Skip to content

cfgate.iocfgate v0.2.0-alpha.11 · Release documentation

CloudflareAccessApplication schema

These fields come from the released CRD. Required means required when its parent object is present. Schema defaults do not describe every runtime fallback.

FieldTypeRequired in parentSchema defaultDescription
FieldTypeRequired in parentSchema defaultDescription
“objectnononeCloudflareAccessApplication binds Gateway API targets to reusable Cloudflare Access policies.
FieldTypeRequired in parentSchema defaultDescription
apiVersionstringnononeAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
FieldTypeRequired in parentSchema defaultDescription
kindstringnononeKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
FieldTypeRequired in parentSchema defaultDescription
metadataobjectnonone
FieldTypeRequired in parentSchema defaultDescription
specobjectnononeCloudflareAccessApplicationSpec defines Gateway API target bindings to reusable Access policies.

Validation for spec:

x-kubernetes-validations:
- message: either targetRef or targetRefs must be specified
rule: has(self.targetRef) || has(self.targetRefs)
- message: targetRef and targetRefs are mutually exclusive
rule: "!(has(self.targetRef) && has(self.targetRefs))"
- message: policyRefs must either all omit precedence or all specify precedence
rule: self.policyRefs.all(p, !has(p.precedence)) || self.policyRefs.all(p,
has(p.precedence))
- message: policyRefs precedence values must be unique
rule: self.policyRefs.all(p, !has(p.precedence)) || self.policyRefs.all(p,
has(p.precedence) && self.policyRefs.exists_one(q, has(q.precedence) &&
q.precedence == p.precedence))
FieldTypeRequired in parentSchema defaultDescription
spec.applicationobjectnononeApplication defines Access Application settings shared by generated apps.
The path field overrides any path derived from HTTPRoute rules.

Validation for spec.application:

x-kubernetes-validations:
- message: corsHeaders and optionsPreflightBypass are mutually exclusive
rule: "!(has(self.corsHeaders) && has(self.optionsPreflightBypass) &&
self.optionsPreflightBypass)"
FieldTypeRequired in parentSchema defaultDescription
spec.application.allowedIdpsarraynononeAllowedIdps restricts which identity providers can authenticate.
Values are Cloudflare Identity Provider UUIDs.
When empty, all IdPs configured in the account are allowed.

Validation for spec.application.allowedIdps:

maxItems: 25
FieldTypeRequired in parentSchema defaultDescription
spec.application.allowedIdps[]stringnonone
FieldTypeRequired in parentSchema defaultDescription
spec.application.appLauncherVisiblebooleannotrueAppLauncherVisible controls whether the application appears in the
Cloudflare App Launcher dashboard. Use pointer to distinguish
explicit false (hidden) from absent (default visible).
FieldTypeRequired in parentSchema defaultDescription
spec.application.autoRedirectToIdentitybooleannononeAutoRedirectToIdentity auto-redirects to the identity provider
when a single IdP is configured in allowedIdps. Skips the IdP
selection page.
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeadersobjectnononeCORSHeaders configures CORS for browser-based APIs behind Access.
When set, Cloudflare responds to OPTIONS preflight on behalf of the origin.
Mutually exclusive with optionsPreflightBypass.
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowAllHeadersbooleannononeAllowAllHeaders allows all HTTP request headers.
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowAllMethodsbooleannononeAllowAllMethods allows all HTTP request methods.
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowAllOriginsbooleannononeAllowAllOrigins allows all origins.
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowCredentialsbooleannononeAllowCredentials includes credentials (cookies, authorization headers,
or TLS client certificates) with CORS requests.
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowedHeadersarraynononeAllowedHeaders lists specific allowed HTTP request headers.
Ignored when allowAllHeaders is true.

Validation for spec.application.corsHeaders.allowedHeaders:

maxItems: 50
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowedHeaders[]stringnonone
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowedMethodsarraynononeAllowedMethods lists specific allowed HTTP request methods.
Ignored when allowAllMethods is true.

Validation for spec.application.corsHeaders.allowedMethods:

maxItems: 9
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowedMethods[]stringnononeCORSAllowedMethod is an HTTP method allowed for CORS requests.

