mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-27 05:28:22 +00:00
6702 lines
287 KiB
YAML
6702 lines
287 KiB
YAML
swagger: '2.0'
|
|
info:
|
|
title: Kubernetes
|
|
version: v1.27.5+k3s1
|
|
paths:
|
|
/apis/management.cattle.io/v3/clusterroletemplatebindings:
|
|
get:
|
|
description: list objects of kind ClusterRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3ClusterRoleTemplateBindingForAllNamespaces
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: >-
|
|
#/definitions/io.cattle.management.v3.ClusterRoleTemplateBindingList
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration (generally
|
|
five to fifteen minutes) or a configuration change on the server, the
|
|
server will respond with a 410 ResourceExpired error together with a
|
|
continue token. If the client needs a consistent list, it must restart
|
|
their list without the continue field. Otherwise, the client may send
|
|
another list request with the token received with the 410 error, the
|
|
server will respond with a list starting from the next key, but from
|
|
the latest snapshot, which is inconsistent from the previous list
|
|
results - objects that are created, modified, or deleted after the
|
|
first list request will be included in the response, as long as their
|
|
keys are after the "next key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the list
|
|
metadata to a value that can be used with the same initial query to
|
|
retrieve the next set of results. Setting a limit may return fewer
|
|
than the requested amount of items (up to zero items) in the event all
|
|
requested objects are filtered out and clients should only use the
|
|
presence of the continue field to determine whether more results are
|
|
available. Servers may choose not to support the limit argument and
|
|
will return all of the available results. If limit is specified and
|
|
the continue field is empty, clients may assume that no more results
|
|
are available. This field is not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit - that
|
|
is, no objects created, modified, or deleted after the first request
|
|
is issued will be included in any subsequent continued requests. This
|
|
is sometimes referred to as a consistent snapshot, and ensures that a
|
|
client that is using limit to receive smaller chunks of a very large
|
|
result can ensure they see all possible objects. If objects are
|
|
updated during a chunked list the version of the object that was
|
|
present at the time the first list result was calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a request
|
|
may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to list
|
|
calls. It is highly recommended that resourceVersionMatch be set for
|
|
list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all such
|
|
events have been sent, a synthetic "Bookmark" event will be sent. The
|
|
bookmark will report the ResourceVersion (RV) corresponding to the set
|
|
of objects, and be marked with `"k8s.io/initial-events-end": "true"`
|
|
annotation. Afterwards, the watch stream will proceed as usual,
|
|
sending watch events corresponding to changes (subsequent to the RV)
|
|
to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` = NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"` (for
|
|
backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the call,
|
|
regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
/apis/management.cattle.io/v3/globalrolebindings:
|
|
get:
|
|
description: list objects of kind GlobalRoleBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3GlobalRoleBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBindingList'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRoleBinding
|
|
version: v3
|
|
post:
|
|
description: create a GlobalRoleBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: createManagementCattleIoV3GlobalRoleBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: post
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRoleBinding
|
|
version: v3
|
|
delete:
|
|
description: delete collection of GlobalRoleBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3CollectionGlobalRoleBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: deletecollection
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRoleBinding
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/globalrolebindings/{name}:
|
|
get:
|
|
description: read the specified GlobalRoleBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: readManagementCattleIoV3GlobalRoleBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: get
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRoleBinding
|
|
version: v3
|
|
put:
|
|
description: replace the specified GlobalRoleBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: replaceManagementCattleIoV3GlobalRoleBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: put
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRoleBinding
|
|
version: v3
|
|
delete:
|
|
description: delete a GlobalRoleBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3GlobalRoleBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
The duration in seconds before the object should be deleted. Value
|
|
must be non-negative integer. The value zero indicates delete
|
|
immediately. If this value is nil, the default grace period for the
|
|
specified type will be used. Defaults to a per object value if not
|
|
specified. zero means delete immediately.
|
|
name: gracePeriodSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Deprecated: please use the PropagationPolicy, this field will be
|
|
deprecated in 1.7. Should the dependent objects be orphaned. If
|
|
true/false, the "orphan" finalizer will be added to/removed from the
|
|
object's finalizers list. Either this field or PropagationPolicy may
|
|
be set, but not both.
|
|
name: orphanDependents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
Whether and how garbage collection will be performed. Either this
|
|
field or OrphanDependents may be set, but not both. The default
|
|
policy is decided by the existing finalizer set in the
|
|
metadata.finalizers and the resource-specific default policy.
|
|
Acceptable values are: 'Orphan' - orphan the dependents;
|
|
'Background' - allow the garbage collector to delete the dependents
|
|
in the background; 'Foreground' - a cascading policy that deletes
|
|
all dependents in the foreground.
|
|
name: propagationPolicy
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: delete
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRoleBinding
|
|
version: v3
|
|
patch:
|
|
description: partially update the specified GlobalRoleBinding
|
|
consumes:
|
|
- application/json-patch+json
|
|
- application/merge-patch+json
|
|
- application/apply-patch+yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: patchManagementCattleIoV3GlobalRoleBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint. This field is required for
|
|
apply requests (application/apply-patch) but optional for non-apply
|
|
patch types (JsonPatch, MergePatch, StrategicMergePatch).
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Force is going to "force" Apply requests. It means user will
|
|
re-acquire conflicting fields owned by other people. Force flag must
|
|
be unset for non-apply patch requests.
|
|
name: force
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: patch
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRoleBinding
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: name of the GlobalRoleBinding
|
|
name: name
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/globalroles:
|
|
get:
|
|
description: list objects of kind GlobalRole
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3GlobalRole
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleList'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRole
|
|
version: v3
|
|
post:
|
|
description: create a GlobalRole
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: createManagementCattleIoV3GlobalRole
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: post
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRole
|
|
version: v3
|
|
delete:
|
|
description: delete collection of GlobalRole
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3CollectionGlobalRole
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: deletecollection
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRole
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/globalroles/{name}:
|
|
get:
|
|
description: read the specified GlobalRole
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: readManagementCattleIoV3GlobalRole
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: get
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRole
|
|
version: v3
|
|
put:
|
|
description: replace the specified GlobalRole
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: replaceManagementCattleIoV3GlobalRole
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: put
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRole
|
|
version: v3
|
|
delete:
|
|
description: delete a GlobalRole
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3GlobalRole
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
The duration in seconds before the object should be deleted. Value
|
|
must be non-negative integer. The value zero indicates delete
|
|
immediately. If this value is nil, the default grace period for the
|
|
specified type will be used. Defaults to a per object value if not
|
|
specified. zero means delete immediately.
|
|
name: gracePeriodSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Deprecated: please use the PropagationPolicy, this field will be
|
|
deprecated in 1.7. Should the dependent objects be orphaned. If
|
|
true/false, the "orphan" finalizer will be added to/removed from the
|
|
object's finalizers list. Either this field or PropagationPolicy may
|
|
be set, but not both.
|
|
name: orphanDependents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
Whether and how garbage collection will be performed. Either this
|
|
field or OrphanDependents may be set, but not both. The default
|
|
policy is decided by the existing finalizer set in the
|
|
metadata.finalizers and the resource-specific default policy.
|
|
Acceptable values are: 'Orphan' - orphan the dependents;
|
|
'Background' - allow the garbage collector to delete the dependents
|
|
in the background; 'Foreground' - a cascading policy that deletes
|
|
all dependents in the foreground.
|
|
name: propagationPolicy
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: delete
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRole
|
|
version: v3
|
|
patch:
|
|
description: partially update the specified GlobalRole
|
|
consumes:
|
|
- application/json-patch+json
|
|
- application/merge-patch+json
|
|
- application/apply-patch+yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: patchManagementCattleIoV3GlobalRole
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint. This field is required for
|
|
apply requests (application/apply-patch) but optional for non-apply
|
|
patch types (JsonPatch, MergePatch, StrategicMergePatch).
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Force is going to "force" Apply requests. It means user will
|
|
re-acquire conflicting fields owned by other people. Force flag must
|
|
be unset for non-apply patch requests.
|
|
name: force
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: patch
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: GlobalRole
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: name of the GlobalRole
|
|
name: name
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/namespaces/{namespace}/clusterroletemplatebindings:
|
|
get:
|
|
description: list objects of kind ClusterRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3NamespacedClusterRoleTemplateBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: >-
|
|
#/definitions/io.cattle.management.v3.ClusterRoleTemplateBindingList
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
post:
|
|
description: create a ClusterRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: createManagementCattleIoV3NamespacedClusterRoleTemplateBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: post
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
delete:
|
|
description: delete collection of ClusterRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3CollectionNamespacedClusterRoleTemplateBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: deletecollection
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: object name and auth scope, such as for teams and projects
|
|
name: namespace
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/namespaces/{namespace}/clusterroletemplatebindings/{name}:
|
|
get:
|
|
description: read the specified ClusterRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: readManagementCattleIoV3NamespacedClusterRoleTemplateBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: get
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
put:
|
|
description: replace the specified ClusterRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: replaceManagementCattleIoV3NamespacedClusterRoleTemplateBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: put
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
delete:
|
|
description: delete a ClusterRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3NamespacedClusterRoleTemplateBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
The duration in seconds before the object should be deleted. Value
|
|
must be non-negative integer. The value zero indicates delete
|
|
immediately. If this value is nil, the default grace period for the
|
|
specified type will be used. Defaults to a per object value if not
|
|
specified. zero means delete immediately.
|
|
name: gracePeriodSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Deprecated: please use the PropagationPolicy, this field will be
|
|
deprecated in 1.7. Should the dependent objects be orphaned. If
|
|
true/false, the "orphan" finalizer will be added to/removed from the
|
|
object's finalizers list. Either this field or PropagationPolicy may
|
|
be set, but not both.
|
|
name: orphanDependents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
Whether and how garbage collection will be performed. Either this
|
|
field or OrphanDependents may be set, but not both. The default
|
|
policy is decided by the existing finalizer set in the
|
|
metadata.finalizers and the resource-specific default policy.
|
|
Acceptable values are: 'Orphan' - orphan the dependents;
|
|
'Background' - allow the garbage collector to delete the dependents
|
|
in the background; 'Foreground' - a cascading policy that deletes
|
|
all dependents in the foreground.
|
|
name: propagationPolicy
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: delete
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
patch:
|
|
description: partially update the specified ClusterRoleTemplateBinding
|
|
consumes:
|
|
- application/json-patch+json
|
|
- application/merge-patch+json
|
|
- application/apply-patch+yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: patchManagementCattleIoV3NamespacedClusterRoleTemplateBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint. This field is required for
|
|
apply requests (application/apply-patch) but optional for non-apply
|
|
patch types (JsonPatch, MergePatch, StrategicMergePatch).
