From 67de14a3b8419541156a328db388d75414d08f7a Mon Sep 17 00:00:00 2001 From: Ryan Richard Date: Sat, 3 Aug 2024 14:05:30 -0700 Subject: [PATCH] ran codegen on previous commit's changes --- ...ion.concierge.pinniped.dev_jwtauthenticators.yaml | 1 + ...concierge.pinniped.dev_webhookauthenticators.yaml | 1 + ...ig.supervisor.pinniped.dev_federationdomains.yaml | 10 ++++++---- ...inniped.dev_activedirectoryidentityproviders.yaml | 1 + ...ervisor.pinniped.dev_githubidentityproviders.yaml | 7 ++++++- ...upervisor.pinniped.dev_ldapidentityproviders.yaml | 1 + ...upervisor.pinniped.dev_oidcidentityproviders.yaml | 1 + generated/1.24/README.adoc | 12 +++++++++++- .../concierge/authentication/v1alpha1/types_tls.go | 1 + .../config/v1alpha1/types_credentialissuer.go | 4 +++- .../config/v1alpha1/types_federationdomain.go | 4 +++- .../idp/v1alpha1/types_githubidentityprovider.go | 5 ++++- .../1.24/apis/supervisor/idp/v1alpha1/types_tls.go | 1 + ...ion.concierge.pinniped.dev_jwtauthenticators.yaml | 1 + ...concierge.pinniped.dev_webhookauthenticators.yaml | 1 + ...ig.supervisor.pinniped.dev_federationdomains.yaml | 10 ++++++---- ...inniped.dev_activedirectoryidentityproviders.yaml | 1 + ...ervisor.pinniped.dev_githubidentityproviders.yaml | 7 ++++++- ...upervisor.pinniped.dev_ldapidentityproviders.yaml | 1 + ...upervisor.pinniped.dev_oidcidentityproviders.yaml | 1 + generated/1.25/README.adoc | 12 +++++++++++- .../concierge/authentication/v1alpha1/types_tls.go | 1 + .../config/v1alpha1/types_credentialissuer.go | 4 +++- .../config/v1alpha1/types_federationdomain.go | 4 +++- .../idp/v1alpha1/types_githubidentityprovider.go | 5 ++++- .../1.25/apis/supervisor/idp/v1alpha1/types_tls.go | 1 + ...ion.concierge.pinniped.dev_jwtauthenticators.yaml | 1 + ...concierge.pinniped.dev_webhookauthenticators.yaml | 1 + ...ig.supervisor.pinniped.dev_federationdomains.yaml | 10 ++++++---- ...inniped.dev_activedirectoryidentityproviders.yaml | 1 + ...ervisor.pinniped.dev_githubidentityproviders.yaml | 7 ++++++- ...upervisor.pinniped.dev_ldapidentityproviders.yaml | 1 + ...upervisor.pinniped.dev_oidcidentityproviders.yaml | 1 + generated/1.26/README.adoc | 12 +++++++++++- .../concierge/authentication/v1alpha1/types_tls.go | 1 + .../config/v1alpha1/types_credentialissuer.go | 4 +++- .../config/v1alpha1/types_federationdomain.go | 4 +++- .../idp/v1alpha1/types_githubidentityprovider.go | 5 ++++- .../1.26/apis/supervisor/idp/v1alpha1/types_tls.go | 1 + ...ion.concierge.pinniped.dev_jwtauthenticators.yaml | 1 + ...concierge.pinniped.dev_webhookauthenticators.yaml | 1 + ...ig.supervisor.pinniped.dev_federationdomains.yaml | 10 ++++++---- ...inniped.dev_activedirectoryidentityproviders.yaml | 1 + ...ervisor.pinniped.dev_githubidentityproviders.yaml | 7 ++++++- ...upervisor.pinniped.dev_ldapidentityproviders.yaml | 1 + ...upervisor.pinniped.dev_oidcidentityproviders.yaml | 1 + generated/1.27/README.adoc | 12 +++++++++++- .../concierge/authentication/v1alpha1/types_tls.go | 1 + .../config/v1alpha1/types_credentialissuer.go | 4 +++- .../config/v1alpha1/types_federationdomain.go | 4 +++- .../idp/v1alpha1/types_githubidentityprovider.go | 5 ++++- .../1.27/apis/supervisor/idp/v1alpha1/types_tls.go | 1 + ...ion.concierge.pinniped.dev_jwtauthenticators.yaml | 1 + ...concierge.pinniped.dev_webhookauthenticators.yaml | 1 + ...ig.supervisor.pinniped.dev_federationdomains.yaml | 10 ++++++---- ...inniped.dev_activedirectoryidentityproviders.yaml | 1 + ...ervisor.pinniped.dev_githubidentityproviders.yaml | 7 ++++++- ...upervisor.pinniped.dev_ldapidentityproviders.yaml | 1 + ...upervisor.pinniped.dev_oidcidentityproviders.yaml | 1 + generated/1.28/README.adoc | 12 +++++++++++- .../concierge/authentication/v1alpha1/types_tls.go | 1 + .../config/v1alpha1/types_credentialissuer.go | 4 +++- .../config/v1alpha1/types_federationdomain.go | 4 +++- .../idp/v1alpha1/types_githubidentityprovider.go | 5 ++++- .../1.28/apis/supervisor/idp/v1alpha1/types_tls.go | 1 + ...ion.concierge.pinniped.dev_jwtauthenticators.yaml | 1 + ...concierge.pinniped.dev_webhookauthenticators.yaml | 1 + ...ig.supervisor.pinniped.dev_federationdomains.yaml | 10 ++++++---- ...inniped.dev_activedirectoryidentityproviders.yaml | 1 + ...ervisor.pinniped.dev_githubidentityproviders.yaml | 7 ++++++- ...upervisor.pinniped.dev_ldapidentityproviders.yaml | 1 + ...upervisor.pinniped.dev_oidcidentityproviders.yaml | 1 + generated/1.29/README.adoc | 12 +++++++++++- .../concierge/authentication/v1alpha1/types_tls.go | 1 + .../config/v1alpha1/types_credentialissuer.go | 4 +++- .../config/v1alpha1/types_federationdomain.go | 4 +++- .../idp/v1alpha1/types_githubidentityprovider.go | 5 ++++- .../1.29/apis/supervisor/idp/v1alpha1/types_tls.go | 1 + ...ion.concierge.pinniped.dev_jwtauthenticators.yaml | 1 + ...concierge.pinniped.dev_webhookauthenticators.yaml | 1 + ...ig.supervisor.pinniped.dev_federationdomains.yaml | 10 ++++++---- ...inniped.dev_activedirectoryidentityproviders.yaml | 1 + ...ervisor.pinniped.dev_githubidentityproviders.yaml | 7 ++++++- ...upervisor.pinniped.dev_ldapidentityproviders.yaml | 1 + ...upervisor.pinniped.dev_oidcidentityproviders.yaml | 1 + generated/1.30/README.adoc | 12 +++++++++++- .../concierge/authentication/v1alpha1/types_tls.go | 1 + .../config/v1alpha1/types_credentialissuer.go | 4 +++- .../config/v1alpha1/types_federationdomain.go | 4 +++- .../idp/v1alpha1/types_githubidentityprovider.go | 5 ++++- .../1.30/apis/supervisor/idp/v1alpha1/types_tls.go | 1 + ...ion.concierge.pinniped.dev_jwtauthenticators.yaml | 1 + ...concierge.pinniped.dev_webhookauthenticators.yaml | 1 + ...ig.supervisor.pinniped.dev_federationdomains.yaml | 10 ++++++---- ...inniped.dev_activedirectoryidentityproviders.yaml | 1 + ...ervisor.pinniped.dev_githubidentityproviders.yaml | 7 ++++++- ...upervisor.pinniped.dev_ldapidentityproviders.yaml | 1 + ...upervisor.pinniped.dev_oidcidentityproviders.yaml | 1 + generated/latest/README.adoc | 12 +++++++++++- .../concierge/authentication/v1alpha1/types_tls.go | 1 + .../config/v1alpha1/types_credentialissuer.go | 4 +++- .../config/v1alpha1/types_federationdomain.go | 4 +++- .../idp/v1alpha1/types_githubidentityprovider.go | 5 ++++- .../latest/apis/supervisor/idp/v1alpha1/types_tls.go | 1 + 104 files changed, 320 insertions(+), 72 deletions(-) diff --git a/deploy/concierge/authentication.concierge.pinniped.dev_jwtauthenticators.yaml b/deploy/concierge/authentication.concierge.pinniped.dev_jwtauthenticators.yaml index 838f11edf..5366768a8 100644 --- a/deploy/concierge/authentication.concierge.pinniped.dev_jwtauthenticators.yaml +++ b/deploy/concierge/authentication.concierge.pinniped.dev_jwtauthenticators.yaml @@ -111,6 +111,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/deploy/concierge/authentication.concierge.pinniped.dev_webhookauthenticators.yaml b/deploy/concierge/authentication.concierge.pinniped.dev_webhookauthenticators.yaml index 0133d62fc..3f4f32dc9 100644 --- a/deploy/concierge/authentication.concierge.pinniped.dev_webhookauthenticators.yaml +++ b/deploy/concierge/authentication.concierge.pinniped.dev_webhookauthenticators.yaml @@ -82,6 +82,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/deploy/supervisor/config.supervisor.pinniped.dev_federationdomains.yaml b/deploy/supervisor/config.supervisor.pinniped.dev_federationdomains.yaml index 033513431..678263520 100644 --- a/deploy/supervisor/config.supervisor.pinniped.dev_federationdomains.yaml +++ b/deploy/supervisor/config.supervisor.pinniped.dev_federationdomains.yaml @@ -143,8 +143,9 @@ spec: Type is "string", and is otherwise ignored. type: string type: - description: Type determines the type of the constant, - and indicates which other field should be non-empty. + description: |- + Type determines the type of the constant, and indicates which other field should be non-empty. + Allowed values are "string" or "stringList". enum: - string - stringList @@ -262,8 +263,9 @@ spec: an authentication attempt. When empty, a default message will be used. type: string type: - description: Type determines the type of the expression. - It must be one of the supported types. + description: |- + Type determines the type of the expression. It must be one of the supported types. + Allowed values are "policy/v1", "username/v1", or "groups/v1". enum: - policy/v1 - username/v1 diff --git a/deploy/supervisor/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml b/deploy/supervisor/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml index dcc1836b6..9a5ec7c90 100644 --- a/deploy/supervisor/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml +++ b/deploy/supervisor/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml @@ -186,6 +186,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/deploy/supervisor/idp.supervisor.pinniped.dev_githubidentityproviders.yaml b/deploy/supervisor/idp.supervisor.pinniped.dev_githubidentityproviders.yaml index 669377e7c..4cf2b9bca 100644 --- a/deploy/supervisor/idp.supervisor.pinniped.dev_githubidentityproviders.yaml +++ b/deploy/supervisor/idp.supervisor.pinniped.dev_githubidentityproviders.yaml @@ -89,7 +89,11 @@ spec: policy: default: OnlyUsersFromAllowedOrganizations description: |- - Policy must be set to "AllGitHubUsers" if allowed is empty. + Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + Defaults to "OnlyUsersFromAllowedOrganizations". + + + Must be set to "AllGitHubUsers" if the allowed field is empty. This field only exists to ensure that Pinniped administrators are aware that an empty list of @@ -241,6 +245,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/deploy/supervisor/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml b/deploy/supervisor/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml index e1fb91934..08b616aed 100644 --- a/deploy/supervisor/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml +++ b/deploy/supervisor/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml @@ -177,6 +177,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/deploy/supervisor/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml b/deploy/supervisor/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml index 83ae89781..75efc06fc 100644 --- a/deploy/supervisor/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml +++ b/deploy/supervisor/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml @@ -227,6 +227,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.24/README.adoc b/generated/1.24/README.adoc index ef1d03c8b..2029b4436 100644 --- a/generated/1.24/README.adoc +++ b/generated/1.24/README.adoc @@ -38,6 +38,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Concierge is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -528,6 +529,7 @@ ImpersonationProxyInfo describes the parameters for the impersonation proxy on t ==== ImpersonationProxyMode (string) ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +Allowed values are "auto", "enabled", or "disabled". .Appears In: **** @@ -564,6 +566,7 @@ This is not supported on all cloud providers. + ==== ImpersonationProxyServiceType (string) ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +Allowed values are "LoadBalancer", "ClusterIP", or "None". .Appears In: **** @@ -953,6 +956,7 @@ the transform expressions. This is a union type, and Type is the discriminator f | Field | Description | *`name`* __string__ | Name determines the name