Allowed values for spec.application.corsHeaders.allowedMethods[]: ["GET","POST","HEAD","PUT","DELETE","CONNECT","OPTIONS","TRACE","PATCH"].

FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowedOriginsarraynononeAllowedOrigins lists specific allowed origins.
Ignored when allowAllOrigins is true.

Validation for spec.application.corsHeaders.allowedOrigins:

maxItems: 50
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.allowedOrigins[]stringnonone
FieldTypeRequired in parentSchema defaultDescription
spec.application.corsHeaders.maxAgeintegernononeMaxAge is the maximum number of seconds preflight results can be cached.

Validation for spec.application.corsHeaders.maxAge:

maximum: 86400
minimum: 0
FieldTypeRequired in parentSchema defaultDescription
spec.application.customDenyMessagestringnononeCustomDenyMessage shown when access is denied.

Validation for spec.application.customDenyMessage:

maxLength: 1024
FieldTypeRequired in parentSchema defaultDescription
spec.application.customDenyUrlstringnononeCustomDenyURL redirects to this URL when denied (instead of message).
FieldTypeRequired in parentSchema defaultDescription
spec.application.customNonIdentityDenyUrlstringnononeCustomNonIdentityDenyURL is the URL users are redirected to when
denied by a non-identity (service auth) policy. Separate from
customDenyUrl which handles identity-based denials.

Validation for spec.application.customNonIdentityDenyUrl:

maxLength: 1024
FieldTypeRequired in parentSchema defaultDescription
spec.application.domainstringnononeDomain is the protected domain (auto-generated from routes if omitted).
Max 253: RFC 1035 section 2.3.4 FQDN presentation-format limit.

Validation for spec.application.domain:

maxLength: 253
x-kubernetes-validations:
- message: each DNS label must not exceed 63 octets (RFC 1035 section 2.3.4)
rule: self == '' || self.split('.').all(s, size(s) <= 63)
FieldTypeRequired in parentSchema defaultDescription
spec.application.enableBindingCookiebooleannofalseEnableBindingCookie enables binding cookies for sticky sessions.
FieldTypeRequired in parentSchema defaultDescription
spec.application.httpOnlyCookieAttributebooleannotrueHttpOnlyCookieAttribute adds HttpOnly to session cookies.
FieldTypeRequired in parentSchema defaultDescription
spec.application.logoUrlstringnononeLogoURL is the application logo in dashboard.

Validation for spec.application.logoUrl:

maxLength: 1024
FieldTypeRequired in parentSchema defaultDescription
spec.application.namestringnononeName is the display name in Cloudflare dashboard.
Defaults to CR name if omitted.

Validation for spec.application.name:

maxLength: 255
FieldTypeRequired in parentSchema defaultDescription
spec.application.optionsPreflightBypassbooleannononeOptionsPreflightBypass allows OPTIONS preflight requests to bypass
Access authentication and go directly to the origin. Enabling this
removes all CORS header settings. Mutually exclusive with corsHeaders.
FieldTypeRequired in parentSchema defaultDescription
spec.application.pathstringnononePath restricts protection to a specific absolute path prefix.
Cloudflare Access paths must not include query strings or fragments.

Validation for spec.application.path:

maxLength: 1024
pattern: ^/[^?#]*$
FieldTypeRequired in parentSchema defaultDescription
spec.application.pathCookieAttributebooleannononePathCookieAttribute scopes the Access JWT cookie to the application
path instead of the hostname. When enabled, users must re-authenticate
for different paths on the same hostname.
FieldTypeRequired in parentSchema defaultDescription
spec.application.readServiceTokensFromHeaderstringnononeReadServiceTokensFromHeader enables reading service tokens from a
single custom HTTP header instead of the standard CF-Access-Client-Id
and CF-Access-Client-Secret header pair. The value is the header name.
The header value must contain a JSON object with “cf-access-client-id”
and “cf-access-client-secret” keys.

Validation for spec.application.readServiceTokensFromHeader:

maxLength: 256
FieldTypeRequired in parentSchema defaultDescription
spec.application.sameSiteCookieAttributestringno"lax"SameSiteCookieAttribute controls cross-site cookie behavior.

