mirror of
https://github.com/fluxcd/flagger.git
synced 2026-04-15 06:57:34 +00:00
Update Gateway API to v1.4.0
Signed-off-by: Stefan Prodan <stefan.prodan@gmail.com>
This commit is contained in:
@@ -20,11 +20,12 @@ import (
|
||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||
)
|
||||
|
||||
// +genclient
|
||||
// +k8s:deepcopy-gen:interfaces=k8s.io/apimachinery/pkg/runtime.Object
|
||||
// +genclient
|
||||
// +kubebuilder:object:root=true
|
||||
// +kubebuilder:resource:categories=gateway-api
|
||||
// +kubebuilder:subresource:status
|
||||
// +kubebuilder:storageversion
|
||||
// +kubebuilder:printcolumn:name="Hostnames",type=string,JSONPath=`.spec.hostnames`
|
||||
// +kubebuilder:printcolumn:name="Age",type=date,JSONPath=`.metadata.creationTimestamp`
|
||||
|
||||
@@ -33,13 +34,16 @@ import (
|
||||
// used to specify additional processing steps. Backends specify where matching
|
||||
// requests should be routed.
|
||||
type HTTPRoute struct {
|
||||
metav1.TypeMeta `json:",inline"`
|
||||
metav1.TypeMeta `json:",inline"`
|
||||
// +optional
|
||||
metav1.ObjectMeta `json:"metadata,omitempty"`
|
||||
|
||||
// Spec defines the desired state of HTTPRoute.
|
||||
// +required
|
||||
Spec HTTPRouteSpec `json:"spec"`
|
||||
|
||||
// Status defines the current state of HTTPRoute.
|
||||
// +optional
|
||||
Status HTTPRouteStatus `json:"status,omitempty"`
|
||||
}
|
||||
|
||||
@@ -112,14 +116,18 @@ type HTTPRouteSpec struct {
|
||||
// Support: Core
|
||||
//
|
||||
// +optional
|
||||
// +listType=atomic
|
||||
// +kubebuilder:validation:MaxItems=16
|
||||
Hostnames []Hostname `json:"hostnames,omitempty"`
|
||||
|
||||
// Rules are a list of HTTP matchers, filters and actions.
|
||||
//
|
||||
// +optional
|
||||
// +listType=atomic
|
||||
// <gateway:experimental:validation:XValidation:message="Rule name must be unique within the route",rule="self.all(l1, !has(l1.name) || self.exists_one(l2, has(l2.name) && l1.name == l2.name))">
|
||||
// +kubebuilder:validation:MaxItems=16
|
||||
// +kubebuilder:default={{matches: {{path: {type: "PathPrefix", value: "/"}}}}}
|
||||
// +kubebuilder:validation:XValidation:message="While 16 rules and 64 matches per rule are allowed, the total number of matches across all rules in a route must be less than 128",rule="(self.size() > 0 ? self[0].matches.size() : 0) + (self.size() > 1 ? self[1].matches.size() : 0) + (self.size() > 2 ? self[2].matches.size() : 0) + (self.size() > 3 ? self[3].matches.size() : 0) + (self.size() > 4 ? self[4].matches.size() : 0) + (self.size() > 5 ? self[5].matches.size() : 0) + (self.size() > 6 ? self[6].matches.size() : 0) + (self.size() > 7 ? self[7].matches.size() : 0) + (self.size() > 8 ? self[8].matches.size() : 0) + (self.size() > 9 ? self[9].matches.size() : 0) + (self.size() > 10 ? self[10].matches.size() : 0) + (self.size() > 11 ? self[11].matches.size() : 0) + (self.size() > 12 ? self[12].matches.size() : 0) + (self.size() > 13 ? self[13].matches.size() : 0) + (self.size() > 14 ? self[14].matches.size() : 0) + (self.size() > 15 ? self[15].matches.size() : 0) <= 128"
|
||||
Rules []HTTPRouteRule `json:"rules,omitempty"`
|
||||
}
|
||||
|
||||
@@ -133,6 +141,12 @@ type HTTPRouteSpec struct {
|
||||
// +kubebuilder:validation:XValidation:message="Within backendRefs, when using RequestRedirect filter with path.replacePrefixMatch, exactly one PathPrefix match must be specified",rule="(has(self.backendRefs) && self.backendRefs.exists_one(b, (has(b.filters) && b.filters.exists_one(f, has(f.requestRedirect) && has(f.requestRedirect.path) && f.requestRedirect.path.type == 'ReplacePrefixMatch' && has(f.requestRedirect.path.replacePrefixMatch))) )) ? ((size(self.matches) != 1 || !has(self.matches[0].path) || self.matches[0].path.type != 'PathPrefix') ? false : true) : true"
|
||||
// +kubebuilder:validation:XValidation:message="Within backendRefs, When using URLRewrite filter with path.replacePrefixMatch, exactly one PathPrefix match must be specified",rule="(has(self.backendRefs) && self.backendRefs.exists_one(b, (has(b.filters) && b.filters.exists_one(f, has(f.urlRewrite) && has(f.urlRewrite.path) && f.urlRewrite.path.type == 'ReplacePrefixMatch' && has(f.urlRewrite.path.replacePrefixMatch))) )) ? ((size(self.matches) != 1 || !has(self.matches[0].path) || self.matches[0].path.type != 'PathPrefix') ? false : true) : true"
|
||||
type HTTPRouteRule struct {
|
||||
// Name is the name of the route rule. This name MUST be unique within a Route if it is set.
|
||||
//
|
||||
// Support: Extended
|
||||
// +optional
|
||||
Name *SectionName `json:"name,omitempty"`
|
||||
|
||||
// Matches define conditions used for matching the rule against incoming
|
||||
// HTTP requests. Each match is independent, i.e. this rule will be matched
|
||||
// if **any** one of the matches is satisfied.
|
||||
@@ -191,15 +205,27 @@ type HTTPRouteRule struct {
|
||||
// parent a request is coming from, a HTTP 404 status code MUST be returned.
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:validation:MaxItems=8
|
||||
// +listType=atomic
|
||||
// +kubebuilder:validation:MaxItems=64
|
||||
// +kubebuilder:default={{path:{ type: "PathPrefix", value: "/"}}}
|
||||
Matches []HTTPRouteMatch `json:"matches,omitempty"`
|
||||
|
||||
// Filters define the filters that are applied to requests that match
|
||||
// this rule.
|
||||
//
|
||||
// The effects of ordering of multiple behaviors are currently unspecified.
|
||||
// This can change in the future based on feedback during the alpha stage.
|
||||
// Wherever possible, implementations SHOULD implement filters in the order
|
||||
// they are specified.
|
||||
//
|
||||
// Implementations MAY choose to implement this ordering strictly, rejecting
|
||||
// any combination or order of filters that cannot be supported. If implementations
|
||||
// choose a strict interpretation of filter ordering, they MUST clearly document
|
||||
// that behavior.
|
||||
//
|
||||
// To reject an invalid combination or order of filters, implementations SHOULD
|
||||
// consider the Route Rules with this configuration invalid. If all Route Rules
|
||||
// in a Route are invalid, the entire Route would be considered invalid. If only
|
||||
// a portion of Route Rules are invalid, implementations MUST set the
|
||||
// "PartiallyInvalid" condition for the Route.
|
||||
//
|
||||
// Conformance-levels at this level are defined based on the type of filter:
|
||||
//
|
||||
@@ -213,7 +239,7 @@ type HTTPRouteRule struct {
|
||||
//
|
||||
// All filters are expected to be compatible with each other except for the
|
||||
// URLRewrite and RequestRedirect filters, which may not be combined. If an
|
||||
// implementation can not support other combinations of filters, they must clearly
|
||||
// implementation cannot support other combinations of filters, they must clearly
|
||||
// document that limitation. In cases where incompatible or unsupported
|
||||
// filters are specified and cause the `Accepted` condition to be set to status
|
||||
// `False`, implementations may use the `IncompatibleFilters` reason to specify
|
||||
@@ -222,6 +248,7 @@ type HTTPRouteRule struct {
|
||||
// Support: Core
|
||||
//
|
||||
// +optional
|
||||
// +listType=atomic
|
||||
// +kubebuilder:validation:MaxItems=16
|
||||
// +kubebuilder:validation:XValidation:message="May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",rule="!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
|
||||
// +kubebuilder:validation:XValidation:message="RequestHeaderModifier filter cannot be repeated",rule="self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
|
||||
@@ -253,6 +280,11 @@ type HTTPRouteRule struct {
|
||||
// invalid, 50 percent of traffic must receive a 500. Implementations may
|
||||
// choose how that 50 percent is determined.
|
||||
//
|
||||
// When a HTTPBackendRef refers to a Service that has no ready endpoints,
|
||||
// implementations SHOULD return a 503 for requests to that backend instead.
|
||||
// If an implementation chooses to do this, all of the above rules for 500 responses
|
||||
// MUST also apply for responses that return a 503.
|
||||
//
|
||||
// Support: Core for Kubernetes Service
|
||||
//
|
||||
// Support: Extended for Kubernetes ServiceImport
|
||||
@@ -262,6 +294,7 @@ type HTTPRouteRule struct {
|
||||
// Support for weight: Core
|
||||
//
|
||||
// +optional
|
||||
// +listType=atomic
|
||||
// +kubebuilder:validation:MaxItems=16
|
||||
BackendRefs []HTTPBackendRef `json:"backendRefs,omitempty"`
|
||||
|
||||
@@ -270,13 +303,28 @@ type HTTPRouteRule struct {
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
// <gateway:experimental>
|
||||
Timeouts *HTTPRouteTimeouts `json:"timeouts,omitempty"`
|
||||
|
||||
// Retry defines the configuration for when to retry an HTTP request.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
// <gateway:experimental>
|
||||
Retry *HTTPRouteRetry `json:"retry,omitempty"`
|
||||
|
||||
// SessionPersistence defines and configures session persistence
|
||||
// for the route rule.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
// <gateway:experimental>
|
||||
SessionPersistence *SessionPersistence `json:"sessionPersistence,omitempty"`
|
||||
}
|
||||
|
||||
// HTTPRouteTimeouts defines timeouts that can be configured for an HTTPRoute.
|
||||
// Timeout values are represented with Gateway API Duration formatting.
|
||||
// Specifying a zero value such as "0s" is interpreted as no timeout.
|
||||
//
|
||||
// +kubebuilder:validation:XValidation:message="backendRequest timeout cannot be longer than request timeout",rule="!(has(self.request) && has(self.backendRequest) && duration(self.request) != duration('0s') && duration(self.backendRequest) > duration(self.request))"
|
||||
type HTTPRouteTimeouts struct {
|
||||
@@ -288,12 +336,18 @@ type HTTPRouteTimeouts struct {
|
||||
// `HTTPRoute` will cause a timeout if a client request is taking longer than 10 seconds
|
||||
// to complete.
|
||||
//
|
||||
// Setting a timeout to the zero duration (e.g. "0s") SHOULD disable the timeout
|
||||
// completely. Implementations that cannot completely disable the timeout MUST
|
||||
// instead interpret the zero duration as the longest possible value to which
|
||||
// the timeout can be set.
|
||||
//
|
||||
// This timeout is intended to cover as close to the whole request-response transaction
|
||||
// as possible although an implementation MAY choose to start the timeout after the entire
|
||||
// request stream has been received instead of immediately after the transaction is
|
||||
// initiated by the client.
|
||||
//
|
||||
// When this field is unspecified, request timeout behavior is implementation-specific.
|
||||
// The value of Request is a Gateway API Duration string as defined by GEP-2257. When this
|
||||
// field is unspecified, request timeout behavior is implementation-specific.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
@@ -304,12 +358,19 @@ type HTTPRouteTimeouts struct {
|
||||
// to a backend. This covers the time from when the request first starts being
|
||||
// sent from the gateway to when the full response has been received from the backend.
|
||||
//
|
||||
// Setting a timeout to the zero duration (e.g. "0s") SHOULD disable the timeout
|
||||
// completely. Implementations that cannot completely disable the timeout MUST
|
||||
// instead interpret the zero duration as the longest possible value to which
|
||||
// the timeout can be set.
|
||||
//
|
||||
// An entire client HTTP transaction with a gateway, covered by the Request timeout,
|
||||
// may result in more than one call from the gateway to the destination backend,
|
||||
// for example, if automatic retries are supported.
|
||||
//
|
||||
// Because the Request timeout encompasses the BackendRequest timeout, the value of
|
||||
// BackendRequest must be <= the value of Request timeout.
|
||||
// The value of BackendRequest must be a Gateway API Duration string as defined by
|
||||
// GEP-2257. When this field is unspecified, its behavior is implementation-specific;
|
||||
// when specified, the value of BackendRequest must be no more than the value of the
|
||||
// Request timeout (since the Request timeout encompasses the BackendRequest timeout).
