cfgate.iocfgate v0.2.0-alpha.11 · Release documentation
CloudflareAccessApplication schema
These fields come from the released CRD. Required means required when its parent object is present. Schema defaults do not describe every runtime fallback.
v1alpha1
Section titled “v1alpha1”| Field | Type | Required in parent | Schema default | Description |
|---|
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
| “ | object | no | none | CloudflareAccessApplication binds Gateway API targets to reusable Cloudflare Access policies. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
apiVersion | string | no | none | APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
kind | string | no | none | Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
metadata | object | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec | object | no | none | CloudflareAccessApplicationSpec defines Gateway API target bindings to reusable Access policies. |
Validation for spec:
x-kubernetes-validations: - message: either targetRef or targetRefs must be specified rule: has(self.targetRef) || has(self.targetRefs) - message: targetRef and targetRefs are mutually exclusive rule: "!(has(self.targetRef) && has(self.targetRefs))" - message: policyRefs must either all omit precedence or all specify precedence rule: self.policyRefs.all(p, !has(p.precedence)) || self.policyRefs.all(p, has(p.precedence)) - message: policyRefs precedence values must be unique rule: self.policyRefs.all(p, !has(p.precedence)) || self.policyRefs.all(p, has(p.precedence) && self.policyRefs.exists_one(q, has(q.precedence) && q.precedence == p.precedence))| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application | object | no | none | Application defines Access Application settings shared by generated apps. The path field overrides any path derived from HTTPRoute rules. |
Validation for spec.application:
x-kubernetes-validations: - message: corsHeaders and optionsPreflightBypass are mutually exclusive rule: "!(has(self.corsHeaders) && has(self.optionsPreflightBypass) && self.optionsPreflightBypass)"| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.allowedIdps | array | no | none | AllowedIdps restricts which identity providers can authenticate. Values are Cloudflare Identity Provider UUIDs. When empty, all IdPs configured in the account are allowed. |
Validation for spec.application.allowedIdps:
maxItems: 25| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.allowedIdps[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.appLauncherVisible | boolean | no | true | AppLauncherVisible controls whether the application appears in the Cloudflare App Launcher dashboard. Use pointer to distinguish explicit false (hidden) from absent (default visible). |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.autoRedirectToIdentity | boolean | no | none | AutoRedirectToIdentity auto-redirects to the identity provider when a single IdP is configured in allowedIdps. Skips the IdP selection page. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders | object | no | none | CORSHeaders configures CORS for browser-based APIs behind Access. When set, Cloudflare responds to OPTIONS preflight on behalf of the origin. Mutually exclusive with optionsPreflightBypass. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowAllHeaders | boolean | no | none | AllowAllHeaders allows all HTTP request headers. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowAllMethods | boolean | no | none | AllowAllMethods allows all HTTP request methods. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowAllOrigins | boolean | no | none | AllowAllOrigins allows all origins. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowCredentials | boolean | no | none | AllowCredentials includes credentials (cookies, authorization headers, or TLS client certificates) with CORS requests. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowedHeaders | array | no | none | AllowedHeaders lists specific allowed HTTP request headers. Ignored when allowAllHeaders is true. |
Validation for spec.application.corsHeaders.allowedHeaders:
maxItems: 50| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowedHeaders[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowedMethods | array | no | none | AllowedMethods lists specific allowed HTTP request methods. Ignored when allowAllMethods is true. |
Validation for spec.application.corsHeaders.allowedMethods:
maxItems: 9| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowedMethods[] | string | no | none | CORSAllowedMethod is an HTTP method allowed for CORS requests. |
Allowed values for spec.application.corsHeaders.allowedMethods[]: ["GET","POST","HEAD","PUT","DELETE","CONNECT","OPTIONS","TRACE","PATCH"].