Allowed values for spec.application.sameSiteCookieAttribute: ["strict","lax","none"].

FieldTypeRequired in parentSchema defaultDescription
spec.application.serviceAuth401RedirectbooleannononeServiceAuth401Redirect returns a 401 status code instead of
redirecting to the Access login page when a request is blocked by a
Service Auth (non_identity) policy. Enable for API consumers.
FieldTypeRequired in parentSchema defaultDescription
spec.application.sessionDurationstringno"24h"SessionDuration controls session cookie lifetime.

Validation for spec.application.sessionDuration:

pattern: ^([0-9]+(ns|us|ms|s|m|h))+$
FieldTypeRequired in parentSchema defaultDescription
spec.application.skipInterstitialbooleannofalseSkipInterstitial bypasses the Access login page for API requests.
FieldTypeRequired in parentSchema defaultDescription
spec.application.typestringno"self_hosted"Type is the application type.

Allowed values for spec.application.type: ["self_hosted"].

FieldTypeRequired in parentSchema defaultDescription
spec.cloudflareRefobjectnononeCloudflareRef references Cloudflare credentials. When omitted, credentials
are inherited from each target’s route -> Gateway -> CloudflareTunnel chain.
Multiple targets must inherit the same Cloudflare account.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflareRef.accountIdstringnononeAccountID is the Cloudflare account ID.

Validation for spec.cloudflareRef.accountId:

maxLength: 32
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflareRef.accountNamestringnononeAccountName is the Cloudflare account name (looked up via API).

Validation for spec.cloudflareRef.accountName:

maxLength: 255
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflareRef.namestringyesnoneName of the secret containing credentials.

Validation for spec.cloudflareRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflareRef.namespacestringnononeNamespace of the secret (defaults to policy namespace).
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflareRef.secretKeysobjectnononeSecretKeys selects credential data keys; omitted keys use their defaults.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflareRef.secretKeys.apiTokenstringno"CLOUDFLARE_API_TOKEN"APIToken is the key name for the Cloudflare API token.

Validation for spec.cloudflareRef.secretKeys.apiToken:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.policyRefsarrayyesnonePolicyRefs lists reusable CloudflareAccessPolicy resources to attach.

Validation for spec.policyRefs:

maxItems: 16
minItems: 1
x-kubernetes-list-map-keys:
- name
- namespace
x-kubernetes-list-type: map
FieldTypeRequired in parentSchema defaultDescription
spec.policyRefs[]objectnononeAccessPolicyReference references a reusable CloudflareAccessPolicy.
FieldTypeRequired in parentSchema defaultDescription
spec.policyRefs[].namestringyesnoneName is the CloudflareAccessPolicy name.

Validation for spec.policyRefs[].name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
spec.policyRefs[].namespacestringyes""Namespace is the CloudflareAccessPolicy namespace. Empty defaults to application namespace.
Cross-namespace references require ReferenceGrant.

Validation for spec.policyRefs[].namespace:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.policyRefs[].precedenceintegernononePrecedence determines policy evaluation order for the application. Lower values run first.
When omitted, the controller uses list order starting at 1.

Validation for spec.policyRefs[].precedence:

maximum: 9999
minimum: 1
FieldTypeRequired in parentSchema defaultDescription
spec.targetRefobjectnononeTargetRef identifies a single Gateway API target.

Validation for spec.targetRef:

x-kubernetes-validations:
- message: group must be gateway.networking.k8s.io
rule: self.group == 'gateway.networking.k8s.io'
- message: kind must be Gateway or HTTPRoute
rule: self.kind in ['Gateway', 'HTTPRoute']
FieldTypeRequired in parentSchema defaultDescription
spec.targetRef.groupstringyes"gateway.networking.k8s.io"Group is the API group of the target resource.

Validation for spec.targetRef.group:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.targetRef.kindstringyesnoneKind is the kind of the target resource.

Allowed values for spec.targetRef.kind: ["Gateway","HTTPRoute"].

Validation for spec.targetRef.kind:

maxLength: 63
FieldTypeRequired in parentSchema defaultDescription
spec.targetRef.namestringyesnoneName is the name of the target resource.

Validation for spec.targetRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
spec.targetRef.namespacestringnononeNamespace is the namespace of the target resource.
Cross-namespace targeting requires ReferenceGrant.