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
@@ -317,6 +378,96 @@ type HTTPRouteTimeouts struct {
|
||||
BackendRequest *Duration `json:"backendRequest,omitempty"`
|
||||
}
|
||||
|
||||
// HTTPRouteRetry defines retry configuration for an HTTPRoute.
|
||||
//
|
||||
// Implementations SHOULD retry on connection errors (disconnect, reset, timeout,
|
||||
// TCP failure) if a retry stanza is configured.
|
||||
type HTTPRouteRetry struct {
|
||||
// Codes defines the HTTP response status codes for which a backend request
|
||||
// should be retried.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
// +listType=atomic
|
||||
Codes []HTTPRouteRetryStatusCode `json:"codes,omitempty"`
|
||||
|
||||
// Attempts specifies the maximum number of times an individual request
|
||||
// from the gateway to a backend should be retried.
|
||||
//
|
||||
// If the maximum number of retries has been attempted without a successful
|
||||
// response from the backend, the Gateway MUST return an error.
|
||||
//
|
||||
// When this field is unspecified, the number of times to attempt to retry
|
||||
// a backend request is implementation-specific.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
Attempts *int `json:"attempts,omitempty"`
|
||||
|
||||
// Backoff specifies the minimum duration a Gateway should wait between
|
||||
// retry attempts and is represented in Gateway API Duration formatting.
|
||||
//
|
||||
// For example, setting the `rules[].retry.backoff` field to the value
|
||||
// `100ms` will cause a backend request to first be retried approximately
|
||||
// 100 milliseconds after timing out or receiving a response code configured
|
||||
// to be retryable.
|
||||
//
|
||||
// An implementation MAY use an exponential or alternative backoff strategy
|
||||
// for subsequent retry attempts, MAY cap the maximum backoff duration to
|
||||
// some amount greater than the specified minimum, and MAY add arbitrary
|
||||
// jitter to stagger requests, as long as unsuccessful backend requests are
|
||||
// not retried before the configured minimum duration.
|
||||
//
|
||||
// If a Request timeout (`rules[].timeouts.request`) is configured on the
|
||||
// route, the entire duration of the initial request and any retry attempts
|
||||
// MUST not exceed the Request timeout duration. If any retry attempts are
|
||||
// still in progress when the Request timeout duration has been reached,
|
||||
// these SHOULD be canceled if possible and the Gateway MUST immediately
|
||||
// return a timeout error.
|
||||
//
|
||||
// If a BackendRequest timeout (`rules[].timeouts.backendRequest`) is
|
||||
// configured on the route, any retry attempts which reach the configured
|
||||
// BackendRequest timeout duration without a response SHOULD be canceled if
|
||||
// possible and the Gateway should wait for at least the specified backoff
|
||||
// duration before attempting to retry the backend request again.
|
||||
//
|
||||
// If a BackendRequest timeout is _not_ configured on the route, retry
|
||||
// attempts MAY time out after an implementation default duration, or MAY
|
||||
// remain pending until a configured Request timeout or implementation
|
||||
// default duration for total request time is reached.
|
||||
//
|
||||
// When this field is unspecified, the time to wait between retry attempts
|
||||
// is implementation-specific.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
Backoff *Duration `json:"backoff,omitempty"`
|
||||
}
|
||||
|
||||
// HTTPRouteRetryStatusCode defines an HTTP response status code for
|
||||
// which a backend request should be retried.
|
||||
//
|
||||
// Implementations MUST support the following status codes as retryable:
|
||||
//
|
||||
// * 500
|
||||
// * 502
|
||||
// * 503
|
||||
// * 504
|
||||
//
|
||||
// Implementations MAY support specifying additional discrete values in the
|
||||
// 500-599 range.
|
||||
//
|
||||
// Implementations MAY support specifying discrete values in the 400-499 range,
|
||||
// which are often inadvisable to retry.
|
||||
//
|
||||
// +kubebuilder:validation:Minimum:=400
|
||||
// +kubebuilder:validation:Maximum:=599
|
||||
// <gateway:experimental>
|
||||
type HTTPRouteRetryStatusCode int
|
||||
|
||||
// PathMatchType specifies the semantics of how HTTP paths should be compared.
|
||||
// Valid PathMatchType values, along with their support levels, are:
|
||||
//
|
||||
@@ -346,7 +497,7 @@ const (
|
||||
PathMatchExact PathMatchType = "Exact"
|
||||
|
||||
// Matches based on a URL path prefix split by `/`. Matching is
|
||||
// case sensitive and done on a path element by element basis. A
|
||||
// case-sensitive and done on a path element by element basis. A
|
||||
// path element refers to the list of labels in the path split by
|
||||
// the `/` separator. When specified, a trailing `/` is ignored.
|
||||
//
|
||||
@@ -455,7 +606,7 @@ type HTTPHeaderMatch struct {
|
||||
Type *HeaderMatchType `json:"type,omitempty"`
|
||||
|
||||
// Name is the name of the HTTP Header to be matched. Name matching MUST be
|
||||
// case insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).
|
||||
// case-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).
|
||||
//
|
||||
// If multiple entries specify equivalent header names, only the first
|
||||
// entry with an equivalent name MUST be considered for a match. Subsequent
|
||||
@@ -468,12 +619,14 @@ type HTTPHeaderMatch struct {
|
||||
// Generally, proxies should follow the guidance from the RFC:
|
||||
// https://www.rfc-editor.org/rfc/rfc7230.html#section-3.2.2 regarding
|
||||
// processing a repeated header, with special handling for "Set-Cookie".
|
||||
// +required
|
||||
Name HTTPHeaderName `json:"name"`
|
||||
|
||||
// Value is the value of HTTP Header to be matched.
|
||||
//
|
||||
// +kubebuilder:validation:MinLength=1
|
||||
// +kubebuilder:validation:MaxLength=4096
|
||||
// +required
|
||||
Value string `json:"value"`
|
||||
}
|
||||
|
||||
@@ -535,12 +688,14 @@ type HTTPQueryParamMatch struct {
|
||||
//
|
||||
// Users SHOULD NOT route traffic based on repeated query params to guard
|
||||
// themselves against potential differences in the implementations.
|
||||
// +required
|
||||
Name HTTPHeaderName `json:"name"`
|
||||
|
||||
// Value is the value of HTTP query param to be matched.
|
||||
//
|
||||
// +kubebuilder:validation:MinLength=1
|
||||
// +kubebuilder:validation:MaxLength=1024
|
||||
// +required
|
||||
Value string `json:"value"`
|
||||
}
|
||||
|
||||
@@ -560,6 +715,9 @@ type HTTPQueryParamMatch struct {
|
||||
// +kubebuilder:validation:Enum=GET;HEAD;POST;PUT;DELETE;CONNECT;OPTIONS;TRACE;PATCH
|
||||
type HTTPMethod string
|
||||
|
||||
// +kubebuilder:validation:Enum=GET;HEAD;POST;PUT;DELETE;CONNECT;OPTIONS;TRACE;PATCH;*
|
||||
type HTTPMethodWithWildcard string
|
||||
|
||||
const (
|
||||
HTTPMethodGet HTTPMethod = "GET"
|
||||
HTTPMethodHead HTTPMethod = "HEAD"
|
||||
@@ -646,6 +804,10 @@ type HTTPRouteMatch struct {
|
||||
// +kubebuilder:validation:XValidation:message="filter.requestRedirect must be specified for RequestRedirect filter.type",rule="!(!has(self.requestRedirect) && self.type == 'RequestRedirect')"
|
||||
// +kubebuilder:validation:XValidation:message="filter.urlRewrite must be nil if the filter.type is not URLRewrite",rule="!(has(self.urlRewrite) && self.type != 'URLRewrite')"
|
||||
// +kubebuilder:validation:XValidation:message="filter.urlRewrite must be specified for URLRewrite filter.type",rule="!(!has(self.urlRewrite) && self.type == 'URLRewrite')"
|
||||
// <gateway:experimental:validation:XValidation:message="filter.cors must be nil if the filter.type is not CORS",rule="!(has(self.cors) && self.type != 'CORS')">
|
||||
// <gateway:experimental:validation:XValidation:message="filter.cors must be specified for CORS filter.type",rule="!(!has(self.cors) && self.type == 'CORS')">
|
||||
// <gateway:experimental:validation:XValidation:message="filter.externalAuth must be nil if the filter.type is not ExternalAuth",rule="!(has(self.externalAuth) && self.type != 'ExternalAuth')">
|
||||
// <gateway:experimental:validation:XValidation:message="filter.externalAuth must be specified for ExternalAuth filter.type",rule="!(!has(self.externalAuth) && self.type == 'ExternalAuth')">
|
||||
// +kubebuilder:validation:XValidation:message="filter.extensionRef must be nil if the filter.type is not ExtensionRef",rule="!(has(self.extensionRef) && self.type != 'ExtensionRef')"
|
||||
// +kubebuilder:validation:XValidation:message="filter.extensionRef must be specified for ExtensionRef filter.type",rule="!(!has(self.extensionRef) && self.type == 'ExtensionRef')"
|
||||
type HTTPRouteFilter struct {
|
||||
@@ -684,6 +846,8 @@ type HTTPRouteFilter struct {
|
||||
//
|
||||
// +unionDiscriminator
|
||||
// +kubebuilder:validation:Enum=RequestHeaderModifier;ResponseHeaderModifier;RequestMirror;RequestRedirect;URLRewrite;ExtensionRef
|
||||
// <gateway:experimental:validation:Enum=RequestHeaderModifier;ResponseHeaderModifier;RequestMirror;RequestRedirect;URLRewrite;ExtensionRef;CORS;ExternalAuth>
|
||||
// +required
|
||||
Type HTTPRouteFilterType `json:"type"`
|
||||
|
||||
// RequestHeaderModifier defines a schema for a filter that modifies request
|
||||
@@ -713,6 +877,8 @@ type HTTPRouteFilter struct {
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
//
|
||||
// +kubebuilder:validation:XValidation:message="Only one of percent or fraction may be specified in HTTPRequestMirrorFilter",rule="!(has(self.percent) && has(self.fraction))"
|
||||
RequestMirror *HTTPRequestMirrorFilter `json:"requestMirror,omitempty"`
|
||||
|
||||
// RequestRedirect defines a schema for a filter that responds to the
|
||||
@@ -730,6 +896,28 @@ type HTTPRouteFilter struct {
|
||||
// +optional
|
||||
URLRewrite *HTTPURLRewriteFilter `json:"urlRewrite,omitempty"`
|
||||
|
||||
// CORS defines a schema for a filter that responds to the
|
||||
// cross-origin request based on HTTP response header.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
// <gateway:experimental>
|
||||
CORS *HTTPCORSFilter `json:"cors,omitempty"`
|
||||
|
||||
// ExternalAuth configures settings related to sending request details
|
||||
// to an external auth service. The external service MUST authenticate
|
||||
// the request, and MAY authorize the request as well.
