DynamoGraphDeployment nvidia.com/v1beta1, nvidia.com/v1alpha1
nvidia.com/v1beta1
# DynamoGraphDeployment is the Schema for the dynamographdeployments API.
#
# v1beta1 is a served version: the API server accepts reads and writes against it, and transparently
# converts to/from v1alpha1 (still the storage version until a later MR flips it). Conversion goes
# through the operator's conversion webhook; see api/v1alpha1/*_conversion.go.
apiVersion: nvidia.com/v1beta1
kind: DynamoGraphDeployment
metadata:
# Name must be unique within a namespace.
name: "<string>" # required
# Namespace defines the space within which each name must be unique.
namespace: "<string>" # required
# Annotations is an unstructured key value map stored with a resource.
# annotations:
# <key>: "<string>"
# CreationTimestamp is set by the server when a resource is created.
# creationTimestamp: "<string>"
# Number of seconds allowed for graceful deletion.
# deletionGracePeriodSeconds: <int64>
# DeletionTimestamp is set by the server when graceful deletion is requested.
# deletionTimestamp: "<string>"
# Finalizers must be empty before the object is deleted from the registry.
# finalizers:
# - "<string>"
# GenerateName is an optional prefix used by the server to generate a unique name.
# generateName: "<string>"
# Generation is a sequence number representing a specific desired state.
# generation: <int64>
# Labels are key value pairs used to organize and select objects.
# labels:
# <key>: "<string>"
# ManagedFields records which actor manages which fields.
# managedFields:
# - # APIVersion defines the version of this field set.
# apiVersion: "<string>"
# FieldsType is the discriminator for the fields format.
# fieldsType: "<string>"
# FieldsV1 stores a versioned field set.
# fieldsV1: {} # preserveUnknownFields
# Manager identifies the workflow managing these fields.
# manager: "<string>"
# Operation is the type of operation that produced this managedFields entry.
# operation: "<string>"
# Subresource is the name of the subresource used to update the object.
# subresource: "<string>"
# Time is when this managedFields entry was added.
# time: "<string>"
# OwnerReferences lists objects depended on by this object.
ownerReferences: # optional
- # API version of the referent.
apiVersion: "<string>" # required
# Kind of the referent.
kind: "<string>" # required
# Name of the referent.
name: "<string>" # required
# UID of the referent.
uid: "<string>" # required
# BlockOwnerDeletion controls foreground deletion behavior.
# blockOwnerDeletion: <boolean>
# Controller marks the managing controller owner reference.
# controller: <boolean>
# ResourceVersion is an opaque internal version value.
# resourceVersion: "<string>"
# SelfLink is a deprecated read-only field.
# selfLink: "<string>"
# UID is the unique in time and space value for this object.
# uid: "<string>"
# spec defines the desired state for this graph deployment.
spec: # optional
# annotations to propagate to all child resources (PCS, DCD, Deployments, and pod templates).
# Component-level (`podTemplate`) values take precedence on conflict.
# annotations:
# <key>: "<string>"
# backendFramework specifies the backend framework (e.g. "sglang", "vllm", "trtllm").
# backendFramework: "sglang" # enum: "vllm" | "trtllm"
# components are the components deployed as part of this graph. Each entry carries its own stable
# logical `name`, and names must be unique within the list. Component types are generally
# repeatable, except `type: epp` which may appear at most once.
components: # optional, listType: map, listMapKeys: name
- # name is the stable logical identifier for this component within its DynamoGraphDeployment.
# It must be unique within the parent's `spec.components` list.
#
# For standalone DynamoComponentDeployment objects, the defaulting webhook populates `name`
# from `metadata.name` on admission, so users typically do not need to set it explicitly.
#
# `name` is decoupled from the underlying Kubernetes resource name so that the operator can
# rename child workloads (e.g. suffixing worker DCDs with a hash during rolling updates)
# without losing the stable identity that downstream consumers (labels, status maps, DGDSA
# references, planner RBAC, EPP filters) depend on.
name: "<string>" # required, minLength: 1, maxLength: 63
# compilationCache configures a PVC-backed compilation cache. The operator handles
# backend-specific mount paths and environment variables, so users do not need to hand-wire
# them into `podTemplate`. Extracted from v1alpha1's `volumeMount.useAsCompilationCache` flag.
compilationCache: # optional
# pvcName references a user-created PVC by name. The PVC must exist in the same namespace as
# the DynamoGraphDeployment.
pvcName: "<string>" # required, minLength: 1
# mountPath overrides the backend-specific default mount path. When empty, the operator
# selects a default appropriate for the backend framework.
# mountPath: "<string>"
# eppConfig holds EPP-specific configuration for Endpoint Picker Plugin components. Only
# meaningful when `type` is `epp`.
eppConfig: # optional
# config allows specifying EPP `EndpointPickerConfig` directly as a structured object. The
# operator marshals this to YAML and creates a ConfigMap automatically. Mutually exclusive
# with `configMapRef`. One of `configMapRef` or `config` must be specified.
config: # optional, preserveUnknownFields
# Plugins is the list of plugins that will be instantiated.
plugins: # required
- # Type specifies the plugin type to be instantiated.
type: "<string>" # required
# Name provides a name for plugin entries to reference. If omitted, the value of the
# Plugin's Type field will be used.
# name: "<string>"
# Parameters are the set of parameters to be passed to the plugin's factory function.
# The factory function is responsible to parse the parameters.
# parameters: {} # preserveUnknownFields
# SchedulingProfiles is the list of named SchedulingProfiles that will be created.
schedulingProfiles: # required
- # Name specifies the name of this SchedulingProfile
name: "<string>" # required
# Plugins is the list of plugins for this SchedulingProfile. They are assigned to the
# appropriate "slots" based on their type.
plugins: # required
- # PluginRef specifies a partiular Plugin instance to be associated with this
# SchedulingProfile. The reference is to the name of an entry of the Plugins
# defined in the configuration's Plugins section
pluginRef: "<string>" # required
# Weight is the weight fo be used if this plugin is a Scorer.
# weight: <integer>
# APIVersion defines the versioned schema of this representation of an object. Servers
# should convert recognized schemas to the latest internal value, and may reject
# unrecognized values. More info:
# https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
# apiVersion: "<string>"
# FeatureGates is a set of flags that enable various experimental features with the EPP.
# If omitted non of these experimental features will be enabled.
# featureGates:
# - "<string>"
# Kind is a string value representing the REST resource this object represents. Servers
# may infer this from the endpoint the client submits requests to. Cannot be updated. In
# CamelCase. More info:
# https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
# kind: "<string>"
# SaturationDetector when present specifies the configuration of the Saturation detector.
# If not present, default values are used.
# saturationDetector:
# KVCacheUtilThreshold defines the KV cache utilization (0.0 to 1.0) above which a pod
# is considered to have insufficient capacity.
# kvCacheUtilThreshold: <number>
# MetricsStalenessThreshold defines how old a pod's metrics can be. If a pod's metrics
# are older than this, it might be excluded from "good capacity" considerations or
# treated as having no capacity for safety.
# metricsStalenessThreshold: "<string>"
# QueueDepthThreshold defines the backend waiting queue size above which a pod is
# considered to have insufficient capacity for new requests.
# queueDepthThreshold: <integer>
# configMapRef references a user-provided ConfigMap containing EPP configuration. Mutually
# exclusive with `config`.
configMapRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value here
# are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# experimental groups opt-in preview features whose API shape and behavior may change in
# breaking ways between v1beta1 releases, including disappearing without a name-preserving
# graduation path. In v1beta1 this block holds `gpuMemoryService` and `failover` (which remain
# tightly coupled -- failover requires GMS -- and are expected to evolve together as the
# DRA-based GPU sharing story matures), and `checkpoint` (whose interaction with the
# standalone DynamoCheckpoint resource and identity-hash computation is still settling).
# Fields here are explicitly NOT covered by the normal v1beta1 deprecation policy; do not
# depend on them for production workloads.
experimental: # optional
# checkpoint configures container-image snapshotting and restore for this component. When
# set, the DGD controller can produce a DGD-scoped DynamoCheckpoint CR and later restore
# pods in the same DGD generation from that checkpoint for faster cold start. The
# user-facing shape of this field is still settling, which is why it lives under
# `experimental` in v1beta1 instead of at the top level.
checkpoint: # optional
# checkpointRef references an existing DynamoCheckpoint CR by `metadata.name`. When set,
# this component's `identity` is ignored and the referenced checkpoint is used directly.
# checkpointRef: "<string>"
# Deprecated: identity is ignored by DGD-managed automatic checkpoints. Automatic
# checkpoints are scoped to the owning DGD/component generation and are never reused
# across DGDs.
identity: # optional
# backendFramework is the runtime framework (`vllm`, `sglang`, `trtllm`).
backendFramework: "vllm" # required, enum: "sglang" | "trtllm"
# model is the model identifier (e.g. "meta-llama/Llama-3-70B").
model: "<string>" # required, minLength: 1
# dtype is the data type (`fp16`, `bf16`, `fp8`, etc.). Deprecated for DGD-managed
# automatic checkpoints; it only participates in the legacy identity hash fallback for
# standalone objects.
# dtype: "<string>"
# dynamoVersion is the Dynamo platform version. Deprecated for DGD-managed automatic
# checkpoints; it only participates in the legacy identity hash fallback for standalone
# objects.
# dynamoVersion: "<string>"
# extraParameters are additional parameters that affect the checkpoint hash. Deprecated
# for DGD-managed automatic checkpoints; it only participates in the legacy identity
# hash fallback for standalone objects.
# extraParameters:
# <key>: "<string>"
# maxModelLen is the maximum sequence length. Deprecated for DGD-managed automatic
# checkpoints; it only participates in the legacy identity hash fallback for standalone
# objects.
# maxModelLen: <int32> # minimum: 1
# pipelineParallelSize is the pipeline parallel configuration. Deprecated for
# DGD-managed automatic checkpoints; it only participates in the legacy identity hash
# fallback for standalone objects.
# pipelineParallelSize: 1 # default, minimum: 1
# tensorParallelSize is the tensor parallel configuration. Deprecated for DGD-managed
# automatic checkpoints; it only participates in the legacy identity hash fallback for
# standalone objects.
# tensorParallelSize: 1 # default, minimum: 1
# job customizes the checkpoint Job that is created in Auto mode.
# job:
# gmsClientContainers lists checkpoint Job containers that should receive GMS client
# wiring. Requires gpuMemoryService on the component.
# gmsClientContainers: # listType: set
# - "<string>"
# podTemplate customizes the checkpoint Job pod. The operator starts from the selected
# workload container and merges this template so users can add helper containers such as
# gms-saver.
# podTemplate: {} # preserveUnknownFields
# mode defines how checkpoint creation is handled. `Auto`: DGD controller creates the
# DynamoCheckpoint CR automatically. `Manual`: user must create the DynamoCheckpoint CR.
# mode: "Auto" # default, enum: "Manual"
# targetContainerName is the workload container to snapshot and restore.
# targetContainerName: "main" # default, minLength: 1, maxLength: 63
# failover configures active-passive GPU failover for this component. Requires
# `gpuMemoryService` to also be set, and `failover.mode` must match `gpuMemoryService.mode`
# (enforced by the validation webhook).
# failover:
# mode selects the failover deployment topology. Must match
# `spec.experimental.gpuMemoryService.mode` (or
# `spec.components[*].experimental.gpuMemoryService.mode` inside a DynamoGraphDeployment).
# mode: "IntraPod" # default, enum: "InterPod"
# numShadows is the number of shadow (standby) engine containers per rank. Reserved for
# future use; the operator currently creates exactly one shadow.
# numShadows: 1 # default, minimum: 1, maximum: 1
# gpuMemoryService configures the GPU Memory Service (GMS). When set, GPU access for GMS
# clients is managed via DRA.
gpuMemoryService: # optional
# deviceClassName is the DRA `DeviceClass` to request GPUs from.
# deviceClassName: "gpu.nvidia.com" # default
# extraClientContainers lists additional user-declared containers that should be wired as
# GMS clients in service pods. Checkpoint Job clients are declared under
# checkpoint.job.gmsClientContainers. In each rendered pod, only matching container names
# are wired; absent names are ignored.
# extraClientContainers: # listType: set
# - "<string>"
# extraClientPods declares additional GMS client pods for inter-pod GMS. This field is
# reserved for future use and is rejected until inter-pod client orchestration is wired.
extraClientPods: # optional, listType: map, listMapKeys: name
- # name identifies this client pod.
name: "<string>" # required, minLength: 1, maxLength: 63
# podTemplate configures the pod to run as a GMS client.
podTemplate: {} # required, preserveUnknownFields
# mode selects the GMS deployment topology.
# mode: "IntraPod" # default, enum: "InterPod"
# frontendSidecar optionally designates a container in `podTemplate.spec.containers` as the
# frontend sidecar. The value must match the `name` of a container in that list; the operator
# merges its frontend-sidecar defaults (auto-generated Dynamo env vars, ports, health probes)
# into that container the same way it merges into `"main"`. The full container definition
# (image, args, envFrom, env) lives in `podTemplate` -- this eliminates the redundant `image`,
# `args`, `envFromSecret`, and `envs` fields from v1alpha1's `FrontendSidecarSpec`. The
# validation webhook rejects values that do not match any container name in
# `podTemplate.spec.containers`.
# frontendSidecar: "<string>"
# globalDynamoNamespace places the component in the global Dynamo namespace rather than the
# per-deployment namespace derived from the DGD name.
# globalDynamoNamespace: <boolean>
# modelRef references a model served by this component. When specified, a headless service is
# created for endpoint discovery.
modelRef: # optional
# name is the base model identifier (e.g. "llama-3-70b-instruct-v1").
name: "<string>" # required, minLength: 1
# revision is the model revision/version.
# revision: "<string>"
# multinode configures multinode components.
# multinode:
# nodeCount is the number of nodes to deploy for the multinode component. Total GPUs used is
# `nodeCount * container GPU request`.
# nodeCount: 2 # default, minimum: 2
# podTemplate is the pod template used to create the component's pods. The operator injects
# its defaults (image, command, env, ports, probes, resources, volume mounts) into the
# container named `"main"` inside `podTemplate.spec.containers`, merging user overrides by
# name. If no container named `"main"` is present, the operator auto-generates it with
# standard defaults. All other containers in `podTemplate.spec.containers` are treated as
# user-managed sidecars: the operator does not inject defaults into them, so sidecars must
# specify required fields (e.g. `image`) themselves. The validation webhook rejects pod
# templates where a non-`"main"` container is missing a required field such as `image`.
podTemplate: # optional
# Standard object's metadata. More info:
# https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
# metadata:
# annotations:
# <key>: "<string>"
# finalizers:
# - "<string>"
# labels:
# <key>: "<string>"
# name: "<string>"
# namespace: "<string>"
# Specification of the desired behavior of the pod. More info:
# https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#spec-and-status
spec: # optional
# List of containers belonging to the pod. Containers cannot currently be added or
# removed. There must be at least one container in a Pod. Cannot be updated.
containers: # required, listType: map, listMapKeys: name
- # Name of the container specified as a DNS_LABEL. Each container in a pod must have a
# unique name (DNS_LABEL). Cannot be updated.
name: "<string>" # required
# Arguments to the entrypoint. The container image's CMD is used if this is not
# provided. Variable references $(VAR_NAME) are expanded using the container's
# environment. If a variable cannot be resolved, the reference in the input string
# will be unchanged. Double $$ are reduced to a single $, which allows for escaping
# the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal
# "$(VAR_NAME)". Escaped references will never be expanded, regardless of whether the
# variable exists or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# args: # listType: atomic
# - "<string>"
# Entrypoint array. Not executed within a shell. The container image's ENTRYPOINT is
# used if this is not provided. Variable references $(VAR_NAME) are expanded using the
# container's environment. If a variable cannot be resolved, the reference in the
# input string will be unchanged. Double $$ are reduced to a single $, which allows
# for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string
# literal "$(VAR_NAME)". Escaped references will never be expanded, regardless of
# whether the variable exists or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# command: # listType: atomic
# - "<string>"
# List of environment variables to set in the container. Cannot be updated.
env: # optional, listType: map, listMapKeys: name
- # Name of the environment variable. May consist of any printable ASCII characters
# except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined
# environment variables in the container and any service environment variables. If
# a variable cannot be resolved, the reference in the input string will be
# unchanged. Double $$ are reduced to a single $, which allows for escaping the
# $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal
# "$(VAR_NAME)". Escaped references will never be expanded, regardless of whether
# the variable exists or not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not
# empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to
# backwards compatibility is allowed to be empty. Instances of this type with
# an empty value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to
# "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate
# to be enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from
# starting. The keys defined within a source may consist of any printable
# ASCII characters except '='. During Alpha stage of the EnvFiles feature
# gate, the key size is limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative
# and may not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does
# not exist, then the env var is not published. If optional is set to true and
# the specified key does not exist, the environment variable will not be set
# in the Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error
# will be returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
# requests.memory and requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to
# backwards compatibility is allowed to be empty. Instances of this type with
# an empty value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# List of sources to populate environment variables in the container. The keys defined
# within a source may consist of any printable ASCII characters except '='. When a key
# exists in multiple sources, the value associated with the last source will take
# precedence. Values defined by an Env with a duplicate key will take precedence.
# Cannot be updated.
# envFrom: # listType: atomic
# - # The ConfigMap to select from
# configMapRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap must be defined
# optional: <boolean>
# Optional text to prepend to the name of each environment variable. May consist
# of any printable ASCII characters except '='.
# prefix: "<string>"
# The Secret to select from
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret must be defined
# optional: <boolean>
# Container image name. More info:
# https://kubernetes.io/docs/concepts/containers/images This field is optional to
# allow higher level config management to default or override container images in
# workload controllers like Deployments and StatefulSets.
# image: "<string>"
# Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if :latest
# tag is specified, or IfNotPresent otherwise. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/containers/images#updating-images
# imagePullPolicy: "<string>"
# Actions that the management system should take in response to container lifecycle
# events. Cannot be updated.
lifecycle: # optional
# PostStart is called immediately after a container is created. If the handler
# fails, the container is terminated and restarted according to its restart policy.
# Other management of the container blocks until the hook completes. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
postStart: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly
# call out to that shell. Exit status of 0 is treated as live/healthy and
# non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set
# "Host" in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for
# backward compatibility. There is no validation of this field and lifecycle hooks
# will fail at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# PreStop is called immediately before a container is terminated due to an API
# request or management event such as liveness/startup probe failure, preemption,
# resource contention, etc. The handler is not called if the container crashes or
# exits. The Pod's termination grace period countdown begins before the PreStop hook
# is executed. Regardless of the outcome of the handler, the container will
# eventually terminate within the Pod's termination grace period (unless delayed by
# finalizers). Other management of the container blocks until the hook completes or
# until the termination grace period is reached. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
preStop: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly
# call out to that shell. Exit status of 0 is treated as live/healthy and
# non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set
# "Host" in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for
# backward compatibility. There is no validation of this field and lifecycle hooks
# will fail at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# StopSignal defines which signal will be sent to a container when it is being
# stopped. If not specified, the default is defined by the container runtime in use.
# StopSignal can only be set for Pods with a non-empty .spec.os.name
# stopSignal: "<string>"
# Periodic probe of container liveness. Container will be restarted if the probe
# fails. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
livenessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# List of ports to expose from the container. Not specifying a port here DOES NOT
# prevent that port from being exposed. Any port which is listening on the default
# "0.0.0.0" address inside a container will be accessible from the network. Modifying
# this array with strategic merge patch may corrupt the data. For more information See
# https://github.com/kubernetes/kubernetes/issues/108255. Cannot be updated.
ports: # optional, listType: map, listMapKeys: containerPort, protocol
- # Number of port to expose on the pod's IP address. This must be a valid port
# number, 0 < x < 65536.
containerPort: <int32> # required
# What host IP to bind the external port to.
# hostIP: "<string>"
# Number of port to expose on the host. If specified, this must be a valid port
# number, 0 < x < 65536. If HostNetwork is specified, this must match
# ContainerPort. Most containers do not need this.
# hostPort: <int32>
# If specified, this must be an IANA_SVC_NAME and unique within the pod. Each
# named port in a pod must have a unique name. Name for the port that can be
# referred to by services.
# name: "<string>"
# Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
# protocol: "TCP" # default
# Periodic probe of container service readiness. Container will be removed from
# service endpoints if the probe fails. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
readinessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Resources resize policy for the container.
resizePolicy: # optional, listType: atomic
- # Name of the resource to which this resource resize policy applies. Supported
# values: cpu, memory.
resourceName: "<string>" # required
# Restart policy to apply when specified resource is resized. If not specified, it
# defaults to NotRequired.
restartPolicy: "<string>" # required
# Compute Resources required by this container. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used
# by this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod
# where this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests
# is omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More
# info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# RestartPolicy defines the restart behavior of individual containers in a pod. This
# overrides the pod-level restart policy. When this field is not specified, the
# restart behavior is defined by the Pod's restart policy and the container type.
# Additionally, setting the RestartPolicy as "Always" for the init container will have
# the following effect: this init container will be continually restarted on exit
# until all regular containers have terminated. Once all regular containers have
# completed, all init containers with restartPolicy "Always" will be shut down. This
# lifecycle differs from normal init containers and is often referred to as a
# "sidecar" container. Although this init container still starts in the init container
# sequence, it does not wait for the container to complete before proceeding to the
# next init container. Instead, the next init container starts immediately after this
# init container is started, or after any startupProbe has successfully completed.
# restartPolicy: "<string>"
# Represents a list of rules to be checked to determine if the container should be
# restarted on exit. The rules are evaluated in order. Once a rule matches a container
# exit condition, the remaining rules are ignored. If no rule matches the container
# exit condition, the Container-level restart policy determines the whether the
# container is restarted or not. Constraints on the rules: - At most 20 rules are
# allowed. - Rules can have the same action. - Identical rules are not forbidden in
# validations. When rules are specified, container MUST set RestartPolicy explicitly
# even it if matches the Pod's RestartPolicy.
restartPolicyRules: # optional, listType: atomic
- # Specifies the action taken on a container exit if the requirements are
# satisfied. The only possible value is "Restart" to restart the container.
action: "<string>" # required
# Represents the exit codes to check on container exits.
exitCodes: # optional
# Represents the relationship between the container exit code(s) and the
# specified values. Possible values are: - In: the requirement is satisfied if
# the container exit code is in the set of specified values. - NotIn: the
# requirement is satisfied if the container exit code is not in the set of
# specified values.
operator: "<string>" # required
# Specifies the set of values to check for container exit codes. At most 255
# elements are allowed.
# values: # listType: set
# - <int32>
# SecurityContext defines the security options the container should be run with. If
# set, the fields of SecurityContext override the equivalent fields of
# PodSecurityContext. More info:
# https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
securityContext: # optional
# AllowPrivilegeEscalation controls whether a process can gain more privileges than
# its parent process. This bool directly controls if the no_new_privs flag will be
# set on the container process. AllowPrivilegeEscalation is true always when the
# container is: 1) run as Privileged 2) has CAP_SYS_ADMIN Note that this field
# cannot be set when spec.os.name is windows.
# allowPrivilegeEscalation: <boolean>
# appArmorProfile is the AppArmor options to use by this container. If set, this
# profile overrides the pod's appArmorProfile. Note that this field cannot be set
# when spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options
# are: Localhost - a profile pre-loaded on the node. RuntimeDefault - the
# container runtime's default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of
# the profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# The capabilities to add/drop when running containers. Defaults to the default set
# of capabilities granted by the container runtime. Note that this field cannot be
# set when spec.os.name is windows.
# capabilities:
# Added capabilities
# add: # listType: atomic
# - "<string>"
# Removed capabilities
# drop: # listType: atomic
# - "<string>"
# Run container in privileged mode. Processes in privileged containers are
# essentially equivalent to root on the host. Defaults to false. Note that this
# field cannot be set when spec.os.name is windows.
# privileged: <boolean>
# procMount denotes the type of proc mount to use for the containers. The default
# value is Default which uses the container runtime defaults for readonly paths and
# masked paths. This requires the ProcMountType feature flag to be enabled. Note
# that this field cannot be set when spec.os.name is windows.
# procMount: "<string>"
# Whether this container has a read-only root filesystem. Default is false. Note
# that this field cannot be set when spec.os.name is windows.
# readOnlyRootFilesystem: <boolean>
# The GID to run the entrypoint of the container process. Uses runtime default if
# unset. May also be set in PodSecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet
# will validate the image at runtime to ensure that it does not run as UID 0 (root)
# and fail to start the container if it does. If unset or false, no such validation
# will be performed. May also be set in PodSecurityContext. If set in both
# SecurityContext and PodSecurityContext, the value specified in SecurityContext
# takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified
# in image metadata if unspecified. May also be set in PodSecurityContext. If set in
# both SecurityContext and PodSecurityContext, the value specified in
# SecurityContext takes precedence. Note that this field cannot be set when
# spec.os.name is windows.
# runAsUser: <int64>
# The SELinux context to be applied to the container. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set
# in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence. Note that this field cannot
# be set when spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by this container. If seccomp options are provided at
# both the pod & container level, the container options override the pod options.
# Note that this field cannot be set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used.
# RuntimeDefault - the container runtime default profile should be used.
# Unconfined - no profile should be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be
# used. The profile must be preconfigured on the node to work. Must be a
# descending path, relative to the kubelet's configured seccomp profile location.
# Must be set if type is "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# The Windows specific settings applied to all containers. If unspecified, the
# options from the PodSecurityContext will be used. If set in both SecurityContext
# and PodSecurityContext, the value specified in SecurityContext takes precedence.
# Note that this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the
# GMSA credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process'
# container. All of a Pod's containers must have the same effective HostProcess
# value (it is not allowed to have a mix of HostProcess containers and
# non-HostProcess containers). In addition, if HostProcess is true then
# HostNetwork must also be set to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults
# to the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# StartupProbe indicates that the Pod has successfully initialized. If specified, no
# other probes are executed until this completes successfully. If this probe fails,
# the Pod will be restarted, just as if the livenessProbe failed. This can be used to
# provide different probe parameters at the beginning of a Pod's lifecycle, when it
# might take a long time to load data or warm a cache, than during steady-state
# operation. This cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
startupProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Whether this container should allocate a buffer for stdin in the container runtime.
# If this is not set, reads from stdin in the container will always result in EOF.
# Default is false.
# stdin: <boolean>
# Whether the container runtime should close the stdin channel after it has been
# opened by a single attach. When stdin is true the stdin stream will remain open
# across multiple attach sessions. If stdinOnce is set to true, stdin is opened on
# container start, is empty until the first client attaches to stdin, and then remains
# open and accepts data until the client disconnects, at which time stdin is closed
# and remains closed until the container is restarted. If this flag is false, a
# container processes that reads from stdin will never receive an EOF. Default is
# false
# stdinOnce: <boolean>
# Optional: Path at which the file to which the container's termination message will
# be written is mounted into the container's filesystem. Message written is intended
# to be brief final status, such as an assertion failure message. Will be truncated by
# the node if greater than 4096 bytes. The total message length across all containers
# will be limited to 12kb. Defaults to /dev/termination-log. Cannot be updated.
# terminationMessagePath: "<string>"
# Indicate how the termination message should be populated. File will use the contents
# of terminationMessagePath to populate the container status message on both success
# and failure. FallbackToLogsOnError will use the last chunk of container log output
# if the termination message file is empty and the container exited with an error. The
# log output is limited to 2048 bytes or 80 lines, whichever is smaller. Defaults to
# File. Cannot be updated.
# terminationMessagePolicy: "<string>"
# Whether this container should allocate a TTY for itself, also requires 'stdin' to be
# true. Default is false.
# tty: <boolean>
# volumeDevices is the list of block devices to be used by the container.
volumeDevices: # optional, listType: map, listMapKeys: devicePath
- # devicePath is the path inside of the container that the device will be mapped
# to.
devicePath: "<string>" # required
# name must match the name of a persistentVolumeClaim in the pod
name: "<string>" # required
# Pod volumes to mount into the container's filesystem. Cannot be updated.
volumeMounts: # optional, listType: map, listMapKeys: mountPath
- # Path within the container at which the volume should be mounted. Must not
# contain ':'.
mountPath: "<string>" # required
# This must match the Name of a Volume.
name: "<string>" # required
# mountPropagation determines how mounts are propagated from the host to container
# and the other way around. When not set, MountPropagationNone is used. This field
# is beta in 1.10. When RecursiveReadOnly is set to IfPossible or to Enabled,
# MountPropagation must be None or unspecified (which defaults to None).
# mountPropagation: "<string>"
# Mounted read-only if true, read-write otherwise (false or unspecified). Defaults
# to false.
# readOnly: <boolean>
# RecursiveReadOnly specifies whether read-only mounts should be handled
# recursively.
#
# If ReadOnly is false, this field has no meaning and must be unspecified.
#
# If ReadOnly is true, and this field is set to Disabled, the mount is not made
# recursively read-only. If this field is set to IfPossible, the mount is made
# recursively read-only, if it is supported by the container runtime. If this
# field is set to Enabled, the mount is made recursively read-only if it is
# supported by the container runtime, otherwise the pod will not be started and an
# error will be generated to indicate the reason.
#
# If this field is set to IfPossible or Enabled, MountPropagation must be set to
# None (or be unspecified, which defaults to None).
#
# If this field is not specified, it is treated as an equivalent of Disabled.
# recursiveReadOnly: "<string>"
# Path within the volume from which the container's volume should be mounted.
# Defaults to "" (volume's root).
# subPath: "<string>"
# Expanded path within the volume from which the container's volume should be
# mounted. Behaves similarly to SubPath but environment variable references
# $(VAR_NAME) are expanded using the container's environment. Defaults to ""
# (volume's root). SubPathExpr and SubPath are mutually exclusive.
# subPathExpr: "<string>"
# Container's working directory. If not specified, the container runtime's default
# will be used, which might be configured in the container image. Cannot be updated.
# workingDir: "<string>"
# Optional duration in seconds the pod may be active on the node relative to StartTime
# before the system will actively try to mark it failed and kill associated containers.
# Value must be a positive integer.
# activeDeadlineSeconds: <int64>
# If specified, the pod's scheduling constraints
affinity: # optional
# Describes node affinity scheduling rules for the pod.
nodeAffinity: # optional
# The scheduler will prefer to schedule pods to nodes that satisfy the affinity
# expressions specified by this field, but it may choose a node that violates one or
# more of the expressions. The node that is most preferred is the one with the
# greatest sum of weights, i.e. for each node that meets all of the scheduling
# requirements (resource request, requiredDuringScheduling affinity expressions,
# etc.), compute a sum by iterating through the elements of this field and adding
# "weight" to the sum if the node matches the corresponding matchExpressions; the
# node(s) with the highest sum are the most preferred.
preferredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # A node selector term, associated with the corresponding weight.
preference: # required, mapType: atomic
# A list of node selector requirements by node's labels.
matchExpressions: # optional, listType: atomic
- # The label key that the selector applies to.
key: "<string>" # required
# Represents a key's relationship to a set of values. Valid operators are
# In, NotIn, Exists, DoesNotExist. Gt, and Lt.
operator: "<string>" # required
# An array of string values. If the operator is In or NotIn, the values
# array must be non-empty. If the operator is Exists or DoesNotExist, the
# values array must be empty. If the operator is Gt or Lt, the values array
# must have a single element, which will be interpreted as an integer. This
# array is replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# A list of node selector requirements by node's fields.
matchFields: # optional, listType: atomic
- # The label key that the selector applies to.
key: "<string>" # required
# Represents a key's relationship to a set of values. Valid operators are
# In, NotIn, Exists, DoesNotExist. Gt, and Lt.
operator: "<string>" # required
# An array of string values. If the operator is In or NotIn, the values
# array must be non-empty. If the operator is Exists or DoesNotExist, the
# values array must be empty. If the operator is Gt or Lt, the values array
# must have a single element, which will be interpreted as an integer. This
# array is replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# Weight associated with matching the corresponding nodeSelectorTerm, in the range
# 1-100.
weight: <int32> # required
# If the affinity requirements specified by this field are not met at scheduling time,
# the pod will not be scheduled onto the node. If the affinity requirements specified
# by this field cease to be met at some point during pod execution (e.g. due to an
# update), the system may or may not try to eventually evict the pod from its node.
requiredDuringSchedulingIgnoredDuringExecution: # optional, mapType: atomic
# Required. A list of node selector terms. The terms are ORed.
nodeSelectorTerms: # required, listType: atomic
- # A list of node selector requirements by node's labels.
matchExpressions: # optional, listType: atomic
- # The label key that the selector applies to.
key: "<string>" # required
# Represents a key's relationship to a set of values. Valid operators are
# In, NotIn, Exists, DoesNotExist. Gt, and Lt.
operator: "<string>" # required
# An array of string values. If the operator is In or NotIn, the values
# array must be non-empty. If the operator is Exists or DoesNotExist, the
# values array must be empty. If the operator is Gt or Lt, the values array
# must have a single element, which will be interpreted as an integer. This
# array is replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# A list of node selector requirements by node's fields.
matchFields: # optional, listType: atomic
- # The label key that the selector applies to.
key: "<string>" # required
# Represents a key's relationship to a set of values. Valid operators are
# In, NotIn, Exists, DoesNotExist. Gt, and Lt.
operator: "<string>" # required
# An array of string values. If the operator is In or NotIn, the values
# array must be non-empty. If the operator is Exists or DoesNotExist, the
# values array must be empty. If the operator is Gt or Lt, the values array
# must have a single element, which will be interpreted as an integer. This
# array is replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# Describes pod affinity scheduling rules (e.g. co-locate this pod in the same node,
# zone, etc. as some other pod(s)).
podAffinity: # optional
# The scheduler will prefer to schedule pods to nodes that satisfy the affinity
# expressions specified by this field, but it may choose a node that violates one or
# more of the expressions. The node that is most preferred is the one with the
# greatest sum of weights, i.e. for each node that meets all of the scheduling
# requirements (resource request, requiredDuringScheduling affinity expressions,
# etc.), compute a sum by iterating through the elements of this field and adding
# "weight" to the sum if the node has pods which matches the corresponding
# podAffinityTerm; the node(s) with the highest sum are the most preferred.
preferredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # Required. A pod affinity term, associated with the corresponding weight.
podAffinityTerm: # required
# This pod should be co-located (affinity) or not co-located (anti-affinity)
# with the pods matching the labelSelector in the specified namespaces, where
# co-located is defined as running on a node whose value of the label with key
# topologyKey matches that of any node on which any of the selected pods is
# running. Empty topologyKey is not allowed.
topologyKey: "<string>" # required
# A label query over a set of resources, in this case pods. If it's null, this
# PodAffinityTerm matches with no Pods.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or
# DoesNotExist, the values array must be empty. This array is replaced
# during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key in
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't
# exist in the incoming pod labels will be ignored. The default value is empty.
# The same key is forbidden to exist in both matchLabelKeys and labelSelector.
# Also, matchLabelKeys cannot be set when labelSelector isn't set.
# matchLabelKeys: # listType: atomic
# - "<string>"
# MismatchLabelKeys is a set of pod label keys to select which pods will be
# taken into consideration. The keys are used to lookup values from the incoming
# pod labels, those key-value labels are merged with `labelSelector` as `key
# notin (value)` to select the group of existing pods which pods will be taken
# into consideration for the incoming pod's pod (anti) affinity. Keys that don't
# exist in the incoming pod labels will be ignored. The default value is empty.
# The same key is forbidden to exist in both mismatchLabelKeys and
# labelSelector. Also, mismatchLabelKeys cannot be set when labelSelector isn't
# set.
# mismatchLabelKeys: # listType: atomic
# - "<string>"
# A label query over the set of namespaces that the term applies to. The term is
# applied to the union of the namespaces selected by this field and the ones
# listed in the namespaces field. null selector and null or empty namespaces
# list means "this pod's namespace". An empty selector ({}) matches all
# namespaces.
namespaceSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or
# DoesNotExist, the values array must be empty. This array is replaced
# during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# namespaces specifies a static list of namespace names that the term applies
# to. The term is applied to the union of the namespaces listed in this field
# and the ones selected by namespaceSelector. null or empty namespaces list and
# null namespaceSelector means "this pod's namespace".
# namespaces: # listType: atomic
# - "<string>"
# weight associated with matching the corresponding podAffinityTerm, in the range
# 1-100.
weight: <int32> # required
# If the affinity requirements specified by this field are not met at scheduling time,
# the pod will not be scheduled onto the node. If the affinity requirements specified
# by this field cease to be met at some point during pod execution (e.g. due to a pod
# label update), the system may or may not try to eventually evict the pod from its
# node. When there are multiple elements, the lists of nodes corresponding to each
# podAffinityTerm are intersected, i.e. all terms must be satisfied.
requiredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # This pod should be co-located (affinity) or not co-located (anti-affinity) with
# the pods matching the labelSelector in the specified namespaces, where
# co-located is defined as running on a node whose value of the label with key
# topologyKey matches that of any node on which any of the selected pods is
# running. Empty topologyKey is not allowed.
topologyKey: "<string>" # required
# A label query over a set of resources, in this case pods. If it's null, this
# PodAffinityTerm matches with no Pods.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key in
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist
# in the incoming pod labels will be ignored. The default value is empty. The same
# key is forbidden to exist in both matchLabelKeys and labelSelector. Also,
# matchLabelKeys cannot be set when labelSelector isn't set.
# matchLabelKeys: # listType: atomic
# - "<string>"
# MismatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key notin
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist
# in the incoming pod labels will be ignored. The default value is empty. The same
# key is forbidden to exist in both mismatchLabelKeys and labelSelector. Also,
# mismatchLabelKeys cannot be set when labelSelector isn't set.
# mismatchLabelKeys: # listType: atomic
# - "<string>"
# A label query over the set of namespaces that the term applies to. The term is
# applied to the union of the namespaces selected by this field and the ones
# listed in the namespaces field. null selector and null or empty namespaces list
# means "this pod's namespace". An empty selector ({}) matches all namespaces.
namespaceSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# namespaces specifies a static list of namespace names that the term applies to.
# The term is applied to the union of the namespaces listed in this field and the
# ones selected by namespaceSelector. null or empty namespaces list and null
# namespaceSelector means "this pod's namespace".
# namespaces: # listType: atomic
# - "<string>"
# Describes pod anti-affinity scheduling rules (e.g. avoid putting this pod in the same
# node, zone, etc. as some other pod(s)).
podAntiAffinity: # optional
# The scheduler will prefer to schedule pods to nodes that satisfy the anti-affinity
# expressions specified by this field, but it may choose a node that violates one or
# more of the expressions. The node that is most preferred is the one with the
# greatest sum of weights, i.e. for each node that meets all of the scheduling
# requirements (resource request, requiredDuringScheduling anti-affinity expressions,
# etc.), compute a sum by iterating through the elements of this field and subtracting
# "weight" from the sum if the node has pods which matches the corresponding
# podAffinityTerm; the node(s) with the highest sum are the most preferred.
preferredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # Required. A pod affinity term, associated with the corresponding weight.
podAffinityTerm: # required
# This pod should be co-located (affinity) or not co-located (anti-affinity)
# with the pods matching the labelSelector in the specified namespaces, where
# co-located is defined as running on a node whose value of the label with key
# topologyKey matches that of any node on which any of the selected pods is
# running. Empty topologyKey is not allowed.
topologyKey: "<string>" # required
# A label query over a set of resources, in this case pods. If it's null, this
# PodAffinityTerm matches with no Pods.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or
# DoesNotExist, the values array must be empty. This array is replaced
# during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key in
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't
# exist in the incoming pod labels will be ignored. The default value is empty.
# The same key is forbidden to exist in both matchLabelKeys and labelSelector.
# Also, matchLabelKeys cannot be set when labelSelector isn't set.
# matchLabelKeys: # listType: atomic
# - "<string>"
# MismatchLabelKeys is a set of pod label keys to select which pods will be
# taken into consideration. The keys are used to lookup values from the incoming
# pod labels, those key-value labels are merged with `labelSelector` as `key
# notin (value)` to select the group of existing pods which pods will be taken
# into consideration for the incoming pod's pod (anti) affinity. Keys that don't
# exist in the incoming pod labels will be ignored. The default value is empty.
# The same key is forbidden to exist in both mismatchLabelKeys and
# labelSelector. Also, mismatchLabelKeys cannot be set when labelSelector isn't
# set.
# mismatchLabelKeys: # listType: atomic
# - "<string>"
# A label query over the set of namespaces that the term applies to. The term is
# applied to the union of the namespaces selected by this field and the ones
# listed in the namespaces field. null selector and null or empty namespaces
# list means "this pod's namespace". An empty selector ({}) matches all
# namespaces.
namespaceSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or
# DoesNotExist, the values array must be empty. This array is replaced
# during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# namespaces specifies a static list of namespace names that the term applies
# to. The term is applied to the union of the namespaces listed in this field
# and the ones selected by namespaceSelector. null or empty namespaces list and
# null namespaceSelector means "this pod's namespace".
# namespaces: # listType: atomic
# - "<string>"
# weight associated with matching the corresponding podAffinityTerm, in the range
# 1-100.
weight: <int32> # required
# If the anti-affinity requirements specified by this field are not met at scheduling
# time, the pod will not be scheduled onto the node. If the anti-affinity requirements
# specified by this field cease to be met at some point during pod execution (e.g. due
# to a pod label update), the system may or may not try to eventually evict the pod
# from its node. When there are multiple elements, the lists of nodes corresponding to
# each podAffinityTerm are intersected, i.e. all terms must be satisfied.
requiredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # This pod should be co-located (affinity) or not co-located (anti-affinity) with
# the pods matching the labelSelector in the specified namespaces, where
# co-located is defined as running on a node whose value of the label with key
# topologyKey matches that of any node on which any of the selected pods is
# running. Empty topologyKey is not allowed.
topologyKey: "<string>" # required
# A label query over a set of resources, in this case pods. If it's null, this
# PodAffinityTerm matches with no Pods.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key in
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist
# in the incoming pod labels will be ignored. The default value is empty. The same
# key is forbidden to exist in both matchLabelKeys and labelSelector. Also,
# matchLabelKeys cannot be set when labelSelector isn't set.
# matchLabelKeys: # listType: atomic
# - "<string>"
# MismatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key notin
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist
# in the incoming pod labels will be ignored. The default value is empty. The same
# key is forbidden to exist in both mismatchLabelKeys and labelSelector. Also,
# mismatchLabelKeys cannot be set when labelSelector isn't set.
# mismatchLabelKeys: # listType: atomic
# - "<string>"
# A label query over the set of namespaces that the term applies to. The term is
# applied to the union of the namespaces selected by this field and the ones
# listed in the namespaces field. null selector and null or empty namespaces list
# means "this pod's namespace". An empty selector ({}) matches all namespaces.
namespaceSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# namespaces specifies a static list of namespace names that the term applies to.
