Files

6702 lines
287 KiB
YAML

swagger: '2.0'
info:
title: Kubernetes
version: v1.27.5+k3s1
paths:
/apis/management.cattle.io/v3/clusterroletemplatebindings:
get:
description: list objects of kind ClusterRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3ClusterRoleTemplateBindingForAllNamespaces
responses:
'200':
description: OK
schema:
$ref: >-
#/definitions/io.cattle.management.v3.ClusterRoleTemplateBindingList
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration (generally
five to fifteen minutes) or a configuration change on the server, the
server will respond with a 410 ResourceExpired error together with a
continue token. If the client needs a consistent list, it must restart
their list without the continue field. Otherwise, the client may send
another list request with the token received with the 410 error, the
server will respond with a list starting from the next key, but from
the latest snapshot, which is inconsistent from the previous list
results - objects that are created, modified, or deleted after the
first list request will be included in the response, as long as their
keys are after the "next key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the list
metadata to a value that can be used with the same initial query to
retrieve the next set of results. Setting a limit may return fewer
than the requested amount of items (up to zero items) in the event all
requested objects are filtered out and clients should only use the
presence of the continue field to determine whether more results are
available. Servers may choose not to support the limit argument and
will return all of the available results. If limit is specified and
the continue field is empty, clients may assume that no more results
are available. This field is not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit - that
is, no objects created, modified, or deleted after the first request
is issued will be included in any subsequent continued requests. This
is sometimes referred to as a consistent snapshot, and ensures that a
client that is using limit to receive smaller chunks of a very large
result can ensure they see all possible objects. If objects are
updated during a chunked list the version of the object that was
present at the time the first list result was calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a request
may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to list
calls. It is highly recommended that resourceVersionMatch be set for
list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all such
events have been sent, a synthetic "Bookmark" event will be sent. The
bookmark will report the ResourceVersion (RV) corresponding to the set
of objects, and be marked with `"k8s.io/initial-events-end": "true"`
annotation. Afterwards, the watch stream will proceed as usual,
sending watch events corresponding to changes (subsequent to the RV)
to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` = NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"` (for
backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the call,
regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
/apis/management.cattle.io/v3/globalrolebindings:
get:
description: list objects of kind GlobalRoleBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3GlobalRoleBinding
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBindingList'
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRoleBinding
version: v3
post:
description: create a GlobalRoleBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: createManagementCattleIoV3GlobalRoleBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
'401':
description: Unauthorized
x-kubernetes-action: post
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRoleBinding
version: v3
delete:
description: delete collection of GlobalRoleBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3CollectionGlobalRoleBinding
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: deletecollection
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRoleBinding
version: v3
parameters:
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/globalrolebindings/{name}:
get:
description: read the specified GlobalRoleBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: readManagementCattleIoV3GlobalRoleBinding
parameters:
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
'401':
description: Unauthorized
x-kubernetes-action: get
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRoleBinding
version: v3
put:
description: replace the specified GlobalRoleBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: replaceManagementCattleIoV3GlobalRoleBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
'401':
description: Unauthorized
x-kubernetes-action: put
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRoleBinding
version: v3
delete:
description: delete a GlobalRoleBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3GlobalRoleBinding
parameters:
- name: body
in: body
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: integer
description: >-
The duration in seconds before the object should be deleted. Value
must be non-negative integer. The value zero indicates delete
immediately. If this value is nil, the default grace period for the
specified type will be used. Defaults to a per object value if not
specified. zero means delete immediately.
name: gracePeriodSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Deprecated: please use the PropagationPolicy, this field will be
deprecated in 1.7. Should the dependent objects be orphaned. If
true/false, the "orphan" finalizer will be added to/removed from the
object's finalizers list. Either this field or PropagationPolicy may
be set, but not both.
name: orphanDependents
in: query
- uniqueItems: true
type: string
description: >-
Whether and how garbage collection will be performed. Either this
field or OrphanDependents may be set, but not both. The default
policy is decided by the existing finalizer set in the
metadata.finalizers and the resource-specific default policy.
Acceptable values are: 'Orphan' - orphan the dependents;
'Background' - allow the garbage collector to delete the dependents
in the background; 'Foreground' - a cascading policy that deletes
all dependents in the foreground.
name: propagationPolicy
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: delete
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRoleBinding
version: v3
patch:
description: partially update the specified GlobalRoleBinding
consumes:
- application/json-patch+json
- application/merge-patch+json
- application/apply-patch+yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: patchManagementCattleIoV3GlobalRoleBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint. This field is required for
apply requests (application/apply-patch) but optional for non-apply
patch types (JsonPatch, MergePatch, StrategicMergePatch).
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
- uniqueItems: true
type: boolean
description: >-
Force is going to "force" Apply requests. It means user will
re-acquire conflicting fields owned by other people. Force flag must
be unset for non-apply patch requests.
name: force
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
'401':
description: Unauthorized
x-kubernetes-action: patch
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRoleBinding
version: v3
parameters:
- uniqueItems: true
type: string
description: name of the GlobalRoleBinding
name: name
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/globalroles:
get:
description: list objects of kind GlobalRole
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3GlobalRole
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleList'
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRole
version: v3
post:
description: create a GlobalRole
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: createManagementCattleIoV3GlobalRole
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
'401':
description: Unauthorized
x-kubernetes-action: post
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRole
version: v3
delete:
description: delete collection of GlobalRole
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3CollectionGlobalRole
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: deletecollection
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRole
version: v3
parameters:
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/globalroles/{name}:
get:
description: read the specified GlobalRole
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: readManagementCattleIoV3GlobalRole
parameters:
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
'401':
description: Unauthorized
x-kubernetes-action: get
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRole
version: v3
put:
description: replace the specified GlobalRole
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: replaceManagementCattleIoV3GlobalRole
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
'401':
description: Unauthorized
x-kubernetes-action: put
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRole
version: v3
delete:
description: delete a GlobalRole
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3GlobalRole
parameters:
- name: body
in: body
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: integer
description: >-
The duration in seconds before the object should be deleted. Value
must be non-negative integer. The value zero indicates delete
immediately. If this value is nil, the default grace period for the
specified type will be used. Defaults to a per object value if not
specified. zero means delete immediately.
name: gracePeriodSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Deprecated: please use the PropagationPolicy, this field will be
deprecated in 1.7. Should the dependent objects be orphaned. If
true/false, the "orphan" finalizer will be added to/removed from the
object's finalizers list. Either this field or PropagationPolicy may
be set, but not both.
name: orphanDependents
in: query
- uniqueItems: true
type: string
description: >-
Whether and how garbage collection will be performed. Either this
field or OrphanDependents may be set, but not both. The default
policy is decided by the existing finalizer set in the
metadata.finalizers and the resource-specific default policy.
Acceptable values are: 'Orphan' - orphan the dependents;
'Background' - allow the garbage collector to delete the dependents
in the background; 'Foreground' - a cascading policy that deletes
all dependents in the foreground.
name: propagationPolicy
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: delete
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRole
version: v3
patch:
description: partially update the specified GlobalRole
consumes:
- application/json-patch+json
- application/merge-patch+json
- application/apply-patch+yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: patchManagementCattleIoV3GlobalRole
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint. This field is required for
apply requests (application/apply-patch) but optional for non-apply
patch types (JsonPatch, MergePatch, StrategicMergePatch).
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
- uniqueItems: true
type: boolean
description: >-
Force is going to "force" Apply requests. It means user will
re-acquire conflicting fields owned by other people. Force flag must
be unset for non-apply patch requests.
name: force
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
'401':
description: Unauthorized
x-kubernetes-action: patch
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: GlobalRole
version: v3
parameters:
- uniqueItems: true
type: string
description: name of the GlobalRole
name: name
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/namespaces/{namespace}/clusterroletemplatebindings:
get:
description: list objects of kind ClusterRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3NamespacedClusterRoleTemplateBinding
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: >-
#/definitions/io.cattle.management.v3.ClusterRoleTemplateBindingList
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
post:
description: create a ClusterRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: createManagementCattleIoV3NamespacedClusterRoleTemplateBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
'401':
description: Unauthorized
x-kubernetes-action: post
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
delete:
description: delete collection of ClusterRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3CollectionNamespacedClusterRoleTemplateBinding
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: deletecollection
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
parameters:
- uniqueItems: true
type: string
description: object name and auth scope, such as for teams and projects
name: namespace
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/namespaces/{namespace}/clusterroletemplatebindings/{name}:
get:
description: read the specified ClusterRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: readManagementCattleIoV3NamespacedClusterRoleTemplateBinding
parameters:
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
'401':
description: Unauthorized
x-kubernetes-action: get
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
put:
description: replace the specified ClusterRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: replaceManagementCattleIoV3NamespacedClusterRoleTemplateBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
'401':
description: Unauthorized
x-kubernetes-action: put
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
delete:
description: delete a ClusterRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3NamespacedClusterRoleTemplateBinding
parameters:
- name: body
in: body
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: integer
description: >-
The duration in seconds before the object should be deleted. Value
must be non-negative integer. The value zero indicates delete
immediately. If this value is nil, the default grace period for the
specified type will be used. Defaults to a per object value if not
specified. zero means delete immediately.
name: gracePeriodSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Deprecated: please use the PropagationPolicy, this field will be
deprecated in 1.7. Should the dependent objects be orphaned. If
true/false, the "orphan" finalizer will be added to/removed from the
object's finalizers list. Either this field or PropagationPolicy may
be set, but not both.
name: orphanDependents
in: query
- uniqueItems: true
type: string
description: >-
Whether and how garbage collection will be performed. Either this
field or OrphanDependents may be set, but not both. The default
policy is decided by the existing finalizer set in the
metadata.finalizers and the resource-specific default policy.
