Skip to main content
Version: 1.33.2

OnPremises - SD On Premises Cluster Schema

This document explains the full schema for the kind: OnPremises for the furyctl.yaml file used by furyctl. This configuration file will be used to deploy the SIGHUP Distribution modules and cluster on premises.

An example configuration file can be created by running the following command:

furyctl create config --kind OnPremises --version v1.29.4 --name example-cluster
note

Replace the version with your desired version of KFD.

Properties​

PropertyTypeRequired
apiVersionstringRequired
flagsobjectOptional
kindstringRequired
metadataobjectRequired
specobjectRequired

Description​

A SD Cluster deployed on top of a set of existing VMs.

.apiVersion​

Constraints​

pattern: the string must match the following regular expression:

^kfd\.sighup\.io/v\d+((alpha|beta)\d+)?$

try pattern

.flags​

Description​

Persistent furyctl command flags, see the documentation for more details: https://docs.sighup.io/furyctl/flags-configuration

.kind​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"OnPremises"

.metadata​

Properties​

PropertyTypeRequired
namestringRequired

.metadata.name​

Description​

The name of the cluster. It will also be used as a prefix for all the other resources created.

Constraints​

maximum length: the maximum number of characters for this string is: 56

minimum length: the minimum number of characters for this string is: 1

.spec​

Properties​

PropertyTypeRequired
distributionobjectRequired
distributionVersionstringRequired
kubernetesobjectOptional
pluginsobjectOptional

.spec.distribution​

Properties​

PropertyTypeRequired
commonobjectOptional
customPatchesobjectOptional
modulesobjectRequired

.spec.distribution.common​

Properties​

PropertyTypeRequired
networkPoliciesEnabledbooleanOptional
nodeSelectorobjectOptional
providerobjectOptional
registrystringOptional
relativeVendorPathstringOptional
tolerationsarrayOptional

Description​

Common configuration for all the distribution modules.

.spec.distribution.common.networkPoliciesEnabled​

Description​

EXPERIMENTAL FEATURE. This field defines whether Network Policies are provided for core modules.

.spec.distribution.common.nodeSelector​

Description​

The node selector to use to place the pods for all the SD modules. Follows Kubernetes selector format. Example: node.kubernetes.io/role: infra.

.spec.distribution.common.provider​

Properties​

PropertyTypeRequired
typestringRequired

.spec.distribution.common.provider.type​

Description​

The provider type. Don't set. FOR INTERNAL USE ONLY.

.spec.distribution.common.registry​

Description​

URL of the registry where to pull images from for the Distribution phase. (Default is registry.sighup.io/fury).

NOTE: If plugins are pulling from the default registry, the registry will be replaced for the plugin too.

.spec.distribution.common.relativeVendorPath​

Description​

The relative path to the vendor directory, does not need to be changed.

.spec.distribution.common.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

An array with the tolerations that will be added to the pods for all the SD modules. Follows Kubernetes tolerations format. Example:

- effect: NoSchedule
key: node.kubernetes.io/role
value: infra

.spec.distribution.common.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.common.tolerations.key​

Description​

The key of the toleration

.spec.distribution.common.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.common.tolerations.value​

Description​

The value of the toleration

.spec.distribution.customPatches​

Properties​

PropertyTypeRequired
configMapGeneratorarrayOptional
imagesarrayOptional
patchesarrayOptional
patchesStrategicMergearrayOptional
secretGeneratorarrayOptional

.spec.distribution.customPatches.configMapGenerator​

Properties​

PropertyTypeRequired
behaviorstringOptional
envsarrayOptional
filesarrayOptional
literalsarrayOptional
namestringRequired
namespacestringOptional
optionsobjectOptional

.spec.distribution.customPatches.configMapGenerator.behavior​

Description​

The behavior of the configmap

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"create"
"replace"
"merge"

.spec.distribution.customPatches.configMapGenerator.envs​

Description​

The envs of the configmap

.spec.distribution.customPatches.configMapGenerator.files​

Description​

The files of the configmap

.spec.distribution.customPatches.configMapGenerator.literals​

Description​

The literals of the configmap

.spec.distribution.customPatches.configMapGenerator.name​

Description​

The name of the configmap

.spec.distribution.customPatches.configMapGenerator.namespace​

Description​

The namespace of the configmap

.spec.distribution.customPatches.configMapGenerator.options​

Properties​

PropertyTypeRequired
annotationsobjectOptional
disableNameSuffixHashbooleanOptional
immutablebooleanOptional
labelsobjectOptional

.spec.distribution.customPatches.configMapGenerator.options.annotations​

Description​

The annotations of the configmap

.spec.distribution.customPatches.configMapGenerator.options.disableNameSuffixHash​

Description​

If true, the name suffix hash will be disabled

.spec.distribution.customPatches.configMapGenerator.options.immutable​

Description​

If true, the configmap will be immutable

.spec.distribution.customPatches.configMapGenerator.options.labels​

Description​

The labels of the configmap

.spec.distribution.customPatches.images​

Description​

Each entry should follow the format of Kustomize's images patch

.spec.distribution.customPatches.patches​

Properties​

PropertyTypeRequired
optionsobjectOptional
patchstringOptional
pathstringOptional
targetobjectOptional

.spec.distribution.customPatches.patches.options​

Properties​

PropertyTypeRequired
allowKindChangebooleanOptional
allowNameChangebooleanOptional

.spec.distribution.customPatches.patches.options.allowKindChange​

Description​

If true, the kind change will be allowed

.spec.distribution.customPatches.patches.options.allowNameChange​

Description​

If true, the name change will be allowed

.spec.distribution.customPatches.patches.patch​

Description​

The patch content

.spec.distribution.customPatches.patches.path​

Description​

The path of the patch

.spec.distribution.customPatches.patches.target​

Properties​

PropertyTypeRequired
annotationSelectorstringOptional
groupstringOptional
kindstringOptional
labelSelectorstringOptional
namestringOptional
namespacestringOptional
versionstringOptional

.spec.distribution.customPatches.patches.target.annotationSelector​

Description​

The annotation selector of the target

.spec.distribution.customPatches.patches.target.group​

Description​

The group of the target

.spec.distribution.customPatches.patches.target.kind​

Description​

The kind of the target

.spec.distribution.customPatches.patches.target.labelSelector​

Description​

The label selector of the target

.spec.distribution.customPatches.patches.target.name​

Description​

The name of the target

.spec.distribution.customPatches.patches.target.namespace​

Description​

The namespace of the target

.spec.distribution.customPatches.patches.target.version​

Description​

The version of the target

.spec.distribution.customPatches.patchesStrategicMerge​

Description​

Each entry should be either a relative file path or an inline content resolving to a partial or complete resource definition

.spec.distribution.customPatches.secretGenerator​

Properties​

PropertyTypeRequired
behaviorstringOptional
envsarrayOptional
filesarrayOptional
literalsarrayOptional
namestringRequired
namespacestringOptional
optionsobjectOptional
typestringOptional

.spec.distribution.customPatches.secretGenerator.behavior​

Description​

The behavior of the secret

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"create"
"replace"
"merge"

.spec.distribution.customPatches.secretGenerator.envs​

Description​

The envs of the secret

.spec.distribution.customPatches.secretGenerator.files​

Description​

The files of the secret

.spec.distribution.customPatches.secretGenerator.literals​

Description​

The literals of the secret

.spec.distribution.customPatches.secretGenerator.name​

Description​

The name of the secret

.spec.distribution.customPatches.secretGenerator.namespace​

Description​

The namespace of the secret

.spec.distribution.customPatches.secretGenerator.options​

Properties​

PropertyTypeRequired
annotationsobjectOptional
disableNameSuffixHashbooleanOptional
immutablebooleanOptional
labelsobjectOptional

.spec.distribution.customPatches.secretGenerator.options.annotations​

Description​

The annotations of the secret

.spec.distribution.customPatches.secretGenerator.options.disableNameSuffixHash​

Description​

If true, the name suffix hash will be disabled

.spec.distribution.customPatches.secretGenerator.options.immutable​

Description​

If true, the secret will be immutable

.spec.distribution.customPatches.secretGenerator.options.labels​

Description​

The labels of the secret

.spec.distribution.customPatches.secretGenerator.type​

Description​

The type of the secret

.spec.distribution.modules​

Properties​

PropertyTypeRequired
authobjectOptional
drobjectRequired
ingressobjectRequired
loggingobjectRequired
monitoringobjectOptional
networkingobjectOptional
policyobjectRequired
tracingobjectOptional

.spec.distribution.modules.auth​

Properties​

PropertyTypeRequired
baseDomainstringOptional
dexobjectOptional
oidcKubernetesAuthobjectOptional
oidcTrustedCAstringOptional
overridesobjectOptional
pomeriumobjectOptional
providerobjectRequired

Description​

Configuration for the Auth module.

.spec.distribution.modules.auth.baseDomain​

Description​

The base domain for the ingresses created by the Auth module (Gangplank, Pomerium, Dex). Notice that when the ingress module type is dual, these will use the external ingress class.

.spec.distribution.modules.auth.dex​

Properties​

PropertyTypeRequired
additionalStaticClientsarrayOptional
connectorsarrayRequired
expiryobjectOptional
overridesobjectOptional

Description​

Configuration for the Dex package.

.spec.distribution.modules.auth.dex.additionalStaticClients​

Description​

Additional static clients defitions that will be added to the default clients included with the distribution in Dex's configuration. Example:

additionalStaticClients:
- id: my-custom-client
name: "A custom additional static client"
redirectURIs:
- "https://myapp.tld/redirect"
- "https://alias.tld/oidc-callback"
secret: supersecretpassword

Reference: https://dexidp.io/docs/connectors/local/

.spec.distribution.modules.auth.dex.connectors​

Description​

A list with each item defining a Dex connector. Follows Dex connectors configuration format: https://dexidp.io/docs/connectors/

.spec.distribution.modules.auth.dex.expiry​

Properties​

PropertyTypeRequired
idTokensstringOptional
signingKeysstringOptional

.spec.distribution.modules.auth.dex.expiry.idTokens​

Description​

Dex ID tokens expiration time duration (default 24h).

.spec.distribution.modules.auth.dex.expiry.signingKeys​

Description​

Dex signing key expiration time duration (default 6h).

.spec.distribution.modules.auth.dex.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.auth.dex.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.auth.dex.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.auth.dex.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.auth.dex.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.auth.dex.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.auth.dex.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.auth.oidcKubernetesAuth​

Properties​

PropertyTypeRequired
clientIDstringOptional
clientSecretstringOptional
emailClaimstringOptional
enabledbooleanRequired
namespacestringOptional
removeCAFromKubeconfigbooleanOptional
scopesarrayOptional
sessionSecurityKeystringOptional
usernameClaimstringOptional

.spec.distribution.modules.auth.oidcKubernetesAuth.clientID​

Description​

The client ID that the Kubernetes API will use to authenticate against the OIDC provider (Dex).

.spec.distribution.modules.auth.oidcKubernetesAuth.clientSecret​

Description​

The client secret that the Kubernetes API will use to authenticate against the OIDC provider (Dex).

.spec.distribution.modules.auth.oidcKubernetesAuth.emailClaim​

Description​

DEPRECATED. Defaults to email.

.spec.distribution.modules.auth.oidcKubernetesAuth.enabled​

Description​

If true, components needed for interacting with the Kubernetes API with OIDC authentication (Gangplank, Dex) be deployed and configued.

.spec.distribution.modules.auth.oidcKubernetesAuth.namespace​

Description​

The namespace to set in the context of the kubeconfig file generated by Gangplank. Defaults to default.

.spec.distribution.modules.auth.oidcKubernetesAuth.removeCAFromKubeconfig​

Description​

Set to true to remove the CA from the kubeconfig file generated by Gangplank.

.spec.distribution.modules.auth.oidcKubernetesAuth.scopes​

Description​

Used to specify the scope of the requested Oauth authorization by Gangplank. Defaults to: ["openid", "profile", "email", "offline_access", "groups"]

.spec.distribution.modules.auth.oidcKubernetesAuth.sessionSecurityKey​

Description​

The Key to use for the sessions in Gangplank. Must be different between different instances of Gangplank.

.spec.distribution.modules.auth.oidcKubernetesAuth.usernameClaim​

Description​

The JWT claim to use as the username. This is used in Gangplank's UI. This is combined with the clusterName for the user portion of the kubeconfig. Defaults to nickname.

.spec.distribution.modules.auth.oidcTrustedCA​

Description​

The Certificate Authority certificate file's content to trust for self-signed certificates at the OAuth2 URL. You can use the "{file://<path>}" notation to get the content from a file.

.spec.distribution.modules.auth.overrides​

Properties​

PropertyTypeRequired
ingressesobjectOptional
nodeSelectorobjectOptional
tolerationsarrayOptional

Description​

Override the common configuration with a particular configuration for the Auth module.

.spec.distribution.modules.auth.overrides.ingresses​

Properties​

PropertyTypeRequired
dexobjectOptional
gangplankobjectOptional

Description​

Override the definition of the Auth module ingresses.