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowedOrigins | array | no | none | AllowedOrigins lists specific allowed origins. Ignored when allowAllOrigins is true. |
Validation for spec.application.corsHeaders.allowedOrigins:
maxItems: 50| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.allowedOrigins[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.corsHeaders.maxAge | integer | no | none | MaxAge is the maximum number of seconds preflight results can be cached. |
Validation for spec.application.corsHeaders.maxAge:
maximum: 86400minimum: 0| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.customDenyMessage | string | no | none | CustomDenyMessage shown when access is denied. |
Validation for spec.application.customDenyMessage:
maxLength: 1024| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.customDenyUrl | string | no | none | CustomDenyURL redirects to this URL when denied (instead of message). |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.customNonIdentityDenyUrl | string | no | none | CustomNonIdentityDenyURL is the URL users are redirected to when denied by a non-identity (service auth) policy. Separate from customDenyUrl which handles identity-based denials. |
Validation for spec.application.customNonIdentityDenyUrl:
maxLength: 1024| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.domain | string | no | none | Domain is the protected domain (auto-generated from routes if omitted). Max 253: RFC 1035 section 2.3.4 FQDN presentation-format limit. |
Validation for spec.application.domain:
maxLength: 253x-kubernetes-validations: - message: each DNS label must not exceed 63 octets (RFC 1035 section 2.3.4) rule: self == '' || self.split('.').all(s, size(s) <= 63)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.enableBindingCookie | boolean | no | false | EnableBindingCookie enables binding cookies for sticky sessions. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.httpOnlyCookieAttribute | boolean | no | true | HttpOnlyCookieAttribute adds HttpOnly to session cookies. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.logoUrl | string | no | none | LogoURL is the application logo in dashboard. |
Validation for spec.application.logoUrl:
maxLength: 1024| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.name | string | no | none | Name is the display name in Cloudflare dashboard. Defaults to CR name if omitted. |
Validation for spec.application.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.optionsPreflightBypass | boolean | no | none | OptionsPreflightBypass allows OPTIONS preflight requests to bypass Access authentication and go directly to the origin. Enabling this removes all CORS header settings. Mutually exclusive with corsHeaders. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.path | string | no | none | Path restricts protection to a specific absolute path prefix. Cloudflare Access paths must not include query strings or fragments. |
Validation for spec.application.path:
maxLength: 1024pattern: ^/[^?#]*$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.pathCookieAttribute | boolean | no | none | PathCookieAttribute scopes the Access JWT cookie to the application path instead of the hostname. When enabled, users must re-authenticate for different paths on the same hostname. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.readServiceTokensFromHeader | string | no | none | ReadServiceTokensFromHeader enables reading service tokens from a single custom HTTP header instead of the standard CF-Access-Client-Id and CF-Access-Client-Secret header pair. The value is the header name. The header value must contain a JSON object with “cf-access-client-id” and “cf-access-client-secret” keys. |
Validation for spec.application.readServiceTokensFromHeader:
maxLength: 256| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.sameSiteCookieAttribute | string | no | "lax" | SameSiteCookieAttribute controls cross-site cookie behavior. |
Allowed values for spec.application.sameSiteCookieAttribute: ["strict","lax","none"].
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.serviceAuth401Redirect | boolean | no | none | ServiceAuth401Redirect returns a 401 status code instead of redirecting to the Access login page when a request is blocked by a Service Auth (non_identity) policy. Enable for API consumers. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.sessionDuration | string | no | "24h" | SessionDuration controls session cookie lifetime. |
Validation for spec.application.sessionDuration:
pattern: ^([0-9]+(ns|us|ms|s|m|h))+$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.skipInterstitial | boolean | no | false | SkipInterstitial bypasses the Access login page for API requests. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.application.type | string | no | "self_hosted" | Type is the application type. |
Allowed values for spec.application.type: ["self_hosted"].