Acceptable values are: 'Orphan' - orphan the dependents;
'Background' - allow the garbage collector to delete the dependents
in the background; 'Foreground' - a cascading policy that deletes
all dependents in the foreground.
name: propagationPolicy
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: delete
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
patch:
description: partially update the specified ClusterRoleTemplateBinding
consumes:
- application/json-patch+json
- application/merge-patch+json
- application/apply-patch+yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: patchManagementCattleIoV3NamespacedClusterRoleTemplateBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint. This field is required for
apply requests (application/apply-patch) but optional for non-apply
patch types (JsonPatch, MergePatch, StrategicMergePatch).
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
- uniqueItems: true
type: boolean
description: >-
Force is going to "force" Apply requests. It means user will
re-acquire conflicting fields owned by other people. Force flag must
be unset for non-apply patch requests.
name: force
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
'401':
description: Unauthorized
x-kubernetes-action: patch
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
parameters:
- uniqueItems: true
type: string
description: name of the ClusterRoleTemplateBinding
name: name
in: path
required: true
- uniqueItems: true
type: string
description: object name and auth scope, such as for teams and projects
name: namespace
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/namespaces/{namespace}/projectroletemplatebindings:
get:
description: list objects of kind ProjectRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3NamespacedProjectRoleTemplateBinding
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: >-
#/definitions/io.cattle.management.v3.ProjectRoleTemplateBindingList
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
post:
description: create a ProjectRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: createManagementCattleIoV3NamespacedProjectRoleTemplateBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
'401':
description: Unauthorized
x-kubernetes-action: post
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
delete:
description: delete collection of ProjectRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3CollectionNamespacedProjectRoleTemplateBinding
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: deletecollection
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
parameters:
- uniqueItems: true
type: string
description: object name and auth scope, such as for teams and projects
name: namespace
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/namespaces/{namespace}/projectroletemplatebindings/{name}:
get:
description: read the specified ProjectRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: readManagementCattleIoV3NamespacedProjectRoleTemplateBinding
parameters:
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
'401':
description: Unauthorized
x-kubernetes-action: get
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
put:
description: replace the specified ProjectRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: replaceManagementCattleIoV3NamespacedProjectRoleTemplateBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
'401':
description: Unauthorized
x-kubernetes-action: put
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
delete:
description: delete a ProjectRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3NamespacedProjectRoleTemplateBinding
parameters:
- name: body
in: body
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: integer
description: >-
The duration in seconds before the object should be deleted. Value
must be non-negative integer. The value zero indicates delete
immediately. If this value is nil, the default grace period for the
specified type will be used. Defaults to a per object value if not
specified. zero means delete immediately.
name: gracePeriodSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Deprecated: please use the PropagationPolicy, this field will be
deprecated in 1.7. Should the dependent objects be orphaned. If
true/false, the "orphan" finalizer will be added to/removed from the
object's finalizers list. Either this field or PropagationPolicy may
be set, but not both.
name: orphanDependents
in: query
- uniqueItems: true
type: string
description: >-
Whether and how garbage collection will be performed. Either this
field or OrphanDependents may be set, but not both. The default
policy is decided by the existing finalizer set in the
metadata.finalizers and the resource-specific default policy.
Acceptable values are: 'Orphan' - orphan the dependents;
'Background' - allow the garbage collector to delete the dependents
in the background; 'Foreground' - a cascading policy that deletes
all dependents in the foreground.
name: propagationPolicy
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: delete
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
patch:
description: partially update the specified ProjectRoleTemplateBinding
consumes:
- application/json-patch+json
- application/merge-patch+json
- application/apply-patch+yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: patchManagementCattleIoV3NamespacedProjectRoleTemplateBinding
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint. This field is required for
apply requests (application/apply-patch) but optional for non-apply
patch types (JsonPatch, MergePatch, StrategicMergePatch).
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
- uniqueItems: true
type: boolean
description: >-
Force is going to "force" Apply requests. It means user will
re-acquire conflicting fields owned by other people. Force flag must
be unset for non-apply patch requests.
name: force
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
'401':
description: Unauthorized
x-kubernetes-action: patch
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
parameters:
- uniqueItems: true
type: string
description: name of the ProjectRoleTemplateBinding
name: name
in: path
required: true
- uniqueItems: true
type: string
description: object name and auth scope, such as for teams and projects
name: namespace
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/namespaces/{namespace}/projects:
get:
description: list objects of kind Project
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3NamespacedProject
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectList'
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: Project
version: v3
post:
description: create a Project
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: createManagementCattleIoV3NamespacedProject
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
'401':
description: Unauthorized
x-kubernetes-action: post
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: Project
version: v3
delete:
description: delete collection of Project
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3CollectionNamespacedProject
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: deletecollection
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: Project
version: v3
parameters:
- uniqueItems: true
type: string
description: object name and auth scope, such as for teams and projects
name: namespace
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/namespaces/{namespace}/projects/{name}:
get:
description: read the specified Project
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: readManagementCattleIoV3NamespacedProject
parameters:
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
'401':
description: Unauthorized
x-kubernetes-action: get
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: Project
version: v3
put:
description: replace the specified Project
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: replaceManagementCattleIoV3NamespacedProject
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
'401':
description: Unauthorized
x-kubernetes-action: put
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: Project
version: v3
delete:
description: delete a Project
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3NamespacedProject
parameters:
- name: body
in: body
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: integer
description: >-
The duration in seconds before the object should be deleted. Value
must be non-negative integer. The value zero indicates delete
immediately. If this value is nil, the default grace period for the
specified type will be used. Defaults to a per object value if not
specified. zero means delete immediately.
name: gracePeriodSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Deprecated: please use the PropagationPolicy, this field will be
deprecated in 1.7. Should the dependent objects be orphaned. If
true/false, the "orphan" finalizer will be added to/removed from the
object's finalizers list. Either this field or PropagationPolicy may
be set, but not both.
name: orphanDependents
in: query
- uniqueItems: true
type: string
description: >-
Whether and how garbage collection will be performed. Either this
field or OrphanDependents may be set, but not both. The default
policy is decided by the existing finalizer set in the
metadata.finalizers and the resource-specific default policy.
Acceptable values are: 'Orphan' - orphan the dependents;
'Background' - allow the garbage collector to delete the dependents
in the background; 'Foreground' - a cascading policy that deletes
all dependents in the foreground.
name: propagationPolicy
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: delete
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: Project
version: v3
patch:
description: partially update the specified Project
consumes:
- application/json-patch+json
- application/merge-patch+json
- application/apply-patch+yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: patchManagementCattleIoV3NamespacedProject
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint. This field is required for
apply requests (application/apply-patch) but optional for non-apply
patch types (JsonPatch, MergePatch, StrategicMergePatch).