# The term is applied to the union of the namespaces listed in this field and the
# ones selected by namespaceSelector. null or empty namespaces list and null
# namespaceSelector means "this pod's namespace".
# namespaces: # listType: atomic
# - "<string>"
# AutomountServiceAccountToken indicates whether a service account token should be
# automatically mounted.
# automountServiceAccountToken: <boolean>
# Specifies the DNS parameters of a pod. Parameters specified here will be merged to the
# generated DNS configuration based on DNSPolicy.
# dnsConfig:
# A list of DNS name server IP addresses. This will be appended to the base nameservers
# generated from DNSPolicy. Duplicated nameservers will be removed.
# nameservers: # listType: atomic
# - "<string>"
# A list of DNS resolver options. This will be merged with the base options generated
# from DNSPolicy. Duplicated entries will be removed. Resolution options given in
# Options will override those that appear in the base DNSPolicy.
# options: # listType: atomic
# - # Name is this DNS resolver option's name. Required.
# name: "<string>"
# Value is this DNS resolver option's value.
# value: "<string>"
# A list of DNS search domains for host-name lookup. This will be appended to the base
# search paths generated from DNSPolicy. Duplicated search paths will be removed.
# searches: # listType: atomic
# - "<string>"
# Set DNS policy for the pod. Defaults to "ClusterFirst". Valid values are
# 'ClusterFirstWithHostNet', 'ClusterFirst', 'Default' or 'None'. DNS parameters given in
# DNSConfig will be merged with the policy selected with DNSPolicy. To have DNS options
# set along with hostNetwork, you have to specify DNS policy explicitly to
# 'ClusterFirstWithHostNet'.
# dnsPolicy: "<string>"
# EnableServiceLinks indicates whether information about services should be injected into
# pod's environment variables, matching the syntax of Docker links. Optional: Defaults to
# true.
# enableServiceLinks: <boolean>
# List of ephemeral containers run in this pod. Ephemeral containers may be run in an
# existing pod to perform user-initiated actions such as debugging. This list cannot be
# specified when creating a pod, and it cannot be modified by updating the pod spec. In
# order to add an ephemeral container to an existing pod, use the pod's
# ephemeralcontainers subresource.
ephemeralContainers: # optional, listType: map, listMapKeys: name
- # Name of the ephemeral container specified as a DNS_LABEL. This name must be unique
# among all containers, init containers and ephemeral containers.
name: "<string>" # required
# Arguments to the entrypoint. The image's CMD is used if this is not provided.
# Variable references $(VAR_NAME) are expanded using the container's environment. If a
# variable cannot be resolved, the reference in the input string will be unchanged.
# Double $$ are reduced to a single $, which allows for escaping the $(VAR_NAME)
# syntax: i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped
# references will never be expanded, regardless of whether the variable exists or not.
# Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# args: # listType: atomic
# - "<string>"
# Entrypoint array. Not executed within a shell. The image's ENTRYPOINT is used if
# this is not provided. Variable references $(VAR_NAME) are expanded using the
# container's environment. If a variable cannot be resolved, the reference in the
# input string will be unchanged. Double $$ are reduced to a single $, which allows
# for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string
# literal "$(VAR_NAME)". Escaped references will never be expanded, regardless of
# whether the variable exists or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# command: # listType: atomic
# - "<string>"
# List of environment variables to set in the container. Cannot be updated.
env: # optional, listType: map, listMapKeys: name
- # Name of the environment variable. May consist of any printable ASCII characters
# except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined
# environment variables in the container and any service environment variables. If
# a variable cannot be resolved, the reference in the input string will be
# unchanged. Double $$ are reduced to a single $, which allows for escaping the
# $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal
# "$(VAR_NAME)". Escaped references will never be expanded, regardless of whether
# the variable exists or not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not
# empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to
# backwards compatibility is allowed to be empty. Instances of this type with
# an empty value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to
# "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate
# to be enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from
# starting. The keys defined within a source may consist of any printable
# ASCII characters except '='. During Alpha stage of the EnvFiles feature
# gate, the key size is limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative
# and may not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does
# not exist, then the env var is not published. If optional is set to true and
# the specified key does not exist, the environment variable will not be set
# in the Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error
# will be returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
# requests.memory and requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to
# backwards compatibility is allowed to be empty. Instances of this type with
# an empty value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# List of sources to populate environment variables in the container. The keys defined
# within a source may consist of any printable ASCII characters except '='. When a key
# exists in multiple sources, the value associated with the last source will take
# precedence. Values defined by an Env with a duplicate key will take precedence.
# Cannot be updated.
# envFrom: # listType: atomic
# - # The ConfigMap to select from
# configMapRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap must be defined
# optional: <boolean>
# Optional text to prepend to the name of each environment variable. May consist
# of any printable ASCII characters except '='.
# prefix: "<string>"
# The Secret to select from
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret must be defined
# optional: <boolean>
# Container image name. More info:
# https://kubernetes.io/docs/concepts/containers/images
# image: "<string>"
# Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if :latest
# tag is specified, or IfNotPresent otherwise. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/containers/images#updating-images
# imagePullPolicy: "<string>"
# Lifecycle is not allowed for ephemeral containers.
lifecycle: # optional
# PostStart is called immediately after a container is created. If the handler
# fails, the container is terminated and restarted according to its restart policy.
# Other management of the container blocks until the hook completes. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
postStart: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly
# call out to that shell. Exit status of 0 is treated as live/healthy and
# non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set
# "Host" in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for
# backward compatibility. There is no validation of this field and lifecycle hooks
# will fail at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# PreStop is called immediately before a container is terminated due to an API
# request or management event such as liveness/startup probe failure, preemption,
# resource contention, etc. The handler is not called if the container crashes or
# exits. The Pod's termination grace period countdown begins before the PreStop hook
# is executed. Regardless of the outcome of the handler, the container will
# eventually terminate within the Pod's termination grace period (unless delayed by
# finalizers). Other management of the container blocks until the hook completes or
# until the termination grace period is reached. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
preStop: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly
# call out to that shell. Exit status of 0 is treated as live/healthy and
# non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set
# "Host" in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for
# backward compatibility. There is no validation of this field and lifecycle hooks
# will fail at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# StopSignal defines which signal will be sent to a container when it is being
# stopped. If not specified, the default is defined by the container runtime in use.
# StopSignal can only be set for Pods with a non-empty .spec.os.name
# stopSignal: "<string>"
# Probes are not allowed for ephemeral containers.
livenessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Ports are not allowed for ephemeral containers.
ports: # optional, listType: map, listMapKeys: containerPort, protocol
- # Number of port to expose on the pod's IP address. This must be a valid port
# number, 0 < x < 65536.
containerPort: <int32> # required
# What host IP to bind the external port to.
# hostIP: "<string>"
# Number of port to expose on the host. If specified, this must be a valid port
# number, 0 < x < 65536. If HostNetwork is specified, this must match
# ContainerPort. Most containers do not need this.
# hostPort: <int32>
# If specified, this must be an IANA_SVC_NAME and unique within the pod. Each
# named port in a pod must have a unique name. Name for the port that can be
# referred to by services.
# name: "<string>"
# Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
# protocol: "TCP" # default
# Probes are not allowed for ephemeral containers.
readinessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Resources resize policy for the container.
resizePolicy: # optional, listType: atomic
- # Name of the resource to which this resource resize policy applies. Supported
# values: cpu, memory.
resourceName: "<string>" # required
# Restart policy to apply when specified resource is resized. If not specified, it
# defaults to NotRequired.
restartPolicy: "<string>" # required
# Resources are not allowed for ephemeral containers. Ephemeral containers use spare
# resources already allocated to the pod.
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used
# by this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod
# where this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests
# is omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More
# info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# Restart policy for the container to manage the restart behavior of each container
# within a pod. You cannot set this field on ephemeral containers.
# restartPolicy: "<string>"
# Represents a list of rules to be checked to determine if the container should be
# restarted on exit. You cannot set this field on ephemeral containers.
restartPolicyRules: # optional, listType: atomic
- # Specifies the action taken on a container exit if the requirements are
# satisfied. The only possible value is "Restart" to restart the container.
action: "<string>" # required
# Represents the exit codes to check on container exits.
exitCodes: # optional
# Represents the relationship between the container exit code(s) and the
# specified values. Possible values are: - In: the requirement is satisfied if
# the container exit code is in the set of specified values. - NotIn: the
# requirement is satisfied if the container exit code is not in the set of
# specified values.
operator: "<string>" # required
# Specifies the set of values to check for container exit codes. At most 255
# elements are allowed.
# values: # listType: set
# - <int32>
# Optional: SecurityContext defines the security options the ephemeral container
# should be run with. If set, the fields of SecurityContext override the equivalent
# fields of PodSecurityContext.
securityContext: # optional
# AllowPrivilegeEscalation controls whether a process can gain more privileges than
# its parent process. This bool directly controls if the no_new_privs flag will be
# set on the container process. AllowPrivilegeEscalation is true always when the
# container is: 1) run as Privileged 2) has CAP_SYS_ADMIN Note that this field
# cannot be set when spec.os.name is windows.
# allowPrivilegeEscalation: <boolean>
# appArmorProfile is the AppArmor options to use by this container. If set, this
# profile overrides the pod's appArmorProfile. Note that this field cannot be set
# when spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options
# are: Localhost - a profile pre-loaded on the node. RuntimeDefault - the
# container runtime's default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of
# the profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# The capabilities to add/drop when running containers. Defaults to the default set
# of capabilities granted by the container runtime. Note that this field cannot be
# set when spec.os.name is windows.
# capabilities:
# Added capabilities
# add: # listType: atomic
# - "<string>"
# Removed capabilities
# drop: # listType: atomic
# - "<string>"
# Run container in privileged mode. Processes in privileged containers are
# essentially equivalent to root on the host. Defaults to false. Note that this
# field cannot be set when spec.os.name is windows.
# privileged: <boolean>
# procMount denotes the type of proc mount to use for the containers. The default
# value is Default which uses the container runtime defaults for readonly paths and
# masked paths. This requires the ProcMountType feature flag to be enabled. Note
# that this field cannot be set when spec.os.name is windows.
# procMount: "<string>"
# Whether this container has a read-only root filesystem. Default is false. Note
# that this field cannot be set when spec.os.name is windows.
# readOnlyRootFilesystem: <boolean>
# The GID to run the entrypoint of the container process. Uses runtime default if
# unset. May also be set in PodSecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet
# will validate the image at runtime to ensure that it does not run as UID 0 (root)
# and fail to start the container if it does. If unset or false, no such validation
# will be performed. May also be set in PodSecurityContext. If set in both
# SecurityContext and PodSecurityContext, the value specified in SecurityContext
# takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified
# in image metadata if unspecified. May also be set in PodSecurityContext. If set in
# both SecurityContext and PodSecurityContext, the value specified in
# SecurityContext takes precedence. Note that this field cannot be set when
# spec.os.name is windows.
# runAsUser: <int64>
# The SELinux context to be applied to the container. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set
# in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence. Note that this field cannot
# be set when spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by this container. If seccomp options are provided at
# both the pod & container level, the container options override the pod options.
# Note that this field cannot be set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used.
# RuntimeDefault - the container runtime default profile should be used.
# Unconfined - no profile should be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be
# used. The profile must be preconfigured on the node to work. Must be a
# descending path, relative to the kubelet's configured seccomp profile location.
# Must be set if type is "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# The Windows specific settings applied to all containers. If unspecified, the
# options from the PodSecurityContext will be used. If set in both SecurityContext
# and PodSecurityContext, the value specified in SecurityContext takes precedence.
# Note that this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the
# GMSA credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process'
# container. All of a Pod's containers must have the same effective HostProcess
# value (it is not allowed to have a mix of HostProcess containers and
# non-HostProcess containers). In addition, if HostProcess is true then
# HostNetwork must also be set to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults
# to the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# Probes are not allowed for ephemeral containers.
startupProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Whether this container should allocate a buffer for stdin in the container runtime.
# If this is not set, reads from stdin in the container will always result in EOF.
# Default is false.
# stdin: <boolean>
# Whether the container runtime should close the stdin channel after it has been
# opened by a single attach. When stdin is true the stdin stream will remain open
# across multiple attach sessions. If stdinOnce is set to true, stdin is opened on
# container start, is empty until the first client attaches to stdin, and then remains
# open and accepts data until the client disconnects, at which time stdin is closed
# and remains closed until the container is restarted. If this flag is false, a
# container processes that reads from stdin will never receive an EOF. Default is
# false
# stdinOnce: <boolean>
# If set, the name of the container from PodSpec that this ephemeral container
# targets. The ephemeral container will be run in the namespaces (IPC, PID, etc) of
# this container. If not set then the ephemeral container uses the namespaces
# configured in the Pod spec.
#
# The container runtime must implement support for this feature. If the runtime does
# not support namespace targeting then the result of setting this field is undefined.
# targetContainerName: "<string>"
# Optional: Path at which the file to which the container's termination message will
# be written is mounted into the container's filesystem. Message written is intended
# to be brief final status, such as an assertion failure message. Will be truncated by
# the node if greater than 4096 bytes. The total message length across all containers
# will be limited to 12kb. Defaults to /dev/termination-log. Cannot be updated.
# terminationMessagePath: "<string>"
# Indicate how the termination message should be populated. File will use the contents
# of terminationMessagePath to populate the container status message on both success
# and failure. FallbackToLogsOnError will use the last chunk of container log output
# if the termination message file is empty and the container exited with an error. The
# log output is limited to 2048 bytes or 80 lines, whichever is smaller. Defaults to
# File. Cannot be updated.
# terminationMessagePolicy: "<string>"
# Whether this container should allocate a TTY for itself, also requires 'stdin' to be
# true. Default is false.
# tty: <boolean>
# volumeDevices is the list of block devices to be used by the container.
volumeDevices: # optional, listType: map, listMapKeys: devicePath
- # devicePath is the path inside of the container that the device will be mapped
# to.
devicePath: "<string>" # required
# name must match the name of a persistentVolumeClaim in the pod
name: "<string>" # required
# Pod volumes to mount into the container's filesystem. Subpath mounts are not allowed
# for ephemeral containers. Cannot be updated.
volumeMounts: # optional, listType: map, listMapKeys: mountPath
- # Path within the container at which the volume should be mounted. Must not
# contain ':'.
mountPath: "<string>" # required
# This must match the Name of a Volume.
name: "<string>" # required
# mountPropagation determines how mounts are propagated from the host to container
# and the other way around. When not set, MountPropagationNone is used. This field
# is beta in 1.10. When RecursiveReadOnly is set to IfPossible or to Enabled,
# MountPropagation must be None or unspecified (which defaults to None).
# mountPropagation: "<string>"
# Mounted read-only if true, read-write otherwise (false or unspecified). Defaults
# to false.
# readOnly: <boolean>
# RecursiveReadOnly specifies whether read-only mounts should be handled
# recursively.
#
# If ReadOnly is false, this field has no meaning and must be unspecified.
#
# If ReadOnly is true, and this field is set to Disabled, the mount is not made
# recursively read-only. If this field is set to IfPossible, the mount is made
# recursively read-only, if it is supported by the container runtime. If this
# field is set to Enabled, the mount is made recursively read-only if it is
# supported by the container runtime, otherwise the pod will not be started and an
# error will be generated to indicate the reason.
#
# If this field is set to IfPossible or Enabled, MountPropagation must be set to
# None (or be unspecified, which defaults to None).
#
# If this field is not specified, it is treated as an equivalent of Disabled.
# recursiveReadOnly: "<string>"
# Path within the volume from which the container's volume should be mounted.
# Defaults to "" (volume's root).
# subPath: "<string>"
# Expanded path within the volume from which the container's volume should be
# mounted. Behaves similarly to SubPath but environment variable references
# $(VAR_NAME) are expanded using the container's environment. Defaults to ""
# (volume's root). SubPathExpr and SubPath are mutually exclusive.
# subPathExpr: "<string>"
# Container's working directory. If not specified, the container runtime's default
# will be used, which might be configured in the container image. Cannot be updated.
# workingDir: "<string>"
# HostAliases is an optional list of hosts and IPs that will be injected into the pod's
# hosts file if specified.
hostAliases: # optional, listType: map, listMapKeys: ip
- # IP address of the host file entry.
ip: "<string>" # required
# Hostnames for the above IP address.
# hostnames: # listType: atomic
# - "<string>"
# Use the host's ipc namespace. Optional: Default to false.
# hostIPC: <boolean>
# Host networking requested for this pod. Use the host's network namespace. When using
# HostNetwork you should specify ports so the scheduler is aware. When `hostNetwork` is
# true, specified `hostPort` fields in port definitions must match `containerPort`, and
# unspecified `hostPort` fields in port definitions are defaulted to match
# `containerPort`. Default to false.
# hostNetwork: <boolean>
# Use the host's pid namespace. Optional: Default to false.
# hostPID: <boolean>
# Use the host's user namespace. Optional: Default to true. If set to true or not present,
# the pod will be run in the host user namespace, useful for when the pod needs a feature
# only available to the host user namespace, such as loading a kernel module with
# CAP_SYS_MODULE. When set to false, a new userns is created for the pod. Setting false is
# useful for mitigating container breakout vulnerabilities even allowing users to run
# their containers as root without actually having root privileges on the host. This field
# is alpha-level and is only honored by servers that enable the UserNamespacesSupport
# feature.
# hostUsers: <boolean>
# Specifies the hostname of the Pod If not specified, the pod's hostname will be set to a
# system-defined value.
# hostname: "<string>"
# HostnameOverride specifies an explicit override for the pod's hostname as perceived by
# the pod. This field only specifies the pod's hostname and does not affect its DNS
# records. When this field is set to a non-empty string: - It takes precedence over the
# values set in `hostname` and `subdomain`. - The Pod's hostname will be set to this
# value. - `setHostnameAsFQDN` must be nil or set to false. - `hostNetwork` must be set to
# false.
#
# This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64
# characters. Requires the HostnameOverride feature gate to be enabled.
# hostnameOverride: "<string>"
# ImagePullSecrets is an optional list of references to secrets in the same namespace to
# use for pulling any of the images used by this PodSpec. If specified, these secrets will
# be passed to individual puller implementations for them to use. More info:
# https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod
# imagePullSecrets: # listType: map, listMapKeys: name
# - # Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# List of initialization containers belonging to the pod. Init containers are executed in
# order prior to containers being started. If any init container fails, the pod is
# considered to have failed and is handled according to its restartPolicy. The name for an
# init container or normal container must be unique among all containers. Init containers
# may not have Lifecycle actions, Readiness probes, Liveness probes, or Startup probes.
# The resourceRequirements of an init container are taken into account during scheduling
# by finding the highest request/limit for each resource type, and then using the max of
# that value or the sum of the normal containers. Limits are applied to init containers in
# a similar fashion. Init containers cannot currently be added or removed. Cannot be
# updated. More info: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/
initContainers: # optional, listType: map, listMapKeys: name
- # Name of the container specified as a DNS_LABEL. Each container in a pod must have a
# unique name (DNS_LABEL). Cannot be updated.
name: "<string>" # required
# Arguments to the entrypoint. The container image's CMD is used if this is not
# provided. Variable references $(VAR_NAME) are expanded using the container's
# environment. If a variable cannot be resolved, the reference in the input string
# will be unchanged. Double $$ are reduced to a single $, which allows for escaping
# the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal
# "$(VAR_NAME)". Escaped references will never be expanded, regardless of whether the
# variable exists or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# args: # listType: atomic
# - "<string>"
# Entrypoint array. Not executed within a shell. The container image's ENTRYPOINT is
# used if this is not provided. Variable references $(VAR_NAME) are expanded using the
# container's environment. If a variable cannot be resolved, the reference in the
# input string will be unchanged. Double $$ are reduced to a single $, which allows
# for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string
# literal "$(VAR_NAME)". Escaped references will never be expanded, regardless of
# whether the variable exists or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# command: # listType: atomic
# - "<string>"
# List of environment variables to set in the container. Cannot be updated.
env: # optional, listType: map, listMapKeys: name
- # Name of the environment variable. May consist of any printable ASCII characters
# except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined
# environment variables in the container and any service environment variables. If
# a variable cannot be resolved, the reference in the input string will be
# unchanged. Double $$ are reduced to a single $, which allows for escaping the
# $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal
# "$(VAR_NAME)". Escaped references will never be expanded, regardless of whether
# the variable exists or not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not
# empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to
# backwards compatibility is allowed to be empty. Instances of this type with
# an empty value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to
# "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate
# to be enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from
# starting. The keys defined within a source may consist of any printable
# ASCII characters except '='. During Alpha stage of the EnvFiles feature
# gate, the key size is limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative
# and may not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does
# not exist, then the env var is not published. If optional is set to true and
# the specified key does not exist, the environment variable will not be set
# in the Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error
# will be returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
# requests.memory and requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to
# backwards compatibility is allowed to be empty. Instances of this type with
# an empty value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# List of sources to populate environment variables in the container. The keys defined
# within a source may consist of any printable ASCII characters except '='. When a key
# exists in multiple sources, the value associated with the last source will take
# precedence. Values defined by an Env with a duplicate key will take precedence.
# Cannot be updated.
# envFrom: # listType: atomic
# - # The ConfigMap to select from
# configMapRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap must be defined
# optional: <boolean>
# Optional text to prepend to the name of each environment variable. May consist
# of any printable ASCII characters except '='.
# prefix: "<string>"
# The Secret to select from
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret must be defined
# optional: <boolean>
# Container image name. More info:
# https://kubernetes.io/docs/concepts/containers/images This field is optional to
# allow higher level config management to default or override container images in
# workload controllers like Deployments and StatefulSets.
# image: "<string>"
# Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if :latest
# tag is specified, or IfNotPresent otherwise. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/containers/images#updating-images
# imagePullPolicy: "<string>"
# Actions that the management system should take in response to container lifecycle
# events. Cannot be updated.
lifecycle: # optional
# PostStart is called immediately after a container is created. If the handler
# fails, the container is terminated and restarted according to its restart policy.
# Other management of the container blocks until the hook completes. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
postStart: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly
# call out to that shell. Exit status of 0 is treated as live/healthy and
# non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set
# "Host" in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for
# backward compatibility. There is no validation of this field and lifecycle hooks
# will fail at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# PreStop is called immediately before a container is terminated due to an API
# request or management event such as liveness/startup probe failure, preemption,
# resource contention, etc. The handler is not called if the container crashes or
# exits. The Pod's termination grace period countdown begins before the PreStop hook
# is executed. Regardless of the outcome of the handler, the container will
# eventually terminate within the Pod's termination grace period (unless delayed by
# finalizers). Other management of the container blocks until the hook completes or
# until the termination grace period is reached. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
preStop: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly
# call out to that shell. Exit status of 0 is treated as live/healthy and
# non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set
# "Host" in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for
# backward compatibility. There is no validation of this field and lifecycle hooks
# will fail at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# StopSignal defines which signal will be sent to a container when it is being
# stopped. If not specified, the default is defined by the container runtime in use.
# StopSignal can only be set for Pods with a non-empty .spec.os.name
# stopSignal: "<string>"
# Periodic probe of container liveness. Container will be restarted if the probe
# fails. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
livenessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# List of ports to expose from the container. Not specifying a port here DOES NOT
# prevent that port from being exposed. Any port which is listening on the default
# "0.0.0.0" address inside a container will be accessible from the network. Modifying
# this array with strategic merge patch may corrupt the data. For more information See
# https://github.com/kubernetes/kubernetes/issues/108255. Cannot be updated.
ports: # optional, listType: map, listMapKeys: containerPort, protocol
- # Number of port to expose on the pod's IP address. This must be a valid port
# number, 0 < x < 65536.
containerPort: <int32> # required
# What host IP to bind the external port to.
# hostIP: "<string>"
# Number of port to expose on the host. If specified, this must be a valid port
# number, 0 < x < 65536. If HostNetwork is specified, this must match
# ContainerPort. Most containers do not need this.
# hostPort: <int32>
# If specified, this must be an IANA_SVC_NAME and unique within the pod. Each
# named port in a pod must have a unique name. Name for the port that can be
# referred to by services.
# name: "<string>"
# Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
# protocol: "TCP" # default
# Periodic probe of container service readiness. Container will be removed from
# service endpoints if the probe fails. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
readinessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Resources resize policy for the container.
resizePolicy: # optional, listType: atomic
- # Name of the resource to which this resource resize policy applies. Supported
# values: cpu, memory.
resourceName: "<string>" # required
# Restart policy to apply when specified resource is resized. If not specified, it
# defaults to NotRequired.
restartPolicy: "<string>" # required
# Compute Resources required by this container. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used
# by this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod
# where this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests
# is omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More
# info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# RestartPolicy defines the restart behavior of individual containers in a pod. This
# overrides the pod-level restart policy. When this field is not specified, the
# restart behavior is defined by the Pod's restart policy and the container type.
# Additionally, setting the RestartPolicy as "Always" for the init container will have
# the following effect: this init container will be continually restarted on exit
# until all regular containers have terminated. Once all regular containers have
# completed, all init containers with restartPolicy "Always" will be shut down. This
# lifecycle differs from normal init containers and is often referred to as a
# "sidecar" container. Although this init container still starts in the init container
# sequence, it does not wait for the container to complete before proceeding to the
# next init container. Instead, the next init container starts immediately after this
# init container is started, or after any startupProbe has successfully completed.
# restartPolicy: "<string>"
# Represents a list of rules to be checked to determine if the container should be
# restarted on exit. The rules are evaluated in order. Once a rule matches a container
# exit condition, the remaining rules are ignored. If no rule matches the container
# exit condition, the Container-level restart policy determines the whether the
# container is restarted or not. Constraints on the rules: - At most 20 rules are
# allowed. - Rules can have the same action. - Identical rules are not forbidden in
# validations. When rules are specified, container MUST set RestartPolicy explicitly
# even it if matches the Pod's RestartPolicy.
restartPolicyRules: # optional, listType: atomic
- # Specifies the action taken on a container exit if the requirements are
# satisfied. The only possible value is "Restart" to restart the container.
action: "<string>" # required
# Represents the exit codes to check on container exits.
exitCodes: # optional
# Represents the relationship between the container exit code(s) and the
# specified values. Possible values are: - In: the requirement is satisfied if
# the container exit code is in the set of specified values. - NotIn: the
# requirement is satisfied if the container exit code is not in the set of
# specified values.
operator: "<string>" # required
# Specifies the set of values to check for container exit codes. At most 255
# elements are allowed.
# values: # listType: set
# - <int32>
# SecurityContext defines the security options the container should be run with. If
# set, the fields of SecurityContext override the equivalent fields of
# PodSecurityContext. More info:
# https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
securityContext: # optional
# AllowPrivilegeEscalation controls whether a process can gain more privileges than
# its parent process. This bool directly controls if the no_new_privs flag will be
# set on the container process. AllowPrivilegeEscalation is true always when the
# container is: 1) run as Privileged 2) has CAP_SYS_ADMIN Note that this field
# cannot be set when spec.os.name is windows.
# allowPrivilegeEscalation: <boolean>
# appArmorProfile is the AppArmor options to use by this container. If set, this
# profile overrides the pod's appArmorProfile. Note that this field cannot be set
# when spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options
# are: Localhost - a profile pre-loaded on the node. RuntimeDefault - the
# container runtime's default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of
# the profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# The capabilities to add/drop when running containers. Defaults to the default set
# of capabilities granted by the container runtime. Note that this field cannot be
# set when spec.os.name is windows.
# capabilities:
# Added capabilities
# add: # listType: atomic
# - "<string>"
# Removed capabilities
# drop: # listType: atomic
# - "<string>"
# Run container in privileged mode. Processes in privileged containers are
# essentially equivalent to root on the host. Defaults to false. Note that this
# field cannot be set when spec.os.name is windows.
# privileged: <boolean>
# procMount denotes the type of proc mount to use for the containers. The default
# value is Default which uses the container runtime defaults for readonly paths and
# masked paths. This requires the ProcMountType feature flag to be enabled. Note
# that this field cannot be set when spec.os.name is windows.
# procMount: "<string>"
# Whether this container has a read-only root filesystem. Default is false. Note
# that this field cannot be set when spec.os.name is windows.
# readOnlyRootFilesystem: <boolean>
# The GID to run the entrypoint of the container process. Uses runtime default if
# unset. May also be set in PodSecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet
# will validate the image at runtime to ensure that it does not run as UID 0 (root)
# and fail to start the container if it does. If unset or false, no such validation
# will be performed. May also be set in PodSecurityContext. If set in both
# SecurityContext and PodSecurityContext, the value specified in SecurityContext
# takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified
# in image metadata if unspecified. May also be set in PodSecurityContext. If set in
# both SecurityContext and PodSecurityContext, the value specified in
# SecurityContext takes precedence. Note that this field cannot be set when
# spec.os.name is windows.
# runAsUser: <int64>
# The SELinux context to be applied to the container. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set
# in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence. Note that this field cannot
# be set when spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by this container. If seccomp options are provided at
# both the pod & container level, the container options override the pod options.
# Note that this field cannot be set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used.
# RuntimeDefault - the container runtime default profile should be used.
# Unconfined - no profile should be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be
# used. The profile must be preconfigured on the node to work. Must be a
# descending path, relative to the kubelet's configured seccomp profile location.
# Must be set if type is "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# The Windows specific settings applied to all containers. If unspecified, the
# options from the PodSecurityContext will be used. If set in both SecurityContext
# and PodSecurityContext, the value specified in SecurityContext takes precedence.
# Note that this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the
# GMSA credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process'
# container. All of a Pod's containers must have the same effective HostProcess
# value (it is not allowed to have a mix of HostProcess containers and
# non-HostProcess containers). In addition, if HostProcess is true then
# HostNetwork must also be set to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults
# to the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# StartupProbe indicates that the Pod has successfully initialized. If specified, no
# other probes are executed until this completes successfully. If this probe fails,
# the Pod will be restarted, just as if the livenessProbe failed. This can be used to
# provide different probe parameters at the beginning of a Pod's lifecycle, when it
# might take a long time to load data or warm a cache, than during steady-state
# operation. This cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
startupProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value
# is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after
# having failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is
# 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running
# in the pod are sent a termination signal and the time when the processes are
# forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. If this value is nil, the pod's
# terminationGracePeriodSeconds will be used. Otherwise, this value overrides the
# value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This
# is a beta field and requires enabling ProbeTerminationGracePeriod feature gate.
# Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Whether this container should allocate a buffer for stdin in the container runtime.
# If this is not set, reads from stdin in the container will always result in EOF.
# Default is false.
# stdin: <boolean>
# Whether the container runtime should close the stdin channel after it has been
# opened by a single attach. When stdin is true the stdin stream will remain open
# across multiple attach sessions. If stdinOnce is set to true, stdin is opened on
# container start, is empty until the first client attaches to stdin, and then remains
# open and accepts data until the client disconnects, at which time stdin is closed
# and remains closed until the container is restarted. If this flag is false, a
# container processes that reads from stdin will never receive an EOF. Default is
# false
# stdinOnce: <boolean>
# Optional: Path at which the file to which the container's termination message will
# be written is mounted into the container's filesystem. Message written is intended
# to be brief final status, such as an assertion failure message. Will be truncated by
# the node if greater than 4096 bytes. The total message length across all containers
# will be limited to 12kb. Defaults to /dev/termination-log. Cannot be updated.
# terminationMessagePath: "<string>"
# Indicate how the termination message should be populated. File will use the contents
# of terminationMessagePath to populate the container status message on both success
# and failure. FallbackToLogsOnError will use the last chunk of container log output
# if the termination message file is empty and the container exited with an error. The
# log output is limited to 2048 bytes or 80 lines, whichever is smaller. Defaults to
# File. Cannot be updated.
# terminationMessagePolicy: "<string>"
# Whether this container should allocate a TTY for itself, also requires 'stdin' to be
# true. Default is false.
# tty: <boolean>
# volumeDevices is the list of block devices to be used by the container.
volumeDevices: # optional, listType: map, listMapKeys: devicePath
- # devicePath is the path inside of the container that the device will be mapped
# to.
devicePath: "<string>" # required
# name must match the name of a persistentVolumeClaim in the pod
name: "<string>" # required
# Pod volumes to mount into the container's filesystem. Cannot be updated.
volumeMounts: # optional, listType: map, listMapKeys: mountPath
- # Path within the container at which the volume should be mounted. Must not
# contain ':'.
mountPath: "<string>" # required
# This must match the Name of a Volume.
name: "<string>" # required
# mountPropagation determines how mounts are propagated from the host to container
# and the other way around. When not set, MountPropagationNone is used. This field
# is beta in 1.10. When RecursiveReadOnly is set to IfPossible or to Enabled,
# MountPropagation must be None or unspecified (which defaults to None).
# mountPropagation: "<string>"
# Mounted read-only if true, read-write otherwise (false or unspecified). Defaults
# to false.
# readOnly: <boolean>
# RecursiveReadOnly specifies whether read-only mounts should be handled
# recursively.
#
# If ReadOnly is false, this field has no meaning and must be unspecified.
#
# If ReadOnly is true, and this field is set to Disabled, the mount is not made
# recursively read-only. If this field is set to IfPossible, the mount is made
# recursively read-only, if it is supported by the container runtime. If this
# field is set to Enabled, the mount is made recursively read-only if it is
# supported by the container runtime, otherwise the pod will not be started and an
# error will be generated to indicate the reason.
#
# If this field is set to IfPossible or Enabled, MountPropagation must be set to
# None (or be unspecified, which defaults to None).
#
# If this field is not specified, it is treated as an equivalent of Disabled.
# recursiveReadOnly: "<string>"
# Path within the volume from which the container's volume should be mounted.
# Defaults to "" (volume's root).
# subPath: "<string>"
# Expanded path within the volume from which the container's volume should be
# mounted. Behaves similarly to SubPath but environment variable references
# $(VAR_NAME) are expanded using the container's environment. Defaults to ""
# (volume's root). SubPathExpr and SubPath are mutually exclusive.
# subPathExpr: "<string>"
# Container's working directory. If not specified, the container runtime's default
# will be used, which might be configured in the container image. Cannot be updated.
# workingDir: "<string>"
# NodeName indicates in which node this pod is scheduled. If empty, this pod is a
# candidate for scheduling by the scheduler defined in schedulerName. Once this field is
# set, the kubelet for this node becomes responsible for the lifecycle of this pod. This
# field should not be used to express a desire for the pod to be scheduled on a specific
# node. https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodename
# nodeName: "<string>"
# NodeSelector is a selector which must be true for the pod to fit on a node. Selector
# which must match a node's labels for the pod to be scheduled on that node. More info:
# https://kubernetes.io/docs/concepts/configuration/assign-pod-node/
# nodeSelector: # mapType: atomic
# <key>: "<string>"
# Specifies the OS of the containers in the pod. Some pod and container fields are
# restricted if this is set.
#
# If the OS field is set to linux, the following fields must be unset:
# -securityContext.windowsOptions
#
# If the OS field is set to windows, following fields must be unset: - spec.hostPID -
# spec.hostIPC - spec.hostUsers - spec.resources - spec.securityContext.appArmorProfile -
# spec.securityContext.seLinuxOptions - spec.securityContext.seccompProfile -
# spec.securityContext.fsGroup - spec.securityContext.fsGroupChangePolicy -
# spec.securityContext.sysctls - spec.shareProcessNamespace -
# spec.securityContext.runAsUser - spec.securityContext.runAsGroup -
# spec.securityContext.supplementalGroups - spec.securityContext.supplementalGroupsPolicy
# - spec.containers[*].securityContext.appArmorProfile -
# spec.containers[*].securityContext.seLinuxOptions -
# spec.containers[*].securityContext.seccompProfile -
# spec.containers[*].securityContext.capabilities -
# spec.containers[*].securityContext.readOnlyRootFilesystem -
# spec.containers[*].securityContext.privileged -
# spec.containers[*].securityContext.allowPrivilegeEscalation -
# spec.containers[*].securityContext.procMount -
# spec.containers[*].securityContext.runAsUser -
# spec.containers[*].securityContext.runAsGroup
os: # optional
# Name is the name of the operating system. The currently supported values are linux and
# windows. Additional value may be defined in future and can be one of:
# https://github.com/opencontainers/runtime-spec/blob/master/config.md#platform-specific-configuration
# Clients should expect to handle additional values and treat unrecognized values in
# this field as os: null
name: "<string>" # required
# Overhead represents the resource overhead associated with running a pod for a given
# RuntimeClass. This field will be autopopulated at admission time by the RuntimeClass
# admission controller. If the RuntimeClass admission controller is enabled, overhead must
# not be set in Pod create requests. The RuntimeClass admission controller will reject Pod
# create requests which have the overhead already set. If RuntimeClass is configured and
# selected in the PodSpec, Overhead will be set to the value defined in the corresponding
# RuntimeClass, otherwise it will remain unset and treated as zero. More info:
# https://git.k8s.io/enhancements/keps/sig-node/688-pod-overhead/README.md
# overhead:
# <key>: <int-or-string> # intOrString
# PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never,
# PreemptLowerPriority. Defaults to PreemptLowerPriority if unset.
# preemptionPolicy: "<string>"
# The priority value. Various system components use this field to find the priority of the
# pod. When Priority Admission Controller is enabled, it prevents users from setting this
# field. The admission controller populates this field from PriorityClassName. The higher
# the value, the higher the priority.
# priority: <int32>
# If specified, indicates the pod's priority. "system-node-critical" and
# "system-cluster-critical" are two special keywords which indicate the highest priorities
# with the former being the highest priority. Any other name must be defined by creating a
# PriorityClass object with that name. If not specified, the pod priority will be default
# or zero if there is no default.
# priorityClassName: "<string>"
# If specified, all readiness gates will be evaluated for pod readiness. A pod is ready
# when all its containers are ready AND all conditions specified in the readiness gates
# have status equal to "True" More info:
# https://git.k8s.io/enhancements/keps/sig-network/580-pod-readiness-gates
readinessGates: # optional, listType: atomic
- # ConditionType refers to a condition in the pod's condition list with matching type.