|
||||
//
|
||||
// If there is any problem communicating with the external service,
|
||||
// this filter MUST fail closed.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
// <gateway:experimental>
|
||||
ExternalAuth *HTTPExternalAuthFilter `json:"externalAuth,omitempty"`
|
||||
|
||||
// ExtensionRef is an optional, implementation-specific extension to the
|
||||
// "filter" behavior. For example, resource "myroutefilter" in group
|
||||
// "networking.example.net"). ExtensionRef MUST NOT be used for core and
|
||||
@@ -792,6 +980,27 @@ const (
|
||||
// Support in HTTPBackendRef: Extended
|
||||
HTTPRouteFilterRequestMirror HTTPRouteFilterType = "RequestMirror"
|
||||
|
||||
// HTTPRouteFilterCORS can be used to add CORS headers to an
|
||||
// HTTP response before it is sent to the client.
|
||||
//
|
||||
// Support in HTTPRouteRule: Extended
|
||||
//
|
||||
// Support in HTTPBackendRef: Extended
|
||||
// <gateway:experimental>
|
||||
HTTPRouteFilterCORS HTTPRouteFilterType = "CORS"
|
||||
|
||||
// HTTPRouteFilterExternalAuth can be used to configure a Gateway implementation
|
||||
// to call out to an external Auth server, which MUST perform Authentication
|
||||
// and MAY perform Authorization on the matched request before the request
|
||||
// is forwarded to the backend.
|
||||
//
|
||||
// Support in HTTPRouteRule: Extended
|
||||
//
|
||||
// Feature Name: HTTPRouteExternalAuth
|
||||
//
|
||||
// <gateway:experimental>
|
||||
HTTPRouteFilterExternalAuth HTTPRouteFilterType = "ExternalAuth"
|
||||
|
||||
// HTTPRouteFilterExtensionRef should be used for configuring custom
|
||||
// HTTP filters.
|
||||
//
|
||||
@@ -804,28 +1013,30 @@ const (
|
||||
// HTTPHeader represents an HTTP Header name and value as defined by RFC 7230.
|
||||
type HTTPHeader struct {
|
||||
// Name is the name of the HTTP Header to be matched. Name matching MUST be
|
||||
// case insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).
|
||||
// case-insensitive. (See https://tools.ietf.org/html/rfc7230#section-3.2).
|
||||
//
|
||||
// If multiple entries specify equivalent header names, the first entry with
|
||||
// an equivalent name MUST be considered for a match. Subsequent entries
|
||||
// with an equivalent header name MUST be ignored. Due to the
|
||||
// case-insensitivity of header names, "foo" and "Foo" are considered
|
||||
// equivalent.
|
||||
// +required
|
||||
Name HTTPHeaderName `json:"name"`
|
||||
|
||||
// Value is the value of HTTP Header to be matched.
|
||||
//
|
||||
// +kubebuilder:validation:MinLength=1
|
||||
// +kubebuilder:validation:MaxLength=4096
|
||||
// +required
|
||||
Value string `json:"value"`
|
||||
}
|
||||
|
||||
// HTTPHeaderFilter defines a filter that modifies the headers of an HTTP
|
||||
// request or response. Only one action for a given header name is permitted.
|
||||
// Filters specifying multiple actions of the same or different type for any one
|
||||
// header name are invalid and will be rejected by the webhook if installed.
|
||||
// Configuration to set or add multiple values for a header must use RFC 7230
|
||||
// header value formatting, separating each value with a comma.
|
||||
// request or response. Only one action for a given header name is
|
||||
// permitted. Filters specifying multiple actions of the same or different
|
||||
// type for any one header name are invalid. Configuration to set or add
|
||||
// multiple values for a header must use RFC 7230 header value formatting,
|
||||
// separating each value with a comma.
|
||||
type HTTPHeaderFilter struct {
|
||||
// Set overwrites the request with the given header (name, value)
|
||||
// before the action.
|
||||
@@ -935,6 +1146,7 @@ type HTTPPathModifier struct {
|
||||
// Reason of `UnsupportedValue`.
|
||||
//
|
||||
// +kubebuilder:validation:Enum=ReplaceFullPath;ReplacePrefixMatch
|
||||
// +required
|
||||
Type HTTPPathModifierType `json:"type"`
|
||||
|
||||
// ReplaceFullPath specifies the value with which to replace the full path
|
||||
@@ -1042,6 +1254,9 @@ type HTTPRequestRedirectFilter struct {
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
//
|
||||
// +kubebuilder:validation:Minimum=1
|
||||
// +kubebuilder:validation:Maximum=65535
|
||||
Port *PortNumber `json:"port,omitempty"`
|
||||
|
||||
// StatusCode is the HTTP status code to be used in response.
|
||||
@@ -1108,7 +1323,438 @@ type HTTPRequestMirrorFilter struct {
|
||||
// Support: Extended for Kubernetes Service
|
||||
//
|
||||
// Support: Implementation-specific for any other resource
|
||||
// +required
|
||||
BackendRef BackendObjectReference `json:"backendRef"`
|
||||
|
||||
// Percent represents the percentage of requests that should be
|
||||
// mirrored to BackendRef. Its minimum value is 0 (indicating 0% of
|
||||
// requests) and its maximum value is 100 (indicating 100% of requests).
|
||||
//
|
||||
// Only one of Fraction or Percent may be specified. If neither field
|
||||
// is specified, 100% of requests will be mirrored.
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:validation:Minimum=0
|
||||
// +kubebuilder:validation:Maximum=100
|
||||
Percent *int32 `json:"percent,omitempty"`
|
||||
|
||||
// Fraction represents the fraction of requests that should be
|
||||
// mirrored to BackendRef.
|
||||
//
|
||||
// Only one of Fraction or Percent may be specified. If neither field
|
||||
// is specified, 100% of requests will be mirrored.
|
||||
//
|
||||
// +optional
|
||||
Fraction *Fraction `json:"fraction,omitempty"`
|
||||
}
|
||||
|
||||
// HTTPCORSFilter defines a filter that that configures Cross-Origin Request
|
||||
// Sharing (CORS).
|
||||
type HTTPCORSFilter struct {
|
||||
// AllowOrigins indicates whether the response can be shared with requested
|
||||
// resource from the given `Origin`.
|
||||
//
|
||||
// The `Origin` consists of a scheme and a host, with an optional port, and
|
||||
// takes the form `<scheme>://<host>(:<port>)`.
|
||||
//
|
||||
// Valid values for scheme are: `http` and `https`.
|
||||
//
|
||||
// Valid values for port are any integer between 1 and 65535 (the list of
|
||||
// available TCP/UDP ports). Note that, if not included, port `80` is
|
||||
// assumed for `http` scheme origins, and port `443` is assumed for `https`
|
||||
// origins. This may affect origin matching.
|
||||
//
|
||||
// The host part of the origin may contain the wildcard character `*`. These
|
||||
// wildcard characters behave as follows:
|
||||
//
|
||||
// * `*` is a greedy match to the _left_, including any number of
|
||||
// DNS labels to the left of its position. This also means that
|
||||
// `*` will include any number of period `.` characters to the
|
||||
// left of its position.
|
||||
// * A wildcard by itself matches all hosts.
|
||||
//
|
||||
// An origin value that includes _only_ the `*` character indicates requests
|
||||
// from all `Origin`s are allowed.
|
||||
//
|
||||
// When the `AllowOrigins` field is configured with multiple origins, it
|
||||
// means the server supports clients from multiple origins. If the request
|
||||
// `Origin` matches the configured allowed origins, the gateway must return
|
||||
// the given `Origin` and sets value of the header
|
||||
// `Access-Control-Allow-Origin` same as the `Origin` header provided by the
|
||||
// client.
|
||||
//
|
||||
// The status code of a successful response to a "preflight" request is
|
||||
// always an OK status (i.e., 204 or 200).
|
||||
//
|
||||
// If the request `Origin` does not match the configured allowed origins,
|
||||
// the gateway returns 204/200 response but doesn't set the relevant
|
||||
// cross-origin response headers. Alternatively, the gateway responds with
|
||||
// 403 status to the "preflight" request is denied, coupled with omitting
|
||||
// the CORS headers. The cross-origin request fails on the client side.
|
||||
// Therefore, the client doesn't attempt the actual cross-origin request.
|
||||
//
|
||||
// The `Access-Control-Allow-Origin` response header can only use `*`
|
||||
// wildcard as value when the `AllowCredentials` field is false or omitted.
|
||||
//
|
||||
// When the `AllowCredentials` field is true and `AllowOrigins` field
|
||||
// specified with the `*` wildcard, the gateway must return a single origin
|
||||
// in the value of the `Access-Control-Allow-Origin` response header,
|
||||
// instead of specifying the `*` wildcard. The value of the header
|
||||
// `Access-Control-Allow-Origin` is same as the `Origin` header provided by
|
||||
// the client.
|
||||
//
|
||||
// Support: Extended
|
||||
// +listType=set
|
||||
// +kubebuilder:validation:MaxItems=64
|
||||
// +kubebuilder:validation:XValidation:message="AllowOrigins cannot contain '*' alongside other origins",rule="!('*' in self && self.size() > 1)"
|
||||
// +optional
|
||||
AllowOrigins []CORSOrigin `json:"allowOrigins,omitempty"`
|
||||
|
||||
// AllowCredentials indicates whether the actual cross-origin request allows
|
||||
// to include credentials.
|
||||
//
|
||||
// When set to true, the gateway will include the `Access-Control-Allow-Credentials`
|
||||
// response header with value true (case-sensitive).
|
||||
//
|
||||
// When set to false or omitted the gateway will omit the header
|
||||
// `Access-Control-Allow-Credentials` entirely (this is the standard CORS
|
||||
// behavior).
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
AllowCredentials *bool `json:"allowCredentials,omitempty"`
|
||||
|
||||
// AllowMethods indicates which HTTP methods are supported for accessing the
|
||||
// requested resource.
|
||||
//
|
||||
// Valid values are any method defined by RFC9110, along with the special
|
||||
// value `*`, which represents all HTTP methods are allowed.
|
||||
//
|
||||
// Method names are case sensitive, so these values are also case-sensitive.
|
||||
// (See https://www.rfc-editor.org/rfc/rfc2616#section-5.1.1)
|
||||
//
|
||||
// Multiple method names in the value of the `Access-Control-Allow-Methods`
|
||||
// response header are separated by a comma (",").
|
||||
//
|
||||
// A CORS-safelisted method is a method that is `GET`, `HEAD`, or `POST`.
|
||||
// (See https://fetch.spec.whatwg.org/#cors-safelisted-method) The
|
||||
// CORS-safelisted methods are always allowed, regardless of whether they
|
||||
// are specified in the `AllowMethods` field.
|
||||
//
|
||||
// When the `AllowMethods` field is configured with one or more methods, the
|
||||
// gateway must return the `Access-Control-Allow-Methods` response header
|
||||
// which value is present in the `AllowMethods` field.
|
||||
//
|
||||
// If the HTTP method of the `Access-Control-Request-Method` request header
|
||||
// is not included in the list of methods specified by the response header
|
||||
// `Access-Control-Allow-Methods`, it will present an error on the client
|
||||
// side.
|
||||
//
|
||||
// The `Access-Control-Allow-Methods` response header can only use `*`
|
||||
// wildcard as value when the `AllowCredentials` field is false or omitted.