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
- uniqueItems: true
type: boolean
description: >-
Force is going to "force" Apply requests. It means user will
re-acquire conflicting fields owned by other people. Force flag must
be unset for non-apply patch requests.
name: force
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.Project'
'401':
description: Unauthorized
x-kubernetes-action: patch
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: Project
version: v3
parameters:
- uniqueItems: true
type: string
description: name of the Project
name: name
in: path
required: true
- uniqueItems: true
type: string
description: object name and auth scope, such as for teams and projects
name: namespace
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/projectroletemplatebindings:
get:
description: list objects of kind ProjectRoleTemplateBinding
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3ProjectRoleTemplateBindingForAllNamespaces
responses:
'200':
description: OK
schema:
$ref: >-
#/definitions/io.cattle.management.v3.ProjectRoleTemplateBindingList
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration (generally
five to fifteen minutes) or a configuration change on the server, the
server will respond with a 410 ResourceExpired error together with a
continue token. If the client needs a consistent list, it must restart
their list without the continue field. Otherwise, the client may send
another list request with the token received with the 410 error, the
server will respond with a list starting from the next key, but from
the latest snapshot, which is inconsistent from the previous list
results - objects that are created, modified, or deleted after the
first list request will be included in the response, as long as their
keys are after the "next key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the list
metadata to a value that can be used with the same initial query to
retrieve the next set of results. Setting a limit may return fewer
than the requested amount of items (up to zero items) in the event all
requested objects are filtered out and clients should only use the
presence of the continue field to determine whether more results are
available. Servers may choose not to support the limit argument and
will return all of the available results. If limit is specified and
the continue field is empty, clients may assume that no more results
are available. This field is not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit - that
is, no objects created, modified, or deleted after the first request
is issued will be included in any subsequent continued requests. This
is sometimes referred to as a consistent snapshot, and ensures that a
client that is using limit to receive smaller chunks of a very large
result can ensure they see all possible objects. If objects are
updated during a chunked list the version of the object that was
present at the time the first list result was calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a request
may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to list
calls. It is highly recommended that resourceVersionMatch be set for
list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all such
events have been sent, a synthetic "Bookmark" event will be sent. The
bookmark will report the ResourceVersion (RV) corresponding to the set
of objects, and be marked with `"k8s.io/initial-events-end": "true"`
annotation. Afterwards, the watch stream will proceed as usual,
sending watch events corresponding to changes (subsequent to the RV)
to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` = NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"` (for
backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the call,
regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
/apis/management.cattle.io/v3/projects:
get:
description: list objects of kind Project
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3ProjectForAllNamespaces
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.ProjectList'
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: Project
version: v3
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration (generally
five to fifteen minutes) or a configuration change on the server, the
server will respond with a 410 ResourceExpired error together with a
continue token. If the client needs a consistent list, it must restart
their list without the continue field. Otherwise, the client may send
another list request with the token received with the 410 error, the
server will respond with a list starting from the next key, but from
the latest snapshot, which is inconsistent from the previous list
results - objects that are created, modified, or deleted after the
first list request will be included in the response, as long as their
keys are after the "next key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the list
metadata to a value that can be used with the same initial query to
retrieve the next set of results. Setting a limit may return fewer
than the requested amount of items (up to zero items) in the event all
requested objects are filtered out and clients should only use the
presence of the continue field to determine whether more results are
available. Servers may choose not to support the limit argument and
will return all of the available results. If limit is specified and
the continue field is empty, clients may assume that no more results
are available. This field is not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit - that
is, no objects created, modified, or deleted after the first request
is issued will be included in any subsequent continued requests. This
is sometimes referred to as a consistent snapshot, and ensures that a
client that is using limit to receive smaller chunks of a very large
result can ensure they see all possible objects. If objects are
updated during a chunked list the version of the object that was
present at the time the first list result was calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a request
may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to list
calls. It is highly recommended that resourceVersionMatch be set for
list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all such
events have been sent, a synthetic "Bookmark" event will be sent. The
bookmark will report the ResourceVersion (RV) corresponding to the set
of objects, and be marked with `"k8s.io/initial-events-end": "true"`
annotation. Afterwards, the watch stream will proceed as usual,
sending watch events corresponding to changes (subsequent to the RV)
to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` = NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"` (for
backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the call,
regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
/apis/management.cattle.io/v3/roletemplates:
get:
description: list objects of kind RoleTemplate
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: listManagementCattleIoV3RoleTemplate
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplateList'
'401':
description: Unauthorized
x-kubernetes-action: list
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: RoleTemplate
version: v3
post:
description: create a RoleTemplate
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: createManagementCattleIoV3RoleTemplate
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
'401':
description: Unauthorized
x-kubernetes-action: post
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: RoleTemplate
version: v3
delete:
description: delete collection of RoleTemplate
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3CollectionRoleTemplate
parameters:
- uniqueItems: true
type: boolean
description: >-
allowWatchBookmarks requests watch events with type "BOOKMARK".
Servers that do not implement bookmarks may ignore this flag and
bookmarks are sent at the server's discretion. Clients should not
assume bookmarks are returned at any specific interval, nor may they
assume the server will send any BOOKMARK event during a session. If
this is not a watch, this field is ignored.
name: allowWatchBookmarks
in: query
- uniqueItems: true
type: string
description: >-
The continue option should be set when retrieving more results from
the server. Since this value is server defined, clients may only use
the continue value from a previous query result with identical query
parameters (except for the value of continue) and the server may
reject a continue value it does not recognize. If the specified
continue value is no longer valid whether due to expiration
(generally five to fifteen minutes) or a configuration change on the
server, the server will respond with a 410 ResourceExpired error
together with a continue token. If the client needs a consistent
list, it must restart their list without the continue field.
Otherwise, the client may send another list request with the token
received with the 410 error, the server will respond with a list
starting from the next key, but from the latest snapshot, which is
inconsistent from the previous list results - objects that are
created, modified, or deleted after the first list request will be
included in the response, as long as their keys are after the "next
key".
This field is not supported when watch is true. Clients may start a
watch from the last resourceVersion value returned by the server and
not miss any modifications.
name: continue
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their fields.
Defaults to everything.
name: fieldSelector
in: query
- uniqueItems: true
type: string
description: >-
A selector to restrict the list of returned objects by their labels.
Defaults to everything.
name: labelSelector
in: query
- uniqueItems: true
type: integer
description: >-
limit is a maximum number of responses to return for a list call. If
more items exist, the server will set the `continue` field on the
list metadata to a value that can be used with the same initial
query to retrieve the next set of results. Setting a limit may
return fewer than the requested amount of items (up to zero items)
in the event all requested objects are filtered out and clients
should only use the presence of the continue field to determine
whether more results are available. Servers may choose not to
support the limit argument and will return all of the available
results. If limit is specified and the continue field is empty,
clients may assume that no more results are available. This field is
not supported if watch is true.
The server guarantees that the objects returned when using continue
will be identical to issuing a single list call without a limit -
that is, no objects created, modified, or deleted after the first
request is issued will be included in any subsequent continued
requests. This is sometimes referred to as a consistent snapshot,
and ensures that a client that is using limit to receive smaller
chunks of a very large result can ensure they see all possible
objects. If objects are updated during a chunked list the version of
the object that was present at the time the first list result was
calculated is returned.
name: limit
in: query
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
- uniqueItems: true
type: string
description: >-
resourceVersionMatch determines how resourceVersion is applied to
list calls. It is highly recommended that resourceVersionMatch be
set for list calls where resourceVersion is set See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersionMatch
in: query
- uniqueItems: true
type: boolean
description: >-
`sendInitialEvents=true` may be set together with `watch=true`. In
that case, the watch stream will begin with synthetic events to
produce the current state of objects in the collection. Once all
such events have been sent, a synthetic "Bookmark" event will be
sent. The bookmark will report the ResourceVersion (RV)
corresponding to the set of objects, and be marked with
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
watch stream will proceed as usual, sending watch events
corresponding to changes (subsequent to the RV) to objects watched.
When `sendInitialEvents` option is set, we require
`resourceVersionMatch` option to also be set. The semantic of the
watch request is as following: - `resourceVersionMatch` =
NotOlderThan
is interpreted as "data at least as new as the provided `resourceVersion`"
and the bookmark event is send when the state is synced
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
bookmark event is send when the state is synced at least to the moment
when request started being processed.
- `resourceVersionMatch` set to any other value or unset
Invalid error is returned.
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
(for backward compatibility reasons) and to false otherwise.
name: sendInitialEvents
in: query
- uniqueItems: true
type: integer
description: >-
Timeout for the list/watch call. This limits the duration of the
call, regardless of any activity or inactivity.
name: timeoutSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Watch for changes to the described resources and return them as a
stream of add, update, and remove notifications. Specify
resourceVersion.
name: watch
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: deletecollection
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: RoleTemplate
version: v3
parameters:
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
/apis/management.cattle.io/v3/roletemplates/{name}:
get:
description: read the specified RoleTemplate
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: readManagementCattleIoV3RoleTemplate
parameters:
- uniqueItems: true
type: string
description: >-
resourceVersion sets a constraint on what resource versions a
request may be served from. See
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
for details.
Defaults to unset
name: resourceVersion
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
'401':
description: Unauthorized
x-kubernetes-action: get
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: RoleTemplate
version: v3
put:
description: replace the specified RoleTemplate
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: replaceManagementCattleIoV3RoleTemplate
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint.