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef | object | no | none | CloudflareRef references Cloudflare credentials. When omitted, credentials are inherited from each target’s route -> Gateway -> CloudflareTunnel chain. Multiple targets must inherit the same Cloudflare account. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.accountId | string | no | none | AccountID is the Cloudflare account ID. |
Validation for spec.cloudflareRef.accountId:
maxLength: 32| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.accountName | string | no | none | AccountName is the Cloudflare account name (looked up via API). |
Validation for spec.cloudflareRef.accountName:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.name | string | yes | none | Name of the secret containing credentials. |
Validation for spec.cloudflareRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.namespace | string | no | none | Namespace of the secret (defaults to policy namespace). |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.secretKeys | object | no | none | SecretKeys selects credential data keys; omitted keys use their defaults. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.secretKeys.apiToken | string | no | "CLOUDFLARE_API_TOKEN" | APIToken is the key name for the Cloudflare API token. |
Validation for spec.cloudflareRef.secretKeys.apiToken:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.policyRefs | array | yes | none | PolicyRefs lists reusable CloudflareAccessPolicy resources to attach. |
Validation for spec.policyRefs:
maxItems: 16minItems: 1x-kubernetes-list-map-keys: - name - namespacex-kubernetes-list-type: map| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.policyRefs[] | object | no | none | AccessPolicyReference references a reusable CloudflareAccessPolicy. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.policyRefs[].name | string | yes | none | Name is the CloudflareAccessPolicy name. |
Validation for spec.policyRefs[].name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.policyRefs[].namespace | string | yes | "" | Namespace is the CloudflareAccessPolicy namespace. Empty defaults to application namespace. Cross-namespace references require ReferenceGrant. |
Validation for spec.policyRefs[].namespace:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.policyRefs[].precedence | integer | no | none | Precedence determines policy evaluation order for the application. Lower values run first. When omitted, the controller uses list order starting at 1. |
Validation for spec.policyRefs[].precedence:
maximum: 9999minimum: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRef | object | no | none | TargetRef identifies a single Gateway API target. |
Validation for spec.targetRef:
x-kubernetes-validations: - message: group must be gateway.networking.k8s.io rule: self.group == 'gateway.networking.k8s.io' - message: kind must be Gateway or HTTPRoute rule: self.kind in ['Gateway', 'HTTPRoute']| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRef.group | string | yes | "gateway.networking.k8s.io" | Group is the API group of the target resource. |
Validation for spec.targetRef.group:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRef.kind | string | yes | none | Kind is the kind of the target resource. |
Allowed values for spec.targetRef.kind: ["Gateway","HTTPRoute"].
Validation for spec.targetRef.kind:
maxLength: 63| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRef.name | string | yes | none | Name is the name of the target resource. |
Validation for spec.targetRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRef.namespace | string | no | none | Namespace is the namespace of the target resource. Cross-namespace targeting requires ReferenceGrant. |
Validation for spec.targetRef.namespace:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRef.sectionName | string | no | none | SectionName targets specific listener (Gateway) or rule (Route). |
Validation for spec.targetRef.sectionName:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRefs | array | no | none | TargetRefs identifies multiple Gateway API targets. |
Validation for spec.targetRefs:
maxItems: 16minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRefs[] | object | no | none | PolicyTargetReference identifies a Gateway API resource for Access application attachment. PolicyTargetReference follows the Gateway API LocalPolicyTargetReferenceWithSectionName pattern. It targets Gateway API Gateway and HTTPRoute resources and extracts hostnames and paths from those resources to create corresponding Cloudflare Access applications. Cross-namespace references require a ReferenceGrant in the target namespace that permits CloudflareAccessApplication resources from the application’s namespace. |
Validation for spec.targetRefs[]:
x-kubernetes-validations: - message: group must be gateway.networking.k8s.io rule: self.group == 'gateway.networking.k8s.io' - message: kind must be Gateway or HTTPRoute rule: self.kind in ['Gateway', 'HTTPRoute']| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRefs[].group | string | yes | "gateway.networking.k8s.io" | Group is the API group of the target resource. |
Validation for spec.targetRefs[].group:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRefs[].kind | string | yes | none | Kind is the kind of the target resource. |
Allowed values for spec.targetRefs[].kind: ["Gateway","HTTPRoute"].
Validation for spec.targetRefs[].kind:
maxLength: 63| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRefs[].name | string | yes | none | Name is the name of the target resource. |
Validation for spec.targetRefs[].name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRefs[].namespace | string | no | none | Namespace is the namespace of the target resource. Cross-namespace targeting requires ReferenceGrant. |
Validation for spec.targetRefs[].namespace:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.targetRefs[].sectionName | string | no | none | SectionName targets specific listener (Gateway) or rule (Route). |
Validation for spec.targetRefs[].sectionName:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status | object | no | none | CloudflareAccessApplicationStatus defines observed Access application state. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.accountId | string | no | none | AccountID is the resolved Cloudflare account ID used for Access application cleanup. |
Validation for status.accountId:
maxLength: 32| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors | array | no | none | Ancestors contains status for each targetRef. |
Validation for status.ancestors:
maxItems: 64| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[] | object | no | none | PolicyAncestorStatus describes the policy attachment status for a specific target. PolicyAncestorStatus follows the Gateway API PolicyAncestorStatus pattern to report per-target attachment status. Each target reference in the spec has a corresponding ancestor status entry showing whether the policy was successfully attached. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].ancestorRef | object | yes | none | AncestorRef identifies the target. |
Validation for status.ancestors[].ancestorRef:
x-kubernetes-validations: - message: group must be gateway.networking.k8s.io rule: self.group == 'gateway.networking.k8s.io' - message: kind must be Gateway or HTTPRoute rule: self.kind in ['Gateway', 'HTTPRoute']| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].ancestorRef.group | string | yes | "gateway.networking.k8s.io" | Group is the API group of the target resource. |
Validation for status.ancestors[].ancestorRef.group:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].ancestorRef.kind | string | yes | none | Kind is the kind of the target resource. |
Allowed values for status.ancestors[].ancestorRef.kind: ["Gateway","HTTPRoute"].