conditionType: "<string>" # required
# ResourceClaims defines which ResourceClaims must be allocated and reserved before the
# Pod is allowed to start. The resources will be made available to those containers which
# consume them by name.
#
# This is an alpha field and requires enabling the DynamicResourceAllocation feature gate.
#
# This field is immutable.
resourceClaims: # optional, listType: map, listMapKeys: name
- # Name uniquely identifies this resource claim inside the pod. This must be a
# DNS_LABEL.
name: "<string>" # required
# ResourceClaimName is the name of a ResourceClaim object in the same namespace as
# this pod.
#
# Exactly one of ResourceClaimName and ResourceClaimTemplateName must be set.
# resourceClaimName: "<string>"
# ResourceClaimTemplateName is the name of a ResourceClaimTemplate object in the same
# namespace as this pod.
#
# The template will be used to create a new ResourceClaim, which will be bound to this
# pod. When this pod is deleted, the ResourceClaim will also be deleted. The pod name
# and resource name, along with a generated component, will be used to form a unique
# name for the ResourceClaim, which will be recorded in
# pod.status.resourceClaimStatuses.
#
# This field is immutable and no changes will be made to the corresponding
# ResourceClaim by the control plane after creating the ResourceClaim.
#
# Exactly one of ResourceClaimName and ResourceClaimTemplateName must be set.
# resourceClaimTemplateName: "<string>"
# Resources is the total amount of CPU and Memory resources required by all containers in
# the pod. It supports specifying Requests and Limits for "cpu", "memory" and "hugepages-"
# resource names only. ResourceClaims are not supported.
#
# This field enables fine-grained control over resource allocation for the entire pod,
# allowing resource sharing among containers in a pod.
#
# This is an alpha field and requires enabling the PodLevelResources feature gate.
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used by
# this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod where
# this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests is
# omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More
# info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# Restart policy for all containers within the pod. One of Always, OnFailure, Never. In
# some contexts, only a subset of those values may be permitted. Default to Always. More
# info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#restart-policy
# restartPolicy: "<string>"
# RuntimeClassName refers to a RuntimeClass object in the node.k8s.io group, which should
# be used to run this pod. If no RuntimeClass resource matches the named class, the pod
# will not be run. If unset or empty, the "legacy" RuntimeClass will be used, which is an
# implicit class with an empty definition that uses the default runtime handler. More
# info: https://git.k8s.io/enhancements/keps/sig-node/585-runtime-class
# runtimeClassName: "<string>"
# If specified, the pod will be dispatched by specified scheduler. If not specified, the
# pod will be dispatched by default scheduler.
# schedulerName: "<string>"
# SchedulingGates is an opaque list of values that if specified will block scheduling the
# pod. If schedulingGates is not empty, the pod will stay in the SchedulingGated state and
# the scheduler will not attempt to schedule the pod.
#
# SchedulingGates can only be set at pod creation time, and be removed only afterwards.
schedulingGates: # optional, listType: map, listMapKeys: name
- # Name of the scheduling gate. Each scheduling gate must have a unique name field.
name: "<string>" # required
# SecurityContext holds pod-level security attributes and common container settings.
# Optional: Defaults to empty. See type description for default values of each field.
securityContext: # optional
# appArmorProfile is the AppArmor options to use by the containers in this pod. Note
# that this field cannot be set when spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options are:
# Localhost - a profile pre-loaded on the node. RuntimeDefault - the container
# runtime's default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of the
# profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# A special supplemental group that applies to all containers in a pod. Some volume
# types allow the Kubelet to change the ownership of that volume to be owned by the pod:
#
# 1. The owning GID will be the FSGroup 2. The setgid bit is set (new files created in
# the volume will be owned by FSGroup) 3. The permission bits are OR'd with rw-rw----
#
# If unset, the Kubelet will not modify the ownership and permissions of any volume.
# Note that this field cannot be set when spec.os.name is windows.
# fsGroup: <int64>
# fsGroupChangePolicy defines behavior of changing ownership and permission of the
# volume before being exposed inside Pod. This field will only apply to volume types
# which support fsGroup based ownership(and permissions). It will have no effect on
# ephemeral volume types such as: secret, configmaps and emptydir. Valid values are
# "OnRootMismatch" and "Always". If not specified, "Always" is used. Note that this
# field cannot be set when spec.os.name is windows.
# fsGroupChangePolicy: "<string>"
# The GID to run the entrypoint of the container process. Uses runtime default if unset.
# May also be set in SecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence for that
# container. Note that this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet will
# validate the image at runtime to ensure that it does not run as UID 0 (root) and fail
# to start the container if it does. If unset or false, no such validation will be
# performed. May also be set in SecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified in
# image metadata if unspecified. May also be set in SecurityContext. If set in both
# SecurityContext and PodSecurityContext, the value specified in SecurityContext takes
# precedence for that container. Note that this field cannot be set when spec.os.name is
# windows.
# runAsUser: <int64>
# seLinuxChangePolicy defines how the container's SELinux label is applied to all
# volumes used by the Pod. It has no effect on nodes that do not support SELinux or to
# volumes does not support SELinux. Valid values are "MountOption" and "Recursive".
#
# "Recursive" means relabeling of all files on all Pod volumes by the container runtime.
# This may be slow for large volumes, but allows mixing privileged and unprivileged Pods
# sharing the same volume on the same node.
#
# "MountOption" mounts all eligible Pod volumes with `-o context` mount option. This
# requires all Pods that share the same volume to use the same SELinux label. It is not
# possible to share the same volume among privileged and unprivileged Pods. Eligible
# volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI
# driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver
# instance. Other volumes are always re-labelled recursively. "MountOption" value is
# allowed only when SELinuxMount feature gate is enabled.
#
# If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. If
# not specified and SELinuxMount feature gate is disabled, "MountOption" is used for
# ReadWriteOncePod volumes and "Recursive" for all other volumes.
#
# This field affects only Pods that have SELinux label set, either in PodSecurityContext
# or in SecurityContext of all containers.
#
# All Pods that use the same volume should use the same seLinuxChangePolicy, otherwise
# some pods can get stuck in ContainerCreating state. Note that this field cannot be set
# when spec.os.name is windows.
# seLinuxChangePolicy: "<string>"
# The SELinux context to be applied to all containers. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set in
# SecurityContext. If set in both SecurityContext and PodSecurityContext, the value
# specified in SecurityContext takes precedence for that container. Note that this field
# cannot be set when spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by the containers in this pod. Note that this field cannot
# be set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used. RuntimeDefault -
# the container runtime default profile should be used. Unconfined - no profile should
# be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be used.
# The profile must be preconfigured on the node to work. Must be a descending path,
# relative to the kubelet's configured seccomp profile location. Must be set if type
# is "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# A list of groups applied to the first process run in each container, in addition to
# the container's primary GID and fsGroup (if specified). If the
# SupplementalGroupsPolicy feature is enabled, the supplementalGroupsPolicy field
# determines whether these are in addition to or instead of any group memberships
# defined in the container image. If unspecified, no additional groups are added, though
# group memberships defined in the container image may still be used, depending on the
# supplementalGroupsPolicy field. Note that this field cannot be set when spec.os.name
# is windows.
# supplementalGroups: # listType: atomic
# - <int64>
# Defines how supplemental groups of the first container processes are calculated. Valid
# values are "Merge" and "Strict". If not specified, "Merge" is used. (Alpha) Using the
# field requires the SupplementalGroupsPolicy feature gate to be enabled and the
# container runtime must implement support for this feature. Note that this field cannot
# be set when spec.os.name is windows.
# supplementalGroupsPolicy: "<string>"
# Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported
# sysctls (by the container runtime) might fail to launch. Note that this field cannot
# be set when spec.os.name is windows.
sysctls: # optional, listType: atomic
- # Name of a property to set
name: "<string>" # required
# Value of a property to set
value: "<string>" # required
# The Windows specific settings applied to all containers. If unspecified, the options
# within a container's SecurityContext will be used. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note that
# this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the GMSA
# credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process' container.
# All of a Pod's containers must have the same effective HostProcess value (it is not
# allowed to have a mix of HostProcess containers and non-HostProcess containers). In
# addition, if HostProcess is true then HostNetwork must also be set to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults to
# the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value
# specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# DeprecatedServiceAccount is a deprecated alias for ServiceAccountName. Deprecated: Use
# serviceAccountName instead.
# serviceAccount: "<string>"
# ServiceAccountName is the name of the ServiceAccount to use to run this pod. More info:
# https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
# serviceAccountName: "<string>"
# If true the pod's hostname will be configured as the pod's FQDN, rather than the leaf
# name (the default). In Linux containers, this means setting the FQDN in the hostname
# field of the kernel (the nodename field of struct utsname). In Windows containers, this
# means setting the registry value of hostname for the registry key
# HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters to FQDN. If a
# pod does not have FQDN, this has no effect. Default to false.
# setHostnameAsFQDN: <boolean>
# Share a single process namespace between all of the containers in a pod. When this is
# set containers will be able to view and signal processes from other containers in the
# same pod, and the first process in each container will not be assigned PID 1. HostPID
# and ShareProcessNamespace cannot both be set. Optional: Default to false.
# shareProcessNamespace: <boolean>
# If specified, the fully qualified Pod hostname will be "<hostname>.<subdomain>.<pod
# namespace>.svc.<cluster domain>". If not specified, the pod will not have a domainname
# at all.
# subdomain: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully. May be decreased in
# delete request. Value must be non-negative integer. The value zero indicates stop
# immediately via the kill signal (no opportunity to shut down). If this value is nil, the
# default grace period will be used instead. The grace period is the duration in seconds
# after the processes running in the pod are sent a termination signal and the time when
# the processes are forcibly halted with a kill signal. Set this value longer than the
# expected cleanup time for your process. Defaults to 30 seconds.
# terminationGracePeriodSeconds: <int64>
# If specified, the pod's tolerations.
# tolerations: # listType: atomic
# - # Effect indicates the taint effect to match. Empty means match all taint effects.
# When specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.
# effect: "<string>"
# Key is the taint key that the toleration applies to. Empty means match all taint
# keys. If the key is empty, operator must be Exists; this combination means to match
# all values and all keys.
# key: "<string>"
# Operator represents a key's relationship to the value. Valid operators are Exists
# and Equal. Defaults to Equal. Exists is equivalent to wildcard for value, so that a
# pod can tolerate all taints of a particular category.
# operator: "<string>"
# TolerationSeconds represents the period of time the toleration (which must be of
# effect NoExecute, otherwise this field is ignored) tolerates the taint. By default,
# it is not set, which means tolerate the taint forever (do not evict). Zero and
# negative values will be treated as 0 (evict immediately) by the system.
# tolerationSeconds: <int64>
# Value is the taint value the toleration matches to. If the operator is Exists, the
# value should be empty, otherwise just a regular string.
# value: "<string>"
# TopologySpreadConstraints describes how a group of pods ought to spread across topology
# domains. Scheduler will schedule pods in a way which abides by the constraints. All
# topologySpreadConstraints are ANDed.
topologySpreadConstraints: # optional, listType: map, listMapKeys: topologyKey,
# whenUnsatisfiable
- # MaxSkew describes the degree to which pods may be unevenly distributed. When
# `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference between
# the number of matching pods in the target topology and the global minimum. The
# global minimum is the minimum number of matching pods in an eligible domain or zero
# if the number of eligible domains is less than MinDomains. For example, in a 3-zone
# cluster, MaxSkew is set to 1, and pods with the same labelSelector spread as 2/2/1:
# In this case, the global minimum is 1. | zone1 | zone2 | zone3 | | P P | P P | P | -
# if MaxSkew is 1, incoming pod can only be scheduled to zone3 to become 2/2/2;
# scheduling it onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2)
# violate MaxSkew(1). - if MaxSkew is 2, incoming pod can be scheduled onto any zone.
# When `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher precedence to
# topologies that satisfy it. It's a required field. Default value is 1 and 0 is not
# allowed.
maxSkew: <int32> # required
# TopologyKey is the key of node labels. Nodes that have a label with this key and
# identical values are considered to be in the same topology. We consider each <key,
# value> as a "bucket", and try to put balanced number of pods into each bucket. We
# define a domain as a particular instance of a topology. Also, we define an eligible
# domain as a domain whose nodes meet the requirements of nodeAffinityPolicy and
# nodeTaintsPolicy. e.g. If TopologyKey is "kubernetes.io/hostname", each Node is a
# domain of that topology. And, if TopologyKey is "topology.kubernetes.io/zone", each
# zone is a domain of that topology. It's a required field.
topologyKey: "<string>" # required
# WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy the spread
# constraint. - DoNotSchedule (default) tells the scheduler not to schedule it. -
# ScheduleAnyway tells the scheduler to schedule the pod in any location, but giving
# higher precedence to topologies that would help reduce the skew. A constraint is
# considered "Unsatisfiable" for an incoming pod if and only if every possible node
# assignment for that pod would violate "MaxSkew" on some topology. For example, in a
# 3-zone cluster, MaxSkew is set to 1, and pods with the same labelSelector spread as
# 3/1/1: | zone1 | zone2 | zone3 | | P P P | P | P | If WhenUnsatisfiable is set to
# DoNotSchedule, incoming pod can only be scheduled to zone2(zone3) to become
# 3/2/1(3/1/2) as ActualSkew(2-1) on zone2(zone3) satisfies MaxSkew(1). In other
# words, the cluster can still be imbalanced, but scheduler won't make it *more*
# imbalanced. It's a required field.
whenUnsatisfiable: "<string>" # required
# LabelSelector is used to find matching pods. Pods that match this label selector are
# counted to determine the number of pods in their corresponding topology domain.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators
# are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist, the
# values array must be empty. This array is replaced during a strategic merge
# patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
# map is equivalent to an element of matchExpressions, whose key field is "key", the
# operator is "In", and the values array contains only "value". The requirements are
# ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select the pods over which spreading
# will be calculated. The keys are used to lookup values from the incoming pod labels,
# those key-value labels are ANDed with labelSelector to select the group of existing
# pods over which spreading will be calculated for the incoming pod. The same key is
# forbidden to exist in both MatchLabelKeys and LabelSelector. MatchLabelKeys cannot
# be set when LabelSelector isn't set. Keys that don't exist in the incoming pod
# labels will be ignored. A null or empty list means only match against labelSelector.
#
# This is a beta field and requires the MatchLabelKeysInPodTopologySpread feature gate
# to be enabled (enabled by default).
# matchLabelKeys: # listType: atomic
# - "<string>"
# MinDomains indicates a minimum number of eligible domains. When the number of
# eligible domains with matching topology keys is less than minDomains, Pod Topology
# Spread treats "global minimum" as 0, and then the calculation of Skew is performed.
# And when the number of eligible domains with matching topology keys equals or
# greater than minDomains, this value has no effect on scheduling. As a result, when
# the number of eligible domains is less than minDomains, scheduler won't schedule
# more than maxSkew Pods to those domains. If value is nil, the constraint behaves as
# if MinDomains is equal to 1. Valid values are integers greater than 0. When value is
# not nil, WhenUnsatisfiable must be DoNotSchedule.
#
# For example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5 and
# pods with the same labelSelector spread as 2/2/2: | zone1 | zone2 | zone3 | | P P |
# P P | P P | The number of domains is less than 5(MinDomains), so "global minimum" is
# treated as 0. In this situation, new pod with the same labelSelector cannot be
# scheduled, because computed skew will be 3(3 - 0) if new Pod is scheduled to any of
# the three zones, it will violate MaxSkew.
# minDomains: <int32>
# NodeAffinityPolicy indicates how we will treat Pod's nodeAffinity/nodeSelector when
# calculating pod topology spread skew. Options are: - Honor: only nodes matching
# nodeAffinity/nodeSelector are included in the calculations. - Ignore:
# nodeAffinity/nodeSelector are ignored. All nodes are included in the calculations.
#
# If this value is nil, the behavior is equivalent to the Honor policy.
# nodeAffinityPolicy: "<string>"
# NodeTaintsPolicy indicates how we will treat node taints when calculating pod
# topology spread skew. Options are: - Honor: nodes without taints, along with tainted
# nodes for which the incoming pod has a toleration, are included. - Ignore: node
# taints are ignored. All nodes are included.
#
# If this value is nil, the behavior is equivalent to the Ignore policy.
# nodeTaintsPolicy: "<string>"
# List of volumes that can be mounted by containers belonging to the pod. More info:
# https://kubernetes.io/docs/concepts/storage/volumes
volumes: # optional, listType: map, listMapKeys: name
- # name of the volume. Must be a DNS_LABEL and unique within the pod. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
name: "<string>" # required
# awsElasticBlockStore represents an AWS Disk resource that is attached to a kubelet's
# host machine and then exposed to the pod. Deprecated: AWSElasticBlockStore is
# deprecated. All operations for the in-tree awsElasticBlockStore type are redirected
# to the ebs.csi.aws.com CSI driver. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
awsElasticBlockStore: # optional
# volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS volume).
# More info:
# https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
volumeID: "<string>" # required
# fsType is the filesystem type of the volume that you want to mount. Tip: Ensure
# that the filesystem type is supported by the host operating system. Examples:
# "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
# fsType: "<string>"
# partition is the partition in the volume that you want to mount. If omitted, the
# default is to mount by volume name. Examples: For volume /dev/sda1, you specify
# the partition as "1". Similarly, the volume partition for /dev/sda is "0" (or you
# can leave the property empty).
# partition: <int32>
# readOnly value true will force the readOnly setting in VolumeMounts. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
# readOnly: <boolean>
# azureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.
# Deprecated: AzureDisk is deprecated. All operations for the in-tree azureDisk type
# are redirected to the disk.csi.azure.com CSI driver.
azureDisk: # optional
# diskName is the Name of the data disk in the blob storage
diskName: "<string>" # required
# diskURI is the URI of data disk in the blob storage
diskURI: "<string>" # required
# cachingMode is the Host Caching mode: None, Read Only, Read Write.
# cachingMode: "<string>"
# fsType is Filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "ext4" # default
# kind expected values are Shared: multiple blob disks per storage account
# Dedicated: single blob disk per storage account Managed: azure managed data disk
# (only in managed availability set). defaults to shared
# kind: "<string>"
# readOnly Defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: false # default
# azureFile represents an Azure File Service mount on the host and bind mount to the
# pod. Deprecated: AzureFile is deprecated. All operations for the in-tree azureFile
# type are redirected to the file.csi.azure.com CSI driver.
azureFile: # optional
# secretName is the name of secret that contains Azure Storage Account Name and Key
secretName: "<string>" # required
# shareName is the azure share Name
shareName: "<string>" # required
# readOnly defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: <boolean>
# cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.
# Deprecated: CephFS is deprecated and the in-tree cephfs type is no longer supported.
cephfs: # optional
# monitors is Required: Monitors is a collection of Ceph monitors More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
monitors: # required, listType: atomic
- "<string>"
# path is Optional: Used as the mounted root, rather than the full Ceph tree,
# default is /
# path: "<string>"
# readOnly is Optional: Defaults to false (read/write). ReadOnly here will force the
# ReadOnly setting in VolumeMounts. More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
# readOnly: <boolean>
# secretFile is Optional: SecretFile is the path to key ring for User, default is
# /etc/ceph/user.secret More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
# secretFile: "<string>"
# secretRef is Optional: SecretRef is reference to the authentication secret for
# User, default is empty. More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# user is optional: User is the rados user name, default is admin More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
# user: "<string>"
# cinder represents a cinder volume attached and mounted on kubelets host machine.
# Deprecated: Cinder is deprecated. All operations for the in-tree cinder type are
# redirected to the cinder.csi.openstack.org CSI driver. More info:
# https://examples.k8s.io/mysql-cinder-pd/README.md
cinder: # optional
# volumeID used to identify the volume in cinder. More info:
# https://examples.k8s.io/mysql-cinder-pd/README.md
volumeID: "<string>" # required
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be
# "ext4" if unspecified. More info:
# https://examples.k8s.io/mysql-cinder-pd/README.md
# fsType: "<string>"
# readOnly defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts. More info:
# https://examples.k8s.io/mysql-cinder-pd/README.md
# readOnly: <boolean>
# secretRef is optional: points to a secret object containing parameters used to
# connect to OpenStack.
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# configMap represents a configMap that should populate this volume
configMap: # optional, mapType: atomic
# defaultMode is optional: mode bits used to set permissions on created files by
# default. Must be an octal value between 0000 and 0777 or a decimal value between 0
# and 511. YAML accepts both octal and decimal values, JSON requires decimal values
# for mode bits. Defaults to 0644. Directories within the path are not affected by
# this setting. This might be in conflict with other options that affect the file
# mode, like fsGroup, and the result can be other mode bits set.
# defaultMode: <int32>
# items if unspecified, each key-value pair in the Data field of the referenced
# ConfigMap will be projected into the volume as a file whose name is the key and
# content is the value. If specified, the listed keys will be projected into the
# specified paths, and unlisted keys will not be present. If a key is specified
# which is not present in the ConfigMap, the volume setup will error unless it is
# marked optional. Paths must be relative and may not contain the '..' path or start
# with '..'.
items: # optional, listType: atomic
- # key is the key to project.
key: "<string>" # required
# path is the relative path of the file to map the key to. May not be an
# absolute path. May not contain the path element '..'. May not start with the
# string '..'.
path: "<string>" # required
# mode is Optional: mode bits used to set permissions on this file. Must be an
# octal value between 0000 and 0777 or a decimal value between 0 and 511. YAML
# accepts both octal and decimal values, JSON requires decimal values for mode
# bits. If not specified, the volume defaultMode will be used. This might be in
# conflict with other options that affect the file mode, like fsGroup, and the
# result can be other mode bits set.
# mode: <int32>
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# optional specify whether the ConfigMap or its keys must be defined
# optional: <boolean>
# csi (Container Storage Interface) represents ephemeral storage that is handled by
# certain external CSI drivers.
csi: # optional
# driver is the name of the CSI driver that handles this volume. Consult with your
# admin for the correct name as registered in the cluster.
driver: "<string>" # required
# fsType to mount. Ex. "ext4", "xfs", "ntfs". If not provided, the empty value is
# passed to the associated CSI driver which will determine the default filesystem to
# apply.
# fsType: "<string>"
# nodePublishSecretRef is a reference to the secret object containing sensitive
# information to pass to the CSI driver to complete the CSI NodePublishVolume and
# NodeUnpublishVolume calls. This field is optional, and may be empty if no secret
# is required. If the secret object contains more than one secret, all secret
# references are passed.
# nodePublishSecretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# readOnly specifies a read-only configuration for the volume. Defaults to false
# (read/write).
# readOnly: <boolean>
# volumeAttributes stores driver-specific properties that are passed to the CSI
# driver. Consult your driver's documentation for supported values.
# volumeAttributes:
# <key>: "<string>"
# downwardAPI represents downward API about the pod that should populate this volume
downwardAPI: # optional
# Optional: mode bits to use on created files by default. Must be a Optional: mode
# bits used to set permissions on created files by default. Must be an octal value
# between 0000 and 0777 or a decimal value between 0 and 511. YAML accepts both
# octal and decimal values, JSON requires decimal values for mode bits. Defaults to
# 0644. Directories within the path are not affected by this setting. This might be
# in conflict with other options that affect the file mode, like fsGroup, and the
# result can be other mode bits set.
# defaultMode: <int32>
# Items is a list of downward API volume file
items: # optional, listType: atomic
- # Required: Path is the relative path name of the file to be created. Must not
# be absolute or contain the '..' path. Must be utf-8 encoded. The first item of
# the relative path must not start with '..'
path: "<string>" # required
# Required: Selects a field of the pod: only annotations, labels, name,
# namespace and uid are supported.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to
# "v1".
# apiVersion: "<string>"
# Optional: mode bits used to set permissions on this file, must be an octal
# value between 0000 and 0777 or a decimal value between 0 and 511. YAML accepts
# both octal and decimal values, JSON requires decimal values for mode bits. If
# not specified, the volume defaultMode will be used. This might be in conflict
# with other options that affect the file mode, like fsGroup, and the result can
# be other mode bits set.
# mode: <int32>
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, requests.cpu and requests.memory) are currently
# supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# emptyDir represents a temporary directory that shares a pod's lifetime. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#emptydir
# emptyDir:
# medium represents what type of storage medium should back this directory. The
# default is "" which means to use the node's default medium. Must be an empty
# string (default) or Memory. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#emptydir
# medium: "<string>"
# sizeLimit is the total amount of local storage required for this EmptyDir volume.
# The size limit is also applicable for memory medium. The maximum usage on memory
# medium EmptyDir would be the minimum value between the SizeLimit specified here
# and the sum of memory limits of all containers in a pod. The default is nil which
# means that the limit is undefined. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#emptydir
# sizeLimit: <int-or-string> # intOrString
# ephemeral represents a volume that is handled by a cluster storage driver. The
# volume's lifecycle is tied to the pod that defines it - it will be created before
# the pod starts, and deleted when the pod is removed.
#
# Use this if: a) the volume is only needed while the pod runs, b) features of normal
# volumes like restoring from snapshot or capacity tracking are needed, c) the storage
# driver is specified through a storage class, and d) the storage driver supports
# dynamic volume provisioning through a PersistentVolumeClaim (see
# EphemeralVolumeSource for more information on the connection between this volume
# type and PersistentVolumeClaim).
#
# Use PersistentVolumeClaim or one of the vendor-specific APIs for volumes that
# persist for longer than the lifecycle of an individual pod.
#
# Use CSI for light-weight local ephemeral volumes if the CSI driver is meant to be
# used that way - see the documentation of the driver for more information.
#
# A pod can use both types of ephemeral volumes and persistent volumes at the same
# time.
ephemeral: # optional
# Will be used to create a stand-alone PVC to provision the volume. The pod in which
# this EphemeralVolumeSource is embedded will be the owner of the PVC, i.e. the PVC
# will be deleted together with the pod. The name of the PVC will be `<pod
# name>-<volume name>` where `<volume name>` is the name from the `PodSpec.Volumes`
# array entry. Pod validation will reject the pod if the concatenated name is not
# valid for a PVC (for example, too long).
#
# An existing PVC with that name that is not owned by the pod will *not* be used for
# the pod to avoid using an unrelated volume by mistake. Starting the pod is then
# blocked until the unrelated PVC is removed. If such a pre-created PVC is meant to
# be used by the pod, the PVC has to updated with an owner reference to the pod once
# the pod exists. Normally this should not be necessary, but it may be useful when
# manually reconstructing a broken cluster.
#
# This field is read-only and no changes will be made by Kubernetes to the PVC after
# it has been created.
#
# Required, must not be nil.
volumeClaimTemplate: # optional
# The specification for the PersistentVolumeClaim. The entire content is copied
# unchanged into the PVC that gets created from this template. The same fields as
# in a PersistentVolumeClaim are also valid here.
spec: # required
# accessModes contains the desired access modes the volume should have. More
# info:
# https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1
# accessModes: # listType: atomic
# - "<string>"
# dataSource field can be used to specify either: * An existing VolumeSnapshot
# object (snapshot.storage.k8s.io/VolumeSnapshot) * An existing PVC
# (PersistentVolumeClaim) If the provisioner or an external controller can
# support the specified data source, it will create a new volume based on the
# contents of the specified data source. When the AnyVolumeDataSource feature
# gate is enabled, dataSource contents will be copied to dataSourceRef, and
# dataSourceRef contents will be copied to dataSource when
# dataSourceRef.namespace is not specified. If the namespace is specified, then
# dataSourceRef will not be copied to dataSource.
dataSource: # optional, mapType: atomic
# Kind is the type of resource being referenced
kind: "<string>" # required
# Name is the name of resource being referenced
name: "<string>" # required
# APIGroup is the group for the resource being referenced. If APIGroup is not
# specified, the specified Kind must be in the core API group. For any other
# third-party types, APIGroup is required.
# apiGroup: "<string>"
# dataSourceRef specifies the object from which to populate the volume with
# data, if a non-empty volume is desired. This may be any object from a
# non-empty API group (non core object) or a PersistentVolumeClaim object. When
# this field is specified, volume binding will only succeed if the type of the
# specified object matches some installed volume populator or dynamic
# provisioner. This field will replace the functionality of the dataSource field
# and as such if both fields are non-empty, they must have the same value. For
# backwards compatibility, when namespace isn't specified in dataSourceRef, both
# fields (dataSource and dataSourceRef) will be set to the same value
# automatically if one of them is empty and the other is non-empty. When
# namespace is specified in dataSourceRef, dataSource isn't set to the same
# value and must be empty. There are three important differences between
# dataSource and dataSourceRef: * While dataSource only allows two specific
# types of objects, dataSourceRef allows any non-core object, as well as
# PersistentVolumeClaim objects. * While dataSource ignores disallowed values
# (dropping them), dataSourceRef preserves all values, and generates an error if
# a disallowed value is specified. * While dataSource only allows local objects,
# dataSourceRef allows objects in any namespaces. (Beta) Using this field
# requires the AnyVolumeDataSource feature gate to be enabled. (Alpha) Using the
# namespace field of dataSourceRef requires the CrossNamespaceVolumeDataSource
# feature gate to be enabled.
dataSourceRef: # optional
# Kind is the type of resource being referenced
kind: "<string>" # required
# Name is the name of resource being referenced
name: "<string>" # required
# APIGroup is the group for the resource being referenced. If APIGroup is not
# specified, the specified Kind must be in the core API group. For any other
# third-party types, APIGroup is required.
# apiGroup: "<string>"
# Namespace is the namespace of resource being referenced Note that when a
# namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is
# required in the referent namespace to allow that namespace's owner to accept
# the reference. See the ReferenceGrant documentation for details. (Alpha)
# This field requires the CrossNamespaceVolumeDataSource feature gate to be
# enabled.
# namespace: "<string>"
# resources represents the minimum resources the volume should have. If
# RecoverVolumeExpansionFailure feature is enabled users are allowed to specify
# resource requirements that are lower than previous value but must still be
# higher than capacity recorded in the status field of the claim. More info:
# https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources
# resources:
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If
# Requests is omitted for a container, it defaults to Limits if that is
# explicitly specified, otherwise to an implementation-defined value. Requests
# cannot exceed Limits. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# selector is a label query over volumes to consider for binding.
selector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or
# DoesNotExist, the values array must be empty. This array is replaced
# during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# storageClassName is the name of the StorageClass required by the claim. More
# info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1
# storageClassName: "<string>"
# volumeAttributesClassName may be used to set the VolumeAttributesClass used by
# this claim. If specified, the CSI driver will create or update the volume with
# the attributes defined in the corresponding VolumeAttributesClass. This has a
# different purpose than storageClassName, it can be changed after the claim is
# created. An empty string or nil value indicates that no VolumeAttributesClass
# will be applied to the claim. If the claim enters an Infeasible error state,
# this field can be reset to its previous value (including nil) to cancel the
# modification. If the resource referred to by volumeAttributesClass does not
# exist, this PersistentVolumeClaim will be set to a Pending state, as reflected
# by the modifyVolumeStatus field, until such as a resource exists. More info:
# https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/
# volumeAttributesClassName: "<string>"
# volumeMode defines what type of volume is required by the claim. Value of
# Filesystem is implied when not included in claim spec.
# volumeMode: "<string>"
# volumeName is the binding reference to the PersistentVolume backing this
# claim.
# volumeName: "<string>"
# May contain labels and annotations that will be copied into the PVC when
# creating it. No other fields are allowed and will be rejected during validation.
# metadata:
# annotations:
# <key>: "<string>"
# finalizers:
# - "<string>"
# labels:
# <key>: "<string>"
# name: "<string>"
# namespace: "<string>"
# fc represents a Fibre Channel resource that is attached to a kubelet's host machine
# and then exposed to the pod.
# fc:
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "<string>"
# lun is Optional: FC target lun number
# lun: <int32>
# readOnly is Optional: Defaults to false (read/write). ReadOnly here will force the
# ReadOnly setting in VolumeMounts.
# readOnly: <boolean>
# targetWWNs is Optional: FC target worldwide names (WWNs)
# targetWWNs: # listType: atomic
# - "<string>"
# wwids Optional: FC volume world wide identifiers (wwids) Either wwids or
# combination of targetWWNs and lun must be set, but not both simultaneously.
# wwids: # listType: atomic
# - "<string>"
# flexVolume represents a generic volume resource that is provisioned/attached using
# an exec based plugin. Deprecated: FlexVolume is deprecated. Consider using a
# CSIDriver instead.
flexVolume: # optional
# driver is the name of the driver to use for this volume.
driver: "<string>" # required
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". The default filesystem depends
# on FlexVolume script.
# fsType: "<string>"
# options is Optional: this field holds extra command options if any.
# options:
# <key>: "<string>"
# readOnly is Optional: defaults to false (read/write). ReadOnly here will force the
# ReadOnly setting in VolumeMounts.
# readOnly: <boolean>
# secretRef is Optional: secretRef is reference to the secret object containing
# sensitive information to pass to the plugin scripts. This may be empty if no
# secret object is specified. If the secret object contains more than one secret,
# all secrets are passed to the plugin scripts.
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# flocker represents a Flocker volume attached to a kubelet's host machine. This
# depends on the Flocker control service being running. Deprecated: Flocker is
# deprecated and the in-tree flocker type is no longer supported.
# flocker:
# datasetName is Name of the dataset stored as metadata -> name on the dataset for
# Flocker should be considered as deprecated
# datasetName: "<string>"
# datasetUUID is the UUID of the dataset. This is unique identifier of a Flocker
# dataset
# datasetUUID: "<string>"
# gcePersistentDisk represents a GCE Disk resource that is attached to a kubelet's
# host machine and then exposed to the pod. Deprecated: GCEPersistentDisk is
# deprecated. All operations for the in-tree gcePersistentDisk type are redirected to
# the pd.csi.storage.gke.io CSI driver. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
gcePersistentDisk: # optional
# pdName is unique name of the PD resource in GCE. Used to identify the disk in GCE.
# More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
pdName: "<string>" # required
# fsType is filesystem type of the volume that you want to mount. Tip: Ensure that
# the filesystem type is supported by the host operating system. Examples: "ext4",
# "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
# fsType: "<string>"
# partition is the partition in the volume that you want to mount. If omitted, the
# default is to mount by volume name. Examples: For volume /dev/sda1, you specify
# the partition as "1". Similarly, the volume partition for /dev/sda is "0" (or you
# can leave the property empty). More info:
# https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
# partition: <int32>
# readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
# More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
# readOnly: <boolean>
# gitRepo represents a git repository at a particular revision. Deprecated: GitRepo is
# deprecated. To provision a container with a git repo, mount an EmptyDir into an
# InitContainer that clones the repo using git, then mount the EmptyDir into the Pod's
# container.
gitRepo: # optional
# repository is the URL
repository: "<string>" # required
# directory is the target directory name. Must not contain or start with '..'. If
# '.' is supplied, the volume directory will be the git repository. Otherwise, if
# specified, the volume will contain the git repository in the subdirectory with the
# given name.
# directory: "<string>"
# revision is the commit hash for the specified revision.
# revision: "<string>"
# glusterfs represents a Glusterfs mount on the host that shares a pod's lifetime.
# Deprecated: Glusterfs is deprecated and the in-tree glusterfs type is no longer
# supported.
glusterfs: # optional
# endpoints is the endpoint name that details Glusterfs topology.
endpoints: "<string>" # required
# path is the Glusterfs volume path. More info:
# https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
path: "<string>" # required
# readOnly here will force the Glusterfs volume to be mounted with read-only
# permissions. Defaults to false. More info:
# https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
# readOnly: <boolean>
# hostPath represents a pre-existing file or directory on the host machine that is
# directly exposed to the container. This is generally used for system agents or other
# privileged things that are allowed to see the host machine. Most containers will NOT
# need this. More info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath
hostPath: # optional
# path of the directory on the host. If the path is a symlink, it will follow the
# link to the real path. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#hostpath
path: "<string>" # required
# type for HostPath Volume Defaults to "" More info:
# https://kubernetes.io/docs/concepts/storage/volumes#hostpath
# type: "<string>"
# image represents an OCI object (a container image or artifact) pulled and mounted on
# the kubelet's host machine. The volume is resolved at pod startup depending on which
# PullPolicy value is provided:
#
# - Always: the kubelet always attempts to pull the reference. Container creation will
# fail If the pull fails. - Never: the kubelet never pulls the reference and only uses
# a local image or artifact. Container creation will fail if the reference isn't
# present. - IfNotPresent: the kubelet pulls if the reference isn't already present on
# disk. Container creation will fail if the reference isn't present and the pull
# fails.
#
# The volume gets re-resolved if the pod gets deleted and recreated, which means that
# new remote content will become available on pod recreation. A failure to resolve or
# pull the image during pod startup will block containers from starting and may add
# significant latency. Failures will be retried using normal volume backoff and will
# be reported on the pod reason and message. The types of objects that may be mounted
# by this volume are defined by the container runtime implementation on a host machine
# and at minimum must include all valid types supported by the container image field.
# The OCI object gets mounted in a single directory
# (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the
# same way as for container images. The volume will be mounted read-only (ro) and
# non-executable files (noexec). Sub path mounts for containers are not supported
# (spec.containers[*].volumeMounts.subpath) before 1.33. The field
# spec.securityContext.fsGroupChangePolicy has no effect on this volume type.
# image:
# Policy for pulling OCI objects. Possible values are: Always: the kubelet always
# attempts to pull the reference. Container creation will fail If the pull fails.
# Never: the kubelet never pulls the reference and only uses a local image or
# artifact. Container creation will fail if the reference isn't present.
# IfNotPresent: the kubelet pulls if the reference isn't already present on disk.
# Container creation will fail if the reference isn't present and the pull fails.
# Defaults to Always if :latest tag is specified, or IfNotPresent otherwise.
# pullPolicy: "<string>"
# Required: Image or artifact reference to be used. Behaves in the same way as
# pod.spec.containers[*].image. Pull secrets will be assembled in the same way as
# for the container image by looking up node credentials, SA image pull secrets, and
# pod spec image pull secrets. More info:
# https://kubernetes.io/docs/concepts/containers/images This field is optional to
# allow higher level config management to default or override container images in
# workload controllers like Deployments and StatefulSets.
# reference: "<string>"
# iscsi represents an ISCSI Disk resource that is attached to a kubelet's host machine
# and then exposed to the pod. More info:
# https://kubernetes.io/docs/concepts/storage/volumes/#iscsi
iscsi: # optional
# iqn is the target iSCSI Qualified Name.
iqn: "<string>" # required
# lun represents iSCSI Target Lun number.
lun: <int32> # required
# targetPortal is iSCSI Target Portal. The Portal is either an IP or ip_addr:port if
# the port is other than default (typically TCP ports 860 and 3260).
targetPortal: "<string>" # required
# chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication
# chapAuthDiscovery: <boolean>
# chapAuthSession defines whether support iSCSI Session CHAP authentication
# chapAuthSession: <boolean>
# fsType is the filesystem type of the volume that you want to mount. Tip: Ensure
# that the filesystem type is supported by the host operating system. Examples:
# "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#iscsi
# fsType: "<string>"
# initiatorName is the custom iSCSI Initiator Name. If initiatorName is specified
# with iscsiInterface simultaneously, new iSCSI interface <target portal>:<volume
# name> will be created for the connection.
# initiatorName: "<string>"
# iscsiInterface is the interface Name that uses an iSCSI transport. Defaults to
# 'default' (tcp).
# iscsiInterface: "default" # default
# portals is the iSCSI Target Portal List. The portal is either an IP or
# ip_addr:port if the port is other than default (typically TCP ports 860 and 3260).
# portals: # listType: atomic
# - "<string>"
# readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
# readOnly: <boolean>
# secretRef is the CHAP Secret for iSCSI target and initiator authentication
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# nfs represents an NFS mount on the host that shares a pod's lifetime More info:
# https://kubernetes.io/docs/concepts/storage/volumes#nfs
nfs: # optional
# path that is exported by the NFS server. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#nfs
path: "<string>" # required
# server is the hostname or IP address of the NFS server. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#nfs
server: "<string>" # required
# readOnly here will force the NFS export to be mounted with read-only permissions.
# Defaults to false. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#nfs
# readOnly: <boolean>
# persistentVolumeClaimVolumeSource represents a reference to a PersistentVolumeClaim
# in the same namespace. More info:
# https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
persistentVolumeClaim: # optional
# claimName is the name of a PersistentVolumeClaim in the same namespace as the pod
# using this volume. More info:
# https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
claimName: "<string>" # required
# readOnly Will force the ReadOnly setting in VolumeMounts. Default false.
# readOnly: <boolean>
# photonPersistentDisk represents a PhotonController persistent disk attached and
# mounted on kubelets host machine. Deprecated: PhotonPersistentDisk is deprecated and
# the in-tree photonPersistentDisk type is no longer supported.
photonPersistentDisk: # optional
# pdID is the ID that identifies Photon Controller persistent disk
pdID: "<string>" # required
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "<string>"
# portworxVolume represents a portworx volume attached and mounted on kubelets host
# machine. Deprecated: PortworxVolume is deprecated. All operations for the in-tree
# portworxVolume type are redirected to the pxd.portworx.com CSI driver when the
# CSIMigrationPortworx feature-gate is on.
portworxVolume: # optional
# volumeID uniquely identifies a Portworx volume
volumeID: "<string>" # required
# fSType represents the filesystem type to mount Must be a filesystem type supported
# by the host operating system. Ex. "ext4", "xfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "<string>"
# readOnly defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: <boolean>
# projected items for all in one resources secrets, configmaps, and downward API
projected: # optional
# defaultMode are the mode bits used to set permissions on created files by default.
# Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
# YAML accepts both octal and decimal values, JSON requires decimal values for mode
# bits. Directories within the path are not affected by this setting. This might be
# in conflict with other options that affect the file mode, like fsGroup, and the
# result can be other mode bits set.
# defaultMode: <int32>
# sources is the list of volume projections. Each entry in this list handles one
# source.
sources: # optional, listType: atomic
- # ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field of
# ClusterTrustBundle objects in an auto-updating file.
#
# Alpha, gated by the ClusterTrustBundleProjection feature gate.
#
# ClusterTrustBundle objects can either be selected by name, or by the
# combination of signer name and a label selector.
#
# Kubelet performs aggressive normalization of the PEM contents written into the
# pod filesystem. Esoteric PEM features such as inter-block comments and block
# headers are stripped. Certificates are deduplicated. The ordering of
# certificates within the file is arbitrary, and Kubelet may change the order
# over time.
clusterTrustBundle: # optional
# Relative path from the volume root to write the bundle.
path: "<string>" # required
# Select all ClusterTrustBundles that match this label selector. Only has
# effect if signerName is set. Mutually-exclusive with name. If unset,
# interpreted as "match nothing". If set but empty, interpreted as "match
# everything".
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The
# requirements are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn,
# the values array must be non-empty. If the operator is Exists or
# DoesNotExist, the values array must be empty. This array is replaced
# during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# Select a single ClusterTrustBundle by object name. Mutually-exclusive with
# signerName and labelSelector.
# name: "<string>"
# If true, don't block pod startup if the referenced ClusterTrustBundle(s)
# aren't available. If using name, then the named ClusterTrustBundle is
# allowed not to exist. If using signerName, then the combination of
# signerName and labelSelector is allowed to match zero ClusterTrustBundles.
# optional: <boolean>
# Select all ClusterTrustBundles that match this signer name.
# Mutually-exclusive with name. The contents of all selected
# ClusterTrustBundles will be unified and deduplicated.
# signerName: "<string>"
# configMap information about the configMap data to project
configMap: # optional, mapType: atomic
# items if unspecified, each key-value pair in the Data field of the
# referenced ConfigMap will be projected into the volume as a file whose name
# is the key and content is the value. If specified, the listed keys will be
# projected into the specified paths, and unlisted keys will not be present.
# If a key is specified which is not present in the ConfigMap, the volume
# setup will error unless it is marked optional. Paths must be relative and
# may not contain the '..' path or start with '..'.
items: # optional, listType: atomic
- # key is the key to project.