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
'201':
description: Created
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
'401':
description: Unauthorized
x-kubernetes-action: put
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: RoleTemplate
version: v3
delete:
description: delete a RoleTemplate
consumes:
- application/json
- application/yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: deleteManagementCattleIoV3RoleTemplate
parameters:
- name: body
in: body
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: integer
description: >-
The duration in seconds before the object should be deleted. Value
must be non-negative integer. The value zero indicates delete
immediately. If this value is nil, the default grace period for the
specified type will be used. Defaults to a per object value if not
specified. zero means delete immediately.
name: gracePeriodSeconds
in: query
- uniqueItems: true
type: boolean
description: >-
Deprecated: please use the PropagationPolicy, this field will be
deprecated in 1.7. Should the dependent objects be orphaned. If
true/false, the "orphan" finalizer will be added to/removed from the
object's finalizers list. Either this field or PropagationPolicy may
be set, but not both.
name: orphanDependents
in: query
- uniqueItems: true
type: string
description: >-
Whether and how garbage collection will be performed. Either this
field or OrphanDependents may be set, but not both. The default
policy is decided by the existing finalizer set in the
metadata.finalizers and the resource-specific default policy.
Acceptable values are: 'Orphan' - orphan the dependents;
'Background' - allow the garbage collector to delete the dependents
in the background; 'Foreground' - a cascading policy that deletes
all dependents in the foreground.
name: propagationPolicy
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'202':
description: Accepted
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
'401':
description: Unauthorized
x-kubernetes-action: delete
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: RoleTemplate
version: v3
patch:
description: partially update the specified RoleTemplate
consumes:
- application/json-patch+json
- application/merge-patch+json
- application/apply-patch+yaml
produces:
- application/json
- application/yaml
schemes:
- https
tags:
- managementCattleIo_v3
operationId: patchManagementCattleIoV3RoleTemplate
parameters:
- name: body
in: body
required: true
schema:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
- uniqueItems: true
type: string
description: >-
When present, indicates that modifications should not be persisted.
An invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are:
- All: all dry run stages will be processed
name: dryRun
in: query
- uniqueItems: true
type: string
description: >-
fieldManager is a name associated with the actor or entity that is
making these changes. The value must be less than or 128 characters
long, and only contain printable characters, as defined by
https://golang.org/pkg/unicode/#IsPrint. This field is required for
apply requests (application/apply-patch) but optional for non-apply
patch types (JsonPatch, MergePatch, StrategicMergePatch).
name: fieldManager
in: query
- uniqueItems: true
type: string
description: >-
fieldValidation instructs the server on how to handle objects in the
request (POST/PUT/PATCH) containing unknown or duplicate fields.
Valid values are: - Ignore: This will ignore any unknown fields that
are silently dropped from the object, and will ignore all but the
last duplicate field that the decoder encounters. This is the
default behavior prior to v1.23. - Warn: This will send a warning
via the standard warning response header for each unknown field that
is dropped from the object, and for each duplicate field that is
encountered. The request will still succeed if there are no other
errors, and will only persist the last of any duplicate fields. This
is the default in v1.23+ - Strict: This will fail the request with a
BadRequest error if any unknown fields would be dropped from the
object, or if any duplicate fields are present. The error returned
from the server will contain all unknown and duplicate fields
encountered.
name: fieldValidation
in: query
- uniqueItems: true
type: boolean
description: >-
Force is going to "force" Apply requests. It means user will
re-acquire conflicting fields owned by other people. Force flag must
be unset for non-apply patch requests.
name: force
in: query
responses:
'200':
description: OK
schema:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
'401':
description: Unauthorized
x-kubernetes-action: patch
x-kubernetes-group-version-kind:
group: management.cattle.io
kind: RoleTemplate
version: v3
parameters:
- uniqueItems: true
type: string
description: name of the RoleTemplate
name: name
in: path
required: true
- uniqueItems: true
type: string
description: If 'true', then the output is pretty printed.
name: pretty
in: query
definitions:
io.cattle.management.v3.ClusterRoleTemplateBinding:
description: >-
ClusterRoleTemplateBinding is the object representing membership of a
subject in a cluster with permissions specified by a given role template.
type: object
required:
- clusterName
- roleTemplateName
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
clusterName:
description: >-
ClusterName is the metadata.name of the cluster to which a subject is
added. Must match the namespace. Immutable.
type: string
groupName:
description: >-
GroupName is the name of the group subject added to the cluster.
Immutable.
type: string
groupPrincipalName:
description: >-
GroupPrincipalName is the name of the group principal subject added to
the cluster. Immutable.
type: string
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard object's metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
roleTemplateName:
description: >-
RoleTemplateName is the name of the role template that defines
permissions to perform actions on resources in the cluster. Immutable.
type: string
userName:
description: >-
UserName is the name of the user subject added to the cluster.
Immutable.
type: string
userPrincipalName:
description: >-
UserPrincipalName is the name of the user principal subject added to
the cluster. Immutable.
type: string
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: ClusterRoleTemplateBinding
version: v3
io.cattle.management.v3.ClusterRoleTemplateBindingList:
description: ClusterRoleTemplateBindingList is a list of ClusterRoleTemplateBinding
type: object
required:
- items
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
items:
description: >-
List of clusterroletemplatebindings. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
type: array
items:
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard list metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: ClusterRoleTemplateBindingList
version: v3
io.cattle.management.v3.GlobalRole:
description: >-
GlobalRole defines rules that can be applied to the local cluster and or
every downstream cluster.
type: object
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
builtin:
description: >-
Builtin specifies that this GlobalRole was created by Rancher if true.
Immutable.
type: boolean
description:
description: Description holds text that describes the resource.
type: string
displayName:
description: >-
DisplayName is the human-readable name displayed in the UI for this
resource.
type: string
inheritedClusterRoles:
description: >-
InheritedClusterRoles are the names of RoleTemplates whose permissions
are granted by this GlobalRole in every cluster besides the local
cluster. To grant permissions in the local cluster, use the Rules
field.
type: array
items:
type: string
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard object's metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
newUserDefault:
description: >-
NewUserDefault specifies that all new users created should be bound to
this GlobalRole if true.
type: boolean
rules:
description: >-
Rules holds a list of PolicyRules that are applied to the local
cluster only.
type: array
items:
description: >-
PolicyRule holds information that describes a policy rule, but does
not contain information about who the rule applies to or which
namespace the rule applies to.
type: object
required:
- verbs
properties:
apiGroups:
description: >-
APIGroups is the name of the APIGroup that contains the
resources. If multiple API groups are specified, any action
requested against one of the enumerated resources in any API
group will be allowed. "" represents the core API group and "*"
represents all API groups.
type: array
items:
type: string
nonResourceURLs:
description: >-
NonResourceURLs is a set of partial urls that a user should have
access to. *s are allowed, but only as the full, final step in
the path Since non-resource URLs are not namespaced, this field
is only applicable for ClusterRoles referenced from a
ClusterRoleBinding. Rules can either apply to API resources
(such as "pods" or "secrets") or non-resource URL paths (such as
"/api"), but not both.
type: array
items:
type: string
resourceNames:
description: >-
ResourceNames is an optional white list of names that the rule
applies to. An empty set means that everything is allowed.
type: array
items:
type: string
resources:
description: >-
Resources is a list of resources this rule applies to. '*'
represents all resources.
type: array
items:
type: string
verbs:
description: >-
Verbs is a list of Verbs that apply to ALL the ResourceKinds
contained in this rule. '*' represents all verbs.
type: array
items:
type: string
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: GlobalRole
version: v3
io.cattle.management.v3.GlobalRoleBinding:
description: GlobalRoleBinding binds a given subject user or group to a GlobalRole.
type: object
required:
- globalRoleName
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
globalRoleName:
description: >-
GlobalRoleName is the name of the Global Role that the subject will be
bound to. Immutable.
type: string
groupPrincipalName:
description: >-
GroupPrincipalName is the name of the group principal subject to be
bound. Immutable.
type: string
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard object's metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
userName:
description: UserName is the name of the user subject to be bound. Immutable.
type: string
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: GlobalRoleBinding
version: v3
io.cattle.management.v3.GlobalRoleBindingList:
description: GlobalRoleBindingList is a list of GlobalRoleBinding
type: object
required:
- items
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
items:
description: >-
List of globalrolebindings. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
type: array
items:
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard list metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: GlobalRoleBindingList
version: v3
io.cattle.management.v3.GlobalRoleList:
description: GlobalRoleList is a list of GlobalRole
type: object
required:
- items
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
items:
description: >-
List of globalroles. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
type: array
items:
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard list metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: GlobalRoleList
version: v3
io.cattle.management.v3.Project:
description: >-
Project is a group of namespaces. Projects are used to create a
multi-tenant environment within a Kubernetes cluster by managing namespace
operations, such as role assignments or quotas, as a group.
type: object
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard object's metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
spec:
description: >-
Spec is the specification of the desired configuration for the
project.
type: object
required:
- clusterName
- displayName
properties:
clusterName:
description: >-
ClusterName is the name of the cluster the project belongs to.
