Skip to content

cfgate.iocfgate v0.2.0-alpha.11 · Release documentation

CloudflareTunnel schema

These fields come from the released CRD. Required means required when its parent object is present. Schema defaults do not describe every runtime fallback.

FieldTypeRequired in parentSchema defaultDescription
FieldTypeRequired in parentSchema defaultDescription
“objectnononeCloudflareTunnel is the Schema for the cloudflaretunnels API.

CloudflareTunnel manages the lifecycle of a Cloudflare Tunnel and its cloudflared daemon
deployment. It handles tunnel creation or adoption, credential management, and deploys
cloudflared pods that establish secure connections to Cloudflare’s edge network.

CloudflareTunnel follows a composable architecture where tunnel lifecycle is separate from
DNS management. Use CloudflareDNS with a tunnelRef to create DNS records pointing to this
tunnel’s domain.

Status conditions:
- Ready: tunnel is fully operational
- CredentialsValid: API credentials have been validated
- TunnelReady: tunnel exists in Cloudflare
- ConfigurationSynced: ingress configuration is synced
- CloudflaredDeployed: cloudflared pods are running
FieldTypeRequired in parentSchema defaultDescription
apiVersionstringnononeAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
FieldTypeRequired in parentSchema defaultDescription
kindstringnononeKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
FieldTypeRequired in parentSchema defaultDescription
metadataobjectnonone
FieldTypeRequired in parentSchema defaultDescription
specobjectnononeCloudflareTunnelSpec defines the desired state of a CloudflareTunnel resource.

CloudflareTunnelSpec configures the tunnel identity, Cloudflare credentials, cloudflared
deployment settings, and origin connection defaults. The tunnel manages lifecycle only;
DNS records are managed separately via CloudflareDNS resources.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflareobjectyesnoneCloudflare defines the Cloudflare API credentials.

Validation for spec.cloudflare:

x-kubernetes-validations:
- message: either accountId or accountName must be specified
rule: has(self.accountId) || has(self.accountName)
- message: accountId must be a 32-character hex string
rule: "!has(self.accountId) || self.accountId.matches('^[a-f0-9]{32}$')"
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflare.accountIdstringnononeAccountID is the Cloudflare Account ID.

Validation for spec.cloudflare.accountId:

maxLength: 32
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflare.accountNamestringnononeAccountName is the Cloudflare Account name. Will be looked up via API.

Validation for spec.cloudflare.accountName:

maxLength: 255
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflare.secretKeysobjectnononeSecretKeys defines the key mappings within the secret.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflare.secretKeys.apiTokenstringno"CLOUDFLARE_API_TOKEN"APIToken is the key name for the Cloudflare API token.

Validation for spec.cloudflare.secretKeys.apiToken:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflare.secretRefobjectyesnoneSecretRef references the Secret containing Cloudflare API credentials.
The secret must contain an API token (not tunnel token).
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflare.secretRef.namestringyesnoneName of the secret.

Validation for spec.cloudflare.secretRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflare.secretRef.namespacestringnononeNamespace of the secret. Defaults to the tunnel’s namespace.

Validation for spec.cloudflare.secretRef.namespace:

maxLength: 63
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflaredobjectnononeCloudflared defines the cloudflared deployment configuration.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.extraArgsarraynononeExtraArgs are additional arguments to pass to cloudflared.

Validation for spec.cloudflared.extraArgs:

maxItems: 20
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.extraArgs[]stringnonone
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.imagestringno"ghcr.io/inherent-design/cloudflared:2026.9.3-h2c.1@sha256:6c46ca006f9d6af5e973e59f2d71f5d6d3dc138c8a5484380d5797092171e3ad"Image is the cloudflared container image.

Validation for spec.cloudflared.image:

maxLength: 255
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.imagePullPolicystringno"IfNotPresent"ImagePullPolicy is the pull policy for the cloudflared image.

Allowed values for spec.cloudflared.imagePullPolicy: ["Always","Never","IfNotPresent"].

FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.metricsobjectnononeMetrics configures the cloudflared metrics endpoint.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.metrics.enabledbooleannotrueEnabled declares the metrics container port for scraping. Health probes and their shared listener remain enabled.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.metrics.portintegerno44483Port is the port for the metrics endpoint.