.spec.distribution.modules.auth.overrides.ingresses.dex​

Properties​

PropertyTypeRequired
hoststringRequired
ingressClassstringRequired

.spec.distribution.modules.auth.overrides.ingresses.dex.host​

Description​

Use this host for the ingress instead of the default one.

.spec.distribution.modules.auth.overrides.ingresses.dex.ingressClass​

Description​

Use this ingress class for the ingress instead of the default one.

.spec.distribution.modules.auth.overrides.ingresses.gangplank​

Properties​

PropertyTypeRequired
hoststringRequired
ingressClassstringRequired

.spec.distribution.modules.auth.overrides.ingresses.gangplank.host​

Description​

Use this host for the ingress instead of the default one.

.spec.distribution.modules.auth.overrides.ingresses.gangplank.ingressClass​

Description​

Use this ingress class for the ingress instead of the default one.

.spec.distribution.modules.auth.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the Auth module.

.spec.distribution.modules.auth.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the Auth module.

.spec.distribution.modules.auth.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.auth.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.auth.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.auth.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.auth.pomerium​

Properties​

PropertyTypeRequired
defaultRoutesPolicyobjectOptional
overridesobjectOptional
policystringOptional
routesarrayOptional
secretsobjectRequired

Description​

Configuration for Pomerium, an identity-aware reverse proxy used for SSO.

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy​

Properties​

PropertyTypeRequired
gatekeeperPolicyManagerarrayOptional
hubbleUiarrayOptional
ingressForecastlearrayOptional
loggingMinioConsolearrayOptional
loggingOpensearchDashboardsarrayOptional
monitoringAlertmanagerarrayOptional
monitoringGrafanaarrayOptional
monitoringMinioConsolearrayOptional
monitoringPrometheusarrayOptional
tracingMinioConsolearrayOptional

Description​

override default routes for SD components

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.gatekeeperPolicyManager​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.hubbleUi​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.ingressForecastle​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.loggingMinioConsole​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.loggingOpensearchDashboards​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.monitoringAlertmanager​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.monitoringGrafana​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.monitoringMinioConsole​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.monitoringPrometheus​

.spec.distribution.modules.auth.pomerium.defaultRoutesPolicy.tracingMinioConsole​

.spec.distribution.modules.auth.pomerium.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.auth.pomerium.overrides.nodeSelector​

.spec.distribution.modules.auth.pomerium.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringRequired

.spec.distribution.modules.auth.pomerium.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.auth.pomerium.overrides.tolerations.key​

.spec.distribution.modules.auth.pomerium.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.auth.pomerium.overrides.tolerations.value​

.spec.distribution.modules.auth.pomerium.policy​

Description​

DEPRECATED: Use defaultRoutesPolicy and/or routes

.spec.distribution.modules.auth.pomerium.routes​

Description​

Additional routes configuration for Pomerium. Follows Pomerium's route format: https://www.pomerium.com/docs/reference/routes

.spec.distribution.modules.auth.pomerium.secrets​

Properties​

PropertyTypeRequired
COOKIE_SECRETstringRequired
IDP_CLIENT_SECRETstringRequired
SHARED_SECRETstringRequired
SIGNING_KEYstringRequired

Description​

Pomerium needs some user-provided secrets to be fully configured. These secrets should be unique between clusters.

.spec.distribution.modules.auth.pomerium.secrets.COOKIE_SECRET​

Description​

Cookie Secret is the secret used to encrypt and sign session cookies.

To generate a random key, run the following command: head -c32 /dev/urandom | base64

.spec.distribution.modules.auth.pomerium.secrets.IDP_CLIENT_SECRET​

Description​

Identity Provider Client Secret is the OAuth 2.0 Secret Identifier. When auth type is SSO, this value will be the secret used to authenticate Pomerium with Dex, use a strong random value.

.spec.distribution.modules.auth.pomerium.secrets.SHARED_SECRET​

Description​

Shared Secret is the base64-encoded, 256-bit key used to mutually authenticate requests between Pomerium services. It's critical that secret keys are random, and stored safely.

To generate a key, run the following command: head -c32 /dev/urandom | base64

.spec.distribution.modules.auth.pomerium.secrets.SIGNING_KEY​

Description​

Signing Key is the base64 representation of one or more PEM-encoded private keys used to sign a user's attestation JWT, which can be consumed by upstream applications to pass along identifying user information like username, id, and groups.

To generates an P-256 (ES256) signing key:

openssl ecparam -genkey -name prime256v1 -noout -out ec_private.pem
# careful! this will output your private key in terminal
cat ec_private.pem | base64

.spec.distribution.modules.auth.provider​

Properties​

PropertyTypeRequired
basicAuthobjectOptional
typestringRequired

.spec.distribution.modules.auth.provider.basicAuth​

Properties​

PropertyTypeRequired
passwordstringRequired
usernamestringRequired

Description​

Configuration for the HTTP Basic Auth provider.

.spec.distribution.modules.auth.provider.basicAuth.password​

Description​

The password for logging in with the HTTP basic authentication.

.spec.distribution.modules.auth.provider.basicAuth.username​

Description​

The username for logging in with the HTTP basic authentication.

.spec.distribution.modules.auth.provider.type​

Description​

The type of the Auth provider, options are:

  • none: will disable authentication in the infrastructural ingresses.
  • sso: will protect the infrastructural ingresses with Pomerium and Dex (SSO) and require authentication before accessing them.
  • basicAuth: will protect the infrastructural ingresses with HTTP basic auth (username and password) authentication.

Default is none.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"none"
"basicAuth"
"sso"

.spec.distribution.modules.dr​

Properties​

PropertyTypeRequired
etcdBackupobjectOptional
overridesobjectOptional
typestringRequired
veleroobjectOptional

Description​

Configuration for the Disaster Recovery module.

.spec.distribution.modules.dr.etcdBackup​

Properties​

PropertyTypeRequired
backupPrefixstringOptional
pvcobjectOptional
s3objectOptional
typestringOptional

Description​

Configuration for the ETCD backup package.

.spec.distribution.modules.dr.etcdBackup.backupPrefix​

Description​

A prefix to be prepended to the backup filenames. If unset, the prefix defaults to the cluster's name.

.spec.distribution.modules.dr.etcdBackup.pvc​

Properties​

PropertyTypeRequired
accessModesarrayOptional
namestringOptional
retentionTimestringOptional
schedulestringOptional
sizestringOptional
storageClassstringOptional

Description​

Configuration parameters for the pvc type of etcdBackup.

.spec.distribution.modules.dr.etcdBackup.pvc.accessModes​

Description​

The accessModes that the furyctl-managed PersistentVolumeClaim will use. This has no effect and is ignored if name is set. Default is ["ReadOnlyOnce"]

.spec.distribution.modules.dr.etcdBackup.pvc.name​

Description​

The PersistentVolumeClaim name where the backups will be saved. If set, size and storageClass will be ignored and etcd-backup will use the PersistentVolumeClaim that matches the name set. Please note that the PersistentVolumeClaim must be created inside the kube-system namespace.

If you leave name unset furyctl will create a PersistentVolumeClaim for you with an arbitrary name.

.spec.distribution.modules.dr.etcdBackup.pvc.retentionTime​

Description​

The retention time of the backups inside the PersistentVolumeClaim. Follows rclone's min-age format. Example: '30d' for 30 days. Default is 10d (ten days).

.spec.distribution.modules.dr.etcdBackup.pvc.schedule​

Description​

The cron expression for the etcd-backup-pvc backup schedule. Default is 0 1 * * * (everyday at 01:00).

.spec.distribution.modules.dr.etcdBackup.pvc.size​

Description​

The size that the furyctl-managed PersistentVolumeClaim will use. This has no effect and is ignored if name is set. Default is 10G.

.spec.distribution.modules.dr.etcdBackup.pvc.storageClass​

Description​

The storage class that the furyctl-managed PersistentVolumeClaim will use. This has no effect and is ignored if name is set. Default is default.

.spec.distribution.modules.dr.etcdBackup.s3​

Properties​

PropertyTypeRequired
accessKeyIdstringRequired
bucketNamestringRequired
endpointstringRequired
insecurebooleanOptional
retentionTimestringOptional
schedulestringOptional
secretAccessKeystringRequired

Description​

Configuration parameters for the s3 type of etcdBackup.

.spec.distribution.modules.dr.etcdBackup.s3.accessKeyId​

Description​

The access key ID (username) for the external S3-compatible bucket.

.spec.distribution.modules.dr.etcdBackup.s3.bucketName​

Description​

The bucket name of the external S3-compatible object storage.

.spec.distribution.modules.dr.etcdBackup.s3.endpoint​

Description​

External S3-compatible endpoint for etcd-backup-s3's storage.

.spec.distribution.modules.dr.etcdBackup.s3.insecure​

Description​

If true, will use HTTP as protocol instead of HTTPS.

.spec.distribution.modules.dr.etcdBackup.s3.retentionTime​

Description​

The retention time of the external S3-compatible object storage. Follows rclone's min-age format. Example: '30d' for 30 days. Default is 10d (ten days).

.spec.distribution.modules.dr.etcdBackup.s3.schedule​

Description​

The cron expression for the etcd-backup-s3 backup schedule. Default is 0 1 * * * (everyday at 01:00).

.spec.distribution.modules.dr.etcdBackup.s3.secretAccessKey​

Description​

The secret access key (password) for the external S3-compatible bucket.

.spec.distribution.modules.dr.etcdBackup.type​

Description​

The type of the etcd backup to enable, options are:

  • none: no etcd backup CronJob will be installed and no etcd backup will be performed.
  • s3: the etcd-backup-s3 package will be enabled. It will deploy a CronJob which continuously snapshots a healthy etcd node and will save the backups in a configured S3 bucket.
  • pvc: the etcd-backup-pvc package will be enabled. It will deploy a CronJob which continuously snapshots a healthy etcd node and will save the backups in a configured PersistentVolumeClaim.
  • all: both kinds of backups will be enabled.

Default is none.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"s3"
"pvc"
"none"
"all"

.spec.distribution.modules.dr.overrides​

Properties​

PropertyTypeRequired
ingressesobjectOptional
nodeSelectorobjectOptional
tolerationsarrayOptional

Description​

Override the common configuration with a particular configuration for the module.

.spec.distribution.modules.dr.overrides.ingresses​

.spec.distribution.modules.dr.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the module.

.spec.distribution.modules.dr.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the module.

.spec.distribution.modules.dr.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.dr.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.dr.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.dr.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.dr.type​

Description​

The type of the Disaster Recovery, must be none or on-premises. none disables the module and on-premises will install Velero, an optional MinIO deployment and optionally etcd-backup.

Default is none.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"none"
"on-premises"

.spec.distribution.modules.dr.velero​

Properties​

PropertyTypeRequired
backendstringOptional
externalEndpointobjectOptional
gcsobjectOptional
nodeAgentobjectOptional
overridesobjectOptional
schedulesobjectOptional
snapshotControllerobjectOptional

Description​

Configuration for the Velero package.

.spec.distribution.modules.dr.velero.backend​

Description​

The storage backend type for Velero. minio will use an in-cluster MinIO deployment for object storage, externalEndpoint can be used to point to an external S3-compatible object storage instead of deploying an in-cluster MinIO, gcs can be used to point to an external GCS object storage instead of deploying an in-cluster MinIO.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"minio"
"externalEndpoint"
"gcs"

.spec.distribution.modules.dr.velero.externalEndpoint​

Properties​

PropertyTypeRequired
accessKeyIdstringOptional
accessModestringOptional
bucketNamestringOptional
endpointstringOptional
insecurebooleanOptional
prefixNamestringOptional
secretAccessKeystringOptional

Description​

Configuration for Velero's external storage backend.

.spec.distribution.modules.dr.velero.externalEndpoint.accessKeyId​

Description​

The access key ID (username) for the external S3-compatible bucket.

.spec.distribution.modules.dr.velero.externalEndpoint.accessMode​

Description​

How Velero can access the backup storage location.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"ReadWrite"
"ReadOnly"

.spec.distribution.modules.dr.velero.externalEndpoint.bucketName​

Description​

The bucket name of the external object storage.

.spec.distribution.modules.dr.velero.externalEndpoint.endpoint​

Description​

External S3-compatible endpoint for Velero's storage.

.spec.distribution.modules.dr.velero.externalEndpoint.insecure​

Description​

If true, will use HTTP as protocol instead of HTTPS.

.spec.distribution.modules.dr.velero.externalEndpoint.prefixName​

Description​

The prefix name to use inside the bucket.

.spec.distribution.modules.dr.velero.externalEndpoint.secretAccessKey​

Description​

The secret access key (password) for the external S3-compatible bucket.

.spec.distribution.modules.dr.velero.gcs​

Properties​

PropertyTypeRequired
accessModestringOptional
bucketNamestringOptional
clientEmailstringOptional
prefixNamestringOptional
serviceAccountStringstringOptional

Description​

Configuration for Velero's gcs storage backend.