Immutable.
type: string
containerDefaultResourceLimit:
description: >-
ContainerDefaultResourceLimit is a specification for the default
LimitRange for the namespace. See
https://kubernetes.io/docs/concepts/policy/limit-range/ for more
details.
type: object
properties:
limitsCpu:
description: >-
LimitsCPU is the CPU limits across all pods in a non-terminal
state.
type: string
limitsMemory:
description: >-
LimitsMemory is the memory limits across all pods in a
non-terminal state.
type: string
requestsCpu:
description: >-
RequestsCPU is the CPU requests limit across all pods in a
non-terminal state.
type: string
requestsMemory:
description: >-
RequestsMemory is the memory requests limit across all pods in
a non-terminal state.
type: string
description:
description: Description is a human-readable description of the project.
type: string
displayName:
description: DisplayName is the human-readable name for the project.
type: string
enableProjectMonitoring:
description: >-
EnableProjectMonitoring indicates whether Monitoring V1 should be
enabled for this project. Deprecated. Use the Monitoring V2 app
instead. Defaults to false.
type: boolean
namespaceDefaultResourceQuota:
description: >-
NamespaceDefaultResourceQuota is a specification of the default
ResourceQuota that a namespace will receive if none is provided.
Must provide ResourceQuota if NamespaceDefaultResourceQuota is
specified. See
https://kubernetes.io/docs/concepts/policy/resource-quotas/ for
more details.
type: object
properties:
limit:
description: Limit is the default quota limits applied to new namespaces.
type: object
properties:
configMaps:
description: >-
ConfigMaps is the total number of ReplicationControllers
that can exist in the namespace.
type: string
limitsCpu:
description: >-
LimitsCPU is the CPU limits across all pods in a
non-terminal state.
type: string
limitsMemory:
description: >-
LimitsMemory is the memory limits across all pods in a
non-terminal state.
type: string
persistentVolumeClaims:
description: >-
PersistentVolumeClaims is the total number of
PersistentVolumeClaims that can exist in the namespace.
type: string
pods:
description: >-
Pods is the total number of Pods in a non-terminal state
that can exist in the namespace. A pod is in a terminal
state if .status.phase in (Failed, Succeeded) is true.
type: string
replicationControllers:
description: >-
ReplicationControllers is total number of
ReplicationControllers that can exist in the namespace.
type: string
requestsCpu:
description: >-
RequestsCPU is the CPU requests limit across all pods in a
non-terminal state.
type: string
requestsMemory:
description: >-
RequestsMemory is the memory requests limit across all
pods in a non-terminal state.
type: string
requestsStorage:
description: >-
RequestsStorage is the storage requests limit across all
persistent volume claims.
type: string
secrets:
description: >-
Secrets is the total number of ReplicationControllers that
can exist in the namespace.
type: string
services:
description: >-
Services is the total number of Services that can exist in
the namespace.
type: string
servicesLoadBalancers:
description: >-
ServicesLoadBalancers is the total number of Services of
type LoadBalancer that can exist in the namespace.
type: string
servicesNodePorts:
description: >-
ServiceNodePorts is the total number of Services of type
NodePort that can exist in the namespace.
type: string
resourceQuota:
description: >-
ResourceQuota is a specification for the total amount of quota for
standard resources that will be shared by all namespaces in the
project. Must provide NamespaceDefaultResourceQuota if
ResourceQuota is specified. See
https://kubernetes.io/docs/concepts/policy/resource-quotas/ for
more details.
type: object
properties:
limit:
description: >-
Limit is the total allowable quota limits shared by all
namespaces in the project.
type: object
properties:
configMaps:
description: >-
ConfigMaps is the total number of ReplicationControllers
that can exist in the namespace.
type: string
limitsCpu:
description: >-
LimitsCPU is the CPU limits across all pods in a
non-terminal state.
type: string
limitsMemory:
description: >-
LimitsMemory is the memory limits across all pods in a
non-terminal state.
type: string
persistentVolumeClaims:
description: >-
PersistentVolumeClaims is the total number of
PersistentVolumeClaims that can exist in the namespace.
type: string
pods:
description: >-
Pods is the total number of Pods in a non-terminal state
that can exist in the namespace. A pod is in a terminal
state if .status.phase in (Failed, Succeeded) is true.
type: string
replicationControllers:
description: >-
ReplicationControllers is total number of
ReplicationControllers that can exist in the namespace.
type: string
requestsCpu:
description: >-
RequestsCPU is the CPU requests limit across all pods in a
non-terminal state.
type: string
requestsMemory:
description: >-
RequestsMemory is the memory requests limit across all
pods in a non-terminal state.
type: string
requestsStorage:
description: >-
RequestsStorage is the storage requests limit across all
persistent volume claims.
type: string
secrets:
description: >-
Secrets is the total number of ReplicationControllers that
can exist in the namespace.
type: string
services:
description: >-
Services is the total number of Services that can exist in
the namespace.
type: string
servicesLoadBalancers:
description: >-
ServicesLoadBalancers is the total number of Services of
type LoadBalancer that can exist in the namespace.
type: string
servicesNodePorts:
description: >-
ServiceNodePorts is the total number of Services of type
NodePort that can exist in the namespace.
type: string
usedLimit:
description: >-
UsedLimit is the currently allocated quota for all namespaces
in the project.
type: object
properties:
configMaps:
description: >-
ConfigMaps is the total number of ReplicationControllers
that can exist in the namespace.
type: string
limitsCpu:
description: >-
LimitsCPU is the CPU limits across all pods in a
non-terminal state.
type: string
limitsMemory:
description: >-
LimitsMemory is the memory limits across all pods in a
non-terminal state.
type: string
persistentVolumeClaims:
description: >-
PersistentVolumeClaims is the total number of
PersistentVolumeClaims that can exist in the namespace.
type: string
pods:
description: >-
Pods is the total number of Pods in a non-terminal state
that can exist in the namespace. A pod is in a terminal
state if .status.phase in (Failed, Succeeded) is true.
type: string
replicationControllers:
description: >-
ReplicationControllers is total number of
ReplicationControllers that can exist in the namespace.
type: string
requestsCpu:
description: >-
RequestsCPU is the CPU requests limit across all pods in a
non-terminal state.
type: string
requestsMemory:
description: >-
RequestsMemory is the memory requests limit across all
pods in a non-terminal state.
type: string
requestsStorage:
description: >-
RequestsStorage is the storage requests limit across all
persistent volume claims.
type: string
secrets:
description: >-
Secrets is the total number of ReplicationControllers that
can exist in the namespace.
type: string
services:
description: >-
Services is the total number of Services that can exist in
the namespace.
type: string
servicesLoadBalancers:
description: >-
ServicesLoadBalancers is the total number of Services of
type LoadBalancer that can exist in the namespace.
type: string
servicesNodePorts:
description: >-
ServiceNodePorts is the total number of Services of type
NodePort that can exist in the namespace.
type: string
status:
description: Status is the most recently observed status of the project.
type: object
properties:
conditions:
description: Conditions are a set of indicators about aspects of the project.
type: array
items:
description: ProjectCondition is the status of an aspect of the project.
type: object
required:
- status
- type
properties:
lastTransitionTime:
description: >-
Last time the condition transitioned from one status to
another.
type: string
lastUpdateTime:
description: The last time this condition was updated.
type: string
message:
description: >-
Human-readable message indicating details about last
transition.
type: string
reason:
description: The reason for the condition's last transition.
type: string
status:
description: Status of the condition, one of True, False, Unknown.
type: string
type:
description: Type of project condition.
type: string
monitoringStatus:
description: MonitoringStatus is the status of the Monitoring V1 app.
type: object
properties:
conditions:
type: array
items:
type: object
required:
- status
- type
properties:
lastTransitionTime:
description: >-
Last time the condition transitioned from one status to
another.
type: string
lastUpdateTime:
description: The last time this condition was updated.
type: string
message:
description: >-
Human-readable message indicating details about last
transition
type: string
reason:
description: The reason for the condition's last transition.
type: string
status:
description: Status of the condition, one of True, False, Unknown.
type: string
type:
description: Type of cluster condition.
type: string
grafanaEndpoint:
type: string
podSecurityPolicyTemplateId:
description: >-
PodSecurityPolicyTemplateName is the pod security policy template
associated with the project.
type: string
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: Project
version: v3
io.cattle.management.v3.ProjectList:
description: ProjectList is a list of Project
type: object
required:
- items
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
items:
description: >-
List of projects. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
type: array
items:
$ref: '#/definitions/io.cattle.management.v3.Project'
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard list metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: ProjectList
version: v3
io.cattle.management.v3.ProjectRoleTemplateBinding:
description: >-
ProjectRoleTemplateBinding is the object representing membership of a
subject in a project with permissions specified by a given role template.
type: object
required:
- projectName
- roleTemplateName
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
groupName:
description: >-
GroupName is the name of the group subject added to the project.
