cfgate.iocfgate v0.2.0-alpha.11 · Release documentation
CloudflareAccessPolicy schema
These fields come from the released CRD. Required means required when its parent object is present. Schema defaults do not describe every runtime fallback.
v1alpha1
Section titled “v1alpha1”| Field | Type | Required in parent | Schema default | Description |
|---|
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
| “ | object | no | none | CloudflareAccessPolicy is the Schema for the cloudflareaccesspolicies API. CloudflareAccessPolicy manages a reusable account-level Cloudflare Access Policy. CloudflareAccessApplication attaches reusable policies to Gateway API targets. Access rules are organized into implementation tiers based on IdP requirements: - P0: IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken (no IdP) - P1: Email, EmailList, EmailDomain, OIDCClaim (basic IdP required) - P2: GSuiteGroup (Google Workspace required) - P3: not in current product scope (Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc.) Status conditions: - Ready: policy is synced and service tokens are ready when configured - CredentialsValid: Cloudflare credentials have been validated - ServiceTokensReady: all service tokens have been created - PolicySynced: reusable Access policy exists in Cloudflare |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
apiVersion | string | no | none | APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
kind | string | no | none | Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
metadata | object | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec | object | no | none | CloudflareAccessPolicySpec defines a reusable Cloudflare Access policy. CloudflareAccessPolicySpec manages account-level reusable Access policies. Applications attach these policies through CloudflareAccessApplication policyRefs. |
Validation for spec:
x-kubernetes-validations: - message: include rules are required rule: size(self.include) > 0| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.approvalGroups | array | no | none | ApprovalGroups defines who can approve access. |
Validation for spec.approvalGroups:
maxItems: 10| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.approvalGroups[] | object | no | none | ApprovalGroup defines who can approve access requests for approval-required policies. ApprovalGroup specifies approvers by email address or email list UUID. When a policy requires approval, users matching this group can approve or deny access requests. |
Validation for spec.approvalGroups[]:
x-kubernetes-validations: - message: at least one approver (emails or emailListUuid) must be specified rule: (has(self.emails) && size(self.emails) > 0) || has(self.emailListUuid)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.approvalGroups[].approvalsNeeded | integer | no | 1 | ApprovalsNeeded is number of approvals required. |
Validation for spec.approvalGroups[].approvalsNeeded:
minimum: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.approvalGroups[].emailListUuid | string | no | none | EmailListUUID is a Cloudflare Access email list UUID whose members can approve. |
Validation for spec.approvalGroups[].emailListUuid:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.approvalGroups[].emails | array | no | none | Emails of approvers. |
Validation for spec.approvalGroups[].emails:
maxItems: 50| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.approvalGroups[].emails[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.approvalRequired | boolean | no | false | ApprovalRequired requires approval from specific users. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef | object | yes | none | CloudflareRef references Cloudflare credentials. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.accountId | string | no | none | AccountID is the Cloudflare account ID. |
Validation for spec.cloudflareRef.accountId:
maxLength: 32| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.accountName | string | no | none | AccountName is the Cloudflare account name (looked up via API). |
Validation for spec.cloudflareRef.accountName:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.name | string | yes | none | Name of the secret containing credentials. |
Validation for spec.cloudflareRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.namespace | string | no | none | Namespace of the secret (defaults to policy namespace). |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.secretKeys | object | no | none | SecretKeys selects credential data keys; omitted keys use their defaults. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.cloudflareRef.secretKeys.apiToken | string | no | "CLOUDFLARE_API_TOKEN" | APIToken is the key name for the Cloudflare API token. |
Validation for spec.cloudflareRef.secretKeys.apiToken:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.decision | string | yes | "allow" | Decision is the policy action. |
Allowed values for spec.decision: ["allow","deny","bypass","non_identity"].