.spec.distribution.modules.dr.velero.gcs.accessMode​

Description​

How Velero can access the backup storage location.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"ReadWrite"
"ReadOnly"

.spec.distribution.modules.dr.velero.gcs.bucketName​

Description​

The bucket name of the gcs object storage.

.spec.distribution.modules.dr.velero.gcs.clientEmail​

Description​

Full gcs client email.

.spec.distribution.modules.dr.velero.gcs.prefixName​

Description​

The prefix name to use inside the gcs bucket.

.spec.distribution.modules.dr.velero.gcs.serviceAccountString​

Description​

Service gcs account JSON string.

.spec.distribution.modules.dr.velero.nodeAgent​

Properties​

PropertyTypeRequired
prepareQueueLengthintegerOptional

Description​

Configuration for Velero's node-agent DaemonSet.

.spec.distribution.modules.dr.velero.nodeAgent.prepareQueueLength​

Description​

Defines the maximum number of DataUpload/DataDownload/PodVolumeBackup/PodVolumeRestore CRs under preparation statuses but not yet processed by any node. This constrains the number of intermediate objects (PVCs, VolumeSnapshots, etc.) to prevent unnecessary resource usage when cluster parallelism is limited.

.spec.distribution.modules.dr.velero.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.dr.velero.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.dr.velero.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.dr.velero.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.dr.velero.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.dr.velero.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.dr.velero.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.dr.velero.schedules​

Properties​

PropertyTypeRequired
definitionsobjectOptional
installbooleanOptional

Description​

Configuration for Velero's backup schedules.

.spec.distribution.modules.dr.velero.schedules.definitions​

Properties​

PropertyTypeRequired
fullobjectOptional
manifestsobjectOptional

Description​

Configuration for Velero schedules.

.spec.distribution.modules.dr.velero.schedules.definitions.full​

Properties​

PropertyTypeRequired
schedulestringOptional
snapshotMoveDatabooleanOptional
ttlstringOptional

Description​

Configuration for Velero's manifests backup schedule.

.spec.distribution.modules.dr.velero.schedules.definitions.full.schedule​

Description​

The cron expression for the full backup schedule (default 0 1 * * *).

.spec.distribution.modules.dr.velero.schedules.definitions.full.snapshotMoveData​

Description​

EXPERIMENTAL (if you do more than one backups, the following backups after the first are not automatically restorable, see https://github.com/vmware-tanzu/velero/issues/7057#issuecomment-2466815898 for the manual restore solution): SnapshotMoveData specifies whether snapshot data should be moved. Velero will create a new volume from the snapshot and upload the content to the storageLocation.

.spec.distribution.modules.dr.velero.schedules.definitions.full.ttl​

Description​

The Time To Live (TTL) of the backups created by the backup schedules (default 720h0m0s, 30 days). Notice that changing this value will affect only newly created backups, prior backups will keep the old TTL.

.spec.distribution.modules.dr.velero.schedules.definitions.manifests​

Properties​

PropertyTypeRequired
schedulestringOptional
ttlstringOptional

Description​

Configuration for Velero's manifests backup schedule.

.spec.distribution.modules.dr.velero.schedules.definitions.manifests.schedule​

Description​

The cron expression for the manifests backup schedule (default */15 * * * *).

.spec.distribution.modules.dr.velero.schedules.definitions.manifests.ttl​

Description​

The Time To Live (TTL) of the backups created by the backup schedules (default 720h0m0s, 30 days). Notice that changing this value will affect only newly created backups, prior backups will keep the old TTL.

.spec.distribution.modules.dr.velero.schedules.install​

Description​

Whether to install or not the default manifests and full backups schedules. Default is true.

.spec.distribution.modules.dr.velero.snapshotController​

Properties​

PropertyTypeRequired
installbooleanOptional

Description​

Configuration for the additional snapshotController component installation.

.spec.distribution.modules.dr.velero.snapshotController.install​

Description​

Whether to install or not the snapshotController component in the cluster. Before enabling this field, check if your CSI driver does not have snapshotController built-in.

.spec.distribution.modules.ingress​

Properties​

PropertyTypeRequired
baseDomainstringRequired
byoicobjectOptional
certManagerobjectOptional
forecastleobjectOptional
haproxyobjectOptional
infrastructureIngressControllerstringOptional
nginxobjectRequired
overridesobjectOptional

.spec.distribution.modules.ingress.baseDomain​

Description​

The base domain used for all the SD infrastructural ingresses. If using the nginx dual type, this value should be the same as the domain associated with the internal ingress class.

.spec.distribution.modules.ingress.byoic​

Properties​

PropertyTypeRequired
commonAnnotationsobjectOptional
enabledbooleanRequired
ingressClassstringOptional

Description​

Configuration for Bring Your Own Ingress Controller mode. The ingressClass is used for infrastructure ingresses when both controllers are disabled.

.spec.distribution.modules.ingress.byoic.commonAnnotations​

Description​

Annotations to apply to all infrastructure ingresses when using this BYOIC ingress class. Useful for controller-specific configuration (TLS, auth middlewares, etc.).

.spec.distribution.modules.ingress.byoic.enabled​

Description​

Enable BYOIC mode.

.spec.distribution.modules.ingress.byoic.ingressClass​

Description​

The IngressClass to use for infrastructure ingresses (Prometheus, Grafana, etc.) when both nginx and haproxy are disabled.

.spec.distribution.modules.ingress.certManager​

Properties​

PropertyTypeRequired
clusterIssuerobjectRequired
overridesobjectOptional

Description​

Configuration for the cert-manager package. Required even if ingress.nginx.type is none, cert-manager is used for managing other certificates in the cluster besides the TLS termination certificates for the ingresses.

.spec.distribution.modules.ingress.certManager.clusterIssuer​

Properties​

PropertyTypeRequired
emailstringRequired
namestringRequired
solversarrayOptional
typestringOptional

Description​

Configuration for the cert-manager's ACME clusterIssuer used to request certificates from Let's Encrypt.

.spec.distribution.modules.ingress.certManager.clusterIssuer.email​

Description​

The email address to use during the certificate issuing process.

.spec.distribution.modules.ingress.certManager.clusterIssuer.name​

Description​

The name of the clusterIssuer.

.spec.distribution.modules.ingress.certManager.clusterIssuer.solvers​

Description​

The list of challenge solvers to use instead of the default one for the http01 challenge. Check cert manager's documentation for examples for this field.

.spec.distribution.modules.ingress.certManager.clusterIssuer.type​

Description​

The type of the clusterIssuer. Only http01 challenge is supported for on-premises clusters. See solvers for arbitrary configurations.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"http01"

.spec.distribution.modules.ingress.certManager.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.ingress.certManager.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.ingress.certManager.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.ingress.certManager.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.ingress.certManager.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.ingress.certManager.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.ingress.certManager.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.ingress.forecastle​

Properties​

PropertyTypeRequired
overridesobjectOptional

.spec.distribution.modules.ingress.forecastle.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.ingress.forecastle.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.ingress.forecastle.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.ingress.forecastle.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.ingress.forecastle.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.ingress.forecastle.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.ingress.forecastle.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.ingress.haproxy​

Properties​

PropertyTypeRequired
overridesobjectOptional
tlsobjectOptional
typestringRequired

Description​

Configuration for HAProxy Kubernetes Ingress Controller.

.spec.distribution.modules.ingress.haproxy.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.ingress.haproxy.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.ingress.haproxy.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.ingress.haproxy.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.ingress.haproxy.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.ingress.haproxy.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.ingress.haproxy.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.ingress.haproxy.tls​

Properties​

PropertyTypeRequired
providerstringRequired
secretobjectOptional

Description​

TLS configuration for the HAProxy Kubernetes Ingress Controller.

.spec.distribution.modules.ingress.haproxy.tls.provider​

Description​

The provider of the TLS certificates for the ingresses, one of: none, certManager, or secret.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"certManager"
"secret"
"none"

.spec.distribution.modules.ingress.haproxy.tls.secret​

Properties​

PropertyTypeRequired
castringRequired
certstringRequired
keystringRequired

Description​

Kubernetes TLS secret for the HAProxy ingresses TLS certificate.

.spec.distribution.modules.ingress.haproxy.tls.secret.ca​

Description​

The Certificate Authority certificate file's content. You can use the "{file://<path>}" notation to get the content from a file.

.spec.distribution.modules.ingress.haproxy.tls.secret.cert​

Description​

The certificate file's content. You can use the "{file://<path>}" notation to get the content from a file.

.spec.distribution.modules.ingress.haproxy.tls.secret.key​

Description​

The signing key file's content. You can use the "{file://<path>}" notation to get the content from a file.

.spec.distribution.modules.ingress.haproxy.type​

Description​

The type of the HAProxy Kubernetes Ingress Controller, options are:

  • none: HAProxy ingress controller will not be installed.
  • single: a single HAProxy ingress controller with ingress class haproxy will be installed.
  • dual: two independent HAProxy ingress controllers will be installed, one for the haproxy-internal ingress class and one for the haproxy-external ingress class.

Default is none.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"none"
"single"
"dual"

.spec.distribution.modules.ingress.infrastructureIngressController​

Description​

Overrides the default ingress controller for SD infrastructure ingresses. Set to nginx or haproxy to select the controller family; the dual/single class mapping (e.g., haproxy-internal/haproxy-external) is applied automatically based on the controller's type setting. Useful during migrations to keep infrastructure ingresses on one controller while testing another. Do not use this field when both nginx.type and haproxy.type are none: in that case rely on byoic.ingressClass to define the ingress class for SD ingresses.

.spec.distribution.modules.ingress.nginx​

Properties​

PropertyTypeRequired
overridesobjectOptional
tlsobjectOptional
typestringRequired

Description​

(DEPRECATED) Configurations for the Ingress NGINX Controller package.

.spec.distribution.modules.ingress.nginx.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.ingress.nginx.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.ingress.nginx.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.ingress.nginx.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.ingress.nginx.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.ingress.nginx.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.ingress.nginx.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.ingress.nginx.tls​

Properties​

PropertyTypeRequired
providerstringRequired
secretobjectOptional

Description​

TLS configuration for the Ingress NGINX Controller.

.spec.distribution.modules.ingress.nginx.tls.provider​

Description​

The provider of the TLS certificates for the ingresses, one of: none, certManager, or secret.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"certManager"
"secret"
"none"

.spec.distribution.modules.ingress.nginx.tls.secret​

Properties​

PropertyTypeRequired
castringRequired
certstringRequired
keystringRequired

Description​

Kubernetes TLS secret for the ingresses TLS certificate.

.spec.distribution.modules.ingress.nginx.tls.secret.ca​

Description​

The Certificate Authority certificate file's content. You can use the "{file://<path>}" notation to get the content from a file.

.spec.distribution.modules.ingress.nginx.tls.secret.cert​

Description​

The certificate file's content. You can use the "{file://<path>}" notation to get the content from a file.

.spec.distribution.modules.ingress.nginx.tls.secret.key​

Description​

The signing key file's content. You can use the "{file://<path>}" notation to get the content from a file.

.spec.distribution.modules.ingress.nginx.type​

Description​

The type of the Ingress nginx controller, options are:

  • none: no ingress controller will be installed and no infrastructural ingresses will be created.
  • single: a single ingress controller with ingress class nginx will be installed to manage all the ingress resources, infrastructural ingresses will be created.
  • dual: two independent ingress controllers will be installed, one for the internal ingress class intended for private ingresses and one for the external ingress class intended for public ingresses. SD infrastructural ingresses wil use the internal ingress class when using the dual type.

Default is single.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"none"
"single"
"dual"

.spec.distribution.modules.ingress.overrides​

Properties​

PropertyTypeRequired
ingressesobjectOptional
nodeSelectorobjectOptional
tolerationsarrayOptional

Description​

Override the common configuration with a particular configuration for the Ingress module.

.spec.distribution.modules.ingress.overrides.ingresses​

Properties​

PropertyTypeRequired
forecastleobjectOptional

.spec.distribution.modules.ingress.overrides.ingresses.forecastle​

Properties​

PropertyTypeRequired
disableAuthbooleanOptional
hoststringOptional
ingressClassstringOptional

.spec.distribution.modules.ingress.overrides.ingresses.forecastle.disableAuth​

Description​

If true, the ingress will not have authentication even if .spec.modules.auth.provider.type is SSO or Basic Auth.

.spec.distribution.modules.ingress.overrides.ingresses.forecastle.host​

Description​

Use this host for the ingress instead of the default one.

.spec.distribution.modules.ingress.overrides.ingresses.forecastle.ingressClass​

Description​

Use this ingress class for the ingress instead of the default one.

.spec.distribution.modules.ingress.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the Ingress module.

.spec.distribution.modules.ingress.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the Ingress module.

.spec.distribution.modules.ingress.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.ingress.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.ingress.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.ingress.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.logging​

Properties​

PropertyTypeRequired
cerebroobjectOptional
customOutputsobjectOptional
lokiobjectOptional
minioobjectOptional
opensearchobjectOptional
operatorobjectOptional
overridesobjectOptional
typestringRequired

Description​

Configuration for the Logging module.