Immutable.
type: string
groupPrincipalName:
description: >-
GroupPrincipalName is the name of the group principal subject added to
the project. Immutable.
type: string
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard object's metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
projectName:
description: >-
ProjectName is the name of the project to which a subject is added.
Immutable.
type: string
roleTemplateName:
description: >-
RoleTemplateName is the name of the role template that defines
permissions to perform actions on resources in the project. Immutable.
type: string
serviceAccount:
description: >-
ServiceAccount is the name of the service account bound as a subject.
Immutable. Deprecated.
type: string
userName:
description: >-
UserName is the name of the user subject added to the project.
Immutable.
type: string
userPrincipalName:
description: >-
UserPrincipalName is the name of the user principal subject added to
the project. Immutable.
type: string
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: ProjectRoleTemplateBinding
version: v3
io.cattle.management.v3.ProjectRoleTemplateBindingList:
description: ProjectRoleTemplateBindingList is a list of ProjectRoleTemplateBinding
type: object
required:
- items
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
items:
description: >-
List of projectroletemplatebindings. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
type: array
items:
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard list metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: ProjectRoleTemplateBindingList
version: v3
io.cattle.management.v3.RoleTemplate:
description: >-
RoleTemplate holds configuration for a template that is used to create
kubernetes Roles and ClusterRoles (in the rbac.authorization.k8s.io group)
for a cluster or project.
type: object
properties:
administrative:
description: >-
Administrative if false, and context is set to cluster this
RoleTemplate will not grant access to "CatalogTemplates" and
"CatalogTemplateVersions" for any project in the cluster. Default is
false.
type: boolean
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
builtin:
description: >-
Builtin if true specifies that this RoleTemplate was created by
Rancher and is immutable. Default to false.
type: boolean
clusterCreatorDefault:
description: >-
ClusterCreatorDefault if true, a binding with this RoleTemplate will
be created for a users when they create a new cluster.
ClusterCreatorDefault is only evaluated if the context of the
RoleTemplate is set to cluster. Default to false.
type: boolean
context:
description: >-
Context describes if the roleTemplate applies to clusters or projects.
Valid values are "project", "cluster" or "".
type: string
enum:
- project
- cluster
- ''
description:
description: Description holds text that describes the resource.
type: string
displayName:
description: >-
DisplayName is the human-readable name displayed in the UI for this
resource.
type: string
external:
description: >-
External if true specifies that rules for this RoleTemplate should be
gathered from a ClusterRole with the matching name. If set to true the
Rules on the template will not be evaluated. External's value is only
evaluated if the RoleTemplate's context is set to "cluster" Default to
false.
type: boolean
hidden:
description: >-
Hidden if true informs the Rancher UI not to display this
RoleTemplate. Default to false.
type: boolean
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
locked:
description: >-
Locked if true, new bindings will not be able to use this
RoleTemplate. Default to false.
type: boolean
metadata:
description: >-
Standard object's metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
projectCreatorDefault:
description: >-
ProjectCreatorDefault if true, a binding with this RoleTemplate will
be created for a user when they create a new project.
ProjectCreatorDefault is only evaluated if the context of the
RoleTemplate is set to project. Default to false.
type: boolean
roleTemplateNames:
description: >-
RoleTemplateNames list of RoleTemplate names that this RoleTemplate
will inherit. This RoleTemplate will grant all rules defined in an
inherited RoleTemplate. Inherited RoleTemplates must already exist.
type: array
items:
type: string
rules:
description: Rules hold all the PolicyRules for this RoleTemplate.
type: array
items:
description: >-
PolicyRule holds information that describes a policy rule, but does
not contain information about who the rule applies to or which
namespace the rule applies to.
type: object
required:
- verbs
properties:
apiGroups:
description: >-
APIGroups is the name of the APIGroup that contains the
resources. If multiple API groups are specified, any action
requested against one of the enumerated resources in any API
group will be allowed. "" represents the core API group and "*"
represents all API groups.
type: array
items:
type: string
nonResourceURLs:
description: >-
NonResourceURLs is a set of partial urls that a user should have
access to. *s are allowed, but only as the full, final step in
the path Since non-resource URLs are not namespaced, this field
is only applicable for ClusterRoles referenced from a
ClusterRoleBinding. Rules can either apply to API resources
(such as "pods" or "secrets") or non-resource URL paths (such as
"/api"), but not both.
type: array
items:
type: string
resourceNames:
description: >-
ResourceNames is an optional white list of names that the rule
applies to. An empty set means that everything is allowed.
type: array
items:
type: string
resources:
description: >-
Resources is a list of resources this rule applies to. '*'
represents all resources.
type: array
items:
type: string
verbs:
description: >-
Verbs is a list of Verbs that apply to ALL the ResourceKinds
contained in this rule. '*' represents all verbs.
type: array
items:
type: string
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: RoleTemplate
version: v3
io.cattle.management.v3.RoleTemplateList:
description: RoleTemplateList is a list of RoleTemplate
type: object
required:
- items
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
items:
description: >-
List of roletemplates. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
type: array
items:
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
metadata:
description: >-
Standard list metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
x-kubernetes-group-version-kind:
- group: management.cattle.io
kind: RoleTemplateList
version: v3
io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions:
description: DeleteOptions may be provided when deleting an API object.
type: object
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
dryRun:
description: >-
When present, indicates that modifications should not be persisted. An
invalid or unrecognized dryRun directive will result in an error
response and no further processing of the request. Valid values are: -
All: all dry run stages will be processed
type: array
items:
type: string
gracePeriodSeconds:
description: >-
The duration in seconds before the object should be deleted. Value
must be non-negative integer. The value zero indicates delete
immediately. If this value is nil, the default grace period for the
specified type will be used. Defaults to a per object value if not
specified. zero means delete immediately.
type: integer
format: int64
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
orphanDependents:
description: >-
Deprecated: please use the PropagationPolicy, this field will be
deprecated in 1.7. Should the dependent objects be orphaned. If
true/false, the "orphan" finalizer will be added to/removed from the
object's finalizers list. Either this field or PropagationPolicy may
be set, but not both.
type: boolean
preconditions:
description: >-
Must be fulfilled before a deletion is carried out. If not possible, a
409 Conflict status will be returned.
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Preconditions'
propagationPolicy:
description: >-
Whether and how garbage collection will be performed. Either this
field or OrphanDependents may be set, but not both. The default policy
is decided by the existing finalizer set in the metadata.finalizers
and the resource-specific default policy. Acceptable values are:
'Orphan' - orphan the dependents; 'Background' - allow the garbage
collector to delete the dependents in the background; 'Foreground' - a
cascading policy that deletes all dependents in the foreground.