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Force is going to "force" Apply requests. It means user will
|
|
re-acquire conflicting fields owned by other people. Force flag must
|
|
be unset for non-apply patch requests.
|
|
name: force
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: patch
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: name of the ClusterRoleTemplateBinding
|
|
name: name
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: object name and auth scope, such as for teams and projects
|
|
name: namespace
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/namespaces/{namespace}/projectroletemplatebindings:
|
|
get:
|
|
description: list objects of kind ProjectRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3NamespacedProjectRoleTemplateBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: >-
|
|
#/definitions/io.cattle.management.v3.ProjectRoleTemplateBindingList
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
post:
|
|
description: create a ProjectRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: createManagementCattleIoV3NamespacedProjectRoleTemplateBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: post
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
delete:
|
|
description: delete collection of ProjectRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3CollectionNamespacedProjectRoleTemplateBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: deletecollection
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: object name and auth scope, such as for teams and projects
|
|
name: namespace
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/namespaces/{namespace}/projectroletemplatebindings/{name}:
|
|
get:
|
|
description: read the specified ProjectRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: readManagementCattleIoV3NamespacedProjectRoleTemplateBinding
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: get
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
put:
|
|
description: replace the specified ProjectRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: replaceManagementCattleIoV3NamespacedProjectRoleTemplateBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: put
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
delete:
|
|
description: delete a ProjectRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3NamespacedProjectRoleTemplateBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
The duration in seconds before the object should be deleted. Value
|
|
must be non-negative integer. The value zero indicates delete
|
|
immediately. If this value is nil, the default grace period for the
|
|
specified type will be used. Defaults to a per object value if not
|
|
specified. zero means delete immediately.
|
|
name: gracePeriodSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Deprecated: please use the PropagationPolicy, this field will be
|
|
deprecated in 1.7. Should the dependent objects be orphaned. If
|
|
true/false, the "orphan" finalizer will be added to/removed from the
|
|
object's finalizers list. Either this field or PropagationPolicy may
|
|
be set, but not both.
|
|
name: orphanDependents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
Whether and how garbage collection will be performed. Either this
|
|
field or OrphanDependents may be set, but not both. The default
|
|
policy is decided by the existing finalizer set in the
|
|
metadata.finalizers and the resource-specific default policy.
|
|
Acceptable values are: 'Orphan' - orphan the dependents;
|
|
'Background' - allow the garbage collector to delete the dependents
|
|
in the background; 'Foreground' - a cascading policy that deletes
|
|
all dependents in the foreground.
|
|
name: propagationPolicy
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: delete
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
patch:
|
|
description: partially update the specified ProjectRoleTemplateBinding
|
|
consumes:
|
|
- application/json-patch+json
|
|
- application/merge-patch+json
|
|
- application/apply-patch+yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: patchManagementCattleIoV3NamespacedProjectRoleTemplateBinding
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint. This field is required for
|
|
apply requests (application/apply-patch) but optional for non-apply
|
|
patch types (JsonPatch, MergePatch, StrategicMergePatch).
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Force is going to "force" Apply requests. It means user will
|
|
re-acquire conflicting fields owned by other people. Force flag must
|
|
be unset for non-apply patch requests.
|
|
name: force
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: patch
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: name of the ProjectRoleTemplateBinding
|
|
name: name
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: object name and auth scope, such as for teams and projects
|
|
name: namespace
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/namespaces/{namespace}/projects:
|
|
get:
|
|
description: list objects of kind Project
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3NamespacedProject
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectList'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
post:
|
|
description: create a Project
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: createManagementCattleIoV3NamespacedProject
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: post
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
delete:
|
|
description: delete collection of Project
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3CollectionNamespacedProject
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: deletecollection
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: object name and auth scope, such as for teams and projects
|
|
name: namespace
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/namespaces/{namespace}/projects/{name}:
|
|
get:
|
|
description: read the specified Project
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: readManagementCattleIoV3NamespacedProject
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: get
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
put:
|
|
description: replace the specified Project
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: replaceManagementCattleIoV3NamespacedProject
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: put
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
delete:
|
|
description: delete a Project
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3NamespacedProject
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
The duration in seconds before the object should be deleted. Value
|
|
must be non-negative integer. The value zero indicates delete
|
|
immediately. If this value is nil, the default grace period for the
|
|
specified type will be used. Defaults to a per object value if not
|
|
specified. zero means delete immediately.
|
|
name: gracePeriodSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Deprecated: please use the PropagationPolicy, this field will be
|
|
deprecated in 1.7. Should the dependent objects be orphaned. If
|
|
true/false, the "orphan" finalizer will be added to/removed from the
|
|
object's finalizers list. Either this field or PropagationPolicy may
|
|
be set, but not both.
|
|
name: orphanDependents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
Whether and how garbage collection will be performed. Either this
|
|
field or OrphanDependents may be set, but not both. The default
|
|
policy is decided by the existing finalizer set in the
|
|
metadata.finalizers and the resource-specific default policy.
|
|
Acceptable values are: 'Orphan' - orphan the dependents;
|
|
'Background' - allow the garbage collector to delete the dependents
|
|
in the background; 'Foreground' - a cascading policy that deletes
|
|
all dependents in the foreground.
|
|
name: propagationPolicy
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: delete
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
patch:
|
|
description: partially update the specified Project
|
|
consumes:
|
|
- application/json-patch+json
|
|
- application/merge-patch+json
|
|
- application/apply-patch+yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: patchManagementCattleIoV3NamespacedProject
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint. This field is required for
|
|
apply requests (application/apply-patch) but optional for non-apply
|
|
patch types (JsonPatch, MergePatch, StrategicMergePatch).
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Force is going to "force" Apply requests. It means user will
|
|
re-acquire conflicting fields owned by other people. Force flag must
|
|
be unset for non-apply patch requests.
|
|
name: force
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: patch
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: name of the Project
|
|
name: name
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: object name and auth scope, such as for teams and projects
|
|
name: namespace
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/projectroletemplatebindings:
|
|
get:
|
|
description: list objects of kind ProjectRoleTemplateBinding
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3ProjectRoleTemplateBindingForAllNamespaces
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: >-
|
|
#/definitions/io.cattle.management.v3.ProjectRoleTemplateBindingList
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration (generally
|
|
five to fifteen minutes) or a configuration change on the server, the
|
|
server will respond with a 410 ResourceExpired error together with a
|
|
continue token. If the client needs a consistent list, it must restart
|
|
their list without the continue field. Otherwise, the client may send
|
|
another list request with the token received with the 410 error, the
|
|
server will respond with a list starting from the next key, but from
|
|
the latest snapshot, which is inconsistent from the previous list
|
|
results - objects that are created, modified, or deleted after the
|
|
first list request will be included in the response, as long as their
|
|
keys are after the "next key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the list
|
|
metadata to a value that can be used with the same initial query to
|
|
retrieve the next set of results. Setting a limit may return fewer
|
|
than the requested amount of items (up to zero items) in the event all
|
|
requested objects are filtered out and clients should only use the
|
|
presence of the continue field to determine whether more results are
|
|
available. Servers may choose not to support the limit argument and
|
|
will return all of the available results. If limit is specified and
|
|
the continue field is empty, clients may assume that no more results
|
|
are available. This field is not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit - that
|
|
is, no objects created, modified, or deleted after the first request
|
|
is issued will be included in any subsequent continued requests. This
|
|
is sometimes referred to as a consistent snapshot, and ensures that a
|
|
client that is using limit to receive smaller chunks of a very large
|
|
result can ensure they see all possible objects. If objects are
|
|
updated during a chunked list the version of the object that was
|
|
present at the time the first list result was calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a request
|
|
may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to list
|
|
calls. It is highly recommended that resourceVersionMatch be set for
|
|
list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all such
|
|
events have been sent, a synthetic "Bookmark" event will be sent. The
|
|
bookmark will report the ResourceVersion (RV) corresponding to the set
|
|
of objects, and be marked with `"k8s.io/initial-events-end": "true"`
|
|
annotation. Afterwards, the watch stream will proceed as usual,
|
|
sending watch events corresponding to changes (subsequent to the RV)
|
|
to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` = NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"` (for
|
|
backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the call,
|
|
regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
/apis/management.cattle.io/v3/projects:
|
|
get:
|
|
description: list objects of kind Project
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3ProjectForAllNamespaces
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectList'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration (generally
|
|
five to fifteen minutes) or a configuration change on the server, the
|
|
server will respond with a 410 ResourceExpired error together with a
|
|
continue token. If the client needs a consistent list, it must restart
|
|
their list without the continue field. Otherwise, the client may send
|
|
another list request with the token received with the 410 error, the
|
|
server will respond with a list starting from the next key, but from
|
|
the latest snapshot, which is inconsistent from the previous list
|
|
results - objects that are created, modified, or deleted after the
|
|
first list request will be included in the response, as long as their
|
|
keys are after the "next key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the list
|
|
metadata to a value that can be used with the same initial query to
|
|
retrieve the next set of results. Setting a limit may return fewer
|
|
than the requested amount of items (up to zero items) in the event all
|
|
requested objects are filtered out and clients should only use the
|
|
presence of the continue field to determine whether more results are
|
|
available. Servers may choose not to support the limit argument and
|
|
will return all of the available results. If limit is specified and
|
|
the continue field is empty, clients may assume that no more results
|
|
are available. This field is not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit - that
|
|
is, no objects created, modified, or deleted after the first request
|
|
is issued will be included in any subsequent continued requests. This
|
|
is sometimes referred to as a consistent snapshot, and ensures that a
|
|
client that is using limit to receive smaller chunks of a very large
|
|
result can ensure they see all possible objects. If objects are
|
|
updated during a chunked list the version of the object that was
|
|
present at the time the first list result was calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a request
|
|
may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to list
|
|
calls. It is highly recommended that resourceVersionMatch be set for
|
|
list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all such
|
|
events have been sent, a synthetic "Bookmark" event will be sent. The
|
|
bookmark will report the ResourceVersion (RV) corresponding to the set
|
|
of objects, and be marked with `"k8s.io/initial-events-end": "true"`
|
|
annotation. Afterwards, the watch stream will proceed as usual,
|
|
sending watch events corresponding to changes (subsequent to the RV)
|
|
to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` = NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"` (for
|
|
backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the call,
|
|
regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
/apis/management.cattle.io/v3/roletemplates:
|
|
get:
|
|
description: list objects of kind RoleTemplate
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: listManagementCattleIoV3RoleTemplate
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplateList'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: list
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: RoleTemplate
|
|
version: v3
|
|
post:
|
|
description: create a RoleTemplate
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: createManagementCattleIoV3RoleTemplate
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: post
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: RoleTemplate
|
|
version: v3
|
|
delete:
|
|
description: delete collection of RoleTemplate
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3CollectionRoleTemplate
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
allowWatchBookmarks requests watch events with type "BOOKMARK".