.spec.distribution.modules.logging.cerebro​

Properties​

PropertyTypeRequired
overridesobjectOptional

Description​

DEPRECATED since KFD v1.26.6, 1.27.5, v1.28.0.

.spec.distribution.modules.logging.cerebro.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.logging.cerebro.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.logging.cerebro.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.logging.cerebro.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.logging.cerebro.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.logging.cerebro.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.logging.cerebro.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.logging.customOutputs​

Properties​

PropertyTypeRequired
auditstringRequired
errorsstringRequired
eventsstringRequired
infrastringRequired
ingressHaproxystringRequired
ingressNginxstringRequired
kubernetesstringRequired
systemdCommonstringRequired
systemdEtcdstringRequired

Description​

When using the customOutputs logging type, you need to manually specify the spec of the several Output and ClusterOutputs that the Logging Operator expects to forward the logs collected by the pre-defined flows.

.spec.distribution.modules.logging.customOutputs.audit​

Description​

This value defines where the output from the audit Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.customOutputs.errors​

Description​

This value defines where the output from the errors Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.customOutputs.events​

Description​

This value defines where the output from the events Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.customOutputs.infra​

Description​

This value defines where the output from the infra Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.customOutputs.ingressHaproxy​

Description​

This value defines where the output from the ingressHaproxy Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.customOutputs.ingressNginx​

Description​

This value defines where the output from the ingressNginx Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.customOutputs.kubernetes​

Description​

This value defines where the output from the kubernetes Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.customOutputs.systemdCommon​

Description​

This value defines where the output from the systemdCommon Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.customOutputs.systemdEtcd​

Description​

This value defines where the output from the systemdEtcd Flow will be sent. This will be the spec section of the Output object. It must be a string (and not a YAML object) following the OutputSpec definition. Use the nullout output to discard the flow: nullout: {}

.spec.distribution.modules.logging.loki​

Properties​

PropertyTypeRequired
backendstringOptional
externalEndpointobjectOptional
resourcesobjectOptional
retentionTimestringOptional
tsdbStartDatestringOptional

Description​

Configuration for the Loki package.

.spec.distribution.modules.logging.loki.backend​

Description​

The storage backend type for Loki. minio will use an in-cluster MinIO deployment for object storage, externalEndpoint can be used to point to an external object storage instead of deploying an in-cluster MinIO.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"minio"
"externalEndpoint"

.spec.distribution.modules.logging.loki.externalEndpoint​

Properties​

PropertyTypeRequired
accessKeyIdstringOptional
bucketNamestringOptional
endpointstringOptional
insecurebooleanOptional
secretAccessKeystringOptional

Description​

Configuration for Loki's external storage backend.

.spec.distribution.modules.logging.loki.externalEndpoint.accessKeyId​

Description​

The access key ID (username) for the external S3-compatible bucket.

.spec.distribution.modules.logging.loki.externalEndpoint.bucketName​

Description​

The bucket name of the external S3-compatible object storage.

.spec.distribution.modules.logging.loki.externalEndpoint.endpoint​

Description​

External S3-compatible endpoint for Loki's storage.

.spec.distribution.modules.logging.loki.externalEndpoint.insecure​

Description​

If true, will use HTTP as protocol instead of HTTPS.

.spec.distribution.modules.logging.loki.externalEndpoint.secretAccessKey​

Description​

The secret access key (password) for the external S3-compatible bucket.

.spec.distribution.modules.logging.loki.resources​

Properties​

PropertyTypeRequired
limitsobjectOptional
requestsobjectOptional

.spec.distribution.modules.logging.loki.resources.limits​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.logging.loki.resources.limits.cpu​

Description​

The CPU limit for the Pod. Example: 1000m.

.spec.distribution.modules.logging.loki.resources.limits.memory​

Description​

The memory limit for the Pod. Example: 1G.

.spec.distribution.modules.logging.loki.resources.requests​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.logging.loki.resources.requests.cpu​

Description​

The CPU request for the Pod, in cores. Example: 500m.

.spec.distribution.modules.logging.loki.resources.requests.memory​

Description​

The memory request for the Pod. Example: 500M.

.spec.distribution.modules.logging.loki.retentionTime​

Description​

Optional retention period for logs stored in Loki (default 720h, 30 days). Setting it to 0s disables retention. Format must match: [0-9]+(s|m|h|d|w|y).

.spec.distribution.modules.logging.loki.tsdbStartDate​

Description​

Starting from versions 1.28.4, 1.29.5 and 1.30.0 of SIGHUP Distribution, Loki changed the time series database from BoltDB to TSDB and the schema that it uses to store the logs from v11 to v13.

The value of this field will determine the date when Loki will start writing using the new TSDB and the schema v13, always at midnight UTC. The old BoltDB and schema will be kept until all the logs expire for reading purposes.

From versions 1.29.7, 1.30.2 and 1.31.1 of the Distribution, this field will be immutable once set and its value should be a date before upgrading to one of these versions or creating the cluster, Loki does not support writing BoltDB and schema v11 anymore.

Value must be a string in ISO 8601 date format (yyyy-mm-dd). Example: 2024-11-18.

.spec.distribution.modules.logging.minio​

Properties​

PropertyTypeRequired
overridesobjectOptional
rootUserobjectOptional
storageSizestringOptional

Description​

Configuration for Logging's MinIO deployment.

.spec.distribution.modules.logging.minio.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.logging.minio.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.logging.minio.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.logging.minio.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.logging.minio.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.logging.minio.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.logging.minio.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.logging.minio.rootUser​

Properties​

PropertyTypeRequired
passwordstringOptional
usernamestringOptional

.spec.distribution.modules.logging.minio.rootUser.password​

Description​

The password for the default MinIO root user.

.spec.distribution.modules.logging.minio.rootUser.username​

Description​

The username for the default MinIO root user.

.spec.distribution.modules.logging.minio.storageSize​

Description​

The PVC size for each MinIO disk, 6 disks total.

.spec.distribution.modules.logging.opensearch​

Properties​

PropertyTypeRequired
overridesobjectOptional
resourcesobjectOptional
storageSizestringOptional
typestringRequired

.spec.distribution.modules.logging.opensearch.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.logging.opensearch.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.logging.opensearch.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.logging.opensearch.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.logging.opensearch.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.logging.opensearch.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.logging.opensearch.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.logging.opensearch.resources​

Properties​

PropertyTypeRequired
limitsobjectOptional
requestsobjectOptional

.spec.distribution.modules.logging.opensearch.resources.limits​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.logging.opensearch.resources.limits.cpu​

Description​

The CPU limit for the Pod. Example: 1000m.

.spec.distribution.modules.logging.opensearch.resources.limits.memory​

Description​

The memory limit for the Pod. Example: 1G.

.spec.distribution.modules.logging.opensearch.resources.requests​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.logging.opensearch.resources.requests.cpu​

Description​

The CPU request for the Pod, in cores. Example: 500m.

.spec.distribution.modules.logging.opensearch.resources.requests.memory​

Description​

The memory request for the Pod. Example: 500M.

.spec.distribution.modules.logging.opensearch.storageSize​

Description​

The storage size for the OpenSearch volumes. Follows Kubernetes resources storage requests. Default is 150Gi.

.spec.distribution.modules.logging.opensearch.type​

Description​

The type of OpenSearch deployment. One of: single for a single replica or triple for an HA 3-replicas deployment.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"single"
"triple"

.spec.distribution.modules.logging.operator​

Properties​

PropertyTypeRequired
fluentbitobjectOptional
fluentdobjectOptional
overridesobjectOptional

Description​

Configuration for the Logging Operator.

.spec.distribution.modules.logging.operator.fluentbit​

Properties​

PropertyTypeRequired
resourcesobjectOptional

Description​

Configuration for Fluent Bit that reads the logs from the workload and forwards them to Fluentd.

.spec.distribution.modules.logging.operator.fluentbit.resources​

Properties​

PropertyTypeRequired
limitsobjectOptional
requestsobjectOptional

.spec.distribution.modules.logging.operator.fluentbit.resources.limits​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.logging.operator.fluentbit.resources.limits.cpu​

Description​

The CPU limit for the Pod. Example: 1000m.

.spec.distribution.modules.logging.operator.fluentbit.resources.limits.memory​

Description​

The memory limit for the Pod. Example: 1G.

.spec.distribution.modules.logging.operator.fluentbit.resources.requests​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.logging.operator.fluentbit.resources.requests.cpu​

Description​

The CPU request for the Pod, in cores. Example: 500m.

.spec.distribution.modules.logging.operator.fluentbit.resources.requests.memory​

Description​

The memory request for the Pod. Example: 500M.

.spec.distribution.modules.logging.operator.fluentd​

Properties​

PropertyTypeRequired
replicasintegerOptional
resourcesobjectOptional

Description​

Configuration for Fluentd that collects the logs and forwards them to the outputs.

.spec.distribution.modules.logging.operator.fluentd.replicas​

Description​

The number of Fluentd replicas to run. Default is 2.

.spec.distribution.modules.logging.operator.fluentd.resources​

Properties​

PropertyTypeRequired
limitsobjectOptional
requestsobjectOptional

.spec.distribution.modules.logging.operator.fluentd.resources.limits​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.logging.operator.fluentd.resources.limits.cpu​

Description​

The CPU limit for the Pod. Example: 1000m.

.spec.distribution.modules.logging.operator.fluentd.resources.limits.memory​

Description​

The memory limit for the Pod. Example: 1G.

.spec.distribution.modules.logging.operator.fluentd.resources.requests​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.logging.operator.fluentd.resources.requests.cpu​

Description​

The CPU request for the Pod, in cores. Example: 500m.

.spec.distribution.modules.logging.operator.fluentd.resources.requests.memory​

Description​

The memory request for the Pod. Example: 500M.

.spec.distribution.modules.logging.operator.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.logging.operator.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.logging.operator.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.logging.operator.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.logging.operator.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.logging.operator.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.logging.operator.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.logging.overrides​

Properties​

PropertyTypeRequired
ingressesobjectOptional
nodeSelectorobjectOptional
tolerationsarrayOptional

Description​

Override the common configuration with a particular configuration for the module.

.spec.distribution.modules.logging.overrides.ingresses​

.spec.distribution.modules.logging.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the module.

.spec.distribution.modules.logging.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the module.

.spec.distribution.modules.logging.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.logging.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.logging.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.logging.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.logging.type​

Description​

Selects the logging stack. Options are:

  • none: will disable the centralized logging.
  • opensearch: will deploy and configure the Logging Operator and an OpenSearch cluster (can be single or triple for HA) where the logs will be stored.
  • loki: will use a distributed Grafana Loki instead of OpenSearch for storage.
  • customOuputs: the Logging Operator will be deployed and installed but without in-cluster storage, you will have to create the needed Outputs and ClusterOutputs to ship the logs to your desired storage.

Default is opensearch.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"none"
"opensearch"
"loki"
"customOutputs"

.spec.distribution.modules.monitoring​

Properties​

PropertyTypeRequired
alertmanagerobjectOptional
blackboxExporterobjectOptional
grafanaobjectOptional
kubeStateMetricsobjectOptional
mimirobjectOptional
minioobjectOptional
overridesobjectOptional
prometheusobjectOptional
prometheusAdapterobjectOptional
prometheusAgentobjectOptional
typestringRequired
x509ExporterobjectOptional

Description​

Configuration for the Monitoring module.

.spec.distribution.modules.monitoring.alertmanager​

Properties​

PropertyTypeRequired
deadManSwitchWebhookUrlstringOptional
installDefaultRulesbooleanOptional
slackWebhookUrlstringOptional

.spec.distribution.modules.monitoring.alertmanager.deadManSwitchWebhookUrl​

Description​

The webhook URL to send dead man's switch monitoring, for example to use with healthchecks.io.

.spec.distribution.modules.monitoring.alertmanager.installDefaultRules​

Description​

Set to false to avoid installing the Prometheus rules (alerts) included with the distribution.

.spec.distribution.modules.monitoring.alertmanager.slackWebhookUrl​

Description​

The Slack webhook URL where to send the infrastructural and workload alerts to.

.spec.distribution.modules.monitoring.blackboxExporter​

Properties​

PropertyTypeRequired
overridesobjectOptional

.spec.distribution.modules.monitoring.blackboxExporter.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.monitoring.blackboxExporter.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.monitoring.blackboxExporter.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.monitoring.blackboxExporter.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.monitoring.blackboxExporter.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.monitoring.blackboxExporter.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.monitoring.blackboxExporter.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.monitoring.grafana​

Properties​

PropertyTypeRequired
basicAuthIngressbooleanOptional
overridesobjectOptional
usersRoleAttributePathstringOptional

.spec.distribution.modules.monitoring.grafana.basicAuthIngress​

Description​

Setting this to true will deploy an additional grafana-basic-auth ingress protected with Grafana's basic auth instead of SSO. It's intended use is as a temporary ingress for when there are problems with the SSO login flow.

Notice that by default anonymous access is enabled.