of the constant. It must be a valid identifier name. + | *`type`* __string__ | Type determines the type of the constant, and indicates which other field should be non-empty. + +Allowed values are "string" or "stringList". + | *`stringValue`* __string__ | StringValue should hold the value when Type is "string", and is otherwise ignored. + | *`stringListValue`* __string array__ | StringListValue should hold the value when Type is "stringList", and is otherwise ignored. + |=== @@ -1019,6 +1023,7 @@ FederationDomainTransformsExpression defines a transform expression. |=== | Field | Description | *`type`* __string__ | Type determines the type of the expression. It must be one of the supported types. + +Allowed values are "policy/v1", "username/v1", or "groups/v1". + | *`expression`* __string__ | Expression is a CEL expression that will be evaluated based on the Type during an authentication. + | *`message`* __string__ | Message is only used when Type is policy/v1. It defines an error message to be used when the policy rejects + an authentication attempt. When empty, a default message will be used. + @@ -1685,6 +1690,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Supervisor is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -1938,7 +1944,11 @@ GitHubIdentityProviderStatus is the status of an GitHub identity provider. [cols="25a,75a", options="header"] |=== | Field | Description -| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-24-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Policy must be set to "AllGitHubUsers" if allowed is empty. + +| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-24-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + +Defaults to "OnlyUsersFromAllowedOrganizations". + + + +Must be set to "AllGitHubUsers" if the allowed field is empty. + This field only exists to ensure that Pinniped administrators are aware that an empty list of + diff --git a/generated/1.24/apis/concierge/authentication/v1alpha1/types_tls.go b/generated/1.24/apis/concierge/authentication/v1alpha1/types_tls.go index 883dc7fc7..db9f4ceff 100644 --- a/generated/1.24/apis/concierge/authentication/v1alpha1/types_tls.go +++ b/generated/1.24/apis/concierge/authentication/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.24/apis/concierge/config/v1alpha1/types_credentialissuer.go b/generated/1.24/apis/concierge/config/v1alpha1/types_credentialissuer.go index 0ee0f0dbf..de976f5c1 100644 --- a/generated/1.24/apis/concierge/config/v1alpha1/types_credentialissuer.go +++ b/generated/1.24/apis/concierge/config/v1alpha1/types_credentialissuer.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -49,6 +49,7 @@ type CredentialIssuerSpec struct { } // ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +// Allowed values are "auto", "enabled", or "disabled". // // +kubebuilder:validation:Enum=auto;enabled;disabled type ImpersonationProxyMode string @@ -65,6 +66,7 @@ const ( ) // ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +// Allowed values are "LoadBalancer", "ClusterIP", or "None". // // +kubebuilder:validation:Enum=LoadBalancer;ClusterIP;None type ImpersonationProxyServiceType string diff --git a/generated/1.24/apis/supervisor/config/v1alpha1/types_federationdomain.go b/generated/1.24/apis/supervisor/config/v1alpha1/types_federationdomain.go index 95f7da282..d1a6e6278 100644 --- a/generated/1.24/apis/supervisor/config/v1alpha1/types_federationdomain.go +++ b/generated/1.24/apis/supervisor/config/v1alpha1/types_federationdomain.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -55,6 +55,7 @@ type FederationDomainTransformsConstant struct { Name string `json:"name"` // Type determines the type of the constant, and indicates which other field should be non-empty. + // Allowed values are "string" or "stringList". // +kubebuilder:validation:Enum=string;stringList Type string `json:"type"` @@ -70,6 +71,7 @@ type FederationDomainTransformsConstant struct { // FederationDomainTransformsExpression defines a transform expression. type FederationDomainTransformsExpression struct { // Type determines the type of the expression. It must be one of the supported types. + // Allowed values are "policy/v1", "username/v1", or "groups/v1". // +kubebuilder:validation:Enum=policy/v1;username/v1;groups/v1 Type string `json:"type"` diff --git a/generated/1.24/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go b/generated/1.24/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go index c84f46dbd..437974778 100644 --- a/generated/1.24/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go +++ b/generated/1.24/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go @@ -167,7 +167,10 @@ type GitHubClientSpec struct { } type GitHubOrganizationsSpec struct { - // Policy must be set to "AllGitHubUsers" if allowed is empty. + // Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + // Defaults to "OnlyUsersFromAllowedOrganizations". + // + // Must be set to "AllGitHubUsers" if the allowed field is empty. // // This field only exists to ensure that Pinniped administrators are aware that an empty list of // allowedOrganizations means all GitHub users are allowed to log in. diff --git a/generated/1.24/apis/supervisor/idp/v1alpha1/types_tls.go b/generated/1.24/apis/supervisor/idp/v1alpha1/types_tls.go index 407a5cde5..70f1c71cc 100644 --- a/generated/1.24/apis/supervisor/idp/v1alpha1/types_tls.go +++ b/generated/1.24/apis/supervisor/idp/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.24/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml b/generated/1.24/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml index 838f11edf..5366768a8 100644 --- a/generated/1.24/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml +++ b/generated/1.24/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml @@ -111,6 +111,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.24/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml b/generated/1.24/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml index 0133d62fc..3f4f32dc9 100644 --- a/generated/1.24/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml +++ b/generated/1.24/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml @@ -82,6 +82,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.24/crds/config.supervisor.pinniped.dev_federationdomains.yaml b/generated/1.24/crds/config.supervisor.pinniped.dev_federationdomains.yaml index d43c7406d..b7390da91 100644 --- a/generated/1.24/crds/config.supervisor.pinniped.dev_federationdomains.yaml +++ b/generated/1.24/crds/config.supervisor.pinniped.dev_federationdomains.yaml @@ -143,8 +143,9 @@ spec: Type is "string", and is otherwise ignored. type: string type: - description: Type determines the type of the constant, - and indicates which other field should be non-empty. + description: |- + Type determines the type of the constant, and indicates which other field should be non-empty. + Allowed values are "string" or "stringList". enum: - string - stringList @@ -262,8 +263,9 @@ spec: an authentication attempt. When empty, a default message will be used. type: string type: - description: Type determines the type of the expression. - It must be one of the supported types. + description: |- + Type determines the type of the expression. It must be one of the supported types. + Allowed values are "policy/v1", "username/v1", or "groups/v1". enum: - policy/v1 - username/v1 diff --git a/generated/1.24/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml b/generated/1.24/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml index dcc1836b6..9a5ec7c90 100644 --- a/generated/1.24/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml +++ b/generated/1.24/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml @@ -186,6 +186,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.24/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml b/generated/1.24/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml index 669377e7c..4cf2b9bca 100644 --- a/generated/1.24/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml +++ b/generated/1.24/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml @@ -89,7 +89,11 @@ spec: policy: default: OnlyUsersFromAllowedOrganizations description: |- - Policy must be set to "AllGitHubUsers" if allowed is empty. + Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + Defaults to "OnlyUsersFromAllowedOrganizations". + + + Must be set to "AllGitHubUsers" if the allowed field is empty. This field only exists to ensure that Pinniped administrators are aware that an empty list of @@ -241,6 +245,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.24/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml b/generated/1.24/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml index e1fb91934..08b616aed 100644 --- a/generated/1.24/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml +++ b/generated/1.24/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml @@ -177,6 +177,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.24/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml b/generated/1.24/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml index 83ae89781..75efc06fc 100644 --- a/generated/1.24/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml +++ b/generated/1.24/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml @@ -227,6 +227,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.25/README.adoc b/generated/1.25/README.adoc index ac3c245ca..9797af1d9 100644 --- a/generated/1.25/README.adoc +++ b/generated/1.25/README.adoc @@ -38,6 +38,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Concierge is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -528,6 +529,7 @@ ImpersonationProxyInfo describes the parameters for the impersonation proxy on t ==== ImpersonationProxyMode (string) ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +Allowed values are "auto", "enabled", or "disabled". .Appears In: **** @@ -564,6 +566,7 @@ This is not supported on all cloud providers. + ==== ImpersonationProxyServiceType (string) ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +Allowed values are "LoadBalancer", "ClusterIP", or "None". .Appears In: **** @@ -953,6 +956,7 @@ the transform expressions. This is a union type, and Type is the discriminator f | Field | Description | *`name`* __string__ | Name determines the name of the constant. It must be a valid identifier name. + | *`type`* __string__ | Type determines the type of the constant, and indicates which other field should be non-empty. + +Allowed values are "string" or "stringList". + | *`stringValue`* __string__ | StringValue should hold the value when Type is "string", and is otherwise ignored. + | *`stringListValue`* __string array__ | StringListValue should hold the value when Type is "stringList", and is otherwise ignored. + |=== @@ -1019,6 +1023,7 @@ FederationDomainTransformsExpression defines a transform expression. |=== | Field | Description | *`type`* __string__ | Type determines the type of the expression. It must be one of the supported types. + +Allowed values are "policy/v1", "username/v1", or "groups/v1". + | *`expression`* __string__ | Expression is a CEL expression that will be evaluated based on the Type during an authentication. + | *`message`* __string__ | Message is only used when Type is policy/v1. It defines an error message to be used when the policy rejects + an authentication attempt. When empty, a default message will be used. + @@ -1685,6 +1690,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Supervisor is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -1938,7 +1944,11 @@ GitHubIdentityProviderStatus is the status of an GitHub identity provider. [cols="25a,75a", options="header"] |=== | Field | Description -| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-25-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Policy must be set to "AllGitHubUsers" if allowed is empty. + +| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-25-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + +Defaults to "OnlyUsersFromAllowedOrganizations". + + + +Must be set to "AllGitHubUsers" if the allowed field is empty. + This field only exists to ensure that Pinniped administrators are aware that an empty list of + diff --git a/generated/1.25/apis/concierge/authentication/v1alpha1/types_tls.go b/generated/1.25/apis/concierge/authentication/v1alpha1/types_tls.go index 883dc7fc7..db9f4ceff 100644 --- a/generated/1.25/apis/concierge/authentication/v1alpha1/types_tls.go +++ b/generated/1.25/apis/concierge/authentication/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.25/apis/concierge/config/v1alpha1/types_credentialissuer.go b/generated/1.25/apis/concierge/config/v1alpha1/types_credentialissuer.go index 0ee0f0dbf..de976f5c1 100644 --- a/generated/1.25/apis/concierge/config/v1alpha1/types_credentialissuer.go +++ b/generated/1.25/apis/concierge/config/v1alpha1/types_credentialissuer.