Validation for spec.targetRef.namespace:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.targetRef.sectionNamestringnononeSectionName targets specific listener (Gateway) or rule (Route).

Validation for spec.targetRef.sectionName:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.targetRefsarraynononeTargetRefs identifies multiple Gateway API targets.

Validation for spec.targetRefs:

maxItems: 16
minItems: 1
FieldTypeRequired in parentSchema defaultDescription
spec.targetRefs[]objectnononePolicyTargetReference identifies a Gateway API resource for Access application attachment.

PolicyTargetReference follows the Gateway API LocalPolicyTargetReferenceWithSectionName
pattern. It targets Gateway API Gateway and HTTPRoute resources and extracts
hostnames and paths from those resources to create corresponding Cloudflare Access
applications.

Cross-namespace references require a ReferenceGrant in the target namespace that permits
CloudflareAccessApplication resources from the application’s namespace.

Validation for spec.targetRefs[]:

x-kubernetes-validations:
- message: group must be gateway.networking.k8s.io
rule: self.group == 'gateway.networking.k8s.io'
- message: kind must be Gateway or HTTPRoute
rule: self.kind in ['Gateway', 'HTTPRoute']
FieldTypeRequired in parentSchema defaultDescription
spec.targetRefs[].groupstringyes"gateway.networking.k8s.io"Group is the API group of the target resource.

Validation for spec.targetRefs[].group:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.targetRefs[].kindstringyesnoneKind is the kind of the target resource.

Allowed values for spec.targetRefs[].kind: ["Gateway","HTTPRoute"].

Validation for spec.targetRefs[].kind:

maxLength: 63
FieldTypeRequired in parentSchema defaultDescription
spec.targetRefs[].namestringyesnoneName is the name of the target resource.

Validation for spec.targetRefs[].name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
spec.targetRefs[].namespacestringnononeNamespace is the namespace of the target resource.
Cross-namespace targeting requires ReferenceGrant.

Validation for spec.targetRefs[].namespace:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.targetRefs[].sectionNamestringnononeSectionName targets specific listener (Gateway) or rule (Route).

Validation for spec.targetRefs[].sectionName:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
statusobjectnononeCloudflareAccessApplicationStatus defines observed Access application state.
FieldTypeRequired in parentSchema defaultDescription
status.accountIdstringnononeAccountID is the resolved Cloudflare account ID used for Access application cleanup.

Validation for status.accountId:

maxLength: 32
FieldTypeRequired in parentSchema defaultDescription
status.ancestorsarraynononeAncestors contains status for each targetRef.

Validation for status.ancestors:

maxItems: 64
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[]objectnononePolicyAncestorStatus describes the policy attachment status for a specific target.

PolicyAncestorStatus follows the Gateway API PolicyAncestorStatus pattern to report
per-target attachment status. Each target reference in the spec has a corresponding
ancestor status entry showing whether the policy was successfully attached.
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].ancestorRefobjectyesnoneAncestorRef identifies the target.

Validation for status.ancestors[].ancestorRef:

x-kubernetes-validations:
- message: group must be gateway.networking.k8s.io
rule: self.group == 'gateway.networking.k8s.io'
- message: kind must be Gateway or HTTPRoute
rule: self.kind in ['Gateway', 'HTTPRoute']
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].ancestorRef.groupstringyes"gateway.networking.k8s.io"Group is the API group of the target resource.

Validation for status.ancestors[].ancestorRef.group:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].ancestorRef.kindstringyesnoneKind is the kind of the target resource.

Allowed values for status.ancestors[].ancestorRef.kind: ["Gateway","HTTPRoute"].

Validation for status.ancestors[].ancestorRef.kind:

maxLength: 63
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].ancestorRef.namestringyesnoneName is the name of the target resource.

Validation for status.ancestors[].ancestorRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].ancestorRef.namespacestringnononeNamespace is the namespace of the target resource.
Cross-namespace targeting requires ReferenceGrant.

Validation for status.ancestors[].ancestorRef.namespace:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].ancestorRef.sectionNamestringnononeSectionName targets specific listener (Gateway) or rule (Route).