type: string
x-kubernetes-group-version-kind:
- group: ''
kind: DeleteOptions
version: v1
- group: admission.k8s.io
kind: DeleteOptions
version: v1
- group: admission.k8s.io
kind: DeleteOptions
version: v1beta1
- group: admissionregistration.k8s.io
kind: DeleteOptions
version: v1
- group: admissionregistration.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: admissionregistration.k8s.io
kind: DeleteOptions
version: v1beta1
- group: apiextensions.k8s.io
kind: DeleteOptions
version: v1
- group: apiextensions.k8s.io
kind: DeleteOptions
version: v1beta1
- group: apiregistration.k8s.io
kind: DeleteOptions
version: v1
- group: apiregistration.k8s.io
kind: DeleteOptions
version: v1beta1
- group: apps
kind: DeleteOptions
version: v1
- group: apps
kind: DeleteOptions
version: v1beta1
- group: apps
kind: DeleteOptions
version: v1beta2
- group: authentication.k8s.io
kind: DeleteOptions
version: v1
- group: authentication.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: authentication.k8s.io
kind: DeleteOptions
version: v1beta1
- group: authorization.k8s.io
kind: DeleteOptions
version: v1
- group: authorization.k8s.io
kind: DeleteOptions
version: v1beta1
- group: autoscaling
kind: DeleteOptions
version: v1
- group: autoscaling
kind: DeleteOptions
version: v2
- group: autoscaling
kind: DeleteOptions
version: v2beta1
- group: autoscaling
kind: DeleteOptions
version: v2beta2
- group: batch
kind: DeleteOptions
version: v1
- group: batch
kind: DeleteOptions
version: v1beta1
- group: certificates.k8s.io
kind: DeleteOptions
version: v1
- group: certificates.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: certificates.k8s.io
kind: DeleteOptions
version: v1beta1
- group: coordination.k8s.io
kind: DeleteOptions
version: v1
- group: coordination.k8s.io
kind: DeleteOptions
version: v1beta1
- group: discovery.k8s.io
kind: DeleteOptions
version: v1
- group: discovery.k8s.io
kind: DeleteOptions
version: v1beta1
- group: events.k8s.io
kind: DeleteOptions
version: v1
- group: events.k8s.io
kind: DeleteOptions
version: v1beta1
- group: extensions
kind: DeleteOptions
version: v1beta1
- group: flowcontrol.apiserver.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: flowcontrol.apiserver.k8s.io
kind: DeleteOptions
version: v1beta1
- group: flowcontrol.apiserver.k8s.io
kind: DeleteOptions
version: v1beta2
- group: flowcontrol.apiserver.k8s.io
kind: DeleteOptions
version: v1beta3
- group: imagepolicy.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: internal.apiserver.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: networking.k8s.io
kind: DeleteOptions
version: v1
- group: networking.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: networking.k8s.io
kind: DeleteOptions
version: v1beta1
- group: node.k8s.io
kind: DeleteOptions
version: v1
- group: node.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: node.k8s.io
kind: DeleteOptions
version: v1beta1
- group: policy
kind: DeleteOptions
version: v1
- group: policy
kind: DeleteOptions
version: v1beta1
- group: rbac.authorization.k8s.io
kind: DeleteOptions
version: v1
- group: rbac.authorization.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: rbac.authorization.k8s.io
kind: DeleteOptions
version: v1beta1
- group: resource.k8s.io
kind: DeleteOptions
version: v1alpha2
- group: scheduling.k8s.io
kind: DeleteOptions
version: v1
- group: scheduling.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: scheduling.k8s.io
kind: DeleteOptions
version: v1beta1
- group: storage.k8s.io
kind: DeleteOptions
version: v1
- group: storage.k8s.io
kind: DeleteOptions
version: v1alpha1
- group: storage.k8s.io
kind: DeleteOptions
version: v1beta1
io.k8s.apimachinery.pkg.apis.meta.v1.FieldsV1:
description: >-
FieldsV1 stores a set of fields in a data structure like a Trie, in JSON
format.
Each key is either a '.' representing the field itself, and will always
map to an empty set, or a string representing a sub-field or item. The
string will follow one of these four formats: 'f:<name>', where <name> is
the name of a field in a struct, or key in a map 'v:<value>', where
<value> is the exact json formatted value of a list item 'i:<index>',
where <index> is position of a item in a list 'k:<keys>', where <keys> is
a map of a list item's key fields to their unique values If a key maps to
an empty Fields value, the field that key represents is part of the set.
The exact format is defined in sigs.k8s.io/structured-merge-diff
type: object
io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta:
description: >-
ListMeta describes metadata that synthetic resources must have, including
lists and various status objects. A resource may have only one of
{ObjectMeta, ListMeta}.
type: object
properties:
continue:
description: >-
continue may be set if the user set a limit on the number of items
returned, and indicates that the server has more data available. The
value is opaque and may be used to issue another request to the
endpoint that served this list to retrieve the next set of available
objects. Continuing a consistent list may not be possible if the
server configuration has changed or more than a few minutes have
passed. The resourceVersion field returned when using this continue
value will be identical to the value in the first response, unless you
have received this token from an error message.
type: string
remainingItemCount:
description: >-
remainingItemCount is the number of subsequent items in the list which
are not included in this list response. If the list request contained
label or field selectors, then the number of remaining items is
unknown and the field will be left unset and omitted during
serialization. If the list is complete (either because it is not
chunking or because this is the last chunk), then there are no more
remaining items and this field will be left unset and omitted during
serialization. Servers older than v1.15 do not set this field. The
intended use of the remainingItemCount is *estimating* the size of a
collection. Clients should not rely on the remainingItemCount to be
set or to be exact.
type: integer
format: int64
resourceVersion:
description: >-
String that identifies the server's internal version of this object
that can be used by clients to determine when objects have changed.
Value must be treated as opaque by clients and passed unmodified back
to the server. Populated by the system. Read-only. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
selfLink:
description: >-
Deprecated: selfLink is a legacy read-only field that is no longer
populated by the system.
type: string
io.k8s.apimachinery.pkg.apis.meta.v1.ManagedFieldsEntry:
description: >-
ManagedFieldsEntry is a workflow-id, a FieldSet and the group version of
the resource that the fieldset applies to.
type: object
properties:
apiVersion:
description: >-
APIVersion defines the version of this resource that this field set
applies to. The format is "group/version" just like the top-level
APIVersion field. It is necessary to track the version of a field set
because it cannot be automatically converted.
type: string
fieldsType:
description: >-
FieldsType is the discriminator for the different fields format and
version. There is currently only one possible value: "FieldsV1"
type: string
fieldsV1:
description: >-
FieldsV1 holds the first JSON version format as described in the
"FieldsV1" type.
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.FieldsV1'
manager:
description: Manager is an identifier of the workflow managing these fields.
type: string
operation:
description: >-
Operation is the type of operation which lead to this
ManagedFieldsEntry being created. The only valid values for this field
are 'Apply' and 'Update'.
type: string
subresource:
description: >-
Subresource is the name of the subresource used to update that object,
or empty string if the object was updated through the main resource.
The value of this field is used to distinguish between managers, even
if they share the same name. For example, a status update will be
distinct from a regular update using the same manager name. Note that
the APIVersion field is not related to the Subresource field and it
always corresponds to the version of the main resource.
type: string
time:
description: >-
Time is the timestamp of when the ManagedFields entry was added. The
timestamp will also be updated if a field is added, the manager
changes any of the owned fields value or removes a field. The
timestamp does not update when a field is removed from the entry
because another manager took it over.
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Time'
io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta:
description: >-
ObjectMeta is metadata that all persisted resources must have, which
includes all objects users must create.
type: object
properties:
annotations:
description: >-
Annotations is an unstructured key value map stored with a resource
that may be set by external tools to store and retrieve arbitrary
metadata. They are not queryable and should be preserved when
modifying objects. More info:
https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations
type: object
additionalProperties:
type: string
creationTimestamp:
description: >-
CreationTimestamp is a timestamp representing the server time when
this object was created. It is not guaranteed to be set in
happens-before order across separate operations. Clients may not set
this value. It is represented in RFC3339 form and is in UTC.
Populated by the system. Read-only. Null for lists. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Time'
deletionGracePeriodSeconds:
description: >-
Number of seconds allowed for this object to gracefully terminate
before it will be removed from the system. Only set when
deletionTimestamp is also set. May only be shortened. Read-only.
type: integer
format: int64
deletionTimestamp:
description: >-
DeletionTimestamp is RFC 3339 date and time at which this resource
will be deleted. This field is set by the server when a graceful
deletion is requested by the user, and is not directly settable by a
client. The resource is expected to be deleted (no longer visible from
resource lists, and not reachable by name) after the time in this
field, once the finalizers list is empty. As long as the finalizers
list contains items, deletion is blocked. Once the deletionTimestamp
is set, this value may not be unset or be set further into the future,
although it may be shortened or the resource may be deleted prior to
this time. For example, a user may request that a pod is deleted in 30
seconds. The Kubelet will react by sending a graceful termination
signal to the containers in the pod. After that 30 seconds, the
Kubelet will send a hard termination signal (SIGKILL) to the container
and after cleanup, remove the pod from the API. In the presence of
network partitions, this object may still exist after this timestamp,
until an administrator or automated process can determine the resource
is fully terminated. If not set, graceful deletion of the object has
not been requested.
Populated by the system when a graceful deletion is requested.