Validation for spec.cloudflared.metrics.port:

format: int32
maximum: 65535
minimum: 1
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.nodeSelectorobjectnononeNodeSelector is a selector for nodes to run cloudflared on.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.nodeSelector[key]stringnonone
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.podAnnotationsobjectnononePodAnnotations are annotations to add to cloudflared pods.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.podAnnotations[key]stringnonone
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.protocolstringno"auto"Protocol is the tunnel transport protocol: auto, quic, http2.

Allowed values for spec.cloudflared.protocol: ["auto","quic","http2"].

FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.replicasintegerno2Replicas is the number of cloudflared replicas.

Validation for spec.cloudflared.replicas:

format: int32
maximum: 10
minimum: 1
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resourcesobjectnononeResources are the resource requirements for cloudflared containers.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resources.claimsarraynononeClaims lists the names of resources, defined in spec.resourceClaims,
that are used by this container.

This field depends on the
DynamicResourceAllocation feature gate.

This field is immutable. It can only be set for containers.

Validation for spec.cloudflared.resources.claims:

x-kubernetes-list-map-keys:
- name
x-kubernetes-list-type: map
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resources.claims[]objectnononeResourceClaim references one entry in PodSpec.ResourceClaims.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resources.claims[].namestringyesnoneName must match the name of one entry in pod.spec.resourceClaims of
the Pod where this field is used. It makes that resource available
inside a container.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resources.claims[].requeststringnononeRequest is the name chosen for a request in the referenced claim.
If empty, everything from the claim is made available, otherwise
only the result of this request.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resources.limitsobjectnononeLimits describes the maximum amount of compute resources allowed.
More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resources.limits[key]integer or stringnonone

Validation for spec.cloudflared.resources.limits[key]:

anyOf:
- type: integer
- type: string
pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
x-kubernetes-int-or-string: true
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resources.requestsobjectnononeRequests describes the minimum amount of compute resources required.
If Requests is omitted for a container, it defaults to Limits if that is explicitly specified,
otherwise to an implementation-defined value. Requests cannot exceed Limits.
More info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.resources.requests[key]integer or stringnonone

Validation for spec.cloudflared.resources.requests[key]:

anyOf:
- type: integer
- type: string
pattern: ^(\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\+|-)?(([0-9]+(\.[0-9]*)?)|(\.[0-9]+))))?$
x-kubernetes-int-or-string: true
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.tolerationsarraynononeTolerations are tolerations for the cloudflared pods.

Validation for spec.cloudflared.tolerations:

maxItems: 20
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.tolerations[]objectnononeThe pod this Toleration is attached to tolerates any taint that matches
the triple <key,value,effect> using the matching operator .
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.tolerations[].effectstringnononeEffect indicates the taint effect to match. Empty means match all taint effects.
When specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.tolerations[].keystringnononeKey is the taint key that the toleration applies to. Empty means match all taint keys.
If the key is empty, operator must be Exists; this combination means to match all values and all keys.
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.tolerations[].operatorstringnononeOperator represents a key’s relationship to the value.
Valid operators are Exists, Equal, Lt, and Gt. Defaults to Equal.
Exists is equivalent to wildcard for value, so that a pod can
tolerate all taints of a particular category.
Lt and Gt perform numeric comparisons (requires feature gate TaintTolerationComparisonOperators).
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.tolerations[].tolerationSecondsintegernononeTolerationSeconds represents the period of time the toleration (which must be
of effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,
it is not set, which means tolerate the taint forever (do not evict). Zero and
negative values will be treated as 0 (evict immediately) by the system.

Validation for spec.cloudflared.tolerations[].tolerationSeconds:

format: int64
FieldTypeRequired in parentSchema defaultDescription
spec.cloudflared.tolerations[].valuestringnononeValue is the taint value the toleration matches to.
If the operator is Exists, the value should be empty, otherwise just a regular string.
FieldTypeRequired in parentSchema defaultDescription
spec.fallbackCredentialsRefobjectnononeFallbackCredentialsRef references a secret containing fallback Cloudflare API credentials.
Used during deletion when primary credentials (in Cloudflare.SecretRef) are unavailable.
This enables cleanup of Cloudflare resources even if the per-tunnel secret is deleted.
The secret must contain the same keys as the primary credentials secret.
FieldTypeRequired in parentSchema defaultDescription
spec.fallbackCredentialsRef.namestringyesnoneName of the secret.