|
||||
//
|
||||
// When the `AllowCredentials` field is true and `AllowMethods` field
|
||||
// specified with the `*` wildcard, the gateway must specify one HTTP method
|
||||
// in the value of the Access-Control-Allow-Methods response header. The
|
||||
// value of the header `Access-Control-Allow-Methods` is same as the
|
||||
// `Access-Control-Request-Method` header provided by the client. If the
|
||||
// header `Access-Control-Request-Method` is not included in the request,
|
||||
// the gateway will omit the `Access-Control-Allow-Methods` response header,
|
||||
// instead of specifying the `*` wildcard. A Gateway implementation may
|
||||
// choose to add implementation-specific default methods.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +listType=set
|
||||
// +kubebuilder:validation:MaxItems=9
|
||||
// +kubebuilder:validation:XValidation:message="AllowMethods cannot contain '*' alongside other methods",rule="!('*' in self && self.size() > 1)"
|
||||
// +optional
|
||||
AllowMethods []HTTPMethodWithWildcard `json:"allowMethods,omitempty"`
|
||||
|
||||
// AllowHeaders indicates which HTTP request headers are supported for
|
||||
// accessing the requested resource.
|
||||
//
|
||||
// Header names are not case sensitive.
|
||||
//
|
||||
// Multiple header names in the value of the `Access-Control-Allow-Headers`
|
||||
// response header are separated by a comma (",").
|
||||
//
|
||||
// When the `AllowHeaders` field is configured with one or more headers, the
|
||||
// gateway must return the `Access-Control-Allow-Headers` response header
|
||||
// which value is present in the `AllowHeaders` field.
|
||||
//
|
||||
// If any header name in the `Access-Control-Request-Headers` request header
|
||||
// is not included in the list of header names specified by the response
|
||||
// header `Access-Control-Allow-Headers`, it will present an error on the
|
||||
// client side.
|
||||
//
|
||||
// If any header name in the `Access-Control-Allow-Headers` response header
|
||||
// does not recognize by the client, it will also occur an error on the
|
||||
// client side.
|
||||
//
|
||||
// A wildcard indicates that the requests with all HTTP headers are allowed.
|
||||
// The `Access-Control-Allow-Headers` response header can only use `*`
|
||||
// wildcard as value when the `AllowCredentials` field is false or omitted.
|
||||
//
|
||||
// When the `AllowCredentials` field is true and `AllowHeaders` field
|
||||
// specified with the `*` wildcard, the gateway must specify one or more
|
||||
// HTTP headers in the value of the `Access-Control-Allow-Headers` response
|
||||
// header. The value of the header `Access-Control-Allow-Headers` is same as
|
||||
// the `Access-Control-Request-Headers` header provided by the client. If
|
||||
// the header `Access-Control-Request-Headers` is not included in the
|
||||
// request, the gateway will omit the `Access-Control-Allow-Headers`
|
||||
// response header, instead of specifying the `*` wildcard. A Gateway
|
||||
// implementation may choose to add implementation-specific default headers.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +listType=set
|
||||
// +kubebuilder:validation:MaxItems=64
|
||||
// +optional
|
||||
AllowHeaders []HTTPHeaderName `json:"allowHeaders,omitempty"`
|
||||
|
||||
// ExposeHeaders indicates which HTTP response headers can be exposed
|
||||
// to client-side scripts in response to a cross-origin request.
|
||||
//
|
||||
// A CORS-safelisted response header is an HTTP header in a CORS response
|
||||
// that it is considered safe to expose to the client scripts.
|
||||
// The CORS-safelisted response headers include the following headers:
|
||||
// `Cache-Control`
|
||||
// `Content-Language`
|
||||
// `Content-Length`
|
||||
// `Content-Type`
|
||||
// `Expires`
|
||||
// `Last-Modified`
|
||||
// `Pragma`
|
||||
// (See https://fetch.spec.whatwg.org/#cors-safelisted-response-header-name)
|
||||
// The CORS-safelisted response headers are exposed to client by default.
|
||||
//
|
||||
// When an HTTP header name is specified using the `ExposeHeaders` field,
|
||||
// this additional header will be exposed as part of the response to the
|
||||
// client.
|
||||
//
|
||||
// Header names are not case sensitive.
|
||||
//
|
||||
// Multiple header names in the value of the `Access-Control-Expose-Headers`
|
||||
// response header are separated by a comma (",").
|
||||
//
|
||||
// A wildcard indicates that the responses with all HTTP headers are exposed
|
||||
// to clients. The `Access-Control-Expose-Headers` response header can only
|
||||
// use `*` wildcard as value when the `AllowCredentials` field is false or omitted.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
// +listType=set
|
||||
// +kubebuilder:validation:MaxItems=64
|
||||
ExposeHeaders []HTTPHeaderName `json:"exposeHeaders,omitempty"`
|
||||
|
||||
// MaxAge indicates the duration (in seconds) for the client to cache the
|
||||
// results of a "preflight" request.
|
||||
//
|
||||
// The information provided by the `Access-Control-Allow-Methods` and
|
||||
// `Access-Control-Allow-Headers` response headers can be cached by the
|
||||
// client until the time specified by `Access-Control-Max-Age` elapses.
|
||||
//
|
||||
// The default value of `Access-Control-Max-Age` response header is 5
|
||||
// (seconds).
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:default=5
|
||||
// +kubebuilder:validation:Minimum=1
|
||||
MaxAge int32 `json:"maxAge,omitempty"`
|
||||
}
|
||||
|
||||
// HTTPRouteExternalAuthProtcol specifies what protocol should be used
|
||||
// for communicating with an external authorization server.
|
||||
//
|
||||
// Valid values are supplied as constants below.
|
||||
type HTTPRouteExternalAuthProtocol string
|
||||
|
||||
const (
|
||||
HTTPRouteExternalAuthGRPCProtocol HTTPRouteExternalAuthProtocol = "GRPC"
|
||||
HTTPRouteExternalAuthHTTPProtocol HTTPRouteExternalAuthProtocol = "HTTP"
|
||||
)
|
||||
|
||||
// HTTPExternalAuthFilter defines a filter that modifies requests by sending
|
||||
// request details to an external authorization server.
|
||||
//
|
||||
// Support: Extended
|
||||
// Feature Name: HTTPRouteExternalAuth
|
||||
// +kubebuilder:validation:XValidation:message="grpc must be specified when protocol is set to 'GRPC'",rule="self.protocol == 'GRPC' ? has(self.grpc) : true"
|
||||
// +kubebuilder:validation:XValidation:message="protocol must be 'GRPC' when grpc is set",rule="has(self.grpc) ? self.protocol == 'GRPC' : true"
|
||||
// +kubebuilder:validation:XValidation:message="http must be specified when protocol is set to 'HTTP'",rule="self.protocol == 'HTTP' ? has(self.http) : true"
|
||||
// +kubebuilder:validation:XValidation:message="protocol must be 'HTTP' when http is set",rule="has(self.http) ? self.protocol == 'HTTP' : true"
|
||||
type HTTPExternalAuthFilter struct {
|
||||
// ExternalAuthProtocol describes which protocol to use when communicating with an
|
||||
// ext_authz authorization server.
|
||||
//
|
||||
// When this is set to GRPC, each backend must use the Envoy ext_authz protocol
|
||||
// on the port specified in `backendRefs`. Requests and responses are defined
|
||||
// in the protobufs explained at:
|
||||
// https://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto
|
||||
//
|
||||
// When this is set to HTTP, each backend must respond with a `200` status
|
||||
// code in on a successful authorization. Any other code is considered
|
||||
// an authorization failure.
|
||||
//
|
||||
// Feature Names:
|
||||
// GRPC Support - HTTPRouteExternalAuthGRPC
|
||||
// HTTP Support - HTTPRouteExternalAuthHTTP
|
||||
//
|
||||
// +unionDiscriminator
|
||||
// +required
|
||||
// +kubebuilder:validation:Enum=HTTP;GRPC
|
||||
ExternalAuthProtocol HTTPRouteExternalAuthProtocol `json:"protocol,omitempty"`
|
||||
|
||||
// BackendRef is a reference to a backend to send authorization
|
||||
// requests to.
|
||||
//
|
||||
// The backend must speak the selected protocol (GRPC or HTTP) on the
|
||||
// referenced port.
|
||||
//
|
||||
// If the backend service requires TLS, use BackendTLSPolicy to tell the
|
||||
// implementation to supply the TLS details to be used to connect to that
|
||||
// backend.
|
||||
//
|
||||
// +required
|
||||
BackendRef BackendObjectReference `json:"backendRef,omitempty"`
|
||||
|
||||
// GRPCAuthConfig contains configuration for communication with ext_authz
|
||||
// protocol-speaking backends.
|
||||
//
|
||||
// If unset, implementations must assume the default behavior for each
|
||||
// included field is intended.
|
||||
//
|
||||
// +optional
|
||||
GRPCAuthConfig *GRPCAuthConfig `json:"grpc,omitempty"`
|
||||
|
||||
// HTTPAuthConfig contains configuration for communication with HTTP-speaking
|
||||
// backends.
|
||||
//
|
||||
// If unset, implementations must assume the default behavior for each
|
||||
// included field is intended.
|
||||
//
|
||||
// +optional
|
||||
HTTPAuthConfig *HTTPAuthConfig `json:"http,omitempty"`
|
||||
|
||||
// ForwardBody controls if requests to the authorization server should include
|
||||
// the body of the client request; and if so, how big that body is allowed
|
||||
// to be.
|
||||
//
|
||||
// It is expected that implementations will buffer the request body up to
|
||||
// `forwardBody.maxSize` bytes. Bodies over that size must be rejected with a
|
||||
// 4xx series error (413 or 403 are common examples), and fail processing
|
||||
// of the filter.
|
||||
//
|
||||
// If unset, or `forwardBody.maxSize` is set to `0`, then the body will not
|
||||
// be forwarded.
|
||||
//
|
||||
// Feature Name: HTTPRouteExternalAuthForwardBody
|
||||
//
|
||||
//
|
||||
// +optional
|
||||
ForwardBody *ForwardBodyConfig `json:"forwardBody,omitempty"`
|
||||
}
|
||||
|
||||
// GRPCAuthConfig contains configuration for communication with Auth server
|
||||
// backends that speak Envoy's ext_authz gRPC protocol.
|
||||
//
|
||||
// Requests and responses are defined in the protobufs explained at:
|
||||
// https://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto
|
||||
type GRPCAuthConfig struct {
|
||||
// AllowedRequestHeaders specifies what headers from the client request
|
||||
// will be sent to the authorization server.
|
||||
//
|
||||
// If this list is empty, then all headers must be sent.
|
||||
//
|
||||
// If the list has entries, only those entries must be sent.
|
||||
//
|
||||
// +optional
|
||||
// +listType=set
|
||||
// +kubebuilder:validation:MaxLength=64
|
||||
AllowedRequestHeaders []string `json:"allowedHeaders,omitempty"`
|
||||
}
|
||||
|
||||
// HTTPAuthConfig contains configuration for communication with HTTP-speaking
|
||||
// backends.
|
||||
type HTTPAuthConfig struct {
|
||||
// Path sets the prefix that paths from the client request will have added
|
||||
// when forwarded to the authorization server.
|
||||
//
|
||||
// When empty or unspecified, no prefix is added.
|
||||
//
|
||||
// Valid values are the same as the "value" regex for path values in the `match`
|
||||
// stanza, and the validation regex will screen out invalid paths in the same way.
|
||||
// Even with the validation, implementations MUST sanitize this input before using it
|
||||
// directly.