.spec.distribution.modules.monitoring.grafana.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.monitoring.grafana.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.monitoring.grafana.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.monitoring.grafana.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.monitoring.grafana.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.monitoring.grafana.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.monitoring.grafana.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.monitoring.grafana.usersRoleAttributePath​

Description​

JMESPath expression to retrieve the user's role. Example:

usersRoleAttributePath: "contains(groups[*], 'beta') && 'Admin' || contains(groups[*], 'gamma') && 'Editor' || contains(groups[*], 'delta') && 'Viewer'

More details in Grafana's documentation.

.spec.distribution.modules.monitoring.kubeStateMetrics​

Properties​

PropertyTypeRequired
overridesobjectOptional

.spec.distribution.modules.monitoring.kubeStateMetrics.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.monitoring.kubeStateMetrics.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.monitoring.kubeStateMetrics.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.monitoring.kubeStateMetrics.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.monitoring.kubeStateMetrics.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.monitoring.kubeStateMetrics.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.monitoring.kubeStateMetrics.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.monitoring.mimir​

Properties​

PropertyTypeRequired
backendstringOptional
externalEndpointobjectOptional
overridesobjectOptional
retentionTimestringOptional

Description​

Configuration for the Mimir package.

.spec.distribution.modules.monitoring.mimir.backend​

Description​

The storage backend type for Mimir. minio will use an in-cluster MinIO deployment for object storage, externalEndpoint can be used to point to an external S3-compatible object storage instead of deploying an in-cluster MinIO.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"minio"
"externalEndpoint"

.spec.distribution.modules.monitoring.mimir.externalEndpoint​

Properties​

PropertyTypeRequired
accessKeyIdstringOptional
bucketNamestringOptional
endpointstringOptional
insecurebooleanOptional
secretAccessKeystringOptional

Description​

Configuration for Mimir's external storage backend.

.spec.distribution.modules.monitoring.mimir.externalEndpoint.accessKeyId​

Description​

The access key ID (username) for the external S3-compatible bucket.

.spec.distribution.modules.monitoring.mimir.externalEndpoint.bucketName​

Description​

The bucket name of the external S3-compatible object storage.

.spec.distribution.modules.monitoring.mimir.externalEndpoint.endpoint​

Description​

The external S3-compatible endpoint for Mimir's storage.

.spec.distribution.modules.monitoring.mimir.externalEndpoint.insecure​

Description​

If true, will use HTTP as protocol instead of HTTPS.

.spec.distribution.modules.monitoring.mimir.externalEndpoint.secretAccessKey​

Description​

The secret access key (password) for the external S3-compatible bucket.

.spec.distribution.modules.monitoring.mimir.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.monitoring.mimir.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.monitoring.mimir.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.monitoring.mimir.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.monitoring.mimir.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.monitoring.mimir.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.monitoring.mimir.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.monitoring.mimir.retentionTime​

Description​

The retention time for the logs stored in Mimir. Default is 30d. Value must match the regular expression [0-9]+(ns|us|µs|ms|s|m|h|d|w|y) where y = 365 days.

.spec.distribution.modules.monitoring.minio​

Properties​

PropertyTypeRequired
overridesobjectOptional
rootUserobjectOptional
storageSizestringOptional

Description​

Configuration for Monitoring's MinIO deployment.

.spec.distribution.modules.monitoring.minio.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.monitoring.minio.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.monitoring.minio.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.monitoring.minio.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.monitoring.minio.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.monitoring.minio.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.monitoring.minio.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.monitoring.minio.rootUser​

Properties​

PropertyTypeRequired
passwordstringOptional
usernamestringOptional

.spec.distribution.modules.monitoring.minio.rootUser.password​

Description​

The password for the default MinIO root user.

.spec.distribution.modules.monitoring.minio.rootUser.username​

Description​

The username for the default MinIO root user.

.spec.distribution.modules.monitoring.minio.storageSize​

Description​

The PVC size for each MinIO disk, 6 disks total.

.spec.distribution.modules.monitoring.overrides​

Properties​

PropertyTypeRequired
ingressesobjectOptional
nodeSelectorobjectOptional
tolerationsarrayOptional

Description​

Override the common configuration with a particular configuration for the module.

.spec.distribution.modules.monitoring.overrides.ingresses​

.spec.distribution.modules.monitoring.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the module.

.spec.distribution.modules.monitoring.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the module.

.spec.distribution.modules.monitoring.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.monitoring.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.monitoring.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.monitoring.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.monitoring.prometheus​

Properties​

PropertyTypeRequired
remoteWritearrayOptional
resourcesobjectOptional
retentionSizestringOptional
retentionTimestringOptional
storageSizestringOptional

.spec.distribution.modules.monitoring.prometheus.remoteWrite​

Description​

Set this option to ship the collected metrics to a remote Prometheus receiver.

remoteWrite is an array of objects that allows configuring the remoteWrite options for Prometheus. The objects in the array follow the same schema as in the prometheus operator.

.spec.distribution.modules.monitoring.prometheus.resources​

Properties​

PropertyTypeRequired
limitsobjectOptional
requestsobjectOptional

.spec.distribution.modules.monitoring.prometheus.resources.limits​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.monitoring.prometheus.resources.limits.cpu​

Description​

The CPU limit for the Pod. Example: 1000m.

.spec.distribution.modules.monitoring.prometheus.resources.limits.memory​

Description​

The memory limit for the Pod. Example: 1G.

.spec.distribution.modules.monitoring.prometheus.resources.requests​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.monitoring.prometheus.resources.requests.cpu​

Description​

The CPU request for the Pod, in cores. Example: 500m.

.spec.distribution.modules.monitoring.prometheus.resources.requests.memory​

Description​

The memory request for the Pod. Example: 500M.

.spec.distribution.modules.monitoring.prometheus.retentionSize​

Description​

The retention size for the k8s Prometheus instance.

.spec.distribution.modules.monitoring.prometheus.retentionTime​

Description​

The retention time for the k8s Prometheus instance.

.spec.distribution.modules.monitoring.prometheus.storageSize​

Description​

The storage size for the k8s Prometheus instance.

.spec.distribution.modules.monitoring.prometheusAdapter​

Properties​

PropertyTypeRequired
installEnhancedHPAMetricsbooleanOptional
resourcesobjectOptional

.spec.distribution.modules.monitoring.prometheusAdapter.installEnhancedHPAMetrics​

Description​

Configures whether to enable advanced HPA metric collection in the Prometheus Adapter. When set to true, the Prometheus Adapter component will query Prometheus instances directly to retrieve additional metrics related to the Horizontal Pod Autoscaler (HPA). These metrics provide deeper visibility into HPA behaviour and performance. Caution: Enabling this feature results in a significant increase in RAM consumption of the Prometheus Adapter, as it requires managing an additional dataset. Default value: true.

.spec.distribution.modules.monitoring.prometheusAdapter.resources​

Properties​

PropertyTypeRequired
limitsobjectOptional
requestsobjectOptional

.spec.distribution.modules.monitoring.prometheusAdapter.resources.limits​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.monitoring.prometheusAdapter.resources.limits.cpu​

Description​

The CPU limit for the Pod. Example: 1000m.

.spec.distribution.modules.monitoring.prometheusAdapter.resources.limits.memory​

Description​

The memory limit for the Pod. Example: 1G.

.spec.distribution.modules.monitoring.prometheusAdapter.resources.requests​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.monitoring.prometheusAdapter.resources.requests.cpu​

Description​

The CPU request for the Pod, in cores. Example: 500m.

.spec.distribution.modules.monitoring.prometheusAdapter.resources.requests.memory​

Description​

The memory request for the Pod. Example: 500M.

.spec.distribution.modules.monitoring.prometheusAgent​

Properties​

PropertyTypeRequired
remoteWritearrayOptional
resourcesobjectOptional

.spec.distribution.modules.monitoring.prometheusAgent.remoteWrite​

Description​

Set this option to ship the collected metrics to a remote Prometheus receiver.

remoteWrite is an array of objects that allows configuring the remoteWrite options for Prometheus. The objects in the array follow the same schema as in the prometheus operator.

.spec.distribution.modules.monitoring.prometheusAgent.resources​

Properties​

PropertyTypeRequired
limitsobjectOptional
requestsobjectOptional

.spec.distribution.modules.monitoring.prometheusAgent.resources.limits​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.monitoring.prometheusAgent.resources.limits.cpu​

Description​

The CPU limit for the Pod. Example: 1000m.

.spec.distribution.modules.monitoring.prometheusAgent.resources.limits.memory​

Description​

The memory limit for the Pod. Example: 1G.

.spec.distribution.modules.monitoring.prometheusAgent.resources.requests​

Properties​

PropertyTypeRequired
cpustringOptional
memorystringOptional

.spec.distribution.modules.monitoring.prometheusAgent.resources.requests.cpu​

Description​

The CPU request for the Pod, in cores. Example: 500m.

.spec.distribution.modules.monitoring.prometheusAgent.resources.requests.memory​

Description​

The memory request for the Pod. Example: 500M.

.spec.distribution.modules.monitoring.type​

Description​

The type of the monitoring, must be none, prometheus, prometheusAgent or mimir.

  • none: will disable the whole monitoring stack.
  • prometheus: will install Prometheus Operator and a preconfigured Prometheus instance, Alertmanager, a set of alert rules, exporters needed to monitor all the components of the cluster, Grafana and a series of dashboards to view the collected metrics, and more.
  • prometheusAgent: will install Prometheus operator, an instance of Prometheus in Agent mode (no alerting, no queries, no storage), and all the exporters needed to get metrics for the status of the cluster and the workloads. Useful when having a centralized (remote) Prometheus where to ship the metrics and not storing them locally in the cluster.
  • mimir: will install the same as the prometheus option, plus Grafana Mimir that allows for longer retention of metrics and the usage of Object Storage.

Default is prometheus.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"none"
"prometheus"
"prometheusAgent"
"mimir"

.spec.distribution.modules.monitoring.x509Exporter​

Properties​

PropertyTypeRequired
overridesobjectOptional

.spec.distribution.modules.monitoring.x509Exporter.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.monitoring.x509Exporter.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.monitoring.x509Exporter.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.monitoring.x509Exporter.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.monitoring.x509Exporter.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.monitoring.x509Exporter.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.monitoring.x509Exporter.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.networking​

Properties​

PropertyTypeRequired
ciliumobjectOptional
overridesobjectOptional
tigeraOperatorobjectOptional
typestringRequired

Description​

Configuration for the Networking module.

.spec.distribution.modules.networking.cilium​

Properties​

PropertyTypeRequired
maskSizestringOptional
overridesobjectOptional
podCidrstringOptional

.spec.distribution.modules.networking.cilium.maskSize​

Description​

The mask size to use for the Pods network on each node.

.spec.distribution.modules.networking.cilium.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.networking.cilium.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.networking.cilium.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.networking.cilium.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.networking.cilium.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.networking.cilium.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.networking.cilium.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.networking.cilium.podCidr​

Description​

Allows specifing a CIDR for the Pods network different from .spec.kubernetes.podCidr. If not set the default is to use .spec.kubernetes.podCidr.

Constraints​

pattern: the string must match the following regular expression:

^((25[0-5]|(2[0-4]|1\d|[1-9]|)\d)\.?\b){4}\/(3[0-2]|[1-2][0-9]|[0-9])$

try pattern

.spec.distribution.modules.networking.overrides​

Properties​

PropertyTypeRequired
ingressesobjectOptional
nodeSelectorobjectOptional
tolerationsarrayOptional

Description​

Override the common configuration with a particular configuration for the module.

.spec.distribution.modules.networking.overrides.ingresses​

.spec.distribution.modules.networking.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the module.

.spec.distribution.modules.networking.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the module.

.spec.distribution.modules.networking.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.networking.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.networking.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.networking.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.networking.tigeraOperator​

Properties​

PropertyTypeRequired
blockSizeintegerOptional
overridesobjectOptional
podCidrstringOptional

.spec.distribution.modules.networking.tigeraOperator.blockSize​

Description​

BlockSize specifies the CIDR prefix length to use when allocating per-node IP blocks from the main IP pool CIDR. WARNING: The value for this field cannot be changed once set. Default is 26.

.spec.distribution.modules.networking.tigeraOperator.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.networking.tigeraOperator.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.networking.tigeraOperator.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.networking.tigeraOperator.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.networking.tigeraOperator.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.networking.tigeraOperator.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.networking.tigeraOperator.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.networking.tigeraOperator.podCidr​

Description​

Allows specifing a CIDR for the Pods network different from .spec.kubernetes.podCidr. If not set the default is to use .spec.kubernetes.podCidr. WARNING: The value for this field cannot be changed once set.

Constraints​

pattern: the string must match the following regular expression:

^((25[0-5]|(2[0-4]|1\d|[1-9]|)\d)\.?\b){4}\/(3[0-2]|[1-2][0-9]|[0-9])$

try pattern

.spec.distribution.modules.networking.type​

Description​

The type of CNI plugin to use, either calico (Tigera Operator) or cilium. Default is calico.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"calico"
"cilium"

.spec.distribution.modules.policy​

Properties​

PropertyTypeRequired
gatekeeperobjectOptional
kyvernoobjectOptional
overridesobjectOptional
typestringRequired

Description​

Configuration for the Policy module.