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude | array | no | none | Exclude rules (if ANY match, policy does not apply). |
Validation for spec.exclude:
maxItems: 25| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[] | object | no | none | AccessRule defines identity matching criteria for Access policies. AccessRule specifies conditions that identify users or services. Rules are organized into implementation tiers based on IdP requirements: - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim - P2 (Google Workspace): GSuiteGroup - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc. Selector types map to the Cloudflare API: IPRule, IPListRule, CountryRule, EveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule, EmailListRule, AccessOIDCClaimRule, GSuiteGroupRule. |
Validation for spec.exclude[]:
x-kubernetes-validations: - message: exactly one rule type must be specified rule: "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].anyValidServiceToken | boolean | no | none | AnyValidServiceToken matches any valid service token. When present, it must be true. Omit the rule to disable it. SDK: AnyValidServiceTokenRule |
Validation for spec.exclude[].anyValidServiceToken:
x-kubernetes-validations: - message: must be true; omit the rule to disable it rule: self == true| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].country | object | no | none | Country matches source country codes (ISO 3166-1 alpha-2). SDK: CountryRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].country.codes | array | yes | none | Codes are ISO 3166-1 alpha-2 country codes. |
Validation for spec.exclude[].country.codes:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].country.codes[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].email | object | no | none | Email matches specific email addresses. SDK: EmailRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].email.addresses | array | yes | none | Addresses to match. |
Validation for spec.exclude[].email.addresses:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].email.addresses[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].emailDomain | object | no | none | EmailDomain matches email domain suffix. SDK: DomainRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].emailDomain.domain | string | yes | none | Domain suffix (e.g., “example.com”). Max 253: RFC 1035 section 2.3.4 FQDN presentation-format limit. |
Validation for spec.exclude[].emailDomain.domain:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].emailList | object | no | none | EmailList references a Cloudflare Access email list. SDK: EmailListRule |
Validation for spec.exclude[].emailList:
x-kubernetes-validations: - message: id must be specified rule: has(self.id)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].emailList.id | string | no | none | ID of the Access list in Cloudflare. |
Validation for spec.exclude[].emailList.id:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].emailList.name | string | no | none | Name is not supported for lookup in v1alpha1. Specify id instead. Deprecated: use id. |
Validation for spec.exclude[].emailList.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].everyone | boolean | no | none | Everyone matches all users. When present, it must be true. Omit the rule to disable it. SDK: EveryoneRule |
Validation for spec.exclude[].everyone:
x-kubernetes-validations: - message: must be true; omit the rule to disable it rule: self == true| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].group | object | no | none | Group matches a Cloudflare Access Group by ID. SDK: GroupRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].group.id | string | yes | none | ID is the Cloudflare Access Group ID. |
Validation for spec.exclude[].group.id:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].gsuiteGroup | object | no | none | GSuiteGroup matches Google Workspace groups. SDK: GSuiteGroupRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].gsuiteGroup.email | string | yes | none | Email is the Google Workspace group email. |
Validation for spec.exclude[].gsuiteGroup.email:
maxLength: 320minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].gsuiteGroup.identityProviderId | string | yes | none | IdentityProviderID in Cloudflare. |
Validation for spec.exclude[].gsuiteGroup.identityProviderId:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].ip | object | no | none | IP matches source IP CIDR ranges. SDK: IPRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].ip.ranges | array | yes | none | Ranges are CIDR blocks (IPv4 or IPv6). |
Validation for spec.exclude[].ip.ranges:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].ip.ranges[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].ipList | object | no | none | IPList references a Cloudflare IP List. SDK: IPListRule |
Validation for spec.exclude[].ipList:
x-kubernetes-validations: - message: id must be specified rule: has(self.id)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].ipList.id | string | no | none | ID of the IP list in Cloudflare. |
Validation for spec.exclude[].ipList.id:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].ipList.name | string | no | none | Name is not supported for lookup in v1alpha1. Specify id instead. Deprecated: use id. |
Validation for spec.exclude[].ipList.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].oidcClaim | object | no | none | OIDCClaim matches OIDC token claims. SDK: AccessOIDCClaimRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].oidcClaim.claimName | string | yes | none | ClaimName is the OIDC claim to match. |
Validation for spec.exclude[].oidcClaim.claimName:
maxLength: 255minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].oidcClaim.claimValue | string | yes | none | ClaimValue is the expected value. |
Validation for spec.exclude[].oidcClaim.claimValue:
maxLength: 255minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].oidcClaim.identityProviderId | string | yes | none | IdentityProviderID in Cloudflare. |
Validation for spec.exclude[].oidcClaim.identityProviderId:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].serviceToken | object | no | none | ServiceToken matches a specific service token by ID. SDK: ServiceTokenRule |
Validation for spec.exclude[].serviceToken:
x-kubernetes-validations: - message: either tokenId or name must be specified rule: has(self.tokenId) || has(self.name)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].serviceToken.name | string | no | none | Name references an entry in spec.serviceTokens. The controller replaces it with the created Cloudflare service token ID during policy sync. |
Validation for spec.exclude[].serviceToken.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.exclude[].serviceToken.tokenId | string | no | none | TokenID is the Cloudflare service token ID. |
Validation for spec.exclude[].serviceToken.tokenId:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include | array | yes | none | Include rules (ANY must match for policy to apply). |
Validation for spec.include:
maxItems: 25minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[] | object | no | none | AccessRule defines identity matching criteria for Access policies. AccessRule specifies conditions that identify users or services. Rules are organized into implementation tiers based on IdP requirements: - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim - P2 (Google Workspace): GSuiteGroup - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc. Selector types map to the Cloudflare API: IPRule, IPListRule, CountryRule, EveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule, EmailListRule, AccessOIDCClaimRule, GSuiteGroupRule. |
Validation for spec.include[]:
x-kubernetes-validations: - message: exactly one rule type must be specified rule: "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].anyValidServiceToken | boolean | no | none | AnyValidServiceToken matches any valid service token. When present, it must be true. Omit the rule to disable it. SDK: AnyValidServiceTokenRule |
Validation for spec.include[].anyValidServiceToken:
x-kubernetes-validations: - message: must be true; omit the rule to disable it rule: self == true| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].country | object | no | none | Country matches source country codes (ISO 3166-1 alpha-2). SDK: CountryRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].country.codes | array | yes | none | Codes are ISO 3166-1 alpha-2 country codes. |
Validation for spec.include[].country.codes:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].country.codes[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].email | object | no | none | Email matches specific email addresses. SDK: EmailRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].email.addresses | array | yes | none | Addresses to match. |
Validation for spec.include[].email.addresses:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].email.addresses[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].emailDomain | object | no | none | EmailDomain matches email domain suffix. SDK: DomainRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].emailDomain.domain | string | yes | none | Domain suffix (e.g., “example.com”). Max 253: RFC 1035 section 2.3.4 FQDN presentation-format limit. |
Validation for spec.include[].emailDomain.domain:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].emailList | object | no | none | EmailList references a Cloudflare Access email list. SDK: EmailListRule |
Validation for spec.include[].emailList:
x-kubernetes-validations: - message: id must be specified rule: has(self.id)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].emailList.id | string | no | none | ID of the Access list in Cloudflare. |
Validation for spec.include[].emailList.id:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].emailList.name | string | no | none | Name is not supported for lookup in v1alpha1. Specify id instead. Deprecated: use id. |
Validation for spec.include[].emailList.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].everyone | boolean | no | none | Everyone matches all users. When present, it must be true. Omit the rule to disable it. SDK: EveryoneRule |
Validation for spec.include[].everyone:
x-kubernetes-validations: - message: must be true; omit the rule to disable it rule: self == true| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].group | object | no | none | Group matches a Cloudflare Access Group by ID. SDK: GroupRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].group.id | string | yes | none | ID is the Cloudflare Access Group ID. |
Validation for spec.include[].group.id:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].gsuiteGroup | object | no | none | GSuiteGroup matches Google Workspace groups. SDK: GSuiteGroupRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].gsuiteGroup.email | string | yes | none | Email is the Google Workspace group email. |
Validation for spec.include[].gsuiteGroup.email:
maxLength: 320minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].gsuiteGroup.identityProviderId | string | yes | none | IdentityProviderID in Cloudflare. |
Validation for spec.include[].gsuiteGroup.identityProviderId:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].ip | object | no | none | IP matches source IP CIDR ranges. SDK: IPRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].ip.ranges | array | yes | none | Ranges are CIDR blocks (IPv4 or IPv6). |