|
|
Servers that do not implement bookmarks may ignore this flag and
|
|
bookmarks are sent at the server's discretion. Clients should not
|
|
assume bookmarks are returned at any specific interval, nor may they
|
|
assume the server will send any BOOKMARK event during a session. If
|
|
this is not a watch, this field is ignored.
|
|
name: allowWatchBookmarks
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
The continue option should be set when retrieving more results from
|
|
the server. Since this value is server defined, clients may only use
|
|
the continue value from a previous query result with identical query
|
|
parameters (except for the value of continue) and the server may
|
|
reject a continue value it does not recognize. If the specified
|
|
continue value is no longer valid whether due to expiration
|
|
(generally five to fifteen minutes) or a configuration change on the
|
|
server, the server will respond with a 410 ResourceExpired error
|
|
together with a continue token. If the client needs a consistent
|
|
list, it must restart their list without the continue field.
|
|
Otherwise, the client may send another list request with the token
|
|
received with the 410 error, the server will respond with a list
|
|
starting from the next key, but from the latest snapshot, which is
|
|
inconsistent from the previous list results - objects that are
|
|
created, modified, or deleted after the first list request will be
|
|
included in the response, as long as their keys are after the "next
|
|
key".
|
|
|
|
|
|
This field is not supported when watch is true. Clients may start a
|
|
watch from the last resourceVersion value returned by the server and
|
|
not miss any modifications.
|
|
name: continue
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their fields.
|
|
Defaults to everything.
|
|
name: fieldSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
A selector to restrict the list of returned objects by their labels.
|
|
Defaults to everything.
|
|
name: labelSelector
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
limit is a maximum number of responses to return for a list call. If
|
|
more items exist, the server will set the `continue` field on the
|
|
list metadata to a value that can be used with the same initial
|
|
query to retrieve the next set of results. Setting a limit may
|
|
return fewer than the requested amount of items (up to zero items)
|
|
in the event all requested objects are filtered out and clients
|
|
should only use the presence of the continue field to determine
|
|
whether more results are available. Servers may choose not to
|
|
support the limit argument and will return all of the available
|
|
results. If limit is specified and the continue field is empty,
|
|
clients may assume that no more results are available. This field is
|
|
not supported if watch is true.
|
|
|
|
|
|
The server guarantees that the objects returned when using continue
|
|
will be identical to issuing a single list call without a limit -
|
|
that is, no objects created, modified, or deleted after the first
|
|
request is issued will be included in any subsequent continued
|
|
requests. This is sometimes referred to as a consistent snapshot,
|
|
and ensures that a client that is using limit to receive smaller
|
|
chunks of a very large result can ensure they see all possible
|
|
objects. If objects are updated during a chunked list the version of
|
|
the object that was present at the time the first list result was
|
|
calculated is returned.
|
|
name: limit
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersionMatch determines how resourceVersion is applied to
|
|
list calls. It is highly recommended that resourceVersionMatch be
|
|
set for list calls where resourceVersion is set See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersionMatch
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
`sendInitialEvents=true` may be set together with `watch=true`. In
|
|
that case, the watch stream will begin with synthetic events to
|
|
produce the current state of objects in the collection. Once all
|
|
such events have been sent, a synthetic "Bookmark" event will be
|
|
sent. The bookmark will report the ResourceVersion (RV)
|
|
corresponding to the set of objects, and be marked with
|
|
`"k8s.io/initial-events-end": "true"` annotation. Afterwards, the
|
|
watch stream will proceed as usual, sending watch events
|
|
corresponding to changes (subsequent to the RV) to objects watched.
|
|
|
|
|
|
When `sendInitialEvents` option is set, we require
|
|
`resourceVersionMatch` option to also be set. The semantic of the
|
|
watch request is as following: - `resourceVersionMatch` =
|
|
NotOlderThan
|
|
is interpreted as "data at least as new as the provided `resourceVersion`"
|
|
and the bookmark event is send when the state is synced
|
|
to a `resourceVersion` at least as fresh as the one provided by the ListOptions.
|
|
If `resourceVersion` is unset, this is interpreted as "consistent read" and the
|
|
bookmark event is send when the state is synced at least to the moment
|
|
when request started being processed.
|
|
- `resourceVersionMatch` set to any other value or unset
|
|
Invalid error is returned.
|
|
|
|
Defaults to true if `resourceVersion=""` or `resourceVersion="0"`
|
|
(for backward compatibility reasons) and to false otherwise.
|
|
name: sendInitialEvents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
Timeout for the list/watch call. This limits the duration of the
|
|
call, regardless of any activity or inactivity.
|
|
name: timeoutSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Watch for changes to the described resources and return them as a
|
|
stream of add, update, and remove notifications. Specify
|
|
resourceVersion.
|
|
name: watch
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: deletecollection
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: RoleTemplate
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
/apis/management.cattle.io/v3/roletemplates/{name}:
|
|
get:
|
|
description: read the specified RoleTemplate
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: readManagementCattleIoV3RoleTemplate
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
resourceVersion sets a constraint on what resource versions a
|
|
request may be served from. See
|
|
https://kubernetes.io/docs/reference/using-api/api-concepts/#resource-versions
|
|
for details.
|
|
|
|
|
|
Defaults to unset
|
|
name: resourceVersion
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: get
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: RoleTemplate
|
|
version: v3
|
|
put:
|
|
description: replace the specified RoleTemplate
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: replaceManagementCattleIoV3RoleTemplate
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint.
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
'201':
|
|
description: Created
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: put
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: RoleTemplate
|
|
version: v3
|
|
delete:
|
|
description: delete a RoleTemplate
|
|
consumes:
|
|
- application/json
|
|
- application/yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: deleteManagementCattleIoV3RoleTemplate
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: integer
|
|
description: >-
|
|
The duration in seconds before the object should be deleted. Value
|
|
must be non-negative integer. The value zero indicates delete
|
|
immediately. If this value is nil, the default grace period for the
|
|
specified type will be used. Defaults to a per object value if not
|
|
specified. zero means delete immediately.
|
|
name: gracePeriodSeconds
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Deprecated: please use the PropagationPolicy, this field will be
|
|
deprecated in 1.7. Should the dependent objects be orphaned. If
|
|
true/false, the "orphan" finalizer will be added to/removed from the
|
|
object's finalizers list. Either this field or PropagationPolicy may
|
|
be set, but not both.
|
|
name: orphanDependents
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
Whether and how garbage collection will be performed. Either this
|
|
field or OrphanDependents may be set, but not both. The default
|
|
policy is decided by the existing finalizer set in the
|
|
metadata.finalizers and the resource-specific default policy.
|
|
Acceptable values are: 'Orphan' - orphan the dependents;
|
|
'Background' - allow the garbage collector to delete the dependents
|
|
in the background; 'Foreground' - a cascading policy that deletes
|
|
all dependents in the foreground.
|
|
name: propagationPolicy
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'202':
|
|
description: Accepted
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Status'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: delete
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: RoleTemplate
|
|
version: v3
|
|
patch:
|
|
description: partially update the specified RoleTemplate
|
|
consumes:
|
|
- application/json-patch+json
|
|
- application/merge-patch+json
|
|
- application/apply-patch+yaml
|
|
produces:
|
|
- application/json
|
|
- application/yaml
|
|
schemes:
|
|
- https
|
|
tags:
|
|
- managementCattleIo_v3
|
|
operationId: patchManagementCattleIoV3RoleTemplate
|
|
parameters:
|
|
- name: body
|
|
in: body
|
|
required: true
|
|
schema:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Patch'
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted.
|
|
An invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are:
|
|
- All: all dry run stages will be processed
|
|
name: dryRun
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldManager is a name associated with the actor or entity that is
|
|
making these changes. The value must be less than or 128 characters
|
|
long, and only contain printable characters, as defined by
|
|
https://golang.org/pkg/unicode/#IsPrint. This field is required for
|
|
apply requests (application/apply-patch) but optional for non-apply
|
|
patch types (JsonPatch, MergePatch, StrategicMergePatch).
|
|
name: fieldManager
|
|
in: query
|
|
- uniqueItems: true
|
|
type: string
|
|
description: >-
|
|
fieldValidation instructs the server on how to handle objects in the
|
|
request (POST/PUT/PATCH) containing unknown or duplicate fields.