.spec.distribution.modules.policy.gatekeeper​

Properties​

PropertyTypeRequired
additionalExcludedNamespacesarrayOptional
enforcementActionstringRequired
installDefaultPoliciesbooleanRequired
overridesobjectOptional

Description​

Configuration for the Gatekeeper package.

.spec.distribution.modules.policy.gatekeeper.additionalExcludedNamespaces​

Description​

This parameter adds namespaces to Gatekeeper's exemption list, so it will not enforce the constraints on them.

.spec.distribution.modules.policy.gatekeeper.enforcementAction​

Description​

The default enforcement action to use for the included constraints. deny will block the admission when violations to the policies are found, warn will show a message to the user but will admit the violating requests and dryrun won't give any feedback to the user but it will log the violations.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"deny"
"dryrun"
"warn"

.spec.distribution.modules.policy.gatekeeper.installDefaultPolicies​

Description​

Set to false to avoid installing the default Gatekeeper policies (constraints templates and constraints) included with the distribution.

.spec.distribution.modules.policy.gatekeeper.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.policy.gatekeeper.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.policy.gatekeeper.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.policy.gatekeeper.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.policy.gatekeeper.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.policy.gatekeeper.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.policy.gatekeeper.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.policy.kyverno​

Properties​

PropertyTypeRequired
additionalExcludedNamespacesarrayOptional
installDefaultPoliciesbooleanRequired
overridesobjectOptional
validationFailureActionstringRequired

Description​

Configuration for the Kyverno package.

.spec.distribution.modules.policy.kyverno.additionalExcludedNamespaces​

Description​

This parameter adds namespaces to Kyverno's exemption list, so it will not enforce the policies on them.

.spec.distribution.modules.policy.kyverno.installDefaultPolicies​

Description​

Set to false to avoid installing the default Kyverno policies included with distribution.

.spec.distribution.modules.policy.kyverno.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.policy.kyverno.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.policy.kyverno.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.policy.kyverno.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.policy.kyverno.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.policy.kyverno.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.policy.kyverno.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.policy.kyverno.validationFailureAction​

Description​

The validation failure action to use for the included policies, Enforce will block when a request does not comply with the policies and Audit will not block but log when a request does not comply with the policies.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Audit"
"Enforce"

.spec.distribution.modules.policy.overrides​

Properties​

PropertyTypeRequired
ingressesobjectOptional
nodeSelectorobjectOptional
tolerationsarrayOptional

Description​

Override the common configuration with a particular configuration for the module.

.spec.distribution.modules.policy.overrides.ingresses​

.spec.distribution.modules.policy.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the module.

.spec.distribution.modules.policy.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the module.

.spec.distribution.modules.policy.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.policy.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.policy.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.policy.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.policy.type​

Description​

The type of policy enforcement to use, either none, gatekeeper or kyverno.

Default is none.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"none"
"gatekeeper"
"kyverno"

.spec.distribution.modules.tracing​

Properties​

PropertyTypeRequired
minioobjectOptional
overridesobjectOptional
tempoobjectOptional
typestringRequired

Description​

Configuration for the Tracing module.

.spec.distribution.modules.tracing.minio​

Properties​

PropertyTypeRequired
overridesobjectOptional
rootUserobjectOptional
storageSizestringOptional

Description​

Configuration for Tracing's MinIO deployment.

.spec.distribution.modules.tracing.minio.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.tracing.minio.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.tracing.minio.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.tracing.minio.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.tracing.minio.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.tracing.minio.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.tracing.minio.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.tracing.minio.rootUser​

Properties​

PropertyTypeRequired
passwordstringOptional
usernamestringOptional

.spec.distribution.modules.tracing.minio.rootUser.password​

Description​

The password for the default MinIO root user.

.spec.distribution.modules.tracing.minio.rootUser.username​

Description​

The username for the default MinIO root user.

.spec.distribution.modules.tracing.minio.storageSize​

Description​

The PVC size for each MinIO disk, 6 disks total.

.spec.distribution.modules.tracing.overrides​

Properties​

PropertyTypeRequired
ingressesobjectOptional
nodeSelectorobjectOptional
tolerationsarrayOptional

Description​

Override the common configuration with a particular configuration for the module.

.spec.distribution.modules.tracing.overrides.ingresses​

.spec.distribution.modules.tracing.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the module.

.spec.distribution.modules.tracing.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the module.

.spec.distribution.modules.tracing.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.tracing.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.tracing.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.tracing.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.tracing.tempo​

Properties​

PropertyTypeRequired
backendstringOptional
externalEndpointobjectOptional
overridesobjectOptional
retentionTimestringOptional

Description​

Configuration for the Tempo package.

.spec.distribution.modules.tracing.tempo.backend​

Description​

The storage backend type for Tempo. minio will use an in-cluster MinIO deployment for object storage, externalEndpoint can be used to point to an external S3-compatible object storage instead of deploying an in-cluster MinIO.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"minio"
"externalEndpoint"

.spec.distribution.modules.tracing.tempo.externalEndpoint​

Properties​

PropertyTypeRequired
accessKeyIdstringOptional
bucketNamestringOptional
endpointstringOptional
insecurebooleanOptional
secretAccessKeystringOptional

Description​

Configuration for Tempo's external storage backend.

.spec.distribution.modules.tracing.tempo.externalEndpoint.accessKeyId​

Description​

The access key ID (username) for the external S3-compatible bucket.

.spec.distribution.modules.tracing.tempo.externalEndpoint.bucketName​

Description​

The bucket name of the external S3-compatible object storage.

.spec.distribution.modules.tracing.tempo.externalEndpoint.endpoint​

Description​

The external S3-compatible endpoint for Tempo's storage.

.spec.distribution.modules.tracing.tempo.externalEndpoint.insecure​

Description​

If true, will use HTTP as protocol instead of HTTPS.

.spec.distribution.modules.tracing.tempo.externalEndpoint.secretAccessKey​

Description​

The secret access key (password) for the external S3-compatible bucket.

.spec.distribution.modules.tracing.tempo.overrides​

Properties​

PropertyTypeRequired
nodeSelectorobjectOptional
tolerationsarrayOptional

.spec.distribution.modules.tracing.tempo.overrides.nodeSelector​

Description​

Set to override the node selector used to place the pods of the package.

.spec.distribution.modules.tracing.tempo.overrides.tolerations​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
operatorstringOptional
valuestringOptional

Description​

Set to override the tolerations that will be added to the pods of the package.

.spec.distribution.modules.tracing.tempo.overrides.tolerations.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.distribution.modules.tracing.tempo.overrides.tolerations.key​

Description​

The key of the toleration

.spec.distribution.modules.tracing.tempo.overrides.tolerations.operator​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Exists"
"Equal"

.spec.distribution.modules.tracing.tempo.overrides.tolerations.value​

Description​

The value of the toleration

.spec.distribution.modules.tracing.tempo.retentionTime​

Description​

The retention time for the traces stored in Tempo.

.spec.distribution.modules.tracing.type​

Description​

The type of tracing to use, either none or tempo. none will disable the Tracing module and tempo will install a Grafana Tempo deployment.

Default is tempo.

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"none"
"tempo"

.spec.distributionVersion​

Description​

Defines which SD version will be installed and, in consequence, the Kubernetes version used to create the cluster. It supports git tags and branches. Example: v1.30.1.

Constraints​

minimum length: the minimum number of characters for this string is: 1

.spec.kubernetes​

Properties​

PropertyTypeRequired
advancedobjectOptional
advancedAnsibleobjectOptional
controlPlaneAddressstringRequired
dnsZonestringRequired
etcdobjectOptional
loadBalancersobjectRequired
mastersobjectRequired
nodesarrayRequired
pkiFolderstringRequired
podCidrstringRequired
proxyobjectOptional
sshobjectRequired
svcCidrstringRequired

Description​

Defines the Kubernetes components configuration and the values needed for the kubernetes phase of furyctl.

.spec.kubernetes.advanced​

Properties​

PropertyTypeRequired
airGapobjectOptional
apiServerCertSANsarrayOptional
cloudobjectOptional
containerdobjectOptional
controllerManagerobjectOptional
encryptionobjectOptional
eventRateLimitsarrayOptional
kernelParametersarrayOptional
kubeProxyobjectOptional
kubeletConfigurationobjectOptional
oidcobjectOptional
registrystringOptional
selfmanagedRepositoriesbooleanOptional
usersobjectOptional

.spec.kubernetes.advanced.airGap​

Properties​

PropertyTypeRequired
containerdDownloadUrlstringOptional
dependenciesOverrideobjectOptional
etcdDownloadUrlstringOptional
kubeadmBinaryDirstringOptional
kubeadmChecksumstringOptional
kubeadmDownloadUrlstringOptional
runcChecksumstringOptional
runcDownloadUrlstringOptional

Description​

Advanced configuration for air-gapped installations. Allows setting custom URLs where to download the binaries dependencies from and custom .deb and .rpm package repositories.

.spec.kubernetes.advanced.airGap.containerdDownloadUrl​

Description​

URL where to download the .tar.gz with containerd from. The tar.gz should be as the one downloaded from containerd GitHub releases page.

.spec.kubernetes.advanced.airGap.dependenciesOverride​

Properties​

PropertyTypeRequired
aptobjectOptional
yumobjectOptional

.spec.kubernetes.advanced.airGap.dependenciesOverride.apt​

Properties​

PropertyTypeRequired
gpg_keystringRequired
gpg_key_idstringRequired
namestringRequired
repostringRequired

.spec.kubernetes.advanced.airGap.dependenciesOverride.apt.gpg_key​

Description​

URL where to download the GPG key of the Apt repository. Example: https://pkgs.k8s.io/core:/stable:/v1.29/deb/Release.key

.spec.kubernetes.advanced.airGap.dependenciesOverride.apt.gpg_key_id​

Description​

The GPG key ID of the Apt repository. Example: 36A1D7869245C8950F966E92D8576A8BA88D21E9

.spec.kubernetes.advanced.airGap.dependenciesOverride.apt.name​

Description​

An indicative name for the Apt repository. Example: k8s-1.29

.spec.kubernetes.advanced.airGap.dependenciesOverride.apt.repo​

Description​

A source string for the new Apt repository. Example: deb https://pkgs.k8s.io/core:/stable:/v1.29/deb/ /

.spec.kubernetes.advanced.airGap.dependenciesOverride.yum​

Properties​

PropertyTypeRequired
gpg_keystringRequired
gpg_key_checkbooleanRequired
namestringRequired
repostringRequired
repo_gpg_checkbooleanRequired

.spec.kubernetes.advanced.airGap.dependenciesOverride.yum.gpg_key​

Description​

URL where to download the ASCII-armored GPG key of the Yum repository. Example: https://pkgs.k8s.io/core:/stable:/v1.29/deb/Release.key

.spec.kubernetes.advanced.airGap.dependenciesOverride.yum.gpg_key_check​

Description​

If true, the GPG signature check on the packages will be enabled.

.spec.kubernetes.advanced.airGap.dependenciesOverride.yum.name​

Description​

An indicative name for the Yum repository. Example: k8s-1.29

.spec.kubernetes.advanced.airGap.dependenciesOverride.yum.repo​

Description​

URL to the directory where the Yum repository's repodata directory lives. Example: https://pkgs.k8s.io/core:/stable:/v1.29/rpm/

.spec.kubernetes.advanced.airGap.dependenciesOverride.yum.repo_gpg_check​

Description​

If true, the GPG signature check on the repodata will be enabled.

.spec.kubernetes.advanced.airGap.etcdDownloadUrl​

Description​

URL to the path where the etcd tar.gzs are available. etcd will be downloaded from <etcdDownloadUrl>/<etcd_version>/etcd-<etcd_version>-linux-<host_architecture>.tar.gz

.spec.kubernetes.advanced.airGap.kubeadmBinaryDir​

Description​

Directory where to install the kubeadm binary on dedicated etcd nodes. Defaults to /usr/local/bin.

.spec.kubernetes.advanced.airGap.kubeadmChecksum​

Description​

Checksum for the kubeadm binary on dedicated etcd nodes.

.spec.kubernetes.advanced.airGap.kubeadmDownloadUrl​

Description​

URL where to download the kubeadm binary from. Used for certificate management on dedicated etcd nodes.

.spec.kubernetes.advanced.airGap.runcChecksum​

Description​

Checksum for the runc binary.

.spec.kubernetes.advanced.airGap.runcDownloadUrl​

Description​

URL where to download the runc binary from.

.spec.kubernetes.advanced.apiServerCertSANs​

Description​

Additional Subject Alternative Names for the API server certificates. These are used to secure connections to the API server from various clients.