Validation for spec.include[].ip.ranges:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].ip.ranges[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].ipList | object | no | none | IPList references a Cloudflare IP List. SDK: IPListRule |
Validation for spec.include[].ipList:
x-kubernetes-validations: - message: id must be specified rule: has(self.id)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].ipList.id | string | no | none | ID of the IP list in Cloudflare. |
Validation for spec.include[].ipList.id:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].ipList.name | string | no | none | Name is not supported for lookup in v1alpha1. Specify id instead. Deprecated: use id. |
Validation for spec.include[].ipList.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].oidcClaim | object | no | none | OIDCClaim matches OIDC token claims. SDK: AccessOIDCClaimRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].oidcClaim.claimName | string | yes | none | ClaimName is the OIDC claim to match. |
Validation for spec.include[].oidcClaim.claimName:
maxLength: 255minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].oidcClaim.claimValue | string | yes | none | ClaimValue is the expected value. |
Validation for spec.include[].oidcClaim.claimValue:
maxLength: 255minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].oidcClaim.identityProviderId | string | yes | none | IdentityProviderID in Cloudflare. |
Validation for spec.include[].oidcClaim.identityProviderId:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].serviceToken | object | no | none | ServiceToken matches a specific service token by ID. SDK: ServiceTokenRule |
Validation for spec.include[].serviceToken:
x-kubernetes-validations: - message: either tokenId or name must be specified rule: has(self.tokenId) || has(self.name)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].serviceToken.name | string | no | none | Name references an entry in spec.serviceTokens. The controller replaces it with the created Cloudflare service token ID during policy sync. |
Validation for spec.include[].serviceToken.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.include[].serviceToken.tokenId | string | no | none | TokenID is the Cloudflare service token ID. |
Validation for spec.include[].serviceToken.tokenId:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.name | string | yes | none | Name is the Cloudflare Access policy display name. |
Validation for spec.name:
maxLength: 255minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.purposeJustificationPrompt | string | no | none | PurposeJustificationPrompt is the prompt shown to user. |
Validation for spec.purposeJustificationPrompt:
maxLength: 1024| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.purposeJustificationRequired | boolean | no | false | PurposeJustificationRequired requires user to provide justification. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require | array | no | none | Require rules (ALL must match for policy to apply). |
Validation for spec.require:
maxItems: 25| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[] | object | no | none | AccessRule defines identity matching criteria for Access policies. AccessRule specifies conditions that identify users or services. Rules are organized into implementation tiers based on IdP requirements: - P0 (no IdP): IP, IPList, Country, Everyone, ServiceToken, AnyValidServiceToken - P1 (basic IdP): Email, EmailList, EmailDomain, OIDCClaim - P2 (Google Workspace): GSuiteGroup - P3 (not in current product scope): Certificate, CommonName, Group, GitHub, Azure, Okta, SAML, etc. Selector types map to the Cloudflare API: IPRule, IPListRule, CountryRule, EveryoneRule, ServiceTokenRule, AnyValidServiceTokenRule, EmailRule, DomainRule, EmailListRule, AccessOIDCClaimRule, GSuiteGroupRule. |
Validation for spec.require[]:
x-kubernetes-validations: - message: exactly one rule type must be specified rule: "[has(self.ip), has(self.ipList), has(self.country), has(self.everyone), has(self.serviceToken), has(self.anyValidServiceToken), has(self.email), has(self.emailList), has(self.emailDomain), has(self.oidcClaim), has(self.gsuiteGroup), has(self.group)].filter(x, x).size() == 1"| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].anyValidServiceToken | boolean | no | none | AnyValidServiceToken matches any valid service token. When present, it must be true. Omit the rule to disable it. SDK: AnyValidServiceTokenRule |
Validation for spec.require[].anyValidServiceToken:
x-kubernetes-validations: - message: must be true; omit the rule to disable it rule: self == true| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].country | object | no | none | Country matches source country codes (ISO 3166-1 alpha-2). SDK: CountryRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].country.codes | array | yes | none | Codes are ISO 3166-1 alpha-2 country codes. |
Validation for spec.require[].country.codes:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].country.codes[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].email | object | no | none | Email matches specific email addresses. SDK: EmailRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].email.addresses | array | yes | none | Addresses to match. |
Validation for spec.require[].email.addresses:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].email.addresses[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].emailDomain | object | no | none | EmailDomain matches email domain suffix. SDK: DomainRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].emailDomain.domain | string | yes | none | Domain suffix (e.g., “example.com”). Max 253: RFC 1035 section 2.3.4 FQDN presentation-format limit. |