key: "<string>" # required
# path is the relative path of the file to map the key to. May not be an
# absolute path. May not contain the path element '..'. May not start with
# the string '..'.
path: "<string>" # required
# mode is Optional: mode bits used to set permissions on this file. Must
# be an octal value between 0000 and 0777 or a decimal value between 0 and
# 511. YAML accepts both octal and decimal values, JSON requires decimal
# values for mode bits. If not specified, the volume defaultMode will be
# used. This might be in conflict with other options that affect the file
# mode, like fsGroup, and the result can be other mode bits set.
# mode: <int32>
# Name of the referent. This field is effectively required, but due to
# backwards compatibility is allowed to be empty. Instances of this type with
# an empty value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# optional specify whether the ConfigMap or its keys must be defined
# optional: <boolean>
# downwardAPI information about the downwardAPI data to project
downwardAPI: # optional
# Items is a list of DownwardAPIVolume file
items: # optional, listType: atomic
- # Required: Path is the relative path name of the file to be created. Must
# not be absolute or contain the '..' path. Must be utf-8 encoded. The
# first item of the relative path must not start with '..'
path: "<string>" # required
# Required: Selects a field of the pod: only annotations, labels, name,
# namespace and uid are supported.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults
# to "v1".
# apiVersion: "<string>"
# Optional: mode bits used to set permissions on this file, must be an
# octal value between 0000 and 0777 or a decimal value between 0 and 511.
# YAML accepts both octal and decimal values, JSON requires decimal values
# for mode bits. If not specified, the volume defaultMode will be used.
# This might be in conflict with other options that affect the file mode,
# like fsGroup, and the result can be other mode bits set.
# mode: <int32>
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, requests.cpu and requests.memory) are
# currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Projects an auto-rotating credential bundle (private key and certificate
# chain) that the pod can use either as a TLS client or server.
#
# Kubelet generates a private key and uses it to send a PodCertificateRequest to
# the named signer. Once the signer approves the request and issues a
# certificate chain, Kubelet writes the key and certificate chain to the pod
# filesystem. The pod does not start until certificates have been issued for
# each podCertificate projected volume source in its spec.
#
# Kubelet will begin trying to rotate the certificate at the time indicated by
# the signer using the PodCertificateRequest.Status.BeginRefreshAt timestamp.
#
# Kubelet can write a single file, indicated by the credentialBundlePath field,
# or separate files, indicated by the keyPath and certificateChainPath fields.
#
# The credential bundle is a single file in PEM format. The first PEM entry is
# the private key (in PKCS#8 format), and the remaining PEM entries are the
# certificate chain issued by the signer (typically, signers will return their
# certificate chain in leaf-to-root order).
#
# Prefer using the credential bundle format, since your application code can
# read it atomically. If you use keyPath and certificateChainPath, your
# application must make two separate file reads. If these coincide with a
# certificate rotation, it is possible that the private key and leaf certificate
# you read may not correspond to each other. Your application will need to check
# for this condition, and re-read until they are consistent.
#
# The named signer controls chooses the format of the certificate it issues;
# consult the signer implementation's documentation to learn how to use the
# certificates it issues.
podCertificate: # optional
# The type of keypair Kubelet will generate for the pod.
#
# Valid values are "RSA3072", "RSA4096", "ECDSAP256", "ECDSAP384",
# "ECDSAP521", and "ED25519".
keyType: "<string>" # required
# Kubelet's generated CSRs will be addressed to this signer.
signerName: "<string>" # required
# Write the certificate chain at this path in the projected volume.
#
# Most applications should use credentialBundlePath. When using keyPath and
# certificateChainPath, your application needs to check that the key and leaf
# certificate are consistent, because it is possible to read the files
# mid-rotation.
# certificateChainPath: "<string>"
# Write the credential bundle at this path in the projected volume.
#
# The credential bundle is a single file that contains multiple PEM blocks.
# The first PEM block is a PRIVATE KEY block, containing a PKCS#8 private key.
#
# The remaining blocks are CERTIFICATE blocks, containing the issued
# certificate chain from the signer (leaf and any intermediates).
#
# Using credentialBundlePath lets your Pod's application code make a single
# atomic read that retrieves a consistent key and certificate chain. If you
# project them to separate files, your application code will need to
# additionally check that the leaf certificate was issued to the key.
# credentialBundlePath: "<string>"
# Write the key at this path in the projected volume.
#
# Most applications should use credentialBundlePath. When using keyPath and
# certificateChainPath, your application needs to check that the key and leaf
# certificate are consistent, because it is possible to read the files
# mid-rotation.
# keyPath: "<string>"
# maxExpirationSeconds is the maximum lifetime permitted for the certificate.
#
# Kubelet copies this value verbatim into the PodCertificateRequests it
# generates for this projection.
#
# If omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver
# will reject values shorter than 3600 (1 hour). The maximum allowable value
# is 7862400 (91 days).
#
# The signer implementation is then free to issue a certificate with any
# lifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600
# seconds (1 hour). This constraint is enforced by kube-apiserver.
# `kubernetes.io` signers will never issue certificates with a lifetime longer
# than 24 hours.
# maxExpirationSeconds: <int32>
# secret information about the secret data to project
secret: # optional, mapType: atomic
# items if unspecified, each key-value pair in the Data field of the
# referenced Secret will be projected into the volume as a file whose name is
# the key and content is the value. If specified, the listed keys will be
# projected into the specified paths, and unlisted keys will not be present.
# If a key is specified which is not present in the Secret, the volume setup
# will error unless it is marked optional. Paths must be relative and may not
# contain the '..' path or start with '..'.
items: # optional, listType: atomic
- # key is the key to project.
key: "<string>" # required
# path is the relative path of the file to map the key to. May not be an
# absolute path. May not contain the path element '..'. May not start with
# the string '..'.
path: "<string>" # required
# mode is Optional: mode bits used to set permissions on this file. Must
# be an octal value between 0000 and 0777 or a decimal value between 0 and
# 511. YAML accepts both octal and decimal values, JSON requires decimal
# values for mode bits. If not specified, the volume defaultMode will be
# used. This might be in conflict with other options that affect the file
# mode, like fsGroup, and the result can be other mode bits set.
# mode: <int32>
# Name of the referent. This field is effectively required, but due to
# backwards compatibility is allowed to be empty. Instances of this type with
# an empty value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# optional field specify whether the Secret or its key must be defined
# optional: <boolean>
# serviceAccountToken is information about the serviceAccountToken data to
# project
serviceAccountToken: # optional
# path is the path relative to the mount point of the file to project the
# token into.
path: "<string>" # required
# audience is the intended audience of the token. A recipient of a token must
# identify itself with an identifier specified in the audience of the token,
# and otherwise should reject the token. The audience defaults to the
# identifier of the apiserver.
# audience: "<string>"
# expirationSeconds is the requested duration of validity of the service
# account token. As the token approaches expiration, the kubelet volume plugin
# will proactively rotate the service account token. The kubelet will start
# trying to rotate the token if the token is older than 80 percent of its time
# to live or if the token is older than 24 hours.Defaults to 1 hour and must
# be at least 10 minutes.
# expirationSeconds: <int64>
# quobyte represents a Quobyte mount on the host that shares a pod's lifetime.
# Deprecated: Quobyte is deprecated and the in-tree quobyte type is no longer
# supported.
quobyte: # optional
# registry represents a single or multiple Quobyte Registry services specified as a
# string as host:port pair (multiple entries are separated with commas) which acts
# as the central registry for volumes
registry: "<string>" # required
# volume is a string that references an already created Quobyte volume by name.
volume: "<string>" # required
# group to map volume access to Default is no group
# group: "<string>"
# readOnly here will force the Quobyte volume to be mounted with read-only
# permissions. Defaults to false.
# readOnly: <boolean>
# tenant owning the given Quobyte volume in the Backend Used with dynamically
# provisioned Quobyte volumes, value is set by the plugin
# tenant: "<string>"
# user to map volume access to Defaults to serivceaccount user
# user: "<string>"
# rbd represents a Rados Block Device mount on the host that shares a pod's lifetime.
# Deprecated: RBD is deprecated and the in-tree rbd type is no longer supported.
rbd: # optional
# image is the rados image name. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
image: "<string>" # required
# monitors is a collection of Ceph monitors. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
monitors: # required, listType: atomic
- "<string>"
# fsType is the filesystem type of the volume that you want to mount. Tip: Ensure
# that the filesystem type is supported by the host operating system. Examples:
# "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#rbd
# fsType: "<string>"
# keyring is the path to key ring for RBDUser. Default is /etc/ceph/keyring. More
# info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# keyring: "/etc/ceph/keyring" # default
# pool is the rados pool name. Default is rbd. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# pool: "rbd" # default
# readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
# More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# readOnly: <boolean>
# secretRef is name of the authentication secret for RBDUser. If provided overrides
# keyring. Default is nil. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# user is the rados user name. Default is admin. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# user: "admin" # default
# scaleIO represents a ScaleIO persistent volume attached and mounted on Kubernetes
# nodes. Deprecated: ScaleIO is deprecated and the in-tree scaleIO type is no longer
# supported.
scaleIO: # optional
# gateway is the host address of the ScaleIO API Gateway.
gateway: "<string>" # required
# secretRef references to the secret for ScaleIO user and other sensitive
# information. If this is not provided, Login operation will fail.
secretRef: # required, mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# system is the name of the storage system as configured in ScaleIO.
system: "<string>" # required
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Default is "xfs".
# fsType: "xfs" # default
# protectionDomain is the name of the ScaleIO Protection Domain for the configured
# storage.
# protectionDomain: "<string>"
# readOnly Defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: <boolean>
# sslEnabled Flag enable/disable SSL communication with Gateway, default false
# sslEnabled: <boolean>
# storageMode indicates whether the storage for a volume should be ThickProvisioned
# or ThinProvisioned. Default is ThinProvisioned.
# storageMode: "ThinProvisioned" # default
# storagePool is the ScaleIO Storage Pool associated with the protection domain.
# storagePool: "<string>"
# volumeName is the name of a volume already created in the ScaleIO system that is
# associated with this volume source.
# volumeName: "<string>"
# secret represents a secret that should populate this volume. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#secret
secret: # optional
# defaultMode is Optional: mode bits used to set permissions on created files by
# default. Must be an octal value between 0000 and 0777 or a decimal value between 0
# and 511. YAML accepts both octal and decimal values, JSON requires decimal values
# for mode bits. Defaults to 0644. Directories within the path are not affected by
# this setting. This might be in conflict with other options that affect the file
# mode, like fsGroup, and the result can be other mode bits set.
# defaultMode: <int32>
# items If unspecified, each key-value pair in the Data field of the referenced
# Secret will be projected into the volume as a file whose name is the key and
# content is the value. If specified, the listed keys will be projected into the
# specified paths, and unlisted keys will not be present. If a key is specified
# which is not present in the Secret, the volume setup will error unless it is
# marked optional. Paths must be relative and may not contain the '..' path or start
# with '..'.
items: # optional, listType: atomic
- # key is the key to project.
key: "<string>" # required
# path is the relative path of the file to map the key to. May not be an
# absolute path. May not contain the path element '..'. May not start with the
# string '..'.
path: "<string>" # required
# mode is Optional: mode bits used to set permissions on this file. Must be an
# octal value between 0000 and 0777 or a decimal value between 0 and 511. YAML
# accepts both octal and decimal values, JSON requires decimal values for mode
# bits. If not specified, the volume defaultMode will be used. This might be in
# conflict with other options that affect the file mode, like fsGroup, and the
# result can be other mode bits set.
# mode: <int32>
# optional field specify whether the Secret or its keys must be defined
# optional: <boolean>
# secretName is the name of the secret in the pod's namespace to use. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#secret
# secretName: "<string>"
# storageOS represents a StorageOS volume attached and mounted on Kubernetes nodes.
# Deprecated: StorageOS is deprecated and the in-tree storageos type is no longer
# supported.
# storageos:
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "<string>"
# readOnly defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: <boolean>
# secretRef specifies the secret to use for obtaining the StorageOS API credentials.
# If not specified, default values will be attempted.
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# volumeName is the human-readable name of the StorageOS volume. Volume names are
# only unique within a namespace.
# volumeName: "<string>"
# volumeNamespace specifies the scope of the volume within StorageOS. If no
# namespace is specified then the Pod's namespace will be used. This allows the
# Kubernetes name scoping to be mirrored within StorageOS for tighter integration.
# Set VolumeName to any name to override the default behaviour. Set to "default" if
# you are not using namespaces within StorageOS. Namespaces that do not pre-exist
# within StorageOS will be created.
# volumeNamespace: "<string>"
# vsphereVolume represents a vSphere volume attached and mounted on kubelets host
# machine. Deprecated: VsphereVolume is deprecated. All operations for the in-tree
# vsphereVolume type are redirected to the csi.vsphere.vmware.com CSI driver.
vsphereVolume: # optional
# volumePath is the path that identifies vSphere volume vmdk
volumePath: "<string>" # required
# fsType is filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "<string>"
# storagePolicyID is the storage Policy Based Management (SPBM) profile ID
# associated with the StoragePolicyName.
# storagePolicyID: "<string>"
# storagePolicyName is the storage Policy Based Management (SPBM) profile name.
# storagePolicyName: "<string>"
# replicas is the desired number of Pods for this component. When `scalingAdapter` is set on
# this component, this field is managed by the DynamoGraphDeploymentScalingAdapter and should
# not be modified directly.
# replicas: <int32> # minimum: 0
# scalingAdapter opts this component into using the DynamoGraphDeploymentScalingAdapter. When
# set (even as an empty object, `scalingAdapter: {}`), a DGDSA is created and owns the
# `replicas` field so that external autoscalers (HPA/KEDA/Planner) can drive scaling via the
# Scale subresource. Omit the field to opt out.
# scalingAdapter: {}
# sharedMemorySize controls the size of the tmpfs mounted at `/dev/shm`. `nil` selects the
# operator default (8Gi), a positive quantity sets a custom size, and `"0"` disables the
# shared-memory volume entirely. Simpler replacement for v1alpha1's `SharedMemorySpec` struct
# with its `disabled bool` + `size Quantity` pattern.
# sharedMemorySize: <int-or-string> # intOrString
# topologyConstraint applies to this component. `topologyConstraint.packDomain` is required.
# When both this and `spec.topologyConstraint.packDomain` are set, this field's `packDomain`
# must be narrower than or equal to the spec-level value.
topologyConstraint: # optional
# packDomain is the topology domain to pack pods within. Must match a domain defined in the
# referenced ClusterTopology CR.
packDomain: "<string>" # required
# type indicates the role of this component within a Dynamo graph. Drives port mapping,
# frontend detection, planner RBAC, and the pod label `nvidia.com/dynamo-component-type`.
# Because `prefill` and `decode` are first-class values, users can set them directly.
# type: "frontend" # enum: "worker" | "prefill" | "decode" | "planner" | "epp"
# env is prepended to every component's environment. Component-specific env entries with the same
# name take precedence and may reference values from this list.
env: # optional
- # Name of the environment variable. May consist of any printable ASCII characters except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined environment
# variables in the container and any service environment variables. If a variable cannot be
# resolved, the reference in the input string will be unchanged. Double $$ are reduced to a
# single $, which allows for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce
# the string literal "$(VAR_NAME)". Escaped references will never be expanded, regardless of
# whether the variable exists or not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value here
# are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to be
# enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from starting. The keys
# defined within a source may consist of any printable ASCII characters except '='. During
# Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative and may not
# contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does not exist,
# then the env var is not published. If optional is set to true and the specified key does
# not exist, the environment variable will not be set in the Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error will be
# returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests (limits.cpu,
# limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and
# requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value here
# are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# experimental groups graph-level preview features whose API shape and behavior may change in
# breaking ways between v1beta1 releases.
experimental: # optional
# kvTransferPolicy configures topology-aware routing for KV-cache transfers between prefill and
# decode workers.
kvTransferPolicy: # optional
# domain is the logical name for the topology level to enforce (e.g. "zone", "rack"). The
# router uses this to match workers that share the same value for the label identified by
# `labelKey`.
domain: "<string>" # required
# enforcement controls how the selected prefill worker's topology is applied to decode
# routing. "required" only allows decode workers in the same topology domain as the selected
# prefill worker. "preferred" keeps all decode workers eligible, but biases selection toward
# workers in the same topology domain. Defaults to "required".
# enforcement: "required" # default, enum: "preferred"
# labelKey is a Kubernetes node label key (e.g. "topology.kubernetes.io/zone") whose value
# identifies the topology domain for each worker. The operator copies the node label onto
# worker pods so the runtime can publish it as worker metadata. The label should correspond to
# the topology level named in `domain`.
# labelKey: "<string>" # minLength: 1, maxLength: 317
# preferredWeight is required and used only when enforcement is "preferred". Higher values
# create a stronger same-domain routing preference, but do not guarantee same-domain
# selection. The value is not a probability; worker selection still depends on load and other
# routing inputs. A value of 0 disables the topology preference; 1 is the strongest supported
# preference.
# preferredWeight: <number> # minimum: 0, maximum: 1
# labels to propagate to all child resources. Same precedence rules as `annotations`.
# labels:
# <key>: "<string>"
# priorityClassName is the name of the PriorityClass to use for Grove PodCliqueSets. Requires the
# Grove pathway.
# priorityClassName: "<string>"
# restart specifies the restart policy for the graph deployment.
restart: # optional
# id is an arbitrary string that triggers a restart when changed. Any modification to this value
# initiates a restart of the graph deployment according to the configured strategy.
id: "<string>" # required, minLength: 1
# strategy specifies the restart strategy for the graph deployment.
# strategy:
# order is the complete ordered set of component names for sequential restarts. Omit or leave
# empty to use the controller's default order. This field must not be set for parallel
# restarts.
# order:
# - "<string>"
# type specifies the restart strategy type.
# type: "Sequential" # default, enum: "Parallel"
# topologyConstraint is the deployment-level topology constraint. When set,
# `spec.topologyConstraint.clusterTopologyName` names the ClusterTopology CR to use.
# `spec.topologyConstraint.packDomain` is optional at this level and can be omitted when only
# components carry constraints. Components without their own `topologyConstraint` inherit from
# this value.
topologyConstraint: # optional
# clusterTopologyName is the name of the ClusterTopology resource that defines the topology
# hierarchy for this deployment.
clusterTopologyName: "<string>" # required, minLength: 1
# packDomain is the default topology domain to pack pods within. Optional; omit when only
# components carry constraints.
# packDomain: "<string>"
# status reflects the current observed state of this graph deployment.
status: # optional
# state is a high-level textual status of the graph deployment lifecycle.
state: "initializing" # default, required, enum: "pending" | "successful" | "failed"
# checkpoints contains per-component checkpoint status, keyed by component name.
# checkpoints:
# ComponentCheckpointStatus contains checkpoint information for a single component.
# <key>:
# checkpointID is the artifact ID used by the snapshot protocol.
# checkpointID: "<string>"
# checkpointName is the name of the associated DynamoCheckpoint CR.
# checkpointName: "<string>"
# identityHash is the computed hash of the checkpoint identity. Deprecated: automatic
# checkpoints use checkpointID. This field is retained for older status consumers.
# identityHash: "<string>"
# ready indicates the checkpoint artifact is ready for future pods to restore.
# ready: <boolean>
# components contains per-component replica status information, keyed by component name.
components: # optional
# ComponentReplicaStatus contains replica information for a single component.
<key>: # optional
# componentKind is the underlying resource kind (e.g. `PodClique`, `Deployment`,
# `LeaderWorkerSet`).
componentKind: "PodClique" # required, enum: "PodCliqueScalingGroup" | "Deployment" |
# "LeaderWorkerSet"
# replicas is the total number of non-terminated replicas.
replicas: <int32> # required, minimum: 0
# updatedReplicas is the number of replicas at the current/desired revision.
updatedReplicas: <int32> # required, minimum: 0
# availableReplicas is the number of available replicas. Populated for `Deployment` and
# `PodCliqueScalingGroup`; not available for `PodClique` or `LeaderWorkerSet`.
# availableReplicas: <int32> # minimum: 0
# componentNames is the list of underlying Kubernetes resource names for this Dynamo
# component. During normal operation this contains a single name; during rolling updates it
# contains both old and new resource names.
# componentNames:
# - "<string>"
# readyReplicas is the number of ready replicas. Populated for `PodClique`, `Deployment`, and
# `LeaderWorkerSet`; not available for `PodCliqueScalingGroup`.
# readyReplicas: <int32> # minimum: 0
# conditions contains the latest observed conditions of the graph deployment. Merged by type on
# patch updates.
conditions: # optional, listType: map, listMapKeys: type
- # lastTransitionTime is the last time the condition transitioned from one status to another.
# This should be when the underlying condition changed. If that is not known, then using the
# time when the API field changed is acceptable.
lastTransitionTime: "<string>" # required
# message is a human readable message indicating details about the transition. This may be an
# empty string.
message: "<string>" # required, maxLength: 32768
# reason contains a programmatic identifier indicating the reason for the condition's last
# transition. Producers of specific condition types may define expected values and meanings
# for this field, and whether the values are considered a guaranteed API. The value should be
# a CamelCase string. This field may not be empty.
reason: "<string>" # required, minLength: 1, maxLength: 1024
# status of the condition, one of True, False, Unknown.
status: "True" # required, enum: "False" | "Unknown"
# type of condition in CamelCase or in foo.example.com/CamelCase.
type: "<string>" # required, maxLength: 316
# observedGeneration represents the .metadata.generation that the condition was set based
# upon. For instance, if .metadata.generation is currently 12, but the
# .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to
# the current state of the instance.
# observedGeneration: <int64> # minimum: 0
# observedGeneration is the most recent generation observed by the controller.
# observedGeneration: <int64>
# restart contains the status of a graph-level restart.
# restart:
# inProgress contains the names of the components currently being restarted.
# inProgress:
# - "<string>"
# observedID is the restart ID currently being processed. Matches `Restart.id` in the spec.
# observedID: "<string>"
# phase is the phase of the restart.
# phase: "<string>"
# rollingUpdate tracks the progress of operator-managed rolling updates. Currently only supported
# for single-node, non-Grove deployments (DCD/Deployment).
# rollingUpdate:
# endTime is when the rolling update completed (successfully or failed).
# endTime: "<string>"
# phase indicates the current phase of the rolling update.
# phase: "Pending" # enum: "InProgress" | "Completed" | "Failed" | ""
# startTime is when the rolling update began.
# startTime: "<string>"
# updatedComponents is the list of components that have completed the rolling update.
# updatedComponents:
# - "<string>"
nvidia.com/v1alpha1
# DynamoGraphDeployment is the Schema for the dynamographdeployments API.
apiVersion: nvidia.com/v1alpha1
kind: DynamoGraphDeployment
metadata:
# Name must be unique within a namespace.
name: "<string>" # required
# Namespace defines the space within which each name must be unique.
namespace: "<string>" # required
# Annotations is an unstructured key value map stored with a resource.
# annotations:
# <key>: "<string>"
# CreationTimestamp is set by the server when a resource is created.
# creationTimestamp: "<string>"
# Number of seconds allowed for graceful deletion.
# deletionGracePeriodSeconds: <int64>
# DeletionTimestamp is set by the server when graceful deletion is requested.
# deletionTimestamp: "<string>"
# Finalizers must be empty before the object is deleted from the registry.
# finalizers:
# - "<string>"
# GenerateName is an optional prefix used by the server to generate a unique name.
# generateName: "<string>"
# Generation is a sequence number representing a specific desired state.
# generation: <int64>
# Labels are key value pairs used to organize and select objects.
# labels:
# <key>: "<string>"
# ManagedFields records which actor manages which fields.
# managedFields:
# - # APIVersion defines the version of this field set.
# apiVersion: "<string>"
# FieldsType is the discriminator for the fields format.
# fieldsType: "<string>"
# FieldsV1 stores a versioned field set.
# fieldsV1: {} # preserveUnknownFields
# Manager identifies the workflow managing these fields.
# manager: "<string>"
# Operation is the type of operation that produced this managedFields entry.
# operation: "<string>"
# Subresource is the name of the subresource used to update the object.
# subresource: "<string>"
# Time is when this managedFields entry was added.
# time: "<string>"
# OwnerReferences lists objects depended on by this object.
ownerReferences: # optional
- # API version of the referent.
apiVersion: "<string>" # required
# Kind of the referent.
kind: "<string>" # required
# Name of the referent.
name: "<string>" # required
# UID of the referent.
uid: "<string>" # required
# BlockOwnerDeletion controls foreground deletion behavior.
# blockOwnerDeletion: <boolean>
# Controller marks the managing controller owner reference.
# controller: <boolean>
# ResourceVersion is an opaque internal version value.
# resourceVersion: "<string>"
# SelfLink is a deprecated read-only field.
# selfLink: "<string>"
# UID is the unique in time and space value for this object.
# uid: "<string>"
# Spec defines the desired state for this graph deployment.
spec: # optional
# Annotations to propagate to all child resources (PCS, DCD, Deployments, and pod templates).
# Service-level annotations take precedence over these values.
# annotations:
# <key>: "<string>"
# BackendFramework specifies the backend framework (e.g., "sglang", "vllm", "trtllm").
# backendFramework: "sglang" # enum: "vllm" | "trtllm"
# Envs are environment variables applied to all services in the deployment unless overridden by
# service-specific configuration.
envs: # optional
- # Name of the environment variable. May consist of any printable ASCII characters except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined environment
# variables in the container and any service environment variables. If a variable cannot be
# resolved, the reference in the input string will be unchanged. Double $$ are reduced to a
# single $, which allows for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce
# the string literal "$(VAR_NAME)". Escaped references will never be expanded, regardless of
# whether the variable exists or not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value here
# are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to be
# enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from starting. The keys
# defined within a source may consist of any printable ASCII characters except '='. During
# Alpha stage of the EnvFiles feature gate, the key size is limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative and may not
# contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does not exist,
# then the env var is not published. If optional is set to true and the specified key does
# not exist, the environment variable will not be set in the Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error will be
# returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests (limits.cpu,
# limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and
# requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value here
# are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# Experimental groups graph-level preview features whose API shape and behavior may change in
# breaking ways between releases.
experimental: # optional
# KvTransferPolicy configures topology-aware routing for KV-cache transfers between prefill and
# decode workers.
kvTransferPolicy: # optional
# Domain is the logical name for the topology level to enforce (e.g. "zone", "rack"). The
# router uses this to match workers that share the same value for the label identified by
# `labelKey`.
domain: "<string>" # required
# Enforcement controls how the selected prefill worker's topology is applied to decode
# routing. "required" only allows decode workers in the same topology domain as the selected
# prefill worker. "preferred" keeps all decode workers eligible, but biases selection toward
# workers in the same topology domain. Defaults to "required".
# enforcement: "required" # default, enum: "preferred"
# LabelKey is a Kubernetes node label key (e.g. "topology.kubernetes.io/zone") whose value
# identifies the topology domain for each worker. The operator copies the node label onto
# worker pods so the runtime can publish it as worker metadata. The label should correspond to
# the topology level named in `domain`.
# labelKey: "<string>" # minLength: 1, maxLength: 317
# PreferredWeight is required and used only when enforcement is "preferred". Higher values
# create a stronger same-domain routing preference, but do not guarantee same-domain
# selection. The value is not a probability; worker selection still depends on load and other
# routing inputs. A value of 0 disables the topology preference; 1 is the strongest supported
# preference.
# preferredWeight: <number> # minimum: 0, maximum: 1
# Labels to propagate to all child resources (PCS, DCD, Deployments, and pod templates).
# Service-level labels take precedence over these values.
# labels:
# <key>: "<string>"
# PriorityClassName is the name of the PriorityClass to use for Grove PodCliqueSets. Requires the
# Grove pathway.
# priorityClassName: "<string>"
# PVCs defines a list of persistent volume claims that can be referenced by components. Each PVC
# must have a unique name that can be referenced in component specifications.
pvcs: # optional
- # Name is the name of the PVC
name: "<string>" # required
# Create indicates to create a new PVC
# create: <boolean>
# Size of the volume in Gi, used during PVC creation. Required when create is true.
# size: <int-or-string> # intOrString
# StorageClass to be used for PVC creation. Required when create is true.
# storageClass: "<string>"
# VolumeAccessMode is the volume access mode of the PVC. Required when create is true.
# volumeAccessMode: "<string>"
# Restart specifies the restart policy for the graph deployment.
restart: # optional
# ID is an arbitrary string that triggers a restart when changed. Any modification to this value
# will initiate a restart of the graph deployment according to the strategy.
id: "<string>" # required, minLength: 1
# Strategy specifies the restart strategy for the graph deployment.
# strategy:
# Order specifies the order in which the services should be restarted.
# order:
# - "<string>"
# Type specifies the restart strategy type.
# type: "Sequential" # default, enum: "Parallel"
# Services are the services to deploy as part of this deployment.
services: # optional
<key>: # optional
# Annotations to add to generated Kubernetes resources for this component (such as Pod,
# Service, and Ingress when applicable).
# annotations:
# <key>: "<string>"
# Deprecated: This field is deprecated and ignored. Use DynamoGraphDeploymentScalingAdapter
# with HPA, KEDA, or Planner for autoscaling instead. See docs/kubernetes/autoscaling.md for
# migration guidance. This field will be removed in a future API version.
autoscaling: # optional
# Deprecated: This field is ignored.
behavior: # optional
# scaleDown is scaling policy for scaling Down. If not set, the default value is to allow
# to scale down to minReplicas pods, with a 300 second stabilization window (i.e., the
# highest recommendation for the last 300sec is used).
scaleDown: # optional
# policies is a list of potential scaling polices which can be used during scaling. If
# not set, use the default values: - For scale up: allow doubling the number of pods, or
# an absolute change of 4 pods in a 15s window. - For scale down: allow all pods to be
# removed in a 15s window.
policies: # optional, listType: atomic
- # periodSeconds specifies the window of time for which the policy should hold true.
# PeriodSeconds must be greater than zero and less than or equal to 1800 (30 min).
periodSeconds: <int32> # required
# type is used to specify the scaling policy.
type: "<string>" # required
# value contains the amount of change which is permitted by the policy. It must be
# greater than zero
value: <int32> # required
# selectPolicy is used to specify which policy should be used. If not set, the default
# value Max is used.
# selectPolicy: "<string>"
# stabilizationWindowSeconds is the number of seconds for which past recommendations
# should be considered while scaling up or scaling down. StabilizationWindowSeconds must
# be greater than or equal to zero and less than or equal to 3600 (one hour). If not
# set, use the default values: - For scale up: 0 (i.e. no stabilization is done). - For
# scale down: 300 (i.e. the stabilization window is 300 seconds long).
# stabilizationWindowSeconds: <int32>
# tolerance is the tolerance on the ratio between the current and desired metric value
# under which no updates are made to the desired number of replicas (e.g. 0.01 for 1%).
# Must be greater than or equal to zero. If not set, the default cluster-wide tolerance
# is applied (by default 10%).
#
# For example, if autoscaling is configured with a memory consumption target of 100Mi,
# and scale-down and scale-up tolerances of 5% and 1% respectively, scaling will be
# triggered when the actual consumption falls below 95Mi or exceeds 101Mi.
#
# This is an alpha field and requires enabling the HPAConfigurableTolerance feature
# gate.
# tolerance: <int-or-string> # intOrString
# scaleUp is scaling policy for scaling Up. If not set, the default value is the higher
# of: * increase no more than 4 pods per 60 seconds * double the number of pods per 60
# seconds No stabilization is used.
scaleUp: # optional
# policies is a list of potential scaling polices which can be used during scaling. If
# not set, use the default values: - For scale up: allow doubling the number of pods, or
# an absolute change of 4 pods in a 15s window. - For scale down: allow all pods to be
# removed in a 15s window.
policies: # optional, listType: atomic
- # periodSeconds specifies the window of time for which the policy should hold true.
# PeriodSeconds must be greater than zero and less than or equal to 1800 (30 min).
periodSeconds: <int32> # required
# type is used to specify the scaling policy.
type: "<string>" # required
# value contains the amount of change which is permitted by the policy. It must be
# greater than zero
value: <int32> # required
# selectPolicy is used to specify which policy should be used. If not set, the default
# value Max is used.
# selectPolicy: "<string>"
# stabilizationWindowSeconds is the number of seconds for which past recommendations
# should be considered while scaling up or scaling down. StabilizationWindowSeconds must
# be greater than or equal to zero and less than or equal to 3600 (one hour). If not
# set, use the default values: - For scale up: 0 (i.e. no stabilization is done). - For
# scale down: 300 (i.e. the stabilization window is 300 seconds long).
# stabilizationWindowSeconds: <int32>
# tolerance is the tolerance on the ratio between the current and desired metric value
# under which no updates are made to the desired number of replicas (e.g. 0.01 for 1%).
# Must be greater than or equal to zero. If not set, the default cluster-wide tolerance
# is applied (by default 10%).
#
# For example, if autoscaling is configured with a memory consumption target of 100Mi,
# and scale-down and scale-up tolerances of 5% and 1% respectively, scaling will be
# triggered when the actual consumption falls below 95Mi or exceeds 101Mi.
#
# This is an alpha field and requires enabling the HPAConfigurableTolerance feature
# gate.
# tolerance: <int-or-string> # intOrString
# Deprecated: This field is ignored.
# enabled: <boolean>
# Deprecated: This field is ignored.
# maxReplicas: <integer>
# Deprecated: This field is ignored.
metrics: # optional
- # type is the type of metric source. It should be one of "ContainerResource",
# "External", "Object", "Pods" or "Resource", each mapping to a matching field in the
# object.
type: "<string>" # required
# containerResource refers to a resource metric (such as those specified in requests and
# limits) known to Kubernetes describing a single container in each pod of the current
# scale target (e.g. CPU or memory). Such metrics are built in to Kubernetes, and have
# special scaling options on top of those available to normal per-pod metrics using the
# "pods" source.
containerResource: # optional
# container is the name of the container in the pods of the scaling target
container: "<string>" # required
# name is the name of the resource in question.
name: "<string>" # required
# target specifies the target value for the given metric
target: # required
# type represents whether the metric type is Utilization, Value, or AverageValue
type: "<string>" # required
# averageUtilization is the target value of the average of the resource metric
# across all relevant pods, represented as a percentage of the requested value of
# the resource for the pods. Currently only valid for Resource metric source type
# averageUtilization: <int32>
# averageValue is the target value of the average of the metric across all relevant
# pods (as a quantity)
# averageValue: <int-or-string> # intOrString
# value is the target value of the metric (as a quantity).
# value: <int-or-string> # intOrString
# external refers to a global metric that is not associated with any Kubernetes object.
# It allows autoscaling based on information coming from components running outside of
# cluster (for example length of queue in cloud messaging service, or QPS from
# loadbalancer running outside of cluster).
external: # optional
# metric identifies the target metric by name and selector
metric: # required
# name is the name of the given metric
name: "<string>" # required
# selector is the string-encoded form of a standard kubernetes label selector for
# the given metric When set, it is passed as an additional parameter to the metrics
# server for more specific metrics scoping. When unset, just the metricName will be
# used to gather metrics.
selector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators
# are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key field
# is "key", the operator is "In", and the values array contains only "value". The
# requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# target specifies the target value for the given metric
target: # required
# type represents whether the metric type is Utilization, Value, or AverageValue
type: "<string>" # required
# averageUtilization is the target value of the average of the resource metric
# across all relevant pods, represented as a percentage of the requested value of
# the resource for the pods. Currently only valid for Resource metric source type
# averageUtilization: <int32>
# averageValue is the target value of the average of the metric across all relevant
# pods (as a quantity)
# averageValue: <int-or-string> # intOrString
# value is the target value of the metric (as a quantity).
# value: <int-or-string> # intOrString
# object refers to a metric describing a single kubernetes object (for example,
# hits-per-second on an Ingress object).
object: # optional
# describedObject specifies the descriptions of a object,such as kind,name apiVersion
describedObject: # required
# kind is the kind of the referent; More info:
# https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
kind: "<string>" # required
# name is the name of the referent; More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
name: "<string>" # required
# apiVersion is the API version of the referent
# apiVersion: "<string>"
# metric identifies the target metric by name and selector
metric: # required
# name is the name of the given metric
name: "<string>" # required
# selector is the string-encoded form of a standard kubernetes label selector for
# the given metric When set, it is passed as an additional parameter to the metrics
# server for more specific metrics scoping. When unset, just the metricName will be
# used to gather metrics.
selector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators
# are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key field
# is "key", the operator is "In", and the values array contains only "value". The
# requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# target specifies the target value for the given metric
target: # required
# type represents whether the metric type is Utilization, Value, or AverageValue
type: "<string>" # required
# averageUtilization is the target value of the average of the resource metric
# across all relevant pods, represented as a percentage of the requested value of
# the resource for the pods. Currently only valid for Resource metric source type
# averageUtilization: <int32>
# averageValue is the target value of the average of the metric across all relevant
# pods (as a quantity)
# averageValue: <int-or-string> # intOrString
# value is the target value of the metric (as a quantity).
# value: <int-or-string> # intOrString
# pods refers to a metric describing each pod in the current scale target (for example,
# transactions-processed-per-second). The values will be averaged together before being
# compared to the target value.
pods: # optional
# metric identifies the target metric by name and selector
metric: # required
# name is the name of the given metric
name: "<string>" # required
# selector is the string-encoded form of a standard kubernetes label selector for
# the given metric When set, it is passed as an additional parameter to the metrics
# server for more specific metrics scoping. When unset, just the metricName will be
# used to gather metrics.
selector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators
# are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key field
# is "key", the operator is "In", and the values array contains only "value". The
# requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# target specifies the target value for the given metric
target: # required
# type represents whether the metric type is Utilization, Value, or AverageValue
type: "<string>" # required
# averageUtilization is the target value of the average of the resource metric
# across all relevant pods, represented as a percentage of the requested value of
# the resource for the pods. Currently only valid for Resource metric source type
# averageUtilization: <int32>
# averageValue is the target value of the average of the metric across all relevant
# pods (as a quantity)
# averageValue: <int-or-string> # intOrString
# value is the target value of the metric (as a quantity).
# value: <int-or-string> # intOrString
# resource refers to a resource metric (such as those specified in requests and limits)
# known to Kubernetes describing each pod in the current scale target (e.g. CPU or
# memory). Such metrics are built in to Kubernetes, and have special scaling options on
# top of those available to normal per-pod metrics using the "pods" source.
resource: # optional
# name is the name of the resource in question.
name: "<string>" # required
# target specifies the target value for the given metric
target: # required
# type represents whether the metric type is Utilization, Value, or AverageValue
type: "<string>" # required
# averageUtilization is the target value of the average of the resource metric
# across all relevant pods, represented as a percentage of the requested value of
# the resource for the pods. Currently only valid for Resource metric source type
# averageUtilization: <int32>
# averageValue is the target value of the average of the metric across all relevant
# pods (as a quantity)
# averageValue: <int-or-string> # intOrString
# value is the target value of the metric (as a quantity).
# value: <int-or-string> # intOrString
# Deprecated: This field is ignored.
# minReplicas: <integer>
# Checkpoint configures container checkpointing for this service. When enabled, pods can be
# restored from a checkpoint files for faster cold start.
checkpoint: # optional
# CheckpointRef references an existing DynamoCheckpoint CR by metadata.name. If specified,
# this service's Identity is ignored and the referenced checkpoint is used directly.
# checkpointRef: "<string>"
# Enabled indicates whether checkpointing is enabled for this service
# enabled: false # default
# Deprecated: Identity is ignored by DGD-managed automatic checkpoints. Automatic
# checkpoints are scoped to the owning DGD/component generation and are never reused across
# DGDs.
identity: # optional
# BackendFramework is the runtime framework (vllm, sglang, trtllm)
backendFramework: "vllm" # required, enum: "sglang" | "trtllm"
# Model is the model identifier (e.g., "meta-llama/Llama-3-70B")
model: "<string>" # required
# Dtype is the data type (fp16, bf16, fp8, etc.). Deprecated for DGD-managed automatic
# checkpoints; it only participates in the legacy identity hash fallback for standalone
# objects.
# dtype: "<string>"
# DynamoVersion is the Dynamo platform version (optional). Deprecated for DGD-managed
# automatic checkpoints; it only participates in the legacy identity hash fallback for
# standalone objects.
# dynamoVersion: "<string>"
# ExtraParameters are additional parameters that affect the checkpoint hash. Use for any
# framework-specific or custom parameters not covered above. Deprecated for DGD-managed
# automatic checkpoints; it only participates in the legacy identity hash fallback for
# standalone objects.
# extraParameters:
# <key>: "<string>"
# MaxModelLen is the maximum sequence length. Deprecated for DGD-managed automatic
# checkpoints; it only participates in the legacy identity hash fallback for standalone
# objects.
# maxModelLen: <int32> # minimum: 1
# PipelineParallelSize is the pipeline parallel configuration. Deprecated for DGD-managed
# automatic checkpoints; it only participates in the legacy identity hash fallback for
# standalone objects.
# pipelineParallelSize: 1 # default, minimum: 1
# TensorParallelSize is the tensor parallel configuration. Deprecated for DGD-managed
# automatic checkpoints; it only participates in the legacy identity hash fallback for
# standalone objects.
# tensorParallelSize: 1 # default, minimum: 1
# Job customizes the checkpoint Job that is created in Auto mode.
# job:
# GMSClientContainers lists checkpoint Job containers that should receive GMS client
# wiring. Requires gpuMemoryService on the service.
# gmsClientContainers: # listType: set
# - "<string>"
# PodTemplate customizes the checkpoint Job pod. The operator starts from the selected
# workload container and merges this template so users can add helper containers such as
# gms-saver.
# podTemplate: {} # preserveUnknownFields
# Mode defines how checkpoint creation is handled - Auto: DGD controller creates Checkpoint
# CR automatically - Manual: User must create Checkpoint CR
# mode: "Auto" # default, enum: "Manual"
# TargetContainerName is the workload container to snapshot and restore.
# targetContainerName: "main" # default, minLength: 1, maxLength: 63
# ComponentType indicates the role of this component (for example, "main").
# componentType: "<string>"
# DynamoNamespace is deprecated and will be removed in a future version. The DGD Kubernetes
# namespace and DynamoGraphDeployment name are used to construct the Dynamo namespace for each
# component
# dynamoNamespace: "<string>"
# EnvFromSecret references a Secret whose key/value pairs will be exposed as environment
# variables in the component containers.
# envFromSecret: "<string>"
# Envs defines additional environment variables to inject into the component containers.
envs: # optional
- # Name of the environment variable. May consist of any printable ASCII characters except
# '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined environment
# variables in the container and any service environment variables. If a variable cannot
# be resolved, the reference in the input string will be unchanged. Double $$ are reduced
# to a single $, which allows for escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)"
# will produce the string literal "$(VAR_NAME)". Escaped references will never be
# expanded, regardless of whether the variable exists or not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to be
# enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from starting. The
# keys defined within a source may consist of any printable ASCII characters except
# '='. During Alpha stage of the EnvFiles feature gate, the key size is limited to 128
# characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative and may
# not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does not
# exist, then the env var is not published. If optional is set to true and the
# specified key does not exist, the environment variable will not be set in the Pod's
# containers.
#
# If optional is set to false and the specified key does not exist, an error will be
# returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests (limits.cpu,
# limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and
# requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# EPPConfig defines EPP-specific configuration options for Endpoint Picker Plugin components.