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:validation:MaxLength=1024
|
||||
// +kubebuilder:validation:Pattern="^(?:[-A-Za-z0-9/._~!$&'()*+,;=:@]|[%][0-9a-fA-F]{2})+$"
|
||||
Path string `json:"path,omitempty"`
|
||||
|
||||
// AllowedRequestHeaders specifies what additional headers from the client request
|
||||
// will be sent to the authorization server.
|
||||
//
|
||||
// The following headers must always be sent to the authorization server,
|
||||
// regardless of this setting:
|
||||
//
|
||||
// * `Host`
|
||||
// * `Method`
|
||||
// * `Path`
|
||||
// * `Content-Length`
|
||||
// * `Authorization`
|
||||
//
|
||||
// If this list is empty, then only those headers must be sent.
|
||||
//
|
||||
// Note that `Content-Length` has a special behavior, in that the length
|
||||
// sent must be correct for the actual request to the external authorization
|
||||
// server - that is, it must reflect the actual number of bytes sent in the
|
||||
// body of the request to the authorization server.
|
||||
//
|
||||
// So if the `forwardBody` stanza is unset, or `forwardBody.maxSize` is set
|
||||
// to `0`, then `Content-Length` must be `0`. If `forwardBody.maxSize` is set
|
||||
// to anything other than `0`, then the `Content-Length` of the authorization
|
||||
// request must be set to the actual number of bytes forwarded.
|
||||
//
|
||||
// +optional
|
||||
// +listType=set
|
||||
// +kubebuilder:validation:MaxLength=64
|
||||
AllowedRequestHeaders []string `json:"allowedHeaders,omitempty"`
|
||||
|
||||
// AllowedResponseHeaders specifies what headers from the authorization response
|
||||
// will be copied into the request to the backend.
|
||||
//
|
||||
// If this list is empty, then all headers from the authorization server
|
||||
// except Authority or Host must be copied.
|
||||
//
|
||||
// +optional
|
||||
// +listType=set
|
||||
// +kubebuilder:validation:MaxLength=64
|
||||
AllowedResponseHeaders []string `json:"allowedResponseHeaders,omitempty"`
|
||||
}
|
||||
|
||||
// ForwardBody configures if requests to the authorization server should include
|
||||
// the body of the client request; and if so, how big that body is allowed
|
||||
// to be.
|
||||
//
|
||||
// If empty or unset, do not forward the body.
|
||||
type ForwardBodyConfig struct {
|
||||
// MaxSize specifies how large in bytes the largest body that will be buffered
|
||||
// and sent to the authorization server. If the body size is larger than
|
||||
// `maxSize`, then the body sent to the authorization server must be
|
||||
// truncated to `maxSize` bytes.
|
||||
//
|
||||
// Experimental note: This behavior needs to be checked against
|
||||
// various dataplanes; it may need to be changed.
|
||||
// See https://github.com/kubernetes-sigs/gateway-api/pull/4001#discussion_r2291405746
|
||||
// for more.
|
||||
//
|
||||
// If 0, the body will not be sent to the authorization server.
|
||||
// +optional
|
||||
MaxSize uint16 `json:"maxSize,omitempty"`
|
||||
}
|
||||
|
||||
// HTTPBackendRef defines how a HTTPRoute forwards a HTTP request.
|
||||
@@ -1187,9 +1833,9 @@ type HTTPBackendRef struct {
|
||||
// Filters field in HTTPRouteRule.)
|
||||
//
|
||||
// +optional
|
||||
// +listType=atomic
|
||||
// +kubebuilder:validation:MaxItems=16
|
||||
// +kubebuilder:validation:XValidation:message="May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",rule="!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
|
||||
// +kubebuilder:validation:XValidation:message="May specify either httpRouteFilterRequestRedirect or httpRouteFilterRequestRewrite, but not both",rule="!(self.exists(f, f.type == 'RequestRedirect') && self.exists(f, f.type == 'URLRewrite'))"
|
||||
// +kubebuilder:validation:XValidation:message="RequestHeaderModifier filter cannot be repeated",rule="self.filter(f, f.type == 'RequestHeaderModifier').size() <= 1"
|
||||
// +kubebuilder:validation:XValidation:message="ResponseHeaderModifier filter cannot be repeated",rule="self.filter(f, f.type == 'ResponseHeaderModifier').size() <= 1"
|
||||
// +kubebuilder:validation:XValidation:message="RequestRedirect filter cannot be repeated",rule="self.filter(f, f.type == 'RequestRedirect').size() <= 1"
|
||||
|
||||
@@ -1,9 +1,12 @@
|
||||
/*
|
||||
Copyright 2020 The Kubernetes Authors.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
@@ -24,12 +27,15 @@ package v1
|
||||
type LocalObjectReference struct {
|
||||
// Group is the group of the referent. For example, "gateway.networking.k8s.io".
|
||||
// When unspecified or empty string, core API group is inferred.
|
||||
// +required
|
||||
Group Group `json:"group"`
|
||||
|
||||
// Kind is kind of the referent. For example "HTTPRoute" or "Service".
|
||||
// +required
|
||||
Kind Kind `json:"kind"`
|
||||
|
||||
// Name is the name of the referent.
|
||||
// +required
|
||||
Name ObjectName `json:"name"`
|
||||
}
|
||||
|
||||
@@ -50,22 +56,23 @@ type SecretObjectReference struct {
|
||||
// +kubebuilder:default=""
|
||||
Group *Group `json:"group"`
|
||||
|
||||
// Kind is kind of the referent. For example "HTTPRoute" or "Service".
|
||||
// Kind is kind of the referent. For example "Secret".
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:default=Secret
|
||||
Kind *Kind `json:"kind"`
|
||||
|
||||
// Name is the name of the referent.
|
||||
// +required
|
||||
Name ObjectName `json:"name"`
|
||||
|
||||
// Namespace is the namespace of the backend. When unspecified, the local
|
||||
// Namespace is the namespace of the referenced object. When unspecified, the local
|
||||
// namespace is inferred.
|
||||
//
|
||||
// Note that when a namespace is specified, a ReferenceGrant object
|
||||
// is required in the referent namespace to allow that namespace's
|
||||
// owner to accept the reference. See the ReferenceGrant documentation
|
||||
// for details.
|
||||
// Note that when a namespace different than the local namespace is specified,
|
||||
// a ReferenceGrant object is required in the referent namespace to allow that
|
||||
// namespace's owner to accept the reference. See the ReferenceGrant
|
||||
// documentation for details.
|
||||
//
|
||||
// Support: Core
|
||||
//
|
||||
@@ -77,10 +84,10 @@ type SecretObjectReference struct {
|
||||
// specific to BackendRef. It includes a few additional fields and features
|
||||
// than a regular ObjectReference.
|
||||
//
|
||||
// Note that when a namespace is specified, a ReferenceGrant object
|
||||
// is required in the referent namespace to allow that namespace's
|
||||
// owner to accept the reference. See the ReferenceGrant documentation
|
||||
// for details.
|
||||
// Note that when a namespace different than the local namespace is specified, a
|
||||
// ReferenceGrant object is required in the referent namespace to allow that
|
||||
// namespace's owner to accept the reference. See the ReferenceGrant
|
||||
// documentation for details.
|
||||
//
|
||||
// The API object must be valid in the cluster; the Group and Kind must
|
||||
// be registered in the cluster for this reference to be valid.
|
||||
@@ -88,6 +95,8 @@ type SecretObjectReference struct {
|
||||
// References to objects with invalid Group and Kind are not valid, and must
|
||||
// be rejected by the implementation, with appropriate Conditions set
|
||||
// on the containing object.
|
||||
//
|
||||
// +kubebuilder:validation:XValidation:message="Must have port for Service reference",rule="(size(self.group) == 0 && self.kind == 'Service') ? has(self.port) : true"
|
||||
type BackendObjectReference struct {
|
||||
// Group is the group of the referent. For example, "gateway.networking.k8s.io".
|
||||
// When unspecified or empty string, core API group is inferred.
|
||||
@@ -96,23 +105,36 @@ type BackendObjectReference struct {
|
||||
// +kubebuilder:default=""
|
||||
Group *Group `json:"group,omitempty"`
|
||||
|
||||
// Kind is kind of the referent. For example "HTTPRoute" or "Service".
|
||||
// Kind is the Kubernetes resource kind of the referent. For example
|
||||
// "Service".
|
||||
//
|
||||
// Defaults to "Service" when not specified.
|
||||
//
|
||||
// ExternalName services can refer to CNAME DNS records that may live
|
||||
// outside of the cluster and as such are difficult to reason about in
|
||||
// terms of conformance. They also may not be safe to forward to (see
|
||||
// CVE-2021-25740 for more information). Implementations SHOULD NOT
|
||||
// support ExternalName Services.
|
||||
//
|
||||
// Support: Core (Services with a type other than ExternalName)
|
||||
//
|
||||
// Support: Implementation-specific (Services with type ExternalName)
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:default=Service
|
||||
Kind *Kind `json:"kind,omitempty"`
|
||||
|
||||
// Name is the name of the referent.
|
||||
// +required
|
||||
Name ObjectName `json:"name"`
|
||||
|
||||
// Namespace is the namespace of the backend. When unspecified, the local
|
||||
// namespace is inferred.
|
||||
//
|
||||
// Note that when a namespace is specified, a ReferenceGrant object
|
||||
// is required in the referent namespace to allow that namespace's
|
||||
// owner to accept the reference. See the ReferenceGrant documentation
|
||||
// for details.
|
||||
// Note that when a namespace different than the local namespace is specified,
|
||||
// a ReferenceGrant object is required in the referent namespace to allow that
|
||||
// namespace's owner to accept the reference. See the ReferenceGrant
|
||||
// documentation for details.
|
||||
//
|
||||
// Support: Core
|
||||
//
|
||||
@@ -126,5 +148,43 @@ type BackendObjectReference struct {
|
||||
// resource or this field.
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:validation:Minimum=1
|
||||
// +kubebuilder:validation:Maximum=65535
|
||||
Port *PortNumber `json:"port,omitempty"`
|
||||
}
|
||||
|
||||
// ObjectReference identifies an API object including its namespace.
|
||||
//
|
||||
// The API object must be valid in the cluster; the Group and Kind must
|
||||
// be registered in the cluster for this reference to be valid.
|
||||
//
|
||||
// References to objects with invalid Group and Kind are not valid, and must
|
||||
// be rejected by the implementation, with appropriate Conditions set
|
||||
// on the containing object.
|
||||
type ObjectReference struct {
|
||||
// Group is the group of the referent. For example, "gateway.networking.k8s.io".
|
||||
// When set to the empty string, core API group is inferred.
|
||||
// +required
|
||||
Group Group `json:"group"`
|
||||
|
||||
// Kind is kind of the referent. For example "ConfigMap" or "Service".
|
||||
// +required
|
||||
Kind Kind `json:"kind"`
|
||||
|
||||
// Name is the name of the referent.
|
||||
// +required
|
||||
Name ObjectName `json:"name"`
|
||||
|
||||
// Namespace is the namespace of the referenced object. When unspecified, the local
|
||||
// namespace is inferred.
|
||||
//
|
||||
// Note that when a namespace different than the local namespace is specified,
|
||||
// a ReferenceGrant object is required in the referent namespace to allow that
|
||||
// namespace's owner to accept the reference. See the ReferenceGrant
|
||||
// documentation for details.
|
||||
//
|
||||
// Support: Core
|
||||
//
|
||||
// +optional
|
||||
Namespace *Namespace `json:"namespace,omitempty"`
|
||||
}
|
||||
|
||||
@@ -25,7 +25,7 @@ import (
|
||||
// with "Core" support:
|
||||
//
|
||||
// * Gateway (Gateway conformance profile)
|
||||
// * Service (Mesh conformance profile, experimental, ClusterIP Services only)
|
||||
// * Service (Mesh conformance profile, ClusterIP Services only)
|
||||
//
|
||||
// This API may be extended in the future to support additional kinds of parent
|
||||
// resources.
|
||||
@@ -49,7 +49,7 @@ type ParentReference struct {
|
||||
// There are two kinds of parent resources with "Core" support:
|
||||
//
|
||||
// * Gateway (Gateway conformance profile)
|
||||
// * Service (Mesh conformance profile, experimental, ClusterIP Services only)
|
||||
// * Service (Mesh conformance profile, ClusterIP Services only)
|
||||
//
|
||||
// Support for other resources is Implementation-Specific.
|
||||
//
|
||||
@@ -86,19 +86,18 @@ type ParentReference struct {
|
||||
// Name is the name of the referent.