Validation for status.ancestors[].ancestorRef.kind:
maxLength: 63| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].ancestorRef.name | string | yes | none | Name is the name of the target resource. |
Validation for status.ancestors[].ancestorRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].ancestorRef.namespace | string | no | none | Namespace is the namespace of the target resource. Cross-namespace targeting requires ReferenceGrant. |
Validation for status.ancestors[].ancestorRef.namespace:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].ancestorRef.sectionName | string | no | none | SectionName targets specific listener (Gateway) or rule (Route). |
Validation for status.ancestors[].ancestorRef.sectionName:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].conditions | array | no | none | Conditions for this specific target. |
Validation for status.ancestors[].conditions:
maxItems: 8| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].conditions[] | object | no | none | Condition contains details for one aspect of the current state of this API Resource. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].conditions[].lastTransitionTime | string | yes | none | lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. |
Validation for status.ancestors[].conditions[].lastTransitionTime:
format: date-time| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].conditions[].message | string | yes | none | message is a human readable message indicating details about the transition. This may be an empty string. |
Validation for status.ancestors[].conditions[].message:
maxLength: 32768| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].conditions[].observedGeneration | integer | no | none | observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. |
Validation for status.ancestors[].conditions[].observedGeneration:
format: int64minimum: 0| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].conditions[].reason | string | yes | none | reason contains a programmatic identifier indicating the reason for the condition’s last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. |
Validation for status.ancestors[].conditions[].reason:
maxLength: 1024minLength: 1pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].conditions[].status | string | yes | none | status of the condition, one of True, False, Unknown. |
Allowed values for status.ancestors[].conditions[].status: ["True","False","Unknown"].
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].conditions[].type | string | yes | none | type of condition in CamelCase or in foo.example.com/CamelCase. |
Validation for status.ancestors[].conditions[].type:
maxLength: 316pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ancestors[].controllerName | string | yes | none | ControllerName identifies the controller managing this attachment. |
Validation for status.ancestors[].controllerName:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications | array | no | none | Applications are Cloudflare Access Applications managed by this resource. |
Validation for status.applications:
maxItems: 64| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[] | object | no | none | AccessApplicationObserved records a Cloudflare Access Application created for one host/path target. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].aud | string | no | none | AUD is the Application Audience Tag. |
Validation for status.applications[].aud:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].domain | string | no | none | Domain is the protected hostname/path in Cloudflare. |
Validation for status.applications[].domain:
maxLength: 1024| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].id | string | no | none | ID is the Cloudflare Access Application ID. |
Validation for status.applications[].id:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].targetRef | object | no | none | TargetRef identifies the Gateway API target that produced this application. |
Validation for status.applications[].targetRef:
x-kubernetes-validations: - message: group must be gateway.networking.k8s.io rule: self.group == 'gateway.networking.k8s.io' - message: kind must be Gateway or HTTPRoute rule: self.kind in ['Gateway', 'HTTPRoute']| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].targetRef.group | string | yes | "gateway.networking.k8s.io" | Group is the API group of the target resource. |
Validation for status.applications[].targetRef.group:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].targetRef.kind | string | yes | none | Kind is the kind of the target resource. |
Allowed values for status.applications[].targetRef.kind: ["Gateway","HTTPRoute"].