Read-only. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Time'
finalizers:
description: >-
Must be empty before the object is deleted from the registry. Each
entry is an identifier for the responsible component that will remove
the entry from the list. If the deletionTimestamp of the object is
non-nil, entries in this list can only be removed. Finalizers may be
processed and removed in any order. Order is NOT enforced because it
introduces significant risk of stuck finalizers. finalizers is a
shared field, any actor with permission can reorder it. If the
finalizer list is processed in order, then this can lead to a
situation in which the component responsible for the first finalizer
in the list is waiting for a signal (field value, external system, or
other) produced by a component responsible for a finalizer later in
the list, resulting in a deadlock. Without enforced ordering
finalizers are free to order amongst themselves and are not vulnerable
to ordering changes in the list.
type: array
items:
type: string
x-kubernetes-patch-strategy: merge
generateName:
description: >-
GenerateName is an optional prefix, used by the server, to generate a
unique name ONLY IF the Name field has not been provided. If this
field is used, the name returned to the client will be different than
the name passed. This value will also be combined with a unique
suffix. The provided value has the same validation rules as the Name
field, and may be truncated by the length of the suffix required to
make the value unique on the server.
If this field is specified and the generated name exists, the server
will return a 409.
Applied only if Name is not specified. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#idempotency
type: string
generation:
description: >-
A sequence number representing a specific generation of the desired
state. Populated by the system. Read-only.
type: integer
format: int64
labels:
description: >-
Map of string keys and values that can be used to organize and
categorize (scope and select) objects. May match selectors of
replication controllers and services. More info:
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels
type: object
additionalProperties:
type: string
managedFields:
description: >-
ManagedFields maps workflow-id and version to the set of fields that
are managed by that workflow. This is mostly for internal
housekeeping, and users typically shouldn't need to set or understand
this field. A workflow can be the user's name, a controller's name, or
the name of a specific apply path like "ci-cd". The set of fields is
always in the version that the workflow used when modifying the
object.
type: array
items:
$ref: >-
#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ManagedFieldsEntry
name:
description: >-
Name must be unique within a namespace. Is required when creating
resources, although some resources may allow a client to request the
generation of an appropriate name automatically. Name is primarily
intended for creation idempotence and configuration definition. Cannot
be updated. More info:
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#names
type: string
namespace:
description: >-
Namespace defines the space within which each name must be unique. An
empty namespace is equivalent to the "default" namespace, but
"default" is the canonical representation. Not all objects are
required to be scoped to a namespace - the value of this field for
those objects will be empty.
Must be a DNS_LABEL. Cannot be updated. More info:
https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces
type: string
ownerReferences:
description: >-
List of objects depended by this object. If ALL objects in the list
have been deleted, this object will be garbage collected. If this
object is managed by a controller, then an entry in this list will
point to this controller, with the controller field set to true. There
cannot be more than one managing controller.
type: array
items:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.OwnerReference'
x-kubernetes-patch-merge-key: uid
x-kubernetes-patch-strategy: merge
resourceVersion:
description: >-
An opaque value that represents the internal version of this object
that can be used by clients to determine when objects have changed.
May be used for optimistic concurrency, change detection, and the
watch operation on a resource or set of resources. Clients must treat
these values as opaque and passed unmodified back to the server. They
may only be valid for a particular resource or set of resources.
Populated by the system. Read-only. Value must be treated as opaque by
clients and . More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
type: string
selfLink:
description: >-
Deprecated: selfLink is a legacy read-only field that is no longer
populated by the system.
type: string
uid:
description: >-
UID is the unique in time and space value for this object. It is
typically generated by the server on successful creation of a resource
and is not allowed to change on PUT operations.
Populated by the system. Read-only. More info:
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#uids
type: string
io.k8s.apimachinery.pkg.apis.meta.v1.OwnerReference:
description: >-
OwnerReference contains enough information to let you identify an owning
object. An owning object must be in the same namespace as the dependent,
or be cluster-scoped, so there is no namespace field.
type: object
required:
- apiVersion
- kind
- name
- uid
properties:
apiVersion:
description: API version of the referent.
type: string
blockOwnerDeletion:
description: >-
If true, AND if the owner has the "foregroundDeletion" finalizer, then
the owner cannot be deleted from the key-value store until this
reference is removed. See
https://kubernetes.io/docs/concepts/architecture/garbage-collection/#foreground-deletion
for how the garbage collector interacts with this field and enforces
the foreground deletion. Defaults to false. To set this field, a user
needs "delete" permission of the owner, otherwise 422 (Unprocessable
Entity) will be returned.
type: boolean
controller:
description: If true, this reference points to the managing controller.
type: boolean
kind:
description: >-
Kind of the referent. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: >-
Name of the referent. More info:
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#names
type: string
uid:
description: >-
UID of the referent. More info:
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#uids
type: string
x-kubernetes-map-type: atomic
io.k8s.apimachinery.pkg.apis.meta.v1.Patch:
description: >-
Patch is provided to give a concrete name and type to the Kubernetes PATCH
request body.
type: object
io.k8s.apimachinery.pkg.apis.meta.v1.Preconditions:
description: >-
Preconditions must be fulfilled before an operation (update, delete, etc.)
is carried out.
type: object
properties:
resourceVersion:
description: Specifies the target ResourceVersion
type: string
uid:
description: Specifies the target UID.
type: string
io.k8s.apimachinery.pkg.apis.meta.v1.Status:
description: Status is a return value for calls that don't return other objects.
type: object
properties:
apiVersion:
description: >-
APIVersion defines the versioned schema of this representation of an
object. Servers should convert recognized schemas to the latest
internal value, and may reject unrecognized values. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
type: string
code:
description: Suggested HTTP return code for this status, 0 if not set.
type: integer
format: int32
details:
description: >-
Extended data associated with the reason. Each reason may define its
own extended details. This field is optional and the data returned is
not guaranteed to conform to any schema except that defined by the
reason type.
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.StatusDetails'
kind:
description: >-
Kind is a string value representing the REST resource this object
represents. Servers may infer this from the endpoint the client
submits requests to. Cannot be updated. In CamelCase. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
message:
description: A human-readable description of the status of this operation.
type: string
metadata:
description: >-
Standard list metadata. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
reason:
description: >-
A machine-readable description of why this operation is in the
"Failure" status. If this value is empty there is no information
available. A Reason clarifies an HTTP status code but does not
override it.
type: string
status:
description: >-
Status of the operation. One of: "Success" or "Failure". More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
type: string
x-kubernetes-group-version-kind:
- group: ''
kind: Status
version: v1
- group: resource.k8s.io
kind: Status
version: v1alpha2
io.k8s.apimachinery.pkg.apis.meta.v1.StatusCause:
description: >-
StatusCause provides more information about an api.Status failure,
including cases when multiple errors are encountered.
type: object
properties:
field:
description: >-
The field of the resource that has caused this error, as named by its
JSON serialization. May include dot and postfix notation for nested
attributes. Arrays are zero-indexed. Fields may appear more than once
in an array of causes due to fields having multiple errors. Optional.
Examples:
"name" - the field "name" on the current resource
"items[0].name" - the field "name" on the first array entry in "items"
type: string
message:
description: >-
A human-readable description of the cause of the error. This field
may be presented as-is to a reader.
type: string
reason:
description: >-
A machine-readable description of the cause of the error. If this
value is empty there is no information available.
type: string
io.k8s.apimachinery.pkg.apis.meta.v1.StatusDetails:
description: >-
StatusDetails is a set of additional properties that MAY be set by the
server to provide additional information about a response. The Reason
field of a Status object defines what attributes will be set. Clients must
ignore fields that do not match the defined type of each attribute, and
should assume that any attribute may be empty, invalid, or under defined.
type: object
properties:
causes:
description: >-
The Causes array includes more details associated with the
StatusReason failure. Not all StatusReasons may provide detailed
causes.
type: array
items:
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.StatusCause'
group:
description: >-
The group attribute of the resource associated with the status
StatusReason.
type: string
kind:
description: >-
The kind attribute of the resource associated with the status
StatusReason. On some operations may differ from the requested
resource Kind. More info:
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
type: string
name:
description: >-
The name attribute of the resource associated with the status
StatusReason (when there is a single name which can be described).
type: string
retryAfterSeconds:
description: >-
If specified, the time in seconds before the operation should be
retried. Some errors may indicate the client must take an alternate
action - for those errors this field may indicate how long to wait
before taking the alternate action.
type: integer
format: int32
uid:
description: >-
UID of the resource. (when there is a single resource which can be
described). More info:
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#uids
type: string
io.k8s.apimachinery.pkg.apis.meta.v1.Time:
description: >-
Time is a wrapper around time.Time which supports correct marshaling to
YAML and JSON. Wrappers are provided for many of the factory methods that
the time package offers.
type: string
format: date-time
securityDefinitions:
BearerToken:
description: Bearer Token authentication
type: apiKey
name: authorization
in: header
security:
- BearerToken: []