|
||||
//
|
||||
// Support: Core
|
||||
// +required
|
||||
Name ObjectName `json:"name"`
|
||||
|
||||
// SectionName is the name of a section within the target resource. In the
|
||||
// following resources, SectionName is interpreted as the following:
|
||||
//
|
||||
// * Gateway: Listener Name. When both Port (experimental) and SectionName
|
||||
// * Gateway: Listener name. When both Port (experimental) and SectionName
|
||||
// are specified, the name and port of the selected listener must match
|
||||
// both specified values.
|
||||
// * Service: Port Name. When both Port (experimental) and SectionName
|
||||
// * Service: Port name. When both Port (experimental) and SectionName
|
||||
// are specified, the name and port of the selected listener must match
|
||||
// both specified values. Note that attaching Routes to Services as Parents
|
||||
// is part of experimental Mesh support and is not supported for any other
|
||||
// purpose.
|
||||
// both specified values.
|
||||
//
|
||||
// Implementations MAY choose to support attaching Routes to other resources.
|
||||
// If that is the case, they MUST clearly document how SectionName is
|
||||
@@ -150,10 +149,31 @@ type ParentReference struct {
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
// <gateway:experimental>
|
||||
//
|
||||
// +kubebuilder:validation:Minimum=1
|
||||
// +kubebuilder:validation:Maximum=65535
|
||||
Port *PortNumber `json:"port,omitempty"`
|
||||
}
|
||||
|
||||
// GatewayDefaultScope defines the set of default scopes that a Gateway
|
||||
// can claim, for use in any Route type. At present the only supported
|
||||
// scopes are "All" and "None". "None" is a special scope which
|
||||
// explicitly means that the Route MUST NOT attached to any default
|
||||
// Gateway.
|
||||
//
|
||||
// +kubebuilder:validation:Enum=All;None
|
||||
type GatewayDefaultScope string
|
||||
|
||||
const (
|
||||
// GatewayDefaultScopeAll indicates that a Gateway can claim absolutely
|
||||
// any Route asking for a default Gateway.
|
||||
GatewayDefaultScopeAll GatewayDefaultScope = "All"
|
||||
|
||||
// GatewayDefaultScopeNone indicates that a Gateway MUST NOT claim
|
||||
// any Route asking for a default Gateway.
|
||||
GatewayDefaultScopeNone GatewayDefaultScope = "None"
|
||||
)
|
||||
|
||||
// CommonRouteSpec defines the common attributes that all Routes MUST include
|
||||
// within their spec.
|
||||
type CommonRouteSpec struct {
|
||||
@@ -171,9 +191,8 @@ type CommonRouteSpec struct {
|
||||
// There are two kinds of parent resources with "Core" support:
|
||||
//
|
||||
// * Gateway (Gateway conformance profile)
|
||||
// <gateway:experimental:description>
|
||||
// * Service (Mesh conformance profile, experimental, ClusterIP Services only)
|
||||
// </gateway:experimental:description>
|
||||
// * Service (Mesh conformance profile, ClusterIP Services only)
|
||||
//
|
||||
// This API may be extended in the future to support additional kinds of parent
|
||||
// resources.
|
||||
//
|
||||
@@ -222,19 +241,34 @@ type CommonRouteSpec struct {
|
||||
// </gateway:experimental:description>
|
||||
//
|
||||
// +optional
|
||||
// +listType=atomic
|
||||
// +kubebuilder:validation:MaxItems=32
|
||||
// <gateway:standard:validation:XValidation:message="sectionName must be specified when parentRefs includes 2 or more references to the same parent",rule="self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '')) : true))">
|
||||
// <gateway:standard:validation:XValidation:message="sectionName must be unique when parentRefs includes 2 or more references to the same parent",rule="self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || (has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName))))">
|
||||
// <gateway:experimental:validation:XValidation:message="sectionName or port must be specified when parentRefs includes 2 or more references to the same parent",rule="self.all(p1, self.all(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__)) ? ((!has(p1.sectionName) || p1.sectionName == '') == (!has(p2.sectionName) || p2.sectionName == '') && (!has(p1.port) || p1.port == 0) == (!has(p2.port) || p2.port == 0)): true))">
|
||||
// <gateway:experimental:validation:XValidation:message="sectionName or port must be unique when parentRefs includes 2 or more references to the same parent",rule="self.all(p1, self.exists_one(p2, p1.group == p2.group && p1.kind == p2.kind && p1.name == p2.name && (((!has(p1.__namespace__) || p1.__namespace__ == '') && (!has(p2.__namespace__) || p2.__namespace__ == '')) || (has(p1.__namespace__) && has(p2.__namespace__) && p1.__namespace__ == p2.__namespace__ )) && (((!has(p1.sectionName) || p1.sectionName == '') && (!has(p2.sectionName) || p2.sectionName == '')) || ( has(p1.sectionName) && has(p2.sectionName) && p1.sectionName == p2.sectionName)) && (((!has(p1.port) || p1.port == 0) && (!has(p2.port) || p2.port == 0)) || (has(p1.port) && has(p2.port) && p1.port == p2.port))))">
|
||||
ParentRefs []ParentReference `json:"parentRefs,omitempty"`
|
||||
|
||||
// UseDefaultGateways indicates the default Gateway scope to use for this
|
||||
// Route. If unset (the default) or set to None, the Route will not be
|
||||
// attached to any default Gateway; if set, it will be attached to any
|
||||
// default Gateway supporting the named scope, subject to the usual rules
|
||||
// about which Routes a Gateway is allowed to claim.
|
||||
//
|
||||
// Think carefully before using this functionality! The set of default
|
||||
// Gateways supporting the requested scope can change over time without
|
||||
// any notice to the Route author, and in many situations it will not be
|
||||
// appropriate to request a default Gateway for a given Route -- for
|
||||
// example, a Route with specific security requirements should almost
|
||||
// certainly not use a default Gateway.
|
||||
//
|
||||
// +optional
|
||||
// <gateway:experimental>
|
||||
UseDefaultGateways GatewayDefaultScope `json:"useDefaultGateways,omitempty"`
|
||||
}
|
||||
|
||||
// PortNumber defines a network port.
|
||||
//
|
||||
// +kubebuilder:validation:Minimum=1
|
||||
// +kubebuilder:validation:Maximum=65535
|
||||
type PortNumber int32
|
||||
type PortNumber = int32
|
||||
|
||||
// BackendRef defines how a Route should forward a request to a Kubernetes
|
||||
// resource.
|
||||
@@ -440,6 +474,7 @@ const (
|
||||
type RouteParentStatus struct {
|
||||
// ParentRef corresponds with a ParentRef in the spec that this
|
||||
// RouteParentStatus struct describes the status of.
|
||||
// +required
|
||||
ParentRef ParentReference `json:"parentRef"`
|
||||
|
||||
// ControllerName is a domain/path string that indicates the name of the
|
||||
@@ -455,6 +490,7 @@ type RouteParentStatus struct {
|
||||
// Controllers MUST populate this field when writing status. Controllers should ensure that
|
||||
// entries to status populated with their ControllerName are cleaned up when they are no
|
||||
// longer necessary.
|
||||
// +required
|
||||
ControllerName GatewayController `json:"controllerName"`
|
||||
|
||||
// Conditions describes the status of the route with respect to the Gateway.
|
||||
@@ -473,14 +509,45 @@ type RouteParentStatus struct {
|
||||
// There are a number of cases where the "Accepted" condition may not be set
|
||||
// due to lack of controller visibility, that includes when:
|
||||
//
|
||||
// * The Route refers to a non-existent parent.
|
||||
// * The Route refers to a nonexistent parent.
|
||||
// * The Route is of a type that the controller does not support.
|
||||
// * The Route is in a namespace the controller does not have access to.
|
||||
//
|
||||
// <gateway:util:excludeFromCRD>
|
||||
//
|
||||
// Notes for implementors:
|
||||
//
|
||||
// Conditions are a listType `map`, which means that they function like a
|
||||
// map with a key of the `type` field _in the k8s apiserver_.
|
||||
//
|
||||
// This means that implementations must obey some rules when updating this
|
||||
// section.
|
||||
//
|
||||
// * Implementations MUST perform a read-modify-write cycle on this field
|
||||
// before modifying it. That is, when modifying this field, implementations
|
||||
// must be confident they have fetched the most recent version of this field,
|
||||
// and ensure that changes they make are on that recent version.
|
||||
// * Implementations MUST NOT remove or reorder Conditions that they are not
|
||||
// directly responsible for. For example, if an implementation sees a Condition
|
||||
// with type `special.io/SomeField`, it MUST NOT remove, change or update that
|
||||
// Condition.
|
||||
// * Implementations MUST always _merge_ changes into Conditions of the same Type,
|
||||
// rather than creating more than one Condition of the same Type.
|
||||
// * Implementations MUST always update the `observedGeneration` field of the
|
||||
// Condition to the `metadata.generation` of the Gateway at the time of update creation.
|
||||
// * If the `observedGeneration` of a Condition is _greater than_ the value the
|
||||
// implementation knows about, then it MUST NOT perform the update on that Condition,
|
||||
// but must wait for a future reconciliation and status update. (The assumption is that
|
||||
// the implementation's copy of the object is stale and an update will be re-triggered
|
||||
// if relevant.)
|
||||
//
|
||||
// </gateway:util:excludeFromCRD>
|
||||
//
|
||||
// +listType=map
|
||||
// +listMapKey=type
|
||||
// +kubebuilder:validation:MinItems=1
|
||||
// +kubebuilder:validation:MaxItems=8
|
||||
// +required
|
||||
Conditions []metav1.Condition `json:"conditions,omitempty"`
|
||||
}
|
||||
|
||||
@@ -502,6 +569,31 @@ type RouteStatus struct {
|
||||
// A maximum of 32 Gateways will be represented in this list. An empty list
|
||||
// means the route has not been attached to any Gateway.
|
||||
//
|
||||
// <gateway:util:excludeFromCRD>
|
||||
// Notes for implementors:
|
||||
//
|
||||
// While parents is not a listType `map`, this is due to the fact that the
|
||||
// list key is not scalar, and Kubernetes is unable to represent this.
|
||||
//
|
||||
// Parent status MUST be considered to be namespaced by the combination of
|
||||
// the parentRef and controllerName fields, and implementations should keep
|
||||
// the following rules in mind when updating this status:
|
||||
//
|
||||
// * Implementations MUST update only entries that have a matching value of
|
||||
// `controllerName` for that implementation.
|
||||
// * Implementations MUST NOT update entries with non-matching `controllerName`
|
||||
// fields.
|
||||
// * Implementations MUST treat each `parentRef`` in the Route separately and
|
||||
// update its status based on the relationship with that parent.
|
||||
// * Implementations MUST perform a read-modify-write cycle on this field
|
||||
// before modifying it. That is, when modifying this field, implementations
|
||||
// must be confident they have fetched the most recent version of this field,
|
||||
// and ensure that changes they make are on that recent version.
|
||||
//
|
||||
// </gateway:util:excludeFromCRD>
|
||||
//
|
||||
// +required
|
||||
// +listType=atomic
|
||||
// +kubebuilder:validation:MaxItems=32
|
||||
Parents []RouteParentStatus `json:"parents"`
|
||||
}
|
||||
@@ -539,6 +631,30 @@ type Hostname string
|
||||
// +kubebuilder:validation:Pattern=`^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$`
|
||||
type PreciseHostname string
|
||||
|
||||
// AbsoluteURI represents a Uniform Resource Identifier (URI) as defined by RFC3986.
|
||||
|
||||
// The AbsoluteURI MUST NOT be a relative URI, and it MUST follow the URI syntax and
|
||||
// encoding rules specified in RFC3986. The AbsoluteURI MUST include both a
|
||||
// scheme (e.g., "http" or "spiffe") and a scheme-specific-part. URIs that
|
||||
// include an authority MUST include a fully qualified domain name or
|
||||
// IP address as the host.