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -49,6 +49,7 @@ type CredentialIssuerSpec struct { } // ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +// Allowed values are "auto", "enabled", or "disabled". // // +kubebuilder:validation:Enum=auto;enabled;disabled type ImpersonationProxyMode string @@ -65,6 +66,7 @@ const ( ) // ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +// Allowed values are "LoadBalancer", "ClusterIP", or "None". // // +kubebuilder:validation:Enum=LoadBalancer;ClusterIP;None type ImpersonationProxyServiceType string diff --git a/generated/1.25/apis/supervisor/config/v1alpha1/types_federationdomain.go b/generated/1.25/apis/supervisor/config/v1alpha1/types_federationdomain.go index 95f7da282..d1a6e6278 100644 --- a/generated/1.25/apis/supervisor/config/v1alpha1/types_federationdomain.go +++ b/generated/1.25/apis/supervisor/config/v1alpha1/types_federationdomain.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -55,6 +55,7 @@ type FederationDomainTransformsConstant struct { Name string `json:"name"` // Type determines the type of the constant, and indicates which other field should be non-empty. + // Allowed values are "string" or "stringList". // +kubebuilder:validation:Enum=string;stringList Type string `json:"type"` @@ -70,6 +71,7 @@ type FederationDomainTransformsConstant struct { // FederationDomainTransformsExpression defines a transform expression. type FederationDomainTransformsExpression struct { // Type determines the type of the expression. It must be one of the supported types. + // Allowed values are "policy/v1", "username/v1", or "groups/v1". // +kubebuilder:validation:Enum=policy/v1;username/v1;groups/v1 Type string `json:"type"` diff --git a/generated/1.25/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go b/generated/1.25/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go index c84f46dbd..437974778 100644 --- a/generated/1.25/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go +++ b/generated/1.25/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go @@ -167,7 +167,10 @@ type GitHubClientSpec struct { } type GitHubOrganizationsSpec struct { - // Policy must be set to "AllGitHubUsers" if allowed is empty. + // Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + // Defaults to "OnlyUsersFromAllowedOrganizations". + // + // Must be set to "AllGitHubUsers" if the allowed field is empty. // // This field only exists to ensure that Pinniped administrators are aware that an empty list of // allowedOrganizations means all GitHub users are allowed to log in. diff --git a/generated/1.25/apis/supervisor/idp/v1alpha1/types_tls.go b/generated/1.25/apis/supervisor/idp/v1alpha1/types_tls.go index 407a5cde5..70f1c71cc 100644 --- a/generated/1.25/apis/supervisor/idp/v1alpha1/types_tls.go +++ b/generated/1.25/apis/supervisor/idp/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.25/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml b/generated/1.25/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml index 838f11edf..5366768a8 100644 --- a/generated/1.25/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml +++ b/generated/1.25/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml @@ -111,6 +111,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.25/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml b/generated/1.25/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml index 0133d62fc..3f4f32dc9 100644 --- a/generated/1.25/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml +++ b/generated/1.25/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml @@ -82,6 +82,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.25/crds/config.supervisor.pinniped.dev_federationdomains.yaml b/generated/1.25/crds/config.supervisor.pinniped.dev_federationdomains.yaml index d43c7406d..b7390da91 100644 --- a/generated/1.25/crds/config.supervisor.pinniped.dev_federationdomains.yaml +++ b/generated/1.25/crds/config.supervisor.pinniped.dev_federationdomains.yaml @@ -143,8 +143,9 @@ spec: Type is "string", and is otherwise ignored. type: string type: - description: Type determines the type of the constant, - and indicates which other field should be non-empty. + description: |- + Type determines the type of the constant, and indicates which other field should be non-empty. + Allowed values are "string" or "stringList". enum: - string - stringList @@ -262,8 +263,9 @@ spec: an authentication attempt. When empty, a default message will be used. type: string type: - description: Type determines the type of the expression. - It must be one of the supported types. + description: |- + Type determines the type of the expression. It must be one of the supported types. + Allowed values are "policy/v1", "username/v1", or "groups/v1". enum: - policy/v1 - username/v1 diff --git a/generated/1.25/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml b/generated/1.25/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml index dcc1836b6..9a5ec7c90 100644 --- a/generated/1.25/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml +++ b/generated/1.25/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml @@ -186,6 +186,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.25/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml b/generated/1.25/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml index 669377e7c..4cf2b9bca 100644 --- a/generated/1.25/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml +++ b/generated/1.25/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml @@ -89,7 +89,11 @@ spec: policy: default: OnlyUsersFromAllowedOrganizations description: |- - Policy must be set to "AllGitHubUsers" if allowed is empty. + Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + Defaults to "OnlyUsersFromAllowedOrganizations". + + + Must be set to "AllGitHubUsers" if the allowed field is empty. This field only exists to ensure that Pinniped administrators are aware that an empty list of @@ -241,6 +245,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.25/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml b/generated/1.25/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml index e1fb91934..08b616aed 100644 --- a/generated/1.25/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml +++ b/generated/1.25/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml @@ -177,6 +177,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.25/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml b/generated/1.25/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml index 83ae89781..75efc06fc 100644 --- a/generated/1.25/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml +++ b/generated/1.25/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml @@ -227,6 +227,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.26/README.adoc b/generated/1.26/README.adoc index 22635e322..312c1f4b0 100644 --- a/generated/1.26/README.adoc +++ b/generated/1.26/README.adoc @@ -38,6 +38,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Concierge is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -528,6 +529,7 @@ ImpersonationProxyInfo describes the parameters for the impersonation proxy on t ==== ImpersonationProxyMode (string) ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +Allowed values are "auto", "enabled", or "disabled". .Appears In: **** @@ -564,6 +566,7 @@ This is not supported on all cloud providers. + ==== ImpersonationProxyServiceType (string) ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +Allowed values are "LoadBalancer", "ClusterIP", or "None". .Appears In: **** @@ -953,6 +956,7 @@ the transform expressions. This is a union type, and Type is the discriminator f | Field | Description | *`name`* __string__ | Name determines the name of the constant. It must be a valid identifier name. + | *`type`* __string__ | Type determines the type of the constant, and indicates which other field should be non-empty. + +Allowed values are "string" or "stringList". + | *`stringValue`* __string__ | StringValue should hold the value when Type is "string", and is otherwise ignored. + | *`stringListValue`* __string array__ | StringListValue should hold the value when Type is "stringList", and is otherwise ignored. + |=== @@ -1019,6 +1023,7 @@ FederationDomainTransformsExpression defines a transform expression. |=== | Field | Description | *`type`* __string__ | Type determines the type of the expression. It must be one of the supported types. + +Allowed values are "policy/v1", "username/v1", or "groups/v1". + | *`expression`* __string__ | Expression is a CEL expression that will be evaluated based on the Type during an authentication. + | *`message`* __string__ | Message is only used when Type is policy/v1. It defines an error message to be used when the policy rejects + an authentication attempt. When empty, a default message will be used. + @@ -1685,6 +1690,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Supervisor is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -1938,7 +1944,11 @@ GitHubIdentityProviderStatus is the status of an GitHub identity provider. [cols="25a,75a", options="header"] |=== | Field | Description -| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-26-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Policy must be set to "AllGitHubUsers" if allowed is empty. + +| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-26-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + +Defaults to "OnlyUsersFromAllowedOrganizations". + + + +Must be set to "AllGitHubUsers" if the allowed field is empty. + This field only exists to ensure that Pinniped administrators are aware that an empty list of + diff --git a/generated/1.26/apis/concierge/authentication/v1alpha1/types_tls.go b/generated/1.26/apis/concierge/authentication/v1alpha1/types_tls.go index 883dc7fc7..db9f4ceff 100644 --- a/generated/1.26/apis/concierge/authentication/v1alpha1/types_tls.go +++ b/generated/1.26/apis/concierge/authentication/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.26/apis/concierge/config/v1alpha1/types_credentialissuer.go b/generated/1.26/apis/concierge/config/v1alpha1/types_credentialissuer.go index 0ee0f0dbf..de976f5c1 100644 --- a/generated/1.26/apis/concierge/config/v1alpha1/types_credentialissuer.go +++ b/generated/1.26/apis/concierge/config/v1alpha1/types_credentialissuer.