ b/charts/gha-runner-scale-set-controller/crds/actions.github.com_autoscalinglisteners.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: autoscalinglisteners.actions.github.com spec: group: actions.github.com @@ -85,7 +85,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1304,7 +1306,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1579,6 +1583,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1693,6 +1702,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1775,6 +1789,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -1833,6 +1854,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1990,6 +2016,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2048,6 +2081,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2503,6 +2541,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2561,6 +2606,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2702,10 +2752,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -2917,7 +2978,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3189,6 +3252,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3303,6 +3371,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3381,6 +3454,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3439,6 +3519,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3584,6 +3669,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3642,6 +3734,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4066,6 +4163,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -4124,6 +4228,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4274,10 +4383,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -4349,6 +4469,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4419,7 +4596,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4526,7 +4702,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4801,6 +4979,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4915,6 +5098,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4997,6 +5185,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5055,6 +5250,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5212,6 +5412,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5270,6 +5477,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5725,6 +5937,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5783,6 +6002,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5924,10 +6148,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -6081,6 +6316,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6425,11 +6662,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -7049,6 +7283,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -7082,6 +7323,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7169,6 +7417,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -7237,6 +7492,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7255,6 +7517,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7365,8 +7639,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7411,7 +7685,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7980,6 +8253,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -8080,6 +8360,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8120,6 +8407,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8219,6 +8513,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8326,6 +8627,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -8385,6 +8693,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8432,6 +8747,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8638,6 +8960,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8671,6 +9000,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/gha-runner-scale-set-controller/crds/actions.github.com_autoscalingrunnersets.yaml b/charts/gha-runner-scale-set-controller/crds/actions.github.com_autoscalingrunnersets.yaml index 17128cf1..ffdc6068 100644 --- a/charts/gha-runner-scale-set-controller/crds/actions.github.com_autoscalingrunnersets.yaml +++ b/charts/gha-runner-scale-set-controller/crds/actions.github.com_autoscalingrunnersets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: autoscalingrunnersets.actions.github.com spec: group: actions.github.com @@ -110,7 +110,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1217,7 +1219,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1472,6 +1476,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1578,6 +1587,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1656,6 +1670,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1710,6 +1731,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1862,6 +1888,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1916,6 +1949,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2357,6 +2395,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2411,6 +2456,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2544,10 +2594,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2755,7 +2815,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3006,6 +3068,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3112,6 +3179,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3186,6 +3258,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3240,6 +3319,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3380,6 +3464,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3434,6 +3525,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3844,6 +3940,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3898,6 +4001,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4040,10 +4148,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4115,6 +4233,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4185,7 +4360,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4289,7 +4463,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4544,6 +4720,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4650,6 +4831,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4728,6 +4914,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4782,6 +4975,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4934,6 +5132,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4988,6 +5193,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5429,6 +5639,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5483,6 +5700,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5616,10 +5838,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5773,6 +6005,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6114,11 +6348,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6717,6 +6948,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6749,6 +6987,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6832,6 +7077,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6885,6 +7137,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6903,6 +7162,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7013,8 +7284,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7057,7 +7328,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7604,6 +7874,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7699,6 +7976,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7737,6 +8021,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7813,6 +8104,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7919,6 +8217,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7976,6 +8281,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8021,6 +8333,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8221,6 +8540,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8253,6 +8579,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9368,7 +9701,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -9623,6 +9958,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -9729,6 +10069,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -9807,6 +10152,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -9861,6 +10213,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10013,6 +10370,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -10067,6 +10431,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10505,6 +10874,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -10559,6 +10935,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10692,10 +11073,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -10903,7 +11294,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -11154,6 +11547,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11260,6 +11658,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11334,6 +11737,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -11388,6 +11798,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11528,6 +11943,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -11582,6 +12004,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11989,6 +12416,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -12043,6 +12477,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12185,10 +12624,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -12260,6 +12709,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -12330,7 +12836,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -12434,7 +12939,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -12689,6 +13196,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12795,6 +13307,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12873,6 +13390,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -12927,6 +13451,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13079,6 +13608,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -13133,6 +13669,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13571,6 +14112,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -13625,6 +14173,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13758,10 +14311,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -13915,6 +14478,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -14253,11 +14818,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -14856,6 +15418,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -14888,6 +15457,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -14971,6 +15547,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -15024,6 +15607,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15042,6 +15632,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -15152,8 +15754,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -15196,7 +15798,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -15743,6 +16344,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -15838,6 +16446,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15876,6 +16491,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -15952,6 +16574,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16058,6 +16687,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -16115,6 +16751,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -16160,6 +16803,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16360,6 +17010,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -16392,6 +17049,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/gha-runner-scale-set-controller/crds/actions.github.com_ephemeralrunners.yaml b/charts/gha-runner-scale-set-controller/crds/actions.github.com_ephemeralrunners.yaml index e6d671a1..7ae231e4 100644 --- a/charts/gha-runner-scale-set-controller/crds/actions.github.com_ephemeralrunners.yaml +++ b/charts/gha-runner-scale-set-controller/crds/actions.github.com_ephemeralrunners.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: ephemeralrunners.actions.github.com spec: group: actions.github.com @@ -95,7 +95,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1120,7 +1122,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1375,6 +1379,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1481,6 +1490,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1559,6 +1573,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1613,6 +1634,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1765,6 +1791,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1819,6 +1852,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2257,6 +2295,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2311,6 +2356,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2444,10 +2494,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2655,7 +2715,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2906,6 +2968,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3012,6 +3079,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3086,6 +3158,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3140,6 +3219,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3280,6 +3364,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3334,6 +3425,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3741,6 +3837,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3795,6 +3898,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3937,10 +4045,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4012,6 +4130,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4082,7 +4257,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4186,7 +4360,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4441,6 +4617,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4547,6 +4728,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4625,6 +4811,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4679,6 +4872,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4831,6 +5029,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4885,6 +5090,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5323,6 +5533,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5377,6 +5594,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5510,10 +5732,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5667,6 +5899,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6008,11 +6242,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6611,6 +6842,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6643,6 +6881,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6726,6 +6971,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6779,6 +7031,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6797,6 +7056,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -6907,8 +7178,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -6951,7 +7222,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7498,6 +7768,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7593,6 +7870,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7631,6 +7915,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7707,6 +7998,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7813,6 +8111,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7870,6 +8175,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7915,6 +8227,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8115,6 +8434,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8147,6 +8473,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/gha-runner-scale-set-controller/crds/actions.github.com_ephemeralrunnersets.yaml b/charts/gha-runner-scale-set-controller/crds/actions.github.com_ephemeralrunnersets.yaml index 03702649..539817bb 100644 --- a/charts/gha-runner-scale-set-controller/crds/actions.github.com_ephemeralrunnersets.yaml +++ b/charts/gha-runner-scale-set-controller/crds/actions.github.com_ephemeralrunnersets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: ephemeralrunnersets.actions.github.com spec: group: actions.github.com @@ -97,7 +97,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1122,7 +1124,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1377,6 +1381,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1483,6 +1492,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1561,6 +1575,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1615,6 +1636,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1767,6 +1793,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1821,6 +1854,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2259,6 +2297,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2313,6 +2358,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2446,10 +2496,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2657,7 +2717,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2908,6 +2970,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3014,6 +3081,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3088,6 +3160,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3142,6 +3221,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3282,6 +3366,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3336,6 +3427,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3743,6 +3839,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3797,6 +3900,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3939,10 +4047,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4014,6 +4132,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4084,7 +4259,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4188,7 +4362,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4443,6 +4619,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4549,6 +4730,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4627,6 +4813,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4681,6 +4874,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4833,6 +5031,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4887,6 +5092,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5325,6 +5535,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5379,6 +5596,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5512,10 +5734,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5669,6 +5901,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6010,11 +6244,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6613,6 +6844,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6645,6 +6883,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6728,6 +6973,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6781,6 +7033,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6799,6 +7058,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -6909,8 +7180,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -6953,7 +7224,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7500,6 +7770,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7595,6 +7872,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7633,6 +7917,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7709,6 +8000,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7815,6 +8113,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7872,6 +8177,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7917,6 +8229,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8117,6 +8436,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8149,6 +8475,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/charts/gha-runner-scale-set-controller/tests/template_test.go b/charts/gha-runner-scale-set-controller/tests/template_test.go index faafee3b..a2a34aa0 100644 --- a/charts/gha-runner-scale-set-controller/tests/template_test.go +++ b/charts/gha-runner-scale-set-controller/tests/template_test.go @@ -430,16 +430,16 @@ func TestTemplate_ControllerDeployment_Customize(t *testing.T) { "affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].key": "foo", "affinity.nodeAffinity.requiredDuringSchedulingIgnoredDuringExecution.nodeSelectorTerms[0].matchExpressions[0].operator": "bar", "topologySpreadConstraints[0].labelSelector.matchLabels.foo": "bar", - "topologySpreadConstraints[0].maxSkew": "1", - "topologySpreadConstraints[0].topologyKey": "foo", - "priorityClassName": "test-priority-class", - "terminationGracePeriodSeconds": "60", - "flags.logLevel": "info", - "flags.logFormat": "json", - "volumes[0].name": "customMount", - "volumes[0].configMap.name": "my-configmap", - "volumeMounts[0].name": "customMount", - "volumeMounts[0].mountPath": "/my/mount/path", + "topologySpreadConstraints[0].maxSkew": "1", + "topologySpreadConstraints[0].topologyKey": "foo", + "priorityClassName": "test-priority-class", + "terminationGracePeriodSeconds": "60", + "flags.logLevel": "info", + "flags.logFormat": "json", + "volumes[0].name": "customMount", + "volumes[0].configMap.name": "my-configmap", + "volumeMounts[0].name": "customMount", + "volumeMounts[0].mountPath": "/my/mount/path", }, KubectlOptions: k8s.NewKubectlOptions("", "", namespaceName), } diff --git a/charts/gha-runner-scale-set/tests/template_test.go b/charts/gha-runner-scale-set/tests/template_test.go index 579ffcb1..23f7a7e0 100644 --- a/charts/gha-runner-scale-set/tests/template_test.go +++ b/charts/gha-runner-scale-set/tests/template_test.go @@ -3420,7 +3420,7 @@ func TestTemplateRenderedAutoScalingRunnerSet_NonScalarMetadataValueValidationEr "controllerServiceAccount.name": "arc", "controllerServiceAccount.namespace": "arc-system", }, - SetJsonValues: map[string]string{ + SetJSONValues: map[string]string{ "template.metadata.annotations": `{"nested":{"inner":"value"}}`, }, KubectlOptions: k8s.NewKubectlOptions("", "", namespaceName), diff --git a/config/crd/bases/actions.github.com_autoscalinglisteners.yaml b/config/crd/bases/actions.github.com_autoscalinglisteners.yaml index c9f7bb27..79e336b4 100644 --- a/config/crd/bases/actions.github.com_autoscalinglisteners.yaml +++ b/config/crd/bases/actions.github.com_autoscalinglisteners.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: autoscalinglisteners.actions.github.com spec: group: actions.github.com @@ -85,7 +85,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1304,7 +1306,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1579,6 +1583,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1693,6 +1702,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1775,6 +1789,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -1833,6 +1854,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1990,6 +2016,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2048,6 +2081,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2503,6 +2541,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -2561,6 +2606,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2702,10 +2752,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -2917,7 +2978,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3189,6 +3252,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3303,6 +3371,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3381,6 +3454,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3439,6 +3519,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3584,6 +3669,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -3642,6 +3734,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4066,6 +4163,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -4124,6 +4228,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4274,10 +4383,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -4349,6 +4469,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4419,7 +4596,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4526,7 +4702,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4801,6 +4979,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4915,6 +5098,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4997,6 +5185,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5055,6 +5250,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5212,6 +5412,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5270,6 +5477,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5725,6 +5937,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. @@ -5783,6 +6002,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5924,10 +6148,21 @@ spec: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which + the volume should be mounted. type: string mountPropagation: description: |- @@ -6081,6 +6316,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6425,11 +6662,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -7049,6 +7283,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -7082,6 +7323,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7169,6 +7417,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file @@ -7237,6 +7492,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7255,6 +7517,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7365,8 +7639,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7411,7 +7685,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7980,6 +8253,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -8080,6 +8360,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8120,6 +8407,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8219,6 +8513,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8326,6 +8627,13 @@ spec: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -8385,6 +8693,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8432,6 +8747,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8638,6 +8960,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8671,6 +9000,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/config/crd/bases/actions.github.com_autoscalingrunnersets.yaml b/config/crd/bases/actions.github.com_autoscalingrunnersets.yaml index 17128cf1..ffdc6068 100644 --- a/config/crd/bases/actions.github.com_autoscalingrunnersets.yaml +++ b/config/crd/bases/actions.github.com_autoscalingrunnersets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: autoscalingrunnersets.actions.github.com spec: group: actions.github.com @@ -110,7 +110,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1217,7 +1219,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1472,6 +1476,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1578,6 +1587,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1656,6 +1670,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1710,6 +1731,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1862,6 +1888,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1916,6 +1949,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2357,6 +2395,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2411,6 +2456,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2544,10 +2594,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2755,7 +2815,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3006,6 +3068,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3112,6 +3179,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3186,6 +3258,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3240,6 +3319,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3380,6 +3464,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3434,6 +3525,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3844,6 +3940,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3898,6 +4001,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4040,10 +4148,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4115,6 +4233,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4185,7 +4360,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4289,7 +4463,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4544,6 +4720,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4650,6 +4831,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4728,6 +4914,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4782,6 +4975,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4934,6 +5132,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4988,6 +5193,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5429,6 +5639,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5483,6 +5700,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5616,10 +5838,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5773,6 +6005,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6114,11 +6348,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6717,6 +6948,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6749,6 +6987,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6832,6 +7077,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6885,6 +7137,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6903,6 +7162,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7013,8 +7284,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7057,7 +7328,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7604,6 +7874,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7699,6 +7976,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7737,6 +8021,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7813,6 +8104,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7919,6 +8217,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7976,6 +8281,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8021,6 +8333,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8221,6 +8540,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8253,6 +8579,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9368,7 +9701,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -9623,6 +9958,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -9729,6 +10069,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -9807,6 +10152,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -9861,6 +10213,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10013,6 +10370,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -10067,6 +10431,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10505,6 +10874,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -10559,6 +10935,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -10692,10 +11073,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -10903,7 +11294,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -11154,6 +11547,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11260,6 +11658,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11334,6 +11737,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -11388,6 +11798,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11528,6 +11943,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -11582,6 +12004,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -11989,6 +12416,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -12043,6 +12477,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12185,10 +12624,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -12260,6 +12709,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -12330,7 +12836,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -12434,7 +12939,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -12689,6 +13196,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12795,6 +13307,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -12873,6 +13390,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -12927,6 +13451,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13079,6 +13608,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -13133,6 +13669,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13571,6 +14112,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -13625,6 +14173,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -13758,10 +14311,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -13915,6 +14478,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -14253,11 +14818,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -14856,6 +15418,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -14888,6 +15457,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -14971,6 +15547,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -15024,6 +15607,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15042,6 +15632,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -15152,8 +15754,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -15196,7 +15798,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -15743,6 +16344,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -15838,6 +16446,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -15876,6 +16491,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -15952,6 +16574,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16058,6 +16687,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -16115,6 +16751,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -16160,6 +16803,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -16360,6 +17010,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -16392,6 +17049,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/config/crd/bases/actions.github.com_ephemeralrunners.yaml b/config/crd/bases/actions.github.com_ephemeralrunners.yaml index e6d671a1..7ae231e4 100644 --- a/config/crd/bases/actions.github.com_ephemeralrunners.yaml +++ b/config/crd/bases/actions.github.com_ephemeralrunners.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: ephemeralrunners.actions.github.com spec: group: actions.github.com @@ -95,7 +95,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1120,7 +1122,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1375,6 +1379,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1481,6 +1490,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1559,6 +1573,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1613,6 +1634,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1765,6 +1791,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1819,6 +1852,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2257,6 +2295,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2311,6 +2356,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2444,10 +2494,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2655,7 +2715,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2906,6 +2968,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3012,6 +3079,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3086,6 +3158,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3140,6 +3219,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3280,6 +3364,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3334,6 +3425,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3741,6 +3837,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3795,6 +3898,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3937,10 +4045,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4012,6 +4130,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4082,7 +4257,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4186,7 +4360,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4441,6 +4617,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4547,6 +4728,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4625,6 +4811,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4679,6 +4872,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4831,6 +5029,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4885,6 +5090,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5323,6 +5533,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5377,6 +5594,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5510,10 +5732,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5667,6 +5899,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6008,11 +6242,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6611,6 +6842,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6643,6 +6881,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6726,6 +6971,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6779,6 +7031,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6797,6 +7056,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -6907,8 +7178,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -6951,7 +7222,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7498,6 +7768,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7593,6 +7870,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7631,6 +7915,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7707,6 +7998,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7813,6 +8111,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7870,6 +8175,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7915,6 +8227,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8115,6 +8434,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8147,6 +8473,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/config/crd/bases/actions.github.com_ephemeralrunnersets.yaml b/config/crd/bases/actions.github.com_ephemeralrunnersets.yaml index 03702649..539817bb 100644 --- a/config/crd/bases/actions.github.com_ephemeralrunnersets.yaml +++ b/config/crd/bases/actions.github.com_ephemeralrunnersets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: ephemeralrunnersets.actions.github.com spec: group: actions.github.com @@ -97,7 +97,9 @@ spec: description: Required properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1122,7 +1124,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1377,6 +1381,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1483,6 +1492,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1561,6 +1575,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1615,6 +1636,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1767,6 +1793,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1821,6 +1854,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2259,6 +2297,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2313,6 +2358,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2446,10 +2496,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2657,7 +2717,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2908,6 +2970,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3014,6 +3081,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3088,6 +3160,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3142,6 +3221,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3282,6 +3366,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3336,6 +3427,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3743,6 +3839,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3797,6 +3900,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3939,10 +4047,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4014,6 +4132,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4084,7 +4259,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4188,7 +4362,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4443,6 +4619,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4549,6 +4730,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4627,6 +4813,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4681,6 +4874,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4833,6 +5031,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4887,6 +5092,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5325,6 +5535,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5379,6 +5596,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5512,10 +5734,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5669,6 +5901,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6010,11 +6244,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6613,6 +6844,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6645,6 +6883,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6728,6 +6973,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6781,6 +7033,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6799,6 +7058,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -6909,8 +7180,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -6953,7 +7224,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7500,6 +7770,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7595,6 +7872,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7633,6 +7917,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7709,6 +8000,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7815,6 +8113,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7872,6 +8177,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7917,6 +8229,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8117,6 +8436,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8149,6 +8475,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/config/crd/bases/actions.summerwind.dev_horizontalrunnerautoscalers.yaml b/config/crd/bases/actions.summerwind.dev_horizontalrunnerautoscalers.yaml index beb4a089..069dab97 100644 --- a/config/crd/bases/actions.summerwind.dev_horizontalrunnerautoscalers.yaml +++ b/config/crd/bases/actions.summerwind.dev_horizontalrunnerautoscalers.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: horizontalrunnerautoscalers.actions.summerwind.dev spec: group: actions.summerwind.dev diff --git a/config/crd/bases/actions.summerwind.dev_runnerdeployments.yaml b/config/crd/bases/actions.summerwind.dev_runnerdeployments.yaml index 4a2804f9..6e69f846 100644 --- a/config/crd/bases/actions.summerwind.dev_runnerdeployments.yaml +++ b/config/crd/bases/actions.summerwind.dev_runnerdeployments.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: runnerdeployments.actions.summerwind.dev spec: group: actions.summerwind.dev @@ -1095,7 +1095,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1350,6 +1352,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1456,6 +1463,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1534,6 +1546,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1588,6 +1607,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1740,6 +1764,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1794,6 +1825,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2232,6 +2268,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2286,6 +2329,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2419,10 +2467,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2568,7 +2626,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2701,10 +2761,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2850,7 +2920,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3086,7 +3158,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3337,6 +3411,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3443,6 +3522,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3517,6 +3601,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3571,6 +3662,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3711,6 +3807,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3765,6 +3868,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4172,6 +4280,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4226,6 +4341,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4368,10 +4488,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4557,7 +4687,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4812,6 +4944,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4918,6 +5055,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4996,6 +5138,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5050,6 +5199,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5202,6 +5356,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5256,6 +5417,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5694,6 +5860,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5748,6 +5921,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5881,10 +6059,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -6127,11 +6315,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6325,7 +6510,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -6580,6 +6767,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6686,6 +6878,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6764,6 +6961,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -6818,6 +7022,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6970,6 +7179,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7024,6 +7240,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7462,6 +7683,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7516,6 +7744,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7649,10 +7882,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -7937,10 +8180,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -8208,6 +8461,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -8240,6 +8500,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8323,6 +8590,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -8376,6 +8650,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8394,6 +8675,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -8504,8 +8797,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8548,7 +8841,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9095,6 +9387,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -9190,6 +9489,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9228,6 +9534,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9304,6 +9617,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9410,6 +9730,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -9467,6 +9794,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9512,6 +9846,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9712,6 +10053,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -9744,6 +10092,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/config/crd/bases/actions.summerwind.dev_runnerreplicasets.yaml b/config/crd/bases/actions.summerwind.dev_runnerreplicasets.yaml index b029730c..f399e5a5 100644 --- a/config/crd/bases/actions.summerwind.dev_runnerreplicasets.yaml +++ b/config/crd/bases/actions.summerwind.dev_runnerreplicasets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: runnerreplicasets.actions.summerwind.dev spec: group: actions.summerwind.dev @@ -1078,7 +1078,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1333,6 +1335,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1439,6 +1446,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1517,6 +1529,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1571,6 +1590,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1723,6 +1747,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1777,6 +1808,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2215,6 +2251,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2269,6 +2312,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2402,10 +2450,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2551,7 +2609,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2684,10 +2744,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2833,7 +2903,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3069,7 +3141,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3320,6 +3394,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3426,6 +3505,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3500,6 +3584,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3554,6 +3645,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3694,6 +3790,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3748,6 +3851,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4155,6 +4263,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4209,6 +4324,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4351,10 +4471,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4540,7 +4670,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4795,6 +4927,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4901,6 +5038,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4979,6 +5121,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5033,6 +5182,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5185,6 +5339,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5239,6 +5400,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5677,6 +5843,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5731,6 +5904,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5864,10 +6042,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -6110,11 +6298,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6308,7 +6493,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -6563,6 +6750,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6669,6 +6861,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6747,6 +6944,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -6801,6 +7005,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6953,6 +7162,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7007,6 +7223,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7445,6 +7666,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7499,6 +7727,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7632,10 +7865,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -7920,10 +8163,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -8191,6 +8444,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -8223,6 +8483,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8306,6 +8573,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -8359,6 +8633,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8377,6 +8658,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -8487,8 +8780,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8531,7 +8824,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9078,6 +9370,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -9173,6 +9472,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9211,6 +9517,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9287,6 +9600,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9393,6 +9713,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -9450,6 +9777,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9495,6 +9829,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9695,6 +10036,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -9727,6 +10075,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/config/crd/bases/actions.summerwind.dev_runners.yaml b/config/crd/bases/actions.summerwind.dev_runners.yaml index 938f1813..5f9d8a29 100644 --- a/config/crd/bases/actions.summerwind.dev_runners.yaml +++ b/config/crd/bases/actions.summerwind.dev_runners.