Validation for spec.fallbackCredentialsRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
spec.fallbackCredentialsRef.namespacestringnononeNamespace of the secret. Defaults to the resource’s namespace if empty.

Validation for spec.fallbackCredentialsRef.namespace:

maxLength: 63
FieldTypeRequired in parentSchema defaultDescription
spec.fallbackTargetstringno"http_status:404"FallbackTarget is the service for unmatched requests.

Validation for spec.fallbackTarget:

maxLength: 255
FieldTypeRequired in parentSchema defaultDescription
spec.originDefaultsobjectnononeOriginDefaults defines default settings for origin connections.

Validation for spec.originDefaults:

x-kubernetes-validations:
- message: http2Origin and h2cOrigin are mutually exclusive
rule: "!(self.http2Origin && self.h2cOrigin)"
FieldTypeRequired in parentSchema defaultDescription
spec.originDefaults.caPoolSecretRefobjectnononeCAPoolSecretRef references a Secret containing CA certificates for origin verification.
FieldTypeRequired in parentSchema defaultDescription
spec.originDefaults.caPoolSecretRef.keystringno"ca.crt"Key is the key within the secret data.

Validation for spec.originDefaults.caPoolSecretRef.key:

maxLength: 253
FieldTypeRequired in parentSchema defaultDescription
spec.originDefaults.caPoolSecretRef.namestringyesnoneName of the secret.

Validation for spec.originDefaults.caPoolSecretRef.name:

maxLength: 253
minLength: 1
FieldTypeRequired in parentSchema defaultDescription
spec.originDefaults.connectTimeoutstringno"30s"ConnectTimeout is the timeout for connecting to the origin.

Validation for spec.originDefaults.connectTimeout:

pattern: ^[0-9]+(s|m|h)$
FieldTypeRequired in parentSchema defaultDescription
spec.originDefaults.h2cOriginbooleannofalseH2cOrigin enables HTTP/2 cleartext (h2c) for origin connections.
Use this for origins that speak HTTP/2 without TLS (e.g., gRPC services).
Mutually exclusive with http2Origin (TLS-based HTTP/2).
FieldTypeRequired in parentSchema defaultDescription
spec.originDefaults.http2OriginbooleannofalseHTTP2Origin enables HTTP/2 for origin connections.
FieldTypeRequired in parentSchema defaultDescription
spec.originDefaults.noTLSVerifybooleannofalseNoTLSVerify disables TLS verification for origin connections.
FieldTypeRequired in parentSchema defaultDescription
spec.tunnelobjectyesnoneTunnel defines the tunnel identity configuration.
FieldTypeRequired in parentSchema defaultDescription
spec.tunnel.namestringyesnoneName is the tunnel name in Cloudflare. Existing tunnels require explicit
cfgate.io/adopt-existing=true and an exclusive installation ownership claim.
If not, create it. Tunnel ID is stored in status after resolution/creation.

Validation for spec.tunnel.name:

maxLength: 63
minLength: 1
pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
FieldTypeRequired in parentSchema defaultDescription
statusobjectnononeCloudflareTunnelStatus defines the observed state of a CloudflareTunnel resource.

CloudflareTunnelStatus captures the tunnel’s Cloudflare-assigned identifiers, deployment
status, and reconciliation state. The TunnelDomain field provides the CNAME target
({tunnelId}.cfargotunnel.com) that CloudflareDNS uses for DNS record creation.
FieldTypeRequired in parentSchema defaultDescription
status.accessDependenciesarraynononeAccessDependencies track applications needed by current or possibly applied configurations.
Entries are cleared only after remote configuration withdrawal is confirmed.