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -49,6 +49,7 @@ type CredentialIssuerSpec struct { } // ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +// Allowed values are "auto", "enabled", or "disabled". // // +kubebuilder:validation:Enum=auto;enabled;disabled type ImpersonationProxyMode string @@ -65,6 +66,7 @@ const ( ) // ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +// Allowed values are "LoadBalancer", "ClusterIP", or "None". // // +kubebuilder:validation:Enum=LoadBalancer;ClusterIP;None type ImpersonationProxyServiceType string diff --git a/generated/1.26/apis/supervisor/config/v1alpha1/types_federationdomain.go b/generated/1.26/apis/supervisor/config/v1alpha1/types_federationdomain.go index 95f7da282..d1a6e6278 100644 --- a/generated/1.26/apis/supervisor/config/v1alpha1/types_federationdomain.go +++ b/generated/1.26/apis/supervisor/config/v1alpha1/types_federationdomain.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -55,6 +55,7 @@ type FederationDomainTransformsConstant struct { Name string `json:"name"` // Type determines the type of the constant, and indicates which other field should be non-empty. + // Allowed values are "string" or "stringList". // +kubebuilder:validation:Enum=string;stringList Type string `json:"type"` @@ -70,6 +71,7 @@ type FederationDomainTransformsConstant struct { // FederationDomainTransformsExpression defines a transform expression. type FederationDomainTransformsExpression struct { // Type determines the type of the expression. It must be one of the supported types. + // Allowed values are "policy/v1", "username/v1", or "groups/v1". // +kubebuilder:validation:Enum=policy/v1;username/v1;groups/v1 Type string `json:"type"` diff --git a/generated/1.26/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go b/generated/1.26/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go index c84f46dbd..437974778 100644 --- a/generated/1.26/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go +++ b/generated/1.26/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go @@ -167,7 +167,10 @@ type GitHubClientSpec struct { } type GitHubOrganizationsSpec struct { - // Policy must be set to "AllGitHubUsers" if allowed is empty. + // Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + // Defaults to "OnlyUsersFromAllowedOrganizations". + // + // Must be set to "AllGitHubUsers" if the allowed field is empty. // // This field only exists to ensure that Pinniped administrators are aware that an empty list of // allowedOrganizations means all GitHub users are allowed to log in. diff --git a/generated/1.26/apis/supervisor/idp/v1alpha1/types_tls.go b/generated/1.26/apis/supervisor/idp/v1alpha1/types_tls.go index 407a5cde5..70f1c71cc 100644 --- a/generated/1.26/apis/supervisor/idp/v1alpha1/types_tls.go +++ b/generated/1.26/apis/supervisor/idp/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.26/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml b/generated/1.26/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml index 838f11edf..5366768a8 100644 --- a/generated/1.26/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml +++ b/generated/1.26/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml @@ -111,6 +111,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.26/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml b/generated/1.26/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml index 0133d62fc..3f4f32dc9 100644 --- a/generated/1.26/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml +++ b/generated/1.26/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml @@ -82,6 +82,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.26/crds/config.supervisor.pinniped.dev_federationdomains.yaml b/generated/1.26/crds/config.supervisor.pinniped.dev_federationdomains.yaml index d43c7406d..b7390da91 100644 --- a/generated/1.26/crds/config.supervisor.pinniped.dev_federationdomains.yaml +++ b/generated/1.26/crds/config.supervisor.pinniped.dev_federationdomains.yaml @@ -143,8 +143,9 @@ spec: Type is "string", and is otherwise ignored. type: string type: - description: Type determines the type of the constant, - and indicates which other field should be non-empty. + description: |- + Type determines the type of the constant, and indicates which other field should be non-empty. + Allowed values are "string" or "stringList". enum: - string - stringList @@ -262,8 +263,9 @@ spec: an authentication attempt. When empty, a default message will be used. type: string type: - description: Type determines the type of the expression. - It must be one of the supported types. + description: |- + Type determines the type of the expression. It must be one of the supported types. + Allowed values are "policy/v1", "username/v1", or "groups/v1". enum: - policy/v1 - username/v1 diff --git a/generated/1.26/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml b/generated/1.26/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml index dcc1836b6..9a5ec7c90 100644 --- a/generated/1.26/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml +++ b/generated/1.26/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml @@ -186,6 +186,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.26/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml b/generated/1.26/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml index 669377e7c..4cf2b9bca 100644 --- a/generated/1.26/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml +++ b/generated/1.26/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml @@ -89,7 +89,11 @@ spec: policy: default: OnlyUsersFromAllowedOrganizations description: |- - Policy must be set to "AllGitHubUsers" if allowed is empty. + Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + Defaults to "OnlyUsersFromAllowedOrganizations". + + + Must be set to "AllGitHubUsers" if the allowed field is empty. This field only exists to ensure that Pinniped administrators are aware that an empty list of @@ -241,6 +245,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.26/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml b/generated/1.26/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml index e1fb91934..08b616aed 100644 --- a/generated/1.26/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml +++ b/generated/1.26/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml @@ -177,6 +177,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.26/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml b/generated/1.26/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml index 83ae89781..75efc06fc 100644 --- a/generated/1.26/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml +++ b/generated/1.26/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml @@ -227,6 +227,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.27/README.adoc b/generated/1.27/README.adoc index 4408cc279..f973f3223 100644 --- a/generated/1.27/README.adoc +++ b/generated/1.27/README.adoc @@ -38,6 +38,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Concierge is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -528,6 +529,7 @@ ImpersonationProxyInfo describes the parameters for the impersonation proxy on t ==== ImpersonationProxyMode (string) ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +Allowed values are "auto", "enabled", or "disabled". .Appears In: **** @@ -564,6 +566,7 @@ This is not supported on all cloud providers. + ==== ImpersonationProxyServiceType (string) ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +Allowed values are "LoadBalancer", "ClusterIP", or "None". .Appears In: **** @@ -953,6 +956,7 @@ the transform expressions. This is a union type, and Type is the discriminator f | Field | Description | *`name`* __string__ | Name determines the name of the constant. It must be a valid identifier name. + | *`type`* __string__ | Type determines the type of the constant, and indicates which other field should be non-empty. + +Allowed values are "string" or "stringList". + | *`stringValue`* __string__ | StringValue should hold the value when Type is "string", and is otherwise ignored. + | *`stringListValue`* __string array__ | StringListValue should hold the value when Type is "stringList", and is otherwise ignored. + |=== @@ -1019,6 +1023,7 @@ FederationDomainTransformsExpression defines a transform expression. |=== | Field | Description | *`type`* __string__ | Type determines the type of the expression. It must be one of the supported types. + +Allowed values are "policy/v1", "username/v1", or "groups/v1". + | *`expression`* __string__ | Expression is a CEL expression that will be evaluated based on the Type during an authentication. + | *`message`* __string__ | Message is only used when Type is policy/v1. It defines an error message to be used when the policy rejects + an authentication attempt. When empty, a default message will be used. + @@ -1685,6 +1690,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Supervisor is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -1938,7 +1944,11 @@ GitHubIdentityProviderStatus is the status of an GitHub identity provider. [cols="25a,75a", options="header"] |=== | Field | Description -| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-27-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Policy must be set to "AllGitHubUsers" if allowed is empty. + +| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-27-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + +Defaults to "OnlyUsersFromAllowedOrganizations". + + + +Must be set to "AllGitHubUsers" if the allowed field is empty. + This field only exists to ensure that Pinniped administrators are aware that an empty list of + diff --git a/generated/1.27/apis/concierge/authentication/v1alpha1/types_tls.go b/generated/1.27/apis/concierge/authentication/v1alpha1/types_tls.go index 883dc7fc7..db9f4ceff 100644 --- a/generated/1.27/apis/concierge/authentication/v1alpha1/types_tls.go +++ b/generated/1.27/apis/concierge/authentication/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.27/apis/concierge/config/v1alpha1/types_credentialissuer.go b/generated/1.27/apis/concierge/config/v1alpha1/types_credentialissuer.go index 0ee0f0dbf..de976f5c1 100644 --- a/generated/1.27/apis/concierge/config/v1alpha1/types_credentialissuer.go +++ b/generated/1.27/apis/concierge/config/v1alpha1/types_credentialissuer.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -49,6 +49,7 @@ type CredentialIssuerSpec struct { } // ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +// Allowed values are "auto", "enabled", or "disabled". // // +kubebuilder:validation:Enum=auto;enabled;disabled type ImpersonationProxyMode string @@ -65,6 +66,7 @@ const ( ) // ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +// Allowed values are "LoadBalancer", "ClusterIP", or "None". // // +kubebuilder:validation:Enum=LoadBalancer;ClusterIP;None type ImpersonationProxyServiceType string diff --git a/generated/1.27/apis/supervisor/config/v1alpha1/types_federationdomain.go b/generated/1.27/apis/supervisor/config/v1alpha1/types_federationdomain.go index 95f7da282..d1a6e6278 100644 --- a/generated/1.27/apis/supervisor/config/v1alpha1/types_federationdomain.go +++ b/generated/1.27/apis/supervisor/config/v1alpha1/types_federationdomain.