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: runners.actions.summerwind.dev spec: group: actions.summerwind.dev @@ -1010,7 +1010,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1265,6 +1267,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1371,6 +1378,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1449,6 +1461,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1503,6 +1522,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1655,6 +1679,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1709,6 +1740,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2147,6 +2183,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2201,6 +2244,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2334,10 +2382,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2483,7 +2541,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -2616,10 +2676,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2765,7 +2835,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3001,7 +3073,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3252,6 +3326,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3358,6 +3437,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3432,6 +3516,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3486,6 +3577,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3626,6 +3722,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3680,6 +3783,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4087,6 +4195,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4141,6 +4256,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4283,10 +4403,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4472,7 +4602,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4727,6 +4859,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4833,6 +4970,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4911,6 +5053,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4965,6 +5114,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5117,6 +5271,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5171,6 +5332,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5609,6 +5775,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5663,6 +5836,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5796,10 +5974,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -6042,11 +6230,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6240,7 +6425,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -6495,6 +6682,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6601,6 +6793,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6679,6 +6876,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -6733,6 +6937,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -6885,6 +7094,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -6939,6 +7155,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7377,6 +7598,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -7431,6 +7659,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -7564,10 +7797,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -7852,10 +8095,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -8123,6 +8376,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -8155,6 +8415,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8238,6 +8505,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -8291,6 +8565,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8309,6 +8590,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -8419,8 +8712,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8463,7 +8756,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -9010,6 +9302,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -9105,6 +9404,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9143,6 +9449,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9219,6 +9532,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9325,6 +9645,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -9382,6 +9709,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -9427,6 +9761,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -9627,6 +9968,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -9659,6 +10007,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path diff --git a/config/crd/bases/actions.summerwind.dev_runnersets.yaml b/config/crd/bases/actions.summerwind.dev_runnersets.yaml index a510d0bd..b6637fb4 100644 --- a/config/crd/bases/actions.summerwind.dev_runnersets.yaml +++ b/config/crd/bases/actions.summerwind.dev_runnersets.yaml @@ -3,7 +3,7 @@ apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: - controller-gen.kubebuilder.io/version: v0.20.1 + controller-gen.kubebuilder.io/version: v0.22.0 name: runnersets.actions.summerwind.dev spec: group: actions.summerwind.dev @@ -1232,7 +1232,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -1487,6 +1489,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1593,6 +1600,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1671,6 +1683,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1725,6 +1744,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -1877,6 +1901,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -1931,6 +1962,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2369,6 +2405,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -2423,6 +2466,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -2556,10 +2604,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -2767,7 +2825,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -3018,6 +3078,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3124,6 +3189,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3198,6 +3268,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3252,6 +3329,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3392,6 +3474,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3446,6 +3535,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -3853,6 +3947,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -3907,6 +4008,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4049,10 +4155,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -4124,6 +4240,63 @@ spec: x-kubernetes-list-map-keys: - name x-kubernetes-list-type: map + evictionResponders: + description: |- + evictionResponders reference responders that react to Evictions based on EvictionRequests. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful termination of a pod. The responders are selected sequentially, according to + their specified priority. + + Responders should periodically report on an eviction progress by updating the + .status.responders[].heartbeatTime field of the Eviction object. If this field is not updated + within the heartbeat deadline defined by the Eviction API (currently 20 minutes), the eviction + is passed over to the next responder with a lower priority. If there is no other responder, + the last default imperative-eviction.k8s.io/evictor responder with a priority of 100 will + evict the pod using the imperative Eviction API (pods//eviction subresource). + + The maximum length of the responders list is 10. + Responders are not supported when the pod is part of a PodGroup (.spec.schedulingGroup is set). + This field can only be set on creation and is immutable afterwards. + items: + description: |- + EvictionResponder allows you to specify the responder reacting to an Eviction. + Responders should observe and communicate through the Eviction Resource API to help with + the graceful eviction of a target (e.g. termination of a pod). + properties: + name: + description: |- + name allows you to identify the responder responding to the Eviction. + + It must be a valid domain-prefixed key (such as "acme.io/foo"). + Domain names *.k8s.io and *.kubernetes.io are reserved. + This field must be unique for each responder. + This field is required. + type: string + priority: + description: |- + priority for this responder. Higher priorities are selected first by the evictionrequest-controller. + If there are responders with the same priority, the responder whose domain name comes first in the + alphabetical higher domain order, will be picked. This means that the top domain labels are compared + alphabetically first, followed by the lower domain labels. The key is compared last. + + The responder that is the managing controller of the pod should set the value of + this field to 10000 to allow both for preemption or fallback registration by other + responders. + + The minimum value is 0 and the maximum value is 100000. + The interval 0-999 is reserved for responders with *.k8s.io suffix. + This field is required. + format: int32 + type: integer + required: + - name + - priority + type: object + x-kubernetes-map-type: atomic + type: array + x-kubernetes-list-map-keys: + - name + x-kubernetes-list-type: map hostAliases: description: |- HostAliases is an optional list of hosts and IPs that will be injected into the pod's hosts @@ -4194,7 +4367,6 @@ spec: - `hostNetwork` must be set to false. This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64 characters. - Requires the HostnameOverride feature gate to be enabled. type: string imagePullSecrets: description: |- @@ -4298,7 +4470,9 @@ spec: description: Selects a key of a ConfigMap. properties: key: - description: The key to select. + description: |- + The key to select from the ConfigMap's Data field. + Keys in the BinaryData field are not currently propagated to container env vars. type: string name: default: "" @@ -4553,6 +4727,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4659,6 +4838,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4737,6 +4921,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4791,6 +4982,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -4943,6 +5139,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -4997,6 +5200,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5435,6 +5643,13 @@ spec: grpc: description: GRPC specifies a GRPC HealthCheckRequest. properties: + mode: + description: |- + mode specifies the connection mode for the gRPC health probe. + Set to "TLS" to use TLS without certificate verification. + Set to "Plaintext" to use a plaintext (insecure) connection explicitly. + If not specified, the probe uses a plaintext (insecure) connection. + type: string port: description: Port number of the gRPC service. Number must be in the range 1 to 65535. format: int32 @@ -5489,6 +5704,11 @@ spec: Number must be in the range 1 to 65535. Name must be an IANA_SVC_NAME. x-kubernetes-int-or-string: true + protocol: + description: |- + Protocol selects the wire protocol for the probe connection. + Nil defaults to HTTP/1.1. + type: string scheme: description: |- Scheme to use for connecting to the host. @@ -5622,10 +5842,20 @@ spec: items: description: VolumeMount describes a mounting of a Volume within a container. properties: - mountPath: + bindMountOptions: description: |- - Path within the container at which the volume should be mounted. Must - not contain ':'. + bindMountOptions is the list of additional bind mount options to apply when + mounting this volume into the container. Allowed values are noexec, + nodev, and nosuid. These are Linux mount options and have no effect on + Windows nodes. + This field is not supported with image volumes. + This is an alpha field and requires enabling the VolumeBindMountOptions feature gate. + items: + type: string + type: array + x-kubernetes-list-type: set + mountPath: + description: Path within the container at which the volume should be mounted. type: string mountPropagation: description: |- @@ -5779,6 +6009,8 @@ spec: description: |- PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never, PreemptLowerPriority. + When Priority Admission Controller is enabled, it prevents users from setting + this field. The admission controller populates this field from PriorityClassName. Defaults to PreemptLowerPriority if unset. type: string priority: @@ -6117,11 +6349,8 @@ spec: Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. - "MountOption" value is allowed only when SELinuxMount feature gate is enabled. - If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. - If not specified and SELinuxMount feature gate is disabled, "MountOption" is used for ReadWriteOncePod volumes - and "Recursive" for all other volumes. + If not specified, "MountOption" is used. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. @@ -6720,6 +6949,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items if unspecified, each key-value pair in the Data field of the referenced @@ -6752,6 +6988,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -6835,6 +7078,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: Items is a list of downward API volume file items: @@ -6888,6 +7138,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -6906,6 +7163,18 @@ spec: Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir type: string + mode: + description: |- + mode specifies the permission bits for the emptyDir directory, in numeric + notation (e.g., 0755, 01777). Must be a value between 0000 and 01777. + If not specified, defaults to 0777. + This might be in conflict with other options that affect the file + mode, like fsGroup. If fsGroup is specified, the fsGroup permissions + will override the mode specified here. + This field has no effect on Windows. + This field is alpha and requires EmptyDirVolumeMode featuregate to be enabled. + format: int32 + type: integer sizeLimit: anyOf: - type: integer @@ -7016,8 +7285,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -7060,7 +7329,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -7607,6 +7875,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer sources: description: |- sources is the list of volume projections. Each entry in this list @@ -7702,6 +7977,13 @@ spec: Mutually-exclusive with name. The contents of all selected ClusterTrustBundles will be unified and deduplicated. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7740,6 +8022,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -7816,6 +8105,13 @@ spec: - resource type: object x-kubernetes-map-type: atomic + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -7922,6 +8218,13 @@ spec: signerName: description: Kubelet's generated CSRs will be addressed to this signer. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer userAnnotations: additionalProperties: type: string @@ -7979,6 +8282,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8024,6 +8334,13 @@ spec: path is the path relative to the mount point of the file to project the token into. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - path type: object @@ -8224,6 +8541,13 @@ spec: mode, like fsGroup, and the result can be other mode bits set. format: int32 type: integer + defaultUser: + description: |- + defaultUser is Optional: The owner UID of the created files by default. + The defaultUser field is only used as a fallback when the item-level user field is unset. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer items: description: |- items If unspecified, each key-value pair in the Data field of the referenced @@ -8256,6 +8580,13 @@ spec: May not contain the path element '..'. May not start with the string '..'. type: string + user: + description: |- + user is Optional: The owner UID of the created file. + If specified, the item-level user field takes precedence over defaultUser. + (Alpha) This field requires the AtomicWriteVolumeUserFields feature gate to be enabled. + format: int64 + type: integer required: - key - path @@ -8458,8 +8789,8 @@ spec: * An existing PVC (PersistentVolumeClaim) If the provisioner or an external controller can support the specified data source, it will create a new volume based on the contents of the specified data source. - When the AnyVolumeDataSource feature gate is enabled, dataSource contents will be copied to dataSourceRef, - and dataSourceRef contents will be copied to dataSource when dataSourceRef.namespace is not specified. + dataSource contents will be copied to dataSourceRef, and dataSourceRef contents will be + copied to dataSource when dataSourceRef.namespace is not specified. If the namespace is specified, then dataSourceRef will not be copied to dataSource. properties: apiGroup: @@ -8502,7 +8833,6 @@ spec: specified. * While dataSource only allows local objects, dataSourceRef allows objects in any namespaces. - (Beta) Using this field requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource feature gate to be enabled. properties: apiGroup: @@ -8721,6 +9051,56 @@ spec: currentVolumeAttributesClassName is the current name of the VolumeAttributesClass the PVC is using. When unset, there is no VolumeAttributeClass applied to this PersistentVolumeClaim type: string + healthStatus: + description: |- + healthStatus contains the latest controller-reported health information + for the volume bound to this claim. + properties: + healthConditions: + description: |- + conditions is the set of adverse conditions reported by + the CSI controller plugin. An empty list means no adverse condition. + At most 16 conditions may be reported. + items: + description: VolumeHealthCondition represents an adverse health condition reported for a volume. + properties: + message: + description: |- + message is a human-readable description. + Maximum permitted length of a message is 1024 bytes. + type: string + reason: + description: |- + reason is a brief CamelCase machine-parseable reason. + Together with status it forms the unique identity of a condition entry. + Maximum permitted length of a reason is 256 bytes. + type: string + status: + description: |- + status is the machine-parseable health category. + Possible values: + - "Inaccessible": the volume cannot be accessed. + - "DataLoss": data loss has been detected on the volume. + - "Degraded": the volume is functioning with reduced capability. + enum: + - DataLoss + - Degraded + - Inaccessible + type: string + required: + - reason + - status + type: object + type: array + x-kubernetes-list-map-keys: + - status + - reason + x-kubernetes-list-type: map + lastTransitionTime: + description: lastTransitionTime is when the current set of conditions first appeared. + format: date-time + type: string + type: object modifyVolumeStatus: description: |- ModifyVolumeStatus represents the status object of ControllerModifyVolume operation. diff --git a/controllers/actions.github.com/autoscalinglistener_controller.go b/controllers/actions.github.com/autoscalinglistener_controller.go index f232484e..4764c014 100644 --- a/controllers/actions.github.com/autoscalinglistener_controller.go +++ b/controllers/actions.github.com/autoscalinglistener_controller.go @@ -46,6 +46,11 @@ import ( const ( autoscalingListenerContainerName = "listener" autoscalingListenerFinalizerName = "autoscalinglistener.actions.github.com/finalizer" + + // listenerSecretFinalizerPollInterval is how often cleanup checks back on + // a listener secret that a foreign finalizer keeps from going away. + // Secrets are not watched, so that is the one wait no event ends. + listenerSecretFinalizerPollInterval = 500 * time.Millisecond ) // AutoscalingListenerReconciler reconciles a AutoscalingListener object @@ -87,14 +92,14 @@ func (r *AutoscalingListenerReconciler) Reconcile(ctx context.Context, req ctrl. } log.Info("Deleting resources") - requeue, err := r.cleanupResources(ctx, &autoscalingListener, log) + done, requeueAfter, err := r.cleanupResources(ctx, &autoscalingListener, log) if err != nil { log.Error(err, "Failed to cleanup resources after deletion") return ctrl.Result{}, err } - if requeue { + if !done { log.Info("Waiting for resources to be deleted before removing finalizer") - return ctrl.Result{Requeue: true, RequeueAfter: time.Second}, nil + return ctrl.Result{RequeueAfter: requeueAfter}, nil } log.Info("Removing finalizer") @@ -155,13 +160,13 @@ func (r *AutoscalingListenerReconciler) Reconcile(ctx context.Context, req ctrl. // through to the regular reconcile below, which rebuilds the children. if autoscalingListener.Spec.Phase.Stopped() { log.Info("Listener is stopped, cleaning up its resources") - requeue, err := r.cleanupResources(ctx, &autoscalingListener, log) + done, requeueAfter, err := r.cleanupResources(ctx, &autoscalingListener, log) if err != nil { log.Error(err, "Failed to clean up the resources of a stopped listener") return ctrl.Result{}, err } - if requeue { - return ctrl.Result{RequeueAfter: time.Second}, nil + if !done { + return ctrl.Result{RequeueAfter: requeueAfter}, nil } log.Info("Listener is stopped and all of its resources are cleaned up") @@ -205,7 +210,11 @@ func (r *AutoscalingListenerReconciler) Reconcile(ctx context.Context, req ctrl. return ctrl.Result{}, err } - return ctrl.Result{Requeue: true}, nil + // The service account is owned and watched, so the update event + // brings the next reconcile, and it is guaranteed to see the + // patched object in the cache. A timed requeue could only fire + // before that event and act on a stale cache. + return ctrl.Result{}, nil } case kerrors.IsNotFound(err): // Create a service account for the listener pod in the controller namespace @@ -250,7 +259,8 @@ func (r *AutoscalingListenerReconciler) Reconcile(ctx context.Context, req ctrl. log.Error(err, "Failed to update listener role") return ctrl.Result{}, err } - return ctrl.Result{Requeue: true}, nil + // Roles are watched by label, the update event brings us back. + return ctrl.Result{}, nil } case kerrors.IsNotFound(err): // Create a role for the listener pod in the AutoScalingRunnerSet namespace @@ -290,7 +300,8 @@ func (r *AutoscalingListenerReconciler) Reconcile(ctx context.Context, req ctrl. } log.Info("Updated listener role binding") - return ctrl.Result{Requeue: true}, nil + // Role bindings are watched by label, the update event brings us back. + return ctrl.Result{}, nil } case kerrors.IsNotFound(err): @@ -343,12 +354,18 @@ func (r *AutoscalingListenerReconciler) Reconcile(ctx context.Context, req ctrl. log.Error(err, "Failed to update listener proxy secret") return ctrl.Result{}, err } - return ctrl.Result{Requeue: true}, nil + // Secrets are not watched, so nothing would bring us back. + // The listener pod only references the proxy secret by name, + // so carry on in the same reconcile. } case kerrors.IsNotFound(err): // Create a mirror secret for the listener pod in the Controller namespace for listener pod to use log.Info("Creating a listener proxy secret for the listener pod") - return r.createProxySecret(ctx, &autoscalingListener, log) + if err := r.createProxySecret(ctx, &autoscalingListener, log); err != nil { + return ctrl.Result{}, err + } + // Secrets are not watched and reads of them bypass the cache, so + // carry on in the same reconcile instead of requeueing. default: // error log.Error(err, "Unable to get listener proxy secret", "namespace", autoscalingListener.Namespace, "name", proxyListenerSecretName(&autoscalingListener)) return ctrl.Result{}, err @@ -433,7 +450,11 @@ func (r *AutoscalingListenerReconciler) Reconcile(ctx context.Context, req ctrl. if err := r.Patch(ctx, updatedSecret, client.MergeFrom(&listenerConfigSecret)); err != nil { return ctrl.Result{}, fmt.Errorf("failed to update listener config secret: %w", err) } - return ctrl.Result{Requeue: true}, nil + // Secrets are not watched, so nothing would bring us back. The + // patch response carries the new resource version, which is what + // the listener pod is compared against below, so carry on with + // it in the same reconcile. + listenerConfigSecret = *updatedSecret } case kerrors.IsNotFound(err): cfg, err := getAppConfig() @@ -458,8 +479,11 @@ func (r *AutoscalingListenerReconciler) Reconcile(ctx context.Context, req ctrl. return ctrl.Result{}, fmt.Errorf("failed to create listener config secret: %w", err) } - // Requeue to create listener pod with the config secret - return ctrl.Result{Requeue: true}, nil + // The secret create does not enqueue another reconcile, since secrets + // are not watched. The create response carries the resource version + // the listener pod is built against, so carry on with it in the same + // reconcile instead of requeueing. + listenerConfigSecret = *desiredSecret default: log.Error(err, "Unable to get listener config secret", "namespace", autoscalingListener.Namespace, "name", scaleSetListenerConfigName(&autoscalingListener)) return ctrl.Result{}, err @@ -606,7 +630,18 @@ func (r *AutoscalingListenerReconciler) deleteListenerPod(ctx context.Context, a return nil } -func (r *AutoscalingListenerReconciler) cleanupResources(ctx context.Context, autoscalingListener *v1alpha1.AutoscalingListener, logger logr.Logger) (requeue bool, err error) { +// cleanupResources deletes everything the listener owns and reports whether +// all of it is gone. When it is not, requeueAfter says how the caller should +// wait for the rest. +// +// The pod, service account, role and role binding are watched, so their +// delete events wake the reconciler the moment they are gone, and waiting on +// them needs no requeue at all. A timed requeue would only add reconciles +// that find the pod still terminating. Secrets are not watched, so a secret +// that a foreign finalizer holds is the one wait that needs a timed requeue. +func (r *AutoscalingListenerReconciler) cleanupResources(ctx context.Context, autoscalingListener *v1alpha1.AutoscalingListener, logger logr.Logger) (done bool, requeueAfter time.Duration, err error) { + var waitingOnWatched, waitingOnSecret bool + logger.Info("Cleaning up the listener pod") listenerPod := new(corev1.Pod) err = r.Get(ctx, types.NamespacedName{Name: autoscalingListener.Name, Namespace: autoscalingListener.Namespace}, listenerPod) @@ -614,15 +649,15 @@ func (r *AutoscalingListenerReconciler) cleanupResources(ctx context.Context, au case err == nil: if listenerPod.DeletionTimestamp.IsZero() { logger.Info("Deleting the listener pod") - if err := r.Delete(ctx, listenerPod); err != nil { - return false, fmt.Errorf("failed to delete listener pod: %w", err) + if err := r.Delete(ctx, listenerPod); client.IgnoreNotFound(err) != nil { + return false, 0, fmt.Errorf("failed to delete listener pod: %w", err) } } - requeue = true + waitingOnWatched = true case kerrors.IsNotFound(err): _ = r.publishRunningListener(autoscalingListener, false) // If error is returned, we never published