Validation for status.ancestors[].ancestorRef.sectionName:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].conditionsarraynononeConditions for this specific target.

Validation for status.ancestors[].conditions:

maxItems: 8
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].conditions[]objectnononeCondition contains details for one aspect of the current state of this API Resource.
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].conditions[].lastTransitionTimestringyesnonelastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.

Validation for status.ancestors[].conditions[].lastTransitionTime:

format: date-time
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].conditions[].messagestringyesnonemessage is a human readable message indicating details about the transition.
This may be an empty string.

Validation for status.ancestors[].conditions[].message:

maxLength: 32768
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].conditions[].observedGenerationintegernononeobservedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.

Validation for status.ancestors[].conditions[].observedGeneration:

format: int64
minimum: 0
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].conditions[].reasonstringyesnonereason contains a programmatic identifier indicating the reason for the condition’s last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.

Validation for status.ancestors[].conditions[].reason:

maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].conditions[].statusstringyesnonestatus of the condition, one of True, False, Unknown.

Allowed values for status.ancestors[].conditions[].status: ["True","False","Unknown"].

FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].conditions[].typestringyesnonetype of condition in CamelCase or in foo.example.com/CamelCase.

Validation for status.ancestors[].conditions[].type:

maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
FieldTypeRequired in parentSchema defaultDescription
status.ancestors[].controllerNamestringyesnoneControllerName identifies the controller managing this attachment.

Validation for status.ancestors[].controllerName:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.applicationsarraynononeApplications are Cloudflare Access Applications managed by this resource.

Validation for status.applications:

maxItems: 64
FieldTypeRequired in parentSchema defaultDescription
status.applications[]objectnononeAccessApplicationObserved records a Cloudflare Access Application created for one host/path target.
FieldTypeRequired in parentSchema defaultDescription
status.applications[].audstringnononeAUD is the Application Audience Tag.

Validation for status.applications[].aud:

maxLength: 255
FieldTypeRequired in parentSchema defaultDescription
status.applications[].domainstringnononeDomain is the protected hostname/path in Cloudflare.

Validation for status.applications[].domain:

maxLength: 1024
FieldTypeRequired in parentSchema defaultDescription
status.applications[].idstringnononeID is the Cloudflare Access Application ID.

Validation for status.applications[].id:

maxLength: 36
FieldTypeRequired in parentSchema defaultDescription
status.applications[].targetRefobjectnononeTargetRef identifies the Gateway API target that produced this application.

Validation for status.applications[].targetRef:

x-kubernetes-validations:
- message: group must be gateway.networking.k8s.io
rule: self.group == 'gateway.networking.k8s.io'
- message: kind must be Gateway or HTTPRoute
rule: self.kind in ['Gateway', 'HTTPRoute']
FieldTypeRequired in parentSchema defaultDescription
status.applications[].targetRef.groupstringyes"gateway.networking.k8s.io"Group is the API group of the target resource.

Validation for status.applications[].targetRef.group:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.applications[].targetRef.kindstringyesnoneKind is the kind of the target resource.

Allowed values for status.applications[].targetRef.kind: ["Gateway","HTTPRoute"].

Validation for status.applications[].targetRef.kind:

maxLength: 63
FieldTypeRequired in parentSchema defaultDescription
status.applications[].targetRef.namestringyesnoneName is the name of the target resource.

Validation for status.applications[].targetRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
status.applications[].targetRef.namespacestringnononeNamespace is the namespace of the target resource.
Cross-namespace targeting requires ReferenceGrant.

Validation for status.applications[].targetRef.namespace:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.applications[].targetRef.sectionNamestringnononeSectionName targets specific listener (Gateway) or rule (Route).

Validation for status.applications[].targetRef.sectionName:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.attachedTargetsintegernononeAttachedTargets is the count of successfully attached Gateway API targets.

Validation for status.attachedTargets:

format: int32
FieldTypeRequired in parentSchema defaultDescription
status.conditionsarraynononeConditions describe current state.

Validation for status.conditions:

x-kubernetes-list-map-keys:
- type
x-kubernetes-list-type: map
FieldTypeRequired in parentSchema defaultDescription
status.conditions[]objectnononeCondition contains details for one aspect of the current state of this API Resource.
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].lastTransitionTimestringyesnonelastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.