|
||||
// <gateway:util:excludeFromCRD> The below regex is taken from the regex section in RFC 3986 with a slight modification to enforce a full URI and not relative. </gateway:util:excludeFromCRD>
|
||||
// +kubebuilder:validation:MinLength=1
|
||||
// +kubebuilder:validation:MaxLength=253
|
||||
// +kubebuilder:validation:Pattern=`^(([^:/?#]+):)(//([^/?#]*))([^?#]*)(\?([^#]*))?(#(.*))?`
|
||||
type AbsoluteURI string
|
||||
|
||||
// The CORSOrigin MUST NOT be a relative URI, and it MUST follow the URI syntax and
|
||||
// encoding rules specified in RFC3986. The CORSOrigin MUST include both a
|
||||
// scheme (e.g., "http" or "spiffe") and a scheme-specific-part, or it should be a single '*' character.
|
||||
// URIs that include an authority MUST include a fully qualified domain name or
|
||||
// IP address as the host.
|
||||
// <gateway:util:excludeFromCRD> The below regex was generated to simplify the assertion of scheme://host:<port> being port optional </gateway:util:excludeFromCRD>
|
||||
// +kubebuilder:validation:MinLength=1
|
||||
// +kubebuilder:validation:MaxLength=253
|
||||
// +kubebuilder:validation:Pattern=`(^\*$)|(^([a-zA-Z][a-zA-Z0-9+\-.]+):\/\/([^:/?#]+)(:([0-9]{1,5}))?$)`
|
||||
type CORSOrigin string
|
||||
|
||||
// Group refers to a Kubernetes Group. It must either be an empty string or a
|
||||
// RFC 1123 subdomain.
|
||||
//
|
||||
@@ -576,7 +692,7 @@ type Group string
|
||||
type Kind string
|
||||
|
||||
// ObjectName refers to the name of a Kubernetes object.
|
||||
// Object names can have a variety of forms, including RFC1123 subdomains,
|
||||
// Object names can have a variety of forms, including RFC 1123 subdomains,
|
||||
// RFC 1123 labels, or RFC 1035 labels.
|
||||
//
|
||||
// +kubebuilder:validation:MinLength=1
|
||||
@@ -606,11 +722,22 @@ type Namespace string
|
||||
|
||||
// SectionName is the name of a section in a Kubernetes resource.
|
||||
//
|
||||
// In the following resources, SectionName is interpreted as the following:
|
||||
//
|
||||
// * Gateway: Listener name
|
||||
// * HTTPRoute: HTTPRouteRule name
|
||||
// * Service: Port name
|
||||
//
|
||||
// Section names can have a variety of forms, including RFC 1123 subdomains,
|
||||
// RFC 1123 labels, or RFC 1035 labels.
|
||||
//
|
||||
// This validation is based off of the corresponding Kubernetes validation:
|
||||
// https://github.com/kubernetes/apimachinery/blob/02cfb53916346d085a6c6c7c66f882e3c6b0eca6/pkg/util/validation/validation.go#L208
|
||||
//
|
||||
// Valid values include:
|
||||
//
|
||||
// * "example"
|
||||
// * "foo-example"
|
||||
// * "example.com"
|
||||
// * "foo.example.com"
|
||||
//
|
||||
@@ -655,11 +782,11 @@ type GatewayController string
|
||||
// Invalid values include:
|
||||
//
|
||||
// * example~ - "~" is an invalid character
|
||||
// * example.com. - can not start or end with "."
|
||||
// * example.com. - cannot start or end with "."
|
||||
//
|
||||
// +kubebuilder:validation:MinLength=1
|
||||
// +kubebuilder:validation:MaxLength=253
|
||||
// +kubebuilder:validation:Pattern=`^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9]/?)*$`
|
||||
// +kubebuilder:validation:Pattern=`^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?([A-Za-z0-9][-A-Za-z0-9_.]{0,61})?[A-Za-z0-9]$`
|
||||
type AnnotationKey string
|
||||
|
||||
// AnnotationValue is the value of an annotation in Gateway API. This is used
|
||||
@@ -671,6 +798,45 @@ type AnnotationKey string
|
||||
// +kubebuilder:validation:MaxLength=4096
|
||||
type AnnotationValue string
|
||||
|
||||
// LabelKey is the key of a label in the Gateway API. This is used for validation
|
||||
// of maps such as Gateway infrastructure labels. This matches the Kubernetes
|
||||
// "qualified name" validation that is used for labels.
|
||||
//
|
||||
// Valid values include:
|
||||
//
|
||||
// * example
|
||||
// * example.com
|
||||
// * example.com/path
|
||||
// * example.com/path.html
|
||||
//
|
||||
// Invalid values include:
|
||||
//
|
||||
// * example~ - "~" is an invalid character
|
||||
// * example.com. - cannot start or end with "."
|
||||
//
|
||||
// +kubebuilder:validation:MinLength=1
|
||||
// +kubebuilder:validation:MaxLength=253
|
||||
// +kubebuilder:validation:Pattern=`^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?([A-Za-z0-9][-A-Za-z0-9_.]{0,61})?[A-Za-z0-9]$`
|
||||
type LabelKey string
|
||||
|
||||
// LabelValue is the value of a label in the Gateway API. This is used for validation
|
||||
// of maps such as Gateway infrastructure labels. This matches the Kubernetes
|
||||
// label validation rules:
|
||||
// * must be 63 characters or less (can be empty),
|
||||
// * unless empty, must begin and end with an alphanumeric character ([a-z0-9A-Z]),
|
||||
// * could contain dashes (-), underscores (_), dots (.), and alphanumerics between.
|
||||
//
|
||||
// Valid values include:
|
||||
//
|
||||
// * MyValue
|
||||
// * my.name
|
||||
// * 123-my-value
|
||||
//
|
||||
// +kubebuilder:validation:MinLength=0
|
||||
// +kubebuilder:validation:MaxLength=63
|
||||
// +kubebuilder:validation:Pattern=`^(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])?$`
|
||||
type LabelValue string
|
||||
|
||||
// AddressType defines how a network address is represented as a text string.
|
||||
// This may take two possible forms:
|
||||
//
|
||||
@@ -712,7 +878,7 @@ const (
|
||||
// (see [RFC 5952](https://tools.ietf.org/html/rfc5952)).
|
||||
//
|
||||
// This type is intended for specific addresses. Address ranges are not
|
||||
// supported (e.g. you can not use a CIDR range like 127.0.0.0/24 as an
|
||||
// supported (e.g. you cannot use a CIDR range like 127.0.0.0/24 as an
|
||||
// IPAddress).
|
||||
//
|
||||
// Support: Extended
|
||||
@@ -736,3 +902,129 @@ const (
|
||||
// Support: Implementation-specific
|
||||
NamedAddressType AddressType = "NamedAddress"
|
||||
)
|
||||
|
||||
// SessionPersistence defines the desired state of SessionPersistence.
|
||||
// +kubebuilder:validation:XValidation:message="AbsoluteTimeout must be specified when cookie lifetimeType is Permanent",rule="!has(self.cookieConfig) || !has(self.cookieConfig.lifetimeType) || self.cookieConfig.lifetimeType != 'Permanent' || has(self.absoluteTimeout)"
|
||||
type SessionPersistence struct {
|
||||
// SessionName defines the name of the persistent session token
|
||||
// which may be reflected in the cookie or the header. Users
|
||||
// should avoid reusing session names to prevent unintended
|
||||
// consequences, such as rejection or unpredictable behavior.
|
||||
//
|
||||
// Support: Implementation-specific
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:validation:MaxLength=128
|
||||
SessionName *string `json:"sessionName,omitempty"`
|
||||
|
||||
// AbsoluteTimeout defines the absolute timeout of the persistent
|
||||
// session. Once the AbsoluteTimeout duration has elapsed, the
|
||||
// session becomes invalid.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
AbsoluteTimeout *Duration `json:"absoluteTimeout,omitempty"`
|
||||
|
||||
// IdleTimeout defines the idle timeout of the persistent session.
|
||||
// Once the session has been idle for more than the specified
|
||||
// IdleTimeout duration, the session becomes invalid.
|
||||
//
|
||||
// Support: Extended
|
||||
//
|
||||
// +optional
|
||||
IdleTimeout *Duration `json:"idleTimeout,omitempty"`
|
||||
|
||||
// Type defines the type of session persistence such as through
|
||||
// the use a header or cookie. Defaults to cookie based session
|
||||
// persistence.
|
||||
//
|
||||
// Support: Core for "Cookie" type
|
||||
//
|
||||
// Support: Extended for "Header" type
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:default=Cookie
|
||||
Type *SessionPersistenceType `json:"type,omitempty"`
|
||||
|
||||
// CookieConfig provides configuration settings that are specific
|
||||
// to cookie-based session persistence.
|
||||
//
|
||||
// Support: Core
|
||||
//
|
||||
// +optional
|
||||
CookieConfig *CookieConfig `json:"cookieConfig,omitempty"`
|
||||
}
|
||||
|
||||
// +kubebuilder:validation:Enum=Cookie;Header
|
||||
type SessionPersistenceType string
|
||||
|
||||
const (
|
||||
// CookieBasedSessionPersistence specifies cookie-based session
|
||||
// persistence.
|
||||
//
|
||||
// Support: Core
|
||||
CookieBasedSessionPersistence SessionPersistenceType = "Cookie"
|
||||
|
||||
// HeaderBasedSessionPersistence specifies header-based session
|
||||
// persistence.
|
||||
//
|
||||
// Support: Extended
|
||||
HeaderBasedSessionPersistence SessionPersistenceType = "Header"
|
||||
)
|
||||
|
||||
// CookieConfig defines the configuration for cookie-based session persistence.
|
||||
type CookieConfig struct {
|
||||
// LifetimeType specifies whether the cookie has a permanent or
|
||||
// session-based lifetime. A permanent cookie persists until its
|
||||
// specified expiry time, defined by the Expires or Max-Age cookie
|
||||
// attributes, while a session cookie is deleted when the current
|
||||
// session ends.
|
||||
//
|
||||
// When set to "Permanent", AbsoluteTimeout indicates the
|
||||
// cookie's lifetime via the Expires or Max-Age cookie attributes
|
||||
// and is required.
|
||||
//
|
||||
// When set to "Session", AbsoluteTimeout indicates the
|
||||
// absolute lifetime of the cookie tracked by the gateway and
|
||||
// is optional.
|
||||
//
|
||||
// Defaults to "Session".
|
||||
//
|
||||
// Support: Core for "Session" type
|
||||
//
|
||||
// Support: Extended for "Permanent" type
|
||||
//
|
||||
// +optional
|
||||
// +kubebuilder:default=Session
|
||||
LifetimeType *CookieLifetimeType `json:"lifetimeType,omitempty"`
|
||||
}
|
||||
|
||||
// +kubebuilder:validation:Enum=Permanent;Session
|
||||
type CookieLifetimeType string
|
||||
|
||||
const (
|
||||
// SessionCookieLifetimeType specifies the type for a session
|
||||
// cookie.
|
||||
//
|
||||
// Support: Core
|
||||
SessionCookieLifetimeType CookieLifetimeType = "Session"
|
||||
|
||||
// PermanentCookieLifetimeType specifies the type for a permanent
|
||||
// cookie.