Validation for status.applications[].targetRef.kind:
maxLength: 63| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].targetRef.name | string | yes | none | Name is the name of the target resource. |
Validation for status.applications[].targetRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].targetRef.namespace | string | no | none | Namespace is the namespace of the target resource. Cross-namespace targeting requires ReferenceGrant. |
Validation for status.applications[].targetRef.namespace:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.applications[].targetRef.sectionName | string | no | none | SectionName targets specific listener (Gateway) or rule (Route). |
Validation for status.applications[].targetRef.sectionName:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.attachedTargets | integer | no | none | AttachedTargets is the count of successfully attached Gateway API targets. |
Validation for status.attachedTargets:
format: int32| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions | array | no | none | Conditions describe current state. |
Validation for status.conditions:
x-kubernetes-list-map-keys: - typex-kubernetes-list-type: map| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[] | object | no | none | Condition contains details for one aspect of the current state of this API Resource. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].lastTransitionTime | string | yes | none | lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. |
Validation for status.conditions[].lastTransitionTime:
format: date-time| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].message | string | yes | none | message is a human readable message indicating details about the transition. This may be an empty string. |
Validation for status.conditions[].message:
maxLength: 32768| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].observedGeneration | integer | no | none | observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. |
Validation for status.conditions[].observedGeneration:
format: int64minimum: 0| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].reason | string | yes | none | reason contains a programmatic identifier indicating the reason for the condition’s last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. |
Validation for status.conditions[].reason:
maxLength: 1024minLength: 1pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].status | string | yes | none | status of the condition, one of True, False, Unknown. |
Allowed values for status.conditions[].status: ["True","False","Unknown"].
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].type | string | yes | none | type of condition in CamelCase or in foo.example.com/CamelCase. |
Validation for status.conditions[].type:
maxLength: 316pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretKeys | object | no | none | CredentialSecretKeys preserves the selected token key for cleanup. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretKeys.apiToken | string | no | "CLOUDFLARE_API_TOKEN" | APIToken is the key name for the Cloudflare API token. |
Validation for status.credentialSecretKeys.apiToken:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretRef | object | no | none | CredentialSecretRef is the resolved credentials Secret used for cleanup. The namespace is always stored explicitly. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretRef.name | string | yes | none | Name of the secret. |
Validation for status.credentialSecretRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretRef.namespace | string | no | none | Namespace of the secret. Defaults to the resource’s namespace if empty. |
Validation for status.credentialSecretRef.namespace:
maxLength: 63| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.observedGeneration | integer | no | none | ObservedGeneration is the last generation processed. |
Validation for status.observedGeneration:
format: int64| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ownerId | string | no | none | OwnerID binds remote Access resources to this installation and CR incarnation. |
Validation for status.ownerId:
pattern: ^[a-f0-9]{28}$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications | array | no | none | PendingApplications checkpoint successful targets while previous protection is retained. |
Validation for status.pendingApplications:
maxItems: 64| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[] | object | no | none | AccessApplicationObserved records a Cloudflare Access Application created for one host/path target. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].aud | string | no | none | AUD is the Application Audience Tag. |
Validation for status.pendingApplications[].aud:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].domain | string | no | none | Domain is the protected hostname/path in Cloudflare. |
Validation for status.pendingApplications[].domain:
maxLength: 1024| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].id | string | no | none | ID is the Cloudflare Access Application ID. |
Validation for status.pendingApplications[].id:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].targetRef | object | no | none | TargetRef identifies the Gateway API target that produced this application. |
Validation for status.pendingApplications[].targetRef:
x-kubernetes-validations: - message: group must be gateway.networking.k8s.io rule: self.group == 'gateway.networking.k8s.io' - message: kind must be Gateway or HTTPRoute rule: self.kind in ['Gateway', 'HTTPRoute']| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].targetRef.group | string | yes | "gateway.networking.k8s.io" | Group is the API group of the target resource. |
Validation for status.pendingApplications[].targetRef.group:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].targetRef.kind | string | yes | none | Kind is the kind of the target resource. |
Allowed values for status.pendingApplications[].targetRef.kind: ["Gateway","HTTPRoute"].
Validation for status.pendingApplications[].targetRef.kind:
maxLength: 63| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].targetRef.name | string | yes | none | Name is the name of the target resource. |
Validation for status.pendingApplications[].targetRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].targetRef.namespace | string | no | none | Namespace is the namespace of the target resource. Cross-namespace targeting requires ReferenceGrant. |
Validation for status.pendingApplications[].targetRef.namespace:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.pendingApplications[].targetRef.sectionName | string | no | none | SectionName targets specific listener (Gateway) or rule (Route). |
Validation for status.pendingApplications[].targetRef.sectionName:
maxLength: 253