Validation for spec.require[].emailDomain.domain:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].emailList | object | no | none | EmailList references a Cloudflare Access email list. SDK: EmailListRule |
Validation for spec.require[].emailList:
x-kubernetes-validations: - message: id must be specified rule: has(self.id)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].emailList.id | string | no | none | ID of the Access list in Cloudflare. |
Validation for spec.require[].emailList.id:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].emailList.name | string | no | none | Name is not supported for lookup in v1alpha1. Specify id instead. Deprecated: use id. |
Validation for spec.require[].emailList.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].everyone | boolean | no | none | Everyone matches all users. When present, it must be true. Omit the rule to disable it. SDK: EveryoneRule |
Validation for spec.require[].everyone:
x-kubernetes-validations: - message: must be true; omit the rule to disable it rule: self == true| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].group | object | no | none | Group matches a Cloudflare Access Group by ID. SDK: GroupRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].group.id | string | yes | none | ID is the Cloudflare Access Group ID. |
Validation for spec.require[].group.id:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].gsuiteGroup | object | no | none | GSuiteGroup matches Google Workspace groups. SDK: GSuiteGroupRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].gsuiteGroup.email | string | yes | none | Email is the Google Workspace group email. |
Validation for spec.require[].gsuiteGroup.email:
maxLength: 320minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].gsuiteGroup.identityProviderId | string | yes | none | IdentityProviderID in Cloudflare. |
Validation for spec.require[].gsuiteGroup.identityProviderId:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].ip | object | no | none | IP matches source IP CIDR ranges. SDK: IPRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].ip.ranges | array | yes | none | Ranges are CIDR blocks (IPv4 or IPv6). |
Validation for spec.require[].ip.ranges:
maxItems: 50minItems: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].ip.ranges[] | string | no | none |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].ipList | object | no | none | IPList references a Cloudflare IP List. SDK: IPListRule |
Validation for spec.require[].ipList:
x-kubernetes-validations: - message: id must be specified rule: has(self.id)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].ipList.id | string | no | none | ID of the IP list in Cloudflare. |
Validation for spec.require[].ipList.id:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].ipList.name | string | no | none | Name is not supported for lookup in v1alpha1. Specify id instead. Deprecated: use id. |
Validation for spec.require[].ipList.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].oidcClaim | object | no | none | OIDCClaim matches OIDC token claims. SDK: AccessOIDCClaimRule |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].oidcClaim.claimName | string | yes | none | ClaimName is the OIDC claim to match. |
Validation for spec.require[].oidcClaim.claimName:
maxLength: 255minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].oidcClaim.claimValue | string | yes | none | ClaimValue is the expected value. |
Validation for spec.require[].oidcClaim.claimValue:
maxLength: 255minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].oidcClaim.identityProviderId | string | yes | none | IdentityProviderID in Cloudflare. |
Validation for spec.require[].oidcClaim.identityProviderId:
maxLength: 36minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].serviceToken | object | no | none | ServiceToken matches a specific service token by ID. SDK: ServiceTokenRule |
Validation for spec.require[].serviceToken:
x-kubernetes-validations: - message: either tokenId or name must be specified rule: has(self.tokenId) || has(self.name)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].serviceToken.name | string | no | none | Name references an entry in spec.serviceTokens. The controller replaces it with the created Cloudflare service token ID during policy sync. |
Validation for spec.require[].serviceToken.name:
maxLength: 255| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.require[].serviceToken.tokenId | string | no | none | TokenID is the Cloudflare service token ID. |
Validation for spec.require[].serviceToken.tokenId:
maxLength: 36| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.serviceTokens | array | no | none | ServiceTokens for machine-to-machine authentication. |
Validation for spec.serviceTokens:
maxItems: 10x-kubernetes-validations: - message: service token names must be unique rule: self.all(t, self.filter(x, x.name == t.name).size() == 1) - message: service token destination Secrets must be unique rule: self.all(t, self.filter(x, x.secretRef.name == t.secretRef.name).size() == 1)| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.serviceTokens[] | object | no | none | ServiceTokenConfig defines configuration for Cloudflare Access service tokens. ServiceTokenConfig enables machine-to-machine authentication. The controller creates the service token in Cloudflare and stores the credentials (client ID and secret) in the referenced Kubernetes Secret. The secret is only visible at creation time. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.serviceTokens[].duration | string | no | "8760h" | Duration is the token validity period using Go duration format. Only hours (h) supported by Cloudflare API. Use “8760h” for 1 year. |