|
|
Valid values are: - Ignore: This will ignore any unknown fields that
|
|
are silently dropped from the object, and will ignore all but the
|
|
last duplicate field that the decoder encounters. This is the
|
|
default behavior prior to v1.23. - Warn: This will send a warning
|
|
via the standard warning response header for each unknown field that
|
|
is dropped from the object, and for each duplicate field that is
|
|
encountered. The request will still succeed if there are no other
|
|
errors, and will only persist the last of any duplicate fields. This
|
|
is the default in v1.23+ - Strict: This will fail the request with a
|
|
BadRequest error if any unknown fields would be dropped from the
|
|
object, or if any duplicate fields are present. The error returned
|
|
from the server will contain all unknown and duplicate fields
|
|
encountered.
|
|
name: fieldValidation
|
|
in: query
|
|
- uniqueItems: true
|
|
type: boolean
|
|
description: >-
|
|
Force is going to "force" Apply requests. It means user will
|
|
re-acquire conflicting fields owned by other people. Force flag must
|
|
be unset for non-apply patch requests.
|
|
name: force
|
|
in: query
|
|
responses:
|
|
'200':
|
|
description: OK
|
|
schema:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
'401':
|
|
description: Unauthorized
|
|
x-kubernetes-action: patch
|
|
x-kubernetes-group-version-kind:
|
|
group: management.cattle.io
|
|
kind: RoleTemplate
|
|
version: v3
|
|
parameters:
|
|
- uniqueItems: true
|
|
type: string
|
|
description: name of the RoleTemplate
|
|
name: name
|
|
in: path
|
|
required: true
|
|
- uniqueItems: true
|
|
type: string
|
|
description: If 'true', then the output is pretty printed.
|
|
name: pretty
|
|
in: query
|
|
definitions:
|
|
io.cattle.management.v3.ClusterRoleTemplateBinding:
|
|
description: >-
|
|
ClusterRoleTemplateBinding is the object representing membership of a
|
|
subject in a cluster with permissions specified by a given role template.
|
|
type: object
|
|
required:
|
|
- clusterName
|
|
- roleTemplateName
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
clusterName:
|
|
description: >-
|
|
ClusterName is the metadata.name of the cluster to which a subject is
|
|
added. Must match the namespace. Immutable.
|
|
type: string
|
|
groupName:
|
|
description: >-
|
|
GroupName is the name of the group subject added to the cluster.
|
|
Immutable.
|
|
type: string
|
|
groupPrincipalName:
|
|
description: >-
|
|
GroupPrincipalName is the name of the group principal subject added to
|
|
the cluster. Immutable.
|
|
type: string
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard object's metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
|
|
roleTemplateName:
|
|
description: >-
|
|
RoleTemplateName is the name of the role template that defines
|
|
permissions to perform actions on resources in the cluster. Immutable.
|
|
type: string
|
|
userName:
|
|
description: >-
|
|
UserName is the name of the user subject added to the cluster.
|
|
Immutable.
|
|
type: string
|
|
userPrincipalName:
|
|
description: >-
|
|
UserPrincipalName is the name of the user principal subject added to
|
|
the cluster. Immutable.
|
|
type: string
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: ClusterRoleTemplateBinding
|
|
version: v3
|
|
io.cattle.management.v3.ClusterRoleTemplateBindingList:
|
|
description: ClusterRoleTemplateBindingList is a list of ClusterRoleTemplateBinding
|
|
type: object
|
|
required:
|
|
- items
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
items:
|
|
description: >-
|
|
List of clusterroletemplatebindings. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
|
|
type: array
|
|
items:
|
|
$ref: '#/definitions/io.cattle.management.v3.ClusterRoleTemplateBinding'
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard list metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: ClusterRoleTemplateBindingList
|
|
version: v3
|
|
io.cattle.management.v3.GlobalRole:
|
|
description: >-
|
|
GlobalRole defines rules that can be applied to the local cluster and or
|
|
every downstream cluster.
|
|
type: object
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
builtin:
|
|
description: >-
|
|
Builtin specifies that this GlobalRole was created by Rancher if true.
|
|
Immutable.
|
|
type: boolean
|
|
description:
|
|
description: Description holds text that describes the resource.
|
|
type: string
|
|
displayName:
|
|
description: >-
|
|
DisplayName is the human-readable name displayed in the UI for this
|
|
resource.
|
|
type: string
|
|
inheritedClusterRoles:
|
|
description: >-
|
|
InheritedClusterRoles are the names of RoleTemplates whose permissions
|
|
are granted by this GlobalRole in every cluster besides the local
|
|
cluster. To grant permissions in the local cluster, use the Rules
|
|
field.
|
|
type: array
|
|
items:
|
|
type: string
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard object's metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
|
|
newUserDefault:
|
|
description: >-
|
|
NewUserDefault specifies that all new users created should be bound to
|
|
this GlobalRole if true.
|
|
type: boolean
|
|
rules:
|
|
description: >-
|
|
Rules holds a list of PolicyRules that are applied to the local
|
|
cluster only.
|
|
type: array
|
|
items:
|
|
description: >-
|
|
PolicyRule holds information that describes a policy rule, but does
|
|
not contain information about who the rule applies to or which
|
|
namespace the rule applies to.
|
|
type: object
|
|
required:
|
|
- verbs
|
|
properties:
|
|
apiGroups:
|
|
description: >-
|
|
APIGroups is the name of the APIGroup that contains the
|
|
resources. If multiple API groups are specified, any action
|
|
requested against one of the enumerated resources in any API
|
|
group will be allowed. "" represents the core API group and "*"
|
|
represents all API groups.
|
|
type: array
|
|
items:
|
|
type: string
|
|
nonResourceURLs:
|
|
description: >-
|
|
NonResourceURLs is a set of partial urls that a user should have
|
|
access to. *s are allowed, but only as the full, final step in
|
|
the path Since non-resource URLs are not namespaced, this field
|
|
is only applicable for ClusterRoles referenced from a
|
|
ClusterRoleBinding. Rules can either apply to API resources
|
|
(such as "pods" or "secrets") or non-resource URL paths (such as
|
|
"/api"), but not both.
|
|
type: array
|
|
items:
|
|
type: string
|
|
resourceNames:
|
|
description: >-
|
|
ResourceNames is an optional white list of names that the rule
|
|
applies to. An empty set means that everything is allowed.
|
|
type: array
|
|
items:
|
|
type: string
|
|
resources:
|
|
description: >-
|
|
Resources is a list of resources this rule applies to. '*'
|
|
represents all resources.
|
|
type: array
|
|
items:
|
|
type: string
|
|
verbs:
|
|
description: >-
|
|
Verbs is a list of Verbs that apply to ALL the ResourceKinds
|
|
contained in this rule. '*' represents all verbs.
|
|
type: array
|
|
items:
|
|
type: string
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: GlobalRole
|
|
version: v3
|
|
io.cattle.management.v3.GlobalRoleBinding:
|
|
description: GlobalRoleBinding binds a given subject user or group to a GlobalRole.
|
|
type: object
|
|
required:
|
|
- globalRoleName
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
globalRoleName:
|
|
description: >-
|
|
GlobalRoleName is the name of the Global Role that the subject will be
|
|
bound to. Immutable.
|
|
type: string
|
|
groupPrincipalName:
|
|
description: >-
|
|
GroupPrincipalName is the name of the group principal subject to be
|
|
bound. Immutable.
|
|
type: string
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard object's metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
|
|
userName:
|
|
description: UserName is the name of the user subject to be bound. Immutable.
|
|
type: string
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: GlobalRoleBinding
|
|
version: v3
|
|
io.cattle.management.v3.GlobalRoleBindingList:
|
|
description: GlobalRoleBindingList is a list of GlobalRoleBinding
|
|
type: object
|
|
required:
|
|
- items
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
items:
|
|
description: >-
|
|
List of globalrolebindings. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
|
|
type: array
|
|
items:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRoleBinding'
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard list metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: GlobalRoleBindingList
|
|
version: v3
|
|
io.cattle.management.v3.GlobalRoleList:
|
|
description: GlobalRoleList is a list of GlobalRole
|
|
type: object
|
|
required:
|
|
- items
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
items:
|
|
description: >-
|
|
List of globalroles. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
|
|
type: array
|
|
items:
|
|
$ref: '#/definitions/io.cattle.management.v3.GlobalRole'
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard list metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: GlobalRoleList
|
|
version: v3
|
|
io.cattle.management.v3.Project:
|
|
description: >-
|
|
Project is a group of namespaces. Projects are used to create a
|
|
multi-tenant environment within a Kubernetes cluster by managing namespace
|
|
operations, such as role assignments or quotas, as a group.
|
|
type: object
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard object's metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
|
|
spec:
|
|
description: >-
|
|
Spec is the specification of the desired configuration for the
|
|
project.
|
|
type: object
|
|
required:
|
|
- clusterName
|
|
- displayName
|
|
properties:
|
|
clusterName:
|
|
description: >-
|
|
ClusterName is the name of the cluster the project belongs to.
|
|
Immutable.
|
|
type: string
|
|
containerDefaultResourceLimit:
|
|
description: >-
|
|
ContainerDefaultResourceLimit is a specification for the default
|
|
LimitRange for the namespace. See
|
|
https://kubernetes.io/docs/concepts/policy/limit-range/ for more
|
|
details.
|
|
type: object
|
|
properties:
|
|
limitsCpu:
|
|
description: >-
|
|
LimitsCPU is the CPU limits across all pods in a non-terminal
|
|
state.
|
|
type: string
|
|
limitsMemory:
|
|
description: >-
|
|
LimitsMemory is the memory limits across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
requestsCpu:
|
|
description: >-
|
|
RequestsCPU is the CPU requests limit across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
requestsMemory:
|
|
description: >-
|
|
RequestsMemory is the memory requests limit across all pods in
|
|
a non-terminal state.
|
|
type: string
|
|
description:
|
|
description: Description is a human-readable description of the project.
|
|
type: string
|
|
displayName:
|
|
description: DisplayName is the human-readable name for the project.
|
|
type: string
|
|
enableProjectMonitoring:
|
|
description: >-
|
|
EnableProjectMonitoring indicates whether Monitoring V1 should be
|
|
enabled for this project. Deprecated. Use the Monitoring V2 app
|
|
instead. Defaults to false.