Validation for status.conditions[].lastTransitionTime:

format: date-time
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].messagestringyesnonemessage is a human readable message indicating details about the transition.
This may be an empty string.

Validation for status.conditions[].message:

maxLength: 32768
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].observedGenerationintegernononeobservedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.

Validation for status.conditions[].observedGeneration:

format: int64
minimum: 0
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].reasonstringyesnonereason contains a programmatic identifier indicating the reason for the condition’s last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.

Validation for status.conditions[].reason:

maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].statusstringyesnonestatus of the condition, one of True, False, Unknown.

Allowed values for status.conditions[].status: ["True","False","Unknown"].

FieldTypeRequired in parentSchema defaultDescription
status.conditions[].typestringyesnonetype of condition in CamelCase or in foo.example.com/CamelCase.

Validation for status.conditions[].type:

maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
FieldTypeRequired in parentSchema defaultDescription
status.credentialSecretKeysobjectnononeCredentialSecretKeys preserves the selected token key for cleanup.
FieldTypeRequired in parentSchema defaultDescription
status.credentialSecretKeys.apiTokenstringno"CLOUDFLARE_API_TOKEN"APIToken is the key name for the Cloudflare API token.

Validation for status.credentialSecretKeys.apiToken:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.credentialSecretRefobjectnononeCredentialSecretRef is the resolved credentials Secret used for cleanup.
The namespace is always stored explicitly.
FieldTypeRequired in parentSchema defaultDescription
status.credentialSecretRef.namestringyesnoneName of the secret.

Validation for status.credentialSecretRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
status.credentialSecretRef.namespacestringnononeNamespace of the secret. Defaults to the resource’s namespace if empty.

Validation for status.credentialSecretRef.namespace:

maxLength: 63
FieldTypeRequired in parentSchema defaultDescription
status.observedGenerationintegernononeObservedGeneration is the last generation processed.

Validation for status.observedGeneration:

format: int64
FieldTypeRequired in parentSchema defaultDescription
status.ownerIdstringnononeOwnerID binds remote Access resources to this installation and CR incarnation.

Validation for status.ownerId:

pattern: ^[a-f0-9]{28}$
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplicationsarraynononePendingApplications checkpoint successful targets while previous protection is retained.

Validation for status.pendingApplications:

maxItems: 64
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[]objectnononeAccessApplicationObserved records a Cloudflare Access Application created for one host/path target.
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].audstringnononeAUD is the Application Audience Tag.

Validation for status.pendingApplications[].aud:

maxLength: 255
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].domainstringnononeDomain is the protected hostname/path in Cloudflare.

Validation for status.pendingApplications[].domain:

maxLength: 1024
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].idstringnononeID is the Cloudflare Access Application ID.

Validation for status.pendingApplications[].id:

maxLength: 36
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].targetRefobjectnononeTargetRef identifies the Gateway API target that produced this application.

Validation for status.pendingApplications[].targetRef:

x-kubernetes-validations:
- message: group must be gateway.networking.k8s.io
rule: self.group == 'gateway.networking.k8s.io'
- message: kind must be Gateway or HTTPRoute
rule: self.kind in ['Gateway', 'HTTPRoute']
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].targetRef.groupstringyes"gateway.networking.k8s.io"Group is the API group of the target resource.

Validation for status.pendingApplications[].targetRef.group:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].targetRef.kindstringyesnoneKind is the kind of the target resource.

Allowed values for status.pendingApplications[].targetRef.kind: ["Gateway","HTTPRoute"].

Validation for status.pendingApplications[].targetRef.kind:

maxLength: 63
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].targetRef.namestringyesnoneName is the name of the target resource.

Validation for status.pendingApplications[].targetRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].targetRef.namespacestringnononeNamespace is the namespace of the target resource.
Cross-namespace targeting requires ReferenceGrant.

Validation for status.pendingApplications[].targetRef.namespace:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
status.pendingApplications[].targetRef.sectionNamestringnononeSectionName targets specific listener (Gateway) or rule (Route).

Validation for status.pendingApplications[].targetRef.sectionName:

maxLength: 253