metrics so it is safe to ignore default: - return false, fmt.Errorf("failed to get listener pods: %w", err) + return false, 0, fmt.Errorf("failed to get listener pods: %w", err) } logger.Info("Listener pod is deleted") @@ -630,15 +665,16 @@ func (r *AutoscalingListenerReconciler) cleanupResources(ctx context.Context, au err = r.Get(ctx, types.NamespacedName{Namespace: autoscalingListener.Namespace, Name: scaleSetListenerConfigName(autoscalingListener)}, &secret) switch { case err == nil: - if secret.DeletionTimestamp.IsZero() { - logger.Info("Deleting the listener config secret") - if err := r.Delete(ctx, &secret); err != nil { - return false, fmt.Errorf("failed to delete listener config secret: %w", err) - } + logger.Info("Deleting the listener config secret") + gone, err := r.deleteUnwatchedSecret(ctx, &secret) + if err != nil { + return false, 0, fmt.Errorf("failed to delete listener config secret: %w", err) + } + if !gone { + waitingOnSecret = true } - requeue = true case !kerrors.IsNotFound(err): - return false, fmt.Errorf("failed to get listener config secret: %w", err) + return false, 0, fmt.Errorf("failed to get listener config secret: %w", err) } // The proxy secret is deleted whatever the current spec says about a proxy. @@ -653,15 +689,16 @@ func (r *AutoscalingListenerReconciler) cleanupResources(ctx context.Context, au err = r.Get(ctx, types.NamespacedName{Name: proxyListenerSecretName(autoscalingListener), Namespace: autoscalingListener.Namespace}, proxySecret) switch { case err == nil: - if proxySecret.DeletionTimestamp.IsZero() { - logger.Info("Deleting the listener proxy secret") - if err := r.Delete(ctx, proxySecret); err != nil { - return false, fmt.Errorf("failed to delete listener proxy secret: %w", err) - } + logger.Info("Deleting the listener proxy secret") + gone, err := r.deleteUnwatchedSecret(ctx, proxySecret) + if err != nil { + return false, 0, fmt.Errorf("failed to delete listener proxy secret: %w", err) + } + if !gone { + waitingOnSecret = true } - requeue = true case !kerrors.IsNotFound(err): - return false, fmt.Errorf("failed to get listener proxy secret: %w", err) + return false, 0, fmt.Errorf("failed to get listener proxy secret: %w", err) } logger.Info("Listener proxy secret is deleted") @@ -671,13 +708,13 @@ func (r *AutoscalingListenerReconciler) cleanupResources(ctx context.Context, au case err == nil: if listenerRoleBinding.DeletionTimestamp.IsZero() { logger.Info("Deleting the listener role binding") - if err := r.Delete(ctx, listenerRoleBinding); err != nil { - return false, fmt.Errorf("failed to delete listener role binding: %w", err) + if err := r.Delete(ctx, listenerRoleBinding); client.IgnoreNotFound(err) != nil { + return false, 0, fmt.Errorf("failed to delete listener role binding: %w", err) } } - requeue = true + waitingOnWatched = true case !kerrors.IsNotFound(err): - return false, fmt.Errorf("failed to get listener role binding: %w", err) + return false, 0, fmt.Errorf("failed to get listener role binding: %w", err) } logger.Info("Listener role binding is deleted") @@ -687,13 +724,13 @@ func (r *AutoscalingListenerReconciler) cleanupResources(ctx context.Context, au case err == nil: if listenerRole.DeletionTimestamp.IsZero() { logger.Info("Deleting the listener role") - if err := r.Delete(ctx, listenerRole); err != nil { - return false, fmt.Errorf("failed to delete listener role: %w", err) + if err := r.Delete(ctx, listenerRole); client.IgnoreNotFound(err) != nil { + return false, 0, fmt.Errorf("failed to delete listener role: %w", err) } } - requeue = true + waitingOnWatched = true case !kerrors.IsNotFound(err): - return false, fmt.Errorf("failed to get listener role: %w", err) + return false, 0, fmt.Errorf("failed to get listener role: %w", err) } logger.Info("Listener role is deleted") @@ -704,17 +741,46 @@ func (r *AutoscalingListenerReconciler) cleanupResources(ctx context.Context, au case err == nil: if listenerSa.DeletionTimestamp.IsZero() { logger.Info("Deleting the listener service account") - if err := r.Delete(ctx, listenerSa); err != nil { - return false, fmt.Errorf("failed to delete listener service account: %w", err) + if err := r.Delete(ctx, listenerSa); client.IgnoreNotFound(err) != nil { + return false, 0, fmt.Errorf("failed to delete listener service account: %w", err) } } - requeue = true + waitingOnWatched = true case !kerrors.IsNotFound(err): - return false, fmt.Errorf("failed to get listener service account: %w", err) + return false, 0, fmt.Errorf("failed to get listener service account: %w", err) } logger.Info("Listener service account is deleted") - return requeue, nil + switch { + case waitingOnSecret: + return false, listenerSecretFinalizerPollInterval, nil + case waitingOnWatched: + return false, 0, nil + default: + return true, 0, nil + } +} + +// deleteUnwatchedSecret deletes a secret the listener controller does not +// watch and reports whether it is gone. +// +// Secrets are not watched, so no event would wake the reconciler once they +// disappear, and waiting on one would need a timed requeue. Secrets are not +// deleted gracefully though: without finalizers the delete removes the object +// before the call returns, so it is only worth waiting on a secret something +// else holds with a finalizer. Reads of secrets bypass the cache, so the +// object passed in is fresh. +func (r *AutoscalingListenerReconciler) deleteUnwatchedSecret(ctx context.Context, secret *corev1.Secret) (gone bool, err error) { + if secret.DeletionTimestamp.IsZero() { + if err := r.Delete(ctx, secret); err != nil { + if kerrors.IsNotFound(err) { + return true, nil + } + return false, err + } + } + + return len(secret.Finalizers) == 0, nil } func (r *AutoscalingListenerReconciler) createServiceAccountForListener(ctx context.Context, autoscalingListener *v1alpha1.AutoscalingListener, logger logr.Logger) (ctrl.Result, error) { @@ -731,6 +797,7 @@ func (r *AutoscalingListenerReconciler) createServiceAccountForListener(ctx cont } logger.Info("Created listener service accounts", "namespace", newServiceAccount.Namespace, "name", newServiceAccount.Name) + // The create event of the owned service account brings the next reconcile. return ctrl.Result{}, nil } @@ -772,7 +839,7 @@ func (r *AutoscalingListenerReconciler) certificate(ctx context.Context, autosca return certificate, nil } -func (r *AutoscalingListenerReconciler) createProxySecret(ctx context.Context, autoscalingListener *v1alpha1.AutoscalingListener, logger logr.Logger) (ctrl.Result, error) { +func (r *AutoscalingListenerReconciler) createProxySecret(ctx context.Context, autoscalingListener *v1alpha1.AutoscalingListener, logger logr.Logger) error { data, err := autoscalingListener.Spec.Proxy.ToSecretData(func(s string) (*corev1.Secret, error) { var secret corev1.Secret err := r.Get(ctx, types.NamespacedName{Name: s, Namespace: autoscalingListener.Spec.AutoscalingRunnerSetNamespace}, &secret) @@ -782,23 +849,23 @@ func (r *AutoscalingListenerReconciler) createProxySecret(ctx context.Context, a return &secret, nil }) if err != nil { - return ctrl.Result{}, fmt.Errorf("failed to convert proxy config to secret data: %w", err) + return fmt.Errorf("failed to convert proxy config to secret data: %w", err) } newProxySecret, err := r.newAutoscalingListenerProxySecret(autoscalingListener, data) if err != nil { - return ctrl.Result{}, fmt.Errorf("failed to build listener proxy secret: %w", err) + return fmt.Errorf("failed to build listener proxy secret: %w", err) } logger.Info("Creating listener proxy secret", "namespace", newProxySecret.Namespace, "name", newProxySecret.Name) if err := r.Create(ctx, newProxySecret); err != nil { logger.Error(err, "Unable to create listener secret", "namespace", newProxySecret.Namespace, "name", newProxySecret.Name) - return ctrl.Result{}, err + return err } logger.Info("Created listener proxy secret", "namespace", newProxySecret.Namespace, "name", newProxySecret.Name) - return ctrl.Result{Requeue: true}, nil + return nil } func (r *AutoscalingListenerReconciler) createRoleForListener(ctx context.Context, autoscalingListener *v1alpha1.AutoscalingListener, logger logr.Logger) (ctrl.Result, error) { @@ -812,7 +879,8 @@ func (r *AutoscalingListenerReconciler) createRoleForListener(ctx context.Contex } logger.Info("Created listener role", "namespace", newRole.Namespace, "name", newRole.Name, "rules", newRole.Rules) - return ctrl.Result{Requeue: true}, nil + // The create event of the labeled role brings the next reconcile. + return ctrl.Result{}, nil } func (r *AutoscalingListenerReconciler) createRoleBindingForListener(ctx context.Context, autoscalingListener *v1alpha1.AutoscalingListener, listenerRole *rbacv1.Role, serviceAccount *corev1.ServiceAccount, logger logr.Logger) (ctrl.Result, error) { @@ -841,7 +909,8 @@ func (r *AutoscalingListenerReconciler) createRoleBindingForListener(ctx context "role", listenerRole.Name, "serviceAccountNamespace", serviceAccount.Namespace, "serviceAccount", serviceAccount.Name) - return ctrl.Result{Requeue: true}, nil + // The create event of the labeled role binding brings the next reconcile. + return ctrl.Result{}, nil } func (r *AutoscalingListenerReconciler) publishRunningListener(autoscalingListener *v1alpha1.AutoscalingListener, isUp bool) error { diff --git a/controllers/actions.github.com/autoscalinglistener_proxy_cleanup_test.go b/controllers/actions.github.com/autoscalinglistener_proxy_cleanup_test.go index 5cfea802..16f96345 100644 --- a/controllers/actions.github.com/autoscalinglistener_proxy_cleanup_test.go +++ b/controllers/actions.github.com/autoscalinglistener_proxy_cleanup_test.go @@ -63,8 +63,12 @@ func TestCleanupResourcesDeletesTheProxySecretWithoutAskingTheSpec(t *testing.T) Log: logr.Discard(), } - _, err := reconciler.cleanupResources(context.Background(), listener, logr.Discard()) + done, requeueAfter, err := reconciler.cleanupResources(context.Background(), listener, logr.Discard()) require.NoError(t, err) + // Secrets are not watched, so cleanup must not wait on one it has just + // deleted: without finalizers it is gone before the delete returns. + require.True(t, done, "a secret without finalizers is gone once the delete returns, there is nothing to wait for") + require.Zero(t, requeueAfter) err = fakeClient.Get( context.Background(), diff --git a/controllers/actions.github.com/autoscalinglistener_requeue_bench_test.go b/controllers/actions.github.com/autoscalinglistener_requeue_bench_test.go new file mode 100644 index 00000000..c5de6552 --- /dev/null +++ b/controllers/actions.github.com/autoscalinglistener_requeue_bench_test.go @@ -0,0 +1,756 @@ +package actionsgithubcom + +import ( + "context" + "fmt" + "maps" + "net/http" + "os" + "path/filepath" + "slices" + "strconv" + "strings" + "sync" + "sync/atomic" + "testing" + "time" + + "github.com/go-logr/logr" + "github.com/stretchr/testify/require" + "golang.org/x/sync/errgroup" + corev1 "k8s.io/api/core/v1" + kerrors "k8s.io/apimachinery/pkg/api/errors" + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/apimachinery/pkg/types" + "k8s.io/client-go/kubernetes/scheme" + "k8s.io/client-go/rest" + "k8s.io/utils/ptr" + ctrl "sigs.k8s.io/controller-runtime" + "sigs.k8s.io/controller-runtime/pkg/cache" + "sigs.k8s.io/controller-runtime/pkg/client" + "sigs.k8s.io/controller-runtime/pkg/config" + "sigs.k8s.io/controller-runtime/pkg/controller" + "sigs.k8s.io/controller-runtime/pkg/controller/controllerutil" + "sigs.k8s.io/controller-runtime/pkg/envtest" + logf "sigs.k8s.io/controller-runtime/pkg/log" + crmetrics "sigs.k8s.io/controller-runtime/pkg/metrics" + metricsserver "sigs.k8s.io/controller-runtime/pkg/metrics/server" + + "github.com/actions/actions-runner-controller/apis/actions.github.com/v1alpha1" + scalefake "github.com/actions/actions-runner-controller/controllers/actions.github.com/multiclient/fake" + "github.com/actions/actions-runner-controller/controllers/actions.github.com/secretresolver" +) + +// TestListenerRequeueBench drives the real AutoscalingListener controller +// against envtest and measures, per lifecycle phase, how long the listener +// takes to converge and how many reconciles it spends doing it. +// +// It is opt-in: ARC_LISTENER_BENCH=1. +// +// envtest has no kubelet, so a pod with no node is deleted immediately. To +// model a listener pod running out its termination grace period, the bench +// holds pods with a finalizer and releases it after a fixed hold. +func TestListenerRequeueBench(t *testing.T) { + if os.Getenv("ARC_LISTENER_BENCH") == "" { + t.Skip("set ARC_LISTENER_BENCH=1 to run") + } + logf.SetLogger(logr.Discard()) + + env := &envtest.Environment{ + CRDDirectoryPaths: []string{filepath.Join("../..", "config", "crd", "bases")}, + } + restCfg, err := env.Start() + require.NoError(t, err) + t.Cleanup(func() { _ = env.Stop() }) + require.NoError(t, v1alpha1.AddToScheme(scheme.Scheme)) + + // The observer must not be what limits the measurement: no client-side + // rate limiting, and one List per poll rather than a Get per listener. + adminCfg := rest.CopyConfig(restCfg) + adminCfg.QPS = -1 + admin, err := client.New(adminCfg, client.Options{Scheme: scheme.Scheme}) + require.NoError(t, err) + + variant := os.Getenv("ARC_LISTENER_BENCH_VARIANT") + reps := benchEnvInt("ARC_LISTENER_BENCH_REPS", 5) + large := benchEnvInt("ARC_LISTENER_BENCH_N", 25) + + for _, n := range []int{1, large} { + agg := newBenchAggregate() + runs := reps + if n > 1 { + runs = 1 + } + for range runs { + runListenerBench(t, restCfg, admin, n, agg) + } + agg.print(t, variant, n) + } +} + +const ( + benchHold = 5 * time.Second + benchSecretHold = 2 * time.Second + benchSettle = 2500 * time.Millisecond + benchTimeout = 60 * time.Second + benchPoll = 2 * time.Millisecond + benchPodHoldFinalizer = "bench.actions.github.com/hold" +) + +// --------------------------------------------------------------------------- +// Recording client: attributes every reconcile, and every write it makes, by +// the reconcile ID controller-runtime puts in the context. + +type benchReconcile struct { + listener string + start time.Time + writes int + alreadyExists int + notFound int +} + +type benchRecorder struct { + mu sync.Mutex + recs map[types.UID]*benchReconcile +} + +func (r *benchRecorder) begin(ctx context.Context, listener string) { + id := controller.ReconcileIDFromContext(ctx) + if id == "" { + return + } + r.mu.Lock() + defer r.mu.Unlock() + if _, ok := r.recs[id]; !ok { + r.recs[id] = &benchReconcile{listener: listener, start: time.Now()} + } +} + +func (r *benchRecorder) write(ctx context.Context, err error) { + id := controller.ReconcileIDFromContext(ctx) + if id == "" { + return + } + r.mu.Lock() + defer r.mu.Unlock() + rec, ok := r.recs[id] + if !ok { + return + } + rec.writes++ + switch { + case kerrors.IsAlreadyExists(err): + rec.alreadyExists++ + case kerrors.IsNotFound(err): + rec.notFound++ + } +} + +type benchWindow struct { + reconciles int + noWrite int + alreadyExists int + notFound int +} + +func (r *benchRecorder) window(listeners map[string]struct{}, from, to time.Time) benchWindow { + r.mu.Lock() + defer r.mu.Unlock() + var w benchWindow + for _, rec := range r.recs { + if _, ok := listeners[rec.listener]; !ok { + continue + } + if rec.start.Before(from) || !rec.start.Before(to) { + continue + } + w.reconciles++ + if rec.writes == 0 { + w.noWrite++ + } + w.alreadyExists += rec.alreadyExists + w.notFound += rec.notFound + } + return w +} + +type benchClient struct { + client.Client + rec *benchRecorder +} + +func (c benchClient) Get(ctx context.Context, key client.ObjectKey, obj client.Object, opts ...client.GetOption) error { + if _, ok := obj.(*v1alpha1.AutoscalingListener); ok { + c.rec.begin(ctx, key.Name) + } + return c.Client.Get(ctx, key, obj, opts...) +} + +func (c benchClient) Create(ctx context.Context, obj client.Object, opts ...client.CreateOption) error { + err := c.Client.Create(ctx, obj, opts...) + c.rec.write(ctx, err) + return err +} + +func (c benchClient) Update(ctx context.Context, obj client.Object, opts ...client.UpdateOption) error { + err := c.Client.Update(ctx, obj, opts...) + c.rec.write(ctx, err) + return err +} + +func (c benchClient) Patch(ctx context.Context, obj client.Object, patch client.Patch, opts ...client.PatchOption) error { + err := c.Client.Patch(ctx, obj, patch, opts...) + c.rec.write(ctx, err) + return err +} + +func (c benchClient) Delete(ctx context.Context, obj client.Object, opts ...client.DeleteOption) error { + err := c.Client.Delete(ctx, obj, opts...) + c.rec.write(ctx, err) + return err +} + +// --------------------------------------------------------------------------- +// API server requests the controller's manager sends, informer LIST/WATCH +// excluded, so what is left is what the reconciler itself costs: live secret +// reads and writes. Under the shipped client rate limit this is what queues. + +type benchRequests struct{ n atomic.Int64 } + +func (c *benchRequests) wrap(rt http.RoundTripper) http.RoundTripper { + return benchRoundTripper{rt: rt, c: c} +} + +type benchRoundTripper struct { + rt http.RoundTripper + c *benchRequests +} + +func (r benchRoundTripper) RoundTrip(req *http.Request) (*http.Response, error) { + q := req.URL.Query() + isInformer := q.Get("watch") == "true" || (req.Method == http.MethodGet && q.Has("resourceVersion") && !strings.Contains(req.URL.Path, "/secrets/")) + if !isInformer { + r.c.n.Add(1) + } + return r.rt.RoundTrip(req) +} + +// --------------------------------------------------------------------------- +// controller-runtime's own per-result counters, for the requeue breakdown. + +func benchReconcileResults(t *testing.T) map[string]float64 { + families, err := crmetrics.Registry.Gather() + require.NoError(t, err) + out := map[string]float64{} + for _, f := range families { + if f.GetName() != "controller_runtime_reconcile_total" { + continue + } + for _, m := range f.GetMetric() { + var ctrlName, result string + for _, l := range m.GetLabel() { + switch l.GetName() { + case "controller": + ctrlName = l.GetValue() + case "result": + result = l.GetValue() + } + } + if ctrlName == "autoscalinglistener" { + out[result] = m.GetCounter().GetValue() + } + } + } + return out +} + +func benchResultsDelta(before, after map[string]float64) map[string]float64 { + out := map[string]float64{} + for k, v := range after { + if d := v - before[k]; d != 0 { + out[k] = d + } + } + return out +} + +// --------------------------------------------------------------------------- +// Aggregation. + +type benchScenario struct { + samples int + requests int64 + latencies []time.Duration + windows []benchWindow + results map[string]float64 +} + +type benchAggregate struct { + order []string + scenarios map[string]*benchScenario +} + +func newBenchAggregate() *benchAggregate { + return &benchAggregate{scenarios: map[string]*benchScenario{}} +} + +func (a *benchAggregate) get(name string) *benchScenario { + s, ok := a.scenarios[name] + if !ok { + s = &benchScenario{results: map[string]float64{}} + a.scenarios[name] = s + a.order = append(a.order, name) + } + return s +} + +func (a *benchAggregate) add(name string, listeners int, requests int64, lat []time.Duration, w benchWindow, results map[string]float64) { + s := a.get(name) + s.samples += listeners + s.requests += requests + s.latencies = append(s.latencies, lat...) + s.windows = append(s.windows, w) + for k, v := range results { + s.results[k] += v + } +} + +func benchPct(d []time.Duration, p float64) time.Duration { + if len(d) == 0 { + return 0 + } + s := slices.Clone(d) + slices.Sort(s) + i := int(float64(len(s)-1) * p) + return s[i] +} + +func (a *benchAggregate) print(t *testing.T, variant string, n int) { + for _, name := range a.order { + s := a.scenarios[name] + var total benchWindow + for _, w := range s.windows { + total.reconciles += w.reconciles + total.noWrite += w.noWrite + total.alreadyExists += w.alreadyExists + total.notFound += w.notFound + } + perListener := func(v int) string { + return strconv.FormatFloat(float64(v)/float64(s.samples), 'f', 1, 64) + } + keys := slices.Sorted(maps.Keys(s.results)) + var res []string + for _, k := range keys { + res = append(res, fmt.Sprintf("%s=%s", k, strconv.FormatFloat(s.results[k]/float64(s.samples), 'f', 1, 64))) + } + lat := "-" + if len(s.latencies) > 0 { + lat = fmt.Sprintf("p50=%v p95=%v max=%v", + benchPct(s.latencies, 0.5).Round(time.Millisecond), + benchPct(s.latencies, 0.95).Round(time.Millisecond), + benchPct(s.latencies, 1).Round(time.Millisecond)) + } + t.Logf("BENCH variant=%s n=%d scenario=%-26s latency[%s] reconciles/listener=%s noWrite/listener=%s apiRequests/listener=%s alreadyExists=%d notFound=%d results/listener[%s]", + variant, n, name, lat, + perListener(total.reconciles), perListener(total.noWrite), perListener(int(s.requests)), + total.alreadyExists, total.notFound, strings.Join(res, " ")) + } +} + +// --------------------------------------------------------------------------- +// One run: fresh namespace, fresh manager, three groups of n listeners. + +func runListenerBench(t *testing.T, restCfg *rest.Config, admin client.Client, n int, agg *benchAggregate) { + ctx := context.Background() + + ns := &corev1.Namespace{ObjectMeta: metav1.ObjectMeta{Name: "bench-" + strings.ToLower(RandStringRunes(6))}} + require.NoError(t, admin.Create(ctx, ns)) + defer func() { _ = admin.Delete(ctx, ns) }() + + // Production manager settings that matter here: secrets and config maps + // are read live, and the listener runs with its shipped concurrency. + // The controller gets the client rate limits it ships with (main.go). + mgrCfg := rest.CopyConfig(restCfg) + mgrCfg.QPS = 20 + mgrCfg.Burst = 30 + requests := &benchRequests{} + mgrCfg.WrapTransport = requests.wrap + mgr, err := ctrl.NewManager(mgrCfg, ctrl.Options{ + Controller: config.Controller{SkipNameValidation: ptr.To(true)}, + Metrics: metricsserver.Options{BindAddress: "0"}, + Cache: cache.Options{ + DefaultNamespaces: map[string]cache.Config{ns.Name: {}}, + }, + Client: client.Options{ + Cache: &client.CacheOptions{ + DisableFor: []client.Object{&corev1.Secret{}, &corev1.ConfigMap{}}, + }, + }, + }) + require.NoError(t, err) + require.NoError(t, SetupIndexers(mgr)) + + rec := &benchRecorder{recs: map[types.UID]*benchReconcile{}} + rc := NewResourceCache() + reconciler := &AutoscalingListenerReconciler{ + Client: benchClient{Client: mgr.GetClient(), rec: rec}, + Scheme: mgr.GetScheme(), + Log: logr.Discard(), + ResourceBuilder: ResourceBuilder{ + ResourceCache: &rc, + SecretResolver: secretresolver.New(mgr.GetClient(), scalefake.NewMultiClient()), + }, + } + require.NoError(t, reconciler.SetupWithManager(mgr, WithMaxConcurrentReconciles(OptionsWithDefault().AutoscalingListenerMaxConcurrentReconciles))) + + mgrCtx, cancel := context.WithCancel(ctx) + g, gctx := errgroup.WithContext(mgrCtx) + g.Go(func() error { return mgr.Start(gctx) }) + defer func() { + cancel() + _ = g.Wait() + }() + require.True(t, mgr.GetCache().WaitForCacheSync(ctx)) + + ghSecret := &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{Name: "github-config-secret", Namespace: ns.Name}, + Data: map[string][]byte{"github_token": []byte(defaultGitHubToken)}, + } + require.NoError(t, admin.Create(ctx, ghSecret)) + + minR, maxR := 1, 10 + ars := &v1alpha1.AutoscalingRunnerSet{ + ObjectMeta: metav1.ObjectMeta{Name: "bench-ars", Namespace: ns.Name}, + Spec: v1alpha1.AutoscalingRunnerSetSpec{ + GitHubConfigUrl: "https://github.com/owner/repo", + GitHubConfigSecret: ghSecret.Name, + MaxRunners: &maxR, + MinRunners: &minR, + Template: corev1.PodTemplateSpec{Spec: corev1.PodSpec{ + Containers: []corev1.Container{{Name: "runner", Image: "ghcr.io/actions/runner"}}, + }}, + }, + } + require.NoError(t, admin.Create(ctx, ars)) + + b := &listenerBench{t: t, admin: admin, rec: rec, requests: requests, ns: ns.Name, ars: ars, agg: agg, n: n} + + // Group A: setup, update, stop with the pod held. + a := b.setup("a", n) + b.update(a) + b.stopHeld(a) + + // Group B: setup, delete with the pod held. + bb := b.setup("b", n) + b.deleteHeld(bb) + + // Group C: setup, delete with the config secret held by a foreign finalizer. + c := b.setup("c", n) + b.deleteSecretHeld(c) +} + +type listenerBench struct { + t *testing.T + admin client.Client + rec *benchRecorder + requests *benchRequests + n int + ns string + ars *v1alpha1.AutoscalingRunnerSet + agg *benchAggregate + reqMark int64 +} + +type benchGroup struct { + listeners []*v1alpha1.AutoscalingListener + names map[string]struct{} +} + +func (b *listenerBench) record(name string, group *benchGroup, lat []time.Duration, from, to time.Time, before map[string]float64) { + w := b.rec.window(group.names, from, to) + now := b.requests.n.Load() + b.agg.add(name, len(group.listeners), now-b.reqMark, lat, w, benchResultsDelta(before, benchReconcileResults(b.t))) + b.reqMark = now +} + +// mark starts a new request-count window. Anything between the previous +// record and the mark (setup of the next scenario) is not attributed. +func (b *listenerBench) mark() { b.reqMark = b.requests.n.Load() } + +// hold is how long a pod or secret is held. It has to outlast the +// controller's first cleanup pass over every listener, which is bound by the +// client rate limit at larger n, or the window never sees steady-state waiting. +func (b *listenerBench) hold(base time.Duration) time.Duration { + return max(base, time.Duration(b.n)*800*time.Millisecond) +} + +func (b *listenerBench) newListener(name string) *v1alpha1.AutoscalingListener { + return &v1alpha1.AutoscalingListener{ + ObjectMeta: metav1.ObjectMeta{Name: name, Namespace: b.ns}, + Spec: v1alpha1.AutoscalingListenerSpec{ + GitHubConfigURL: "https://github.com/owner/repo", + GitHubConfigSecret: "github-config-secret", + RunnerScaleSetID: 1, + AutoscalingRunnerSetNamespace: b.ars.Namespace, + AutoscalingRunnerSetName: b.ars.Name, + EphemeralRunnerSetName: "bench-ers", + MaxRunners: 10, + MinRunners: 1, + Image: "ghcr.io/owner/repo", + ServiceAccountMetadata: &v1alpha1.ResourceMeta{Annotations: map[string]string{"bench/sa": "initial"}}, + RoleMetadata: &v1alpha1.ResourceMeta{Annotations: map[string]string{"bench/role": "initial"}}, + RoleBindingMetadata: &v1alpha1.ResourceMeta{Annotations: map[string]string{"bench/rb": "initial"}}, + }, + } +} + +// waitAll polls until done reports true for every listener, and returns the +// time each one first did, measured from start. snapshot runs once per poll +// and returns the predicate to evaluate against that single read. +func (b *listenerBench) waitAll(group *benchGroup, start time.Time, snapshot func() func(l *v1alpha1.AutoscalingListener) bool) []time.Duration { + lat := make([]time.Duration, len(group.listeners)) + pending := map[int]struct{}{} + for i := range group.listeners { + pending[i] = struct{}{} + } + deadline := time.Now().Add(benchTimeout) + for len(pending) > 0 { + done := snapshot() + now := time.Since(start) + for i := range pending { + if done(group.listeners[i]) { + lat[i] = now + delete(pending, i) + } + } + if time.Now().After(deadline) { + b.t.Errorf("timed out with %d listeners not converged", len(pending)) + return nil + } + time.Sleep(benchPoll) + } + return lat +} + +func (b *listenerBench) pods() map[string]*corev1.Pod { + var list corev1.PodList + require.NoError(b.t, b.admin.List(context.Background(), &list, client.InNamespace(b.ns))) + out := make(map[string]*corev1.Pod, len(list.Items)) + for i := range list.Items { + out[list.Items[i].Name] = &list.Items[i] + } + return out +} + +func (b *listenerBench) listeners() map[string]struct{} { + var list v1alpha1.AutoscalingListenerList + require.NoError(b.t, b.admin.List(context.Background(), &list, client.InNamespace(b.ns))) + out := make(map[string]struct{}, len(list.Items)) + for i := range list.Items { + out[list.Items[i].Name] = struct{}{} + } + return out +} + +func (b *listenerBench) pod(l *v1alpha1.AutoscalingListener) (*corev1.Pod, bool) { + pod := new(corev1.Pod) + if err := b.admin.Get(context.Background(), client.ObjectKey{Namespace: b.ns, Name: l.Name}, pod); err != nil { + return nil, false + } + return pod, true +} + +func (b *listenerBench) setup(prefix string, n int) *benchGroup { + ctx := context.Background() + group := &benchGroup{names: map[string]struct{}{}} + for i := range n { + l := b.newListener(fmt.Sprintf("%s-%d", prefix, i)) + group.listeners = append(group.listeners, l) + group.names[l.Name] = struct{}{} + } + + b.mark() + before := benchReconcileResults(b.t) + start := time.Now() + for _, l := range group.listeners { + require.NoError(b.t, b.admin.Create(ctx, l)) + } + lat := b.waitAll(group, start, func() func(l *v1alpha1.AutoscalingListener) bool { + pods := b.pods() + return func(l *v1alpha1.AutoscalingListener) bool { + _, ok := pods[l.Name] + return ok + } + }) + if b.n == 1 { + b.t.Logf("BENCHRAW setup group=%s latency=%v", prefix, lat) + } + time.Sleep(benchSettle) + b.record("setup (create→pod)", group, lat, start, time.Now(), before) + return group +} + +func (b *listenerBench) update(group *benchGroup) { + ctx := context.Background() + oldPods := map[string]*corev1.Pod{} + for _, l := range group.listeners { + pod, ok := b.pod(l) + require.True(b.t, ok) + oldPods[l.Name] = pod + } + + b.mark() + before := benchReconcileResults(b.t) + start := time.Now() + for _, l := range group.listeners { + current := new(v1alpha1.AutoscalingListener) + require.NoError(b.t, b.admin.Get(ctx, client.ObjectKeyFromObject(l), current)) + original := current.DeepCopy() + current.Spec.MaxRunners = 20 + current.Spec.ServiceAccountMetadata.Annotations["bench/sa"] = "updated" + current.Spec.RoleMetadata.Annotations["bench/role"] = "updated" + current.Spec.RoleBindingMetadata.Annotations["bench/rb"] = "updated" + require.NoError(b.t, b.admin.Patch(ctx, current, client.MergeFrom(original))) + } + lat := b.waitAll(group, start, func() func(l *v1alpha1.AutoscalingListener) bool { + pods := b.pods() + return func(l *v1alpha1.AutoscalingListener) bool { + pod, ok := pods[l.Name] + if !ok || pod.UID == oldPods[l.Name].UID { + return false + } + return pod.Annotations[AnnotationKeyListenerConfigResourceVersion] != oldPods[l.Name].Annotations[AnnotationKeyListenerConfigResourceVersion] + } + }) + time.Sleep(benchSettle) + b.record("update (patch→new pod)", group, lat, start, time.Now(), before) +} + +func (b *listenerBench) holdPods(group *benchGroup) { + ctx := context.Background() + for _, l := range group.listeners { + pod, ok := b.pod(l) + require.True(b.t, ok) + original := pod.DeepCopy() + controllerutil.AddFinalizer(pod, benchPodHoldFinalizer) + require.NoError(b.t, b.admin.Patch(ctx, pod, client.MergeFrom(original))) + } + // Let the finalizer's own update event play out, outside any window. + time.Sleep(benchSettle) +} + +func (b *listenerBench) releasePods(group *benchGroup) { + ctx := context.Background() + for _, l := range group.listeners { + pod, ok := b.pod(l) + if !ok { + continue + } + original := pod.DeepCopy() + controllerutil.RemoveFinalizer(pod, benchPodHoldFinalizer) + require.NoError(b.t, client.IgnoreNotFound(b.admin.Patch(ctx, pod, client.MergeFrom(original)))) + } +} + +func (b *listenerBench) stopHeld(group *benchGroup) { + ctx := context.Background() + b.holdPods(group) + + b.mark() + before := benchReconcileResults(b.t) + start := time.Now() + for _, l := range group.listeners { + current := new(v1alpha1.AutoscalingListener) + require.NoError(b.t, b.admin.Get(ctx, client.ObjectKeyFromObject(l), current)) + original := current.DeepCopy() + current.Spec.Phase = v1alpha1.AutoscalingListenerPhaseStopped + require.NoError(b.t, b.admin.Patch(ctx, current, client.MergeFrom(original))) + } + time.Sleep(b.hold(benchHold)) + released := time.Now() + b.record("stop: pod terminating", group, nil, start, released, before) + + before = benchReconcileResults(b.t) + b.releasePods(group) + lat := b.waitAll(group, released, func() func(l *v1alpha1.AutoscalingListener) bool { + pods := b.pods() + return func(l *v1alpha1.AutoscalingListener) bool { + _, ok := pods[l.Name] + return !ok + } + }) + time.Sleep(benchSettle) + b.record("stop: after pod gone", group, lat, released, time.Now(), before) +} + +func (b *listenerBench) listenerGone() func(l *v1alpha1.AutoscalingListener) bool { + present := b.listeners() + return func(l *v1alpha1.AutoscalingListener) bool { + _, ok := present[l.Name] + return !ok + } +} + +func (b *listenerBench) deleteHeld(group *benchGroup) { + ctx := context.Background() + b.holdPods(group) + + b.mark() + before := benchReconcileResults(b.t) + start := time.Now() + for _, l := range group.listeners { + require.NoError(b.t, b.admin.Delete(ctx, l)) + } + time.Sleep(b.hold(benchHold)) + released := time.Now() + b.record("delete: pod terminating", group, nil, start, released, before) + + before = benchReconcileResults(b.t) + b.releasePods(group) + lat := b.waitAll(group, released, b.listenerGone) + time.Sleep(benchSettle) + b.record("delete: pod gone→gone", group, lat, released, time.Now(), before) +} + +func (b *listenerBench) deleteSecretHeld(group *benchGroup) { + ctx := context.Background() + secretFor := func(l *v1alpha1.AutoscalingListener) client.ObjectKey { + return client.ObjectKey{Namespace: b.ns, Name: scaleSetListenerConfigName(l)} + } + + b.mark() + before := benchReconcileResults(b.t) + start := time.Now() + for _, l := range group.listeners { + secret := new(corev1.Secret) + require.NoError(b.t, b.admin.Get(ctx, secretFor(l), secret)) + original := secret.DeepCopy() + controllerutil.AddFinalizer(secret, benchPodHoldFinalizer) + require.NoError(b.t, b.admin.Patch(ctx, secret, client.MergeFrom(original))) + require.NoError(b.t, b.admin.Delete(ctx, l)) + } + time.Sleep(b.hold(benchSecretHold)) + released := time.Now() + b.record("delete: secret held", group, nil, start, released, before) + + before = benchReconcileResults(b.t) + for _, l := range group.listeners { + secret := new(corev1.Secret) + if err := b.admin.Get(ctx, secretFor(l), secret); err != nil { + continue + } + original := secret.DeepCopy() + controllerutil.RemoveFinalizer(secret, benchPodHoldFinalizer) + require.NoError(b.t, client.IgnoreNotFound(b.admin.Patch(ctx, secret, client.MergeFrom(original)))) + } + lat := b.waitAll(group, released, b.listenerGone) + time.Sleep(benchSettle) + b.record("delete: secret freed→gone", group, lat, released, time.Now(), before) +} + +func benchEnvInt(name string, def int) int { + if v, err := strconv.Atoi(os.Getenv(name)); err == nil && v > 0 { + return v + } + return def +} diff --git a/controllers/actions.github.com/ephemeralrunner_controller.go b/controllers/actions.github.com/ephemeralrunner_controller.go index 8416b270..8c5fb738 100644 --- a/controllers/actions.github.com/ephemeralrunner_controller.go +++ b/controllers/actions.github.com/ephemeralrunner_controller.go @@ -291,7 +291,7 @@ func (r *EphemeralRunnerReconciler) Reconcile(ctx context.Context, req ctrl.Requ case errors.Is(err, retryableError): log.Info("Encountered retryable error, requeueing", "error", err.Error()) - return ctrl.Result{Requeue: true}, nil + return ctrl.Result{RequeueAfter: 500 * time.Millisecond}, nil case errors.Is(err, fatalError): log.Info("JIT config cannot be created for this ephemeral runner, issuing delete", "error", err.Error()) if err := r.Delete(ctx, &ephemeralRunner); err != nil { @@ -315,7 +315,7 @@ func (r *EphemeralRunnerReconciler) Reconcile(ctx context.Context, req ctrl.Requ return ctrl.Result{}, fmt.Errorf("failed to delete the corrupted runner config secret") } log.Info("Corrupted runner config secret has been deleted") - return ctrl.Result{Requeue: true}, nil + return ctrl.Result{RequeueAfter: 500 * time.Millisecond}, nil } runnerName := string(secret.Data["runnerName"]) @@ -351,8 +351,10 @@ func (r *EphemeralRunnerReconciler) Reconcile(ctx context.Context, req ctrl.Requ "nextReconciliation", nextReconciliation, "requeueAfter", requeueAfter, ) + if requeueAfter <= 0 { + requeueAfter = time.Millisecond + } return ctrl.Result{ - Requeue: true, RequeueAfter: requeueAfter, }, nil } @@ -371,7 +373,7 @@ func (r *EphemeralRunnerReconciler) Reconcile(ctx context.Context, req ctrl.Requ return result, nil case kerrors.IsAlreadyExists(err): log.Info("Runner pod already exists. Waiting for the pod event to be received") - return ctrl.Result{Requeue: true, RequeueAfter: 5 * time.Second}, nil + return ctrl.Result{RequeueAfter: 5 * time.Second}, nil case kerrors.IsInvalid(err): log.Error(err, "Failed to create a pod due to unrecoverable failure") errMessage := fmt.Sprintf("Failed to create the pod: %v", err) diff --git a/controllers/actions.github.com/ephemeralrunnerset_controller.go b/controllers/actions.github.com/ephemeralrunnerset_controller.go index c671ad3b..957d7da9 100644 --- a/controllers/actions.github.com/ephemeralrunnerset_controller.go +++ b/controllers/actions.github.com/ephemeralrunnerset_controller.go @@ -198,15 +198,14 @@ func (r *EphemeralRunnerSetReconciler) Reconcile(ctx context.Context, req ctrl.R return ctrl.Result{}, nil } - // Create or update proxy secret if needed - if _, updated, err := r.reconcileEphemeralRunnerSetProxySecret(ctx, &ephemeralRunnerSet, log); err != nil { + // Create or update proxy secret if needed. Secrets are not watched and + // runners only reference the proxy secret by name, so carry on in the same + // reconcile after writing it instead of delaying the scaling below. + if _, _, err := r.reconcileEphemeralRunnerSetProxySecret(ctx, &ephemeralRunnerSet, log); err != nil { log.Error(err, "Unable to reconcile ephemeralRunnerSet proxy secret", "namespace", ephemeralRunnerSet.Namespace, "name", proxyEphemeralRunnerSetSecretName(&ephemeralRunnerSet)) return ctrl.Result{}, err - } else if updated { - return ctrl.Result{RequeueAfter: 1 * time.Second}, nil } - // Find all EphemeralRunner with matching namespace and own by this EphemeralRunnerSet. var ephemeralRunnerList v1alpha1.EphemeralRunnerList if err := r.List( ctx, diff --git a/controllers/actions.summerwind.net/utils_test.go b/controllers/actions.summerwind.net/utils_test.go index 2f2234e6..2f0d57a6 100644 --- a/controllers/actions.summerwind.net/utils_test.go +++ b/controllers/actions.summerwind.net/utils_test.go @@ -121,7 +121,7 @@ func Test_workVolumeClaimTemplateV1VolumeMount(t *testing.T) { got := workVolumeClaimTemplate.V1VolumeMount(mountPath) - if want != got { + if !reflect.DeepEqual(want, got) { t.Fatalf("expected volume mount %+v, actual %+v\n", want, got) } } diff --git a/go.mod b/go.mod index 8543c4db..5f3abff4 100644 --- a/go.mod +++ b/go.mod @@ -1,43 +1,43 @@ module github.com/actions/actions-runner-controller -go 1.26.3 +go 1.27.1 require ( - github.com/Azure/azure-sdk-for-go/sdk/azcore v1.22.0 - github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.0 + github.com/Azure/azure-sdk-for-go/sdk/azcore v1.23.1 + github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.1 github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/azsecrets v1.5.0 github.com/actions/scaleset v0.4.1-0.20260706130337-9b2803251ede github.com/bradleyfalzon/ghinstallation/v2 v2.19.0 github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc github.com/evanphx/json-patch v5.9.11+incompatible - github.com/go-logr/logr v1.4.3 + github.com/go-logr/logr v1.4.4 github.com/google/go-cmp v0.7.0 github.com/google/go-github/v52 v52.0.0 github.com/google/uuid v1.6.0 github.com/gorilla/mux v1.8.1 github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 - github.com/gruntwork-io/terratest v1.0.0 + github.com/gruntwork-io/terratest v1.0.1 github.com/hashicorp/go-retryablehttp v0.7.8 github.com/kelseyhightower/envconfig v1.4.0 github.com/onsi/ginkgo v1.16.5 - github.com/onsi/ginkgo/v2 v2.31.0 - github.com/onsi/gomega v1.42.0 - github.com/prometheus/client_golang v1.23.2 - github.com/prometheus/client_model v0.6.2 - github.com/stretchr/testify v1.11.1 + github.com/onsi/ginkgo/v2 v2.33.0 + github.com/onsi/gomega v1.43.1 + github.com/prometheus/client_golang v1.24.1 + github.com/prometheus/client_model v0.6.3 + github.com/stretchr/testify v1.12.1 github.com/teambition/rrule-go v1.8.2 go.uber.org/multierr v1.11.0 go.uber.org/zap v1.28.0 - golang.org/x/net v0.55.0 - golang.org/x/oauth2 v0.36.0 - golang.org/x/sync v0.21.0 + golang.org/x/net v0.59.0 + golang.org/x/oauth2 v0.37.0 + golang.org/x/sync v0.23.0 gomodules.xyz/jsonpatch/v2 v2.5.0 gopkg.in/yaml.v2 v2.4.0 - k8s.io/api v0.36.2 - k8s.io/apimachinery v0.36.2 - k8s.io/client-go v0.36.2 - k8s.io/utils v0.0.0-20260210185600-b8788abfbbc2 - sigs.k8s.io/controller-runtime v0.24.1 + k8s.io/api v0.37.0 + k8s.io/apimachinery v0.37.0 + k8s.io/client-go v0.37.0 + k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 + sigs.k8s.io/controller-runtime v0.25.1 sigs.k8s.io/yaml v1.6.0 ) @@ -45,101 +45,116 @@ require ( filippo.io/edwards25519 v1.2.0 // indirect github.com/Azure/azure-sdk-for-go/sdk/internal v1.12.0 // indirect github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 // indirect - github.com/AzureAD/microsoft-authentication-library-for-go v1.7.2 // indirect + github.com/AzureAD/microsoft-authentication-library-for-go v1.9.0 // indirect github.com/BurntSushi/toml v1.6.0 // indirect - github.com/Masterminds/semver/v3 v3.4.0 // indirect - github.com/ProtonMail/go-crypto v1.4.0 // indirect - github.com/aws/aws-sdk-go-v2 v1.41.6 // indirect - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.9 // indirect - github.com/aws/aws-sdk-go-v2/config v1.32.16 // indirect - github.com/aws/aws-sdk-go-v2/credentials v1.19.15 // indirect - github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.22 // indirect - github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.1.17 // indirect - github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.22 // indirect - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.22 // indirect - github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.23 // indirect - github.com/aws/aws-sdk-go-v2/service/acm v1.38.2 // indirect - github.com/aws/aws-sdk-go-v2/service/autoscaling v1.66.1 // indirect - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.69.1 // indirect - github.com/aws/aws-sdk-go-v2/service/dynamodb v1.57.2 // indirect - github.com/aws/aws-sdk-go-v2/service/ec2 v1.297.1 // indirect - github.com/aws/aws-sdk-go-v2/service/ecr v1.57.1 // indirect - github.com/aws/aws-sdk-go-v2/service/ecs v1.78.1 // indirect - github.com/aws/aws-sdk-go-v2/service/iam v1.53.8 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.8 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.14 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.11.22 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.22 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.22 // indirect - github.com/aws/aws-sdk-go-v2/service/kms v1.50.5 // indirect - github.com/aws/aws-sdk-go-v2/service/lambda v1.89.1 // indirect - github.com/aws/aws-sdk-go-v2/service/rds v1.118.1 // indirect - github.com/aws/aws-sdk-go-v2/service/route53 v1.62.6 // indirect - github.com/aws/aws-sdk-go-v2/service/s3 v1.99.1 // indirect - github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.41.6 // indirect - github.com/aws/aws-sdk-go-v2/service/signin v1.0.10 // indirect - github.com/aws/aws-sdk-go-v2/service/sns v1.39.16 // indirect - github.com/aws/aws-sdk-go-v2/service/sqs v1.42.26 // indirect - github.com/aws/aws-sdk-go-v2/service/ssm v1.68.5 // indirect - github.com/aws/aws-sdk-go-v2/service/sso v1.30.16 // indirect - github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.20 // indirect - github.com/aws/aws-sdk-go-v2/service/sts v1.42.0 // indirect - github.com/aws/smithy-go v1.25.0 // indirect + github.com/Masterminds/semver/v3 v3.5.0 // indirect + github.com/ProtonMail/go-crypto v1.4.1 // indirect + github.com/a8m/envsubst v1.4.3 // indirect + github.com/agext/levenshtein v1.2.3 // indirect + github.com/alecthomas/participle/v2 v2.1.4 // indirect + github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect + github.com/apparentlymart/go-textseg/v17 v17.0.1 // indirect + github.com/aws/aws-sdk-go-v2 v1.47.0 // indirect + github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20 // indirect + github.com/aws/aws-sdk-go-v2/config v1.33.5 // indirect + github.com/aws/aws-sdk-go-v2/credentials v1.20.5 // indirect + github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.20.0 // indirect + github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.4.8 // indirect + github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.3 // indirect + github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.3 // indirect + github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.3 // indirect + github.com/aws/aws-sdk-go-v2/service/acm v1.50.0 // indirect + github.com/aws/aws-sdk-go-v2/service/autoscaling v1.78.0 // indirect + github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.88.0 // indirect + github.com/aws/aws-sdk-go-v2/service/dynamodb v1.69.0 // indirect + github.com/aws/aws-sdk-go-v2/service/ec2 v1.335.0 // indirect + github.com/aws/aws-sdk-go-v2/service/ecr v1.66.0 // indirect + github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.47.0 // indirect + github.com/aws/aws-sdk-go-v2/service/ecs v1.99.0 // indirect + github.com/aws/aws-sdk-go-v2/service/iam v1.64.0 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.11.3 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.13.3 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.3 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.20.3 // indirect + github.com/aws/aws-sdk-go-v2/service/kms v1.61.0 // indirect + github.com/aws/aws-sdk-go-v2/service/lambda v1.109.0 // indirect + github.com/aws/aws-sdk-go-v2/service/rds v1.129.0 // indirect + github.com/aws/aws-sdk-go-v2/service/route53 v1.70.0 // indirect + github.com/aws/aws-sdk-go-v2/service/s3 v1.113.2 // indirect + github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.50.0 // indirect + github.com/aws/aws-sdk-go-v2/service/signin v1.10.0 // indirect + github.com/aws/aws-sdk-go-v2/service/sns v1.47.1 // indirect + github.com/aws/aws-sdk-go-v2/service/sqs v1.52.0 // indirect + github.com/aws/aws-sdk-go-v2/service/ssm v1.78.0 // indirect + github.com/aws/aws-sdk-go-v2/service/sso v1.38.0 // indirect + github.com/aws/aws-sdk-go-v2/service/ssooidc v1.43.0 // indirect + github.com/aws/aws-sdk-go-v2/service/sts v1.51.0 // indirect + github.com/aws/smithy-go v1.28.2 // indirect github.com/beorn7/perks v1.0.1 // indirect github.com/boombuler/barcode v1.1.0 // indirect github.com/brunoga/deep v1.2.4 // indirect github.com/cespare/xxhash/v2 v2.3.0 // indirect - github.com/cloudflare/circl v1.6.3 // indirect + github.com/cloudflare/circl v1.6.5 // indirect github.com/cpuguy83/go-md2man/v2 v2.0.7 // indirect + github.com/dimchansky/utfbom v1.1.1 // indirect + github.com/elliotchance/orderedmap v1.8.0 // indirect github.com/emicklei/go-restful/v3 v3.13.0 // indirect github.com/evanphx/json-patch/v5 v5.9.11 // indirect + github.com/fatih/color v1.19.0 // indirect github.com/fatih/structs v1.1.0 // indirect - github.com/fsnotify/fsnotify v1.9.0 // indirect - github.com/fxamacker/cbor/v2 v2.9.0 // indirect + github.com/fsnotify/fsnotify v1.10.1 // indirect + github.com/fxamacker/cbor/v2 v2.9.4 // indirect github.com/go-errors/errors v1.5.1 // indirect + github.com/go-ini/ini v1.67.0 // indirect github.com/go-logr/zapr v1.3.0 // indirect - github.com/go-openapi/jsonpointer v0.22.5 // indirect - github.com/go-openapi/jsonreference v0.21.5 // indirect - github.com/go-openapi/swag v0.25.5 // indirect - github.com/go-openapi/swag/cmdutils v0.25.5 // indirect - github.com/go-openapi/swag/conv v0.25.5 // indirect - github.com/go-openapi/swag/fileutils v0.25.5 // indirect - github.com/go-openapi/swag/jsonname v0.25.5 // indirect - github.com/go-openapi/swag/jsonutils v0.25.5 // indirect - github.com/go-openapi/swag/loading v0.25.5 // indirect - github.com/go-openapi/swag/mangling v0.25.5 // indirect - github.com/go-openapi/swag/netutils v0.25.5 // indirect - github.com/go-openapi/swag/stringutils v0.25.5 // indirect - github.com/go-openapi/swag/typeutils v0.25.5 // indirect - github.com/go-openapi/swag/yamlutils v0.25.5 // indirect - github.com/go-sql-driver/mysql v1.9.3 // indirect + github.com/go-openapi/jsonpointer v1.0.1 // indirect + github.com/go-openapi/jsonreference v1.0.2 // indirect + github.com/go-openapi/swag v0.29.2 // indirect + github.com/go-openapi/swag/cmdutils v0.29.2 // indirect + github.com/go-openapi/swag/conv v0.29.2 // indirect + github.com/go-openapi/swag/fileutils v0.29.2 // indirect + github.com/go-openapi/swag/jsonutils v0.29.2 // indirect + github.com/go-openapi/swag/loading v0.29.2 // indirect + github.com/go-openapi/swag/mangling v0.29.2 // indirect + github.com/go-openapi/swag/netutils v0.29.2 // indirect + github.com/go-openapi/swag/pools v0.29.2 // indirect + github.com/go-openapi/swag/stringutils v0.29.2 // indirect + github.com/go-openapi/swag/typeutils v0.29.2 // indirect + github.com/go-openapi/swag/yamlutils v0.29.2 // indirect + github.com/go-sql-driver/mysql v1.10.1 // indirect github.com/go-task/slim-sprig/v3 v3.0.0 // indirect github.com/go-viper/mapstructure/v2 v2.5.0 // indirect + github.com/gobuffalo/flect v1.0.3 // indirect + github.com/goccy/go-json v0.10.6 // indirect + github.com/goccy/go-yaml v1.19.2 // indirect github.com/golang-jwt/jwt/v4 v4.5.2 // indirect github.com/golang-jwt/jwt/v5 v5.3.1 // indirect github.com/gonvenience/bunt v1.4.3 // indirect github.com/gonvenience/idem v0.0.3 // indirect - github.com/gonvenience/neat v1.3.18 // indirect + github.com/gonvenience/neat v1.3.20 // indirect github.com/gonvenience/term v1.0.5 // indirect github.com/gonvenience/text v1.0.10 // indirect - github.com/gonvenience/ytbx v1.4.8 // indirect + github.com/gonvenience/ytbx v1.5.0 // indirect github.com/google/gnostic-models v0.7.1 // indirect github.com/google/go-github/v88 v88.0.0 // indirect github.com/google/go-querystring v1.2.0 // indirect - github.com/google/pprof v0.0.0-20260402051712-545e8a4df936 // indirect + github.com/google/pprof v0.0.0-20260906184651-6331bc6350fe // indirect github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect github.com/gruntwork-io/go-commons v0.17.2 // indirect github.com/hashicorp/errwrap v1.1.0 // indirect github.com/hashicorp/go-cleanhttp v0.5.2 // indirect github.com/hashicorp/go-multierror