|
|
type: boolean
|
|
namespaceDefaultResourceQuota:
|
|
description: >-
|
|
NamespaceDefaultResourceQuota is a specification of the default
|
|
ResourceQuota that a namespace will receive if none is provided.
|
|
Must provide ResourceQuota if NamespaceDefaultResourceQuota is
|
|
specified. See
|
|
https://kubernetes.io/docs/concepts/policy/resource-quotas/ for
|
|
more details.
|
|
type: object
|
|
properties:
|
|
limit:
|
|
description: Limit is the default quota limits applied to new namespaces.
|
|
type: object
|
|
properties:
|
|
configMaps:
|
|
description: >-
|
|
ConfigMaps is the total number of ReplicationControllers
|
|
that can exist in the namespace.
|
|
type: string
|
|
limitsCpu:
|
|
description: >-
|
|
LimitsCPU is the CPU limits across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
limitsMemory:
|
|
description: >-
|
|
LimitsMemory is the memory limits across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
persistentVolumeClaims:
|
|
description: >-
|
|
PersistentVolumeClaims is the total number of
|
|
PersistentVolumeClaims that can exist in the namespace.
|
|
type: string
|
|
pods:
|
|
description: >-
|
|
Pods is the total number of Pods in a non-terminal state
|
|
that can exist in the namespace. A pod is in a terminal
|
|
state if .status.phase in (Failed, Succeeded) is true.
|
|
type: string
|
|
replicationControllers:
|
|
description: >-
|
|
ReplicationControllers is total number of
|
|
ReplicationControllers that can exist in the namespace.
|
|
type: string
|
|
requestsCpu:
|
|
description: >-
|
|
RequestsCPU is the CPU requests limit across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
requestsMemory:
|
|
description: >-
|
|
RequestsMemory is the memory requests limit across all
|
|
pods in a non-terminal state.
|
|
type: string
|
|
requestsStorage:
|
|
description: >-
|
|
RequestsStorage is the storage requests limit across all
|
|
persistent volume claims.
|
|
type: string
|
|
secrets:
|
|
description: >-
|
|
Secrets is the total number of ReplicationControllers that
|
|
can exist in the namespace.
|
|
type: string
|
|
services:
|
|
description: >-
|
|
Services is the total number of Services that can exist in
|
|
the namespace.
|
|
type: string
|
|
servicesLoadBalancers:
|
|
description: >-
|
|
ServicesLoadBalancers is the total number of Services of
|
|
type LoadBalancer that can exist in the namespace.
|
|
type: string
|
|
servicesNodePorts:
|
|
description: >-
|
|
ServiceNodePorts is the total number of Services of type
|
|
NodePort that can exist in the namespace.
|
|
type: string
|
|
resourceQuota:
|
|
description: >-
|
|
ResourceQuota is a specification for the total amount of quota for
|
|
standard resources that will be shared by all namespaces in the
|
|
project. Must provide NamespaceDefaultResourceQuota if
|
|
ResourceQuota is specified. See
|
|
https://kubernetes.io/docs/concepts/policy/resource-quotas/ for
|
|
more details.
|
|
type: object
|
|
properties:
|
|
limit:
|
|
description: >-
|
|
Limit is the total allowable quota limits shared by all
|
|
namespaces in the project.
|
|
type: object
|
|
properties:
|
|
configMaps:
|
|
description: >-
|
|
ConfigMaps is the total number of ReplicationControllers
|
|
that can exist in the namespace.
|
|
type: string
|
|
limitsCpu:
|
|
description: >-
|
|
LimitsCPU is the CPU limits across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
limitsMemory:
|
|
description: >-
|
|
LimitsMemory is the memory limits across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
persistentVolumeClaims:
|
|
description: >-
|
|
PersistentVolumeClaims is the total number of
|
|
PersistentVolumeClaims that can exist in the namespace.
|
|
type: string
|
|
pods:
|
|
description: >-
|
|
Pods is the total number of Pods in a non-terminal state
|
|
that can exist in the namespace. A pod is in a terminal
|
|
state if .status.phase in (Failed, Succeeded) is true.
|
|
type: string
|
|
replicationControllers:
|
|
description: >-
|
|
ReplicationControllers is total number of
|
|
ReplicationControllers that can exist in the namespace.
|
|
type: string
|
|
requestsCpu:
|
|
description: >-
|
|
RequestsCPU is the CPU requests limit across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
requestsMemory:
|
|
description: >-
|
|
RequestsMemory is the memory requests limit across all
|
|
pods in a non-terminal state.
|
|
type: string
|
|
requestsStorage:
|
|
description: >-
|
|
RequestsStorage is the storage requests limit across all
|
|
persistent volume claims.
|
|
type: string
|
|
secrets:
|
|
description: >-
|
|
Secrets is the total number of ReplicationControllers that
|
|
can exist in the namespace.
|
|
type: string
|
|
services:
|
|
description: >-
|
|
Services is the total number of Services that can exist in
|
|
the namespace.
|
|
type: string
|
|
servicesLoadBalancers:
|
|
description: >-
|
|
ServicesLoadBalancers is the total number of Services of
|
|
type LoadBalancer that can exist in the namespace.
|
|
type: string
|
|
servicesNodePorts:
|
|
description: >-
|
|
ServiceNodePorts is the total number of Services of type
|
|
NodePort that can exist in the namespace.
|
|
type: string
|
|
usedLimit:
|
|
description: >-
|
|
UsedLimit is the currently allocated quota for all namespaces
|
|
in the project.
|
|
type: object
|
|
properties:
|
|
configMaps:
|
|
description: >-
|
|
ConfigMaps is the total number of ReplicationControllers
|
|
that can exist in the namespace.
|
|
type: string
|
|
limitsCpu:
|
|
description: >-
|
|
LimitsCPU is the CPU limits across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
limitsMemory:
|
|
description: >-
|
|
LimitsMemory is the memory limits across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
persistentVolumeClaims:
|
|
description: >-
|
|
PersistentVolumeClaims is the total number of
|
|
PersistentVolumeClaims that can exist in the namespace.
|
|
type: string
|
|
pods:
|
|
description: >-
|
|
Pods is the total number of Pods in a non-terminal state
|
|
that can exist in the namespace. A pod is in a terminal
|
|
state if .status.phase in (Failed, Succeeded) is true.
|
|
type: string
|
|
replicationControllers:
|
|
description: >-
|
|
ReplicationControllers is total number of
|
|
ReplicationControllers that can exist in the namespace.
|
|
type: string
|
|
requestsCpu:
|
|
description: >-
|
|
RequestsCPU is the CPU requests limit across all pods in a
|
|
non-terminal state.
|
|
type: string
|
|
requestsMemory:
|
|
description: >-
|
|
RequestsMemory is the memory requests limit across all
|
|
pods in a non-terminal state.
|
|
type: string
|
|
requestsStorage:
|
|
description: >-
|
|
RequestsStorage is the storage requests limit across all
|
|
persistent volume claims.
|
|
type: string
|
|
secrets:
|
|
description: >-
|
|
Secrets is the total number of ReplicationControllers that
|
|
can exist in the namespace.
|
|
type: string
|
|
services:
|
|
description: >-
|
|
Services is the total number of Services that can exist in
|
|
the namespace.
|
|
type: string
|
|
servicesLoadBalancers:
|
|
description: >-
|
|
ServicesLoadBalancers is the total number of Services of
|
|
type LoadBalancer that can exist in the namespace.
|
|
type: string
|
|
servicesNodePorts:
|
|
description: >-
|
|
ServiceNodePorts is the total number of Services of type
|
|
NodePort that can exist in the namespace.
|
|
type: string
|
|
status:
|
|
description: Status is the most recently observed status of the project.
|
|
type: object
|
|
properties:
|
|
conditions:
|
|
description: Conditions are a set of indicators about aspects of the project.
|
|
type: array
|
|
items:
|
|
description: ProjectCondition is the status of an aspect of the project.
|
|
type: object
|
|
required:
|
|
- status
|
|
- type
|
|
properties:
|
|
lastTransitionTime:
|
|
description: >-
|
|
Last time the condition transitioned from one status to
|
|
another.
|
|
type: string
|
|
lastUpdateTime:
|
|
description: The last time this condition was updated.
|
|
type: string
|
|
message:
|
|
description: >-
|
|
Human-readable message indicating details about last
|
|
transition.
|
|
type: string
|
|
reason:
|
|
description: The reason for the condition's last transition.
|
|
type: string
|
|
status:
|
|
description: Status of the condition, one of True, False, Unknown.
|
|
type: string
|
|
type:
|
|
description: Type of project condition.
|
|
type: string
|
|
monitoringStatus:
|
|
description: MonitoringStatus is the status of the Monitoring V1 app.
|
|
type: object
|
|
properties:
|
|
conditions:
|
|
type: array
|
|
items:
|
|
type: object
|
|
required:
|
|
- status
|
|
- type
|
|
properties:
|
|
lastTransitionTime:
|
|
description: >-
|
|
Last time the condition transitioned from one status to
|
|
another.
|
|
type: string
|
|
lastUpdateTime:
|
|
description: The last time this condition was updated.
|
|
type: string
|
|
message:
|
|
description: >-
|
|
Human-readable message indicating details about last
|
|
transition
|
|
type: string
|
|
reason:
|
|
description: The reason for the condition's last transition.
|
|
type: string
|
|
status:
|
|
description: Status of the condition, one of True, False, Unknown.
|
|
type: string
|
|
type:
|
|
description: Type of cluster condition.
|
|
type: string
|
|
grafanaEndpoint:
|
|
type: string
|
|
podSecurityPolicyTemplateId:
|
|
description: >-
|
|
PodSecurityPolicyTemplateName is the pod security policy template
|
|
associated with the project.
|
|
type: string
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: Project
|
|
version: v3
|
|
io.cattle.management.v3.ProjectList:
|
|
description: ProjectList is a list of Project
|
|
type: object
|
|
required:
|
|
- items
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
items:
|
|
description: >-
|
|
List of projects. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
|
|
type: array
|
|
items:
|
|
$ref: '#/definitions/io.cattle.management.v3.Project'
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard list metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: ProjectList
|
|
version: v3
|
|
io.cattle.management.v3.ProjectRoleTemplateBinding:
|
|
description: >-
|
|
ProjectRoleTemplateBinding is the object representing membership of a
|
|
subject in a project with permissions specified by a given role template.