Validation for status.accessDependencies:

maxItems: 256
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[]objectnononeTunnelAccessDependency records possibly active application and policy protection.
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].accountIdstringyesnone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].hostnamesarrayyesnone

Validation for status.accessDependencies[].hostnames:

maxItems: 64
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].hostnames[]stringnonone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].namestringyesnone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].namespacestringyesnone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].pendingbooleannononePending records an unconfirmed publication attempt; protection cannot be removed until a later confirmed sync.
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].policiesarraynonone

Validation for status.accessDependencies[].policies:

maxItems: 64
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].policies[]objectnononeTunnelAccessPolicyDependency retains policy identity until remote withdrawal is verified.
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].policies[].namestringyesnone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].policies[].namespacestringyesnone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].policies[].policyIdstringnonone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].policies[].uidstringnonone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].tunnelIdstringyesnone
FieldTypeRequired in parentSchema defaultDescription
status.accessDependencies[].uidstringnonone
FieldTypeRequired in parentSchema defaultDescription
status.accountIdstringnononeAccountID is the resolved Cloudflare account ID.
FieldTypeRequired in parentSchema defaultDescription
status.conditionsarraynononeConditions represent the latest available observations of the tunnel’s state.

Validation for status.conditions:

x-kubernetes-list-map-keys:
- type
x-kubernetes-list-type: map
FieldTypeRequired in parentSchema defaultDescription
status.conditions[]objectnononeCondition contains details for one aspect of the current state of this API Resource.
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].lastTransitionTimestringyesnonelastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.

Validation for status.conditions[].lastTransitionTime:

format: date-time
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].messagestringyesnonemessage is a human readable message indicating details about the transition.
This may be an empty string.

Validation for status.conditions[].message:

maxLength: 32768
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].observedGenerationintegernononeobservedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.

Validation for status.conditions[].observedGeneration:

format: int64
minimum: 0
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].reasonstringyesnonereason contains a programmatic identifier indicating the reason for the condition’s last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.

Validation for status.conditions[].reason:

maxLength: 1024
minLength: 1
pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
FieldTypeRequired in parentSchema defaultDescription
status.conditions[].statusstringyesnonestatus of the condition, one of True, False, Unknown.

Allowed values for status.conditions[].status: ["True","False","Unknown"].

FieldTypeRequired in parentSchema defaultDescription
status.conditions[].typestringyesnonetype of condition in CamelCase or in foo.example.com/CamelCase.

Validation for status.conditions[].type:

maxLength: 316
pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$
FieldTypeRequired in parentSchema defaultDescription
status.connectedRouteCountintegernononeConnectedRouteCount is the number of routes connected to this tunnel.

Validation for status.connectedRouteCount:

format: int32
FieldTypeRequired in parentSchema defaultDescription
status.lastFullReconcileTimestringnononeLastFullReconcileTime is the last successful credentials, tunnel, deployment, and configuration reconciliation.
Configuration-only reconciliations do not advance this timestamp.

Validation for status.lastFullReconcileTime:

format: date-time
FieldTypeRequired in parentSchema defaultDescription
status.lastSyncTimestringnononeLastSyncTime is the last time the configuration was synced to Cloudflare.

Validation for status.lastSyncTime:

format: date-time
FieldTypeRequired in parentSchema defaultDescription
status.lifecycleDependencyHashstringnononeLifecycleDependencyHash identifies the Secret revisions and Deployment generation checked during the last full reconciliation.
It contains no Secret data.
FieldTypeRequired in parentSchema defaultDescription
status.observedGenerationintegernononeObservedGeneration is the generation observed by the controller.

Validation for status.observedGeneration:

format: int64
FieldTypeRequired in parentSchema defaultDescription
status.readyReplicasintegernononeReadyReplicas is the number of ready cloudflared replicas.

Validation for status.readyReplicas:

format: int32
FieldTypeRequired in parentSchema defaultDescription
status.replicasintegernononeReplicas is the total number of cloudflared replicas.

Validation for status.replicas:

format: int32
FieldTypeRequired in parentSchema defaultDescription
status.tunnelDomainstringnononeTunnelDomain is the tunnel’s CNAME target domain (e.g., {tunnelId}.cfargotunnel.com).
FieldTypeRequired in parentSchema defaultDescription
status.tunnelIdstringnononeTunnelID is the Cloudflare tunnel ID.
FieldTypeRequired in parentSchema defaultDescription
status.tunnelNamestringnononeTunnelName is the Cloudflare tunnel name.