# Only applicable when ComponentType is "epp".
eppConfig: # optional
# Config allows specifying EPP EndpointPickerConfig directly as a structured object. The
# operator will marshal this to YAML and create a ConfigMap automatically. Mutually
# exclusive with ConfigMapRef. One of ConfigMapRef or Config must be specified (no default
# configuration). Uses the upstream type from
# github.com/kubernetes-sigs/gateway-api-inference-extension
config: # optional, preserveUnknownFields
# Plugins is the list of plugins that will be instantiated.
plugins: # required
- # Type specifies the plugin type to be instantiated.
type: "<string>" # required
# Name provides a name for plugin entries to reference. If omitted, the value of the
# Plugin's Type field will be used.
# name: "<string>"
# Parameters are the set of parameters to be passed to the plugin's factory function.
# The factory function is responsible to parse the parameters.
# parameters: {} # preserveUnknownFields
# SchedulingProfiles is the list of named SchedulingProfiles that will be created.
schedulingProfiles: # required
- # Name specifies the name of this SchedulingProfile
name: "<string>" # required
# Plugins is the list of plugins for this SchedulingProfile. They are assigned to the
# appropriate "slots" based on their type.
plugins: # required
- # PluginRef specifies a partiular Plugin instance to be associated with this
# SchedulingProfile. The reference is to the name of an entry of the Plugins
# defined in the configuration's Plugins section
pluginRef: "<string>" # required
# Weight is the weight fo be used if this plugin is a Scorer.
# weight: <integer>
# APIVersion defines the versioned schema of this representation of an object. Servers
# should convert recognized schemas to the latest internal value, and may reject
# unrecognized values. More info:
# https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
# apiVersion: "<string>"
# FeatureGates is a set of flags that enable various experimental features with the EPP.
# If omitted non of these experimental features will be enabled.
# featureGates:
# - "<string>"
# Kind is a string value representing the REST resource this object represents. Servers
# may infer this from the endpoint the client submits requests to. Cannot be updated. In
# CamelCase. More info:
# https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
# kind: "<string>"
# SaturationDetector when present specifies the configuration of the Saturation detector.
# If not present, default values are used.
# saturationDetector:
# KVCacheUtilThreshold defines the KV cache utilization (0.0 to 1.0) above which a pod
# is considered to have insufficient capacity.
# kvCacheUtilThreshold: <number>
# MetricsStalenessThreshold defines how old a pod's metrics can be. If a pod's metrics
# are older than this, it might be excluded from "good capacity" considerations or
# treated as having no capacity for safety.
# metricsStalenessThreshold: "<string>"
# QueueDepthThreshold defines the backend waiting queue size above which a pod is
# considered to have insufficient capacity for new requests.
# queueDepthThreshold: <integer>
# ConfigMapRef references a user-provided ConfigMap containing EPP configuration. The
# ConfigMap should contain EndpointPickerConfig YAML. Mutually exclusive with Config.
configMapRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value here
# are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# ExtraPodMetadata adds labels/annotations to the created Pods.
# extraPodMetadata:
# annotations:
# <key>: "<string>"
# labels:
# <key>: "<string>"
# ExtraPodSpec allows to override the main pod spec configuration. It is a k8s standard
# PodSpec. It also contains a MainContainer (standard k8s Container) field that allows
# overriding the main container configuration.
extraPodSpec: # optional
# Optional duration in seconds the pod may be active on the node relative to StartTime
# before the system will actively try to mark it failed and kill associated containers.
# Value must be a positive integer.
# activeDeadlineSeconds: <int64>
# If specified, the pod's scheduling constraints
affinity: # optional
# Describes node affinity scheduling rules for the pod.
nodeAffinity: # optional
# The scheduler will prefer to schedule pods to nodes that satisfy the affinity
# expressions specified by this field, but it may choose a node that violates one or
# more of the expressions. The node that is most preferred is the one with the greatest
# sum of weights, i.e. for each node that meets all of the scheduling requirements
# (resource request, requiredDuringScheduling affinity expressions, etc.), compute a sum
# by iterating through the elements of this field and adding "weight" to the sum if the
# node matches the corresponding matchExpressions; the node(s) with the highest sum are
# the most preferred.
preferredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # A node selector term, associated with the corresponding weight.
preference: # required, mapType: atomic
# A list of node selector requirements by node's labels.
matchExpressions: # optional, listType: atomic
- # The label key that the selector applies to.
key: "<string>" # required
# Represents a key's relationship to a set of values. Valid operators are In,
# NotIn, Exists, DoesNotExist. Gt, and Lt.
operator: "<string>" # required
# An array of string values. If the operator is In or NotIn, the values array
# must be non-empty. If the operator is Exists or DoesNotExist, the values
# array must be empty. If the operator is Gt or Lt, the values array must have
# a single element, which will be interpreted as an integer. This array is
# replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# A list of node selector requirements by node's fields.
matchFields: # optional, listType: atomic
- # The label key that the selector applies to.
key: "<string>" # required
# Represents a key's relationship to a set of values. Valid operators are In,
# NotIn, Exists, DoesNotExist. Gt, and Lt.
operator: "<string>" # required
# An array of string values. If the operator is In or NotIn, the values array
# must be non-empty. If the operator is Exists or DoesNotExist, the values
# array must be empty. If the operator is Gt or Lt, the values array must have
# a single element, which will be interpreted as an integer. This array is
# replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# Weight associated with matching the corresponding nodeSelectorTerm, in the range
# 1-100.
weight: <int32> # required
# If the affinity requirements specified by this field are not met at scheduling time,
# the pod will not be scheduled onto the node. If the affinity requirements specified by
# this field cease to be met at some point during pod execution (e.g. due to an update),
# the system may or may not try to eventually evict the pod from its node.
requiredDuringSchedulingIgnoredDuringExecution: # optional, mapType: atomic
# Required. A list of node selector terms. The terms are ORed.
nodeSelectorTerms: # required, listType: atomic
- # A list of node selector requirements by node's labels.
matchExpressions: # optional, listType: atomic
- # The label key that the selector applies to.
key: "<string>" # required
# Represents a key's relationship to a set of values. Valid operators are In,
# NotIn, Exists, DoesNotExist. Gt, and Lt.
operator: "<string>" # required
# An array of string values. If the operator is In or NotIn, the values array
# must be non-empty. If the operator is Exists or DoesNotExist, the values
# array must be empty. If the operator is Gt or Lt, the values array must have
# a single element, which will be interpreted as an integer. This array is
# replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# A list of node selector requirements by node's fields.
matchFields: # optional, listType: atomic
- # The label key that the selector applies to.
key: "<string>" # required
# Represents a key's relationship to a set of values. Valid operators are In,
# NotIn, Exists, DoesNotExist. Gt, and Lt.
operator: "<string>" # required
# An array of string values. If the operator is In or NotIn, the values array
# must be non-empty. If the operator is Exists or DoesNotExist, the values
# array must be empty. If the operator is Gt or Lt, the values array must have
# a single element, which will be interpreted as an integer. This array is
# replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# Describes pod affinity scheduling rules (e.g. co-locate this pod in the same node, zone,
# etc. as some other pod(s)).
podAffinity: # optional
# The scheduler will prefer to schedule pods to nodes that satisfy the affinity
# expressions specified by this field, but it may choose a node that violates one or
# more of the expressions. The node that is most preferred is the one with the greatest
# sum of weights, i.e. for each node that meets all of the scheduling requirements
# (resource request, requiredDuringScheduling affinity expressions, etc.), compute a sum
# by iterating through the elements of this field and adding "weight" to the sum if the
# node has pods which matches the corresponding podAffinityTerm; the node(s) with the
# highest sum are the most preferred.
preferredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # Required. A pod affinity term, associated with the corresponding weight.
podAffinityTerm: # required
# This pod should be co-located (affinity) or not co-located (anti-affinity) with
# the pods matching the labelSelector in the specified namespaces, where
# co-located is defined as running on a node whose value of the label with key
# topologyKey matches that of any node on which any of the selected pods is
# running. Empty topologyKey is not allowed.
topologyKey: "<string>" # required
# A label query over a set of resources, in this case pods. If it's null, this
# PodAffinityTerm matches with no Pods.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key in
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist
# in the incoming pod labels will be ignored. The default value is empty. The same
# key is forbidden to exist in both matchLabelKeys and labelSelector. Also,
# matchLabelKeys cannot be set when labelSelector isn't set.
# matchLabelKeys: # listType: atomic
# - "<string>"
# MismatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key notin
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist
# in the incoming pod labels will be ignored. The default value is empty. The same
# key is forbidden to exist in both mismatchLabelKeys and labelSelector. Also,
# mismatchLabelKeys cannot be set when labelSelector isn't set.
# mismatchLabelKeys: # listType: atomic
# - "<string>"
# A label query over the set of namespaces that the term applies to. The term is
# applied to the union of the namespaces selected by this field and the ones
# listed in the namespaces field. null selector and null or empty namespaces list
# means "this pod's namespace". An empty selector ({}) matches all namespaces.
namespaceSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# namespaces specifies a static list of namespace names that the term applies to.
# The term is applied to the union of the namespaces listed in this field and the
# ones selected by namespaceSelector. null or empty namespaces list and null
# namespaceSelector means "this pod's namespace".
# namespaces: # listType: atomic
# - "<string>"
# weight associated with matching the corresponding podAffinityTerm, in the range
# 1-100.
weight: <int32> # required
# If the affinity requirements specified by this field are not met at scheduling time,
# the pod will not be scheduled onto the node. If the affinity requirements specified by
# this field cease to be met at some point during pod execution (e.g. due to a pod label
# update), the system may or may not try to eventually evict the pod from its node. When
# there are multiple elements, the lists of nodes corresponding to each podAffinityTerm
# are intersected, i.e. all terms must be satisfied.
requiredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # This pod should be co-located (affinity) or not co-located (anti-affinity) with
# the pods matching the labelSelector in the specified namespaces, where co-located
# is defined as running on a node whose value of the label with key topologyKey
# matches that of any node on which any of the selected pods is running. Empty
# topologyKey is not allowed.
topologyKey: "<string>" # required
# A label query over a set of resources, in this case pods. If it's null, this
# PodAffinityTerm matches with no Pods.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators
# are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key field
# is "key", the operator is "In", and the values array contains only "value". The
# requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select which pods will be taken into
# consideration. The keys are used to lookup values from the incoming pod labels,
# those key-value labels are merged with `labelSelector` as `key in (value)` to
# select the group of existing pods which pods will be taken into consideration for
# the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming pod
# labels will be ignored. The default value is empty. The same key is forbidden to
# exist in both matchLabelKeys and labelSelector. Also, matchLabelKeys cannot be set
# when labelSelector isn't set.
# matchLabelKeys: # listType: atomic
# - "<string>"
# MismatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key notin
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist in
# the incoming pod labels will be ignored. The default value is empty. The same key
# is forbidden to exist in both mismatchLabelKeys and labelSelector. Also,
# mismatchLabelKeys cannot be set when labelSelector isn't set.
# mismatchLabelKeys: # listType: atomic
# - "<string>"
# A label query over the set of namespaces that the term applies to. The term is
# applied to the union of the namespaces selected by this field and the ones listed
# in the namespaces field. null selector and null or empty namespaces list means
# "this pod's namespace". An empty selector ({}) matches all namespaces.
namespaceSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators
# are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key field
# is "key", the operator is "In", and the values array contains only "value". The
# requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# namespaces specifies a static list of namespace names that the term applies to.
# The term is applied to the union of the namespaces listed in this field and the
# ones selected by namespaceSelector. null or empty namespaces list and null
# namespaceSelector means "this pod's namespace".
# namespaces: # listType: atomic
# - "<string>"
# Describes pod anti-affinity scheduling rules (e.g. avoid putting this pod in the same
# node, zone, etc. as some other pod(s)).
podAntiAffinity: # optional
# The scheduler will prefer to schedule pods to nodes that satisfy the anti-affinity
# expressions specified by this field, but it may choose a node that violates one or
# more of the expressions. The node that is most preferred is the one with the greatest
# sum of weights, i.e. for each node that meets all of the scheduling requirements
# (resource request, requiredDuringScheduling anti-affinity expressions, etc.), compute
# a sum by iterating through the elements of this field and subtracting "weight" from
# the sum if the node has pods which matches the corresponding podAffinityTerm; the
# node(s) with the highest sum are the most preferred.
preferredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # Required. A pod affinity term, associated with the corresponding weight.
podAffinityTerm: # required
# This pod should be co-located (affinity) or not co-located (anti-affinity) with
# the pods matching the labelSelector in the specified namespaces, where
# co-located is defined as running on a node whose value of the label with key
# topologyKey matches that of any node on which any of the selected pods is
# running. Empty topologyKey is not allowed.
topologyKey: "<string>" # required
# A label query over a set of resources, in this case pods. If it's null, this
# PodAffinityTerm matches with no Pods.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key in
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist
# in the incoming pod labels will be ignored. The default value is empty. The same
# key is forbidden to exist in both matchLabelKeys and labelSelector. Also,
# matchLabelKeys cannot be set when labelSelector isn't set.
# matchLabelKeys: # listType: atomic
# - "<string>"
# MismatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key notin
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist
# in the incoming pod labels will be ignored. The default value is empty. The same
# key is forbidden to exist in both mismatchLabelKeys and labelSelector. Also,
# mismatchLabelKeys cannot be set when labelSelector isn't set.
# mismatchLabelKeys: # listType: atomic
# - "<string>"
# A label query over the set of namespaces that the term applies to. The term is
# applied to the union of the namespaces selected by this field and the ones
# listed in the namespaces field. null selector and null or empty namespaces list
# means "this pod's namespace". An empty selector ({}) matches all namespaces.
namespaceSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# namespaces specifies a static list of namespace names that the term applies to.
# The term is applied to the union of the namespaces listed in this field and the
# ones selected by namespaceSelector. null or empty namespaces list and null
# namespaceSelector means "this pod's namespace".
# namespaces: # listType: atomic
# - "<string>"
# weight associated with matching the corresponding podAffinityTerm, in the range
# 1-100.
weight: <int32> # required
# If the anti-affinity requirements specified by this field are not met at scheduling
# time, the pod will not be scheduled onto the node. If the anti-affinity requirements
# specified by this field cease to be met at some point during pod execution (e.g. due
# to a pod label update), the system may or may not try to eventually evict the pod from
# its node. When there are multiple elements, the lists of nodes corresponding to each
# podAffinityTerm are intersected, i.e. all terms must be satisfied.
requiredDuringSchedulingIgnoredDuringExecution: # optional, listType: atomic
- # This pod should be co-located (affinity) or not co-located (anti-affinity) with
# the pods matching the labelSelector in the specified namespaces, where co-located
# is defined as running on a node whose value of the label with key topologyKey
# matches that of any node on which any of the selected pods is running. Empty
# topologyKey is not allowed.
topologyKey: "<string>" # required
# A label query over a set of resources, in this case pods. If it's null, this
# PodAffinityTerm matches with no Pods.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators
# are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key field
# is "key", the operator is "In", and the values array contains only "value". The
# requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select which pods will be taken into
# consideration. The keys are used to lookup values from the incoming pod labels,
# those key-value labels are merged with `labelSelector` as `key in (value)` to
# select the group of existing pods which pods will be taken into consideration for
# the incoming pod's pod (anti) affinity. Keys that don't exist in the incoming pod
# labels will be ignored. The default value is empty. The same key is forbidden to
# exist in both matchLabelKeys and labelSelector. Also, matchLabelKeys cannot be set
# when labelSelector isn't set.
# matchLabelKeys: # listType: atomic
# - "<string>"
# MismatchLabelKeys is a set of pod label keys to select which pods will be taken
# into consideration. The keys are used to lookup values from the incoming pod
# labels, those key-value labels are merged with `labelSelector` as `key notin
# (value)` to select the group of existing pods which pods will be taken into
# consideration for the incoming pod's pod (anti) affinity. Keys that don't exist in
# the incoming pod labels will be ignored. The default value is empty. The same key
# is forbidden to exist in both mismatchLabelKeys and labelSelector. Also,
# mismatchLabelKeys cannot be set when labelSelector isn't set.
# mismatchLabelKeys: # listType: atomic
# - "<string>"
# A label query over the set of namespaces that the term applies to. The term is
# applied to the union of the namespaces selected by this field and the ones listed
# in the namespaces field. null selector and null or empty namespaces list means
# "this pod's namespace". An empty selector ({}) matches all namespaces.
namespaceSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators
# are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key field
# is "key", the operator is "In", and the values array contains only "value". The
# requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# namespaces specifies a static list of namespace names that the term applies to.
# The term is applied to the union of the namespaces listed in this field and the
# ones selected by namespaceSelector. null or empty namespaces list and null
# namespaceSelector means "this pod's namespace".
# namespaces: # listType: atomic
# - "<string>"
# AutomountServiceAccountToken indicates whether a service account token should be
# automatically mounted.
# automountServiceAccountToken: <boolean>
# List of containers belonging to the pod. Containers cannot currently be added or removed.
# There must be at least one container in a Pod. Cannot be updated.
containers: # optional, listType: map, listMapKeys: name
- # Name of the container specified as a DNS_LABEL. Each container in a pod must have a
# unique name (DNS_LABEL). Cannot be updated.
name: "<string>" # required
# Arguments to the entrypoint. The container image's CMD is used if this is not
# provided. Variable references $(VAR_NAME) are expanded using the container's
# environment. If a variable cannot be resolved, the reference in the input string will
# be unchanged. Double $$ are reduced to a single $, which allows for escaping the
# $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)".
# Escaped references will never be expanded, regardless of whether the variable exists
# or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# args: # listType: atomic
# - "<string>"
# Entrypoint array. Not executed within a shell. The container image's ENTRYPOINT is
# used if this is not provided. Variable references $(VAR_NAME) are expanded using the
# container's environment. If a variable cannot be resolved, the reference in the input
# string will be unchanged. Double $$ are reduced to a single $, which allows for
# escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal
# "$(VAR_NAME)". Escaped references will never be expanded, regardless of whether the
# variable exists or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# command: # listType: atomic
# - "<string>"
# List of environment variables to set in the container. Cannot be updated.
env: # optional, listType: map, listMapKeys: name
- # Name of the environment variable. May consist of any printable ASCII characters
# except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined
# environment variables in the container and any service environment variables. If a
# variable cannot be resolved, the reference in the input string will be unchanged.
# Double $$ are reduced to a single $, which allows for escaping the $(VAR_NAME)
# syntax: i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped
# references will never be expanded, regardless of whether the variable exists or
# not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to
# be enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from
# starting. The keys defined within a source may consist of any printable ASCII
# characters except '='. During Alpha stage of the EnvFiles feature gate, the
# key size is limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative and
# may not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does
# not exist, then the env var is not published. If optional is set to true and
# the specified key does not exist, the environment variable will not be set in
# the Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error
# will be returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
# requests.memory and requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# List of sources to populate environment variables in the container. The keys defined
# within a source may consist of any printable ASCII characters except '='. When a key
# exists in multiple sources, the value associated with the last source will take
# precedence. Values defined by an Env with a duplicate key will take precedence. Cannot
# be updated.
# envFrom: # listType: atomic
# - # The ConfigMap to select from
# configMapRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap must be defined
# optional: <boolean>
# Optional text to prepend to the name of each environment variable. May consist of
# any printable ASCII characters except '='.
# prefix: "<string>"
# The Secret to select from
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret must be defined
# optional: <boolean>
# Container image name. More info: https://kubernetes.io/docs/concepts/containers/images
# This field is optional to allow higher level config management to default or override
# container images in workload controllers like Deployments and StatefulSets.
# image: "<string>"
# Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if :latest
# tag is specified, or IfNotPresent otherwise. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/containers/images#updating-images
# imagePullPolicy: "<string>"
# Actions that the management system should take in response to container lifecycle
# events. Cannot be updated.
lifecycle: # optional
# PostStart is called immediately after a container is created. If the handler fails,
# the container is terminated and restarted according to its restart policy. Other
# management of the container blocks until the hook completes. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
postStart: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for backward
# compatibility. There is no validation of this field and lifecycle hooks will fail
# at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# PreStop is called immediately before a container is terminated due to an API request
# or management event such as liveness/startup probe failure, preemption, resource
# contention, etc. The handler is not called if the container crashes or exits. The
# Pod's termination grace period countdown begins before the PreStop hook is executed.
# Regardless of the outcome of the handler, the container will eventually terminate
# within the Pod's termination grace period (unless delayed by finalizers). Other
# management of the container blocks until the hook completes or until the termination
# grace period is reached. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
preStop: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for backward
# compatibility. There is no validation of this field and lifecycle hooks will fail
# at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# StopSignal defines which signal will be sent to a container when it is being
# stopped. If not specified, the default is defined by the container runtime in use.
# StopSignal can only be set for Pods with a non-empty .spec.os.name
# stopSignal: "<string>"
# Periodic probe of container liveness. Container will be restarted if the probe fails.
# Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
livenessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# List of ports to expose from the container. Not specifying a port here DOES NOT
# prevent that port from being exposed. Any port which is listening on the default
# "0.0.0.0" address inside a container will be accessible from the network. Modifying
# this array with strategic merge patch may corrupt the data. For more information See
# https://github.com/kubernetes/kubernetes/issues/108255. Cannot be updated.
ports: # optional, listType: map, listMapKeys: containerPort, protocol
- # Number of port to expose on the pod's IP address. This must be a valid port
# number, 0 < x < 65536.
containerPort: <int32> # required
# What host IP to bind the external port to.
# hostIP: "<string>"
# Number of port to expose on the host. If specified, this must be a valid port
# number, 0 < x < 65536. If HostNetwork is specified, this must match ContainerPort.
# Most containers do not need this.
# hostPort: <int32>
# If specified, this must be an IANA_SVC_NAME and unique within the pod. Each named
# port in a pod must have a unique name. Name for the port that can be referred to
# by services.
# name: "<string>"
# Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
# protocol: "TCP" # default
# Periodic probe of container service readiness. Container will be removed from service
# endpoints if the probe fails. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
readinessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Resources resize policy for the container.
resizePolicy: # optional, listType: atomic
- # Name of the resource to which this resource resize policy applies. Supported
# values: cpu, memory.
resourceName: "<string>" # required
# Restart policy to apply when specified resource is resized. If not specified, it
# defaults to NotRequired.
restartPolicy: "<string>" # required
# Compute Resources required by this container. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used
# by this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod
# where this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests is
# omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More
# info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# RestartPolicy defines the restart behavior of individual containers in a pod. This
# overrides the pod-level restart policy. When this field is not specified, the restart
# behavior is defined by the Pod's restart policy and the container type. Additionally,
# setting the RestartPolicy as "Always" for the init container will have the following
# effect: this init container will be continually restarted on exit until all regular
# containers have terminated. Once all regular containers have completed, all init
# containers with restartPolicy "Always" will be shut down. This lifecycle differs from
# normal init containers and is often referred to as a "sidecar" container. Although
# this init container still starts in the init container sequence, it does not wait for
# the container to complete before proceeding to the next init container. Instead, the
# next init container starts immediately after this init container is started, or after
# any startupProbe has successfully completed.
# restartPolicy: "<string>"
# Represents a list of rules to be checked to determine if the container should be
# restarted on exit. The rules are evaluated in order. Once a rule matches a container
# exit condition, the remaining rules are ignored. If no rule matches the container exit
# condition, the Container-level restart policy determines the whether the container is
# restarted or not. Constraints on the rules: - At most 20 rules are allowed. - Rules
# can have the same action. - Identical rules are not forbidden in validations. When
# rules are specified, container MUST set RestartPolicy explicitly even it if matches
# the Pod's RestartPolicy.
restartPolicyRules: # optional, listType: atomic
- # Specifies the action taken on a container exit if the requirements are satisfied.
# The only possible value is "Restart" to restart the container.
action: "<string>" # required
# Represents the exit codes to check on container exits.
exitCodes: # optional
# Represents the relationship between the container exit code(s) and the specified
# values. Possible values are: - In: the requirement is satisfied if the container
# exit code is in the set of specified values. - NotIn: the requirement is
# satisfied if the container exit code is not in the set of specified values.
operator: "<string>" # required
# Specifies the set of values to check for container exit codes. At most 255
# elements are allowed.
# values: # listType: set
# - <int32>
# SecurityContext defines the security options the container should be run with. If set,
# the fields of SecurityContext override the equivalent fields of PodSecurityContext.
# More info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
securityContext: # optional
# AllowPrivilegeEscalation controls whether a process can gain more privileges than
# its parent process. This bool directly controls if the no_new_privs flag will be set
# on the container process. AllowPrivilegeEscalation is true always when the container
# is: 1) run as Privileged 2) has CAP_SYS_ADMIN Note that this field cannot be set
# when spec.os.name is windows.
# allowPrivilegeEscalation: <boolean>
# appArmorProfile is the AppArmor options to use by this container. If set, this
# profile overrides the pod's appArmorProfile. Note that this field cannot be set when
# spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options are:
# Localhost - a profile pre-loaded on the node. RuntimeDefault - the container
# runtime's default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of
# the profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# The capabilities to add/drop when running containers. Defaults to the default set of
# capabilities granted by the container runtime. Note that this field cannot be set
# when spec.os.name is windows.
# capabilities:
# Added capabilities
# add: # listType: atomic
# - "<string>"
# Removed capabilities
# drop: # listType: atomic
# - "<string>"
# Run container in privileged mode. Processes in privileged containers are essentially
# equivalent to root on the host. Defaults to false. Note that this field cannot be
# set when spec.os.name is windows.
# privileged: <boolean>
# procMount denotes the type of proc mount to use for the containers. The default
# value is Default which uses the container runtime defaults for readonly paths and
# masked paths. This requires the ProcMountType feature flag to be enabled. Note that
# this field cannot be set when spec.os.name is windows.
# procMount: "<string>"
# Whether this container has a read-only root filesystem. Default is false. Note that
# this field cannot be set when spec.os.name is windows.
# readOnlyRootFilesystem: <boolean>
# The GID to run the entrypoint of the container process. Uses runtime default if
# unset. May also be set in PodSecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet will
# validate the image at runtime to ensure that it does not run as UID 0 (root) and
# fail to start the container if it does. If unset or false, no such validation will
# be performed. May also be set in PodSecurityContext. If set in both SecurityContext
# and PodSecurityContext, the value specified in SecurityContext takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified
# in image metadata if unspecified. May also be set in PodSecurityContext. If set in
# both SecurityContext and PodSecurityContext, the value specified in SecurityContext
# takes precedence. Note that this field cannot be set when spec.os.name is windows.
# runAsUser: <int64>
# The SELinux context to be applied to the container. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set
# in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence. Note that this field cannot be
# set when spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by this container. If seccomp options are provided at
# both the pod & container level, the container options override the pod options. Note
# that this field cannot be set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used. RuntimeDefault
# - the container runtime default profile should be used. Unconfined - no profile
# should be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be used.
# The profile must be preconfigured on the node to work. Must be a descending path,
# relative to the kubelet's configured seccomp profile location. Must be set if type
# is "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# The Windows specific settings applied to all containers. If unspecified, the options
# from the PodSecurityContext will be used. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the GMSA
# credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process' container.
# All of a Pod's containers must have the same effective HostProcess value (it is
# not allowed to have a mix of HostProcess containers and non-HostProcess
# containers). In addition, if HostProcess is true then HostNetwork must also be set
# to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults
# to the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# StartupProbe indicates that the Pod has successfully initialized. If specified, no
# other probes are executed until this completes successfully. If this probe fails, the
# Pod will be restarted, just as if the livenessProbe failed. This can be used to
# provide different probe parameters at the beginning of a Pod's lifecycle, when it
# might take a long time to load data or warm a cache, than during steady-state
# operation. This cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
startupProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Whether this container should allocate a buffer for stdin in the container runtime. If
# this is not set, reads from stdin in the container will always result in EOF. Default
# is false.
# stdin: <boolean>
# Whether the container runtime should close the stdin channel after it has been opened
# by a single attach. When stdin is true the stdin stream will remain open across
# multiple attach sessions. If stdinOnce is set to true, stdin is opened on container
# start, is empty until the first client attaches to stdin, and then remains open and
# accepts data until the client disconnects, at which time stdin is closed and remains
# closed until the container is restarted. If this flag is false, a container processes
# that reads from stdin will never receive an EOF. Default is false
# stdinOnce: <boolean>
# Optional: Path at which the file to which the container's termination message will be
# written is mounted into the container's filesystem. Message written is intended to be
# brief final status, such as an assertion failure message. Will be truncated by the
# node if greater than 4096 bytes. The total message length across all containers will
# be limited to 12kb. Defaults to /dev/termination-log. Cannot be updated.
# terminationMessagePath: "<string>"
# Indicate how the termination message should be populated. File will use the contents
# of terminationMessagePath to populate the container status message on both success and
# failure. FallbackToLogsOnError will use the last chunk of container log output if the
# termination message file is empty and the container exited with an error. The log
# output is limited to 2048 bytes or 80 lines, whichever is smaller. Defaults to File.
# Cannot be updated.
# terminationMessagePolicy: "<string>"
# Whether this container should allocate a TTY for itself, also requires 'stdin' to be
# true. Default is false.
# tty: <boolean>
# volumeDevices is the list of block devices to be used by the container.
volumeDevices: # optional, listType: map, listMapKeys: devicePath
- # devicePath is the path inside of the container that the device will be mapped to.
devicePath: "<string>" # required
# name must match the name of a persistentVolumeClaim in the pod
name: "<string>" # required
# Pod volumes to mount into the container's filesystem. Cannot be updated.
volumeMounts: # optional, listType: map, listMapKeys: mountPath
- # Path within the container at which the volume should be mounted. Must not contain
# ':'.
mountPath: "<string>" # required
# This must match the Name of a Volume.
name: "<string>" # required
# mountPropagation determines how mounts are propagated from the host to container
# and the other way around. When not set, MountPropagationNone is used. This field
# is beta in 1.10. When RecursiveReadOnly is set to IfPossible or to Enabled,
# MountPropagation must be None or unspecified (which defaults to None).
# mountPropagation: "<string>"
# Mounted read-only if true, read-write otherwise (false or unspecified). Defaults
# to false.
# readOnly: <boolean>
# RecursiveReadOnly specifies whether read-only mounts should be handled
# recursively.
#
# If ReadOnly is false, this field has no meaning and must be unspecified.
#
# If ReadOnly is true, and this field is set to Disabled, the mount is not made
# recursively read-only. If this field is set to IfPossible, the mount is made
# recursively read-only, if it is supported by the container runtime. If this field
# is set to Enabled, the mount is made recursively read-only if it is supported by
# the container runtime, otherwise the pod will not be started and an error will be
# generated to indicate the reason.
#
# If this field is set to IfPossible or Enabled, MountPropagation must be set to
# None (or be unspecified, which defaults to None).
#
# If this field is not specified, it is treated as an equivalent of Disabled.
# recursiveReadOnly: "<string>"
# Path within the volume from which the container's volume should be mounted.
# Defaults to "" (volume's root).
# subPath: "<string>"
# Expanded path within the volume from which the container's volume should be
# mounted. Behaves similarly to SubPath but environment variable references
# $(VAR_NAME) are expanded using the container's environment. Defaults to ""
# (volume's root). SubPathExpr and SubPath are mutually exclusive.
# subPathExpr: "<string>"
# Container's working directory. If not specified, the container runtime's default will
# be used, which might be configured in the container image. Cannot be updated.
# workingDir: "<string>"
# Specifies the DNS parameters of a pod. Parameters specified here will be merged to the
# generated DNS configuration based on DNSPolicy.
# dnsConfig:
# A list of DNS name server IP addresses. This will be appended to the base nameservers
# generated from DNSPolicy. Duplicated nameservers will be removed.
# nameservers: # listType: atomic
# - "<string>"
# A list of DNS resolver options. This will be merged with the base options generated from
# DNSPolicy. Duplicated entries will be removed. Resolution options given in Options will
# override those that appear in the base DNSPolicy.
# options: # listType: atomic
# - # Name is this DNS resolver option's name. Required.
# name: "<string>"
# Value is this DNS resolver option's value.
# value: "<string>"
# A list of DNS search domains for host-name lookup. This will be appended to the base
# search paths generated from DNSPolicy. Duplicated search paths will be removed.
# searches: # listType: atomic
# - "<string>"
# Set DNS policy for the pod. Defaults to "ClusterFirst". Valid values are
# 'ClusterFirstWithHostNet', 'ClusterFirst', 'Default' or 'None'. DNS parameters given in
# DNSConfig will be merged with the policy selected with DNSPolicy. To have DNS options set
# along with hostNetwork, you have to specify DNS policy explicitly to
# 'ClusterFirstWithHostNet'.
# dnsPolicy: "<string>"
# EnableServiceLinks indicates whether information about services should be injected into
# pod's environment variables, matching the syntax of Docker links. Optional: Defaults to
# true.
# enableServiceLinks: <boolean>
# List of ephemeral containers run in this pod. Ephemeral containers may be run in an
# existing pod to perform user-initiated actions such as debugging. This list cannot be
# specified when creating a pod, and it cannot be modified by updating the pod spec. In
# order to add an ephemeral container to an existing pod, use the pod's ephemeralcontainers
# subresource.
ephemeralContainers: # optional, listType: map, listMapKeys: name
- # Name of the ephemeral container specified as a DNS_LABEL. This name must be unique
# among all containers, init containers and ephemeral containers.
name: "<string>" # required
# Arguments to the entrypoint. The image's CMD is used if this is not provided. Variable
# references $(VAR_NAME) are expanded using the container's environment. If a variable
# cannot be resolved, the reference in the input string will be unchanged. Double $$ are
# reduced to a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.
# "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped references will
# never be expanded, regardless of whether the variable exists or not. Cannot be
# updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# args: # listType: atomic
# - "<string>"
# Entrypoint array. Not executed within a shell. The image's ENTRYPOINT is used if this
# is not provided. Variable references $(VAR_NAME) are expanded using the container's
# environment. If a variable cannot be resolved, the reference in the input string will
# be unchanged. Double $$ are reduced to a single $, which allows for escaping the
# $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)".
# Escaped references will never be expanded, regardless of whether the variable exists
# or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# command: # listType: atomic
# - "<string>"
# List of environment variables to set in the container. Cannot be updated.
env: # optional, listType: map, listMapKeys: name
- # Name of the environment variable. May consist of any printable ASCII characters
# except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined
# environment variables in the container and any service environment variables. If a
# variable cannot be resolved, the reference in the input string will be unchanged.
# Double $$ are reduced to a single $, which allows for escaping the $(VAR_NAME)
# syntax: i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped
# references will never be expanded, regardless of whether the variable exists or
# not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to
# be enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from
# starting. The keys defined within a source may consist of any printable ASCII
# characters except '='. During Alpha stage of the EnvFiles feature gate, the
# key size is limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative and
# may not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does
# not exist, then the env var is not published. If optional is set to true and
# the specified key does not exist, the environment variable will not be set in
# the Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error
# will be returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
# requests.memory and requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# List of sources to populate environment variables in the container. The keys defined
# within a source may consist of any printable ASCII characters except '='. When a key
# exists in multiple sources, the value associated with the last source will take
# precedence. Values defined by an Env with a duplicate key will take precedence. Cannot
# be updated.
# envFrom: # listType: atomic
# - # The ConfigMap to select from
# configMapRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap must be defined
# optional: <boolean>
# Optional text to prepend to the name of each environment variable. May consist of
# any printable ASCII characters except '='.
# prefix: "<string>"
# The Secret to select from
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret must be defined
# optional: <boolean>
# Container image name. More info: https://kubernetes.io/docs/concepts/containers/images
# image: "<string>"
# Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if :latest
# tag is specified, or IfNotPresent otherwise. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/containers/images#updating-images
# imagePullPolicy: "<string>"
# Lifecycle is not allowed for ephemeral containers.
lifecycle: # optional
# PostStart is called immediately after a container is created. If the handler fails,
# the container is terminated and restarted according to its restart policy. Other
# management of the container blocks until the hook completes. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
postStart: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for backward
# compatibility. There is no validation of this field and lifecycle hooks will fail
# at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# PreStop is called immediately before a container is terminated due to an API request
# or management event such as liveness/startup probe failure, preemption, resource
# contention, etc. The handler is not called if the container crashes or exits. The
# Pod's termination grace period countdown begins before the PreStop hook is executed.
# Regardless of the outcome of the handler, the container will eventually terminate
# within the Pod's termination grace period (unless delayed by finalizers). Other
# management of the container blocks until the hook completes or until the termination
# grace period is reached. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
preStop: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for backward
# compatibility. There is no validation of this field and lifecycle hooks will fail
# at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# StopSignal defines which signal will be sent to a container when it is being
# stopped. If not specified, the default is defined by the container runtime in use.
# StopSignal can only be set for Pods with a non-empty .spec.os.name
# stopSignal: "<string>"
# Probes are not allowed for ephemeral containers.
livenessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Ports are not allowed for ephemeral containers.
ports: # optional, listType: map, listMapKeys: containerPort, protocol
- # Number of port to expose on the pod's IP address. This must be a valid port
# number, 0 < x < 65536.
containerPort: <int32> # required
# What host IP to bind the external port to.
# hostIP: "<string>"
# Number of port to expose on the host. If specified, this must be a valid port
# number, 0 < x < 65536. If HostNetwork is specified, this must match ContainerPort.
# Most containers do not need this.
# hostPort: <int32>
# If specified, this must be an IANA_SVC_NAME and unique within the pod. Each named
# port in a pod must have a unique name. Name for the port that can be referred to
# by services.
# name: "<string>"
# Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
# protocol: "TCP" # default
# Probes are not allowed for ephemeral containers.
readinessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Resources resize policy for the container.
resizePolicy: # optional, listType: atomic
- # Name of the resource to which this resource resize policy applies. Supported
# values: cpu, memory.
resourceName: "<string>" # required
# Restart policy to apply when specified resource is resized. If not specified, it
# defaults to NotRequired.
restartPolicy: "<string>" # required
# Resources are not allowed for ephemeral containers. Ephemeral containers use spare
# resources already allocated to the pod.
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used
# by this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod
# where this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests is
# omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More
# info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# Restart policy for the container to manage the restart behavior of each container
# within a pod. You cannot set this field on ephemeral containers.
# restartPolicy: "<string>"
# Represents a list of rules to be checked to determine if the container should be
# restarted on exit. You cannot set this field on ephemeral containers.
restartPolicyRules: # optional, listType: atomic
- # Specifies the action taken on a container exit if the requirements are satisfied.