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -55,6 +55,7 @@ type FederationDomainTransformsConstant struct { Name string `json:"name"` // Type determines the type of the constant, and indicates which other field should be non-empty. + // Allowed values are "string" or "stringList". // +kubebuilder:validation:Enum=string;stringList Type string `json:"type"` @@ -70,6 +71,7 @@ type FederationDomainTransformsConstant struct { // FederationDomainTransformsExpression defines a transform expression. type FederationDomainTransformsExpression struct { // Type determines the type of the expression. It must be one of the supported types. + // Allowed values are "policy/v1", "username/v1", or "groups/v1". // +kubebuilder:validation:Enum=policy/v1;username/v1;groups/v1 Type string `json:"type"` diff --git a/generated/1.27/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go b/generated/1.27/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go index c84f46dbd..437974778 100644 --- a/generated/1.27/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go +++ b/generated/1.27/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go @@ -167,7 +167,10 @@ type GitHubClientSpec struct { } type GitHubOrganizationsSpec struct { - // Policy must be set to "AllGitHubUsers" if allowed is empty. + // Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + // Defaults to "OnlyUsersFromAllowedOrganizations". + // + // Must be set to "AllGitHubUsers" if the allowed field is empty. // // This field only exists to ensure that Pinniped administrators are aware that an empty list of // allowedOrganizations means all GitHub users are allowed to log in. diff --git a/generated/1.27/apis/supervisor/idp/v1alpha1/types_tls.go b/generated/1.27/apis/supervisor/idp/v1alpha1/types_tls.go index 407a5cde5..70f1c71cc 100644 --- a/generated/1.27/apis/supervisor/idp/v1alpha1/types_tls.go +++ b/generated/1.27/apis/supervisor/idp/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.27/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml b/generated/1.27/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml index 838f11edf..5366768a8 100644 --- a/generated/1.27/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml +++ b/generated/1.27/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml @@ -111,6 +111,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.27/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml b/generated/1.27/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml index 0133d62fc..3f4f32dc9 100644 --- a/generated/1.27/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml +++ b/generated/1.27/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml @@ -82,6 +82,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.27/crds/config.supervisor.pinniped.dev_federationdomains.yaml b/generated/1.27/crds/config.supervisor.pinniped.dev_federationdomains.yaml index d43c7406d..b7390da91 100644 --- a/generated/1.27/crds/config.supervisor.pinniped.dev_federationdomains.yaml +++ b/generated/1.27/crds/config.supervisor.pinniped.dev_federationdomains.yaml @@ -143,8 +143,9 @@ spec: Type is "string", and is otherwise ignored. type: string type: - description: Type determines the type of the constant, - and indicates which other field should be non-empty. + description: |- + Type determines the type of the constant, and indicates which other field should be non-empty. + Allowed values are "string" or "stringList". enum: - string - stringList @@ -262,8 +263,9 @@ spec: an authentication attempt. When empty, a default message will be used. type: string type: - description: Type determines the type of the expression. - It must be one of the supported types. + description: |- + Type determines the type of the expression. It must be one of the supported types. + Allowed values are "policy/v1", "username/v1", or "groups/v1". enum: - policy/v1 - username/v1 diff --git a/generated/1.27/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml b/generated/1.27/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml index dcc1836b6..9a5ec7c90 100644 --- a/generated/1.27/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml +++ b/generated/1.27/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml @@ -186,6 +186,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.27/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml b/generated/1.27/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml index 669377e7c..4cf2b9bca 100644 --- a/generated/1.27/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml +++ b/generated/1.27/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml @@ -89,7 +89,11 @@ spec: policy: default: OnlyUsersFromAllowedOrganizations description: |- - Policy must be set to "AllGitHubUsers" if allowed is empty. + Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + Defaults to "OnlyUsersFromAllowedOrganizations". + + + Must be set to "AllGitHubUsers" if the allowed field is empty. This field only exists to ensure that Pinniped administrators are aware that an empty list of @@ -241,6 +245,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.27/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml b/generated/1.27/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml index e1fb91934..08b616aed 100644 --- a/generated/1.27/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml +++ b/generated/1.27/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml @@ -177,6 +177,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.27/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml b/generated/1.27/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml index 83ae89781..75efc06fc 100644 --- a/generated/1.27/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml +++ b/generated/1.27/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml @@ -227,6 +227,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.28/README.adoc b/generated/1.28/README.adoc index 65ef835b8..52bf0d702 100644 --- a/generated/1.28/README.adoc +++ b/generated/1.28/README.adoc @@ -38,6 +38,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Concierge is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -528,6 +529,7 @@ ImpersonationProxyInfo describes the parameters for the impersonation proxy on t ==== ImpersonationProxyMode (string) ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +Allowed values are "auto", "enabled", or "disabled". .Appears In: **** @@ -564,6 +566,7 @@ This is not supported on all cloud providers. + ==== ImpersonationProxyServiceType (string) ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +Allowed values are "LoadBalancer", "ClusterIP", or "None". .Appears In: **** @@ -953,6 +956,7 @@ the transform expressions. This is a union type, and Type is the discriminator f | Field | Description | *`name`* __string__ | Name determines the name of the constant. It must be a valid identifier name. + | *`type`* __string__ | Type determines the type of the constant, and indicates which other field should be non-empty. + +Allowed values are "string" or "stringList". + | *`stringValue`* __string__ | StringValue should hold the value when Type is "string", and is otherwise ignored. + | *`stringListValue`* __string array__ | StringListValue should hold the value when Type is "stringList", and is otherwise ignored. + |=== @@ -1019,6 +1023,7 @@ FederationDomainTransformsExpression defines a transform expression. |=== | Field | Description | *`type`* __string__ | Type determines the type of the expression. It must be one of the supported types. + +Allowed values are "policy/v1", "username/v1", or "groups/v1". + | *`expression`* __string__ | Expression is a CEL expression that will be evaluated based on the Type during an authentication. + | *`message`* __string__ | Message is only used when Type is policy/v1. It defines an error message to be used when the policy rejects + an authentication attempt. When empty, a default message will be used. + @@ -1685,6 +1690,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Supervisor is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -1938,7 +1944,11 @@ GitHubIdentityProviderStatus is the status of an GitHub identity provider. [cols="25a,75a", options="header"] |=== | Field | Description -| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-28-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Policy must be set to "AllGitHubUsers" if allowed is empty. + +| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-28-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + +Defaults to "OnlyUsersFromAllowedOrganizations". + + + +Must be set to "AllGitHubUsers" if the allowed field is empty. + This field only exists to ensure that Pinniped administrators are aware that an empty list of + diff --git a/generated/1.28/apis/concierge/authentication/v1alpha1/types_tls.go b/generated/1.28/apis/concierge/authentication/v1alpha1/types_tls.go index 883dc7fc7..db9f4ceff 100644 --- a/generated/1.28/apis/concierge/authentication/v1alpha1/types_tls.go +++ b/generated/1.28/apis/concierge/authentication/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.28/apis/concierge/config/v1alpha1/types_credentialissuer.go b/generated/1.28/apis/concierge/config/v1alpha1/types_credentialissuer.go index 0ee0f0dbf..de976f5c1 100644 --- a/generated/1.28/apis/concierge/config/v1alpha1/types_credentialissuer.go +++ b/generated/1.28/apis/concierge/config/v1alpha1/types_credentialissuer.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -49,6 +49,7 @@ type CredentialIssuerSpec struct { } // ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +// Allowed values are "auto", "enabled", or "disabled". // // +kubebuilder:validation:Enum=auto;enabled;disabled type ImpersonationProxyMode string @@ -65,6 +66,7 @@ const ( ) // ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +// Allowed values are "LoadBalancer", "ClusterIP", or "None". // // +kubebuilder:validation:Enum=LoadBalancer;ClusterIP;None type ImpersonationProxyServiceType string diff --git a/generated/1.28/apis/supervisor/config/v1alpha1/types_federationdomain.go b/generated/1.28/apis/supervisor/config/v1alpha1/types_federationdomain.go index 95f7da282..d1a6e6278 100644 --- a/generated/1.28/apis/supervisor/config/v1alpha1/types_federationdomain.go +++ b/generated/1.28/apis/supervisor/config/v1alpha1/types_federationdomain.