v1.1.1 // indirect - github.com/homeport/dyff v1.11.2 // indirect + github.com/hashicorp/hcl/v2 v2.24.0 // indirect + github.com/homeport/dyff v1.12.0 // indirect github.com/huandu/xstrings v1.5.0 // indirect github.com/inconshreveable/mousetrap v1.1.0 // indirect github.com/jackc/pgpassfile v1.0.0 // indirect github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 // indirect - github.com/jackc/pgx/v5 v5.9.0 // indirect + github.com/jackc/pgx/v5 v5.11.0 // indirect github.com/jackc/puddle/v2 v2.2.2 // indirect github.com/jedib0t/go-pretty/v6 v6.6.7 // indirect + github.com/jinzhu/copier v0.4.0 // indirect github.com/json-iterator/go v1.1.12 // indirect github.com/knadh/koanf/maps v0.1.2 // indirect github.com/knadh/koanf/parsers/yaml v0.1.0 // indirect @@ -149,29 +164,34 @@ require ( github.com/knadh/koanf/providers/structs v0.1.0 // indirect github.com/knadh/koanf/v2 v2.3.0 // indirect github.com/kylelemons/godebug v1.1.0 // indirect - github.com/lucasb-eyer/go-colorful v1.3.0 // indirect + github.com/lucasb-eyer/go-colorful v1.4.1 // indirect + github.com/magiconair/properties v1.18.11 // indirect github.com/mattn/go-ciede2000 v0.0.0-20170301095244-782e8c62fec3 // indirect github.com/mattn/go-colorable v0.1.14 // indirect - github.com/mattn/go-isatty v0.0.20 // indirect + github.com/mattn/go-isatty v0.0.24 // indirect github.com/mattn/go-runewidth v0.0.16 // indirect - github.com/mattn/go-zglob v0.0.6 // indirect + github.com/mattn/go-zglob v0.0.8 // indirect + github.com/mikefarah/yq/v4 v4.53.6 // indirect github.com/mitchellh/copystructure v1.2.0 // indirect github.com/mitchellh/go-ps v1.0.0 // indirect - github.com/mitchellh/hashstructure v1.1.0 // indirect + github.com/mitchellh/go-wordwrap v1.0.1 // indirect + github.com/mitchellh/hashstructure/v2 v2.0.2 // indirect github.com/mitchellh/reflectwalk v1.0.2 // indirect github.com/moby/spdystream v0.5.1 // indirect github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect github.com/modern-go/reflect2 v1.0.3-0.20250322232337-35a7c28c31ee // indirect github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect + github.com/pelletier/go-toml/v2 v2.4.3 // indirect github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c // indirect github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect github.com/pquerna/otp v1.5.0 // indirect - github.com/prometheus/common v0.67.5 // indirect - github.com/prometheus/procfs v0.20.1 // indirect + github.com/prometheus/common v0.71.0 // indirect + github.com/prometheus/procfs v0.22.0 // indirect github.com/rivo/uniseg v0.4.7 // indirect github.com/rs/zerolog v1.33.0 // indirect github.com/russross/blackfriday/v2 v2.1.0 // indirect github.com/sergi/go-diff v1.4.0 // indirect + github.com/spf13/afero v1.15.0 // indirect github.com/spf13/cobra v1.10.2 // indirect github.com/spf13/pflag v1.0.10 // indirect github.com/stretchr/objx v0.5.3 // indirect @@ -184,29 +204,41 @@ require ( github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect github.com/xeipuuv/gojsonschema v1.2.0 // indirect github.com/xrash/smetrics v0.0.0-20250705151800-55b8f293f342 // indirect + github.com/yuin/gopher-lua v1.1.2 // indirect + github.com/zclconf/go-cty v1.19.0 // indirect go.yaml.in/yaml/v2 v2.4.4 // indirect - go.yaml.in/yaml/v3 v3.0.4 // indirect - golang.org/x/crypto v0.52.0 // indirect - golang.org/x/exp v0.0.0-20260312153236-7ab1446f8b90 // indirect - golang.org/x/mod v0.35.0 // indirect - golang.org/x/sys v0.45.0 // indirect - golang.org/x/term v0.43.0 // indirect - golang.org/x/text v0.37.0 // indirect - golang.org/x/time v0.15.0 // indirect - golang.org/x/tools v0.44.0 // indirect - google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // indirect + go.yaml.in/yaml/v3 v3.0.5 // indirect + go.yaml.in/yaml/v4 v4.0.0-rc.6 // indirect + golang.org/x/crypto v0.57.0 // indirect + golang.org/x/exp v0.0.0-20260908205506-85c1c2202aba // indirect + golang.org/x/mod v0.41.0 // indirect + golang.org/x/sys v0.48.0 // indirect + golang.org/x/term v0.46.0 // indirect + golang.org/x/text v0.42.0 // indirect + golang.org/x/time v0.16.0 // indirect + golang.org/x/tools v0.50.0 // indirect + google.golang.org/protobuf v1.36.12 // indirect gopkg.in/evanphx/json-patch.v4 v4.13.0 // indirect gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect - k8s.io/apiextensions-apiserver v0.36.0 // indirect + k8s.io/apiextensions-apiserver v0.37.0 // indirect + k8s.io/code-generator v0.37.0 // indirect + k8s.io/gengo/v2 v2.0.0-20260408192533-25e2208e0dc3 // indirect k8s.io/klog/v2 v2.140.0 // indirect - k8s.io/kube-openapi v0.0.0-20260317180543-43fb72c5454a // indirect - k8s.io/streaming v0.36.2 // indirect - sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 // indirect + k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad // indirect + k8s.io/streaming v0.37.0 // indirect + sigs.k8s.io/controller-runtime/tools/setup-envtest v0.25.1 // indirect + sigs.k8s.io/controller-tools v0.22.0 // indirect + sigs.k8s.io/json v0.0.0-20260909141634-11ed52e25bc5 // indirect sigs.k8s.io/randfill v1.0.0 // indirect - sigs.k8s.io/structured-merge-diff/v6 v6.3.2 // indirect + sigs.k8s.io/structured-merge-diff/v6 v6.4.2 // indirect ) -tool github.com/vektra/mockery/v3 +tool ( + github.com/mikefarah/yq/v4 + github.com/vektra/mockery/v3 + sigs.k8s.io/controller-runtime/tools/setup-envtest + sigs.k8s.io/controller-tools/cmd/controller-gen +) replace github.com/gregjones/httpcache => github.com/actions-runner-controller/httpcache v0.2.0 diff --git a/go.sum b/go.sum index 76ed2e69..6cd5c0d5 100644 --- a/go.sum +++ b/go.sum @@ -1,9 +1,11 @@ +cel.dev/expr v0.25.1 h1:1KrZg61W6TWSxuNZ37Xy49ps13NUovb66QLprthtwi4= +cel.dev/expr v0.25.1/go.mod h1:hrXvqGP6G6gyx8UAHSHJ5RGk//1Oj5nXQ2NI02Nrsg4= filippo.io/edwards25519 v1.2.0 h1:crnVqOiS4jqYleHd9vaKZ+HKtHfllngJIiOpNpoJsjo= filippo.io/edwards25519 v1.2.0/go.mod h1:xzAOLCNug/yB62zG1bQ8uziwrIqIuxhctzJT18Q77mc= -github.com/Azure/azure-sdk-for-go/sdk/azcore v1.22.0 h1:aokoqcHvaGjiM3VpjKDfMMnF/8epJ+Q1HLJ7CudztqE= -github.com/Azure/azure-sdk-for-go/sdk/azcore v1.22.0/go.mod h1:/WYEx9pcM9Y+Dd/APJaNlSvVSvzl54rrMdZT5+Oi2LM= -github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.0 h1:CU4+EJeJi3TKYWEcYuSdWsjzw0nVsK/H0MSQOiPcymU= -github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.0/go.mod h1:q0+UTSRvShwUCrR/s5HtyInYphN7Wvxb7snFM3u+SLA= +github.com/Azure/azure-sdk-for-go/sdk/azcore v1.23.1 h1:zvXfGJCWvywnCA814d8ZiVyt+fm9nnTE8xSb99zRyfo= +github.com/Azure/azure-sdk-for-go/sdk/azcore v1.23.1/go.mod h1:iptorS+VYKFL2N6PnebpS91dubG35eAOEERnT4PJbQU= +github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.1 h1:u93s+zU2JD62im61Bm5CZIc1ZrOJaIAWEg0WOrMVkEo= +github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.14.1/go.mod h1:oXtinPO4OLj9d1DOTrqrL1oRwGhcqadvAmrl6wTeGlk= github.com/Azure/azure-sdk-for-go/sdk/azidentity/cache v0.4.0 h1:xFaZZ+IubdftrDHnGGwZ6QvQ3KHTtWl2MCK+GMt2vxs= github.com/Azure/azure-sdk-for-go/sdk/azidentity/cache v0.4.0/go.mod h1:mCBhUhlMjLLJKr5aqw2TNS/VqJOie8MzWq3DAMJeKso= github.com/Azure/azure-sdk-for-go/sdk/internal v1.12.0 h1:fhqpLE3UEXi9lPaBRpQ6XuRW0nU7hgg4zlmZZa+a9q4= @@ -14,94 +16,114 @@ github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0 h1:nCYfg github.com/Azure/azure-sdk-for-go/sdk/security/keyvault/internal v1.2.0/go.mod h1:ucUjca2JtSZboY8IoUqyQyuuXvwbMBVwFOm0vdQPNhA= github.com/AzureAD/microsoft-authentication-extensions-for-go/cache v0.1.1 h1:WJTmL004Abzc5wDB5VtZG2PJk5ndYDgVacGqfirKxjM= github.com/AzureAD/microsoft-authentication-extensions-for-go/cache v0.1.1/go.mod h1:tCcJZ0uHAmvjsVYzEFivsRTN00oz5BEsRgQHu5JZ9WE= -github.com/AzureAD/microsoft-authentication-library-for-go v1.7.2 h1:RHK7bS+HQMslb1sZpAokUt+zTVmue0hKSs2C791hhzU= -github.com/AzureAD/microsoft-authentication-library-for-go v1.7.2/go.mod h1:HKpQxkWaGLJ+D/5H8QRpyQXA1eKjxkFlOMwck5+33Jk= +github.com/AzureAD/microsoft-authentication-library-for-go v1.9.0 h1:MDT4FxAPve5FnYn6vOL1r7RCRDG+l9cI7a5LlCuHsqA= +github.com/AzureAD/microsoft-authentication-library-for-go v1.9.0/go.mod h1:Y33QHnf0FfdVewFFISOGe20mkZbxX4H839o955/PoeI= github.com/BurntSushi/toml v1.6.0 h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk= github.com/BurntSushi/toml v1.6.0/go.mod h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho= -github.com/Masterminds/semver/v3 v3.4.0 h1:Zog+i5UMtVoCU8oKka5P7i9q9HgrJeGzI9SA1Xbatp0= -github.com/Masterminds/semver/v3 v3.4.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= -github.com/ProtonMail/go-crypto v1.4.0 h1:Zq/pbM3F5DFgJiMouxEdSVY44MVoQNEKp5d5QxIQceQ= -github.com/ProtonMail/go-crypto v1.4.0/go.mod h1:e1OaTyu5SYVrO9gKOEhTc+5UcXtTUa+P3uLudwcgPqo= +github.com/Masterminds/semver/v3 v3.5.0 h1:kQceYJfbupGfZOKZQg0kou0DgAKhzDg2NZPAwZ/2OOE= +github.com/Masterminds/semver/v3 v3.5.0/go.mod h1:4V+yj/TJE1HU9XfppCwVMZq3I84lprf4nC11bSS5beM= +github.com/ProtonMail/go-crypto v1.4.1 h1:9RfcZHqEQUvP8RzecWEUafnZVtEvrBVL9BiF67IQOfM= +github.com/ProtonMail/go-crypto v1.4.1/go.mod h1:e1OaTyu5SYVrO9gKOEhTc+5UcXtTUa+P3uLudwcgPqo= +github.com/a8m/envsubst v1.4.3 h1:kDF7paGK8QACWYaQo6KtyYBozY2jhQrTuNNuUxQkhJY= +github.com/a8m/envsubst v1.4.3/go.mod h1:4jjHWQlZoaXPoLQUb7H2qT4iLkZDdmEQiOUogdUmqVU= github.com/actions-runner-controller/httpcache v0.2.0 h1:hCNvYuVPJ2xxYBymqBvH0hSiQpqz4PHF/LbU3XghGNI= github.com/actions-runner-controller/httpcache v0.2.0/go.mod h1:JLu9/2M/btPz1Zu/vTZ71XzukQHn2YeISPmJoM5exBI= github.com/actions/scaleset v0.4.1-0.20260706130337-9b2803251ede h1:75hCLFGd2GLYrFry4TpbBcEbIYZQ6NCHIl3Kd34IyOU= github.com/actions/scaleset v0.4.1-0.20260706130337-9b2803251ede/go.mod h1:+Ylz7IYPnOTJd8dZmMziJ7J9HEfZhdoH7iliEWSb/Ms= +github.com/agext/levenshtein v1.2.3 h1:YB2fHEn0UJagG8T1rrWknE3ZQzWM06O8AMAatNn7lmo= +github.com/agext/levenshtein v1.2.3/go.mod h1:JEDfjyjHDjOF/1e4FlBE/PkbqA9OfWu2ki2W0IB5558= +github.com/alecthomas/assert/v2 v2.11.0 h1:2Q9r3ki8+JYXvGsDyBXwH3LcJ+WK5D0gc5E8vS6K3D0= +github.com/alecthomas/assert/v2 v2.11.0/go.mod h1:Bze95FyfUr7x34QZrjL+XP+0qgp/zg8yS+TtBj1WA3k= +github.com/alecthomas/participle/v2 v2.1.4 h1:W/H79S8Sat/krZ3el6sQMvMaahJ+XcM9WSI2naI7w2U= +github.com/alecthomas/participle/v2 v2.1.4/go.mod h1:8tqVbpTX20Ru4NfYQgZf4mP18eXPTBViyMWiArNEgGI= +github.com/alecthomas/repr v0.5.4 h1:OVP7JEcuzU9CCDsT6STCr3rg17oQfWILtPWd2EG0uN4= +github.com/alecthomas/repr v0.5.4/go.mod h1:Fr0507jx4eOXV7AlPV6AVZLYrLIuIeSOWtW57eE/O/4= +github.com/antlr4-go/antlr/v4 v4.13.1 h1:SqQKkuVZ+zWkMMNkjy5FZe5mr5WURWnlpmOuzYWrPrQ= +github.com/antlr4-go/antlr/v4 v4.13.1/go.mod h1:GKmUxMtwp6ZgGwZSva4eWPC5mS6vUAmOABFgjdkM7Nw= +github.com/apparentlymart/go-textseg/v15 v15.0.0 h1:uYvfpb3DyLSCGWnctWKGj857c6ew1u1fNQOlOtuGxQY= +github.com/apparentlymart/go-textseg/v15 v15.0.0/go.mod h1:K8XmNZdhEBkdlyDdvbmmsvpAG721bKi0joRfFdHIWJ4= +github.com/apparentlymart/go-textseg/v17 v17.0.1 h1:bpMXRgQ5cEoRNuQke1a80/Nl6w3G5eoIbWo9f3gXkAs= +github.com/apparentlymart/go-textseg/v17 v17.0.1/go.mod h1:fa8X4jgGeevslICIY6LcdjkSecWnXmYd9Lk34z/VxZs= github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5 h1:0CwZNZbxp69SHPdPJAN/hZIm0C4OItdklCFmMRWYpio= github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5/go.mod h1:wHh0iHkYZB8zMSxRWpUBQtwG5a7fFgvEO+odwuTv2gs= -github.com/aws/aws-sdk-go-v2 v1.41.6 h1:1AX0AthnBQzMx1vbmir3Y4WsnJgiydmnJjiLu+LvXOg= -github.com/aws/aws-sdk-go-v2 v1.41.6/go.mod h1:dy0UzBIfwSeot4grGvY1AqFWN5zgziMmWGzysDnHFcQ= -github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.9 h1:adBsCIIpLbLmYnkQU+nAChU5yhVTvu5PerROm+/Kq2A= -github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.9/go.mod h1:uOYhgfgThm/ZyAuJGNQ5YgNyOlYfqnGpTHXvk3cpykg= -github.com/aws/aws-sdk-go-v2/config v1.32.16 h1:Q0iQ7quUgJP0F/SCRTieScnaMdXr9h/2+wze1u3cNeM= -github.com/aws/aws-sdk-go-v2/config v1.32.16/go.mod h1:duCCnJEFqpt2RC6no1iK6q+8HpwOAkiUua0pY507dQc= -github.com/aws/aws-sdk-go-v2/credentials v1.19.15 h1:fyvgWTszojq8hEnMi8PPBTvZdTtEVmAVyo+NFLHBhH4= -github.com/aws/aws-sdk-go-v2/credentials v1.19.15/go.mod h1:gJiYyMOjNg8OEdRWOf3CrFQxM2a98qmrtjx1zuiQfB8= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.22 h1:IOGsJ1xVWhsi+ZO7/NW8OuZZBtMJLZbk4P5HDjJO0jQ= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.22/go.mod h1:b+hYdbU+jGKfXE8kKM6g1+h+L/Go3vMvzlxBsiuGsxg= -github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.1.17 h1:95y7/EqethAhFwMKJ9cDutzBhsS1h8uBwkJ5rp8pNTU= -github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.1.17/go.mod h1:77baheqr62SkTw77HWH8qpdWTd2gXKN0xg0qLvDSkpk= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.22 h1:GmLa5Kw1ESqtFpXsx5MmC84QWa/ZrLZvlJGa2y+4kcQ= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.22/go.mod h1:6sW9iWm9DK9YRpRGga/qzrzNLgKpT2cIxb7Vo2eNOp0= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.22 h1:dY4kWZiSaXIzxnKlj17nHnBcXXBfac6UlsAx2qL6XrU= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.22/go.mod h1:KIpEUx0JuRZLO7U6cbV204cWAEco2iC3l061IxlwLtI= -github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.23 h1:FPXsW9+gMuIeKmz7j6ENWcWtBGTe1kH8r9thNt5Uxx4= -github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.23/go.mod h1:7J8iGMdRKk6lw2C+cMIphgAnT8uTwBwNOsGkyOCm80U= -github.com/aws/aws-sdk-go-v2/service/acm v1.38.2 h1:ozcwethaFOi2ST9h6MKGq1GAIHP68tjiDqgkWVPwfR8= -github.com/aws/aws-sdk-go-v2/service/acm v1.38.2/go.mod h1:HNtDOv4XmqExPxNIBp171KKc5ZoUJwHH9ZhlCcZmdt0= -github.com/aws/aws-sdk-go-v2/service/autoscaling v1.66.1 h1:kGlbhb5GMfkP/bcqcbt3oDi50kwDTpRmNzYUY9LqbLk= -github.com/aws/aws-sdk-go-v2/service/autoscaling v1.66.1/go.mod h1:z45kurrOonQepd3SN5LIgropAn1NGHwBn1yOMF+QVFU= -github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.69.1 h1:2ANEV0YkO/NlWxVmHBui7w7NE3lHW2sJji+OtjKJwck= -github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.69.1/go.mod h1:O7cQtpXZSk+P59gPFZIpcMpKwLk5d9zabFpV8fw68RM= -github.com/aws/aws-sdk-go-v2/service/dynamodb v1.57.2 h1:J2ibOhlMLx1o6QwDFsHHfbQjaZ6t5LXodiLNuK6jbZA= -github.com/aws/aws-sdk-go-v2/service/dynamodb v1.57.2/go.mod h1:Tj8VcffnduuewrM8HN8xQ9wzzez0CJ0FGSGEovq7Sgs= -github.com/aws/aws-sdk-go-v2/service/ec2 v1.297.1 h1:9nfacm+uWgbdPaOplvJjxN50qgthexb7GOR/97ygc5o= -github.com/aws/aws-sdk-go-v2/service/ec2 v1.297.1/go.mod h1:E1pnYwWFZ8N3REmeN9Fe/Zipbpps4HJj8DQGNnLUMYc= -github.com/aws/aws-sdk-go-v2/service/ecr v1.57.1 h1:G/O4muLF2pe1UJBKEyF7J+kdokEEqFJjm42cU68FqH4= -github.com/aws/aws-sdk-go-v2/service/ecr v1.57.1/go.mod h1:KBzTxiBlQ2bB5XT367+t18i3Qe7NZDRyGKxdzN43aOw= -github.com/aws/aws-sdk-go-v2/service/ecs v1.78.1 h1:9zSVr4X6X8JNTxSMip2RORaBB+Mu0/IfzNu3iRWZE9c= -github.com/aws/aws-sdk-go-v2/service/ecs v1.78.1/go.mod h1:1DlTqkp+8uc5At3UXyJAvJXFaWoMmxSHcp2Zdor0qGw= -github.com/aws/aws-sdk-go-v2/service/iam v1.53.8 h1:p0oB4eZfBfBAOasnKvHJOlNcuHVE/ieuWs7uIZgQlyQ= -github.com/aws/aws-sdk-go-v2/service/iam v1.53.8/go.mod h1:epCaPnGVdiX5ra1lHPfRkVuiQGxrdY8bRI2FBJU+6ok= -github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.8 h1:HtOTYcbVcGABLOVuPYaIihj6IlkqubBwFj10K5fxRek= -github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.8/go.mod h1:VsK9abqQeGlzPgUr+isNWzPlK2vKe9INMLWnY65f5Xs= -github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.14 h1:xnvDEnw+pnj5mctWiYuFbigrEzSm35x7k4KS/ZkCANg= -github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.14/go.mod h1:yS5rNogD8e0Wu9+l3MUwr6eENBzEeGejvINpN5PAYfY= -github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.11.22 h1:8IXbJCgOn8ztzvRUOm27iCeTSxmPW45JsSDW3EGi16M= -github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.11.22/go.mod h1:l53RbOWvncp4DEmlEz6dSXJS913AIxtFqkJZ+Xz7pHs= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.22 h1:PUmZeJU6Y1Lbvt9WFuJ0ugUK2xn6hIWUBBbKuOWF30s= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.22/go.mod h1:nO6egFBoAaoXze24a2C0NjQCvdpk8OueRoYimvEB9jo= -github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.22 h1:SE+aQ4DEqG53RRCAIHlCf//B2ycxGH7jFkpnAh/kKPM= -github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.22/go.mod h1:ES3ynECd7fYeJIL6+oax+uIEljmfps0S70BaQzbMd/o= -github.com/aws/aws-sdk-go-v2/service/kms v1.50.5 h1:nEzwx/ZlpUZ2Y6WztsgYmfBh5Ixd3QiECawXMzvTMeo= -github.com/aws/aws-sdk-go-v2/service/kms v1.50.5/go.mod h1:GBO/aaEi47QldDVoqw2CsM2UZQDoqDiFIMJD/ztHPs0= -github.com/aws/aws-sdk-go-v2/service/lambda v1.89.1 h1:JxHLwNK5mIKsh2Q0APTSijdzkk5ccI4gyvYdar1JU/0= -github.com/aws/aws-sdk-go-v2/service/lambda v1.89.1/go.mod h1:7qoh/MlWG5QCnZwq9bvdXomEAkmumayXcjEjIemIV7U= -github.com/aws/aws-sdk-go-v2/service/rds v1.118.1 h1:cywOPYUFOSOAjrovJNxuBXd6SV3osiP3KJ5p412IEJQ= -github.com/aws/aws-sdk-go-v2/service/rds v1.118.1/go.mod h1:BaS59j6evm68pt9EaJnb7tnTOaT0MY4rJeESKh8RKKY= -github.com/aws/aws-sdk-go-v2/service/route53 v1.62.6 h1:6b+KS0uVMMsCUKlW8OPNxmcEmoEUtqP1LfnzSzWmuQM= -github.com/aws/aws-sdk-go-v2/service/route53 v1.62.6/go.mod h1:+wmraHmxwqi7feUL/41uULJWl8V1HxtxzOJH6a4ZRg4= -github.com/aws/aws-sdk-go-v2/service/s3 v1.99.1 h1:kU/eBN5+MWNo/LcbNa4hWDdN76hdcd7hocU5kvu7IsU= -github.com/aws/aws-sdk-go-v2/service/s3 v1.99.1/go.mod h1:Fw9aqhJicIVee1VytBBjH+l+5ov6/PhbtIK/u3rt/ls= -github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.41.6 h1:XR42AXidhYs4HwH0I+yElLXVt7zb2hAyNHQJe6Blv7w= -github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.41.6/go.mod h1:nOTsSVQlAsgwVRdtZYtECSnsInF8IUhrpnclCPat7Fs= -github.com/aws/aws-sdk-go-v2/service/signin v1.0.10 h1:a1Fq/KXn75wSzoJaPQTgZO0wHGqE9mjFnylnqEPTchA= -github.com/aws/aws-sdk-go-v2/service/signin v1.0.10/go.mod h1:p6+MXNxW7IA6dMgHfTAzljuwSKD0NCm/4lbS4t6+7vI= -github.com/aws/aws-sdk-go-v2/service/sns v1.39.16 h1:CIFDzcrpG87cjj5Op1NZ55BZV64mFka1DuJIEjedxmI= -github.com/aws/aws-sdk-go-v2/service/sns v1.39.16/go.mod h1:468X50NBvl50h/poFrQXD1oZMxbOCTQSVdvowm0i4aw= -github.com/aws/aws-sdk-go-v2/service/sqs v1.42.26 h1:jtUEQz/c14fCMkOX3r2/nhYmhXZas0XdcQhUaIW5ubY= -github.com/aws/aws-sdk-go-v2/service/sqs v1.42.26/go.mod h1:gcJv70rH+Z/Q1PM3jKsJr6+vfKrDHJOfmKq7342+Vq8= -github.com/aws/aws-sdk-go-v2/service/ssm v1.68.5 h1:TY5Vh7uXQgJVuc6ahI6toLcRajG1aYSDCP3a0xsPvmo= -github.com/aws/aws-sdk-go-v2/service/ssm v1.68.5/go.mod h1:UkzShnbxHRIIL2cHi/7fBGLUAZIVTEADQjaA53bWWCE= -github.com/aws/aws-sdk-go-v2/service/sso v1.30.16 h1:x6bKbmDhsgSZwv6q19wY/u3rLk/3FGjJWyqKcIRufpE= -github.com/aws/aws-sdk-go-v2/service/sso v1.30.16/go.mod h1:CudnEVKRtLn0+3uMV0yEXZ+YZOKnAtUJ5DmDhilVnIw= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.20 h1:oK/njaL8GtyEihkWMD4k3VgHCT64RQKkZwh0DG5j8ak= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.20/go.mod h1:JHs8/y1f3zY7U5WcuzoJ/yAYGYtNIVPKLIbp61euvmg= -github.com/aws/aws-sdk-go-v2/service/sts v1.42.0 h1:ks8KBcZPh3PYISr5dAiXCM5/Thcuxk8l+PG4+A0exds= -github.com/aws/aws-sdk-go-v2/service/sts v1.42.0/go.mod h1:pFw33T0WLvXU3rw1WBkpMlkgIn54eCB5FYLhjDc9Foo= -github.com/aws/smithy-go v1.25.0 h1:Sz/XJ64rwuiKtB6j98nDIPyYrV1nVNJ4YU74gttcl5U= -github.com/aws/smithy-go v1.25.0/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= +github.com/aws/aws-sdk-go-v2 v1.47.0 h1:0jsHallhJCeaU0Ko48c/3FK1ctOQ7NpzggxriJOQ8MQ= +github.com/aws/aws-sdk-go-v2 v1.47.0/go.mod h1:bttEH6JqnUL8LepvDVfdrds/fZ5bCIxzpe3abyUrhDU= +github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20 h1:GPRlPwz40I2B2VrBEASOA3Bi77NyeqejNLkifosX0rs= +github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20/go.mod h1:g7PNzKcsOKWb4fkSRBA7BZVAS6Y8IcxzN+nRohhQ1Q8= +github.com/aws/aws-sdk-go-v2/config v1.33.5 h1:UA1dmokBFOLFoOyVBhO6HjM6edy0MIk5AZSkJVcksQw= +github.com/aws/aws-sdk-go-v2/config v1.33.5/go.mod h1:Dop8axzz0xx38GExIYWXdeyc8QQ7Cr+nPsxpD/LYy4U= +github.com/aws/aws-sdk-go-v2/credentials v1.20.5 h1:wklUVvHMc9xTQ3rcp49/ISpiMnhbCicJcA6n6S8m7J8= +github.com/aws/aws-sdk-go-v2/credentials v1.20.5/go.mod h1:fyEdrn6ccLFOkoK84j5bQyGTxp9zPt5l2XMhxf4DVZs= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.20.0 h1:AM4hHjww+PSFtt6E+UrBrPlZkWsePCLEt9AjkfQX+yM= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.20.0/go.mod h1:3x/yXezeQjpOvBb4jEMxrS8SXvpdvJ5abv6l5c1gWM8= +github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.4.8 h1:qoWdBFsShMGN4UkecqJha9OZUfHLxRV8jOhKWuhJogc= +github.com/aws/aws-sdk-go-v2/feature/s3/transfermanager v0.4.8/go.mod h1:FARsDtg+5ervVKytHVfCUf4wMMxVvebPqHIw39jTApI= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.3 h1:Hp/VgjP0BysR3OgLlR057Vz2LcbbVnoWeJ+3qWiS/fY= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.5.3/go.mod h1:nwGV5qw7F1IZPgxCvA/ph8N2TAuz+BkRG/bXn808qMA= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.3 h1:MUaM4f+kj1ZIBPZfUS8cxP1GKXXZtHJjAthy93AN7SM= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.8.3/go.mod h1:6YmVmEVRI5ZZzRjCSsb9SryKH0hAlMRdgA7kG9aDvBU= +github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.3 h1:fuSCw4Z2qfRCztMPO3GXJNSiEp6Wee+WOLwrHHUMy9c= +github.com/aws/aws-sdk-go-v2/internal/v4a v1.5.3/go.mod h1:6SxcHheD1pPR5+kWm1wGvjlL/YqUsh267sAfEmN4K7A= +github.com/aws/aws-sdk-go-v2/service/acm v1.50.0 h1:rdTVn2eXD8DM7BCzKlPUgYQtzAbjBjBe/H67P1ovmgQ= +github.com/aws/aws-sdk-go-v2/service/acm v1.50.0/go.mod h1:T/Y6CzJBYpYOGoRDxQxdZcxSNbQ8+ZR+Qlx0U7yGOy0= +github.com/aws/aws-sdk-go-v2/service/autoscaling v1.78.0 h1:CN7ZkNEZb5Ob0DtntBQLE7cdpT13gzS1Gn+QMoZOjHA= +github.com/aws/aws-sdk-go-v2/service/autoscaling v1.78.0/go.mod h1:nkWNnRTHDlkZZrZzhmcPrOkoF+werzJzCOHGpbIpcfA= +github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.88.0 h1:KyeagiHCnUF7s91ulQNtzPYp1EkrfSITu1UVEksNERs= +github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs v1.88.0/go.mod h1:wsz6uFaBRCfqWjNLeBH0jutf0ek8CQGVCO/QSTWZl54= +github.com/aws/aws-sdk-go-v2/service/dynamodb v1.69.0 h1:JapCBy1C76JRQRw++NmoQVPdkt5PolQ9HZFEI1r9A4Y= +github.com/aws/aws-sdk-go-v2/service/dynamodb v1.69.0/go.mod h1:d7bRXj2c3K52qdd62I1c0o+ua/44QScJFj6EP0ufZeI= +github.com/aws/aws-sdk-go-v2/service/ec2 v1.335.0 h1:F4FgmFpQEuf1cb74G5nZvcjt4Y8lOUrTjpY8ZGaQzq4= +github.com/aws/aws-sdk-go-v2/service/ec2 v1.335.0/go.mod h1:2o5yJcnWuaBOsnNqlO1reYs1OQffFkqf2xJ2mmMWNH4= +github.com/aws/aws-sdk-go-v2/service/ecr v1.66.0 h1:9i19IigAYxnAxTUQcsxkiIXeeytHllTOetWBhr1DTQs= +github.com/aws/aws-sdk-go-v2/service/ecr v1.66.0/go.mod h1:iSlv4VibruxMhWfiKrNbn97Yjhe2855EFrgUitSESfM= +github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.47.0 h1:qLVBL6u7+Ob+H0s+eJAD54+UAn7eCBOlbngmBZRtv+k= +github.com/aws/aws-sdk-go-v2/service/ecrpublic v1.47.0/go.mod h1:r/ctJh/VqBZY1N0C6oKmdA4Dd4AeMHGQBTb46AGDs8A= +github.com/aws/aws-sdk-go-v2/service/ecs v1.99.0 h1:cPs0zxkcuEpcT2jIFclGr6VWc5ofICYXXW/6UMAhjMY= +github.com/aws/aws-sdk-go-v2/service/ecs v1.99.0/go.mod h1:n91ZROStH0gUedR5Rh4RKLyHXG+XiDGcEi3rvTt2HCY= +github.com/aws/aws-sdk-go-v2/service/iam v1.64.0 h1:CjgiPuyW26WQeQ934DxMNuwkDg6+ziqgPN9lHQ5rwYA= +github.com/aws/aws-sdk-go-v2/service/iam v1.64.0/go.mod h1:TI7OT5XlpXfs4BM4Y5NXcHTiyBwkqv6NpGiM4/usn5A= +github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 h1:bAdDl/HkGCcGPoe25ToSHEw23VIxt6CT5fLcg111BKg= +github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19/go.mod h1:KaUzbLxv4CeSxh6ZCl9B4m7CuFenS8kUEaDs+f/DQr4= +github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.11.3 h1:BHKCSX4QXERe8So8rbWqaM7owqOmDJxATXgJwGng22A= +github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.11.3/go.mod h1:GqWeeKfYfezihA2KfFL9l7ohEdZWe1tuFWh3GfyNSnE= +github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.13.3 h1:76FYKEDB9AzQzOaERx6TKaKKS1fxjswzO/cfestdWnI= +github.com/aws/aws-sdk-go-v2/service/internal/endpoint-discovery v1.13.3/go.mod h1:BH5hXFPEK6XdipZfv99bfbjV44tKwyjImyOaB3gIzts= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.3 h1:bON1rJf67TSTDCKg816AAIE4xSTtoo9tl0XRkO72R+I= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.14.3/go.mod h1:c5BBpjJcQXpfeq9iASyVKA3T6vX6B6LEXY4mL/gklDY= +github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.20.3 h1:L8vIOxylma91TcR96NFTEC07G3JDwSl+CvK2b+IODms= +github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.20.3/go.mod h1:fmPIZQzTExYuBNWFyi1P7IoDjvskgphXqK1yObMzusM= +github.com/aws/aws-sdk-go-v2/service/kms v1.61.0 h1:Ux0dqd8Pj64DcFk/HLtPyaDgwv6M6GhipSAsMd9YxbM= +github.com/aws/aws-sdk-go-v2/service/kms v1.61.0/go.mod h1:/eZ9xj8IZyb7fj+/t3HO7x89X+7Vn+gCDDbQ2NHCVtM= +github.com/aws/aws-sdk-go-v2/service/lambda v1.109.0 h1:r/JmqiXqHhZ2CpifXgDm83XuVslpE4e72fh3s1jqJMI= +github.com/aws/aws-sdk-go-v2/service/lambda v1.109.0/go.mod h1:KYgalOoMYV+Dm9vz0ydRM+SQ3RtFcqGHR/rl36YD6oY= +github.com/aws/aws-sdk-go-v2/service/rds v1.129.0 h1:rfqkLgq6+N4R2+03T8VS6B7yU4l1gx21zaK/v54Qaik= +github.com/aws/aws-sdk-go-v2/service/rds v1.129.0/go.mod h1:UKCSI4ZmISkI7H6ndDvwB64cwzbxJssyHe2wrmX60LU= +github.com/aws/aws-sdk-go-v2/service/route53 v1.70.0 h1:VxLw9i321VscFgoYqfSkd2UdLcRVmp9tiv9xnk4VSIY= +github.com/aws/aws-sdk-go-v2/service/route53 v1.70.0/go.mod h1:ZFR4YYQvjghZDMjaAmpXRaO/qxfCns/kjsQtguzvQVU= +github.com/aws/aws-sdk-go-v2/service/s3 v1.113.2 h1:2qsrxKfGgJrHBp4udIsZZVJGTX5lySaY9cJbZRB4J2Y= +github.com/aws/aws-sdk-go-v2/service/s3 v1.113.2/go.mod h1:/uA+2Qj4jd5qBWagVC1AyzzDFXVK997E7U04w7Kw0wI= +github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.50.0 h1:xpgbxBPYQeVHrJni4vd3wq69elhr8cqrVSwd8dgPkaQ= +github.com/aws/aws-sdk-go-v2/service/secretsmanager v1.50.0/go.mod h1:HMOw7but3OQg86ARfV8Hvoc8h/kNiB3OQm1q6AwO27I= +github.com/aws/aws-sdk-go-v2/service/signin v1.10.0 h1:ZD5qFpWcaOKdTuhBi431pIDkCgrMkMlMT6jlpSPoIRI= +github.com/aws/aws-sdk-go-v2/service/signin v1.10.0/go.mod