.spec.kubernetes.advanced.cloud​

Properties​

PropertyTypeRequired
configstringOptional
providerstringOptional

.spec.kubernetes.advanced.cloud.config​

Description​

Sets cloud config for the Kubelet

.spec.kubernetes.advanced.cloud.provider​

Description​

Sets the cloud provider for the Kubelet

.spec.kubernetes.advanced.containerd​

Properties​

PropertyTypeRequired
debugLevelstringOptional
deviceOwnershipFromSecurityContextbooleanOptional
grpcMaxRecvMessageSizeintegerOptional
grpcMaxSendMessageSizeintegerOptional
maxContainerLogLineSizeintegerOptional
metricsAddressstringOptional
metricsGrpcHistogrambooleanOptional
oomScoreintegerOptional
registryConfigsarrayOptional
selfmanagedRepositoriesbooleanOptional
stateDirstringOptional
storageDirstringOptional
systemdDirstringOptional

Description​

Advanced configuration for containerd

.spec.kubernetes.advanced.containerd.debugLevel​

Description​

The Containerd debug level used in the config.toml file.

.spec.kubernetes.advanced.containerd.deviceOwnershipFromSecurityContext​

Description​

Set to true to apply device ownership from the container runtime's security context instead of the host's defaults, used in the config.toml file.

.spec.kubernetes.advanced.containerd.grpcMaxRecvMessageSize​

Description​

The Containerd gRPC maximum receive message size in bytes used in the config.toml file.

.spec.kubernetes.advanced.containerd.grpcMaxSendMessageSize​

Description​

The Containerd gRPC maximum send message size in bytes used in the config.toml file.

.spec.kubernetes.advanced.containerd.maxContainerLogLineSize​

Description​

The maximum container log line size in bytes used in the config.toml file.

.spec.kubernetes.advanced.containerd.metricsAddress​

Description​

The Containerd metrics address used in the config.toml file.

.spec.kubernetes.advanced.containerd.metricsGrpcHistogram​

Description​

Enable Containerd metrics gRPC histogram in the config.toml file.

.spec.kubernetes.advanced.containerd.oomScore​

Description​

The Containerd OOM score adjustment used in the config.toml file.

.spec.kubernetes.advanced.containerd.registryConfigs​

Properties​

PropertyTypeRequired
insecureSkipVerifybooleanOptional
mirrorEndpointarrayOptional
passwordstringOptional
registrystringOptional
usernamestringOptional

Description​

Allows specifying custom configuration for a registry at containerd level. You can set authentication details and mirrors for a registry. This feature can be used for example to authenticate to a private registry at containerd (container runtime) level, i.e. globally instead of using imagePullSecrets. It also can be used to use a mirror for a registry or to enable insecure connections to trusted registries that have self-signed certificates.

.spec.kubernetes.advanced.containerd.registryConfigs.insecureSkipVerify​

Description​

Set to true to skip TLS verification (e.g. when using self-signed certificates).

.spec.kubernetes.advanced.containerd.registryConfigs.mirrorEndpoint​

Description​

Array of URLs with the mirrors to use for the registry. Example: ["http://mymirror.tld:8080"]

.spec.kubernetes.advanced.containerd.registryConfigs.password​

Description​

The password containerd will use to authenticate against the registry.

.spec.kubernetes.advanced.containerd.registryConfigs.registry​

Description​

Registry address on which you would like to configure authentication or mirror(s). Example: myregistry.tld:5000

.spec.kubernetes.advanced.containerd.registryConfigs.username​

Description​

The username containerd will use to authenticate against the registry.

.spec.kubernetes.advanced.containerd.selfmanagedRepositories​

Description​

Set to true if you manage the NVIDIA container toolkit's repositories externally and wish to skip their automatic configuration with furyctl. Default is false (furyctl manages repositories automatically). Notice that containerd itself is installed from binaries and does not use a repository. See .spec.kubernetes.advanced.airGap for other download options for containerd.

.spec.kubernetes.advanced.containerd.stateDir​

Description​

The Containerd state directory used in the config.toml file.

.spec.kubernetes.advanced.containerd.storageDir​

Description​

The Containerd storage directory used in the config.toml file.

.spec.kubernetes.advanced.containerd.systemdDir​

Description​

The Containerd systemd service directory used in the config.toml file.

.spec.kubernetes.advanced.controllerManager​

Properties​

PropertyTypeRequired
gcThresholdintegerOptional

Description​

Advanced configuration for the controller-manager.

.spec.kubernetes.advanced.controllerManager.gcThreshold​

Description​

Maximum number of terminated Pods retained by the controller-manager before automatic deletion.

.spec.kubernetes.advanced.encryption​

Properties​

PropertyTypeRequired
configurationstringOptional
tlsCipherSuitesarrayOptional
tlsCipherSuitesKubeletarrayOptional

.spec.kubernetes.advanced.encryption.configuration​

Description​

etcd's encryption at rest configuration. Must be a string with the EncryptionConfiguration object in YAML. Example:


apiVersion: apiserver.config.k8s.io/v1
kind: EncryptionConfiguration
resources:
- resources:
- secrets
providers:
- aescbc:
keys:
- name: mykey
secret: base64_encoded_secret

.spec.kubernetes.advanced.encryption.tlsCipherSuites​

Description​

The TLS cipher suites to use for etcd and kubeadm static pods. Example:

tlsCipherSuites:
- "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
- "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
- "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
- "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"
- "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256"
- "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256"
- "TLS_AES_128_GCM_SHA256"
- "TLS_AES_256_GCM_SHA384"
- "TLS_CHACHA20_POLY1305_SHA256"

.

.spec.kubernetes.advanced.encryption.tlsCipherSuitesKubelet​

Description​

The TLS cipher suites to use for the kubelet. Example:

tlsCipherSuitesKubelet:
- "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256"
- "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"
- "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384"
- "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305"
- "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305"
- "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384"

. NOTE: to customize the TLS cipher suites of the kubelet, set only this field - do not configure them under the KubeletConfiguration.

.spec.kubernetes.advanced.eventRateLimits​

Properties​

PropertyTypeRequired
burstintegerRequired
cacheSizeintegerOptional
qpsintegerRequired
typestringRequired

Description​

Configures the limits of the API Server's EventRateLimit plugin. Each item represents a bucket (Server, Namespace, User, etc).

.spec.kubernetes.advanced.eventRateLimits.burst​

Description​

Maximum allowed burst for this bucket type.

.spec.kubernetes.advanced.eventRateLimits.cacheSize​

Description​

Maximum number of cached objects for this bucket. Only for certain types like Namespace or User.

.spec.kubernetes.advanced.eventRateLimits.qps​

Description​

Maximum allowed queries per second (QPS) for this bucket type.

.spec.kubernetes.advanced.eventRateLimits.type​

Description​

Type of limit to apply (Server, Namespace, User, SourceAndObject).

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"Server"
"Namespace"
"User"
"SourceAndObject"

.spec.kubernetes.advanced.kernelParameters​

Properties​

PropertyTypeRequired
namestringRequired
valuestringRequired

Description​

Allows customization of kernel parameters with sysctl on all Kubernetes nodes. NOTE: if you remove a parameter from this list, it will not be reset to its default value without a reboot.

.spec.kubernetes.advanced.kernelParameters.name​

Description​

The kernel parameter to edit. Example: kernel.panic

.spec.kubernetes.advanced.kernelParameters.value​

Description​

The value of the kernel parameter to edit. Example: "15"

.spec.kubernetes.advanced.kubeProxy​

Properties​

PropertyTypeRequired
additionalPropertiesobjectOptional
enabledbooleanOptional

Description​

Configuration for the kube-proxy component.

.spec.kubernetes.advanced.kubeProxy.additionalProperties​

.spec.kubernetes.advanced.kubeProxy.enabled​

Description​

Setting this option to false will skip the installation of the kube-proxy component and install the CNI plugin with the following configuration: Cilium in kube-proxy-replacement mode and Calico in eBPF mode. Default is true.

NOTE: Changing this option after the cluster has been created is not currently supported.

.spec.kubernetes.advanced.kubeletConfiguration​

Properties​

PropertyTypeRequired
kubeletCertificateAuthorityFilestringOptional
streamingConnectionIdleTimeoutstringOptional

Description​

Advanced configuration for Kubelet. This open field allows users to specify any parameter supported by the KubeletConfiguration object. Examples of uses include controlling the maximum number of pods per core (podsPerCore), managing container logging (containerLogMaxSize), Topology Manager options (topologyManagerPolicyOptions). All values must follow the official Kubelet specification: https://kubernetes.io/docs/reference/config-api/kubelet-config.v1beta1/.

NOTE: Content will not be validated by furyctl. To customize the TLS cipher suites of the Kubelet, set only the Spec.Kubernetes.Advanced.Encryption.tlsCipherSuitesKubelet field - do not configure them under this field.

.spec.kubernetes.advanced.kubeletConfiguration.kubeletCertificateAuthorityFile​

Description​

Path to the CA file used to verify the kubelet servers' TLS certificates.

.spec.kubernetes.advanced.kubeletConfiguration.streamingConnectionIdleTimeout​

Description​

The maximum time a streaming connection can be idle before it is closed. Example: 5m0s

.spec.kubernetes.advanced.oidc​

Properties​

PropertyTypeRequired
ca_filestringOptional
client_idstringOptional
group_prefixstringOptional
groups_claimstringOptional
issuer_urlstringOptional
username_claimstringOptional
username_prefixstringOptional

Description​

OIDC configuration for the Kubernetes API server.

.spec.kubernetes.advanced.oidc.ca_file​

Description​

The path to the certificate for the CA that signed the identity provider's web certificate. Defaults to the host's root CAs. This should be a path available to the API Server.

.spec.kubernetes.advanced.oidc.client_id​

Description​

The client ID the API server will use to authenticate to the OIDC provider.

.spec.kubernetes.advanced.oidc.group_prefix​

Description​

Prefix prepended to group claims to prevent clashes with existing names (such as system: groups).

.spec.kubernetes.advanced.oidc.groups_claim​

Description​

JWT claim to use as the user's group.

.spec.kubernetes.advanced.oidc.issuer_url​

Description​

The issuer URL of the OIDC provider.

.spec.kubernetes.advanced.oidc.username_claim​

Description​

JWT claim to use as the user name. The default value is sub, which is expected to be a unique identifier of the end user.

.spec.kubernetes.advanced.oidc.username_prefix​

Description​

Prefix prepended to username claims to prevent clashes with existing names (such as system: users).

.spec.kubernetes.advanced.registry​

Description​

URL of the registry where to pull images from for the Kubernetes phase. (Default is registry.sighup.io/fury/on-premises).

.spec.kubernetes.advanced.selfmanagedRepositories​

Description​

Set to true if you manage the Kubernetes package repositories externally and wish to skip their automatic configuration with furyctl. Default is false (furyctl manages repositories automatically).

.spec.kubernetes.advanced.users​

Properties​

PropertyTypeRequired
namesarrayOptional
orgstringOptional

.spec.kubernetes.advanced.users.names​

Description​

List of user names to create and get a kubeconfig file. Users will not have any permissions by default, RBAC setup for the new users is needed.

.spec.kubernetes.advanced.users.org​

Description​

The organization the users belong to.

.spec.kubernetes.advancedAnsible​

Properties​

PropertyTypeRequired
configstringOptional
pythonInterpreterstringOptional

.spec.kubernetes.advancedAnsible.config​

Description​

Additional configuration to append to the ansible.cfg file

.spec.kubernetes.advancedAnsible.pythonInterpreter​

Description​

The Python interpreter to use for running Ansible. Example: python3

.spec.kubernetes.controlPlaneAddress​

Description​

The address for the Kubernetes control plane. Usually a DNS entry pointing to a Load Balancer on port 6443.

.spec.kubernetes.dnsZone​

Description​

The DNS zone of the machines. It will be appended to the name of each host to generate the kubernetes_hostname in the Ansible inventory file. It is also used to calculate etcd's initial cluster value.

.spec.kubernetes.etcd​

Properties​

PropertyTypeRequired
hostsarrayRequired

Description​

Optional configuration for an etcd cluster on dedicated nodes. If omitted, etcd will run on control plane nodes.

.spec.kubernetes.etcd.hosts​

Properties​

PropertyTypeRequired
ipstringRequired
namestringRequired

Description​

List of nodes of the dedicated etcd cluster.

Constraints​

minimum number of items: the minimum number of items for this array is: 1

.spec.kubernetes.etcd.hosts.ip​

Description​

The IP address of the etcd node.

.spec.kubernetes.etcd.hosts.name​

Description​

A name to identify the etcd node. This value will be concatenated to .spec.kubernetes.dnsZone to calculate the FQDN for the host as <name>.<dnsZone>.

.spec.kubernetes.loadBalancers​

Properties​

PropertyTypeRequired
additionalConfigstringOptional
enabledbooleanRequired
hostsarrayOptional
keepalivedobjectOptional
selfmanagedRepositoriesbooleanOptional
statsobjectOptional

.spec.kubernetes.loadBalancers.additionalConfig​

Description​

Additional configuration to append to HAProxy's configuration file.

.spec.kubernetes.loadBalancers.enabled​

Description​

Set to true to install HAProxy and configure it as a load balancer on the the load balancer hosts.