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -55,6 +55,7 @@ type FederationDomainTransformsConstant struct { Name string `json:"name"` // Type determines the type of the constant, and indicates which other field should be non-empty. + // Allowed values are "string" or "stringList". // +kubebuilder:validation:Enum=string;stringList Type string `json:"type"` @@ -70,6 +71,7 @@ type FederationDomainTransformsConstant struct { // FederationDomainTransformsExpression defines a transform expression. type FederationDomainTransformsExpression struct { // Type determines the type of the expression. It must be one of the supported types. + // Allowed values are "policy/v1", "username/v1", or "groups/v1". // +kubebuilder:validation:Enum=policy/v1;username/v1;groups/v1 Type string `json:"type"` diff --git a/generated/1.28/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go b/generated/1.28/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go index c84f46dbd..437974778 100644 --- a/generated/1.28/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go +++ b/generated/1.28/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go @@ -167,7 +167,10 @@ type GitHubClientSpec struct { } type GitHubOrganizationsSpec struct { - // Policy must be set to "AllGitHubUsers" if allowed is empty. + // Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + // Defaults to "OnlyUsersFromAllowedOrganizations". + // + // Must be set to "AllGitHubUsers" if the allowed field is empty. // // This field only exists to ensure that Pinniped administrators are aware that an empty list of // allowedOrganizations means all GitHub users are allowed to log in. diff --git a/generated/1.28/apis/supervisor/idp/v1alpha1/types_tls.go b/generated/1.28/apis/supervisor/idp/v1alpha1/types_tls.go index 407a5cde5..70f1c71cc 100644 --- a/generated/1.28/apis/supervisor/idp/v1alpha1/types_tls.go +++ b/generated/1.28/apis/supervisor/idp/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.28/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml b/generated/1.28/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml index 838f11edf..5366768a8 100644 --- a/generated/1.28/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml +++ b/generated/1.28/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml @@ -111,6 +111,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.28/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml b/generated/1.28/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml index 0133d62fc..3f4f32dc9 100644 --- a/generated/1.28/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml +++ b/generated/1.28/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml @@ -82,6 +82,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.28/crds/config.supervisor.pinniped.dev_federationdomains.yaml b/generated/1.28/crds/config.supervisor.pinniped.dev_federationdomains.yaml index d43c7406d..b7390da91 100644 --- a/generated/1.28/crds/config.supervisor.pinniped.dev_federationdomains.yaml +++ b/generated/1.28/crds/config.supervisor.pinniped.dev_federationdomains.yaml @@ -143,8 +143,9 @@ spec: Type is "string", and is otherwise ignored. type: string type: - description: Type determines the type of the constant, - and indicates which other field should be non-empty. + description: |- + Type determines the type of the constant, and indicates which other field should be non-empty. + Allowed values are "string" or "stringList". enum: - string - stringList @@ -262,8 +263,9 @@ spec: an authentication attempt. When empty, a default message will be used. type: string type: - description: Type determines the type of the expression. - It must be one of the supported types. + description: |- + Type determines the type of the expression. It must be one of the supported types. + Allowed values are "policy/v1", "username/v1", or "groups/v1". enum: - policy/v1 - username/v1 diff --git a/generated/1.28/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml b/generated/1.28/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml index dcc1836b6..9a5ec7c90 100644 --- a/generated/1.28/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml +++ b/generated/1.28/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml @@ -186,6 +186,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.28/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml b/generated/1.28/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml index 669377e7c..4cf2b9bca 100644 --- a/generated/1.28/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml +++ b/generated/1.28/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml @@ -89,7 +89,11 @@ spec: policy: default: OnlyUsersFromAllowedOrganizations description: |- - Policy must be set to "AllGitHubUsers" if allowed is empty. + Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + Defaults to "OnlyUsersFromAllowedOrganizations". + + + Must be set to "AllGitHubUsers" if the allowed field is empty. This field only exists to ensure that Pinniped administrators are aware that an empty list of @@ -241,6 +245,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.28/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml b/generated/1.28/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml index e1fb91934..08b616aed 100644 --- a/generated/1.28/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml +++ b/generated/1.28/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml @@ -177,6 +177,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.28/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml b/generated/1.28/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml index 83ae89781..75efc06fc 100644 --- a/generated/1.28/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml +++ b/generated/1.28/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml @@ -227,6 +227,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.29/README.adoc b/generated/1.29/README.adoc index b5ae5e4a4..5350ab237 100644 --- a/generated/1.29/README.adoc +++ b/generated/1.29/README.adoc @@ -38,6 +38,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Concierge is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -528,6 +529,7 @@ ImpersonationProxyInfo describes the parameters for the impersonation proxy on t ==== ImpersonationProxyMode (string) ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +Allowed values are "auto", "enabled", or "disabled". .Appears In: **** @@ -564,6 +566,7 @@ This is not supported on all cloud providers. + ==== ImpersonationProxyServiceType (string) ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +Allowed values are "LoadBalancer", "ClusterIP", or "None". .Appears In: **** @@ -953,6 +956,7 @@ the transform expressions. This is a union type, and Type is the discriminator f | Field | Description | *`name`* __string__ | Name determines the name of the constant. It must be a valid identifier name. + | *`type`* __string__ | Type determines the type of the constant, and indicates which other field should be non-empty. + +Allowed values are "string" or "stringList". + | *`stringValue`* __string__ | StringValue should hold the value when Type is "string", and is otherwise ignored. + | *`stringListValue`* __string array__ | StringListValue should hold the value when Type is "stringList", and is otherwise ignored. + |=== @@ -1019,6 +1023,7 @@ FederationDomainTransformsExpression defines a transform expression. |=== | Field | Description | *`type`* __string__ | Type determines the type of the expression. It must be one of the supported types. + +Allowed values are "policy/v1", "username/v1", or "groups/v1". + | *`expression`* __string__ | Expression is a CEL expression that will be evaluated based on the Type during an authentication. + | *`message`* __string__ | Message is only used when Type is policy/v1. It defines an error message to be used when the policy rejects + an authentication attempt. When empty, a default message will be used. + @@ -1685,6 +1690,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Supervisor is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -1938,7 +1944,11 @@ GitHubIdentityProviderStatus is the status of an GitHub identity provider. [cols="25a,75a", options="header"] |=== | Field | Description -| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-29-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Policy must be set to "AllGitHubUsers" if allowed is empty. + +| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-29-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + +Defaults to "OnlyUsersFromAllowedOrganizations". + + + +Must be set to "AllGitHubUsers" if the allowed field is empty. + This field only exists to ensure that Pinniped administrators are aware that an empty list of + diff --git a/generated/1.29/apis/concierge/authentication/v1alpha1/types_tls.go b/generated/1.29/apis/concierge/authentication/v1alpha1/types_tls.go index 883dc7fc7..db9f4ceff 100644 --- a/generated/1.29/apis/concierge/authentication/v1alpha1/types_tls.go +++ b/generated/1.29/apis/concierge/authentication/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.29/apis/concierge/config/v1alpha1/types_credentialissuer.go b/generated/1.29/apis/concierge/config/v1alpha1/types_credentialissuer.go index 0ee0f0dbf..de976f5c1 100644 --- a/generated/1.29/apis/concierge/config/v1alpha1/types_credentialissuer.go +++ b/generated/1.29/apis/concierge/config/v1alpha1/types_credentialissuer.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -49,6 +49,7 @@ type CredentialIssuerSpec struct { } // ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +// Allowed values are "auto", "enabled", or "disabled". // // +kubebuilder:validation:Enum=auto;enabled;disabled type ImpersonationProxyMode string @@ -65,6 +66,7 @@ const ( ) // ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +// Allowed values are "LoadBalancer", "ClusterIP", or "None". // // +kubebuilder:validation:Enum=LoadBalancer;ClusterIP;None type ImpersonationProxyServiceType string diff --git a/generated/1.29/apis/supervisor/config/v1alpha1/types_federationdomain.go b/generated/1.29/apis/supervisor/config/v1alpha1/types_federationdomain.go index 95f7da282..d1a6e6278 100644 --- a/generated/1.29/apis/supervisor/config/v1alpha1/types_federationdomain.go +++ b/generated/1.29/apis/supervisor/config/v1alpha1/types_federationdomain.