# The only possible value is "Restart" to restart the container.
action: "<string>" # required
# Represents the exit codes to check on container exits.
exitCodes: # optional
# Represents the relationship between the container exit code(s) and the specified
# values. Possible values are: - In: the requirement is satisfied if the container
# exit code is in the set of specified values. - NotIn: the requirement is
# satisfied if the container exit code is not in the set of specified values.
operator: "<string>" # required
# Specifies the set of values to check for container exit codes. At most 255
# elements are allowed.
# values: # listType: set
# - <int32>
# Optional: SecurityContext defines the security options the ephemeral container should
# be run with. If set, the fields of SecurityContext override the equivalent fields of
# PodSecurityContext.
securityContext: # optional
# AllowPrivilegeEscalation controls whether a process can gain more privileges than
# its parent process. This bool directly controls if the no_new_privs flag will be set
# on the container process. AllowPrivilegeEscalation is true always when the container
# is: 1) run as Privileged 2) has CAP_SYS_ADMIN Note that this field cannot be set
# when spec.os.name is windows.
# allowPrivilegeEscalation: <boolean>
# appArmorProfile is the AppArmor options to use by this container. If set, this
# profile overrides the pod's appArmorProfile. Note that this field cannot be set when
# spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options are:
# Localhost - a profile pre-loaded on the node. RuntimeDefault - the container
# runtime's default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of
# the profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# The capabilities to add/drop when running containers. Defaults to the default set of
# capabilities granted by the container runtime. Note that this field cannot be set
# when spec.os.name is windows.
# capabilities:
# Added capabilities
# add: # listType: atomic
# - "<string>"
# Removed capabilities
# drop: # listType: atomic
# - "<string>"
# Run container in privileged mode. Processes in privileged containers are essentially
# equivalent to root on the host. Defaults to false. Note that this field cannot be
# set when spec.os.name is windows.
# privileged: <boolean>
# procMount denotes the type of proc mount to use for the containers. The default
# value is Default which uses the container runtime defaults for readonly paths and
# masked paths. This requires the ProcMountType feature flag to be enabled. Note that
# this field cannot be set when spec.os.name is windows.
# procMount: "<string>"
# Whether this container has a read-only root filesystem. Default is false. Note that
# this field cannot be set when spec.os.name is windows.
# readOnlyRootFilesystem: <boolean>
# The GID to run the entrypoint of the container process. Uses runtime default if
# unset. May also be set in PodSecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet will
# validate the image at runtime to ensure that it does not run as UID 0 (root) and
# fail to start the container if it does. If unset or false, no such validation will
# be performed. May also be set in PodSecurityContext. If set in both SecurityContext
# and PodSecurityContext, the value specified in SecurityContext takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified
# in image metadata if unspecified. May also be set in PodSecurityContext. If set in
# both SecurityContext and PodSecurityContext, the value specified in SecurityContext
# takes precedence. Note that this field cannot be set when spec.os.name is windows.
# runAsUser: <int64>
# The SELinux context to be applied to the container. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set
# in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence. Note that this field cannot be
# set when spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by this container. If seccomp options are provided at
# both the pod & container level, the container options override the pod options. Note
# that this field cannot be set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used. RuntimeDefault
# - the container runtime default profile should be used. Unconfined - no profile
# should be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be used.
# The profile must be preconfigured on the node to work. Must be a descending path,
# relative to the kubelet's configured seccomp profile location. Must be set if type
# is "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# The Windows specific settings applied to all containers. If unspecified, the options
# from the PodSecurityContext will be used. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the GMSA
# credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process' container.
# All of a Pod's containers must have the same effective HostProcess value (it is
# not allowed to have a mix of HostProcess containers and non-HostProcess
# containers). In addition, if HostProcess is true then HostNetwork must also be set
# to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults
# to the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# Probes are not allowed for ephemeral containers.
startupProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Whether this container should allocate a buffer for stdin in the container runtime. If
# this is not set, reads from stdin in the container will always result in EOF. Default
# is false.
# stdin: <boolean>
# Whether the container runtime should close the stdin channel after it has been opened
# by a single attach. When stdin is true the stdin stream will remain open across
# multiple attach sessions. If stdinOnce is set to true, stdin is opened on container
# start, is empty until the first client attaches to stdin, and then remains open and
# accepts data until the client disconnects, at which time stdin is closed and remains
# closed until the container is restarted. If this flag is false, a container processes
# that reads from stdin will never receive an EOF. Default is false
# stdinOnce: <boolean>
# If set, the name of the container from PodSpec that this ephemeral container targets.
# The ephemeral container will be run in the namespaces (IPC, PID, etc) of this
# container. If not set then the ephemeral container uses the namespaces configured in
# the Pod spec.
#
# The container runtime must implement support for this feature. If the runtime does not
# support namespace targeting then the result of setting this field is undefined.
# targetContainerName: "<string>"
# Optional: Path at which the file to which the container's termination message will be
# written is mounted into the container's filesystem. Message written is intended to be
# brief final status, such as an assertion failure message. Will be truncated by the
# node if greater than 4096 bytes. The total message length across all containers will
# be limited to 12kb. Defaults to /dev/termination-log. Cannot be updated.
# terminationMessagePath: "<string>"
# Indicate how the termination message should be populated. File will use the contents
# of terminationMessagePath to populate the container status message on both success and
# failure. FallbackToLogsOnError will use the last chunk of container log output if the
# termination message file is empty and the container exited with an error. The log
# output is limited to 2048 bytes or 80 lines, whichever is smaller. Defaults to File.
# Cannot be updated.
# terminationMessagePolicy: "<string>"
# Whether this container should allocate a TTY for itself, also requires 'stdin' to be
# true. Default is false.
# tty: <boolean>
# volumeDevices is the list of block devices to be used by the container.
volumeDevices: # optional, listType: map, listMapKeys: devicePath
- # devicePath is the path inside of the container that the device will be mapped to.
devicePath: "<string>" # required
# name must match the name of a persistentVolumeClaim in the pod
name: "<string>" # required
# Pod volumes to mount into the container's filesystem. Subpath mounts are not allowed
# for ephemeral containers. Cannot be updated.
volumeMounts: # optional, listType: map, listMapKeys: mountPath
- # Path within the container at which the volume should be mounted. Must not contain
# ':'.
mountPath: "<string>" # required
# This must match the Name of a Volume.
name: "<string>" # required
# mountPropagation determines how mounts are propagated from the host to container
# and the other way around. When not set, MountPropagationNone is used. This field
# is beta in 1.10. When RecursiveReadOnly is set to IfPossible or to Enabled,
# MountPropagation must be None or unspecified (which defaults to None).
# mountPropagation: "<string>"
# Mounted read-only if true, read-write otherwise (false or unspecified). Defaults
# to false.
# readOnly: <boolean>
# RecursiveReadOnly specifies whether read-only mounts should be handled
# recursively.
#
# If ReadOnly is false, this field has no meaning and must be unspecified.
#
# If ReadOnly is true, and this field is set to Disabled, the mount is not made
# recursively read-only. If this field is set to IfPossible, the mount is made
# recursively read-only, if it is supported by the container runtime. If this field
# is set to Enabled, the mount is made recursively read-only if it is supported by
# the container runtime, otherwise the pod will not be started and an error will be
# generated to indicate the reason.
#
# If this field is set to IfPossible or Enabled, MountPropagation must be set to
# None (or be unspecified, which defaults to None).
#
# If this field is not specified, it is treated as an equivalent of Disabled.
# recursiveReadOnly: "<string>"
# Path within the volume from which the container's volume should be mounted.
# Defaults to "" (volume's root).
# subPath: "<string>"
# Expanded path within the volume from which the container's volume should be
# mounted. Behaves similarly to SubPath but environment variable references
# $(VAR_NAME) are expanded using the container's environment. Defaults to ""
# (volume's root). SubPathExpr and SubPath are mutually exclusive.
# subPathExpr: "<string>"
# Container's working directory. If not specified, the container runtime's default will
# be used, which might be configured in the container image. Cannot be updated.
# workingDir: "<string>"
# HostAliases is an optional list of hosts and IPs that will be injected into the pod's
# hosts file if specified.
hostAliases: # optional, listType: map, listMapKeys: ip
- # IP address of the host file entry.
ip: "<string>" # required
# Hostnames for the above IP address.
# hostnames: # listType: atomic
# - "<string>"
# Use the host's ipc namespace. Optional: Default to false.
# hostIPC: <boolean>
# Host networking requested for this pod. Use the host's network namespace. When using
# HostNetwork you should specify ports so the scheduler is aware. When `hostNetwork` is
# true, specified `hostPort` fields in port definitions must match `containerPort`, and
# unspecified `hostPort` fields in port definitions are defaulted to match `containerPort`.
# Default to false.
# hostNetwork: <boolean>
# Use the host's pid namespace. Optional: Default to false.
# hostPID: <boolean>
# Use the host's user namespace. Optional: Default to true. If set to true or not present,
# the pod will be run in the host user namespace, useful for when the pod needs a feature
# only available to the host user namespace, such as loading a kernel module with
# CAP_SYS_MODULE. When set to false, a new userns is created for the pod. Setting false is
# useful for mitigating container breakout vulnerabilities even allowing users to run their
# containers as root without actually having root privileges on the host. This field is
# alpha-level and is only honored by servers that enable the UserNamespacesSupport feature.
# hostUsers: <boolean>
# Specifies the hostname of the Pod If not specified, the pod's hostname will be set to a
# system-defined value.
# hostname: "<string>"
# HostnameOverride specifies an explicit override for the pod's hostname as perceived by the
# pod. This field only specifies the pod's hostname and does not affect its DNS records.
# When this field is set to a non-empty string: - It takes precedence over the values set in
# `hostname` and `subdomain`. - The Pod's hostname will be set to this value. -
# `setHostnameAsFQDN` must be nil or set to false. - `hostNetwork` must be set to false.
#
# This field must be a valid DNS subdomain as defined in RFC 1123 and contain at most 64
# characters. Requires the HostnameOverride feature gate to be enabled.
# hostnameOverride: "<string>"
# ImagePullSecrets is an optional list of references to secrets in the same namespace to use
# for pulling any of the images used by this PodSpec. If specified, these secrets will be
# passed to individual puller implementations for them to use. More info:
# https://kubernetes.io/docs/concepts/containers/images#specifying-imagepullsecrets-on-a-pod
# imagePullSecrets: # listType: map, listMapKeys: name
# - # Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value here
# are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# List of initialization containers belonging to the pod. Init containers are executed in
# order prior to containers being started. If any init container fails, the pod is
# considered to have failed and is handled according to its restartPolicy. The name for an
# init container or normal container must be unique among all containers. Init containers
# may not have Lifecycle actions, Readiness probes, Liveness probes, or Startup probes. The
# resourceRequirements of an init container are taken into account during scheduling by
# finding the highest request/limit for each resource type, and then using the max of that
# value or the sum of the normal containers. Limits are applied to init containers in a
# similar fashion. Init containers cannot currently be added or removed. Cannot be updated.
# More info: https://kubernetes.io/docs/concepts/workloads/pods/init-containers/
initContainers: # optional, listType: map, listMapKeys: name
- # Name of the container specified as a DNS_LABEL. Each container in a pod must have a
# unique name (DNS_LABEL). Cannot be updated.
name: "<string>" # required
# Arguments to the entrypoint. The container image's CMD is used if this is not
# provided. Variable references $(VAR_NAME) are expanded using the container's
# environment. If a variable cannot be resolved, the reference in the input string will
# be unchanged. Double $$ are reduced to a single $, which allows for escaping the
# $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)".
# Escaped references will never be expanded, regardless of whether the variable exists
# or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# args: # listType: atomic
# - "<string>"
# Entrypoint array. Not executed within a shell. The container image's ENTRYPOINT is
# used if this is not provided. Variable references $(VAR_NAME) are expanded using the
# container's environment. If a variable cannot be resolved, the reference in the input
# string will be unchanged. Double $$ are reduced to a single $, which allows for
# escaping the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal
# "$(VAR_NAME)". Escaped references will never be expanded, regardless of whether the
# variable exists or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# command: # listType: atomic
# - "<string>"
# List of environment variables to set in the container. Cannot be updated.
env: # optional, listType: map, listMapKeys: name
- # Name of the environment variable. May consist of any printable ASCII characters
# except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined
# environment variables in the container and any service environment variables. If a
# variable cannot be resolved, the reference in the input string will be unchanged.
# Double $$ are reduced to a single $, which allows for escaping the $(VAR_NAME)
# syntax: i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped
# references will never be expanded, regardless of whether the variable exists or
# not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to
# be enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from
# starting. The keys defined within a source may consist of any printable ASCII
# characters except '='. During Alpha stage of the EnvFiles feature gate, the
# key size is limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative and
# may not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does
# not exist, then the env var is not published. If optional is set to true and
# the specified key does not exist, the environment variable will not be set in
# the Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error
# will be returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
# requests.memory and requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# List of sources to populate environment variables in the container. The keys defined
# within a source may consist of any printable ASCII characters except '='. When a key
# exists in multiple sources, the value associated with the last source will take
# precedence. Values defined by an Env with a duplicate key will take precedence. Cannot
# be updated.
# envFrom: # listType: atomic
# - # The ConfigMap to select from
# configMapRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap must be defined
# optional: <boolean>
# Optional text to prepend to the name of each environment variable. May consist of
# any printable ASCII characters except '='.
# prefix: "<string>"
# The Secret to select from
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret must be defined
# optional: <boolean>
# Container image name. More info: https://kubernetes.io/docs/concepts/containers/images
# This field is optional to allow higher level config management to default or override
# container images in workload controllers like Deployments and StatefulSets.
# image: "<string>"
# Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if :latest
# tag is specified, or IfNotPresent otherwise. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/containers/images#updating-images
# imagePullPolicy: "<string>"
# Actions that the management system should take in response to container lifecycle
# events. Cannot be updated.
lifecycle: # optional
# PostStart is called immediately after a container is created. If the handler fails,
# the container is terminated and restarted according to its restart policy. Other
# management of the container blocks until the hook completes. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
postStart: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for backward
# compatibility. There is no validation of this field and lifecycle hooks will fail
# at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# PreStop is called immediately before a container is terminated due to an API request
# or management event such as liveness/startup probe failure, preemption, resource
# contention, etc. The handler is not called if the container crashes or exits. The
# Pod's termination grace period countdown begins before the PreStop hook is executed.
# Regardless of the outcome of the handler, the container will eventually terminate
# within the Pod's termination grace period (unless delayed by finalizers). Other
# management of the container blocks until the hook completes or until the termination
# grace period is reached. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
preStop: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working
# directory for the command is root ('/') in the container's filesystem. The
# command is simply exec'd, it is not run inside a shell, so traditional shell
# instructions ('|', etc) won't work. To use a shell, you need to explicitly call
# out to that shell. Exit status of 0 is treated as live/healthy and non-zero is
# unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so
# case-variant names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for backward
# compatibility. There is no validation of this field and lifecycle hooks will fail
# at runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the
# range 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# StopSignal defines which signal will be sent to a container when it is being
# stopped. If not specified, the default is defined by the container runtime in use.
# StopSignal can only be set for Pods with a non-empty .spec.os.name
# stopSignal: "<string>"
# Periodic probe of container liveness. Container will be restarted if the probe fails.
# Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
livenessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# List of ports to expose from the container. Not specifying a port here DOES NOT
# prevent that port from being exposed. Any port which is listening on the default
# "0.0.0.0" address inside a container will be accessible from the network. Modifying
# this array with strategic merge patch may corrupt the data. For more information See
# https://github.com/kubernetes/kubernetes/issues/108255. Cannot be updated.
ports: # optional, listType: map, listMapKeys: containerPort, protocol
- # Number of port to expose on the pod's IP address. This must be a valid port
# number, 0 < x < 65536.
containerPort: <int32> # required
# What host IP to bind the external port to.
# hostIP: "<string>"
# Number of port to expose on the host. If specified, this must be a valid port
# number, 0 < x < 65536. If HostNetwork is specified, this must match ContainerPort.
# Most containers do not need this.
# hostPort: <int32>
# If specified, this must be an IANA_SVC_NAME and unique within the pod. Each named
# port in a pod must have a unique name. Name for the port that can be referred to
# by services.
# name: "<string>"
# Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
# protocol: "TCP" # default
# Periodic probe of container service readiness. Container will be removed from service
# endpoints if the probe fails. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
readinessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Resources resize policy for the container.
resizePolicy: # optional, listType: atomic
- # Name of the resource to which this resource resize policy applies. Supported
# values: cpu, memory.
resourceName: "<string>" # required
# Restart policy to apply when specified resource is resized. If not specified, it
# defaults to NotRequired.
restartPolicy: "<string>" # required
# Compute Resources required by this container. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used
# by this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod
# where this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests is
# omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More
# info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# RestartPolicy defines the restart behavior of individual containers in a pod. This
# overrides the pod-level restart policy. When this field is not specified, the restart
# behavior is defined by the Pod's restart policy and the container type. Additionally,
# setting the RestartPolicy as "Always" for the init container will have the following
# effect: this init container will be continually restarted on exit until all regular
# containers have terminated. Once all regular containers have completed, all init
# containers with restartPolicy "Always" will be shut down. This lifecycle differs from
# normal init containers and is often referred to as a "sidecar" container. Although
# this init container still starts in the init container sequence, it does not wait for
# the container to complete before proceeding to the next init container. Instead, the
# next init container starts immediately after this init container is started, or after
# any startupProbe has successfully completed.
# restartPolicy: "<string>"
# Represents a list of rules to be checked to determine if the container should be
# restarted on exit. The rules are evaluated in order. Once a rule matches a container
# exit condition, the remaining rules are ignored. If no rule matches the container exit
# condition, the Container-level restart policy determines the whether the container is
# restarted or not. Constraints on the rules: - At most 20 rules are allowed. - Rules
# can have the same action. - Identical rules are not forbidden in validations. When
# rules are specified, container MUST set RestartPolicy explicitly even it if matches
# the Pod's RestartPolicy.
restartPolicyRules: # optional, listType: atomic
- # Specifies the action taken on a container exit if the requirements are satisfied.
# The only possible value is "Restart" to restart the container.
action: "<string>" # required
# Represents the exit codes to check on container exits.
exitCodes: # optional
# Represents the relationship between the container exit code(s) and the specified
# values. Possible values are: - In: the requirement is satisfied if the container
# exit code is in the set of specified values. - NotIn: the requirement is
# satisfied if the container exit code is not in the set of specified values.
operator: "<string>" # required
# Specifies the set of values to check for container exit codes. At most 255
# elements are allowed.
# values: # listType: set
# - <int32>
# SecurityContext defines the security options the container should be run with. If set,
# the fields of SecurityContext override the equivalent fields of PodSecurityContext.
# More info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
securityContext: # optional
# AllowPrivilegeEscalation controls whether a process can gain more privileges than
# its parent process. This bool directly controls if the no_new_privs flag will be set
# on the container process. AllowPrivilegeEscalation is true always when the container
# is: 1) run as Privileged 2) has CAP_SYS_ADMIN Note that this field cannot be set
# when spec.os.name is windows.
# allowPrivilegeEscalation: <boolean>
# appArmorProfile is the AppArmor options to use by this container. If set, this
# profile overrides the pod's appArmorProfile. Note that this field cannot be set when
# spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options are:
# Localhost - a profile pre-loaded on the node. RuntimeDefault - the container
# runtime's default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of
# the profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# The capabilities to add/drop when running containers. Defaults to the default set of
# capabilities granted by the container runtime. Note that this field cannot be set
# when spec.os.name is windows.
# capabilities:
# Added capabilities
# add: # listType: atomic
# - "<string>"
# Removed capabilities
# drop: # listType: atomic
# - "<string>"
# Run container in privileged mode. Processes in privileged containers are essentially
# equivalent to root on the host. Defaults to false. Note that this field cannot be
# set when spec.os.name is windows.
# privileged: <boolean>
# procMount denotes the type of proc mount to use for the containers. The default
# value is Default which uses the container runtime defaults for readonly paths and
# masked paths. This requires the ProcMountType feature flag to be enabled. Note that
# this field cannot be set when spec.os.name is windows.
# procMount: "<string>"
# Whether this container has a read-only root filesystem. Default is false. Note that
# this field cannot be set when spec.os.name is windows.
# readOnlyRootFilesystem: <boolean>
# The GID to run the entrypoint of the container process. Uses runtime default if
# unset. May also be set in PodSecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet will
# validate the image at runtime to ensure that it does not run as UID 0 (root) and
# fail to start the container if it does. If unset or false, no such validation will
# be performed. May also be set in PodSecurityContext. If set in both SecurityContext
# and PodSecurityContext, the value specified in SecurityContext takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified
# in image metadata if unspecified. May also be set in PodSecurityContext. If set in
# both SecurityContext and PodSecurityContext, the value specified in SecurityContext
# takes precedence. Note that this field cannot be set when spec.os.name is windows.
# runAsUser: <int64>
# The SELinux context to be applied to the container. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set
# in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence. Note that this field cannot be
# set when spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by this container. If seccomp options are provided at
# both the pod & container level, the container options override the pod options. Note
# that this field cannot be set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used. RuntimeDefault
# - the container runtime default profile should be used. Unconfined - no profile
# should be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be used.
# The profile must be preconfigured on the node to work. Must be a descending path,
# relative to the kubelet's configured seccomp profile location. Must be set if type
# is "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# The Windows specific settings applied to all containers. If unspecified, the options
# from the PodSecurityContext will be used. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note
# that this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the GMSA
# credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process' container.
# All of a Pod's containers must have the same effective HostProcess value (it is
# not allowed to have a mix of HostProcess containers and non-HostProcess
# containers). In addition, if HostProcess is true then HostNetwork must also be set
# to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults
# to the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the
# value specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# StartupProbe indicates that the Pod has successfully initialized. If specified, no
# other probes are executed until this completes successfully. If this probe fails, the
# Pod will be restarted, just as if the livenessProbe failed. This can be used to
# provide different probe parameters at the beginning of a Pod's lifecycle, when it
# might take a long time to load data or warm a cache, than during steady-state
# operation. This cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
startupProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe
# failure. The grace period is the duration in seconds after the processes running in
# the pod are sent a termination signal and the time when the processes are forcibly
# halted with a kill signal. Set this value longer than the expected cleanup time for
# your process. If this value is nil, the pod's terminationGracePeriodSeconds will be
# used. Otherwise, this value overrides the value provided by the pod spec. Value must
# be non-negative integer. The value zero indicates stop immediately via the kill
# signal (no opportunity to shut down). This is a beta field and requires enabling
# ProbeTerminationGracePeriod feature gate. Minimum value is 1.
# spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum
# value is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Whether this container should allocate a buffer for stdin in the container runtime. If
# this is not set, reads from stdin in the container will always result in EOF. Default
# is false.
# stdin: <boolean>
# Whether the container runtime should close the stdin channel after it has been opened
# by a single attach. When stdin is true the stdin stream will remain open across
# multiple attach sessions. If stdinOnce is set to true, stdin is opened on container
# start, is empty until the first client attaches to stdin, and then remains open and
# accepts data until the client disconnects, at which time stdin is closed and remains
# closed until the container is restarted. If this flag is false, a container processes
# that reads from stdin will never receive an EOF. Default is false
# stdinOnce: <boolean>
# Optional: Path at which the file to which the container's termination message will be
# written is mounted into the container's filesystem. Message written is intended to be
# brief final status, such as an assertion failure message. Will be truncated by the
# node if greater than 4096 bytes. The total message length across all containers will
# be limited to 12kb. Defaults to /dev/termination-log. Cannot be updated.
# terminationMessagePath: "<string>"
# Indicate how the termination message should be populated. File will use the contents
# of terminationMessagePath to populate the container status message on both success and
# failure. FallbackToLogsOnError will use the last chunk of container log output if the
# termination message file is empty and the container exited with an error. The log
# output is limited to 2048 bytes or 80 lines, whichever is smaller. Defaults to File.
# Cannot be updated.
# terminationMessagePolicy: "<string>"
# Whether this container should allocate a TTY for itself, also requires 'stdin' to be
# true. Default is false.
# tty: <boolean>
# volumeDevices is the list of block devices to be used by the container.
volumeDevices: # optional, listType: map, listMapKeys: devicePath
- # devicePath is the path inside of the container that the device will be mapped to.
devicePath: "<string>" # required
# name must match the name of a persistentVolumeClaim in the pod
name: "<string>" # required
# Pod volumes to mount into the container's filesystem. Cannot be updated.
volumeMounts: # optional, listType: map, listMapKeys: mountPath
- # Path within the container at which the volume should be mounted. Must not contain
# ':'.
mountPath: "<string>" # required
# This must match the Name of a Volume.
name: "<string>" # required
# mountPropagation determines how mounts are propagated from the host to container
# and the other way around. When not set, MountPropagationNone is used. This field
# is beta in 1.10. When RecursiveReadOnly is set to IfPossible or to Enabled,
# MountPropagation must be None or unspecified (which defaults to None).
# mountPropagation: "<string>"
# Mounted read-only if true, read-write otherwise (false or unspecified). Defaults
# to false.
# readOnly: <boolean>
# RecursiveReadOnly specifies whether read-only mounts should be handled
# recursively.
#
# If ReadOnly is false, this field has no meaning and must be unspecified.
#
# If ReadOnly is true, and this field is set to Disabled, the mount is not made
# recursively read-only. If this field is set to IfPossible, the mount is made
# recursively read-only, if it is supported by the container runtime. If this field
# is set to Enabled, the mount is made recursively read-only if it is supported by
# the container runtime, otherwise the pod will not be started and an error will be
# generated to indicate the reason.
#
# If this field is set to IfPossible or Enabled, MountPropagation must be set to
# None (or be unspecified, which defaults to None).
#
# If this field is not specified, it is treated as an equivalent of Disabled.
# recursiveReadOnly: "<string>"
# Path within the volume from which the container's volume should be mounted.
# Defaults to "" (volume's root).
# subPath: "<string>"
# Expanded path within the volume from which the container's volume should be
# mounted. Behaves similarly to SubPath but environment variable references
# $(VAR_NAME) are expanded using the container's environment. Defaults to ""
# (volume's root). SubPathExpr and SubPath are mutually exclusive.
# subPathExpr: "<string>"
# Container's working directory. If not specified, the container runtime's default will
# be used, which might be configured in the container image. Cannot be updated.
# workingDir: "<string>"
# A single application container that you want to run within a pod.
mainContainer: # optional
# Arguments to the entrypoint. The container image's CMD is used if this is not provided.
# Variable references $(VAR_NAME) are expanded using the container's environment. If a
# variable cannot be resolved, the reference in the input string will be unchanged. Double
# $$ are reduced to a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.
# "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped references will
# never be expanded, regardless of whether the variable exists or not. Cannot be updated.
# More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# args: # listType: atomic
# - "<string>"
# Entrypoint array. Not executed within a shell. The container image's ENTRYPOINT is used
# if this is not provided. Variable references $(VAR_NAME) are expanded using the
# container's environment. If a variable cannot be resolved, the reference in the input
# string will be unchanged. Double $$ are reduced to a single $, which allows for escaping
# the $(VAR_NAME) syntax: i.e. "$$(VAR_NAME)" will produce the string literal
# "$(VAR_NAME)". Escaped references will never be expanded, regardless of whether the
# variable exists or not. Cannot be updated. More info:
# https://kubernetes.io/docs/tasks/inject-data-application/define-command-argument-container/#running-a-command-in-a-shell
# command: # listType: atomic
# - "<string>"
# List of environment variables to set in the container. Cannot be updated.
env: # optional, listType: map, listMapKeys: name
- # Name of the environment variable. May consist of any printable ASCII characters
# except '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined
# environment variables in the container and any service environment variables. If a
# variable cannot be resolved, the reference in the input string will be unchanged.
# Double $$ are reduced to a single $, which allows for escaping the $(VAR_NAME)
# syntax: i.e. "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped
# references will never be expanded, regardless of whether the variable exists or not.
# Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to be
# enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from starting.
# The keys defined within a source may consist of any printable ASCII characters
# except '='. During Alpha stage of the EnvFiles feature gate, the key size is
# limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative and
# may not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does not
# exist, then the env var is not published. If optional is set to true and the
# specified key does not exist, the environment variable will not be set in the
# Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error will
# be returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu,
# requests.memory and requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# List of sources to populate environment variables in the container. The keys defined
# within a source may consist of any printable ASCII characters except '='. When a key
# exists in multiple sources, the value associated with the last source will take
# precedence. Values defined by an Env with a duplicate key will take precedence. Cannot
# be updated.
# envFrom: # listType: atomic
# - # The ConfigMap to select from
# configMapRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap must be defined
# optional: <boolean>
# Optional text to prepend to the name of each environment variable. May consist of
# any printable ASCII characters except '='.
# prefix: "<string>"
# The Secret to select from
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret must be defined
# optional: <boolean>
# Container image name. More info: https://kubernetes.io/docs/concepts/containers/images
# This field is optional to allow higher level config management to default or override
# container images in workload controllers like Deployments and StatefulSets.
# image: "<string>"
# Image pull policy. One of Always, Never, IfNotPresent. Defaults to Always if :latest tag
# is specified, or IfNotPresent otherwise. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/containers/images#updating-images
# imagePullPolicy: "<string>"
# Actions that the management system should take in response to container lifecycle
# events. Cannot be updated.
lifecycle: # optional
# PostStart is called immediately after a container is created. If the handler fails,
# the container is terminated and restarted according to its restart policy. Other
# management of the container blocks until the hook completes. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
postStart: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for backward
# compatibility. There is no validation of this field and lifecycle hooks will fail at
# runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# PreStop is called immediately before a container is terminated due to an API request
# or management event such as liveness/startup probe failure, preemption, resource
# contention, etc. The handler is not called if the container crashes or exits. The
# Pod's termination grace period countdown begins before the PreStop hook is executed.
# Regardless of the outcome of the handler, the container will eventually terminate
# within the Pod's termination grace period (unless delayed by finalizers). Other
# management of the container blocks until the hook completes or until the termination
# grace period is reached. More info:
# https://kubernetes.io/docs/concepts/containers/container-lifecycle-hooks/#container-hooks
preStop: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host"
# in httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Sleep represents a duration that the container should sleep.
sleep: # optional
# Seconds is the number of seconds to sleep.
seconds: <int64> # required
# Deprecated. TCPSocket is NOT supported as a LifecycleHandler and kept for backward
# compatibility. There is no validation of this field and lifecycle hooks will fail at
# runtime when it is specified.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range
# 1 to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# StopSignal defines which signal will be sent to a container when it is being stopped.
# If not specified, the default is defined by the container runtime in use. StopSignal
# can only be set for Pods with a non-empty .spec.os.name
# stopSignal: "<string>"
# Periodic probe of container liveness. Container will be restarted if the probe fails.
# Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
livenessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range 1
# to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host" in
# httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range 1
# to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe failure.
# The grace period is the duration in seconds after the processes running in the pod are
# sent a termination signal and the time when the processes are forcibly halted with a
# kill signal. Set this value longer than the expected cleanup time for your process. If
# this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise,
# this value overrides the value provided by the pod spec. Value must be non-negative
# integer. The value zero indicates stop immediately via the kill signal (no opportunity
# to shut down). This is a beta field and requires enabling ProbeTerminationGracePeriod
# feature gate. Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum value
# is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Name of the container specified as a DNS_LABEL. Each container in a pod must have a
# unique name (DNS_LABEL). Cannot be updated.
# name: "<string>"
# List of ports to expose from the container. Not specifying a port here DOES NOT prevent
# that port from being exposed. Any port which is listening on the default "0.0.0.0"
# address inside a container will be accessible from the network. Modifying this array
# with strategic merge patch may corrupt the data. For more information See
# https://github.com/kubernetes/kubernetes/issues/108255. Cannot be updated.
ports: # optional, listType: map, listMapKeys: containerPort, protocol
- # Number of port to expose on the pod's IP address. This must be a valid port number,
# 0 < x < 65536.
containerPort: <int32> # required
# What host IP to bind the external port to.
# hostIP: "<string>"
# Number of port to expose on the host. If specified, this must be a valid port
# number, 0 < x < 65536. If HostNetwork is specified, this must match ContainerPort.
# Most containers do not need this.
# hostPort: <int32>
# If specified, this must be an IANA_SVC_NAME and unique within the pod. Each named
# port in a pod must have a unique name. Name for the port that can be referred to by
# services.
# name: "<string>"
# Protocol for port. Must be UDP, TCP, or SCTP. Defaults to "TCP".
# protocol: "TCP" # default
# Periodic probe of container service readiness. Container will be removed from service
# endpoints if the probe fails. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
readinessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range 1
# to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host" in
# httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range 1
# to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe failure.
# The grace period is the duration in seconds after the processes running in the pod are
# sent a termination signal and the time when the processes are forcibly halted with a
# kill signal. Set this value longer than the expected cleanup time for your process. If
# this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise,
# this value overrides the value provided by the pod spec. Value must be non-negative
# integer. The value zero indicates stop immediately via the kill signal (no opportunity
# to shut down). This is a beta field and requires enabling ProbeTerminationGracePeriod
# feature gate. Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum value
# is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Resources resize policy for the container.
resizePolicy: # optional, listType: atomic
- # Name of the resource to which this resource resize policy applies. Supported values:
# cpu, memory.
resourceName: "<string>" # required
# Restart policy to apply when specified resource is resized. If not specified, it
# defaults to NotRequired.
restartPolicy: "<string>" # required
# Compute Resources required by this container. Cannot be updated. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used by
# this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod where
# this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests is
# omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More
# info: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# RestartPolicy defines the restart behavior of individual containers in a pod. This
# overrides the pod-level restart policy. When this field is not specified, the restart
# behavior is defined by the Pod's restart policy and the container type. Additionally,
# setting the RestartPolicy as "Always" for the init container will have the following
# effect: this init container will be continually restarted on exit until all regular
# containers have terminated. Once all regular containers have completed, all init
# containers with restartPolicy "Always" will be shut down. This lifecycle differs from
# normal init containers and is often referred to as a "sidecar" container. Although this
# init container still starts in the init container sequence, it does not wait for the
# container to complete before proceeding to the next init container. Instead, the next
# init container starts immediately after this init container is started, or after any
# startupProbe has successfully completed.
# restartPolicy: "<string>"
# Represents a list of rules to be checked to determine if the container should be
# restarted on exit. The rules are evaluated in order. Once a rule matches a container
# exit condition, the remaining rules are ignored. If no rule matches the container exit
# condition, the Container-level restart policy determines the whether the container is
# restarted or not. Constraints on the rules: - At most 20 rules are allowed. - Rules can
# have the same action. - Identical rules are not forbidden in validations. When rules are
# specified, container MUST set RestartPolicy explicitly even it if matches the Pod's
# RestartPolicy.
restartPolicyRules: # optional, listType: atomic
- # Specifies the action taken on a container exit if the requirements are satisfied.