.spec.kubernetes.loadBalancers.hosts​

Properties​

PropertyTypeRequired
ipstringRequired
namestringRequired

.spec.kubernetes.loadBalancers.hosts.ip​

Description​

The IP address of the host.

.spec.kubernetes.loadBalancers.hosts.name​

Description​

A name to identify the host. This value will be concatenated to .spec.kubernetes.dnsZone to calculate the FQDN for the host as <name>.<dnsZone>.

.spec.kubernetes.loadBalancers.keepalived​

Properties​

PropertyTypeRequired
enabledbooleanRequired
interfacestringOptional
ipstringOptional
passphrasestringOptional
virtualRouterIdstringOptional

.spec.kubernetes.loadBalancers.keepalived.enabled​

Description​

Set to install keepalived with a floating virtual IP shared between the load balancer hosts for a deployment in High Availability.

.spec.kubernetes.loadBalancers.keepalived.interface​

Description​

Name of the network interface where to bind the Keepalived virtual IP.

.spec.kubernetes.loadBalancers.keepalived.ip​

Description​

The Virtual floating IP for Keepalived

.spec.kubernetes.loadBalancers.keepalived.passphrase​

Description​

Password for accessing vrrpd. Make it unique between Keepalived clusters.

Constraints​

maximum length: the maximum number of characters for this string is: 8

.spec.kubernetes.loadBalancers.keepalived.virtualRouterId​

Description​

The virtual router ID of Keepalived, an arbitrary unique number from 1 to 255 used to differentiate multiple instances of vrrpd running on the same network interface and address family and multicast/unicast (and hence same socket).

.spec.kubernetes.loadBalancers.selfmanagedRepositories​

Description​

Set to true if you manage the HAProxy repositories externally and wish to skip their automatic configuration with furyctl. Default is false (furyctl manages repositories automatically).

.spec.kubernetes.loadBalancers.stats​

Properties​

PropertyTypeRequired
passwordstringRequired
usernamestringRequired

Description​

Configuration for HAProxy stats page. Accessible at http://<haproxy host>:1936/stats

.spec.kubernetes.loadBalancers.stats.password​

Description​

The basic-auth password for HAProxy's stats page.

.spec.kubernetes.loadBalancers.stats.username​

Description​

The basic-auth username for HAProxy's stats page

.spec.kubernetes.masters​

Properties​

PropertyTypeRequired
annotationsobjectOptional
hostsarrayRequired
kernelParametersarrayOptional
kubeletConfigurationobjectOptional
labelsobjectOptional
taintsarrayOptional

Description​

Configuration for the control plane hosts

.spec.kubernetes.masters.annotations​

Description​

Optional additional Kubernetes annotations that will be added to the control-plane nodes. Follows Kubernetes annotations format. Existing annotations with the same key will be overwritten.

.spec.kubernetes.masters.hosts​

Properties​

PropertyTypeRequired
ipstringRequired
namestringRequired

.spec.kubernetes.masters.hosts.ip​

Description​

The IP address of the host

.spec.kubernetes.masters.hosts.name​

Description​

A name to identify the host. This value will be concatenated to .spec.kubernetes.dnsZone to calculate the FQDN for the host as <name>.<dnsZone>.

.spec.kubernetes.masters.kernelParameters​

Properties​

PropertyTypeRequired
namestringRequired
valuestringRequired

Description​

Allows customization of kernel parameters with sysctl on all Kubernetes nodes. NOTE: if you remove a parameter from this list, it will not be reset to its default value without a reboot.

.spec.kubernetes.masters.kernelParameters.name​

Description​

The kernel parameter to edit. Example: kernel.panic

.spec.kubernetes.masters.kernelParameters.value​

Description​

The value of the kernel parameter to edit. Example: "15"

.spec.kubernetes.masters.kubeletConfiguration​

Properties​

PropertyTypeRequired
kubeletCertificateAuthorityFilestringOptional
streamingConnectionIdleTimeoutstringOptional

Description​

Advanced configuration for Kubelet. This open field allows users to specify any parameter supported by the KubeletConfiguration object. Examples of uses include controlling the maximum number of pods per core (podsPerCore), managing container logging (containerLogMaxSize), Topology Manager options (topologyManagerPolicyOptions). All values must follow the official Kubelet specification: https://kubernetes.io/docs/reference/config-api/kubelet-config.v1beta1/.

NOTE: Content will not be validated by furyctl. To customize the TLS cipher suites of the Kubelet, set only the Spec.Kubernetes.Advanced.Encryption.tlsCipherSuitesKubelet field - do not configure them under this field.

.spec.kubernetes.masters.kubeletConfiguration.kubeletCertificateAuthorityFile​

Description​

Path to the CA file used to verify the kubelet servers' TLS certificates.

.spec.kubernetes.masters.kubeletConfiguration.streamingConnectionIdleTimeout​

Description​

The maximum time a streaming connection can be idle before it is closed. Example: 5m0s

.spec.kubernetes.masters.labels​

Description​

Optional additional Kubernetes labels that will be added to the control-plane nodes. Follows Kubernetes labels format.

Note: Existing labels with the same key will be overwritten and the label setting the control-plane role cannot be deleted.

.spec.kubernetes.masters.taints​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
valuestringRequired

Description​

Kubernetes taints for the control-plane nodes, follows Kubernetes taints format. Default is node-role.kubernetes.io/control-plane:NoSchedule.

Example:

- effect: NoSchedule
key: node.kubernetes.io/role
value: control-plane

NOTE: Setting an empty list will remove the default control-plane taint.

NOTE2: Takes effect only at cluster creation time.

.spec.kubernetes.masters.taints.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.kubernetes.masters.taints.key​

.spec.kubernetes.masters.taints.value​

.spec.kubernetes.nodes​

Properties​

PropertyTypeRequired
annotationsobjectOptional
hostsarrayRequired
kernelParametersarrayOptional
kubeletConfigurationobjectOptional
labelsobjectOptional
namestringRequired
taintsarrayOptional

Description​

Configuration for the node hosts

.spec.kubernetes.nodes.annotations​

Description​

Optional additional Kubernetes annotations that will be added to the nodes in this node group. Follows Kubernetes annotations format. Existing annotations with the same key will be overwritten.

.spec.kubernetes.nodes.hosts​

Properties​

PropertyTypeRequired
ipstringRequired
namestringRequired

Constraints​

minimum number of items: the minimum number of items for this array is: 1

.spec.kubernetes.nodes.hosts.ip​

Description​

The IP address of the host

.spec.kubernetes.nodes.hosts.name​

Description​

A name to identify the host. This value will be concatenated to .spec.kubernetes.dnsZone to calculate the FQDN for the host as <name>.<dnsZone>.

.spec.kubernetes.nodes.kernelParameters​

Properties​

PropertyTypeRequired
namestringRequired
valuestringRequired

Description​

Allows customization of kernel parameters with sysctl on all Kubernetes nodes. NOTE: if you remove a parameter from this list, it will not be reset to its default value without a reboot.

.spec.kubernetes.nodes.kernelParameters.name​

Description​

The kernel parameter to edit. Example: kernel.panic

.spec.kubernetes.nodes.kernelParameters.value​

Description​

The value of the kernel parameter to edit. Example: "15"

.spec.kubernetes.nodes.kubeletConfiguration​

Properties​

PropertyTypeRequired
kubeletCertificateAuthorityFilestringOptional
streamingConnectionIdleTimeoutstringOptional

Description​

Advanced configuration for Kubelet. This open field allows users to specify any parameter supported by the KubeletConfiguration object. Examples of uses include controlling the maximum number of pods per core (podsPerCore), managing container logging (containerLogMaxSize), Topology Manager options (topologyManagerPolicyOptions). All values must follow the official Kubelet specification: https://kubernetes.io/docs/reference/config-api/kubelet-config.v1beta1/.

NOTE: Content will not be validated by furyctl. To customize the TLS cipher suites of the Kubelet, set only the Spec.Kubernetes.Advanced.Encryption.tlsCipherSuitesKubelet field - do not configure them under this field.

.spec.kubernetes.nodes.kubeletConfiguration.kubeletCertificateAuthorityFile​

Description​

Path to the CA file used to verify the kubelet servers' TLS certificates.

.spec.kubernetes.nodes.kubeletConfiguration.streamingConnectionIdleTimeout​

Description​

The maximum time a streaming connection can be idle before it is closed. Example: 5m0s

.spec.kubernetes.nodes.labels​

Description​

Optional additional Kubernetes labels that will be added to the nodes in this node group. Follows Kubernetes labels format.

Note: Existing labels with the same key will be overwritten and the label setting the node role to the node group name cannot be deleted.

.spec.kubernetes.nodes.name​

Description​

Name for the node group. It will be also used as the node role label. It should follow the valid variable names guideline from Ansible.

.spec.kubernetes.nodes.taints​

Properties​

PropertyTypeRequired
effectstringRequired
keystringRequired
valuestringRequired

.spec.kubernetes.nodes.taints.effect​

Constraints​

enum: the value of this property must be equal to one of the following string values:

Value
"NoSchedule"
"PreferNoSchedule"
"NoExecute"

.spec.kubernetes.nodes.taints.key​

.spec.kubernetes.nodes.taints.value​

.spec.kubernetes.pkiFolder​

Description​

The path to the folder where the PKI files for Kubernetes and etcd are stored.

.spec.kubernetes.podCidr​

Description​

The subnet CIDR to use for the Pods network.

Constraints​

pattern: the string must match the following regular expression:

^((25[0-5]|(2[0-4]|1\d|[1-9]|)\d)\.?\b){4}\/(3[0-2]|[1-2][0-9]|[0-9])$

try pattern

.spec.kubernetes.proxy​

Properties​

PropertyTypeRequired
httpstringOptional
httpsstringOptional
noProxystringOptional

.spec.kubernetes.proxy.http​

Description​

The HTTP proxy URL. Example: http://test.example.dev:3128

Constraints​

pattern: the string must match the following regular expression:

^(http|https)\:\/\/.+$

try pattern

.spec.kubernetes.proxy.https​

Description​

The HTTPS proxy URL. Example: https://test.example.dev:3128

Constraints​

pattern: the string must match the following regular expression:

^(http|https)\:\/\/.+$

try pattern

.spec.kubernetes.proxy.noProxy​

Description​

Comma-separated list of hosts that should not use the HTTP(S) proxy. Example: localhost,127.0.0.1,172.16.0.0/17,172.16.128.0/17,10.0.0.0/8,.example.dev

.spec.kubernetes.ssh​

Properties​

PropertyTypeRequired
keyPathstringRequired
usernamestringRequired

Description​

SSH credentials to access the hosts

.spec.kubernetes.ssh.keyPath​

Description​

The path to the private key to use to connect to the hosts

.spec.kubernetes.ssh.username​

Description​

The username to use to connect to the hosts

.spec.kubernetes.svcCidr​

Description​

The subnet CIDR to use for the Services network.

Constraints​

pattern: the string must match the following regular expression:

^((25[0-5]|(2[0-4]|1\d|[1-9]|)\d)\.?\b){4}\/(3[0-2]|[1-2][0-9]|[0-9])$

try pattern

.spec.plugins​

Properties​

PropertyTypeRequired
helmobjectOptional
kustomizearrayOptional

.spec.plugins.helm​

Properties​

PropertyTypeRequired
releasesarrayOptional
repositoriesarrayOptional

.spec.plugins.helm.releases​

Properties​

PropertyTypeRequired
chartstringRequired
disableValidationOnInstallbooleanOptional
namestringRequired
namespacestringRequired
setarrayOptional
valuesarrayOptional
versionstringOptional

.spec.plugins.helm.releases.chart​

Description​

The chart of the release

.spec.plugins.helm.releases.disableValidationOnInstall​

Description​

Disable running helm diff validation when installing the plugin, it will still be done when upgrading.

.spec.plugins.helm.releases.name​

Description​

The name of the release

.spec.plugins.helm.releases.namespace​

Description​

The namespace of the release

.spec.plugins.helm.releases.set​

Properties​

PropertyTypeRequired
namestringRequired
valuestringRequired

.spec.plugins.helm.releases.set.name​

Description​

The name of the set

.spec.plugins.helm.releases.set.value​

Description​

The value of the set

.spec.plugins.helm.releases.values​

Description​

The values of the release

.spec.plugins.helm.releases.version​

Description​

The version of the release

.spec.plugins.helm.repositories​

Properties​

PropertyTypeRequired
namestringRequired
urlstringRequired

.spec.plugins.helm.repositories.name​

Description​

The name of the repository

.spec.plugins.helm.repositories.url​

Description​

The url of the repository

.spec.plugins.kustomize​

Properties​

PropertyTypeRequired
folderstringRequired
namestringRequired

.spec.plugins.kustomize.folder​

Description​

The folder of the kustomize plugin

.spec.plugins.kustomize.name​

Description​

The name of the kustomize plugin. A lowercase RFC 1123 subdomain must consist of lower case alphanumeric characters, '-' or '.', and must start and end with an alphanumeric character (e.g. 'example.com', 'local-storage')

Constraints​

pattern: the string must match the following regular expression:

^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$

try pattern