|
||||
//
|
||||
// Support: Extended
|
||||
PermanentCookieLifetimeType CookieLifetimeType = "Permanent"
|
||||
)
|
||||
|
||||
// +kubebuilder:validation:XValidation:message="numerator must be less than or equal to denominator",rule="self.numerator <= self.denominator"
|
||||
type Fraction struct {
|
||||
// +kubebuilder:validation:Minimum=0
|
||||
// +required
|
||||
Numerator int32 `json:"numerator"`
|
||||
|
||||
// +optional
|
||||
// +kubebuilder:default=100
|
||||
// +kubebuilder:validation:Minimum=1
|
||||
Denominator *int32 `json:"denominator,omitempty"`
|
||||
}
|
||||
|
||||
@@ -46,7 +46,7 @@ func (in *BackendObjectReference) DeepCopyInto(out *BackendObjectReference) {
|
||||
}
|
||||
if in.Port != nil {
|
||||
in, out := &in.Port, &out.Port
|
||||
*out = new(PortNumber)
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
return
|
||||
@@ -107,6 +107,111 @@ func (in *CommonRouteSpec) DeepCopy() *CommonRouteSpec {
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *CookieConfig) DeepCopyInto(out *CookieConfig) {
|
||||
*out = *in
|
||||
if in.LifetimeType != nil {
|
||||
in, out := &in.LifetimeType, &out.LifetimeType
|
||||
*out = new(CookieLifetimeType)
|
||||
**out = **in
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CookieConfig.
|
||||
func (in *CookieConfig) DeepCopy() *CookieConfig {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(CookieConfig)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *ForwardBodyConfig) DeepCopyInto(out *ForwardBodyConfig) {
|
||||
*out = *in
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ForwardBodyConfig.
|
||||
func (in *ForwardBodyConfig) DeepCopy() *ForwardBodyConfig {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(ForwardBodyConfig)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *Fraction) DeepCopyInto(out *Fraction) {
|
||||
*out = *in
|
||||
if in.Denominator != nil {
|
||||
in, out := &in.Denominator, &out.Denominator
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new Fraction.
|
||||
func (in *Fraction) DeepCopy() *Fraction {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(Fraction)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *GRPCAuthConfig) DeepCopyInto(out *GRPCAuthConfig) {
|
||||
*out = *in
|
||||
if in.AllowedRequestHeaders != nil {
|
||||
in, out := &in.AllowedRequestHeaders, &out.AllowedRequestHeaders
|
||||
*out = make([]string, len(*in))
|
||||
copy(*out, *in)
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new GRPCAuthConfig.
|
||||
func (in *GRPCAuthConfig) DeepCopy() *GRPCAuthConfig {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(GRPCAuthConfig)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *HTTPAuthConfig) DeepCopyInto(out *HTTPAuthConfig) {
|
||||
*out = *in
|
||||
if in.AllowedRequestHeaders != nil {
|
||||
in, out := &in.AllowedRequestHeaders, &out.AllowedRequestHeaders
|
||||
*out = make([]string, len(*in))
|
||||
copy(*out, *in)
|
||||
}
|
||||
if in.AllowedResponseHeaders != nil {
|
||||
in, out := &in.AllowedResponseHeaders, &out.AllowedResponseHeaders
|
||||
*out = make([]string, len(*in))
|
||||
copy(*out, *in)
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new HTTPAuthConfig.
|
||||
func (in *HTTPAuthConfig) DeepCopy() *HTTPAuthConfig {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(HTTPAuthConfig)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *HTTPBackendRef) DeepCopyInto(out *HTTPBackendRef) {
|
||||
*out = *in
|
||||
@@ -131,6 +236,79 @@ func (in *HTTPBackendRef) DeepCopy() *HTTPBackendRef {
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *HTTPCORSFilter) DeepCopyInto(out *HTTPCORSFilter) {
|
||||
*out = *in
|
||||
if in.AllowOrigins != nil {
|
||||
in, out := &in.AllowOrigins, &out.AllowOrigins
|
||||
*out = make([]CORSOrigin, len(*in))
|
||||
copy(*out, *in)
|
||||
}
|
||||
if in.AllowCredentials != nil {
|
||||
in, out := &in.AllowCredentials, &out.AllowCredentials
|
||||
*out = new(bool)
|
||||
**out = **in
|
||||
}
|
||||
if in.AllowMethods != nil {
|
||||
in, out := &in.AllowMethods, &out.AllowMethods
|
||||
*out = make([]HTTPMethodWithWildcard, len(*in))
|
||||
copy(*out, *in)
|
||||
}
|
||||
if in.AllowHeaders != nil {
|
||||
in, out := &in.AllowHeaders, &out.AllowHeaders
|
||||
*out = make([]HTTPHeaderName, len(*in))
|
||||
copy(*out, *in)
|
||||
}
|
||||
if in.ExposeHeaders != nil {
|
||||
in, out := &in.ExposeHeaders, &out.ExposeHeaders
|
||||
*out = make([]HTTPHeaderName, len(*in))
|
||||
copy(*out, *in)
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new HTTPCORSFilter.
|
||||
func (in *HTTPCORSFilter) DeepCopy() *HTTPCORSFilter {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(HTTPCORSFilter)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *HTTPExternalAuthFilter) DeepCopyInto(out *HTTPExternalAuthFilter) {
|
||||
*out = *in
|
||||
in.BackendRef.DeepCopyInto(&out.BackendRef)
|
||||
if in.GRPCAuthConfig != nil {
|
||||
in, out := &in.GRPCAuthConfig, &out.GRPCAuthConfig
|
||||
*out = new(GRPCAuthConfig)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
if in.HTTPAuthConfig != nil {
|
||||
in, out := &in.HTTPAuthConfig, &out.HTTPAuthConfig
|
||||
*out = new(HTTPAuthConfig)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
if in.ForwardBody != nil {
|
||||
in, out := &in.ForwardBody, &out.ForwardBody
|
||||
*out = new(ForwardBodyConfig)
|
||||
**out = **in
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new HTTPExternalAuthFilter.
|
||||
func (in *HTTPExternalAuthFilter) DeepCopy() *HTTPExternalAuthFilter {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(HTTPExternalAuthFilter)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *HTTPHeader) DeepCopyInto(out *HTTPHeader) {
|
||||
*out = *in
|
||||
@@ -276,6 +454,16 @@ func (in *HTTPQueryParamMatch) DeepCopy() *HTTPQueryParamMatch {
|
||||
func (in *HTTPRequestMirrorFilter) DeepCopyInto(out *HTTPRequestMirrorFilter) {
|
||||
*out = *in
|
||||
in.BackendRef.DeepCopyInto(&out.BackendRef)
|
||||
if in.Percent != nil {
|
||||
in, out := &in.Percent, &out.Percent
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
if in.Fraction != nil {
|
||||
in, out := &in.Fraction, &out.Fraction
|
||||
*out = new(Fraction)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
@@ -309,7 +497,7 @@ func (in *HTTPRequestRedirectFilter) DeepCopyInto(out *HTTPRequestRedirectFilter
|
||||
}
|
||||
if in.Port != nil {
|
||||
in, out := &in.Port, &out.Port
|
||||
*out = new(PortNumber)
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
if in.StatusCode != nil {
|
||||
@@ -386,6 +574,16 @@ func (in *HTTPRouteFilter) DeepCopyInto(out *HTTPRouteFilter) {
|
||||
*out = new(HTTPURLRewriteFilter)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
if in.CORS != nil {
|
||||
in, out := &in.CORS, &out.CORS
|
||||
*out = new(HTTPCORSFilter)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
if in.ExternalAuth != nil {
|
||||
in, out := &in.ExternalAuth, &out.ExternalAuth
|
||||
*out = new(HTTPExternalAuthFilter)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
if in.ExtensionRef != nil {
|
||||
in, out := &in.ExtensionRef, &out.ExtensionRef
|
||||
*out = new(LocalObjectReference)
|
||||
@@ -477,9 +675,45 @@ func (in *HTTPRouteMatch) DeepCopy() *HTTPRouteMatch {
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *HTTPRouteRetry) DeepCopyInto(out *HTTPRouteRetry) {
|
||||
*out = *in
|
||||
if in.Codes != nil {
|
||||
in, out := &in.Codes, &out.Codes
|
||||
*out = make([]HTTPRouteRetryStatusCode, len(*in))
|
||||
copy(*out, *in)
|
||||
}
|
||||
if in.Attempts != nil {
|
||||
in, out := &in.Attempts, &out.Attempts
|
||||
*out = new(int)
|
||||
**out = **in
|
||||
}
|
||||
if in.Backoff != nil {
|
||||
in, out := &in.Backoff, &out.Backoff
|
||||
*out = new(Duration)
|
||||
**out = **in
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new HTTPRouteRetry.
|
||||
func (in *HTTPRouteRetry) DeepCopy() *HTTPRouteRetry {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(HTTPRouteRetry)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *HTTPRouteRule) DeepCopyInto(out *HTTPRouteRule) {
|
||||
*out = *in
|
||||
if in.Name != nil {
|
||||
in, out := &in.Name, &out.Name
|
||||
*out = new(SectionName)
|
||||
**out = **in
|
||||
}
|
||||
if in.Matches != nil {
|
||||
in, out := &in.Matches, &out.Matches
|
||||
*out = make([]HTTPRouteMatch, len(*in))
|
||||
@@ -506,6 +740,16 @@ func (in *HTTPRouteRule) DeepCopyInto(out *HTTPRouteRule) {
|
||||
*out = new(HTTPRouteTimeouts)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
if in.Retry != nil {
|
||||
in, out := &in.Retry, &out.Retry
|
||||
*out = new(HTTPRouteRetry)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
if in.SessionPersistence != nil {
|
||||
in, out := &in.SessionPersistence, &out.SessionPersistence
|
||||
*out = new(SessionPersistence)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
@@ -633,6 +877,27 @@ func (in *LocalObjectReference) DeepCopy() *LocalObjectReference {
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *ObjectReference) DeepCopyInto(out *ObjectReference) {
|
||||
*out = *in
|
||||
if in.Namespace != nil {
|
||||
in, out := &in.Namespace, &out.Namespace
|
||||
*out = new(Namespace)
|
||||
**out = **in
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new ObjectReference.
|
||||
func (in *ObjectReference) DeepCopy() *ObjectReference {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(ObjectReference)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *ParentReference) DeepCopyInto(out *ParentReference) {
|
||||
*out = *in
|
||||
@@ -658,7 +923,7 @@ func (in *ParentReference) DeepCopyInto(out *ParentReference) {
|
||||
}
|
||||
if in.Port != nil {
|
||||
in, out := &in.Port, &out.Port
|
||||
*out = new(PortNumber)
|
||||
*out = new(int32)
|
||||
**out = **in
|
||||
}
|
||||
return
|
||||
@@ -751,3 +1016,44 @@ func (in *SecretObjectReference) DeepCopy() *SecretObjectReference {
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||
func (in *SessionPersistence) DeepCopyInto(out *SessionPersistence) {
|
||||
*out = *in
|
||||
if in.SessionName != nil {
|
||||
in, out := &in.SessionName, &out.SessionName
|
||||
*out = new(string)
|
||||
**out = **in
|
||||
}
|
||||
if in.AbsoluteTimeout != nil {
|
||||
in, out := &in.AbsoluteTimeout, &out.AbsoluteTimeout
|
||||
*out = new(Duration)
|
||||
**out = **in
|
||||
}
|
||||
if in.IdleTimeout != nil {
|
||||
in, out := &in.IdleTimeout, &out.IdleTimeout
|
||||
*out = new(Duration)
|
||||
**out = **in
|
||||
}
|
||||
if in.Type != nil {
|
||||
in, out := &in.Type, &out.Type
|
||||
*out = new(SessionPersistenceType)
|
||||
**out = **in
|
||||
}
|
||||
if in.CookieConfig != nil {
|
||||
in, out := &in.CookieConfig, &out.CookieConfig
|
||||
*out = new(CookieConfig)
|
||||
(*in).DeepCopyInto(*out)
|
||||
}
|
||||
return
|
||||
}
|
||||
|
||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new SessionPersistence.
|
||||
func (in *SessionPersistence) DeepCopy() *SessionPersistence {
|
||||
if in == nil {
|
||||
return nil
|
||||
}
|
||||
out := new(SessionPersistence)
|
||||
in.DeepCopyInto(out)
|
||||
return out
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user