# The only possible value is "Restart" to restart the container.
action: "<string>" # required
# Represents the exit codes to check on container exits.
exitCodes: # optional
# Represents the relationship between the container exit code(s) and the specified
# values. Possible values are: - In: the requirement is satisfied if the container
# exit code is in the set of specified values. - NotIn: the requirement is satisfied
# if the container exit code is not in the set of specified values.
operator: "<string>" # required
# Specifies the set of values to check for container exit codes. At most 255
# elements are allowed.
# values: # listType: set
# - <int32>
# SecurityContext defines the security options the container should be run with. If set,
# the fields of SecurityContext override the equivalent fields of PodSecurityContext. More
# info: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/
securityContext: # optional
# AllowPrivilegeEscalation controls whether a process can gain more privileges than its
# parent process. This bool directly controls if the no_new_privs flag will be set on
# the container process. AllowPrivilegeEscalation is true always when the container is:
# 1) run as Privileged 2) has CAP_SYS_ADMIN Note that this field cannot be set when
# spec.os.name is windows.
# allowPrivilegeEscalation: <boolean>
# appArmorProfile is the AppArmor options to use by this container. If set, this profile
# overrides the pod's appArmorProfile. Note that this field cannot be set when
# spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options are:
# Localhost - a profile pre-loaded on the node. RuntimeDefault - the container
# runtime's default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of the
# profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# The capabilities to add/drop when running containers. Defaults to the default set of
# capabilities granted by the container runtime. Note that this field cannot be set when
# spec.os.name is windows.
# capabilities:
# Added capabilities
# add: # listType: atomic
# - "<string>"
# Removed capabilities
# drop: # listType: atomic
# - "<string>"
# Run container in privileged mode. Processes in privileged containers are essentially
# equivalent to root on the host. Defaults to false. Note that this field cannot be set
# when spec.os.name is windows.
# privileged: <boolean>
# procMount denotes the type of proc mount to use for the containers. The default value
# is Default which uses the container runtime defaults for readonly paths and masked
# paths. This requires the ProcMountType feature flag to be enabled. Note that this
# field cannot be set when spec.os.name is windows.
# procMount: "<string>"
# Whether this container has a read-only root filesystem. Default is false. Note that
# this field cannot be set when spec.os.name is windows.
# readOnlyRootFilesystem: <boolean>
# The GID to run the entrypoint of the container process. Uses runtime default if unset.
# May also be set in PodSecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note that
# this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet will
# validate the image at runtime to ensure that it does not run as UID 0 (root) and fail
# to start the container if it does. If unset or false, no such validation will be
# performed. May also be set in PodSecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified in
# image metadata if unspecified. May also be set in PodSecurityContext. If set in both
# SecurityContext and PodSecurityContext, the value specified in SecurityContext takes
# precedence. Note that this field cannot be set when spec.os.name is windows.
# runAsUser: <int64>
# The SELinux context to be applied to the container. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value
# specified in SecurityContext takes precedence. Note that this field cannot be set when
# spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by this container. If seccomp options are provided at both
# the pod & container level, the container options override the pod options. Note that
# this field cannot be set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used. RuntimeDefault -
# the container runtime default profile should be used. Unconfined - no profile should
# be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be used.
# The profile must be preconfigured on the node to work. Must be a descending path,
# relative to the kubelet's configured seccomp profile location. Must be set if type
# is "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# The Windows specific settings applied to all containers. If unspecified, the options
# from the PodSecurityContext will be used. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note that
# this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the GMSA
# credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process' container.
# All of a Pod's containers must have the same effective HostProcess value (it is not
# allowed to have a mix of HostProcess containers and non-HostProcess containers). In
# addition, if HostProcess is true then HostNetwork must also be set to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults to
# the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value
# specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# StartupProbe indicates that the Pod has successfully initialized. If specified, no other
# probes are executed until this completes successfully. If this probe fails, the Pod will
# be restarted, just as if the livenessProbe failed. This can be used to provide different
# probe parameters at the beginning of a Pod's lifecycle, when it might take a long time
# to load data or warm a cache, than during steady-state operation. This cannot be
# updated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
startupProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory
# for the command is root ('/') in the container's filesystem. The command is simply
# exec'd, it is not run inside a shell, so traditional shell instructions ('|', etc)
# won't work. To use a shell, you need to explicitly call out to that shell. Exit
# status of 0 is treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having
# succeeded. Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range 1
# to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host" in
# httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant
# names will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are
# initiated. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is
# 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range 1
# to 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe failure.
# The grace period is the duration in seconds after the processes running in the pod are
# sent a termination signal and the time when the processes are forcibly halted with a
# kill signal. Set this value longer than the expected cleanup time for your process. If
# this value is nil, the pod's terminationGracePeriodSeconds will be used. Otherwise,
# this value overrides the value provided by the pod spec. Value must be non-negative
# integer. The value zero indicates stop immediately via the kill signal (no opportunity
# to shut down). This is a beta field and requires enabling ProbeTerminationGracePeriod
# feature gate. Minimum value is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum value
# is 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Whether this container should allocate a buffer for stdin in the container runtime. If
# this is not set, reads from stdin in the container will always result in EOF. Default is
# false.
# stdin: <boolean>
# Whether the container runtime should close the stdin channel after it has been opened by
# a single attach. When stdin is true the stdin stream will remain open across multiple
# attach sessions. If stdinOnce is set to true, stdin is opened on container start, is
# empty until the first client attaches to stdin, and then remains open and accepts data
# until the client disconnects, at which time stdin is closed and remains closed until the
# container is restarted. If this flag is false, a container processes that reads from
# stdin will never receive an EOF. Default is false
# stdinOnce: <boolean>
# Optional: Path at which the file to which the container's termination message will be
# written is mounted into the container's filesystem. Message written is intended to be
# brief final status, such as an assertion failure message. Will be truncated by the node
# if greater than 4096 bytes. The total message length across all containers will be
# limited to 12kb. Defaults to /dev/termination-log. Cannot be updated.
# terminationMessagePath: "<string>"
# Indicate how the termination message should be populated. File will use the contents of
# terminationMessagePath to populate the container status message on both success and
# failure. FallbackToLogsOnError will use the last chunk of container log output if the
# termination message file is empty and the container exited with an error. The log output
# is limited to 2048 bytes or 80 lines, whichever is smaller. Defaults to File. Cannot be
# updated.
# terminationMessagePolicy: "<string>"
# Whether this container should allocate a TTY for itself, also requires 'stdin' to be
# true. Default is false.
# tty: <boolean>
# volumeDevices is the list of block devices to be used by the container.
volumeDevices: # optional, listType: map, listMapKeys: devicePath
- # devicePath is the path inside of the container that the device will be mapped to.
devicePath: "<string>" # required
# name must match the name of a persistentVolumeClaim in the pod
name: "<string>" # required
# Pod volumes to mount into the container's filesystem. Cannot be updated.
volumeMounts: # optional, listType: map, listMapKeys: mountPath
- # Path within the container at which the volume should be mounted. Must not contain
# ':'.
mountPath: "<string>" # required
# This must match the Name of a Volume.
name: "<string>" # required
# mountPropagation determines how mounts are propagated from the host to container and
# the other way around. When not set, MountPropagationNone is used. This field is beta
# in 1.10. When RecursiveReadOnly is set to IfPossible or to Enabled, MountPropagation
# must be None or unspecified (which defaults to None).
# mountPropagation: "<string>"
# Mounted read-only if true, read-write otherwise (false or unspecified). Defaults to
# false.
# readOnly: <boolean>
# RecursiveReadOnly specifies whether read-only mounts should be handled recursively.
#
# If ReadOnly is false, this field has no meaning and must be unspecified.
#
# If ReadOnly is true, and this field is set to Disabled, the mount is not made
# recursively read-only. If this field is set to IfPossible, the mount is made
# recursively read-only, if it is supported by the container runtime. If this field is
# set to Enabled, the mount is made recursively read-only if it is supported by the
# container runtime, otherwise the pod will not be started and an error will be
# generated to indicate the reason.
#
# If this field is set to IfPossible or Enabled, MountPropagation must be set to None
# (or be unspecified, which defaults to None).
#
# If this field is not specified, it is treated as an equivalent of Disabled.
# recursiveReadOnly: "<string>"
# Path within the volume from which the container's volume should be mounted. Defaults
# to "" (volume's root).
# subPath: "<string>"
# Expanded path within the volume from which the container's volume should be mounted.
# Behaves similarly to SubPath but environment variable references $(VAR_NAME) are
# expanded using the container's environment. Defaults to "" (volume's root).
# SubPathExpr and SubPath are mutually exclusive.
# subPathExpr: "<string>"
# Container's working directory. If not specified, the container runtime's default will be
# used, which might be configured in the container image. Cannot be updated.
# workingDir: "<string>"
# NodeName indicates in which node this pod is scheduled. If empty, this pod is a candidate
# for scheduling by the scheduler defined in schedulerName. Once this field is set, the
# kubelet for this node becomes responsible for the lifecycle of this pod. This field should
# not be used to express a desire for the pod to be scheduled on a specific node.
# https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#nodename
# nodeName: "<string>"
# NodeSelector is a selector which must be true for the pod to fit on a node. Selector which
# must match a node's labels for the pod to be scheduled on that node. More info:
# https://kubernetes.io/docs/concepts/configuration/assign-pod-node/
# nodeSelector: # mapType: atomic
# <key>: "<string>"
# Specifies the OS of the containers in the pod. Some pod and container fields are
# restricted if this is set.
#
# If the OS field is set to linux, the following fields must be unset:
# -securityContext.windowsOptions
#
# If the OS field is set to windows, following fields must be unset: - spec.hostPID -
# spec.hostIPC - spec.hostUsers - spec.resources - spec.securityContext.appArmorProfile -
# spec.securityContext.seLinuxOptions - spec.securityContext.seccompProfile -
# spec.securityContext.fsGroup - spec.securityContext.fsGroupChangePolicy -
# spec.securityContext.sysctls - spec.shareProcessNamespace - spec.securityContext.runAsUser
# - spec.securityContext.runAsGroup - spec.securityContext.supplementalGroups -
# spec.securityContext.supplementalGroupsPolicy -
# spec.containers[*].securityContext.appArmorProfile -
# spec.containers[*].securityContext.seLinuxOptions -
# spec.containers[*].securityContext.seccompProfile -
# spec.containers[*].securityContext.capabilities -
# spec.containers[*].securityContext.readOnlyRootFilesystem -
# spec.containers[*].securityContext.privileged -
# spec.containers[*].securityContext.allowPrivilegeEscalation -
# spec.containers[*].securityContext.procMount -
# spec.containers[*].securityContext.runAsUser -
# spec.containers[*].securityContext.runAsGroup
os: # optional
# Name is the name of the operating system. The currently supported values are linux and
# windows. Additional value may be defined in future and can be one of:
# https://github.com/opencontainers/runtime-spec/blob/master/config.md#platform-specific-configuration
# Clients should expect to handle additional values and treat unrecognized values in this
# field as os: null
name: "<string>" # required
# Overhead represents the resource overhead associated with running a pod for a given
# RuntimeClass. This field will be autopopulated at admission time by the RuntimeClass
# admission controller. If the RuntimeClass admission controller is enabled, overhead must
# not be set in Pod create requests. The RuntimeClass admission controller will reject Pod
# create requests which have the overhead already set. If RuntimeClass is configured and
# selected in the PodSpec, Overhead will be set to the value defined in the corresponding
# RuntimeClass, otherwise it will remain unset and treated as zero. More info:
# https://git.k8s.io/enhancements/keps/sig-node/688-pod-overhead/README.md
# overhead:
# <key>: <int-or-string> # intOrString
# PreemptionPolicy is the Policy for preempting pods with lower priority. One of Never,
# PreemptLowerPriority. Defaults to PreemptLowerPriority if unset.
# preemptionPolicy: "<string>"
# The priority value. Various system components use this field to find the priority of the
# pod. When Priority Admission Controller is enabled, it prevents users from setting this
# field. The admission controller populates this field from PriorityClassName. The higher
# the value, the higher the priority.
# priority: <int32>
# If specified, indicates the pod's priority. "system-node-critical" and
# "system-cluster-critical" are two special keywords which indicate the highest priorities
# with the former being the highest priority. Any other name must be defined by creating a
# PriorityClass object with that name. If not specified, the pod priority will be default or
# zero if there is no default.
# priorityClassName: "<string>"
# If specified, all readiness gates will be evaluated for pod readiness. A pod is ready when
# all its containers are ready AND all conditions specified in the readiness gates have
# status equal to "True" More info:
# https://git.k8s.io/enhancements/keps/sig-network/580-pod-readiness-gates
readinessGates: # optional, listType: atomic
- # ConditionType refers to a condition in the pod's condition list with matching type.
conditionType: "<string>" # required
# ResourceClaims defines which ResourceClaims must be allocated and reserved before the Pod
# is allowed to start. The resources will be made available to those containers which
# consume them by name.
#
# This is an alpha field and requires enabling the DynamicResourceAllocation feature gate.
#
# This field is immutable.
resourceClaims: # optional, listType: map, listMapKeys: name
- # Name uniquely identifies this resource claim inside the pod. This must be a DNS_LABEL.
name: "<string>" # required
# ResourceClaimName is the name of a ResourceClaim object in the same namespace as this
# pod.
#
# Exactly one of ResourceClaimName and ResourceClaimTemplateName must be set.
# resourceClaimName: "<string>"
# ResourceClaimTemplateName is the name of a ResourceClaimTemplate object in the same
# namespace as this pod.
#
# The template will be used to create a new ResourceClaim, which will be bound to this
# pod. When this pod is deleted, the ResourceClaim will also be deleted. The pod name
# and resource name, along with a generated component, will be used to form a unique
# name for the ResourceClaim, which will be recorded in
# pod.status.resourceClaimStatuses.
#
# This field is immutable and no changes will be made to the corresponding ResourceClaim
# by the control plane after creating the ResourceClaim.
#
# Exactly one of ResourceClaimName and ResourceClaimTemplateName must be set.
# resourceClaimTemplateName: "<string>"
# Resources is the total amount of CPU and Memory resources required by all containers in
# the pod. It supports specifying Requests and Limits for "cpu", "memory" and "hugepages-"
# resource names only. ResourceClaims are not supported.
#
# This field enables fine-grained control over resource allocation for the entire pod,
# allowing resource sharing among containers in a pod.
#
# This is an alpha field and requires enabling the PodLevelResources feature gate.
resources: # optional
# Claims lists the names of resources, defined in spec.resourceClaims, that are used by
# this container.
#
# This field depends on the DynamicResourceAllocation feature gate.
#
# This field is immutable. It can only be set for containers.
claims: # optional, listType: map, listMapKeys: name
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod where
# this field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty,
# everything from the claim is made available, otherwise only the result of this
# request.
# request: "<string>"
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If Requests is
# omitted for a container, it defaults to Limits if that is explicitly specified,
# otherwise to an implementation-defined value. Requests cannot exceed Limits. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# Restart policy for all containers within the pod. One of Always, OnFailure, Never. In some
# contexts, only a subset of those values may be permitted. Default to Always. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#restart-policy
# restartPolicy: "<string>"
# RuntimeClassName refers to a RuntimeClass object in the node.k8s.io group, which should be
# used to run this pod. If no RuntimeClass resource matches the named class, the pod will
# not be run. If unset or empty, the "legacy" RuntimeClass will be used, which is an
# implicit class with an empty definition that uses the default runtime handler. More info:
# https://git.k8s.io/enhancements/keps/sig-node/585-runtime-class
# runtimeClassName: "<string>"
# If specified, the pod will be dispatched by specified scheduler. If not specified, the pod
# will be dispatched by default scheduler.
# schedulerName: "<string>"
# SchedulingGates is an opaque list of values that if specified will block scheduling the
# pod. If schedulingGates is not empty, the pod will stay in the SchedulingGated state and
# the scheduler will not attempt to schedule the pod.
#
# SchedulingGates can only be set at pod creation time, and be removed only afterwards.
schedulingGates: # optional, listType: map, listMapKeys: name
- # Name of the scheduling gate. Each scheduling gate must have a unique name field.
name: "<string>" # required
# SecurityContext holds pod-level security attributes and common container settings.
# Optional: Defaults to empty. See type description for default values of each field.
securityContext: # optional
# appArmorProfile is the AppArmor options to use by the containers in this pod. Note that
# this field cannot be set when spec.os.name is windows.
appArmorProfile: # optional
# type indicates which kind of AppArmor profile will be applied. Valid options are:
# Localhost - a profile pre-loaded on the node. RuntimeDefault - the container runtime's
# default profile. Unconfined - no AppArmor enforcement.
type: "<string>" # required
# localhostProfile indicates a profile loaded on the node that should be used. The
# profile must be preconfigured on the node to work. Must match the loaded name of the
# profile. Must be set if and only if type is "Localhost".
# localhostProfile: "<string>"
# A special supplemental group that applies to all containers in a pod. Some volume types
# allow the Kubelet to change the ownership of that volume to be owned by the pod:
#
# 1. The owning GID will be the FSGroup 2. The setgid bit is set (new files created in the
# volume will be owned by FSGroup) 3. The permission bits are OR'd with rw-rw----
#
# If unset, the Kubelet will not modify the ownership and permissions of any volume. Note
# that this field cannot be set when spec.os.name is windows.
# fsGroup: <int64>
# fsGroupChangePolicy defines behavior of changing ownership and permission of the volume
# before being exposed inside Pod. This field will only apply to volume types which
# support fsGroup based ownership(and permissions). It will have no effect on ephemeral
# volume types such as: secret, configmaps and emptydir. Valid values are "OnRootMismatch"
# and "Always". If not specified, "Always" is used. Note that this field cannot be set
# when spec.os.name is windows.
# fsGroupChangePolicy: "<string>"
# The GID to run the entrypoint of the container process. Uses runtime default if unset.
# May also be set in SecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence for that
# container. Note that this field cannot be set when spec.os.name is windows.
# runAsGroup: <int64>
# Indicates that the container must run as a non-root user. If true, the Kubelet will
# validate the image at runtime to ensure that it does not run as UID 0 (root) and fail to
# start the container if it does. If unset or false, no such validation will be performed.
# May also be set in SecurityContext. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence.
# runAsNonRoot: <boolean>
# The UID to run the entrypoint of the container process. Defaults to user specified in
# image metadata if unspecified. May also be set in SecurityContext. If set in both
# SecurityContext and PodSecurityContext, the value specified in SecurityContext takes
# precedence for that container. Note that this field cannot be set when spec.os.name is
# windows.
# runAsUser: <int64>
# seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes
# used by the Pod. It has no effect on nodes that do not support SELinux or to volumes
# does not support SELinux. Valid values are "MountOption" and "Recursive".
#
# "Recursive" means relabeling of all files on all Pod volumes by the container runtime.
# This may be slow for large volumes, but allows mixing privileged and unprivileged Pods
# sharing the same volume on the same node.
#
# "MountOption" mounts all eligible Pod volumes with `-o context` mount option. This
# requires all Pods that share the same volume to use the same SELinux label. It is not
# possible to share the same volume among privileged and unprivileged Pods. Eligible
# volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver
# announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver
# instance. Other volumes are always re-labelled recursively. "MountOption" value is
# allowed only when SELinuxMount feature gate is enabled.
#
# If not specified and SELinuxMount feature gate is enabled, "MountOption" is used. If not
# specified and SELinuxMount feature gate is disabled, "MountOption" is used for
# ReadWriteOncePod volumes and "Recursive" for all other volumes.
#
# This field affects only Pods that have SELinux label set, either in PodSecurityContext
# or in SecurityContext of all containers.
#
# All Pods that use the same volume should use the same seLinuxChangePolicy, otherwise
# some pods can get stuck in ContainerCreating state. Note that this field cannot be set
# when spec.os.name is windows.
# seLinuxChangePolicy: "<string>"
# The SELinux context to be applied to all containers. If unspecified, the container
# runtime will allocate a random SELinux context for each container. May also be set in
# SecurityContext. If set in both SecurityContext and PodSecurityContext, the value
# specified in SecurityContext takes precedence for that container. Note that this field
# cannot be set when spec.os.name is windows.
# seLinuxOptions:
# Level is SELinux level label that applies to the container.
# level: "<string>"
# Role is a SELinux role label that applies to the container.
# role: "<string>"
# Type is a SELinux type label that applies to the container.
# type: "<string>"
# User is a SELinux user label that applies to the container.
# user: "<string>"
# The seccomp options to use by the containers in this pod. Note that this field cannot be
# set when spec.os.name is windows.
seccompProfile: # optional
# type indicates which kind of seccomp profile will be applied. Valid options are:
#
# Localhost - a profile defined in a file on the node should be used. RuntimeDefault -
# the container runtime default profile should be used. Unconfined - no profile should
# be applied.
type: "<string>" # required
# localhostProfile indicates a profile defined in a file on the node should be used. The
# profile must be preconfigured on the node to work. Must be a descending path, relative
# to the kubelet's configured seccomp profile location. Must be set if type is
# "Localhost". Must NOT be set for any other type.
# localhostProfile: "<string>"
# A list of groups applied to the first process run in each container, in addition to the
# container's primary GID and fsGroup (if specified). If the SupplementalGroupsPolicy
# feature is enabled, the supplementalGroupsPolicy field determines whether these are in
# addition to or instead of any group memberships defined in the container image. If
# unspecified, no additional groups are added, though group memberships defined in the
# container image may still be used, depending on the supplementalGroupsPolicy field. Note
# that this field cannot be set when spec.os.name is windows.
# supplementalGroups: # listType: atomic
# - <int64>
# Defines how supplemental groups of the first container processes are calculated. Valid
# values are "Merge" and "Strict". If not specified, "Merge" is used. (Alpha) Using the
# field requires the SupplementalGroupsPolicy feature gate to be enabled and the container
# runtime must implement support for this feature. Note that this field cannot be set when
# spec.os.name is windows.
# supplementalGroupsPolicy: "<string>"
# Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported
# sysctls (by the container runtime) might fail to launch. Note that this field cannot be
# set when spec.os.name is windows.
sysctls: # optional, listType: atomic
- # Name of a property to set
name: "<string>" # required
# Value of a property to set
value: "<string>" # required
# The Windows specific settings applied to all containers. If unspecified, the options
# within a container's SecurityContext will be used. If set in both SecurityContext and
# PodSecurityContext, the value specified in SecurityContext takes precedence. Note that
# this field cannot be set when spec.os.name is linux.
# windowsOptions:
# GMSACredentialSpec is where the GMSA admission webhook
# (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the GMSA
# credential spec named by the GMSACredentialSpecName field.
# gmsaCredentialSpec: "<string>"
# GMSACredentialSpecName is the name of the GMSA credential spec to use.
# gmsaCredentialSpecName: "<string>"
# HostProcess determines if a container should be run as a 'Host Process' container. All
# of a Pod's containers must have the same effective HostProcess value (it is not
# allowed to have a mix of HostProcess containers and non-HostProcess containers). In
# addition, if HostProcess is true then HostNetwork must also be set to true.
# hostProcess: <boolean>
# The UserName in Windows to run the entrypoint of the container process. Defaults to
# the user specified in image metadata if unspecified. May also be set in
# PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value
# specified in SecurityContext takes precedence.
# runAsUserName: "<string>"
# DeprecatedServiceAccount is a deprecated alias for ServiceAccountName. Deprecated: Use
# serviceAccountName instead.
# serviceAccount: "<string>"
# ServiceAccountName is the name of the ServiceAccount to use to run this pod. More info:
# https://kubernetes.io/docs/tasks/configure-pod-container/configure-service-account/
# serviceAccountName: "<string>"
# If true the pod's hostname will be configured as the pod's FQDN, rather than the leaf name
# (the default). In Linux containers, this means setting the FQDN in the hostname field of
# the kernel (the nodename field of struct utsname). In Windows containers, this means
# setting the registry value of hostname for the registry key
# HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters to FQDN. If a
# pod does not have FQDN, this has no effect. Default to false.
# setHostnameAsFQDN: <boolean>
# Share a single process namespace between all of the containers in a pod. When this is set
# containers will be able to view and signal processes from other containers in the same
# pod, and the first process in each container will not be assigned PID 1. HostPID and
# ShareProcessNamespace cannot both be set. Optional: Default to false.
# shareProcessNamespace: <boolean>
# If specified, the fully qualified Pod hostname will be "<hostname>.<subdomain>.<pod
# namespace>.svc.<cluster domain>". If not specified, the pod will not have a domainname at
# all.
# subdomain: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully. May be decreased in
# delete request. Value must be non-negative integer. The value zero indicates stop
# immediately via the kill signal (no opportunity to shut down). If this value is nil, the
# default grace period will be used instead. The grace period is the duration in seconds
# after the processes running in the pod are sent a termination signal and the time when the
# processes are forcibly halted with a kill signal. Set this value longer than the expected
# cleanup time for your process. Defaults to 30 seconds.
# terminationGracePeriodSeconds: <int64>
# If specified, the pod's tolerations.
# tolerations: # listType: atomic
# - # Effect indicates the taint effect to match. Empty means match all taint effects. When
# specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute.
# effect: "<string>"
# Key is the taint key that the toleration applies to. Empty means match all taint keys.
# If the key is empty, operator must be Exists; this combination means to match all
# values and all keys.
# key: "<string>"
# Operator represents a key's relationship to the value. Valid operators are Exists and
# Equal. Defaults to Equal. Exists is equivalent to wildcard for value, so that a pod
# can tolerate all taints of a particular category.
# operator: "<string>"
# TolerationSeconds represents the period of time the toleration (which must be of
# effect NoExecute, otherwise this field is ignored) tolerates the taint. By default, it
# is not set, which means tolerate the taint forever (do not evict). Zero and negative
# values will be treated as 0 (evict immediately) by the system.
# tolerationSeconds: <int64>
# Value is the taint value the toleration matches to. If the operator is Exists, the
# value should be empty, otherwise just a regular string.
# value: "<string>"
# TopologySpreadConstraints describes how a group of pods ought to spread across topology
# domains. Scheduler will schedule pods in a way which abides by the constraints. All
# topologySpreadConstraints are ANDed.
topologySpreadConstraints: # optional, listType: map, listMapKeys: topologyKey,
# whenUnsatisfiable
- # MaxSkew describes the degree to which pods may be unevenly distributed. When
# `whenUnsatisfiable=DoNotSchedule`, it is the maximum permitted difference between the
# number of matching pods in the target topology and the global minimum. The global
# minimum is the minimum number of matching pods in an eligible domain or zero if the
# number of eligible domains is less than MinDomains. For example, in a 3-zone cluster,
# MaxSkew is set to 1, and pods with the same labelSelector spread as 2/2/1: In this
# case, the global minimum is 1. | zone1 | zone2 | zone3 | | P P | P P | P | - if
# MaxSkew is 1, incoming pod can only be scheduled to zone3 to become 2/2/2; scheduling
# it onto zone1(zone2) would make the ActualSkew(3-1) on zone1(zone2) violate
# MaxSkew(1). - if MaxSkew is 2, incoming pod can be scheduled onto any zone. When
# `whenUnsatisfiable=ScheduleAnyway`, it is used to give higher precedence to topologies
# that satisfy it. It's a required field. Default value is 1 and 0 is not allowed.
maxSkew: <int32> # required
# TopologyKey is the key of node labels. Nodes that have a label with this key and
# identical values are considered to be in the same topology. We consider each <key,
# value> as a "bucket", and try to put balanced number of pods into each bucket. We
# define a domain as a particular instance of a topology. Also, we define an eligible
# domain as a domain whose nodes meet the requirements of nodeAffinityPolicy and
# nodeTaintsPolicy. e.g. If TopologyKey is "kubernetes.io/hostname", each Node is a
# domain of that topology. And, if TopologyKey is "topology.kubernetes.io/zone", each
# zone is a domain of that topology. It's a required field.
topologyKey: "<string>" # required
# WhenUnsatisfiable indicates how to deal with a pod if it doesn't satisfy the spread
# constraint. - DoNotSchedule (default) tells the scheduler not to schedule it. -
# ScheduleAnyway tells the scheduler to schedule the pod in any location, but giving
# higher precedence to topologies that would help reduce the skew. A constraint is
# considered "Unsatisfiable" for an incoming pod if and only if every possible node
# assignment for that pod would violate "MaxSkew" on some topology. For example, in a
# 3-zone cluster, MaxSkew is set to 1, and pods with the same labelSelector spread as
# 3/1/1: | zone1 | zone2 | zone3 | | P P P | P | P | If WhenUnsatisfiable is set to
# DoNotSchedule, incoming pod can only be scheduled to zone2(zone3) to become
# 3/2/1(3/1/2) as ActualSkew(2-1) on zone2(zone3) satisfies MaxSkew(1). In other words,
# the cluster can still be imbalanced, but scheduler won't make it *more* imbalanced.
# It's a required field.
whenUnsatisfiable: "<string>" # required
# LabelSelector is used to find matching pods. Pods that match this label selector are
# counted to determine the number of pods in their corresponding topology domain.
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements are
# ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid operators are
# In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the values
# array must be non-empty. If the operator is Exists or DoesNotExist, the values
# array must be empty. This array is replaced during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
# map is equivalent to an element of matchExpressions, whose key field is "key", the
# operator is "In", and the values array contains only "value". The requirements are
# ANDed.
# matchLabels:
# <key>: "<string>"
# MatchLabelKeys is a set of pod label keys to select the pods over which spreading will
# be calculated. The keys are used to lookup values from the incoming pod labels, those
# key-value labels are ANDed with labelSelector to select the group of existing pods
# over which spreading will be calculated for the incoming pod. The same key is
# forbidden to exist in both MatchLabelKeys and LabelSelector. MatchLabelKeys cannot be
# set when LabelSelector isn't set. Keys that don't exist in the incoming pod labels
# will be ignored. A null or empty list means only match against labelSelector.
#
# This is a beta field and requires the MatchLabelKeysInPodTopologySpread feature gate
# to be enabled (enabled by default).
# matchLabelKeys: # listType: atomic
# - "<string>"
# MinDomains indicates a minimum number of eligible domains. When the number of eligible
# domains with matching topology keys is less than minDomains, Pod Topology Spread
# treats "global minimum" as 0, and then the calculation of Skew is performed. And when
# the number of eligible domains with matching topology keys equals or greater than
# minDomains, this value has no effect on scheduling. As a result, when the number of
# eligible domains is less than minDomains, scheduler won't schedule more than maxSkew
# Pods to those domains. If value is nil, the constraint behaves as if MinDomains is
# equal to 1. Valid values are integers greater than 0. When value is not nil,
# WhenUnsatisfiable must be DoNotSchedule.
#
# For example, in a 3-zone cluster, MaxSkew is set to 2, MinDomains is set to 5 and pods
# with the same labelSelector spread as 2/2/2: | zone1 | zone2 | zone3 | | P P | P P | P
# P | The number of domains is less than 5(MinDomains), so "global minimum" is treated
# as 0. In this situation, new pod with the same labelSelector cannot be scheduled,
# because computed skew will be 3(3 - 0) if new Pod is scheduled to any of the three
# zones, it will violate MaxSkew.
# minDomains: <int32>
# NodeAffinityPolicy indicates how we will treat Pod's nodeAffinity/nodeSelector when
# calculating pod topology spread skew. Options are: - Honor: only nodes matching
# nodeAffinity/nodeSelector are included in the calculations. - Ignore:
# nodeAffinity/nodeSelector are ignored. All nodes are included in the calculations.
#
# If this value is nil, the behavior is equivalent to the Honor policy.
# nodeAffinityPolicy: "<string>"
# NodeTaintsPolicy indicates how we will treat node taints when calculating pod topology
# spread skew. Options are: - Honor: nodes without taints, along with tainted nodes for
# which the incoming pod has a toleration, are included. - Ignore: node taints are
# ignored. All nodes are included.
#
# If this value is nil, the behavior is equivalent to the Ignore policy.
# nodeTaintsPolicy: "<string>"
# List of volumes that can be mounted by containers belonging to the pod. More info:
# https://kubernetes.io/docs/concepts/storage/volumes
volumes: # optional, listType: map, listMapKeys: name
- # name of the volume. Must be a DNS_LABEL and unique within the pod. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
name: "<string>" # required
# awsElasticBlockStore represents an AWS Disk resource that is attached to a kubelet's
# host machine and then exposed to the pod. Deprecated: AWSElasticBlockStore is
# deprecated. All operations for the in-tree awsElasticBlockStore type are redirected to
# the ebs.csi.aws.com CSI driver. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
awsElasticBlockStore: # optional
# volumeID is unique ID of the persistent disk resource in AWS (Amazon EBS volume).
# More info: https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
volumeID: "<string>" # required
# fsType is the filesystem type of the volume that you want to mount. Tip: Ensure that
# the filesystem type is supported by the host operating system. Examples: "ext4",
# "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
# fsType: "<string>"
# partition is the partition in the volume that you want to mount. If omitted, the
# default is to mount by volume name. Examples: For volume /dev/sda1, you specify the
# partition as "1". Similarly, the volume partition for /dev/sda is "0" (or you can
# leave the property empty).
# partition: <int32>
# readOnly value true will force the readOnly setting in VolumeMounts. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#awselasticblockstore
# readOnly: <boolean>
# azureDisk represents an Azure Data Disk mount on the host and bind mount to the pod.
# Deprecated: AzureDisk is deprecated. All operations for the in-tree azureDisk type are
# redirected to the disk.csi.azure.com CSI driver.
azureDisk: # optional
# diskName is the Name of the data disk in the blob storage
diskName: "<string>" # required
# diskURI is the URI of data disk in the blob storage
diskURI: "<string>" # required
# cachingMode is the Host Caching mode: None, Read Only, Read Write.
# cachingMode: "<string>"
# fsType is Filesystem type to mount. Must be a filesystem type supported by the host
# operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
# unspecified.
# fsType: "ext4" # default
# kind expected values are Shared: multiple blob disks per storage account Dedicated:
# single blob disk per storage account Managed: azure managed data disk (only in
# managed availability set). defaults to shared
# kind: "<string>"
# readOnly Defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: false # default
# azureFile represents an Azure File Service mount on the host and bind mount to the
# pod. Deprecated: AzureFile is deprecated. All operations for the in-tree azureFile
# type are redirected to the file.csi.azure.com CSI driver.
azureFile: # optional
# secretName is the name of secret that contains Azure Storage Account Name and Key
secretName: "<string>" # required
# shareName is the azure share Name
shareName: "<string>" # required
# readOnly defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: <boolean>
# cephFS represents a Ceph FS mount on the host that shares a pod's lifetime.
# Deprecated: CephFS is deprecated and the in-tree cephfs type is no longer supported.
cephfs: # optional
# monitors is Required: Monitors is a collection of Ceph monitors More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
monitors: # required, listType: atomic
- "<string>"
# path is Optional: Used as the mounted root, rather than the full Ceph tree, default
# is /
# path: "<string>"
# readOnly is Optional: Defaults to false (read/write). ReadOnly here will force the
# ReadOnly setting in VolumeMounts. More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
# readOnly: <boolean>
# secretFile is Optional: SecretFile is the path to key ring for User, default is
# /etc/ceph/user.secret More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
# secretFile: "<string>"
# secretRef is Optional: SecretRef is reference to the authentication secret for User,
# default is empty. More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# user is optional: User is the rados user name, default is admin More info:
# https://examples.k8s.io/volumes/cephfs/README.md#how-to-use-it
# user: "<string>"
# cinder represents a cinder volume attached and mounted on kubelets host machine.
# Deprecated: Cinder is deprecated. All operations for the in-tree cinder type are
# redirected to the cinder.csi.openstack.org CSI driver. More info:
# https://examples.k8s.io/mysql-cinder-pd/README.md
cinder: # optional
# volumeID used to identify the volume in cinder. More info:
# https://examples.k8s.io/mysql-cinder-pd/README.md
volumeID: "<string>" # required
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Examples: "ext4", "xfs", "ntfs". Implicitly inferred to be
# "ext4" if unspecified. More info: https://examples.k8s.io/mysql-cinder-pd/README.md
# fsType: "<string>"
# readOnly defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts. More info:
# https://examples.k8s.io/mysql-cinder-pd/README.md
# readOnly: <boolean>
# secretRef is optional: points to a secret object containing parameters used to
# connect to OpenStack.
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# configMap represents a configMap that should populate this volume
configMap: # optional, mapType: atomic
# defaultMode is optional: mode bits used to set permissions on created files by
# default. Must be an octal value between 0000 and 0777 or a decimal value between 0
# and 511. YAML accepts both octal and decimal values, JSON requires decimal values
# for mode bits. Defaults to 0644. Directories within the path are not affected by
# this setting. This might be in conflict with other options that affect the file
# mode, like fsGroup, and the result can be other mode bits set.
# defaultMode: <int32>
# items if unspecified, each key-value pair in the Data field of the referenced
# ConfigMap will be projected into the volume as a file whose name is the key and
# content is the value. If specified, the listed keys will be projected into the
# specified paths, and unlisted keys will not be present. If a key is specified which
# is not present in the ConfigMap, the volume setup will error unless it is marked
# optional. Paths must be relative and may not contain the '..' path or start with
# '..'.
items: # optional, listType: atomic
- # key is the key to project.
key: "<string>" # required
# path is the relative path of the file to map the key to. May not be an absolute
# path. May not contain the path element '..'. May not start with the string '..'.
path: "<string>" # required
# mode is Optional: mode bits used to set permissions on this file. Must be an
# octal value between 0000 and 0777 or a decimal value between 0 and 511. YAML
# accepts both octal and decimal values, JSON requires decimal values for mode
# bits. If not specified, the volume defaultMode will be used. This might be in
# conflict with other options that affect the file mode, like fsGroup, and the
# result can be other mode bits set.
# mode: <int32>
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# optional specify whether the ConfigMap or its keys must be defined
# optional: <boolean>
# csi (Container Storage Interface) represents ephemeral storage that is handled by
# certain external CSI drivers.
csi: # optional
# driver is the name of the CSI driver that handles this volume. Consult with your
# admin for the correct name as registered in the cluster.
driver: "<string>" # required
# fsType to mount. Ex. "ext4", "xfs", "ntfs". If not provided, the empty value is
# passed to the associated CSI driver which will determine the default filesystem to
# apply.
# fsType: "<string>"
# nodePublishSecretRef is a reference to the secret object containing sensitive
# information to pass to the CSI driver to complete the CSI NodePublishVolume and
# NodeUnpublishVolume calls. This field is optional, and may be empty if no secret is
# required. If the secret object contains more than one secret, all secret references
# are passed.
# nodePublishSecretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# readOnly specifies a read-only configuration for the volume. Defaults to false
# (read/write).
# readOnly: <boolean>
# volumeAttributes stores driver-specific properties that are passed to the CSI
# driver. Consult your driver's documentation for supported values.
# volumeAttributes:
# <key>: "<string>"
# downwardAPI represents downward API about the pod that should populate this volume
downwardAPI: # optional
# Optional: mode bits to use on created files by default. Must be a Optional: mode
# bits used to set permissions on created files by default. Must be an octal value
# between 0000 and 0777 or a decimal value between 0 and 511. YAML accepts both octal
# and decimal values, JSON requires decimal values for mode bits. Defaults to 0644.
# Directories within the path are not affected by this setting. This might be in
# conflict with other options that affect the file mode, like fsGroup, and the result
# can be other mode bits set.
# defaultMode: <int32>
# Items is a list of downward API volume file
items: # optional, listType: atomic
- # Required: Path is the relative path name of the file to be created. Must not be
# absolute or contain the '..' path. Must be utf-8 encoded. The first item of the
# relative path must not start with '..'
path: "<string>" # required
# Required: Selects a field of the pod: only annotations, labels, name, namespace
# and uid are supported.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# Optional: mode bits used to set permissions on this file, must be an octal value
# between 0000 and 0777 or a decimal value between 0 and 511. YAML accepts both
# octal and decimal values, JSON requires decimal values for mode bits. If not
# specified, the volume defaultMode will be used. This might be in conflict with
# other options that affect the file mode, like fsGroup, and the result can be
# other mode bits set.
# mode: <int32>
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, requests.cpu and requests.memory) are currently
# supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# emptyDir represents a temporary directory that shares a pod's lifetime. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#emptydir