h1:8Nuuf+tR346PjJ3MvZPh9pekbLiLQFWJhzMXfwy7alA= +github.com/aws/aws-sdk-go-v2/service/sns v1.47.1 h1:jTNa1/JsNYXcLw5VbwqeTh9/NErSLOY7NCk/SIB0VLI= +github.com/aws/aws-sdk-go-v2/service/sns v1.47.1/go.mod h1:s/NR14+UXkT4NCUvC/GemXuNhd+lhAc2QbnZyTVqxlk= +github.com/aws/aws-sdk-go-v2/service/sqs v1.52.0 h1:39EpbrAPFSOPYc9FVr2ki84cLB/9C5nC03aL7ope2rU= +github.com/aws/aws-sdk-go-v2/service/sqs v1.52.0/go.mod h1:yErwLsJkArgQLSGWtLjjwlpvlLK4+c9h0jDZZVN02hw= +github.com/aws/aws-sdk-go-v2/service/ssm v1.78.0 h1:+a7gfPhZYdFvMxKwbC51PljAo4L/cdzg2tmtMusRkDE= +github.com/aws/aws-sdk-go-v2/service/ssm v1.78.0/go.mod h1:sCtehdCzGR2L4tFbPq6qnfqX1A86h2Hna8fU10VuTaA= +github.com/aws/aws-sdk-go-v2/service/sso v1.38.0 h1:JGeeBcMlhg1xtOXYpeCaTQBZObtXMPQCUqBcmr65NRA= +github.com/aws/aws-sdk-go-v2/service/sso v1.38.0/go.mod h1:XwteswG9EOMRFm73UT0t+MbTwyLxMrEXkU6e+v92Lzo= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.43.0 h1:obhahQXDEdVEv8y5bTKXR30LVaxYe1kyYM0L7l2Iq+k= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.43.0/go.mod h1:6twZZ/aXHNy1vXUO8koUbp++MYzMASkOgEBdkbJYmO0= +github.com/aws/aws-sdk-go-v2/service/sts v1.51.0 h1:Zpnqa6XtrNzXZnwbdCqHOXpXhMsa01ql/pcRQ1sb4hk= +github.com/aws/aws-sdk-go-v2/service/sts v1.51.0/go.mod h1:/8JRcdTt//hG0Q4BTmGbuOplT7ABe+5rdtqUHqXvYIM= +github.com/aws/smithy-go v1.28.2 h1:myhcykQcatTul2B/zITjDk203G7t0awUAs1hVry5Bvg= +github.com/aws/smithy-go v1.28.2/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= github.com/beorn7/perks v1.0.1 h1:VlbKKnNfV8bJzeqoa4cOKqO6bYr3WgKZxO8Z16+hsOM= github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw= +github.com/blang/semver/v4 v4.0.0 h1:1PFHFE6yCCTv8C1TeyNNarDzntLi7wMI5i/pzqYIsAM= +github.com/blang/semver/v4 v4.0.0/go.mod h1:IbckMUScFkM3pff0VJDNKRiT6TG/YpiHIM2yvyW5YoQ= github.com/boombuler/barcode v1.0.1-0.20190219062509-6c824513bacc/go.mod h1:paBWMcWSl3LHKBqUq+rly7CNSldXjb2rDl3JlRe0mD8= github.com/boombuler/barcode v1.1.0 h1:ChaYjBR63fr4LFyGn8E8nt7dBSt3MiU3zMOZqFvVkHo= github.com/boombuler/barcode v1.1.0/go.mod h1:paBWMcWSl3LHKBqUq+rly7CNSldXjb2rDl3JlRe0mD8= @@ -109,10 +131,12 @@ github.com/bradleyfalzon/ghinstallation/v2 v2.19.0 h1:KQfD+43pRw9NUJhGycGrFr9vF1 github.com/bradleyfalzon/ghinstallation/v2 v2.19.0/go.mod h1:fe5ECIhCdEnxwLiBlNTxx9CP455wt42BELnlDVMvaAA= github.com/brunoga/deep v1.2.4 h1:Aj9E9oUbE+ccbyh35VC/NHlzzjfIVU69BXu2mt2LmL8= github.com/brunoga/deep v1.2.4/go.mod h1:GDV6dnXqn80ezsLSZ5Wlv1PdKAWAO4L5PnKYtv2dgaI= +github.com/cenkalti/backoff/v5 v5.0.3 h1:ZN+IMa753KfX5hd8vVaMixjnqRZ3y8CuJKRKj1xcsSM= +github.com/cenkalti/backoff/v5 v5.0.3/go.mod h1:rkhZdG3JZukswDf7f0cwqPNk4K0sa+F97BxZthm/crw= github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs= github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs= -github.com/cloudflare/circl v1.6.3 h1:9GPOhQGF9MCYUeXyMYlqTR6a5gTrgR/fBLXvUgtVcg8= -github.com/cloudflare/circl v1.6.3/go.mod h1:2eXP6Qfat4O/Yhh8BznvKnJ+uzEoTQ6jVKJRn81BiS4= +github.com/cloudflare/circl v1.6.5 h1:O64F26HEqNhznd/hrC5KZXVKYuKM2rx4deZDTc4ihQA= +github.com/cloudflare/circl v1.6.5/go.mod h1:h5LNyxAc5nTue9DS5jT+48en2PSDYt3zdGnz5OstK6c= github.com/coreos/go-systemd/v22 v22.5.0/go.mod h1:Y58oyj3AT4RCenI/lSvhwexgC+NSVTIJ3seZv2GcEnc= github.com/cpuguy83/go-md2man/v2 v2.0.6/go.mod h1:oOW0eioCTA6cOiMLiUPZOpcVxMig6NIQQ7OS05n1F4g= github.com/cpuguy83/go-md2man/v2 v2.0.7 h1:zbFlGlXEAKlwXpmvle3d8Oe3YnkKIK4xSRTd3sHPnBo= @@ -121,6 +145,10 @@ github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSs github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM= github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= +github.com/dimchansky/utfbom v1.1.1 h1:vV6w1AhK4VMnhBno/TPVCoK9U/LP0PkLCS9tbxHdi/U= +github.com/dimchansky/utfbom v1.1.1/go.mod h1:SxdoEBH5qIqFocHMyGOXVAybYJdr71b1Q/j0mACtrfE= +github.com/elliotchance/orderedmap v1.8.0 h1:TrOREecvh3JbS+NCgwposXG5ZTFHtEsQiCGOhPElnMw= +github.com/elliotchance/orderedmap v1.8.0/go.mod h1:wsDwEaX5jEoyhbs7x93zk2H/qv0zwuhg4inXhDkYqys= github.com/emicklei/go-restful/v3 v3.13.0 h1:C4Bl2xDndpU6nJ4bc1jXd+uTmYPVUwkD6bFY/oTyCes= github.com/emicklei/go-restful/v3 v3.13.0/go.mod h1:6n3XBCmQQb25CM2LCACGz8ukIrRry+4bhvbpWn3mrbc= github.com/evanphx/json-patch v5.9.11+incompatible h1:ixHHqfcGvxhWkniF1tWxBHA0yb4Z+d1UQi45df52xW8= @@ -131,12 +159,14 @@ github.com/fatih/color v1.19.0 h1:Zp3PiM21/9Ld6FzSKyL5c/BULoe/ONr9KlbYVOfG8+w= github.com/fatih/color v1.19.0/go.mod h1:zNk67I0ZUT1bEGsSGyCZYZNrHuTkJJB+r6Q9VuMi0LE= github.com/fatih/structs v1.1.0 h1:Q7juDM0QtcnhCpeyLGQKyg4TOIghuNXrkL32pHAUMxo= github.com/fatih/structs v1.1.0/go.mod h1:9NiDSp5zOcgEDl+j00MP/WkGVPOlPRLejGD8Ga6PJ7M= +github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg= +github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U= github.com/fsnotify/fsnotify v1.4.7/go.mod h1:jwhsz4b93w/PPRr/qN1Yymfu8t87LnFCMoQvtojpjFo= github.com/fsnotify/fsnotify v1.4.9/go.mod h1:znqG4EE+3YCdAaPaxE2ZRY/06pZUdp0tY4IgpuI1SZQ= -github.com/fsnotify/fsnotify v1.9.0 h1:2Ml+OJNzbYCTzsxtv8vKSFD9PbJjmhYF14k/jKC7S9k= -github.com/fsnotify/fsnotify v1.9.0/go.mod h1:8jBTzvmWwFyi3Pb8djgCCO5IBqzKJ/Jwo8TRcHyHii0= -github.com/fxamacker/cbor/v2 v2.9.0 h1:NpKPmjDBgUfBms6tr6JZkTHtfFGcMKsw3eGcmD/sapM= -github.com/fxamacker/cbor/v2 v2.9.0/go.mod h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ= +github.com/fsnotify/fsnotify v1.10.1 h1:b0/UzAf9yR5rhf3RPm9gf3ehBPpf0oZKIjtpKrx59Ho= +github.com/fsnotify/fsnotify v1.10.1/go.mod h1:TLheqan6HD6GBK6PrDWyDPBaEV8LspOxvPSjC+bVfgo= +github.com/fxamacker/cbor/v2 v2.9.4 h1:xwjVlxEMR3S605oUlgBjKLTTeGFciYPGYCtF/35LKGo= +github.com/fxamacker/cbor/v2 v2.9.4/go.mod h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ= github.com/gkampitakis/ciinfo v0.3.2 h1:JcuOPk8ZU7nZQjdUhctuhQofk7BGHuIy0c9Ez8BNhXs= github.com/gkampitakis/ciinfo v0.3.2/go.mod h1:1NIwaOcFChN4fa/B0hEBdAb6npDlFL8Bwx4dfRLRqAo= github.com/gkampitakis/go-diff v1.3.2 h1:Qyn0J9XJSDTgnsgHRdz9Zp24RaJeKMUHg2+PDZZdC4M= @@ -145,53 +175,63 @@ github.com/gkampitakis/go-snaps v0.5.15 h1:amyJrvM1D33cPHwVrjo9jQxX8g/7E2wYdZ+01 github.com/gkampitakis/go-snaps v0.5.15/go.mod h1:HNpx/9GoKisdhw9AFOBT1N7DBs9DiHo/hGheFGBZ+mc= github.com/go-errors/errors v1.5.1 h1:ZwEMSLRCapFLflTpT7NKaAc7ukJ8ZPEjzlxt8rPN8bk= github.com/go-errors/errors v1.5.1/go.mod h1:sIVyrIiJhuEF+Pj9Ebtd6P/rEYROXFi3BopGUQ5a5Og= -github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI= -github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= +github.com/go-ini/ini v1.67.0 h1:z6ZrTEZqSWOTyH2FlglNbNgARyHG8oLW9gMELqKr06A= +github.com/go-ini/ini v1.67.0/go.mod h1:ByCAeIL28uOIIG0E3PJtZPDL8WnHpFKFOtgjp+3Ies8= +github.com/go-logr/logr v1.4.4 h1:tG4xh9yMsRCAiodLVTxyrkzSZ9+o0L1Kg/+cPVcbP/8= +github.com/go-logr/logr v1.4.4/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY= +github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag= +github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE= github.com/go-logr/zapr v1.3.0 h1:XGdV8XW8zdwFiwOA2Dryh1gj2KRQyOOoNmBy4EplIcQ= github.com/go-logr/zapr v1.3.0/go.mod h1:YKepepNBd1u/oyhd/yQmtjVXmm9uML4IXUgMOwR8/Gg= -github.com/go-openapi/jsonpointer v0.22.5 h1:8on/0Yp4uTb9f4XvTrM2+1CPrV05QPZXu+rvu2o9jcA= -github.com/go-openapi/jsonpointer v0.22.5/go.mod h1:gyUR3sCvGSWchA2sUBJGluYMbe1zazrYWIkWPjjMUY0= -github.com/go-openapi/jsonreference v0.21.5 h1:6uCGVXU/aNF13AQNggxfysJ+5ZcU4nEAe+pJyVWRdiE= -github.com/go-openapi/jsonreference v0.21.5/go.mod h1:u25Bw85sX4E2jzFodh1FOKMTZLcfifd1Q+iKKOUxExw= -github.com/go-openapi/swag v0.25.5 h1:pNkwbUEeGwMtcgxDr+2GBPAk4kT+kJ+AaB+TMKAg+TU= -github.com/go-openapi/swag v0.25.5/go.mod h1:B3RT6l8q7X803JRxa2e59tHOiZlX1t8viplOcs9CwTA= -github.com/go-openapi/swag/cmdutils v0.25.5 h1:yh5hHrpgsw4NwM9KAEtaDTXILYzdXh/I8Whhx9hKj7c= -github.com/go-openapi/swag/cmdutils v0.25.5/go.mod h1:pdae/AFo6WxLl5L0rq87eRzVPm/XRHM3MoYgRMvG4A0= -github.com/go-openapi/swag/conv v0.25.5 h1:wAXBYEXJjoKwE5+vc9YHhpQOFj2JYBMF2DUi+tGu97g= -github.com/go-openapi/swag/conv v0.25.5/go.mod h1:CuJ1eWvh1c4ORKx7unQnFGyvBbNlRKbnRyAvDvzWA4k= -github.com/go-openapi/swag/fileutils v0.25.5 h1:B6JTdOcs2c0dBIs9HnkyTW+5gC+8NIhVBUwERkFhMWk= -github.com/go-openapi/swag/fileutils v0.25.5/go.mod h1:V3cT9UdMQIaH4WiTrUc9EPtVA4txS0TOmRURmhGF4kc= -github.com/go-openapi/swag/jsonname v0.25.5 h1:8p150i44rv/Drip4vWI3kGi9+4W9TdI3US3uUYSFhSo= -github.com/go-openapi/swag/jsonname v0.25.5/go.mod h1:jNqqikyiAK56uS7n8sLkdaNY/uq6+D2m2LANat09pKU= -github.com/go-openapi/swag/jsonutils v0.25.5 h1:XUZF8awQr75MXeC+/iaw5usY/iM7nXPDwdG3Jbl9vYo= -github.com/go-openapi/swag/jsonutils v0.25.5/go.mod h1:48FXUaz8YsDAA9s5AnaUvAmry1UcLcNVWUjY42XkrN4= -github.com/go-openapi/swag/jsonutils/fixtures_test v0.25.5 h1:SX6sE4FrGb4sEnnxbFL/25yZBb5Hcg1inLeErd86Y1U= -github.com/go-openapi/swag/jsonutils/fixtures_test v0.25.5/go.mod h1:/2KvOTrKWjVA5Xli3DZWdMCZDzz3uV/T7bXwrKWPquo= -github.com/go-openapi/swag/loading v0.25.5 h1:odQ/umlIZ1ZVRteI6ckSrvP6e2w9UTF5qgNdemJHjuU= -github.com/go-openapi/swag/loading v0.25.5/go.mod h1:I8A8RaaQ4DApxhPSWLNYWh9NvmX2YKMoB9nwvv6oW6g= -github.com/go-openapi/swag/mangling v0.25.5 h1:hyrnvbQRS7vKePQPHHDso+k6CGn5ZBs5232UqWZmJZw= -github.com/go-openapi/swag/mangling v0.25.5/go.mod h1:6hadXM/o312N/h98RwByLg088U61TPGiltQn71Iw0NY= -github.com/go-openapi/swag/netutils v0.25.5 h1:LZq2Xc2QI8+7838elRAaPCeqJnHODfSyOa7ZGfxDKlU= -github.com/go-openapi/swag/netutils v0.25.5/go.mod h1:lHbtmj4m57APG/8H7ZcMMSWzNqIQcu0RFiXrPUara14= -github.com/go-openapi/swag/stringutils v0.25.5 h1:NVkoDOA8YBgtAR/zvCx5rhJKtZF3IzXcDdwOsYzrB6M= -github.com/go-openapi/swag/stringutils v0.25.5/go.mod h1:PKK8EZdu4QJq8iezt17HM8RXnLAzY7gW0O1KKarrZII= -github.com/go-openapi/swag/typeutils v0.25.5 h1:EFJ+PCga2HfHGdo8s8VJXEVbeXRCYwzzr9u4rJk7L7E= -github.com/go-openapi/swag/typeutils v0.25.5/go.mod h1:itmFmScAYE1bSD8C4rS0W+0InZUBrB2xSPbWt6DLGuc= -github.com/go-openapi/swag/yamlutils v0.25.5 h1:kASCIS+oIeoc55j28T4o8KwlV2S4ZLPT6G0iq2SSbVQ= -github.com/go-openapi/swag/yamlutils v0.25.5/go.mod h1:Gek1/SjjfbYvM+Iq4QGwa/2lEXde9n2j4a3wI3pNuOQ= -github.com/go-openapi/testify/enable/yaml/v2 v2.4.0 h1:7SgOMTvJkM8yWrQlU8Jm18VeDPuAvB/xWrdxFJkoFag= -github.com/go-openapi/testify/enable/yaml/v2 v2.4.0/go.mod h1:14iV8jyyQlinc9StD7w1xVPW3CO3q1Gj04Jy//Kw4VM= -github.com/go-openapi/testify/v2 v2.4.0 h1:8nsPrHVCWkQ4p8h1EsRVymA2XABB4OT40gcvAu+voFM= -github.com/go-openapi/testify/v2 v2.4.0/go.mod h1:HCPmvFFnheKK2BuwSA0TbbdxJ3I16pjwMkYkP4Ywn54= -github.com/go-sql-driver/mysql v1.9.3 h1:U/N249h2WzJ3Ukj8SowVFjdtZKfu9vlLZxjPXV1aweo= -github.com/go-sql-driver/mysql v1.9.3/go.mod h1:qn46aNg1333BRMNU69Lq93t8du/dwxI64Gl8i5p1WMU= +github.com/go-openapi/jsonpointer v1.0.1 h1:2KxywRmNwJkT/FMBa3iRNHEaAxSJvjqoufQZy3au1Mg= +github.com/go-openapi/jsonpointer v1.0.1/go.mod h1:wI7ZYsFmbIi9nBXOZqgDaS/bqOchRGZjqxFli7FBYxY= +github.com/go-openapi/jsonreference v1.0.2 h1:oS4et8FOf3p3UQxEo4Xt0esijmBUM+F259Xl72OSZsc= +github.com/go-openapi/jsonreference v1.0.2/go.mod h1:TbUNSOo+fcorZjFaNoiSDSoaNnnZtqJtLGR1PuvE/Cs= +github.com/go-openapi/swag v0.29.2 h1:9n8frkcsuQRA0INU31VbxNxt1zBaHxrHYGEf5BUjFi4= +github.com/go-openapi/swag v0.29.2/go.mod h1:RkCiX1gCVXWgLOavDXE3ALJrQ/VO2ziiIzOUs3z10xo= +github.com/go-openapi/swag/cmdutils v0.29.2 h1:cXEzX/nWCODon251f+1HgL75/R4XXML5IZxgLCWMoro= +github.com/go-openapi/swag/cmdutils v0.29.2/go.mod h1:XziaSVzYqkDvpWXzASfWajw2YvJrLscq610O2XiyqJw= +github.com/go-openapi/swag/conv v0.29.2 h1:8c9shoB8l0QRSR6ymq1llHdBWDqpIgJfjTGHx3Vuhm0= +github.com/go-openapi/swag/conv v0.29.2/go.mod h1:AZS0YigTNf8qNtD6WqJz/N4RUNmpr76SyjFGkq4+p6Q= +github.com/go-openapi/swag/fileutils v0.29.2 h1:mdUL+Vw5ah1fO1AvFCoHeIyv7YZsCz2MN3KNqd/lLVI= +github.com/go-openapi/swag/fileutils v0.29.2/go.mod h1:7QKmmodjAebaq61lGVJa8ldLdGeMF4DSgYv8tXOGGo0= +github.com/go-openapi/swag/jsonutils v0.29.2 h1:uZNSD2/rJDYAfvsLYkykTzXuyxM3QpDKV9jhRHrMu6k= +github.com/go-openapi/swag/jsonutils v0.29.2/go.mod h1:ONTdNvj3Y+IXRzfa17E+Rgt2ns/qiSOYjIo2K7v2yDs= +github.com/go-openapi/swag/jsonutils/fixtures_test v0.29.2 h1:w+Fd6EBOMGlC74GYGHqCLGyb3Bpams8TtNrgM/SG4jo= +github.com/go-openapi/swag/jsonutils/fixtures_test v0.29.2/go.mod h1:HC2egPORFzbj/gf05Zrfgz8Mgplx3oW7hgGi7pjZVhM= +github.com/go-openapi/swag/loading v0.29.2 h1:QU1ry24e6r6Shoxe380Nx0X5iKkpRO+hJffsyJ2dVlY= +github.com/go-openapi/swag/loading v0.29.2/go.mod h1:DqilDjuiJKETecsS4TRopWG1acUDsfqN39ZmQhPu6uI= +github.com/go-openapi/swag/mangling v0.29.2 h1:ltdo3K0tTP4P6zWhVVWDU9D37/YYBuMJRdZxiS2Dtog= +github.com/go-openapi/swag/mangling v0.29.2/go.mod h1:RjDi4TnItAenS3cgCXSpIl1kKbjG7il6pnmQVl/8bp8= +github.com/go-openapi/swag/netutils v0.29.2 h1:dBli6jyUa93sDS/XYWShJzf4+nnVfFKfvY9SLUaUzB8= +github.com/go-openapi/swag/netutils v0.29.2/go.mod h1:1pM6Xg/Um8E1eps3umWl8Hme3ByWXOtHsvFC0CULHUE= +github.com/go-openapi/swag/pools v0.29.2 h1:PlGoDRF8WtSyXkedZZkpW3f9wDhFf3u8KtaBcmgmh8c= +github.com/go-openapi/swag/pools v0.29.2/go.mod h1:V3lhxVT4qDYRqc2MRSSbLsTYIYV/2HlHafhyEkmzLIc= +github.com/go-openapi/swag/stringutils v0.29.2 h1:lcnBxwAaysT3bMUVBfn9V/PkfVqkurpqufKU6rTUMGk= +github.com/go-openapi/swag/stringutils v0.29.2/go.mod h1:i9cdh7sGaa0nm3CqIvH5IM5h2QClk1wns2ktKeILvRI= +github.com/go-openapi/swag/typeutils v0.29.2 h1:O7aVvkTs3pXwikgtrPLenigEMdQFgONKRooQA9pgf2I= +github.com/go-openapi/swag/typeutils v0.29.2/go.mod h1:7+GDG+uz9Ke+eVt4rClZg7wklSDp8hT/mKNh/pC26TE= +github.com/go-openapi/swag/yamlutils v0.29.2 h1:IFKFFeDnuIwzfsuWRQU+rI8iL3g4XyAYjV/RlnlxPLM= +github.com/go-openapi/swag/yamlutils v0.29.2/go.mod h1:7MGqtcrK73sxQ4ceiyIf8qiXS/s09JLMdR5esK5euYQ= +github.com/go-openapi/testify/enable/yaml/v2 v2.7.0 h1:wPW6YRgx3+SID1yUy/Xwa17L8kFEaEKod2VRbJDZNUs= +github.com/go-openapi/testify/enable/yaml/v2 v2.7.0/go.mod h1:mI1M88etYbc3PhgHsWQK2kwvNwW5aGFqMPbmib+SGIs= +github.com/go-openapi/testify/v2 v2.7.0 h1:bycOreEj6wfBvijg3YFogZ/sFjTCDmQnwSodSzHa3X8= +github.com/go-openapi/testify/v2 v2.7.0/go.mod h1:SgsVHtfooshd0tublTtJ50FPKhujf47YRqauXXOUxfw= +github.com/go-sql-driver/mysql v1.10.1 h1:arlSnNLq6a5yxGxV7qg9lF4j0C+KwD6NbQyKr9QL6ME= +github.com/go-sql-driver/mysql v1.10.1/go.mod h1:M+cqaI7+xxXGG9swrdeUIoPG3Y3KCkF0pZej+SK+nWk= github.com/go-task/slim-sprig v0.0.0-20210107165309-348f09dbbbc0/go.mod h1:fyg7847qk6SyHyPtNmDHnmrv/HOrqktSC+C9fM+CJOE= github.com/go-task/slim-sprig/v3 v3.0.0 h1:sUs3vkvUymDpBKi3qH1YSqBQk9+9D/8M2mN1vB6EwHI= github.com/go-task/slim-sprig/v3 v3.0.0/go.mod h1:W848ghGpv3Qj3dhTPRyJypKRiqCdHZiAzKg9hl15HA8= +github.com/go-test/deep v1.0.3 h1:ZrJSEWsXzPOxaZnFteGEfooLba+ju3FYIbOrS+rQd68= +github.com/go-test/deep v1.0.3/go.mod h1:wGDj63lr65AM2AQyKZd/NYHGb0R+1RLqB8NKt3aSFNA= github.com/go-viper/mapstructure/v2 v2.5.0 h1:vM5IJoUAy3d7zRSVtIwQgBj7BiWtMPfmPEgAXnvj1Ro= github.com/go-viper/mapstructure/v2 v2.5.0/go.mod h1:oJDH3BJKyqBA2TXFhDsKDGDTlndYOZ6rGS0BRZIxGhM= -github.com/goccy/go-yaml v1.18.0 h1:8W7wMFS12Pcas7KU+VVkaiCng+kG8QiFeFwzFb+rwuw= -github.com/goccy/go-yaml v1.18.0/go.mod h1:XBurs7gK8ATbW4ZPGKgcbrY1Br56PdM69F7LkFRi1kA= +github.com/gobuffalo/flect v1.0.3 h1:xeWBM2nui+qnVvNM4S3foBhCAL2XgPU+a7FdpelbTq4= +github.com/gobuffalo/flect v1.0.3/go.mod h1:A5msMlrHtLqh9umBSnvabjsMrCcCpAyzglnDvkbYKHs= +github.com/goccy/go-json v0.10.6 h1:p8HrPJzOakx/mn/bQtjgNjdTcN+/S6FcG2CTtQOrHVU= +github.com/goccy/go-json v0.10.6/go.mod h1:oq7eo15ShAhp70Anwd5lgX2pLfOS3QCiwU/PULtXL6M= +github.com/goccy/go-yaml v1.19.2 h1:PmFC1S6h8ljIz6gMRBopkjP1TVT7xuwrButHID66PoM= +github.com/goccy/go-yaml v1.19.2/go.mod h1:XBurs7gK8ATbW4ZPGKgcbrY1Br56PdM69F7LkFRi1kA= github.com/godbus/dbus/v5 v5.0.4/go.mod h1:xhWf0FNVPg57R7Z0UbKHbJfkEywrmjJnf7w5xrFpKfA= github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI= github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0= @@ -208,14 +248,16 @@ github.com/gonvenience/bunt v1.4.3 h1:MLd8YWu1Vl1tiL+XfXJvVA9kL71yQT0N+x7gXVH9H7 github.com/gonvenience/bunt v1.4.3/go.mod h1:ggA6odP6FNOh50mGxxytSSJTs2Ghy5Veq9wIVSbuoAw= github.com/gonvenience/idem v0.0.3 h1:rZ2f17JU5GHa3b5M5R2fClz0dYN3EFGhHHGo3AZz/1U= github.com/gonvenience/idem v0.0.3/go.mod h1:ChZ+RP8e30+uCBcCIzN/0di6lTO2PucjemgKfzQUQEw= -github.com/gonvenience/neat v1.3.18 h1:WxWoXhsTHA6CStNrGgSEjGTt5MwIm+7Xs+VZmQIuXZA= -github.com/gonvenience/neat v1.3.18/go.mod h1:DTaEyHIOjSkMa066EoZZl3k5KCG/rFGE67n0cjm/9qk= +github.com/gonvenience/neat v1.3.20 h1:KdevSy5GLb3h1U5AYGw3NwW9FAAU2MWfrtsDHzYaKOg= +github.com/gonvenience/neat v1.3.20/go.mod h1:GbVes855L3QYFkDg9pnxHe/FQVsr1Tl+ME0fyOZO4Lg= github.com/gonvenience/term v1.0.5 h1:PYfBH7FB1V+tuuJl4KYrqG/tzAOUnvTy8IFa9YqYrJY= github.com/gonvenience/term v1.0.5/go.mod h1:CYvcU7H3nE6eOP0gvGfYz4BjGJzM1GeNp+fx4IBWKLs= github.com/gonvenience/text v1.0.10 h1:QRqtC/KMk57K7y4jHi4HjLxf8u+tg+/tIRCS5afywNE= github.com/gonvenience/text v1.0.10/go.mod h1:qO4aTZGAXbeW7eJXK+94nIc5Uumz8Q5DphOFZex6JHI= -github.com/gonvenience/ytbx v1.4.8 h1:V7oea89gLUN1C0rGDHxnt1YMAd7wHau9LC80Ng2QauA= -github.com/gonvenience/ytbx v1.4.8/go.mod h1:DVrIUZAiVv/bzOU3esvEvhGWED4YbyhSAuFru5nlzD4= +github.com/gonvenience/ytbx v1.5.0 h1:6AbxnAWwyY+tMLEBENXC4m1j71Ubcv2+UaQmEA7rYv4= +github.com/gonvenience/ytbx v1.5.0/go.mod h1:zxRSqmJ2sHOH+XyYFAPhyb7y+xjnRSRHLcNta5Ybcws= +github.com/google/cel-go v0.29.2 h1:ZtDxkeiMmz0mxbKDYiNkE5Lk7V5edMRcaaDf2jX002k= +github.com/google/cel-go v0.29.2/go.mod h1:X0bD6iVNR8pkROSOoHVdgTkzmRcosof7WQqCD6wcMc8= github.com/google/gnostic-models v0.7.1 h1:SisTfuFKJSKM5CPZkffwi6coztzzeYUhc3v4yxLWH8c= github.com/google/gnostic-models v0.7.1/go.mod h1:whL5G0m6dmc5cPxKc5bdKdEN3UjI7OUGxBlw57miDrQ= github.com/google/go-cmp v0.3.0/go.mod h1:8QqcDgzrUqlUb/G2PQTWiueGozuR1884gddMywk6iLU= @@ -233,18 +275,20 @@ github.com/google/go-querystring v1.2.0/go.mod h1:8IFJqpSRITyJ8QhQ13bmbeMBDfmeEJ github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= github.com/google/gofuzz v1.2.0 h1:xRy4A+RhZaiKjJ1bPfwQ8sedCA+YS2YcCHW6ec7JMi0= github.com/google/gofuzz v1.2.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= -github.com/google/pprof v0.0.0-20260402051712-545e8a4df936 h1:EwtI+Al+DeppwYX2oXJCETMO23COyaKGP6fHVpkpWpg= -github.com/google/pprof v0.0.0-20260402051712-545e8a4df936/go.mod h1:MxpfABSjhmINe3F1It9d+8exIHFvUqtLIRCdOGNXqiI= +github.com/google/pprof v0.0.0-20260906184651-6331bc6350fe h1:QAinXoAFJdGQYztXn3VpFey7KCwpedbZ/EkzbplQ0cY= +github.com/google/pprof v0.0.0-20260906184651-6331bc6350fe/go.mod h1:jl5iWTm0/hd5PjEYEOuwAJ57L/CibdZfrqZ5XA5GrCk= github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/gorilla/mux v1.8.1 h1:TuBL49tXwgrFYWhqrNgrUNEY92u81SPhu7sTdzQEiWY= github.com/gorilla/mux v1.8.1/go.mod h1:AKf9I4AEqPTmMytcMc0KkNouC66V3BtZ4qD5fmWSiMQ= github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 h1:JeSE6pjso5THxAzdVpqr6/geYxZytqFMBCOtn/ujyeo= github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674/go.mod h1:r4w70xmWCQKmi1ONH4KIaBptdivuRPyosB9RmPlGEwA= +github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 h1:5VipnvEpbqr2gA2VbM+nYVbkIF28c5ZQfqCBQ5g2xfk= +github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0/go.mod h1:Hyl3n6Twe1hvtd9XUXDec4pTvgMSEixRuQKPTMH2bNs= github.com/gruntwork-io/go-commons v0.17.2 h1:14dsCJ7M5Vv2X3BIPKeG9Kdy6vTMGhM8L4WZazxfTuY= github.com/gruntwork-io/go-commons v0.17.2/go.mod h1:zs7Q2AbUKuTarBPy19CIxJVUX/rBamfW8IwuWKniWkE= -github.com/gruntwork-io/terratest v1.0.0 h1:Zk7VJ5Z9vBSwv8OQ/zzkG5D/tfqyVyjMK+lq2v+Kn/c= -github.com/gruntwork-io/terratest v1.0.0/go.mod h1:g2XWbOQOvnHBFcIYCt5ryaFBWp69+5L+QMbAwor+CBo= +github.com/gruntwork-io/terratest v1.0.1 h1:5CCp4Matgw5S42t5VW79mLN3YcaN5cEqNpTprVjuzIQ= +github.com/gruntwork-io/terratest v1.0.1/go.mod h1:2lK9XvvGJ+GhsvA6tO7LpALWG34nu+1QecgexHKAGZ8= github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4= github.com/hashicorp/errwrap v1.1.0 h1:OxrOeh75EUXMY8TBjag2fzXGZ40LB6IKw45YeGUDY2I= github.com/hashicorp/errwrap v1.1.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4= @@ -256,8 +300,12 @@ github.com/hashicorp/go-multierror v1.1.1 h1:H5DkEtf6CXdFp0N0Em5UCwQpXMWke8IA0+l github.com/hashicorp/go-multierror v1.1.1/go.mod h1:iw975J/qwKPdAO1clOe2L8331t/9/fmwbPZ6JB6eMoM= github.com/hashicorp/go-retryablehttp v0.7.8 h1:ylXZWnqa7Lhqpk0L1P1LzDtGcCR0rPVUrx/c8Unxc48= github.com/hashicorp/go-retryablehttp v0.7.8/go.mod h1:rjiScheydd+CxvumBsIrFKlx3iS0jrZ7LvzFGFmuKbw= -github.com/homeport/dyff v1.11.2 h1:SOJlKWKyJWaajWqwT6PKnu09Hg7p/0YDKhMvSmcPVgM= -github.com/homeport/dyff v1.11.2/go.mod h1:3BXJOOPsVjehdhzvnZmRzHt5DmjvKh3MkFulmH9Y1ok= +github.com/hashicorp/hcl/v2 v2.24.0 h1:2QJdZ454DSsYGoaE6QheQZjtKZSUs9Nh2izTWiwQxvE= +github.com/hashicorp/hcl/v2 v2.24.0/go.mod h1:oGoO1FIQYfn/AgyOhlg9qLC6/nOJPX3qGbkZpYAcqfM= +github.com/hexops/gotextdiff v1.0.3 h1:gitA9+qJrrTCsiCl7+kh75nPqQt1cx4ZkudSTLoUqJM= +github.com/hexops/gotextdiff v1.0.3/go.mod h1:pSWU5MAI3yDq+fZBTazCSJysOMbxWL1BSow5/V2vxeg= +github.com/homeport/dyff v1.12.0 h1:1d4T2vdY0hYeWtAxjMLIX9bI8OijBfOuKH3wzfdYZT8= +github.com/homeport/dyff v1.12.0/go.mod h1:ArdUQcX099hp+uQ7pnimwU0Xgk2ba7E7nqdFv3WBRr8= github.com/hpcloud/tail v1.0.0/go.mod h1:ab1qPbhIpdTxEkNHXyeSf5vhxWSCs/tWer42PpOxQnU= github.com/huandu/xstrings v1.5.0 h1:2ag3IFq9ZDANvthTwTiqSSZLjDc+BedvHPAp5tJy2TI= github.com/huandu/xstrings v1.5.0/go.mod h1:y5/lhBue+AyNmUVz9RLU9xbLR0o4KIIExikq4ovT0aE= @@ -267,12 +315,14 @@ github.com/jackc/pgpassfile v1.0.0 h1:/6Hmqy13Ss2zCq62VdNG8tM1wchn8zjSGOBJ6icpsI github.com/jackc/pgpassfile v1.0.0/go.mod h1:CEx0iS5ambNFdcRtxPj5JhEz+xB6uRky5eyVu/W2HEg= github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761 h1:iCEnooe7UlwOQYpKFhBabPMi4aNAfoODPEFNiAnClxo= github.com/jackc/pgservicefile v0.0.0-20240606120523-5a60cdf6a761/go.mod h1:5TJZWKEWniPve33vlWYSoGYefn3gLQRzjfDlhSJ9ZKM= -github.com/jackc/pgx/v5 v5.9.0 h1:T/dI+2TvmI2H8s/KH1/lXIbz1CUFk3gn5oTjr0/mBsE= -github.com/jackc/pgx/v5 v5.9.0/go.mod h1:mal1tBGAFfLHvZzaYh77YS/eC6IX9OWbRV1QIIM0Jn4= +github.com/jackc/pgx/v5 v5.11.0 h1:IzBBtyK9AHqf98cctWFifYSci2hgQR/cd56wB4p+ogg= +github.com/jackc/pgx/v5 v5.11.0/go.mod h1:mal1tBGAFfLHvZzaYh77YS/eC6IX9OWbRV1QIIM0Jn4= github.com/jackc/puddle/v2 v2.2.2 h1:PR8nw+E/1w0GLuRFSmiioY6UooMp6KJv0/61nB7icHo= github.com/jackc/puddle/v2 v2.2.2/go.mod h1:vriiEXHvEE654aYKXXjOvZM39qJ0q+azkZFrfEOc3H4= github.com/jedib0t/go-pretty/v6 v6.6.7 h1:m+LbHpm0aIAPLzLbMfn8dc3Ht8MW7lsSO4MPItz/Uuo= github.com/jedib0t/go-pretty/v6 v6.6.7/go.mod h1:YwC5CE4fJ1HFUDeivSV1r//AmANFHyqczZk+U6BDALU= +github.com/jinzhu/copier v0.4.0 h1:w3ciUoD19shMCRargcpm0cm91ytaBhDvuRpz1ODO/U8= +github.com/jinzhu/copier v0.4.0/go.mod h1:DfbEm0FYsaqBcKcFuvmOZb218JkPGtvSHsKg8S8hyyg= github.com/joshdk/go-junit v1.0.0 h1:S86cUKIdwBHWwA6xCmFlf3RTLfVXYQfvanM5Uh+K6GE= github.com/joshdk/go-junit v1.0.0/go.mod h1:TiiV0PqkaNfFXjEiyjWM3XXrhVyCa1K4Zfga6W52ung= github.com/json-iterator/go v1.1.12 h1:PV8peI4a0ysnczrg+LtxykD8LfKY9ML6u2jnxaEnrnM= @@ -281,8 +331,8 @@ github.com/kelseyhightower/envconfig v1.4.0 h1:Im6hONhd3pLkfDFsbRgu68RDNkGF1r3dv github.com/kelseyhightower/envconfig v1.4.0/go.mod h1:cccZRl6mQpaq41TPp5QxidR+Sa3axMbJDNb//FQX6Gg= github.com/keybase/go-keychain v0.0.1 h1:way+bWYa6lDppZoZcgMbYsvC7GxljxrskdNInRtuthU= github.com/keybase/go-keychain v0.0.1/go.mod h1:PdEILRW3i9D8JcdM+FmY6RwkHGnhHxXwkPPMeUgOK1k= -github.com/klauspost/compress v1.18.0 h1:c/Cqfb0r+Yi+JtIEq73FWXVkRonBlf0CRNYc8Zttxdo= -github.com/klauspost/compress v1.18.0/go.mod h1:2Pp+KzxcywXVXMr50+X0Q/Lsb43OQHYWRCY2AiWywWQ= +github.com/klauspost/compress v1.19.1 h1:VsB4HPswih7mmZ8WleSFQ75c/Ui1M4trX5oAsJnhSlk= +github.com/klauspost/compress v1.19.1/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ= github.com/knadh/koanf/maps v0.1.2 h1:RBfmAW5CnZT+PJ1CVc1QSJKf4Xu9kxfQgYVQSu8hpbo= github.com/knadh/koanf/maps v0.1.2/go.mod h1:npD/QZY3V6ghQDdcQzl1W4ICNVTkohC8E73eI2xW4yI= github.com/knadh/koanf/parsers/yaml v0.1.0 h1:ZZ8/iGfRLvKSaMEECEBPM1HQslrZADk8fP1XFUxVI5w= @@ -306,8 +356,10 @@ github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE= github.com/kylelemons/godebug v1.1.0 h1:RPNrshWIDI6G2gRW9EHilWtl7Z6Sb1BR0xunSBf0SNc= github.com/kylelemons/godebug v1.1.0/go.mod h1:9/0rRGxNHcop5bhtWyNeEfOS8JIWk580+fNqagV/RAw= -github.com/lucasb-eyer/go-colorful v1.3.0 h1:2/yBRLdWBZKrf7gB40FoiKfAWYQ0lqNcbuQwVHXptag= -github.com/lucasb-eyer/go-colorful v1.3.0/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0= +github.com/lucasb-eyer/go-colorful v1.4.1 h1:1EO+WB73+EH8EVbzlrG3KLAfEypQWVHIBqlTf+2hNss= +github.com/lucasb-eyer/go-colorful v1.4.1/go.mod h1:R4dSotOR9KMtayYi1e77YzuveK+i7ruzyGqttikkLy0= +github.com/magiconair/properties v1.18.11 h1:j5ozYZl0zCjG7ahMDH0GWIobOvvUzT0BdAguG0ViKy0= +github.com/magiconair/properties v1.18.11/go.mod h1:Dhd985XPs7jluiymwWYZ0G4Z61jb3vdS329zhj2hYo0= github.com/maruel/natural v1.1.1 h1:Hja7XhhmvEFhcByqDoHz9QZbkWey+COd9xWfCfn1ioo= github.com/maruel/natural v1.1.1/go.mod h1:v+Rfd79xlw1AgVBjbO0BEQmptqb5HvL/k9GRHB7ZKEg= github.com/mattn/go-ciede2000 v0.0.0-20170301095244-782e8c62fec3 h1:BXxTozrOU8zgC5dkpn3J6NTRdoP+hjok/e+ACr4Hibk= @@ -317,20 +369,24 @@ github.com/mattn/go-colorable v0.1.14 h1:9A9LHSqF/7dyVVX6g0U9cwm9pG3kP9gSzcuIPHP github.com/mattn/go-colorable v0.1.14/go.mod h1:6LmQG8QLFO4G5z1gPvYEzlUgJ2wF+stgPZH1UqBm1s8= github.com/mattn/go-isatty v0.0.16/go.mod h1:kYGgaQfpe5nmfYZH+SKPsOc2e4SrIfOl2e/yFXSvRLM= github.com/mattn/go-isatty v0.0.19/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y= -github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY= -github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y= +github.com/mattn/go-isatty v0.0.24 h1:tGZZoVgT/KiqK1c8ocVLeDS8BSWMRd47J3Lbz7vsReI= +github.com/mattn/go-isatty v0.0.24/go.mod