|
|
type: object
|
|
required:
|
|
- projectName
|
|
- roleTemplateName
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
groupName:
|
|
description: >-
|
|
GroupName is the name of the group subject added to the project.
|
|
Immutable.
|
|
type: string
|
|
groupPrincipalName:
|
|
description: >-
|
|
GroupPrincipalName is the name of the group principal subject added to
|
|
the project. Immutable.
|
|
type: string
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard object's metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
|
|
projectName:
|
|
description: >-
|
|
ProjectName is the name of the project to which a subject is added.
|
|
Immutable.
|
|
type: string
|
|
roleTemplateName:
|
|
description: >-
|
|
RoleTemplateName is the name of the role template that defines
|
|
permissions to perform actions on resources in the project. Immutable.
|
|
type: string
|
|
serviceAccount:
|
|
description: >-
|
|
ServiceAccount is the name of the service account bound as a subject.
|
|
Immutable. Deprecated.
|
|
type: string
|
|
userName:
|
|
description: >-
|
|
UserName is the name of the user subject added to the project.
|
|
Immutable.
|
|
type: string
|
|
userPrincipalName:
|
|
description: >-
|
|
UserPrincipalName is the name of the user principal subject added to
|
|
the project. Immutable.
|
|
type: string
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: ProjectRoleTemplateBinding
|
|
version: v3
|
|
io.cattle.management.v3.ProjectRoleTemplateBindingList:
|
|
description: ProjectRoleTemplateBindingList is a list of ProjectRoleTemplateBinding
|
|
type: object
|
|
required:
|
|
- items
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
items:
|
|
description: >-
|
|
List of projectroletemplatebindings. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
|
|
type: array
|
|
items:
|
|
$ref: '#/definitions/io.cattle.management.v3.ProjectRoleTemplateBinding'
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard list metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: ProjectRoleTemplateBindingList
|
|
version: v3
|
|
io.cattle.management.v3.RoleTemplate:
|
|
description: >-
|
|
RoleTemplate holds configuration for a template that is used to create
|
|
kubernetes Roles and ClusterRoles (in the rbac.authorization.k8s.io group)
|
|
for a cluster or project.
|
|
type: object
|
|
properties:
|
|
administrative:
|
|
description: >-
|
|
Administrative if false, and context is set to cluster this
|
|
RoleTemplate will not grant access to "CatalogTemplates" and
|
|
"CatalogTemplateVersions" for any project in the cluster. Default is
|
|
false.
|
|
type: boolean
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
builtin:
|
|
description: >-
|
|
Builtin if true specifies that this RoleTemplate was created by
|
|
Rancher and is immutable. Default to false.
|
|
type: boolean
|
|
clusterCreatorDefault:
|
|
description: >-
|
|
ClusterCreatorDefault if true, a binding with this RoleTemplate will
|
|
be created for a users when they create a new cluster.
|
|
ClusterCreatorDefault is only evaluated if the context of the
|
|
RoleTemplate is set to cluster. Default to false.
|
|
type: boolean
|
|
context:
|
|
description: >-
|
|
Context describes if the roleTemplate applies to clusters or projects.
|
|
Valid values are "project", "cluster" or "".
|
|
type: string
|
|
enum:
|
|
- project
|
|
- cluster
|
|
- ''
|
|
description:
|
|
description: Description holds text that describes the resource.
|
|
type: string
|
|
displayName:
|
|
description: >-
|
|
DisplayName is the human-readable name displayed in the UI for this
|
|
resource.
|
|
type: string
|
|
external:
|
|
description: >-
|
|
External if true specifies that rules for this RoleTemplate should be
|
|
gathered from a ClusterRole with the matching name. If set to true the
|
|
Rules on the template will not be evaluated. External's value is only
|
|
evaluated if the RoleTemplate's context is set to "cluster" Default to
|
|
false.
|
|
type: boolean
|
|
hidden:
|
|
description: >-
|
|
Hidden if true informs the Rancher UI not to display this
|
|
RoleTemplate. Default to false.
|
|
type: boolean
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
locked:
|
|
description: >-
|
|
Locked if true, new bindings will not be able to use this
|
|
RoleTemplate. Default to false.
|
|
type: boolean
|
|
metadata:
|
|
description: >-
|
|
Standard object's metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta'
|
|
projectCreatorDefault:
|
|
description: >-
|
|
ProjectCreatorDefault if true, a binding with this RoleTemplate will
|
|
be created for a user when they create a new project.
|
|
ProjectCreatorDefault is only evaluated if the context of the
|
|
RoleTemplate is set to project. Default to false.
|
|
type: boolean
|
|
roleTemplateNames:
|
|
description: >-
|
|
RoleTemplateNames list of RoleTemplate names that this RoleTemplate
|
|
will inherit. This RoleTemplate will grant all rules defined in an
|
|
inherited RoleTemplate. Inherited RoleTemplates must already exist.
|
|
type: array
|
|
items:
|
|
type: string
|
|
rules:
|
|
description: Rules hold all the PolicyRules for this RoleTemplate.
|
|
type: array
|
|
items:
|
|
description: >-
|
|
PolicyRule holds information that describes a policy rule, but does
|
|
not contain information about who the rule applies to or which
|
|
namespace the rule applies to.
|
|
type: object
|
|
required:
|
|
- verbs
|
|
properties:
|
|
apiGroups:
|
|
description: >-
|
|
APIGroups is the name of the APIGroup that contains the
|
|
resources. If multiple API groups are specified, any action
|
|
requested against one of the enumerated resources in any API
|
|
group will be allowed. "" represents the core API group and "*"
|
|
represents all API groups.
|
|
type: array
|
|
items:
|
|
type: string
|
|
nonResourceURLs:
|
|
description: >-
|
|
NonResourceURLs is a set of partial urls that a user should have
|
|
access to. *s are allowed, but only as the full, final step in
|
|
the path Since non-resource URLs are not namespaced, this field
|
|
is only applicable for ClusterRoles referenced from a
|
|
ClusterRoleBinding. Rules can either apply to API resources
|
|
(such as "pods" or "secrets") or non-resource URL paths (such as
|
|
"/api"), but not both.
|
|
type: array
|
|
items:
|
|
type: string
|
|
resourceNames:
|
|
description: >-
|
|
ResourceNames is an optional white list of names that the rule
|
|
applies to. An empty set means that everything is allowed.
|
|
type: array
|
|
items:
|
|
type: string
|
|
resources:
|
|
description: >-
|
|
Resources is a list of resources this rule applies to. '*'
|
|
represents all resources.
|
|
type: array
|
|
items:
|
|
type: string
|
|
verbs:
|
|
description: >-
|
|
Verbs is a list of Verbs that apply to ALL the ResourceKinds
|
|
contained in this rule. '*' represents all verbs.
|
|
type: array
|
|
items:
|
|
type: string
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: RoleTemplate
|
|
version: v3
|
|
io.cattle.management.v3.RoleTemplateList:
|
|
description: RoleTemplateList is a list of RoleTemplate
|
|
type: object
|
|
required:
|
|
- items
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
items:
|
|
description: >-
|
|
List of roletemplates. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md
|
|
type: array
|
|
items:
|
|
$ref: '#/definitions/io.cattle.management.v3.RoleTemplate'
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard list metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
|
|
x-kubernetes-group-version-kind:
|
|
- group: management.cattle.io
|
|
kind: RoleTemplateList
|
|
version: v3
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.DeleteOptions:
|
|
description: DeleteOptions may be provided when deleting an API object.
|
|
type: object
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
dryRun:
|
|
description: >-
|
|
When present, indicates that modifications should not be persisted. An
|
|
invalid or unrecognized dryRun directive will result in an error
|
|
response and no further processing of the request. Valid values are: -
|
|
All: all dry run stages will be processed
|
|
type: array
|
|
items:
|
|
type: string
|
|
gracePeriodSeconds:
|
|
description: >-
|
|
The duration in seconds before the object should be deleted. Value
|
|
must be non-negative integer. The value zero indicates delete
|
|
immediately. If this value is nil, the default grace period for the
|
|
specified type will be used. Defaults to a per object value if not
|
|
specified. zero means delete immediately.
|
|
type: integer
|
|
format: int64
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
orphanDependents:
|
|
description: >-
|
|
Deprecated: please use the PropagationPolicy, this field will be
|
|
deprecated in 1.7. Should the dependent objects be orphaned. If
|
|
true/false, the "orphan" finalizer will be added to/removed from the
|
|
object's finalizers list. Either this field or PropagationPolicy may
|
|
be set, but not both.
|
|
type: boolean
|
|
preconditions:
|
|
description: >-
|
|
Must be fulfilled before a deletion is carried out. If not possible, a
|
|
409 Conflict status will be returned.
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Preconditions'
|
|
propagationPolicy:
|
|
description: >-
|
|
Whether and how garbage collection will be performed. Either this
|
|
field or OrphanDependents may be set, but not both. The default policy
|
|
is decided by the existing finalizer set in the metadata.finalizers
|
|
and the resource-specific default policy. Acceptable values are:
|
|
'Orphan' - orphan the dependents; 'Background' - allow the garbage
|
|
collector to delete the dependents in the background; 'Foreground' - a
|
|
cascading policy that deletes all dependents in the foreground.