Validation for spec.serviceTokens[].duration:
pattern: ^[1-9][0-9]*h$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.serviceTokens[].name | string | yes | none | Name is the token display name. |
Validation for spec.serviceTokens[].name:
maxLength: 255minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.serviceTokens[].rotationOverlap | string | no | "0h" | RotationOverlap keeps the previous secret valid during credential distribution. Zero expires the previous secret immediately. Consumers must reload credentials. |
Validation for spec.serviceTokens[].rotationOverlap:
pattern: ^(0|[1-9][0-9]{0,2})h$x-kubernetes-validations: - message: rotationOverlap must not exceed 720h rule: duration(self) <= duration('720h')| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.serviceTokens[].secretRef | object | yes | none | SecretRef stores the generated token credentials. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.serviceTokens[].secretRef.name | string | yes | none | Name of the Secret. |
Validation for spec.serviceTokens[].secretRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
spec.sessionDuration | string | no | none | SessionDuration overrides application session duration for this policy. |
Validation for spec.sessionDuration:
maxLength: 32pattern: ^([0-9]+(ns|us|ms|s|m|h))+$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status | object | no | none | CloudflareAccessPolicyStatus defines the observed state of a CloudflareAccessPolicy resource. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.accountId | string | no | none | AccountID is the Cloudflare account ID used for this policy. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.appCount | integer | no | none | AppCount is the number of Access Applications currently using this policy. |
Validation for status.appCount:
format: int64| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions | array | no | none | Conditions describe current state. |
Validation for status.conditions:
x-kubernetes-list-map-keys: - typex-kubernetes-list-type: map| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[] | object | no | none | Condition contains details for one aspect of the current state of this API Resource. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].lastTransitionTime | string | yes | none | lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. |
Validation for status.conditions[].lastTransitionTime:
format: date-time| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].message | string | yes | none | message is a human readable message indicating details about the transition. This may be an empty string. |
Validation for status.conditions[].message:
maxLength: 32768| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].observedGeneration | integer | no | none | observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. |
Validation for status.conditions[].observedGeneration:
format: int64minimum: 0| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].reason | string | yes | none | reason contains a programmatic identifier indicating the reason for the condition’s last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. |
Validation for status.conditions[].reason:
maxLength: 1024minLength: 1pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].status | string | yes | none | status of the condition, one of True, False, Unknown. |
Allowed values for status.conditions[].status: ["True","False","Unknown"].
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.conditions[].type | string | yes | none | type of condition in CamelCase or in foo.example.com/CamelCase. |
Validation for status.conditions[].type:
maxLength: 316pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretKeys | object | no | none | CredentialSecretKeys preserves selected token keys for cleanup. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretKeys.apiToken | string | no | "CLOUDFLARE_API_TOKEN" | APIToken is the key name for the Cloudflare API token. |
Validation for status.credentialSecretKeys.apiToken:
maxLength: 253| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretRef | object | no | none | CredentialSecretRef is the resolved credentials Secret used for cleanup. The namespace is always stored explicitly. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretRef.name | string | yes | none | Name of the secret. |
Validation for status.credentialSecretRef.name:
maxLength: 253minLength: 1| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.credentialSecretRef.namespace | string | no | none | Namespace of the secret. Defaults to the resource’s namespace if empty. |
Validation for status.credentialSecretRef.namespace:
maxLength: 63| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.observedGeneration | integer | no | none | ObservedGeneration is the last generation processed. |
Validation for status.observedGeneration:
format: int64| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.ownerId | string | no | none | OwnerID binds remote Access resources to this installation and CR incarnation. |
Validation for status.ownerId:
pattern: ^[a-f0-9]{28}$| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.policyId | string | no | none | PolicyID is the Cloudflare Access reusable policy ID. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.reusable | boolean | no | none | Reusable reports whether Cloudflare returned this policy as reusable. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.serviceTokenIds | object | no | none | ServiceTokenIDs maps token names to Cloudflare IDs. |
| Field | Type | Required in parent | Schema default | Description |
|---|---|---|---|---|
status.serviceTokenIds[key] | string | no | none |