h1:nMCL3Zebbrt45jsMDgnfIwz6ydEQApk5oEI3HqDio6A= github.com/mattn/go-runewidth v0.0.16 h1:E5ScNMtiwvlvB5paMFdw9p4kSQzbXFikJ5SQO6TULQc= github.com/mattn/go-runewidth v0.0.16/go.mod h1:Jdepj2loyihRzMpdS35Xk/zdY8IAYHsh153qUoGf23w= -github.com/mattn/go-zglob v0.0.6 h1:mP8RnmCgho4oaUYDIDn6GNxYk+qJGUs8fJLn+twYj2A= -github.com/mattn/go-zglob v0.0.6/go.mod h1:MxxjyoXXnMxfIpxTK2GAkw1w8glPsQILx3N5wrKakiY= +github.com/mattn/go-zglob v0.0.8 h1:g/5T0tizbs+419GtiXvMDkOg+RIBu1qi+B2teiHsnNE= +github.com/mattn/go-zglob v0.0.8/go.mod h1:MxxjyoXXnMxfIpxTK2GAkw1w8glPsQILx3N5wrKakiY= github.com/mfridman/tparse v0.18.0 h1:wh6dzOKaIwkUGyKgOntDW4liXSo37qg5AXbIhkMV3vE= github.com/mfridman/tparse v0.18.0/go.mod h1:gEvqZTuCgEhPbYk/2lS3Kcxg1GmTxxU7kTC8DvP0i/A= +github.com/mikefarah/yq/v4 v4.53.6 h1:5vB15LTZRvrF6z/metQF31bmF63SjDzCKKX8o8UemQQ= +github.com/mikefarah/yq/v4 v4.53.6/go.mod h1:3tmDcCSTOTUFa5Z1X8R4j0H1kauIwNo2wjKq9sLyAh4= github.com/mitchellh/copystructure v1.2.0 h1:vpKXTN4ewci03Vljg/q9QvCGUDttBOGBIa15WveJJGw= github.com/mitchellh/copystructure v1.2.0/go.mod h1:qLl+cE2AmVv+CoeAwDPye/v+N2HKCj9FbZEVFJRxO9s= github.com/mitchellh/go-ps v1.0.0 h1:i6ampVEEF4wQFF+bkYfwYgY+F/uYJDktmvLPf7qIgjc= github.com/mitchellh/go-ps v1.0.0/go.mod h1:J4lOc8z8yJs6vUwklHw2XEIiT4z4C40KtWVN3nvg8Pg= -github.com/mitchellh/hashstructure v1.1.0 h1:P6P1hdjqAAknpY/M1CGipelZgp+4y9ja9kmUZPXP+H0= -github.com/mitchellh/hashstructure v1.1.0/go.mod h1:xUDAozZz0Wmdiufv0uyhnHkUTN6/6d8ulp4AwfLKrmA= +github.com/mitchellh/go-wordwrap v1.0.1 h1:TLuKupo69TCn6TQSyGxwI1EblZZEsQ0vMlAFQflz0v0= +github.com/mitchellh/go-wordwrap v1.0.1/go.mod h1:R62XHJLzvMFRBbcrT7m7WgmE1eOyTSsCt+hzestvNj0= +github.com/mitchellh/hashstructure/v2 v2.0.2 h1:vGKWl0YJqUNxE8d+h8f6NJLcCJrgbhC4NcD46KavDd4= +github.com/mitchellh/hashstructure/v2 v2.0.2/go.mod h1:MG3aRVU/N29oo/V/IhBX8GR/zz4kQkprJgF2EVszyDE= github.com/mitchellh/reflectwalk v1.0.2 h1:G2LzWKi524PWgd3mLHV8Y5k7s6XUvT0Gef6zxSIeXaQ= github.com/mitchellh/reflectwalk v1.0.2/go.mod h1:mSTlrgnPZtwu0c4WaC2kGObEpuNDbx0jmZXqmk4esnw= github.com/moby/spdystream v0.5.1 h1:9sNYeYZUcci9R6/w7KDaFWEWeV4LStVG78Mpyq/Zm/Y= @@ -349,14 +405,18 @@ github.com/onsi/ginkgo v1.6.0/go.mod h1:lLunBs/Ym6LB5Z9jYTR76FiuTmxDTDusOGeTQH+W github.com/onsi/ginkgo v1.12.1/go.mod h1:zj2OWP4+oCPe1qIXoGWkgMRwljMUYCdkwsT2108oapk= github.com/onsi/ginkgo v1.16.5 h1:8xi0RTUf59SOSfEtZMvwTvXYMzG4gV23XVHOZiXNtnE= github.com/onsi/ginkgo v1.16.5/go.mod h1:+E8gABHa3K6zRBolWtd+ROzc/U5bkGt0FwiG042wbpU= -github.com/onsi/ginkgo/v2 v2.31.0 h1:GtuJos5DFUV9EerYJo8RhYxosYNGvOdDE5haKq6Grfs= -github.com/onsi/ginkgo/v2 v2.31.0/go.mod h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44= +github.com/onsi/ginkgo/v2 v2.33.0 h1:C8gBA6Uc2ZEubiV+SXiu5tZnMTwEmXHgkJwGozKtZf8= +github.com/onsi/ginkgo/v2 v2.33.0/go.mod h1:+aXOY+vzZ5mu2iI2HpTZUPmM//oQfsNFX6gU9kNcA44= github.com/onsi/gomega v1.7.1/go.mod h1:XdKZgCCFLUoM/7CFJVPcG8C1xQ1AJ0vpAezJrB7JYyY= github.com/onsi/gomega v1.10.1/go.mod h1:iN09h71vgCQne3DLsj+A5owkum+a2tYe+TOCB1ybHNo= -github.com/onsi/gomega v1.42.0 h1:CJby8u36xb7v34W78F8WKvqTQP7PCMIPB78IVDB73l4= -github.com/onsi/gomega v1.42.0/go.mod h1:M/Uqpu/8qTjtzCLUA2zJHX9Iilrau25x1PdoSRbWh5A= +github.com/onsi/gomega v1.43.1 h1:vGIPFuYrIO6/0Z09s0I0QQQgFchiX4+tb1re3MScJYo= +github.com/onsi/gomega v1.43.1/go.mod h1:e/C2HwaZ1DhvjzXXuFhcR7hY7Sh9pl7MmoWKEjzwcdA= +github.com/pelletier/go-toml/v2 v2.4.3 h1:GTRvJQutkOSftxIFD5xw9aepkYNuPWmVJpffdDPYVpY= +github.com/pelletier/go-toml/v2 v2.4.3/go.mod h1:2gIqNv+qfxSVS7cM2xJQKtLSTLUE9V8t9Stt+h56mCY= github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c h1:+mdjkGKdHQG3305AYmdv1U2eRNDiU2ErMBj1gwrq8eQ= github.com/pkg/browser v0.0.0-20240102092130-5ac0b6a4141c/go.mod h1:7rwL4CYBLnjLxUqIJNnCWiEdr3bn6IUYi15bNlnbCCU= +github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e h1:aoZm08cpOy4WuID//EZDgcC4zIxODThtZNPirFr42+A= +github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e/go.mod h1:pJLUxLENpZxwdsKMEsNbx1VGcRFpLqf3715MtcvvzbA= github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4= github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0= github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= @@ -364,14 +424,14 @@ github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRI github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= github.com/pquerna/otp v1.5.0 h1:NMMR+WrmaqXU4EzdGJEE1aUUI0AMRzsp96fFFWNPwxs= github.com/pquerna/otp v1.5.0/go.mod h1:dkJfzwRKNiegxyNb54X/3fLwhCynbMspSyWKnvi1AEg= -github.com/prometheus/client_golang v1.23.2 h1:Je96obch5RDVy3FDMndoUsjAhG5Edi49h0RJWRi/o0o= -github.com/prometheus/client_golang v1.23.2/go.mod h1:Tb1a6LWHB3/SPIzCoaDXI4I8UHKeFTEQ1YCr+0Gyqmg= -github.com/prometheus/client_model v0.6.2 h1:oBsgwpGs7iVziMvrGhE53c/GrLUsZdHnqNwqPLxwZyk= -github.com/prometheus/client_model v0.6.2/go.mod h1:y3m2F6Gdpfy6Ut/GBsUqTWZqCUvMVzSfMLjcu6wAwpE= -github.com/prometheus/common v0.67.5 h1:pIgK94WWlQt1WLwAC5j2ynLaBRDiinoAb86HZHTUGI4= -github.com/prometheus/common v0.67.5/go.mod h1:SjE/0MzDEEAyrdr5Gqc6G+sXI67maCxzaT3A2+HqjUw= -github.com/prometheus/procfs v0.20.1 h1:XwbrGOIplXW/AU3YhIhLODXMJYyC1isLFfYCsTEycfc= -github.com/prometheus/procfs v0.20.1/go.mod h1:o9EMBZGRyvDrSPH1RqdxhojkuXstoe4UlK79eF5TGGo= +github.com/prometheus/client_golang v1.24.1 h1:JnJkREXzWxUdCuPFpIWZiPispT9xVV59uiuyR2bPlnU= +github.com/prometheus/client_golang v1.24.1/go.mod h1:F+oSRECHg4sse5ucfYpYDeIv/hu68Zo0uoHKetWnzcE= +github.com/prometheus/client_model v0.6.3 h1:O0jaTVAYNxTHYInEPFJt5I3+sN8zqBtVMPTB1qyxiEo= +github.com/prometheus/client_model v0.6.3/go.mod h1:gpN5P9S7Rr6Yr92PiQ+Ixvhf6JZEkF1dnxsYL2aPBEM= +github.com/prometheus/common v0.71.0 h1:9KDAKb7Mj3HEVKyFCK6Dc/HIwlBzZIN2l7/lrHl3KK8= +github.com/prometheus/common v0.71.0/go.mod h1:CLJ5H8TEsGX8bl31BdMkfhIZ+QmZ9tBPPotUxUbfcmk= +github.com/prometheus/procfs v0.22.0 h1:6q9+/JL9IKAPbCmBrv9n5O5Ty3NKnciV5X7YGw0oics= +github.com/prometheus/procfs v0.22.0/go.mod h1:CvmFr/GVhIjIvWJZW3tgkODBQMRIf0EyWMQLHCHab58= github.com/rivo/uniseg v0.2.0/go.mod h1:J6wj4VEh+S6ZtnVlnTBMWIodfgj8LQOQFoIToxlJtxc= github.com/rivo/uniseg v0.4.7 h1:WUdvkW8uEhrYfLC4ZzdpI2ztxP1I582+49Oc5Mq64VQ= github.com/rivo/uniseg v0.4.7/go.mod h1:FN3SvrM+Zdj16jyLfmOkMNblXMcoc8DfTHruCPUcx88= @@ -384,20 +444,27 @@ github.com/russross/blackfriday/v2 v2.1.0 h1:JIOH55/0cWyOuilr9/qlrm0BSXldqnqwMsf github.com/russross/blackfriday/v2 v2.1.0/go.mod h1:+Rmxgy9KzJVeS9/2gXHxylqXiyQDYRxCVz55jmeOWTM= github.com/sergi/go-diff v1.4.0 h1:n/SP9D5ad1fORl+llWyN+D6qoUETXNZARKjyY2/KVCw= github.com/sergi/go-diff v1.4.0/go.mod h1:A0bzQcvG0E7Rwjx0REVgAGH58e96+X0MeOfepqsbeW4= +github.com/spf13/afero v1.15.0 h1:b/YBCLWAJdFWJTN9cLhiXXcD7mzKn9Dm86dNnfyQw1I= +github.com/spf13/afero v1.15.0/go.mod h1:NC2ByUVxtQs4b3sIUphxK0NioZnmxgyCrfzeuq8lxMg= github.com/spf13/cobra v1.10.2 h1:DMTTonx5m65Ic0GOoRY2c16WCbHxOOw6xxezuLaBpcU= github.com/spf13/cobra v1.10.2/go.mod h1:7C1pvHqHw5A4vrJfjNwvOdzYu0Gml16OCs2GRiTUUS4= github.com/spf13/pflag v1.0.9/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= github.com/spf13/pflag v1.0.10 h1:4EBh2KAYBwaONj6b2Ye1GiHfwjqyROoF4RwYO+vPwFk= github.com/spf13/pflag v1.0.10/go.mod h1:McXfInJRrz4CZXVZOBLb0bTZqETkiAhM9Iw0y3An2Bg= github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= +github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw= +github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo= github.com/stretchr/objx v0.5.3 h1:jmXUvGomnU1o3W/V5h2VEradbpJDwGrzugQQvL0POH4= github.com/stretchr/objx v0.5.3/go.mod h1:rDQraq+vQZU7Fde9LOZLr8Tax6zZvy4kuNKF+QYS+U0= github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI= github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4= github.com/stretchr/testify v1.5.1/go.mod h1:5W2xD1RspED5o8YsWQXVCued0rvSQ+mT+I5cxcmMvtA= github.com/stretchr/testify v1.7.0/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= -github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U= -github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U= +github.com/stretchr/testify v1.7.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= +github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO+kdMU+MU= +github.com/stretchr/testify v1.8.1/go.mod h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4= +github.com/stretchr/testify v1.12.1 h1:EuwCh5fleGS7H32xRwO3wRGT7DxrDhLAT6FF8MpWDWE= +github.com/stretchr/testify v1.12.1/go.mod h1:MDEgiDPPsNp5cuIrHPPCyornHKgEVbtFUmoNlxoYthg= github.com/teambition/rrule-go v1.8.2 h1:lIjpjvWTj9fFUZCmuoVDrKVOtdiyzbzc93qTmRVe/J8= github.com/teambition/rrule-go v1.8.2/go.mod h1:Ieq5AbrKGciP1V//Wq8ktsTXwSwJHDD5mD/wLBGl3p4= github.com/texttheater/golang-levenshtein v1.0.1 h1:+cRNoVrfiwufQPhoMzB6N0Yf/Mqajr6t1lOv8GyGE2U= @@ -427,6 +494,30 @@ github.com/xeipuuv/gojsonschema v1.2.0/go.mod h1:anYRn/JVcOK2ZgGU+IjEV4nwlhoK5sQ github.com/xrash/smetrics v0.0.0-20250705151800-55b8f293f342 h1:FnBeRrxr7OU4VvAzt5X7s6266i6cSVkkFPS0TuXWbIg= github.com/xrash/smetrics v0.0.0-20250705151800-55b8f293f342/go.mod h1:Ohn+xnUBiLI6FVj/9LpzZWtj1/D6lUovWYBkxHVV3aM= github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74= +github.com/yuin/gopher-lua v1.1.2 h1:yF/FjE3hD65tBbt0VXLE13HWS9h34fdzJmrWRXwobGA= +github.com/yuin/gopher-lua v1.1.2/go.mod h1:7aRmXIWl37SqRf0koeyylBEzJ+aPt8A+mmkQ4f1ntR8= +github.com/zclconf/go-cty v1.19.0 h1:IV8WdqYZc2c5rLX9bEoLNXKojBAp0MZPBHMIrCoa/s4= +github.com/zclconf/go-cty v1.19.0/go.mod h1:12W89jGn3JCOIQi7infWr9m80rOkb5RNYJqXMZcN4c8= +github.com/zclconf/go-cty-debug v0.0.0-20240509010212-0d6042c53940 h1:4r45xpDWB6ZMSMNJFMOjqrGHynW3DIBuR2H9j0ug+Mo= +github.com/zclconf/go-cty-debug v0.0.0-20240509010212-0d6042c53940/go.mod h1:CmBdvvj3nqzfzJ6nTCIwDTPZ56aVGvDrmztiO5g3qrM= +go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64= +go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0 h1:8tvICD4vSTOOsNrsI4Ljf6C+6UKvpTEH5XY3JMoyPoo= +go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.69.0/go.mod h1:z9+yiacE0IHRqM4qFfkbt/JYlmYXgss8GY/jXoNuPJI= +go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU= +go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 h1:4YsVu3B8+3qtWYYrsUYgn0OG78pN0rnNPRGX4SbokQI= +go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0/go.mod h1:+wnlSn0mD1ADVMe3v9Z/WIaiz6q6gL2J/ejaAmdmv80= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0 h1:qazEJlUOQzhCpzQpFETGby7EdqjI1wsd0W+6Gg1SCTU= +go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.44.0/go.mod h1:fOD2Yefuxixkx3ahVNf0O/PERb6r4OlbxfATVnYvzCo= +go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc= +go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo= +go.opentelemetry.io/otel/sdk v1.44.0 h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58= +go.opentelemetry.io/otel/sdk v1.44.0/go.mod h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0= +go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk= +go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE= +go.opentelemetry.io/proto/otlp v1.10.0 h1:IQRWgT5srOCYfiWnpqUYz9CVmbO8bFmKcwYxpuCSL2g= +go.opentelemetry.io/proto/otlp v1.10.0/go.mod h1:/CV4QoCR/S9yaPj8utp3lvQPoqMtxXdzn7ozvvozVqk= go.uber.org/goleak v1.3.0 h1:2K3zAYmnTNqV73imy9J1T3WC+gmCePx2hEGkimedGto= go.uber.org/goleak v1.3.0/go.mod h1:CoHD4mav9JJNrW/WLlf7HGZPjdw8EucARQHekz1X6bE= go.uber.org/multierr v1.11.0 h1:blXXJkSxSSfBVBlC76pxqeO+LN3aDfLQo+309xJstO0= @@ -435,32 +526,35 @@ go.uber.org/zap v1.28.0 h1:IZzaP1Fv73/T/pBMLk4VutPl36uNC+OSUh3JLG3FIjo= go.uber.org/zap v1.28.0/go.mod h1:rDLpOi171uODNm/mxFcuYWxDsqWSAVkFdX4XojSKg/Q= go.yaml.in/yaml/v2 v2.4.4 h1:tuyd0P+2Ont/d6e2rl3be67goVK4R6deVxCUX5vyPaQ= go.yaml.in/yaml/v2 v2.4.4/go.mod h1:gMZqIpDtDqOfM0uNfy0SkpRhvUryYH0Z6wdMYcacYXQ= -go.yaml.in/yaml/v3 v3.0.4 h1:tfq32ie2Jv2UxXFdLJdh3jXuOzWiL1fo0bu/FbuKpbc= go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg= +go.yaml.in/yaml/v3 v3.0.5 h1:N6y/pJk8buWs9NY5ERU2HSMfm+IuD/OtfdAnq6kESPw= +go.yaml.in/yaml/v3 v3.0.5/go.mod h1:HVTZu1O7/Vkt2N+BFy8Zza+lnLsABggaTM2ZpNIGuKg= +go.yaml.in/yaml/v4 v4.0.0-rc.6 h1:1h7H1ohdUh93/FyE4YaDa1Zh64K6VVbjF4K6WUxMtH4= +go.yaml.in/yaml/v4 v4.0.0-rc.6/go.mod h1:aZqd9kCMsGL7AuUv/m/PvWLdg5sjJsZ4oHDEnfPPfY0= golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w= golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI= golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto= -golang.org/x/crypto v0.52.0 h1:RMs7fP2rXdep0CftQlK8Uf+kibLm7qkCcradZWYz988= -golang.org/x/crypto v0.52.0/go.mod h1:1QgfPxDqh0T2M/elOJtp9RvuR95kVjir0e6/BvEmGbc= -golang.org/x/exp v0.0.0-20260312153236-7ab1446f8b90 h1:jiDhWWeC7jfWqR9c/uplMOqJ0sbNlNWv0UkzE0vX1MA= -golang.org/x/exp v0.0.0-20260312153236-7ab1446f8b90/go.mod h1:xE1HEv6b+1SCZ5/uscMRjUBKtIxworgEcEi+/n9NQDQ= +golang.org/x/crypto v0.57.0 h1:3ZVCjf8Ggz7zneR/EHRVx68Ctf+2pmIMP2UFhh9cC6M= +golang.org/x/crypto v0.57.0/go.mod h1:Fdz0i5U6CoizGwLda9DttjSk6qlZo25zYNtR+ycvuZA= +golang.org/x/exp v0.0.0-20260908205506-85c1c2202aba h1:Ck8QetSgk912qxWLMCKxd0in+aiyBQyDSMae6e/xmpU= +golang.org/x/exp v0.0.0-20260908205506-85c1c2202aba/go.mod h1:50RgIsmK7OwqzTTeqcSXQW8SswW0o8fRcDxmqGluJ8E= golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA= -golang.org/x/mod v0.35.0 h1:Ww1D637e6Pg+Zb2KrWfHQUnH2dQRLBQyAtpr/haaJeM= -golang.org/x/mod v0.35.0/go.mod h1:+GwiRhIInF8wPm+4AoT6L0FA1QWAad3OMdTRx4tFYlU= +golang.org/x/mod v0.41.0 h1:qJmnOUb4YB+FsEuM3HcWucdZASCPGhsX6uljO6pog0c= +golang.org/x/mod v0.41.0/go.mod h1:Ek9pY8RKWXwsWvd3rQiHYtMqkjSUV+s1Rj7j4H5Ur6o= golang.org/x/net v0.0.0-20180906233101-161cd47e91fd/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg= golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s= golang.org/x/net v0.0.0-20200520004742-59133d7f0dd7/go.mod h1:qpuaurCH72eLCgpAm/N6yyVIVM9cpaDIP3A8BGJEC5A= golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU= -golang.org/x/net v0.55.0 h1:bcvxaJn3e1U6InsFWt1JUq1aSjnRxLzT2rtD2KfkDF8= -golang.org/x/net v0.55.0/go.mod h1:L5U2KuzuOe1lY7Z+aWVIKK6qEeJXnXV9yzGA+WCHJww= -golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs= -golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q= +golang.org/x/net v0.59.0 h1:5zfYln+w5XCxwrnMMJPufRgNoXEaGxl0wo5GqPXyues= +golang.org/x/net v0.59.0/go.mod h1:2DA/G1UfVbCpQPeWTmMPGY7Cs2PkBkwu743bVX5PIVg= +golang.org/x/oauth2 v0.37.0 h1:JUlcxA8oAtauLfiH8FX2/FkAWHAdi0QtGCGc+hofE98= +golang.org/x/oauth2 v0.37.0/go.mod h1:IxwZNxUULJmpBFf9K/9NTMSIfZZuvuTy1gGxhigP/58= golang.org/x/sync v0.0.0-20180314180146-1d60e4601c6f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM= -golang.org/x/sync v0.21.0 h1:HLII4xRRTtCRkxYp4HNFF0Js/Og6q2i++KXbg0gHCwM= -golang.org/x/sync v0.21.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= +golang.org/x/sync v0.23.0 h1:KameEIfc1IkluZyXWLn39Wd4tURc6GbCiISGiZm2bQk= +golang.org/x/sync v0.23.0/go.mod h1:sUUOizhqBxiL6pEWpqNLUiaJn1ShEbZ6BBqskPbjZm0= golang.org/x/sys v0.0.0-20180909124046-d0be0721c37e/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY= golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs= @@ -474,35 +568,46 @@ golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab/go.mod h1:oPkhp1MJrh7nUepCBc golang.org/x/sys v0.1.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= -golang.org/x/sys v0.45.0 h1:dO4czNzziLiiXplLQgBCEpCvXQ3dnkn0SdaZSYdQ+FY= -golang.org/x/sys v0.45.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= -golang.org/x/term v0.43.0 h1:S4RLU2sB31O/NCl+zFN9Aru9A/Cq2aqKpTZJ6B+DwT4= -golang.org/x/term v0.43.0/go.mod h1:lrhlHNdQJHO+1qVYiHfFKVuVioJIheAc3fBSMFYEIsk= +golang.org/x/sys v0.48.0 h1:bbX/i/6MgT9BVLM9RT1thmxL04yeTAhbEz4SyadbXoo= +golang.org/x/sys v0.48.0/go.mod h1:hNLxWAXmnKAxqDtdwIYC4bM9oQPEecfsnNMuSxOs3og= +golang.org/x/term v0.46.0 h1:3+OXuTbaKDgwk8jTi3aSLHRlmWqHEUDUtxnbFigO4YE= +golang.org/x/term v0.46.0/go.mod h1:+K02xbkittuwc0Am4abfA3Fc+XRGXkvBXNO88NCXPoc= golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ= golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ= -golang.org/x/text v0.37.0 h1:Cqjiwd9eSg8e0QAkyCaQTNHFIIzWtidPahFWR83rTrc= -golang.org/x/text v0.37.0/go.mod h1:a5sjxXGs9hsn/AJVwuElvCAo9v8QYLzvavO5z2PiM38= -golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U= -golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno= +golang.org/x/text v0.42.0 h1:JbOZXgfeCPU9gacVtYliJqOhD+zhrEqK4LfdpmlUZqI= +golang.org/x/text v0.42.0/go.mod h1:ojzP1Z+2QtioaF8DTtO8K5q7JWVVYwZKenzujK0Zd0E= +golang.org/x/time v0.16.0 h1:vMb6ptszcQMkcwiRTAuNNU50gom6++Q/6gY2hDM6VDE= +golang.org/x/time v0.16.0/go.mod h1:rVKOqvZeKvrDKTQiAHJ7wmwP0RzleSphoEA9RcdLA0s= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo= golang.org/x/tools v0.0.0-20201224043029-2b0845dc783e/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA= -golang.org/x/tools v0.44.0 h1:UP4ajHPIcuMjT1GqzDWRlalUEoY+uzoZKnhOjbIPD2c= -golang.org/x/tools v0.44.0/go.mod h1:KA0AfVErSdxRZIsOVipbv3rQhVXTnlU6UhKxHd1seDI= +golang.org/x/tools v0.50.0 h1:c2ifzfcuY7L90lZ2aKd8S4K2NpASF08SZx9ZuJkHmSU= +golang.org/x/tools v0.50.0/go.mod h1:7ulVMw3831Mwi5EZD6RomGyffr4VFjuNYXf2BbCEAV0= +golang.org/x/tools/go/expect v0.1.1-deprecated h1:jpBZDwmgPhXsKZC6WhL20P4b/wmnpsEAGHaNy0n/rJM= +golang.org/x/tools/go/expect v0.1.1-deprecated/go.mod h1:eihoPOH+FgIqa3FpoTwguz/bVUSGBlGQU67vpBeOrBY= +golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated h1:1h2MnaIAIXISqTFKdENegdpAgUXz6NrPEsbIeWaBRvM= +golang.org/x/tools/go/packages/packagestest v0.1.1-deprecated/go.mod h1:RVAQXBGNv1ib0J382/DPCRS/BPnsGebyM1Gj5VSDpG8= golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= gomodules.xyz/jsonpatch/v2 v2.5.0 h1:JELs8RLM12qJGXU4u/TO3V25KW8GreMKl9pdkk14RM0= gomodules.xyz/jsonpatch/v2 v2.5.0/go.mod h1:AH3dM2RI6uoBZxn3LVrfvJ3E0/9dG4cSrbuBJT4moAY= +google.golang.org/genproto v0.0.0-20260319201613-d00831a3d3e7 h1:XzmzkmB14QhVhgnawEVsOn6OFsnpyxNPRY9QV01dNB0= +google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa h1:Kjn0N0tCrDgiAFW+lGO4JZ3ck44CehvJQMAwj9QF0G8= +google.golang.org/genproto/googleapis/api v0.0.0-20260526163538-3dc84a4a5aaa/go.mod h1:q4lMZS6kskjT5HvCPrnnypcDPVJqT/f4nfxmkE7gryY= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa h1:mZHHdPZl0dbGHCflZgAq/Q468DWVFcU2whhB2KAo8fk= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= +google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE= +google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA= google.golang.org/protobuf v0.0.0-20200109180630-ec00e32a8dfd/go.mod h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8= google.golang.org/protobuf v0.0.0-20200221191635-4d8936d0db64/go.mod h1:kwYJMbMJ01Woi6D6+Kah6886xMZcty6N08ah7+eCXa0= google.golang.org/protobuf v0.0.0-20200228230310-ab0ca4ff8a60/go.mod h1:cfTl7dwQJ+fmap5saPgwCLgHXTUD7jkjRqWcaiX5VyM= google.golang.org/protobuf v1.20.1-0.20200309200217-e05f789c0967/go.mod h1:A+miEFZTKqfCUM6K7xSMQL9OKL/b6hQv+e19PK+JZNE= google.golang.org/protobuf v1.21.0/go.mod h1:47Nbq4nVaFHyn7ilMalzfO3qCViNmqZ2kzikPIcrTAo= google.golang.org/protobuf v1.23.0/go.mod h1:EGpADcykh3NcUnDUJcl1+ZksZNG86OlYog2l/sGQquU= -google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af h1:+5/Sw3GsDNlEmu7TfklWKPdQ0Ykja5VEmq2i817+jbI= -google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco= +google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc= +google.golang.org/protobuf v1.36.12/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk= @@ -521,29 +626,43 @@ gopkg.in/yaml.v2 v2.4.0/go.mod h1:RDklbk79AGWmwhnvt/jBztapEOGDOx6ZbXqjP6csGnQ= gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= -k8s.io/api v0.36.2 h1:TF6YDLIzKfccK7cq9YpTcGX8TJmEkHVRv78DM51fRYY= -k8s.io/api v0.36.2/go.mod h1:F4LbMO4brjZYh7yFkXWhynSvtB7YauxV4c+HHkNRGNg= -k8s.io/apiextensions-apiserver v0.36.0 h1:Wt7E8J+VBCbj4FjiBfDTK/neXDDjyJVJc7xfuOHImZ0= -k8s.io/apiextensions-apiserver v0.36.0/go.mod h1:kGDjH0msuiIB3tgsYRV0kS9GqpMYMUsQ3GHv7TApyug= -k8s.io/apimachinery v0.36.2 h1:0PE/W/WNy1UX61NLbXY5TMbJ6UwLL6E6lAPkYrKFxbQ= -k8s.io/apimachinery v0.36.2/go.mod h1:fvf/HOLXq9RId0rnDIbN1OEBvHXdQbLMM8nu0LcBUf4= -k8s.io/client-go v0.36.2 h1:bfgxmFKc9CgqsgX4xKLAAdmTQlWee7Ob/HlDOrJ5TBI= -k8s.io/client-go v0.36.2/go.mod h1:1vgO4OAlfPnoLcb+Rze2GF5rAr14w8qjrYMoyXJzQj0= +k8s.io/api v0.37.0 h1:Z//Vj9N7RA/yS2sDmxyeo7h+RR4zbUrd2vrd3Z0TbB4= +k8s.io/api v0.37.0/go.mod h1:LKXgcJWMc+f4OLbP5SFR8rulEg07zZhpi/zMULiBImk= +k8s.io/apiextensions-apiserver v0.37.0 h1:zRMQ3+/LIE5oZ0tVvXwYHC+dIkSP5cjNWju7AZU1LOI= +k8s.io/apiextensions-apiserver v0.37.0/go.mod h1:HU0PfSBwchHL5iDau6jjt9zU6ryWkDDlaVUiq91NK80= +k8s.io/apimachinery v0.37.0 h1:Np2AbDtf8x6RDHiD8T9LbKJ9gaegeVNa8yNm5FuGKm0= +k8s.io/apimachinery v0.37.0/go.mod h1:RN3nhprFSCxOi5Selxd7oMTXOe/c+ZbcE7Im+TS2zkE= +k8s.io/apiserver v0.37.0 h1:TXg7OxsOWrAH8J4Zi/gBAZuMw1Dfdd+6cca2h4qjRqo= +k8s.io/apiserver v0.37.0/go.mod h1:OddHDF4gy9qyIb8o/3+qaeP6S0vEObWLgOygVqXksv0= +k8s.io/client-go v0.37.0 h1:nsN31fy8wBySuZ+QRnKmrjRSQLOG2rvoGN0tKd12zhQ= +k8s.io/client-go v0.37.0/go.mod h1:FcGqw+Ll/gNQiq+nPGY1Oyt9y7SgDh1d3MW3RFDEbn0= +k8s.io/code-generator v0.37.0 h1:AC915wukzlVHHODAQYxvQ25WKibPh95faJ2kxf8dzuo= +k8s.io/code-generator v0.37.0/go.mod h1:qg7E/uDlyvevVRL1V8+h2z9UWmi/8gxaRka/lVXUBdk= +k8s.io/component-base v0.37.0 h1:3SdSa4+itMdFTDFTeR8CxKGmSTSMXFlKL4ky8OqjguM= +k8s.io/component-base v0.37.0/go.mod h1:LjOebp4R9y6LODWZQv102ZQxGheLcDO2ZJLAw6bbh4I= +k8s.io/gengo/v2 v2.0.0-20260408192533-25e2208e0dc3 h1:3L6PNkMLXkU/pz3jWzaaIUz0Rs2V9h+5O51AeRC7poc= +k8s.io/gengo/v2 v2.0.0-20260408192533-25e2208e0dc3/go.mod h1:yvyl3l9E+UxlqOMUULdKTAYB0rEhsmjr7+2Vb/1pCSo= k8s.io/klog/v2 v2.140.0 h1:Tf+J3AH7xnUzZyVVXhTgGhEKnFqye14aadWv7bzXdzc= k8s.io/klog/v2 v2.140.0/go.mod h1:o+/RWfJ6PwpnFn7OyAG3QnO47BFsymfEfrz6XyYSSp0= -k8s.io/kube-openapi v0.0.0-20260317180543-43fb72c5454a h1:xCeOEAOoGYl2jnJoHkC3hkbPJgdATINPMAxaynU2Ovg= -k8s.io/kube-openapi v0.0.0-20260317180543-43fb72c5454a/go.mod h1:uGBT7iTA6c6MvqUvSXIaYZo9ukscABYi2btjhvgKGZ0= -k8s.io/streaming v0.36.2 h1:NSKthPPg9UFSKsRauVJUVGH2Dvn8fhKmY4qrMkw/p98= -k8s.io/streaming v0.36.2/go.mod h1:z6fV3D+NVkoeqRMtWwlUZK6U17SY/LqNzOxWL6GyR/s= -k8s.io/utils v0.0.0-20260210185600-b8788abfbbc2 h1:AZYQSJemyQB5eRxqcPky+/7EdBj0xi3g0ZcxxJ7vbWU= -k8s.io/utils v0.0.0-20260210185600-b8788abfbbc2/go.mod h1:xDxuJ0whA3d0I4mf/C4ppKHxXynQ+fxnkmQH0vTHnuk= -sigs.k8s.io/controller-runtime v0.24.1 h1:miPEwrmirImAvgME1L9qebGHrOnGJoVmVdtOU9fRfo4= -sigs.k8s.io/controller-runtime v0.24.1/go.mod h1:vFkfY5fGt5xAC/sKb8IBFKgWPNKG9OUG29dR8Y2wImw= -sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730 h1:IpInykpT6ceI+QxKBbEflcR5EXP7sU1kvOlxwZh5txg= -sigs.k8s.io/json v0.0.0-20250730193827-2d320260d730/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= +k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad h1:oXImqH8mQNk7PmvzKhmN3ddJoY6OnyM225MXwGHPm0A= +k8s.io/kube-openapi v0.0.0-20260721132016-d427ff9ee9ad/go.mod h1:0/mqHCVhlumdJ3BhCfnjSZQE037nAhNodh1/hK0T8/I= +k8s.io/streaming v0.37.0 h1:iPBUZLZiKt5bV+lxJurASMOV07VuBhNpiwJt2//AWrM= +k8s.io/streaming v0.37.0/go.mod h1:APlJR26ZWRcVy5bIEj0QRrKUXROtBHPcxl2NT7EAzPU= +k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3 h1:jVkFFVfXdXP74B/zbO3hM3hpSFD0xvhQ5U686DPurkE= +k8s.io/utils v0.0.0-20260707023825-cf1189d6abe3/go.mod h1:M2s5JB1lIYP3jzZdorPLHXIPJzt9vv2muW5a6L9DtNM= +sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.36.0 h1:/YpDJ4vReG7ZmzSpBGxduXgywWkJU9zHubgJG03MT+Y= +sigs.k8s.io/apiserver-network-proxy/konnectivity-client v0.36.0/go.mod h1:tJo1aepTXyR+8Xs3sUsGBDk4Ub2AM5dPAPKJx0mpm5c= +sigs.k8s.io/controller-runtime v0.25.1 h1:BKgU9OeE8xv8EbbM8cY0NVzTQs35rokkdq1jh12fMb4= +sigs.k8s.io/controller-runtime v0.25.1/go.mod h1:4QqLdT6z/L6Olj8JJCtvztid4/fnIiYsfaTFScegctc= +sigs.k8s.io/controller-runtime/tools/setup-envtest v0.25.1 h1:OYp0AfSZ1zr338OwcQC4PsyBuaHjkgHEfPuNFTFqw2Y= +sigs.k8s.io/controller-runtime/tools/setup-envtest v0.25.1/go.mod h1:q4i4kLTq6J6o29RUAQieHH8LS5knNkpgalnBhvrLp/8= +sigs.k8s.io/controller-tools v0.22.0 h1:eG3FAVja/KnlXKIWg95udIFz1cMyAtMjP11cqBh3t+k= +sigs.k8s.io/controller-tools v0.22.0/go.mod h1:VizwUStoZK7rReCj704czGGrB7mLxXTiJSJt7wN5ilI= +sigs.k8s.io/json v0.0.0-20260909141634-11ed52e25bc5 h1:k9jo7ED/fsfOcz3L1P20P5tjTNtsdQNwMOG2aKzHrl8= +sigs.k8s.io/json v0.0.0-20260909141634-11ed52e25bc5/go.mod h1:mdzfpAEoE6DHQEN0uh9ZbOCuHbLK5wOm7dK4ctXE9Tg= sigs.k8s.io/randfill v1.0.0 h1:JfjMILfT8A6RbawdsK2JXGBR5AQVfd+9TbzrlneTyrU= sigs.k8s.io/randfill v1.0.0/go.mod h1:XeLlZ/jmk4i1HRopwe7/aU3H5n1zNUcX6TM94b3QxOY= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2 h1:kwVWMx5yS1CrnFWA/2QHyRVJ8jM6dBA80uLmm0wJkk8= -sigs.k8s.io/structured-merge-diff/v6 v6.3.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= +sigs.k8s.io/structured-merge-diff/v6 v6.4.2 h1:qdOxHwrl2Kaag1aQEarlYcOA9vSyGCp3CIki3aW8c4Q= +sigs.k8s.io/structured-merge-diff/v6 v6.4.2/go.mod h1:M3W8sfWvn2HhQDIbGWj3S099YozAsymCo/wrT5ohRUE= sigs.k8s.io/yaml v1.6.0 h1:G8fkbMSAFqgEFgh4b1wmtzDnioxFCUgTZhlbj5P9QYs= sigs.k8s.io/yaml v1.6.0/go.mod h1:796bPqUfzR/0jLAl6XjHl3Ck7MiyVv8dbTdyT3/pMf4= diff --git a/test/e2e/e2e_test.go b/test/e2e/e2e_test.go index 2df5700e..83d7451a 100644 --- a/test/e2e/e2e_test.go +++ b/test/e2e/e2e_test.go @@ -1053,7 +1053,7 @@ func installActionsWorkflow(t *testing.T, testName, runnerLabel, testResultCMNam var container string if kubernetesContainerMode { - container = "golang:1.24" + container = "golang:1.27.1" } for _, j := range testJobs { @@ -1118,7 +1118,7 @@ func installActionsWorkflow(t *testing.T, testName, runnerLabel, testResultCMNam testing.Step{ Uses: "actions/setup-go@v3", With: &testing.With{ - GoVersion: "1.26.3", + GoVersion: "1.27.1", }, }, )