|
|
type: string
|
|
x-kubernetes-group-version-kind:
|
|
- group: ''
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: admission.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: admission.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: admissionregistration.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: admissionregistration.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: admissionregistration.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: apiextensions.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: apiextensions.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: apiregistration.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: apiregistration.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: apps
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: apps
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: apps
|
|
kind: DeleteOptions
|
|
version: v1beta2
|
|
- group: authentication.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: authentication.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: authentication.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: authorization.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: authorization.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: autoscaling
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: autoscaling
|
|
kind: DeleteOptions
|
|
version: v2
|
|
- group: autoscaling
|
|
kind: DeleteOptions
|
|
version: v2beta1
|
|
- group: autoscaling
|
|
kind: DeleteOptions
|
|
version: v2beta2
|
|
- group: batch
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: batch
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: certificates.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: certificates.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: certificates.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: coordination.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: coordination.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: discovery.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: discovery.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: events.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: events.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: extensions
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: flowcontrol.apiserver.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: flowcontrol.apiserver.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: flowcontrol.apiserver.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta2
|
|
- group: flowcontrol.apiserver.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta3
|
|
- group: imagepolicy.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: internal.apiserver.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: networking.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: networking.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: networking.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: node.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: node.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: node.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: policy
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: policy
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: rbac.authorization.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: rbac.authorization.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: rbac.authorization.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: resource.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha2
|
|
- group: scheduling.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: scheduling.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: scheduling.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
- group: storage.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1
|
|
- group: storage.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1alpha1
|
|
- group: storage.k8s.io
|
|
kind: DeleteOptions
|
|
version: v1beta1
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.FieldsV1:
|
|
description: >-
|
|
FieldsV1 stores a set of fields in a data structure like a Trie, in JSON
|
|
format.
|
|
|
|
|
|
Each key is either a '.' representing the field itself, and will always
|
|
map to an empty set, or a string representing a sub-field or item. The
|
|
string will follow one of these four formats: 'f:<name>', where <name> is
|
|
the name of a field in a struct, or key in a map 'v:<value>', where
|
|
<value> is the exact json formatted value of a list item 'i:<index>',
|
|
where <index> is position of a item in a list 'k:<keys>', where <keys> is
|
|
a map of a list item's key fields to their unique values If a key maps to
|
|
an empty Fields value, the field that key represents is part of the set.
|
|
|
|
|
|
The exact format is defined in sigs.k8s.io/structured-merge-diff
|
|
type: object
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta:
|
|
description: >-
|
|
ListMeta describes metadata that synthetic resources must have, including
|
|
lists and various status objects. A resource may have only one of
|
|
{ObjectMeta, ListMeta}.
|
|
type: object
|
|
properties:
|
|
continue:
|
|
description: >-
|
|
continue may be set if the user set a limit on the number of items
|
|
returned, and indicates that the server has more data available. The
|
|
value is opaque and may be used to issue another request to the
|
|
endpoint that served this list to retrieve the next set of available
|
|
objects. Continuing a consistent list may not be possible if the
|
|
server configuration has changed or more than a few minutes have
|
|
passed. The resourceVersion field returned when using this continue
|
|
value will be identical to the value in the first response, unless you
|
|
have received this token from an error message.
|
|
type: string
|
|
remainingItemCount:
|
|
description: >-
|
|
remainingItemCount is the number of subsequent items in the list which
|
|
are not included in this list response. If the list request contained
|
|
label or field selectors, then the number of remaining items is
|
|
unknown and the field will be left unset and omitted during
|
|
serialization. If the list is complete (either because it is not
|
|
chunking or because this is the last chunk), then there are no more
|
|
remaining items and this field will be left unset and omitted during
|
|
serialization. Servers older than v1.15 do not set this field. The
|
|
intended use of the remainingItemCount is *estimating* the size of a
|
|
collection. Clients should not rely on the remainingItemCount to be
|
|
set or to be exact.
|
|
type: integer
|
|
format: int64
|
|
resourceVersion:
|
|
description: >-
|
|
String that identifies the server's internal version of this object
|
|
that can be used by clients to determine when objects have changed.
|
|
Value must be treated as opaque by clients and passed unmodified back
|
|
to the server. Populated by the system. Read-only. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
|
|
type: string
|
|
selfLink:
|
|
description: >-
|
|
Deprecated: selfLink is a legacy read-only field that is no longer
|
|
populated by the system.
|
|
type: string
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.ManagedFieldsEntry:
|
|
description: >-
|
|
ManagedFieldsEntry is a workflow-id, a FieldSet and the group version of
|
|
the resource that the fieldset applies to.
|
|
type: object
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the version of this resource that this field set
|
|
applies to. The format is "group/version" just like the top-level
|
|
APIVersion field. It is necessary to track the version of a field set
|
|
because it cannot be automatically converted.
|
|
type: string
|
|
fieldsType:
|
|
description: >-
|
|
FieldsType is the discriminator for the different fields format and
|
|
version. There is currently only one possible value: "FieldsV1"
|
|
type: string
|
|
fieldsV1:
|
|
description: >-
|
|
FieldsV1 holds the first JSON version format as described in the
|
|
"FieldsV1" type.
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.FieldsV1'
|
|
manager:
|
|
description: Manager is an identifier of the workflow managing these fields.
|
|
type: string
|
|
operation:
|
|
description: >-
|
|
Operation is the type of operation which lead to this
|
|
ManagedFieldsEntry being created. The only valid values for this field
|
|
are 'Apply' and 'Update'.
|
|
type: string
|
|
subresource:
|
|
description: >-
|
|
Subresource is the name of the subresource used to update that object,
|
|
or empty string if the object was updated through the main resource.
|
|
The value of this field is used to distinguish between managers, even
|
|
if they share the same name. For example, a status update will be
|
|
distinct from a regular update using the same manager name. Note that
|
|
the APIVersion field is not related to the Subresource field and it
|
|
always corresponds to the version of the main resource.
|
|
type: string
|
|
time:
|
|
description: >-
|
|
Time is the timestamp of when the ManagedFields entry was added. The
|
|
timestamp will also be updated if a field is added, the manager
|
|
changes any of the owned fields value or removes a field. The
|
|
timestamp does not update when a field is removed from the entry
|
|
because another manager took it over.
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Time'
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.ObjectMeta:
|
|
description: >-
|
|
ObjectMeta is metadata that all persisted resources must have, which
|
|
includes all objects users must create.
|
|
type: object
|
|
properties:
|
|
annotations:
|
|
description: >-
|
|
Annotations is an unstructured key value map stored with a resource
|
|
that may be set by external tools to store and retrieve arbitrary
|
|
metadata. They are not queryable and should be preserved when
|
|
modifying objects. More info:
|
|
https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations
|
|
type: object
|
|
additionalProperties:
|
|
type: string
|
|
creationTimestamp:
|
|
description: >-
|
|
CreationTimestamp is a timestamp representing the server time when
|
|
this object was created. It is not guaranteed to be set in
|
|
happens-before order across separate operations. Clients may not set
|
|
this value. It is represented in RFC3339 form and is in UTC.
|
|
|
|
|
|
Populated by the system. Read-only. Null for lists. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Time'
|
|
deletionGracePeriodSeconds:
|
|
description: >-
|
|
Number of seconds allowed for this object to gracefully terminate
|
|
before it will be removed from the system. Only set when
|
|
deletionTimestamp is also set. May only be shortened. Read-only.
|
|
type: integer
|
|
format: int64
|
|
deletionTimestamp:
|
|
description: >-
|
|
DeletionTimestamp is RFC 3339 date and time at which this resource
|
|
will be deleted. This field is set by the server when a graceful
|
|
deletion is requested by the user, and is not directly settable by a
|
|
client. The resource is expected to be deleted (no longer visible from
|
|
resource lists, and not reachable by name) after the time in this
|
|
field, once the finalizers list is empty. As long as the finalizers
|
|
list contains items, deletion is blocked. Once the deletionTimestamp
|
|
is set, this value may not be unset or be set further into the future,
|
|
although it may be shortened or the resource may be deleted prior to
|
|
this time. For example, a user may request that a pod is deleted in 30
|
|
seconds. The Kubelet will react by sending a graceful termination
|
|
signal to the containers in the pod. After that 30 seconds, the
|
|
Kubelet will send a hard termination signal (SIGKILL) to the container
|
|
and after cleanup, remove the pod from the API. In the presence of
|
|
network partitions, this object may still exist after this timestamp,
|
|
until an administrator or automated process can determine the resource
|
|
is fully terminated. If not set, graceful deletion of the object has
|
|
not been requested.
|
|
|
|
|
|
Populated by the system when a graceful deletion is requested.
|
|
Read-only. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.Time'
|
|
finalizers:
|
|
description: >-
|
|
Must be empty before the object is deleted from the registry. Each
|
|
entry is an identifier for the responsible component that will remove
|
|
the entry from the list. If the deletionTimestamp of the object is
|
|
non-nil, entries in this list can only be removed. Finalizers may be
|
|
processed and removed in any order. Order is NOT enforced because it
|
|
introduces significant risk of stuck finalizers. finalizers is a
|
|
shared field, any actor with permission can reorder it. If the
|
|
finalizer list is processed in order, then this can lead to a
|
|
situation in which the component responsible for the first finalizer
|
|
in the list is waiting for a signal (field value, external system, or
|
|
other) produced by a component responsible for a finalizer later in
|
|
the list, resulting in a deadlock. Without enforced ordering
|
|
finalizers are free to order amongst themselves and are not vulnerable
|
|
to ordering changes in the list.
|
|
type: array
|
|
items:
|
|
type: string
|
|
x-kubernetes-patch-strategy: merge
|
|
generateName:
|
|
description: >-
|
|
GenerateName is an optional prefix, used by the server, to generate a
|
|
unique name ONLY IF the Name field has not been provided. If this
|
|
field is used, the name returned to the client will be different than
|
|
the name passed. This value will also be combined with a unique
|
|
suffix. The provided value has the same validation rules as the Name
|
|
field, and may be truncated by the length of the suffix required to
|
|
make the value unique on the server.
|
|
|
|
|
|
If this field is specified and the generated name exists, the server
|
|
will return a 409.
|
|
|
|
|
|
Applied only if Name is not specified. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#idempotency
|
|
type: string
|
|
generation:
|
|
description: >-
|
|
A sequence number representing a specific generation of the desired
|
|
state. Populated by the system. Read-only.