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -55,6 +55,7 @@ type FederationDomainTransformsConstant struct { Name string `json:"name"` // Type determines the type of the constant, and indicates which other field should be non-empty. + // Allowed values are "string" or "stringList". // +kubebuilder:validation:Enum=string;stringList Type string `json:"type"` @@ -70,6 +71,7 @@ type FederationDomainTransformsConstant struct { // FederationDomainTransformsExpression defines a transform expression. type FederationDomainTransformsExpression struct { // Type determines the type of the expression. It must be one of the supported types. + // Allowed values are "policy/v1", "username/v1", or "groups/v1". // +kubebuilder:validation:Enum=policy/v1;username/v1;groups/v1 Type string `json:"type"` diff --git a/generated/1.29/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go b/generated/1.29/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go index c84f46dbd..437974778 100644 --- a/generated/1.29/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go +++ b/generated/1.29/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go @@ -167,7 +167,10 @@ type GitHubClientSpec struct { } type GitHubOrganizationsSpec struct { - // Policy must be set to "AllGitHubUsers" if allowed is empty. + // Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + // Defaults to "OnlyUsersFromAllowedOrganizations". + // + // Must be set to "AllGitHubUsers" if the allowed field is empty. // // This field only exists to ensure that Pinniped administrators are aware that an empty list of // allowedOrganizations means all GitHub users are allowed to log in. diff --git a/generated/1.29/apis/supervisor/idp/v1alpha1/types_tls.go b/generated/1.29/apis/supervisor/idp/v1alpha1/types_tls.go index 407a5cde5..70f1c71cc 100644 --- a/generated/1.29/apis/supervisor/idp/v1alpha1/types_tls.go +++ b/generated/1.29/apis/supervisor/idp/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.29/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml b/generated/1.29/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml index 838f11edf..5366768a8 100644 --- a/generated/1.29/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml +++ b/generated/1.29/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml @@ -111,6 +111,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.29/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml b/generated/1.29/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml index 0133d62fc..3f4f32dc9 100644 --- a/generated/1.29/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml +++ b/generated/1.29/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml @@ -82,6 +82,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.29/crds/config.supervisor.pinniped.dev_federationdomains.yaml b/generated/1.29/crds/config.supervisor.pinniped.dev_federationdomains.yaml index d43c7406d..b7390da91 100644 --- a/generated/1.29/crds/config.supervisor.pinniped.dev_federationdomains.yaml +++ b/generated/1.29/crds/config.supervisor.pinniped.dev_federationdomains.yaml @@ -143,8 +143,9 @@ spec: Type is "string", and is otherwise ignored. type: string type: - description: Type determines the type of the constant, - and indicates which other field should be non-empty. + description: |- + Type determines the type of the constant, and indicates which other field should be non-empty. + Allowed values are "string" or "stringList". enum: - string - stringList @@ -262,8 +263,9 @@ spec: an authentication attempt. When empty, a default message will be used. type: string type: - description: Type determines the type of the expression. - It must be one of the supported types. + description: |- + Type determines the type of the expression. It must be one of the supported types. + Allowed values are "policy/v1", "username/v1", or "groups/v1". enum: - policy/v1 - username/v1 diff --git a/generated/1.29/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml b/generated/1.29/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml index dcc1836b6..9a5ec7c90 100644 --- a/generated/1.29/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml +++ b/generated/1.29/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml @@ -186,6 +186,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.29/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml b/generated/1.29/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml index 669377e7c..4cf2b9bca 100644 --- a/generated/1.29/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml +++ b/generated/1.29/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml @@ -89,7 +89,11 @@ spec: policy: default: OnlyUsersFromAllowedOrganizations description: |- - Policy must be set to "AllGitHubUsers" if allowed is empty. + Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + Defaults to "OnlyUsersFromAllowedOrganizations". + + + Must be set to "AllGitHubUsers" if the allowed field is empty. This field only exists to ensure that Pinniped administrators are aware that an empty list of @@ -241,6 +245,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.29/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml b/generated/1.29/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml index e1fb91934..08b616aed 100644 --- a/generated/1.29/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml +++ b/generated/1.29/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml @@ -177,6 +177,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.29/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml b/generated/1.29/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml index 83ae89781..75efc06fc 100644 --- a/generated/1.29/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml +++ b/generated/1.29/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml @@ -227,6 +227,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.30/README.adoc b/generated/1.30/README.adoc index 0b9021c99..23ad2e25b 100644 --- a/generated/1.30/README.adoc +++ b/generated/1.30/README.adoc @@ -38,6 +38,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Concierge is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -528,6 +529,7 @@ ImpersonationProxyInfo describes the parameters for the impersonation proxy on t ==== ImpersonationProxyMode (string) ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +Allowed values are "auto", "enabled", or "disabled". .Appears In: **** @@ -564,6 +566,7 @@ This is not supported on all cloud providers. + ==== ImpersonationProxyServiceType (string) ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +Allowed values are "LoadBalancer", "ClusterIP", or "None". .Appears In: **** @@ -953,6 +956,7 @@ the transform expressions. This is a union type, and Type is the discriminator f | Field | Description | *`name`* __string__ | Name determines the name of the constant. It must be a valid identifier name. + | *`type`* __string__ | Type determines the type of the constant, and indicates which other field should be non-empty. + +Allowed values are "string" or "stringList". + | *`stringValue`* __string__ | StringValue should hold the value when Type is "string", and is otherwise ignored. + | *`stringListValue`* __string array__ | StringListValue should hold the value when Type is "stringList", and is otherwise ignored. + |=== @@ -1019,6 +1023,7 @@ FederationDomainTransformsExpression defines a transform expression. |=== | Field | Description | *`type`* __string__ | Type determines the type of the expression. It must be one of the supported types. + +Allowed values are "policy/v1", "username/v1", or "groups/v1". + | *`expression`* __string__ | Expression is a CEL expression that will be evaluated based on the Type during an authentication. + | *`message`* __string__ | Message is only used when Type is policy/v1. It defines an error message to be used when the policy rejects + an authentication attempt. When empty, a default message will be used. + @@ -1685,6 +1690,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Supervisor is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -1938,7 +1944,11 @@ GitHubIdentityProviderStatus is the status of an GitHub identity provider. [cols="25a,75a", options="header"] |=== | Field | Description -| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-30-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Policy must be set to "AllGitHubUsers" if allowed is empty. + +| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-30-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + +Defaults to "OnlyUsersFromAllowedOrganizations". + + + +Must be set to "AllGitHubUsers" if the allowed field is empty. + This field only exists to ensure that Pinniped administrators are aware that an empty list of + diff --git a/generated/1.30/apis/concierge/authentication/v1alpha1/types_tls.go b/generated/1.30/apis/concierge/authentication/v1alpha1/types_tls.go index 883dc7fc7..db9f4ceff 100644 --- a/generated/1.30/apis/concierge/authentication/v1alpha1/types_tls.go +++ b/generated/1.30/apis/concierge/authentication/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.30/apis/concierge/config/v1alpha1/types_credentialissuer.go b/generated/1.30/apis/concierge/config/v1alpha1/types_credentialissuer.go index 0ee0f0dbf..de976f5c1 100644 --- a/generated/1.30/apis/concierge/config/v1alpha1/types_credentialissuer.go +++ b/generated/1.30/apis/concierge/config/v1alpha1/types_credentialissuer.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -49,6 +49,7 @@ type CredentialIssuerSpec struct { } // ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +// Allowed values are "auto", "enabled", or "disabled". // // +kubebuilder:validation:Enum=auto;enabled;disabled type ImpersonationProxyMode string @@ -65,6 +66,7 @@ const ( ) // ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +// Allowed values are "LoadBalancer", "ClusterIP", or "None". // // +kubebuilder:validation:Enum=LoadBalancer;ClusterIP;None type ImpersonationProxyServiceType string diff --git a/generated/1.30/apis/supervisor/config/v1alpha1/types_federationdomain.go b/generated/1.30/apis/supervisor/config/v1alpha1/types_federationdomain.go index 95f7da282..d1a6e6278 100644 --- a/generated/1.30/apis/supervisor/config/v1alpha1/types_federationdomain.go +++ b/generated/1.30/apis/supervisor/config/v1alpha1/types_federationdomain.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -55,6 +55,7 @@ type FederationDomainTransformsConstant struct { Name string `json:"name"` // Type determines the type of the constant, and indicates which other field should be non-empty. + // Allowed values are "string" or "stringList". // +kubebuilder:validation:Enum=string;stringList Type string `json:"type"` @@ -70,6 +71,7 @@ type FederationDomainTransformsConstant struct { // FederationDomainTransformsExpression defines a transform expression. type FederationDomainTransformsExpression struct { // Type determines the type of the expression. It must be one of the supported types. + // Allowed values are "policy/v1", "username/v1", or "groups/v1". // +kubebuilder:validation:Enum=policy/v1;username/v1;groups/v1 Type string `json:"type"` diff --git a/generated/1.30/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go b/generated/1.30/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go index c84f46dbd..437974778 100644 --- a/generated/1.30/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go +++ b/generated/1.30/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go @@ -167,7 +167,10 @@ type GitHubClientSpec struct { } type GitHubOrganizationsSpec struct { - // Policy must be set to "AllGitHubUsers" if allowed is empty. + // Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + // Defaults to "OnlyUsersFromAllowedOrganizations". + // + // Must be set to "AllGitHubUsers" if the allowed field is empty. // // This field only exists to ensure that Pinniped administrators are aware that an empty list of // allowedOrganizations means all GitHub users are allowed to log in. diff --git a/generated/1.30/apis/supervisor/idp/v1alpha1/types_tls.go b/generated/1.30/apis/supervisor/idp/v1alpha1/types_tls.go index 407a5cde5..70f1c71cc 100644 --- a/generated/1.30/apis/supervisor/idp/v1alpha1/types_tls.go +++ b/generated/1.30/apis/supervisor/idp/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/1.30/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml b/generated/1.30/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml index 838f11edf..5366768a8 100644 --- a/generated/1.30/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml +++ b/generated/1.30/crds/authentication.concierge.pinniped.dev_jwtauthenticators.yaml @@ -111,6 +111,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.30/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml b/generated/1.30/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml index 0133d62fc..3f4f32dc9 100644 --- a/generated/1.30/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml +++ b/generated/1.30/crds/authentication.concierge.pinniped.dev_webhookauthenticators.yaml @@ -82,6 +82,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.30/crds/config.supervisor.pinniped.dev_federationdomains.yaml b/generated/1.30/crds/config.supervisor.pinniped.dev_federationdomains.yaml index 033513431..678263520 100644 --- a/generated/1.30/crds/config.supervisor.pinniped.dev_federationdomains.yaml +++ b/generated/1.30/crds/config.supervisor.pinniped.dev_federationdomains.yaml @@ -143,8 +143,9 @@ spec: Type is "string", and is otherwise ignored. type: string type: - description: Type determines the type of the constant, - and indicates which other field should be non-empty. + description: |- + Type determines the type of the constant, and indicates which other field should be non-empty. + Allowed values are "string" or "stringList". enum: - string - stringList @@ -262,8 +263,9 @@ spec: an authentication attempt. When empty, a default message will be used. type: string type: - description: Type determines the type of the expression. - It must be one of the supported types. + description: |- + Type determines the type of the expression. It must be one of the supported types. + Allowed values are "policy/v1", "username/v1", or "groups/v1". enum: - policy/v1 - username/v1 diff --git a/generated/1.30/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml b/generated/1.30/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml index dcc1836b6..9a5ec7c90 100644 --- a/generated/1.30/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml +++ b/generated/1.30/crds/idp.supervisor.pinniped.dev_activedirectoryidentityproviders.yaml @@ -186,6 +186,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.30/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml b/generated/1.30/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml index 669377e7c..4cf2b9bca 100644 --- a/generated/1.30/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml +++ b/generated/1.30/crds/idp.supervisor.pinniped.dev_githubidentityproviders.yaml @@ -89,7 +89,11 @@ spec: policy: default: OnlyUsersFromAllowedOrganizations description: |- - Policy must be set to "AllGitHubUsers" if allowed is empty. + Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + Defaults to "OnlyUsersFromAllowedOrganizations". + + + Must be set to "AllGitHubUsers" if the allowed field is empty. This field only exists to ensure that Pinniped administrators are aware that an empty list of @@ -241,6 +245,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.30/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml b/generated/1.30/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml index e1fb91934..08b616aed 100644 --- a/generated/1.30/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml +++ b/generated/1.30/crds/idp.supervisor.pinniped.dev_ldapidentityproviders.yaml @@ -177,6 +177,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/1.30/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml b/generated/1.30/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml index 83ae89781..75efc06fc 100644 --- a/generated/1.30/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml +++ b/generated/1.30/crds/idp.supervisor.pinniped.dev_oidcidentityproviders.yaml @@ -227,6 +227,7 @@ spec: description: |- Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. Secrets must be of type kubernetes.io/tls or Opaque. + Allowed values are "Secret" or "ConfigMap". enum: - Secret - ConfigMap diff --git a/generated/latest/README.adoc b/generated/latest/README.adoc index 0b9021c99..23ad2e25b 100644 --- a/generated/latest/README.adoc +++ b/generated/latest/README.adoc @@ -38,6 +38,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Concierge is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -528,6 +529,7 @@ ImpersonationProxyInfo describes the parameters for the impersonation proxy on t ==== ImpersonationProxyMode (string) ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +Allowed values are "auto", "enabled", or "disabled". .Appears In: **** @@ -564,6 +566,7 @@ This is not supported on all cloud providers. + ==== ImpersonationProxyServiceType (string) ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +Allowed values are "LoadBalancer", "ClusterIP", or "None". .Appears In: **** @@ -953,6 +956,7 @@ the transform expressions. This is a union type, and Type is the discriminator f | Field | Description | *`name`* __string__ | Name determines the name of the constant. It must be a valid identifier name. + | *`type`* __string__ | Type determines the type of the constant, and indicates which other field should be non-empty. + +Allowed values are "string" or "stringList". + | *`stringValue`* __string__ | StringValue should hold the value when Type is "string", and is otherwise ignored. + | *`stringListValue`* __string array__ | StringListValue should hold the value when Type is "stringList", and is otherwise ignored. + |=== @@ -1019,6 +1023,7 @@ FederationDomainTransformsExpression defines a transform expression. |=== | Field | Description | *`type`* __string__ | Type determines the type of the expression. It must be one of the supported types. + +Allowed values are "policy/v1", "username/v1", or "groups/v1". + | *`expression`* __string__ | Expression is a CEL expression that will be evaluated based on the Type during an authentication. + | *`message`* __string__ | Message is only used when Type is policy/v1. It defines an error message to be used when the policy rejects + an authentication attempt. When empty, a default message will be used. + @@ -1685,6 +1690,7 @@ CertificateAuthorityDataSourceSpec provides a source for CA bundle used for clie | Field | Description | *`kind`* __string__ | Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. + Secrets must be of type kubernetes.io/tls or Opaque. + +Allowed values are "Secret" or "ConfigMap". + | *`name`* __string__ | Name is the resource name of the secret or configmap from which to read the CA bundle. + The referenced secret or configmap must be created in the same namespace where Pinniped Supervisor is installed. + | *`key`* __string__ | Key is the key name within the secret or configmap from which to read the CA bundle. + @@ -1938,7 +1944,11 @@ GitHubIdentityProviderStatus is the status of an GitHub identity provider. [cols="25a,75a", options="header"] |=== | Field | Description -| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-30-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Policy must be set to "AllGitHubUsers" if allowed is empty. + +| *`policy`* __xref:{anchor_prefix}-go-pinniped-dev-generated-1-30-apis-supervisor-idp-v1alpha1-githuballowedauthorganizationspolicy[$$GitHubAllowedAuthOrganizationsPolicy$$]__ | Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + +Defaults to "OnlyUsersFromAllowedOrganizations". + + + +Must be set to "AllGitHubUsers" if the allowed field is empty. + This field only exists to ensure that Pinniped administrators are aware that an empty list of + diff --git a/generated/latest/apis/concierge/authentication/v1alpha1/types_tls.go b/generated/latest/apis/concierge/authentication/v1alpha1/types_tls.go index 883dc7fc7..db9f4ceff 100644 --- a/generated/latest/apis/concierge/authentication/v1alpha1/types_tls.go +++ b/generated/latest/apis/concierge/authentication/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle. diff --git a/generated/latest/apis/concierge/config/v1alpha1/types_credentialissuer.go b/generated/latest/apis/concierge/config/v1alpha1/types_credentialissuer.go index 0ee0f0dbf..de976f5c1 100644 --- a/generated/latest/apis/concierge/config/v1alpha1/types_credentialissuer.go +++ b/generated/latest/apis/concierge/config/v1alpha1/types_credentialissuer.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -49,6 +49,7 @@ type CredentialIssuerSpec struct { } // ImpersonationProxyMode enumerates the configuration modes for the impersonation proxy. +// Allowed values are "auto", "enabled", or "disabled". // // +kubebuilder:validation:Enum=auto;enabled;disabled type ImpersonationProxyMode string @@ -65,6 +66,7 @@ const ( ) // ImpersonationProxyServiceType enumerates the types of service that can be provisioned for the impersonation proxy. +// Allowed values are "LoadBalancer", "ClusterIP", or "None". // // +kubebuilder:validation:Enum=LoadBalancer;ClusterIP;None type ImpersonationProxyServiceType string diff --git a/generated/latest/apis/supervisor/config/v1alpha1/types_federationdomain.go b/generated/latest/apis/supervisor/config/v1alpha1/types_federationdomain.go index 95f7da282..d1a6e6278 100644 --- a/generated/latest/apis/supervisor/config/v1alpha1/types_federationdomain.go +++ b/generated/latest/apis/supervisor/config/v1alpha1/types_federationdomain.go @@ -1,4 +1,4 @@ -// Copyright 2020-2023 the Pinniped contributors. All Rights Reserved. +// Copyright 2020-2024 the Pinniped contributors. All Rights Reserved. // SPDX-License-Identifier: Apache-2.0 package v1alpha1 @@ -55,6 +55,7 @@ type FederationDomainTransformsConstant struct { Name string `json:"name"` // Type determines the type of the constant, and indicates which other field should be non-empty. + // Allowed values are "string" or "stringList". // +kubebuilder:validation:Enum=string;stringList Type string `json:"type"` @@ -70,6 +71,7 @@ type FederationDomainTransformsConstant struct { // FederationDomainTransformsExpression defines a transform expression. type FederationDomainTransformsExpression struct { // Type determines the type of the expression. It must be one of the supported types. + // Allowed values are "policy/v1", "username/v1", or "groups/v1". // +kubebuilder:validation:Enum=policy/v1;username/v1;groups/v1 Type string `json:"type"` diff --git a/generated/latest/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go b/generated/latest/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go index c84f46dbd..437974778 100644 --- a/generated/latest/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go +++ b/generated/latest/apis/supervisor/idp/v1alpha1/types_githubidentityprovider.go @@ -167,7 +167,10 @@ type GitHubClientSpec struct { } type GitHubOrganizationsSpec struct { - // Policy must be set to "AllGitHubUsers" if allowed is empty. + // Allowed values are "OnlyUsersFromAllowedOrganizations" or "AllGitHubUsers". + // Defaults to "OnlyUsersFromAllowedOrganizations". + // + // Must be set to "AllGitHubUsers" if the allowed field is empty. // // This field only exists to ensure that Pinniped administrators are aware that an empty list of // allowedOrganizations means all GitHub users are allowed to log in. diff --git a/generated/latest/apis/supervisor/idp/v1alpha1/types_tls.go b/generated/latest/apis/supervisor/idp/v1alpha1/types_tls.go index 407a5cde5..70f1c71cc 100644 --- a/generated/latest/apis/supervisor/idp/v1alpha1/types_tls.go +++ b/generated/latest/apis/supervisor/idp/v1alpha1/types_tls.go @@ -7,6 +7,7 @@ package v1alpha1 type CertificateAuthorityDataSourceSpec struct { // Kind configures whether the CA bundle is being sourced from a Kubernetes secret or a configmap. // Secrets must be of type kubernetes.io/tls or Opaque. + // Allowed values are "Secret" or "ConfigMap". // +kubebuilder:validation:Enum=Secret;ConfigMap Kind string `json:"kind"` // Name is the resource name of the secret or configmap from which to read the CA bundle.