|
|
type: integer
|
|
format: int64
|
|
labels:
|
|
description: >-
|
|
Map of string keys and values that can be used to organize and
|
|
categorize (scope and select) objects. May match selectors of
|
|
replication controllers and services. More info:
|
|
https://kubernetes.io/docs/concepts/overview/working-with-objects/labels
|
|
type: object
|
|
additionalProperties:
|
|
type: string
|
|
managedFields:
|
|
description: >-
|
|
ManagedFields maps workflow-id and version to the set of fields that
|
|
are managed by that workflow. This is mostly for internal
|
|
housekeeping, and users typically shouldn't need to set or understand
|
|
this field. A workflow can be the user's name, a controller's name, or
|
|
the name of a specific apply path like "ci-cd". The set of fields is
|
|
always in the version that the workflow used when modifying the
|
|
object.
|
|
type: array
|
|
items:
|
|
$ref: >-
|
|
#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ManagedFieldsEntry
|
|
name:
|
|
description: >-
|
|
Name must be unique within a namespace. Is required when creating
|
|
resources, although some resources may allow a client to request the
|
|
generation of an appropriate name automatically. Name is primarily
|
|
intended for creation idempotence and configuration definition. Cannot
|
|
be updated. More info:
|
|
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#names
|
|
type: string
|
|
namespace:
|
|
description: >-
|
|
Namespace defines the space within which each name must be unique. An
|
|
empty namespace is equivalent to the "default" namespace, but
|
|
"default" is the canonical representation. Not all objects are
|
|
required to be scoped to a namespace - the value of this field for
|
|
those objects will be empty.
|
|
|
|
|
|
Must be a DNS_LABEL. Cannot be updated. More info:
|
|
https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces
|
|
type: string
|
|
ownerReferences:
|
|
description: >-
|
|
List of objects depended by this object. If ALL objects in the list
|
|
have been deleted, this object will be garbage collected. If this
|
|
object is managed by a controller, then an entry in this list will
|
|
point to this controller, with the controller field set to true. There
|
|
cannot be more than one managing controller.
|
|
type: array
|
|
items:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.OwnerReference'
|
|
x-kubernetes-patch-merge-key: uid
|
|
x-kubernetes-patch-strategy: merge
|
|
resourceVersion:
|
|
description: >-
|
|
An opaque value that represents the internal version of this object
|
|
that can be used by clients to determine when objects have changed.
|
|
May be used for optimistic concurrency, change detection, and the
|
|
watch operation on a resource or set of resources. Clients must treat
|
|
these values as opaque and passed unmodified back to the server. They
|
|
may only be valid for a particular resource or set of resources.
|
|
|
|
|
|
Populated by the system. Read-only. Value must be treated as opaque by
|
|
clients and . More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency
|
|
type: string
|
|
selfLink:
|
|
description: >-
|
|
Deprecated: selfLink is a legacy read-only field that is no longer
|
|
populated by the system.
|
|
type: string
|
|
uid:
|
|
description: >-
|
|
UID is the unique in time and space value for this object. It is
|
|
typically generated by the server on successful creation of a resource
|
|
and is not allowed to change on PUT operations.
|
|
|
|
|
|
Populated by the system. Read-only. More info:
|
|
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#uids
|
|
type: string
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.OwnerReference:
|
|
description: >-
|
|
OwnerReference contains enough information to let you identify an owning
|
|
object. An owning object must be in the same namespace as the dependent,
|
|
or be cluster-scoped, so there is no namespace field.
|
|
type: object
|
|
required:
|
|
- apiVersion
|
|
- kind
|
|
- name
|
|
- uid
|
|
properties:
|
|
apiVersion:
|
|
description: API version of the referent.
|
|
type: string
|
|
blockOwnerDeletion:
|
|
description: >-
|
|
If true, AND if the owner has the "foregroundDeletion" finalizer, then
|
|
the owner cannot be deleted from the key-value store until this
|
|
reference is removed. See
|
|
https://kubernetes.io/docs/concepts/architecture/garbage-collection/#foreground-deletion
|
|
for how the garbage collector interacts with this field and enforces
|
|
the foreground deletion. Defaults to false. To set this field, a user
|
|
needs "delete" permission of the owner, otherwise 422 (Unprocessable
|
|
Entity) will be returned.
|
|
type: boolean
|
|
controller:
|
|
description: If true, this reference points to the managing controller.
|
|
type: boolean
|
|
kind:
|
|
description: >-
|
|
Kind of the referent. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
name:
|
|
description: >-
|
|
Name of the referent. More info:
|
|
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#names
|
|
type: string
|
|
uid:
|
|
description: >-
|
|
UID of the referent. More info:
|
|
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#uids
|
|
type: string
|
|
x-kubernetes-map-type: atomic
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.Patch:
|
|
description: >-
|
|
Patch is provided to give a concrete name and type to the Kubernetes PATCH
|
|
request body.
|
|
type: object
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.Preconditions:
|
|
description: >-
|
|
Preconditions must be fulfilled before an operation (update, delete, etc.)
|
|
is carried out.
|
|
type: object
|
|
properties:
|
|
resourceVersion:
|
|
description: Specifies the target ResourceVersion
|
|
type: string
|
|
uid:
|
|
description: Specifies the target UID.
|
|
type: string
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.Status:
|
|
description: Status is a return value for calls that don't return other objects.
|
|
type: object
|
|
properties:
|
|
apiVersion:
|
|
description: >-
|
|
APIVersion defines the versioned schema of this representation of an
|
|
object. Servers should convert recognized schemas to the latest
|
|
internal value, and may reject unrecognized values. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
|
|
type: string
|
|
code:
|
|
description: Suggested HTTP return code for this status, 0 if not set.
|
|
type: integer
|
|
format: int32
|
|
details:
|
|
description: >-
|
|
Extended data associated with the reason. Each reason may define its
|
|
own extended details. This field is optional and the data returned is
|
|
not guaranteed to conform to any schema except that defined by the
|
|
reason type.
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.StatusDetails'
|
|
kind:
|
|
description: >-
|
|
Kind is a string value representing the REST resource this object
|
|
represents. Servers may infer this from the endpoint the client
|
|
submits requests to. Cannot be updated. In CamelCase. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
message:
|
|
description: A human-readable description of the status of this operation.
|
|
type: string
|
|
metadata:
|
|
description: >-
|
|
Standard list metadata. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.ListMeta'
|
|
reason:
|
|
description: >-
|
|
A machine-readable description of why this operation is in the
|
|
"Failure" status. If this value is empty there is no information
|
|
available. A Reason clarifies an HTTP status code but does not
|
|
override it.
|
|
type: string
|
|
status:
|
|
description: >-
|
|
Status of the operation. One of: "Success" or "Failure". More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
|
|
type: string
|
|
x-kubernetes-group-version-kind:
|
|
- group: ''
|
|
kind: Status
|
|
version: v1
|
|
- group: resource.k8s.io
|
|
kind: Status
|
|
version: v1alpha2
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.StatusCause:
|
|
description: >-
|
|
StatusCause provides more information about an api.Status failure,
|
|
including cases when multiple errors are encountered.
|
|
type: object
|
|
properties:
|
|
field:
|
|
description: >-
|
|
The field of the resource that has caused this error, as named by its
|
|
JSON serialization. May include dot and postfix notation for nested
|
|
attributes. Arrays are zero-indexed. Fields may appear more than once
|
|
in an array of causes due to fields having multiple errors. Optional.
|
|
|
|
|
|
Examples:
|
|
"name" - the field "name" on the current resource
|
|
"items[0].name" - the field "name" on the first array entry in "items"
|
|
type: string
|
|
message:
|
|
description: >-
|
|
A human-readable description of the cause of the error. This field
|
|
may be presented as-is to a reader.
|
|
type: string
|
|
reason:
|
|
description: >-
|
|
A machine-readable description of the cause of the error. If this
|
|
value is empty there is no information available.
|
|
type: string
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.StatusDetails:
|
|
description: >-
|
|
StatusDetails is a set of additional properties that MAY be set by the
|
|
server to provide additional information about a response. The Reason
|
|
field of a Status object defines what attributes will be set. Clients must
|
|
ignore fields that do not match the defined type of each attribute, and
|
|
should assume that any attribute may be empty, invalid, or under defined.
|
|
type: object
|
|
properties:
|
|
causes:
|
|
description: >-
|
|
The Causes array includes more details associated with the
|
|
StatusReason failure. Not all StatusReasons may provide detailed
|
|
causes.
|
|
type: array
|
|
items:
|
|
$ref: '#/definitions/io.k8s.apimachinery.pkg.apis.meta.v1.StatusCause'
|
|
group:
|
|
description: >-
|
|
The group attribute of the resource associated with the status
|
|
StatusReason.
|
|
type: string
|
|
kind:
|
|
description: >-
|
|
The kind attribute of the resource associated with the status
|
|
StatusReason. On some operations may differ from the requested
|
|
resource Kind. More info:
|
|
https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
|
|
type: string
|
|
name:
|
|
description: >-
|
|
The name attribute of the resource associated with the status
|
|
StatusReason (when there is a single name which can be described).
|
|
type: string
|
|
retryAfterSeconds:
|
|
description: >-
|
|
If specified, the time in seconds before the operation should be
|
|
retried. Some errors may indicate the client must take an alternate
|
|
action - for those errors this field may indicate how long to wait
|
|
before taking the alternate action.
|
|
type: integer
|
|
format: int32
|
|
uid:
|
|
description: >-
|
|
UID of the resource. (when there is a single resource which can be
|
|
described). More info:
|
|
https://kubernetes.io/docs/concepts/overview/working-with-objects/names#uids
|
|
type: string
|
|
io.k8s.apimachinery.pkg.apis.meta.v1.Time:
|
|
description: >-
|
|
Time is a wrapper around time.Time which supports correct marshaling to
|
|
YAML and JSON. Wrappers are provided for many of the factory methods that
|
|
the time package offers.
|
|
type: string
|
|
format: date-time
|
|
securityDefinitions:
|
|
BearerToken:
|
|
description: Bearer Token authentication
|
|
type: apiKey
|
|
name: authorization
|
|
in: header
|
|
security:
|
|
- BearerToken: []
|