# emptyDir:
# medium represents what type of storage medium should back this directory. The
# default is "" which means to use the node's default medium. Must be an empty string
# (default) or Memory. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#emptydir
# medium: "<string>"
# sizeLimit is the total amount of local storage required for this EmptyDir volume.
# The size limit is also applicable for memory medium. The maximum usage on memory
# medium EmptyDir would be the minimum value between the SizeLimit specified here and
# the sum of memory limits of all containers in a pod. The default is nil which means
# that the limit is undefined. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#emptydir
# sizeLimit: <int-or-string> # intOrString
# ephemeral represents a volume that is handled by a cluster storage driver. The
# volume's lifecycle is tied to the pod that defines it - it will be created before the
# pod starts, and deleted when the pod is removed.
#
# Use this if: a) the volume is only needed while the pod runs, b) features of normal
# volumes like restoring from snapshot or capacity tracking are needed, c) the storage
# driver is specified through a storage class, and d) the storage driver supports
# dynamic volume provisioning through a PersistentVolumeClaim (see EphemeralVolumeSource
# for more information on the connection between this volume type and
# PersistentVolumeClaim).
#
# Use PersistentVolumeClaim or one of the vendor-specific APIs for volumes that persist
# for longer than the lifecycle of an individual pod.
#
# Use CSI for light-weight local ephemeral volumes if the CSI driver is meant to be used
# that way - see the documentation of the driver for more information.
#
# A pod can use both types of ephemeral volumes and persistent volumes at the same time.
ephemeral: # optional
# Will be used to create a stand-alone PVC to provision the volume. The pod in which
# this EphemeralVolumeSource is embedded will be the owner of the PVC, i.e. the PVC
# will be deleted together with the pod. The name of the PVC will be `<pod
# name>-<volume name>` where `<volume name>` is the name from the `PodSpec.Volumes`
# array entry. Pod validation will reject the pod if the concatenated name is not
# valid for a PVC (for example, too long).
#
# An existing PVC with that name that is not owned by the pod will *not* be used for
# the pod to avoid using an unrelated volume by mistake. Starting the pod is then
# blocked until the unrelated PVC is removed. If such a pre-created PVC is meant to be
# used by the pod, the PVC has to updated with an owner reference to the pod once the
# pod exists. Normally this should not be necessary, but it may be useful when
# manually reconstructing a broken cluster.
#
# This field is read-only and no changes will be made by Kubernetes to the PVC after
# it has been created.
#
# Required, must not be nil.
volumeClaimTemplate: # optional
# The specification for the PersistentVolumeClaim. The entire content is copied
# unchanged into the PVC that gets created from this template. The same fields as in
# a PersistentVolumeClaim are also valid here.
spec: # required
# accessModes contains the desired access modes the volume should have. More info:
# https://kubernetes.io/docs/concepts/storage/persistent-volumes#access-modes-1
# accessModes: # listType: atomic
# - "<string>"
# dataSource field can be used to specify either: * An existing VolumeSnapshot
# object (snapshot.storage.k8s.io/VolumeSnapshot) * An existing PVC
# (PersistentVolumeClaim) If the provisioner or an external controller can support
# the specified data source, it will create a new volume based on the contents of
# the specified data source. When the AnyVolumeDataSource feature gate is enabled,
# dataSource contents will be copied to dataSourceRef, and dataSourceRef contents
# will be copied to dataSource when dataSourceRef.namespace is not specified. If
# the namespace is specified, then dataSourceRef will not be copied to dataSource.
dataSource: # optional, mapType: atomic
# Kind is the type of resource being referenced
kind: "<string>" # required
# Name is the name of resource being referenced
name: "<string>" # required
# APIGroup is the group for the resource being referenced. If APIGroup is not
# specified, the specified Kind must be in the core API group. For any other
# third-party types, APIGroup is required.
# apiGroup: "<string>"
# dataSourceRef specifies the object from which to populate the volume with data,
# if a non-empty volume is desired. This may be any object from a non-empty API
# group (non core object) or a PersistentVolumeClaim object. When this field is
# specified, volume binding will only succeed if the type of the specified object
# matches some installed volume populator or dynamic provisioner. This field will
# replace the functionality of the dataSource field and as such if both fields are
# non-empty, they must have the same value. For backwards compatibility, when
# namespace isn't specified in dataSourceRef, both fields (dataSource and
# dataSourceRef) will be set to the same value automatically if one of them is
# empty and the other is non-empty. When namespace is specified in dataSourceRef,
# dataSource isn't set to the same value and must be empty. There are three
# important differences between dataSource and dataSourceRef: * While dataSource
# only allows two specific types of objects, dataSourceRef allows any non-core
# object, as well as PersistentVolumeClaim objects. * While dataSource ignores
# disallowed values (dropping them), dataSourceRef preserves all values, and
# generates an error if a disallowed value is specified. * While dataSource only
# allows local objects, dataSourceRef allows objects in any namespaces. (Beta)
# Using this field requires the AnyVolumeDataSource feature gate to be enabled.
# (Alpha) Using the namespace field of dataSourceRef requires the
# CrossNamespaceVolumeDataSource feature gate to be enabled.
dataSourceRef: # optional
# Kind is the type of resource being referenced
kind: "<string>" # required
# Name is the name of resource being referenced
name: "<string>" # required
# APIGroup is the group for the resource being referenced. If APIGroup is not
# specified, the specified Kind must be in the core API group. For any other
# third-party types, APIGroup is required.
# apiGroup: "<string>"
# Namespace is the namespace of resource being referenced Note that when a
# namespace is specified, a gateway.networking.k8s.io/ReferenceGrant object is
# required in the referent namespace to allow that namespace's owner to accept
# the reference. See the ReferenceGrant documentation for details. (Alpha) This
# field requires the CrossNamespaceVolumeDataSource feature gate to be enabled.
# namespace: "<string>"
# resources represents the minimum resources the volume should have. If
# RecoverVolumeExpansionFailure feature is enabled users are allowed to specify
# resource requirements that are lower than previous value but must still be
# higher than capacity recorded in the status field of the claim. More info:
# https://kubernetes.io/docs/concepts/storage/persistent-volumes#resources
# resources:
# Limits describes the maximum amount of compute resources allowed. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# limits:
# <key>: <int-or-string> # intOrString
# Requests describes the minimum amount of compute resources required. If
# Requests is omitted for a container, it defaults to Limits if that is
# explicitly specified, otherwise to an implementation-defined value. Requests
# cannot exceed Limits. More info:
# https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/
# requests:
# <key>: <int-or-string> # intOrString
# selector is a label query over volumes to consider for binding.
selector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or DoesNotExist,
# the values array must be empty. This array is replaced during a strategic
# merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# storageClassName is the name of the StorageClass required by the claim. More
# info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#class-1
# storageClassName: "<string>"
# volumeAttributesClassName may be used to set the VolumeAttributesClass used by
# this claim. If specified, the CSI driver will create or update the volume with
# the attributes defined in the corresponding VolumeAttributesClass. This has a
# different purpose than storageClassName, it can be changed after the claim is
# created. An empty string or nil value indicates that no VolumeAttributesClass
# will be applied to the claim. If the claim enters an Infeasible error state,
# this field can be reset to its previous value (including nil) to cancel the
# modification. If the resource referred to by volumeAttributesClass does not
# exist, this PersistentVolumeClaim will be set to a Pending state, as reflected
# by the modifyVolumeStatus field, until such as a resource exists. More info:
# https://kubernetes.io/docs/concepts/storage/volume-attributes-classes/
# volumeAttributesClassName: "<string>"
# volumeMode defines what type of volume is required by the claim. Value of
# Filesystem is implied when not included in claim spec.
# volumeMode: "<string>"
# volumeName is the binding reference to the PersistentVolume backing this claim.
# volumeName: "<string>"
# May contain labels and annotations that will be copied into the PVC when creating
# it. No other fields are allowed and will be rejected during validation.
# metadata:
# annotations:
# <key>: "<string>"
# finalizers:
# - "<string>"
# labels:
# <key>: "<string>"
# name: "<string>"
# namespace: "<string>"
# fc represents a Fibre Channel resource that is attached to a kubelet's host machine
# and then exposed to the pod.
# fc:
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "<string>"
# lun is Optional: FC target lun number
# lun: <int32>
# readOnly is Optional: Defaults to false (read/write). ReadOnly here will force the
# ReadOnly setting in VolumeMounts.
# readOnly: <boolean>
# targetWWNs is Optional: FC target worldwide names (WWNs)
# targetWWNs: # listType: atomic
# - "<string>"
# wwids Optional: FC volume world wide identifiers (wwids) Either wwids or combination
# of targetWWNs and lun must be set, but not both simultaneously.
# wwids: # listType: atomic
# - "<string>"
# flexVolume represents a generic volume resource that is provisioned/attached using an
# exec based plugin. Deprecated: FlexVolume is deprecated. Consider using a CSIDriver
# instead.
flexVolume: # optional
# driver is the name of the driver to use for this volume.
driver: "<string>" # required
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". The default filesystem depends on
# FlexVolume script.
# fsType: "<string>"
# options is Optional: this field holds extra command options if any.
# options:
# <key>: "<string>"
# readOnly is Optional: defaults to false (read/write). ReadOnly here will force the
# ReadOnly setting in VolumeMounts.
# readOnly: <boolean>
# secretRef is Optional: secretRef is reference to the secret object containing
# sensitive information to pass to the plugin scripts. This may be empty if no secret
# object is specified. If the secret object contains more than one secret, all secrets
# are passed to the plugin scripts.
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# flocker represents a Flocker volume attached to a kubelet's host machine. This depends
# on the Flocker control service being running. Deprecated: Flocker is deprecated and
# the in-tree flocker type is no longer supported.
# flocker:
# datasetName is Name of the dataset stored as metadata -> name on the dataset for
# Flocker should be considered as deprecated
# datasetName: "<string>"
# datasetUUID is the UUID of the dataset. This is unique identifier of a Flocker
# dataset
# datasetUUID: "<string>"
# gcePersistentDisk represents a GCE Disk resource that is attached to a kubelet's host
# machine and then exposed to the pod. Deprecated: GCEPersistentDisk is deprecated. All
# operations for the in-tree gcePersistentDisk type are redirected to the
# pd.csi.storage.gke.io CSI driver. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
gcePersistentDisk: # optional
# pdName is unique name of the PD resource in GCE. Used to identify the disk in GCE.
# More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
pdName: "<string>" # required
# fsType is filesystem type of the volume that you want to mount. Tip: Ensure that the
# filesystem type is supported by the host operating system. Examples: "ext4", "xfs",
# "ntfs". Implicitly inferred to be "ext4" if unspecified. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
# fsType: "<string>"
# partition is the partition in the volume that you want to mount. If omitted, the
# default is to mount by volume name. Examples: For volume /dev/sda1, you specify the
# partition as "1". Similarly, the volume partition for /dev/sda is "0" (or you can
# leave the property empty). More info:
# https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
# partition: <int32>
# readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
# More info: https://kubernetes.io/docs/concepts/storage/volumes#gcepersistentdisk
# readOnly: <boolean>
# gitRepo represents a git repository at a particular revision. Deprecated: GitRepo is
# deprecated. To provision a container with a git repo, mount an EmptyDir into an
# InitContainer that clones the repo using git, then mount the EmptyDir into the Pod's
# container.
gitRepo: # optional
# repository is the URL
repository: "<string>" # required
# directory is the target directory name. Must not contain or start with '..'. If '.'
# is supplied, the volume directory will be the git repository. Otherwise, if
# specified, the volume will contain the git repository in the subdirectory with the
# given name.
# directory: "<string>"
# revision is the commit hash for the specified revision.
# revision: "<string>"
# glusterfs represents a Glusterfs mount on the host that shares a pod's lifetime.
# Deprecated: Glusterfs is deprecated and the in-tree glusterfs type is no longer
# supported.
glusterfs: # optional
# endpoints is the endpoint name that details Glusterfs topology.
endpoints: "<string>" # required
# path is the Glusterfs volume path. More info:
# https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
path: "<string>" # required
# readOnly here will force the Glusterfs volume to be mounted with read-only
# permissions. Defaults to false. More info:
# https://examples.k8s.io/volumes/glusterfs/README.md#create-a-pod
# readOnly: <boolean>
# hostPath represents a pre-existing file or directory on the host machine that is
# directly exposed to the container. This is generally used for system agents or other
# privileged things that are allowed to see the host machine. Most containers will NOT
# need this. More info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath
hostPath: # optional
# path of the directory on the host. If the path is a symlink, it will follow the link
# to the real path. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#hostpath
path: "<string>" # required
# type for HostPath Volume Defaults to "" More info:
# https://kubernetes.io/docs/concepts/storage/volumes#hostpath
# type: "<string>"
# image represents an OCI object (a container image or artifact) pulled and mounted on
# the kubelet's host machine. The volume is resolved at pod startup depending on which
# PullPolicy value is provided:
#
# - Always: the kubelet always attempts to pull the reference. Container creation will
# fail If the pull fails. - Never: the kubelet never pulls the reference and only uses a
# local image or artifact. Container creation will fail if the reference isn't present.
# - IfNotPresent: the kubelet pulls if the reference isn't already present on disk.
# Container creation will fail if the reference isn't present and the pull fails.
#
# The volume gets re-resolved if the pod gets deleted and recreated, which means that
# new remote content will become available on pod recreation. A failure to resolve or
# pull the image during pod startup will block containers from starting and may add
# significant latency. Failures will be retried using normal volume backoff and will be
# reported on the pod reason and message. The types of objects that may be mounted by
# this volume are defined by the container runtime implementation on a host machine and
# at minimum must include all valid types supported by the container image field. The
# OCI object gets mounted in a single directory
# (spec.containers[*].volumeMounts.mountPath) by merging the manifest layers in the same
# way as for container images. The volume will be mounted read-only (ro) and
# non-executable files (noexec). Sub path mounts for containers are not supported
# (spec.containers[*].volumeMounts.subpath) before 1.33. The field
# spec.securityContext.fsGroupChangePolicy has no effect on this volume type.
# image:
# Policy for pulling OCI objects. Possible values are: Always: the kubelet always
# attempts to pull the reference. Container creation will fail If the pull fails.
# Never: the kubelet never pulls the reference and only uses a local image or
# artifact. Container creation will fail if the reference isn't present. IfNotPresent:
# the kubelet pulls if the reference isn't already present on disk. Container creation
# will fail if the reference isn't present and the pull fails. Defaults to Always if
# :latest tag is specified, or IfNotPresent otherwise.
# pullPolicy: "<string>"
# Required: Image or artifact reference to be used. Behaves in the same way as
# pod.spec.containers[*].image. Pull secrets will be assembled in the same way as for
# the container image by looking up node credentials, SA image pull secrets, and pod
# spec image pull secrets. More info:
# https://kubernetes.io/docs/concepts/containers/images This field is optional to
# allow higher level config management to default or override container images in
# workload controllers like Deployments and StatefulSets.
# reference: "<string>"
# iscsi represents an ISCSI Disk resource that is attached to a kubelet's host machine
# and then exposed to the pod. More info:
# https://kubernetes.io/docs/concepts/storage/volumes/#iscsi
iscsi: # optional
# iqn is the target iSCSI Qualified Name.
iqn: "<string>" # required
# lun represents iSCSI Target Lun number.
lun: <int32> # required
# targetPortal is iSCSI Target Portal. The Portal is either an IP or ip_addr:port if
# the port is other than default (typically TCP ports 860 and 3260).
targetPortal: "<string>" # required
# chapAuthDiscovery defines whether support iSCSI Discovery CHAP authentication
# chapAuthDiscovery: <boolean>
# chapAuthSession defines whether support iSCSI Session CHAP authentication
# chapAuthSession: <boolean>
# fsType is the filesystem type of the volume that you want to mount. Tip: Ensure that
# the filesystem type is supported by the host operating system. Examples: "ext4",
# "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#iscsi
# fsType: "<string>"
# initiatorName is the custom iSCSI Initiator Name. If initiatorName is specified with
# iscsiInterface simultaneously, new iSCSI interface <target portal>:<volume name>
# will be created for the connection.
# initiatorName: "<string>"
# iscsiInterface is the interface Name that uses an iSCSI transport. Defaults to
# 'default' (tcp).
# iscsiInterface: "default" # default
# portals is the iSCSI Target Portal List. The portal is either an IP or ip_addr:port
# if the port is other than default (typically TCP ports 860 and 3260).
# portals: # listType: atomic
# - "<string>"
# readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
# readOnly: <boolean>
# secretRef is the CHAP Secret for iSCSI target and initiator authentication
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# nfs represents an NFS mount on the host that shares a pod's lifetime More info:
# https://kubernetes.io/docs/concepts/storage/volumes#nfs
nfs: # optional
# path that is exported by the NFS server. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#nfs
path: "<string>" # required
# server is the hostname or IP address of the NFS server. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#nfs
server: "<string>" # required
# readOnly here will force the NFS export to be mounted with read-only permissions.
# Defaults to false. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#nfs
# readOnly: <boolean>
# persistentVolumeClaimVolumeSource represents a reference to a PersistentVolumeClaim in
# the same namespace. More info:
# https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
persistentVolumeClaim: # optional
# claimName is the name of a PersistentVolumeClaim in the same namespace as the pod
# using this volume. More info:
# https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims
claimName: "<string>" # required
# readOnly Will force the ReadOnly setting in VolumeMounts. Default false.
# readOnly: <boolean>
# photonPersistentDisk represents a PhotonController persistent disk attached and
# mounted on kubelets host machine. Deprecated: PhotonPersistentDisk is deprecated and
# the in-tree photonPersistentDisk type is no longer supported.
photonPersistentDisk: # optional
# pdID is the ID that identifies Photon Controller persistent disk
pdID: "<string>" # required
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "<string>"
# portworxVolume represents a portworx volume attached and mounted on kubelets host
# machine. Deprecated: PortworxVolume is deprecated. All operations for the in-tree
# portworxVolume type are redirected to the pxd.portworx.com CSI driver when the
# CSIMigrationPortworx feature-gate is on.
portworxVolume: # optional
# volumeID uniquely identifies a Portworx volume
volumeID: "<string>" # required
# fSType represents the filesystem type to mount Must be a filesystem type supported
# by the host operating system. Ex. "ext4", "xfs". Implicitly inferred to be "ext4" if
# unspecified.
# fsType: "<string>"
# readOnly defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: <boolean>
# projected items for all in one resources secrets, configmaps, and downward API
projected: # optional
# defaultMode are the mode bits used to set permissions on created files by default.
# Must be an octal value between 0000 and 0777 or a decimal value between 0 and 511.
# YAML accepts both octal and decimal values, JSON requires decimal values for mode
# bits. Directories within the path are not affected by this setting. This might be in
# conflict with other options that affect the file mode, like fsGroup, and the result
# can be other mode bits set.
# defaultMode: <int32>
# sources is the list of volume projections. Each entry in this list handles one
# source.
sources: # optional, listType: atomic
- # ClusterTrustBundle allows a pod to access the `.spec.trustBundle` field of
# ClusterTrustBundle objects in an auto-updating file.
#
# Alpha, gated by the ClusterTrustBundleProjection feature gate.
#
# ClusterTrustBundle objects can either be selected by name, or by the combination
# of signer name and a label selector.
#
# Kubelet performs aggressive normalization of the PEM contents written into the
# pod filesystem. Esoteric PEM features such as inter-block comments and block
# headers are stripped. Certificates are deduplicated. The ordering of
# certificates within the file is arbitrary, and Kubelet may change the order over
# time.
clusterTrustBundle: # optional
# Relative path from the volume root to write the bundle.
path: "<string>" # required
# Select all ClusterTrustBundles that match this label selector. Only has effect
# if signerName is set. Mutually-exclusive with name. If unset, interpreted as
# "match nothing". If set but empty, interpreted as "match everything".
labelSelector: # optional, mapType: atomic
# matchExpressions is a list of label selector requirements. The requirements
# are ANDed.
matchExpressions: # optional, listType: atomic
- # key is the label key that the selector applies to.
key: "<string>" # required
# operator represents a key's relationship to a set of values. Valid
# operators are In, NotIn, Exists and DoesNotExist.
operator: "<string>" # required
# values is an array of string values. If the operator is In or NotIn, the
# values array must be non-empty. If the operator is Exists or
# DoesNotExist, the values array must be empty. This array is replaced
# during a strategic merge patch.
# values: # listType: atomic
# - "<string>"
# matchLabels is a map of {key,value} pairs. A single {key,value} in the
# matchLabels map is equivalent to an element of matchExpressions, whose key
# field is "key", the operator is "In", and the values array contains only
# "value". The requirements are ANDed.
# matchLabels:
# <key>: "<string>"
# Select a single ClusterTrustBundle by object name. Mutually-exclusive with
# signerName and labelSelector.
# name: "<string>"
# If true, don't block pod startup if the referenced ClusterTrustBundle(s)
# aren't available. If using name, then the named ClusterTrustBundle is allowed
# not to exist. If using signerName, then the combination of signerName and
# labelSelector is allowed to match zero ClusterTrustBundles.
# optional: <boolean>
# Select all ClusterTrustBundles that match this signer name. Mutually-exclusive
# with name. The contents of all selected ClusterTrustBundles will be unified
# and deduplicated.
# signerName: "<string>"
# configMap information about the configMap data to project
configMap: # optional, mapType: atomic
# items if unspecified, each key-value pair in the Data field of the referenced
# ConfigMap will be projected into the volume as a file whose name is the key
# and content is the value. If specified, the listed keys will be projected into
# the specified paths, and unlisted keys will not be present. If a key is
# specified which is not present in the ConfigMap, the volume setup will error
# unless it is marked optional. Paths must be relative and may not contain the
# '..' path or start with '..'.
items: # optional, listType: atomic
- # key is the key to project.
key: "<string>" # required
# path is the relative path of the file to map the key to. May not be an
# absolute path. May not contain the path element '..'. May not start with
# the string '..'.
path: "<string>" # required
# mode is Optional: mode bits used to set permissions on this file. Must be
# an octal value between 0000 and 0777 or a decimal value between 0 and 511.
# YAML accepts both octal and decimal values, JSON requires decimal values
# for mode bits. If not specified, the volume defaultMode will be used. This
# might be in conflict with other options that affect the file mode, like
# fsGroup, and the result can be other mode bits set.
# mode: <int32>
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# optional specify whether the ConfigMap or its keys must be defined
# optional: <boolean>
# downwardAPI information about the downwardAPI data to project
downwardAPI: # optional
# Items is a list of DownwardAPIVolume file
items: # optional, listType: atomic
- # Required: Path is the relative path name of the file to be created. Must
# not be absolute or contain the '..' path. Must be utf-8 encoded. The first
# item of the relative path must not start with '..'
path: "<string>" # required
# Required: Selects a field of the pod: only annotations, labels, name,
# namespace and uid are supported.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to
# "v1".
# apiVersion: "<string>"
# Optional: mode bits used to set permissions on this file, must be an octal
# value between 0000 and 0777 or a decimal value between 0 and 511. YAML
# accepts both octal and decimal values, JSON requires decimal values for
# mode bits. If not specified, the volume defaultMode will be used. This
# might be in conflict with other options that affect the file mode, like
# fsGroup, and the result can be other mode bits set.
# mode: <int32>
# Selects a resource of the container: only resources limits and requests
# (limits.cpu, limits.memory, requests.cpu and requests.memory) are
# currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Projects an auto-rotating credential bundle (private key and certificate chain)
# that the pod can use either as a TLS client or server.
#
# Kubelet generates a private key and uses it to send a PodCertificateRequest to
# the named signer. Once the signer approves the request and issues a certificate
# chain, Kubelet writes the key and certificate chain to the pod filesystem. The
# pod does not start until certificates have been issued for each podCertificate
# projected volume source in its spec.
#
# Kubelet will begin trying to rotate the certificate at the time indicated by the
# signer using the PodCertificateRequest.Status.BeginRefreshAt timestamp.
#
# Kubelet can write a single file, indicated by the credentialBundlePath field, or
# separate files, indicated by the keyPath and certificateChainPath fields.
#
# The credential bundle is a single file in PEM format. The first PEM entry is the
# private key (in PKCS#8 format), and the remaining PEM entries are the
# certificate chain issued by the signer (typically, signers will return their
# certificate chain in leaf-to-root order).
#
# Prefer using the credential bundle format, since your application code can read
# it atomically. If you use keyPath and certificateChainPath, your application
# must make two separate file reads. If these coincide with a certificate
# rotation, it is possible that the private key and leaf certificate you read may
# not correspond to each other. Your application will need to check for this
# condition, and re-read until they are consistent.
#
# The named signer controls chooses the format of the certificate it issues;
# consult the signer implementation's documentation to learn how to use the
# certificates it issues.
podCertificate: # optional
# The type of keypair Kubelet will generate for the pod.
#
# Valid values are "RSA3072", "RSA4096", "ECDSAP256", "ECDSAP384", "ECDSAP521",
# and "ED25519".
keyType: "<string>" # required
# Kubelet's generated CSRs will be addressed to this signer.
signerName: "<string>" # required
# Write the certificate chain at this path in the projected volume.
#
# Most applications should use credentialBundlePath. When using keyPath and
# certificateChainPath, your application needs to check that the key and leaf
# certificate are consistent, because it is possible to read the files
# mid-rotation.
# certificateChainPath: "<string>"
# Write the credential bundle at this path in the projected volume.
#
# The credential bundle is a single file that contains multiple PEM blocks. The
# first PEM block is a PRIVATE KEY block, containing a PKCS#8 private key.
#
# The remaining blocks are CERTIFICATE blocks, containing the issued certificate
# chain from the signer (leaf and any intermediates).
#
# Using credentialBundlePath lets your Pod's application code make a single
# atomic read that retrieves a consistent key and certificate chain. If you
# project them to separate files, your application code will need to
# additionally check that the leaf certificate was issued to the key.
# credentialBundlePath: "<string>"
# Write the key at this path in the projected volume.
#
# Most applications should use credentialBundlePath. When using keyPath and
# certificateChainPath, your application needs to check that the key and leaf
# certificate are consistent, because it is possible to read the files
# mid-rotation.
# keyPath: "<string>"
# maxExpirationSeconds is the maximum lifetime permitted for the certificate.
#
# Kubelet copies this value verbatim into the PodCertificateRequests it
# generates for this projection.
#
# If omitted, kube-apiserver will set it to 86400(24 hours). kube-apiserver will
# reject values shorter than 3600 (1 hour). The maximum allowable value is
# 7862400 (91 days).
#
# The signer implementation is then free to issue a certificate with any
# lifetime *shorter* than MaxExpirationSeconds, but no shorter than 3600 seconds
# (1 hour). This constraint is enforced by kube-apiserver. `kubernetes.io`
# signers will never issue certificates with a lifetime longer than 24 hours.
# maxExpirationSeconds: <int32>
# secret information about the secret data to project
secret: # optional, mapType: atomic
# items if unspecified, each key-value pair in the Data field of the referenced
# Secret will be projected into the volume as a file whose name is the key and
# content is the value. If specified, the listed keys will be projected into the
# specified paths, and unlisted keys will not be present. If a key is specified
# which is not present in the Secret, the volume setup will error unless it is
# marked optional. Paths must be relative and may not contain the '..' path or
# start with '..'.
items: # optional, listType: atomic
- # key is the key to project.
key: "<string>" # required
# path is the relative path of the file to map the key to. May not be an
# absolute path. May not contain the path element '..'. May not start with
# the string '..'.
path: "<string>" # required
# mode is Optional: mode bits used to set permissions on this file. Must be
# an octal value between 0000 and 0777 or a decimal value between 0 and 511.
# YAML accepts both octal and decimal values, JSON requires decimal values
# for mode bits. If not specified, the volume defaultMode will be used. This
# might be in conflict with other options that affect the file mode, like
# fsGroup, and the result can be other mode bits set.
# mode: <int32>
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty
# value here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# optional field specify whether the Secret or its key must be defined
# optional: <boolean>
# serviceAccountToken is information about the serviceAccountToken data to project
serviceAccountToken: # optional
# path is the path relative to the mount point of the file to project the token
# into.
path: "<string>" # required
# audience is the intended audience of the token. A recipient of a token must
# identify itself with an identifier specified in the audience of the token, and
# otherwise should reject the token. The audience defaults to the identifier of
# the apiserver.
# audience: "<string>"
# expirationSeconds is the requested duration of validity of the service account
# token. As the token approaches expiration, the kubelet volume plugin will
# proactively rotate the service account token. The kubelet will start trying to
# rotate the token if the token is older than 80 percent of its time to live or
# if the token is older than 24 hours.Defaults to 1 hour and must be at least 10
# minutes.
# expirationSeconds: <int64>
# quobyte represents a Quobyte mount on the host that shares a pod's lifetime.
# Deprecated: Quobyte is deprecated and the in-tree quobyte type is no longer supported.
quobyte: # optional
# registry represents a single or multiple Quobyte Registry services specified as a
# string as host:port pair (multiple entries are separated with commas) which acts as
# the central registry for volumes
registry: "<string>" # required
# volume is a string that references an already created Quobyte volume by name.
volume: "<string>" # required
# group to map volume access to Default is no group
# group: "<string>"
# readOnly here will force the Quobyte volume to be mounted with read-only
# permissions. Defaults to false.
# readOnly: <boolean>
# tenant owning the given Quobyte volume in the Backend Used with dynamically
# provisioned Quobyte volumes, value is set by the plugin
# tenant: "<string>"
# user to map volume access to Defaults to serivceaccount user
# user: "<string>"
# rbd represents a Rados Block Device mount on the host that shares a pod's lifetime.
# Deprecated: RBD is deprecated and the in-tree rbd type is no longer supported.
rbd: # optional
# image is the rados image name. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
image: "<string>" # required
# monitors is a collection of Ceph monitors. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
monitors: # required, listType: atomic
- "<string>"
# fsType is the filesystem type of the volume that you want to mount. Tip: Ensure that
# the filesystem type is supported by the host operating system. Examples: "ext4",
# "xfs", "ntfs". Implicitly inferred to be "ext4" if unspecified. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#rbd
# fsType: "<string>"
# keyring is the path to key ring for RBDUser. Default is /etc/ceph/keyring. More
# info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# keyring: "/etc/ceph/keyring" # default
# pool is the rados pool name. Default is rbd. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# pool: "rbd" # default
# readOnly here will force the ReadOnly setting in VolumeMounts. Defaults to false.
# More info: https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# readOnly: <boolean>
# secretRef is name of the authentication secret for RBDUser. If provided overrides
# keyring. Default is nil. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# user is the rados user name. Default is admin. More info:
# https://examples.k8s.io/volumes/rbd/README.md#how-to-use-it
# user: "admin" # default
# scaleIO represents a ScaleIO persistent volume attached and mounted on Kubernetes
# nodes. Deprecated: ScaleIO is deprecated and the in-tree scaleIO type is no longer
# supported.
scaleIO: # optional
# gateway is the host address of the ScaleIO API Gateway.
gateway: "<string>" # required
# secretRef references to the secret for ScaleIO user and other sensitive information.
# If this is not provided, Login operation will fail.
secretRef: # required, mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# system is the name of the storage system as configured in ScaleIO.
system: "<string>" # required
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Default is "xfs".
# fsType: "xfs" # default
# protectionDomain is the name of the ScaleIO Protection Domain for the configured
# storage.
# protectionDomain: "<string>"
# readOnly Defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: <boolean>
# sslEnabled Flag enable/disable SSL communication with Gateway, default false
# sslEnabled: <boolean>
# storageMode indicates whether the storage for a volume should be ThickProvisioned or
# ThinProvisioned. Default is ThinProvisioned.
# storageMode: "ThinProvisioned" # default
# storagePool is the ScaleIO Storage Pool associated with the protection domain.
# storagePool: "<string>"
# volumeName is the name of a volume already created in the ScaleIO system that is
# associated with this volume source.
# volumeName: "<string>"
# secret represents a secret that should populate this volume. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#secret
secret: # optional
# defaultMode is Optional: mode bits used to set permissions on created files by
# default. Must be an octal value between 0000 and 0777 or a decimal value between 0
# and 511. YAML accepts both octal and decimal values, JSON requires decimal values
# for mode bits. Defaults to 0644. Directories within the path are not affected by
# this setting. This might be in conflict with other options that affect the file
# mode, like fsGroup, and the result can be other mode bits set.
# defaultMode: <int32>
# items If unspecified, each key-value pair in the Data field of the referenced Secret
# will be projected into the volume as a file whose name is the key and content is the
# value. If specified, the listed keys will be projected into the specified paths, and
# unlisted keys will not be present. If a key is specified which is not present in the
# Secret, the volume setup will error unless it is marked optional. Paths must be
# relative and may not contain the '..' path or start with '..'.
items: # optional, listType: atomic
- # key is the key to project.
key: "<string>" # required
# path is the relative path of the file to map the key to. May not be an absolute
# path. May not contain the path element '..'. May not start with the string '..'.
path: "<string>" # required
# mode is Optional: mode bits used to set permissions on this file. Must be an
# octal value between 0000 and 0777 or a decimal value between 0 and 511. YAML
# accepts both octal and decimal values, JSON requires decimal values for mode
# bits. If not specified, the volume defaultMode will be used. This might be in
# conflict with other options that affect the file mode, like fsGroup, and the
# result can be other mode bits set.
# mode: <int32>
# optional field specify whether the Secret or its keys must be defined
# optional: <boolean>
# secretName is the name of the secret in the pod's namespace to use. More info:
# https://kubernetes.io/docs/concepts/storage/volumes#secret
# secretName: "<string>"
# storageOS represents a StorageOS volume attached and mounted on Kubernetes nodes.
# Deprecated: StorageOS is deprecated and the in-tree storageos type is no longer
# supported.
# storageos:
# fsType is the filesystem type to mount. Must be a filesystem type supported by the
# host operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4"
# if unspecified.
# fsType: "<string>"
# readOnly defaults to false (read/write). ReadOnly here will force the ReadOnly
# setting in VolumeMounts.
# readOnly: <boolean>
# secretRef specifies the secret to use for obtaining the StorageOS API credentials.
# If not specified, default values will be attempted.
# secretRef: # mapType: atomic
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# volumeName is the human-readable name of the StorageOS volume. Volume names are only
# unique within a namespace.
# volumeName: "<string>"
# volumeNamespace specifies the scope of the volume within StorageOS. If no namespace
# is specified then the Pod's namespace will be used. This allows the Kubernetes name
# scoping to be mirrored within StorageOS for tighter integration. Set VolumeName to
# any name to override the default behaviour. Set to "default" if you are not using
# namespaces within StorageOS. Namespaces that do not pre-exist within StorageOS will
# be created.
# volumeNamespace: "<string>"
# vsphereVolume represents a vSphere volume attached and mounted on kubelets host
# machine. Deprecated: VsphereVolume is deprecated. All operations for the in-tree
# vsphereVolume type are redirected to the csi.vsphere.vmware.com CSI driver.
vsphereVolume: # optional
# volumePath is the path that identifies vSphere volume vmdk
volumePath: "<string>" # required
# fsType is filesystem type to mount. Must be a filesystem type supported by the host
# operating system. Ex. "ext4", "xfs", "ntfs". Implicitly inferred to be "ext4" if
# unspecified.
# fsType: "<string>"
# storagePolicyID is the storage Policy Based Management (SPBM) profile ID associated
# with the StoragePolicyName.
# storagePolicyID: "<string>"
# storagePolicyName is the storage Policy Based Management (SPBM) profile name.
# storagePolicyName: "<string>"
# Failover configures GMS (GPU Memory Service) failover for this service. For intraPod mode:
# the main container is cloned into two engine containers (active + standby). For interPod
# mode: the operator creates a dedicated GMS weight server pod and multiple engine pods per
# rank that share GPUs via DRA resource claims.
failover: # optional
# Enabled activates failover mode.
enabled: <boolean> # required
# Mode selects the failover deployment topology. intraPod: engine containers run within the
# same pod (requires gpuMemoryService.enabled). interPod: a dedicated GMS weight server pod
# + engine pods per rank (requires Grove).
# mode: "intraPod" # default, enum: "interPod"
# NumShadows is the number of shadow (standby) engine pods per rank. Total engine pods per
# rank = NumShadows + 1 (1 primary + NumShadows shadows).
#
# NumShadows is only meaningful for mode=interPod; intraPod uses a fixed 1 primary + 1
# shadow sidecar layout and any value other than 1 is rejected at admission time.
# numShadows: 1 # default, minimum: 1
# FrontendSidecar configures an auto-generated frontend sidecar container. When specified, the
# operator injects a fully configured frontend container with all standard Dynamo environment
# variables, health probes, and ports. This eliminates the need to manually specify these in
# extraPodSpec.containers. (GAIE)
frontendSidecar: # optional
# Image is the container image for the frontend sidecar.
image: "<string>" # required
# Args overrides the default frontend arguments. When specified, these replace the default
# ["-m", "dynamo.frontend"] entirely. For example, ["-m", "dynamo.frontend",
# "--router-mode", "direct"] for GAIE deployments.
# args:
# - "<string>"
# EnvFromSecret references a Secret whose key/value pairs will be exposed as environment
# variables in the frontend sidecar container.
# envFromSecret: "<string>"
# Envs defines additional environment variables for the frontend sidecar. These are merged
# with (and can override) the auto-generated Dynamo env vars.
envs: # optional
- # Name of the environment variable. May consist of any printable ASCII characters except
# '='.
name: "<string>" # required
# Variable references $(VAR_NAME) are expanded using the previously defined environment
# variables in the container and any service environment variables. If a variable cannot
# be resolved, the reference in the input string will be unchanged. Double $$ are
# reduced to a single $, which allows for escaping the $(VAR_NAME) syntax: i.e.
# "$$(VAR_NAME)" will produce the string literal "$(VAR_NAME)". Escaped references will
# never be expanded, regardless of whether the variable exists or not. Defaults to "".
# value: "<string>"
# Source for the environment variable's value. Cannot be used if value is not empty.
valueFrom: # optional
# Selects a key of a ConfigMap.
configMapKeyRef: # optional, mapType: atomic
# The key to select.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the ConfigMap or its key must be defined
# optional: <boolean>
# Selects a field of the pod: supports metadata.name, metadata.namespace,
# `metadata.labels['<KEY>']`, `metadata.annotations['<KEY>']`, spec.nodeName,
# spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs.
fieldRef: # optional, mapType: atomic
# Path of the field to select in the specified API version.
fieldPath: "<string>" # required
# Version of the schema the FieldPath is written in terms of, defaults to "v1".
# apiVersion: "<string>"
# FileKeyRef selects a key of the env file. Requires the EnvFiles feature gate to be
# enabled.
fileKeyRef: # optional, mapType: atomic
# The key within the env file. An invalid key will prevent the pod from starting.
# The keys defined within a source may consist of any printable ASCII characters
# except '='. During Alpha stage of the EnvFiles feature gate, the key size is
# limited to 128 characters.
key: "<string>" # required
# The path within the volume from which to select the file. Must be relative and may
# not contain the '..' path or start with '..'.
path: "<string>" # required
# The name of the volume mount containing the env file.
volumeName: "<string>" # required
# Specify whether the file or its key must be defined. If the file or key does not
# exist, then the env var is not published. If optional is set to true and the
# specified key does not exist, the environment variable will not be set in the
# Pod's containers.
#
# If optional is set to false and the specified key does not exist, an error will be
# returned during Pod creation.
# optional: false # default
# Selects a resource of the container: only resources limits and requests (limits.cpu,
# limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and
# requests.ephemeral-storage) are currently supported.
resourceFieldRef: # optional, mapType: atomic
# Required: resource to select
resource: "<string>" # required
# Container name: required for volumes, optional for env vars
# containerName: "<string>"
# Specifies the output format of the exposed resources, defaults to "1"
# divisor: <int-or-string> # intOrString
# Selects a key of a secret in the pod's namespace
secretKeyRef: # optional, mapType: atomic
# The key of the secret to select from. Must be a valid secret key.
key: "<string>" # required
# Name of the referent. This field is effectively required, but due to backwards
# compatibility is allowed to be empty. Instances of this type with an empty value
# here are almost certainly wrong. More info:
# https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
# name: "" # default
# Specify whether the Secret or its key must be defined
# optional: <boolean>
# GlobalDynamoNamespace indicates that the Component will be placed in the global Dynamo
# namespace
# globalDynamoNamespace: <boolean>
# GPUMemoryService configures the GPU Memory Service (GMS) sidecar. When enabled, a GMS
# sidecar is injected and GPU access is managed via DRA.
gpuMemoryService: # optional
# Enabled activates GMS wiring. GPU resources on client containers are replaced with a DRA
# ResourceClaim for shared GPU access.
enabled: <boolean> # required
# DeviceClassName is the DRA DeviceClass to request GPUs from.
# deviceClassName: "gpu.nvidia.com" # default
# ExtraClientContainers lists additional user-declared containers that should be wired as
# GMS clients in pods rendered from the enclosing spec. DGD/DCD services apply this to
# service pods. Auto-created checkpoints apply checkpoint job clients before creating the
# DynamoCheckpoint; manual DynamoCheckpoint users must provide an already-prepared pod
# template. In each rendered pod, only matching container names are wired; absent names are
# ignored.
# extraClientContainers: # listType: set
# - "<string>"
# ExtraClientPods declares additional GMS client pods for inter-pod GMS. This field is
# reserved for future use and is rejected until inter-pod client orchestration is wired.
extraClientPods: # optional, listType: map, listMapKeys: name
- # Name identifies this client pod.
name: "<string>" # required, minLength: 1, maxLength: 63
# PodTemplate configures the pod to run as a GMS client.
podTemplate: {} # required, preserveUnknownFields
# Mode selects the GMS deployment topology.
# mode: "intraPod" # default, enum: "interPod"
# Ingress config to expose the component outside the cluster (or through a service mesh).
# ingress:
# Annotations to set on the generated Ingress/VirtualService resources.
# annotations:
# <key>: "<string>"
# Enabled exposes the component through an ingress or virtual service when true.
# enabled: <boolean>
# Host is the base host name to route external traffic to this component.
# host: "<string>"
# HostPrefix is an optional prefix added before the host.
# hostPrefix: "<string>"
# HostSuffix is an optional suffix appended after the host.
# hostSuffix: "<string>"
# IngressControllerClassName selects the ingress controller class (e.g., "nginx").
# ingressControllerClassName: "<string>"
# Labels to set on the generated Ingress/VirtualService resources.
# labels:
# <key>: "<string>"
# TLS holds the TLS configuration used by the Ingress/VirtualService.
# tls:
# SecretName is the name of a Kubernetes Secret containing the TLS certificate and key.
# secretName: "<string>"
# UseVirtualService indicates whether to configure a service-mesh VirtualService instead of
# a standard Ingress.
# useVirtualService: <boolean>
# VirtualServiceGateway optionally specifies the gateway name to attach the VirtualService
# to.
# virtualServiceGateway: "<string>"
# Labels to add to generated Kubernetes resources for this component.
# labels:
# <key>: "<string>"
# LivenessProbe to detect and restart unhealthy containers.
livenessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory for
# the command is root ('/') in the container's filesystem. The command is simply exec'd,
# it is not run inside a shell, so traditional shell instructions ('|', etc) won't work.
# To use a shell, you need to explicitly call out to that shell. Exit status of 0 is
# treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having succeeded.
# Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range 1 to
# 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host" in
# httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant names
# will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are initiated.
# More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range 1 to
# 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe failure. The
# grace period is the duration in seconds after the processes running in the pod are sent a
# termination signal and the time when the processes are forcibly halted with a kill signal.
# Set this value longer than the expected cleanup time for your process. If this value is
# nil, the pod's terminationGracePeriodSeconds will be used. Otherwise, this value overrides
# the value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This is a
# beta field and requires enabling ProbeTerminationGracePeriod feature gate. Minimum value
# is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum value is
# 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# ModelRef references a model that this component serves When specified, a headless service
# will be created for endpoint discovery
modelRef: # optional
# Name is the base model identifier (e.g., "llama-3-70b-instruct-v1")
name: "<string>" # required
# Revision is the model revision/version (optional)
# revision: "<string>"
# Multinode is the configuration for multinode components.
multinode: # optional
# Indicates the number of nodes to deploy for multinode components. Total number of GPUs is
# NumberOfNodes * GPU limit. Must be greater than 1.
nodeCount: 2 # default, required, minimum: 2
# ReadinessProbe to signal when the container is ready to receive traffic.
readinessProbe: # optional
# Exec specifies a command to execute in the container.
# exec:
# Command is the command line to execute inside the container, the working directory for
# the command is root ('/') in the container's filesystem. The command is simply exec'd,
# it is not run inside a shell, so traditional shell instructions ('|', etc) won't work.
# To use a shell, you need to explicitly call out to that shell. Exit status of 0 is
# treated as live/healthy and non-zero is unhealthy.
# command: # listType: atomic
# - "<string>"
# Minimum consecutive failures for the probe to be considered failed after having succeeded.
# Defaults to 3. Minimum value is 1.
# failureThreshold: <int32>
# GRPC specifies a GRPC HealthCheckRequest.
grpc: # optional
# Port number of the gRPC service. Number must be in the range 1 to 65535.
port: <int32> # required
# Service is the name of the service to place in the gRPC HealthCheckRequest (see
# https://github.com/grpc/grpc/blob/master/doc/health-checking.md).
#
# If this is not specified, the default behavior is defined by gRPC.
# service: "" # default
# HTTPGet specifies an HTTP GET request to perform.
httpGet: # optional
# Name or number of the port to access on the container. Number must be in the range 1 to
# 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Host name to connect to, defaults to the pod IP. You probably want to set "Host" in
# httpHeaders instead.
# host: "<string>"
# Custom headers to set in the request. HTTP allows repeated headers.
httpHeaders: # optional, listType: atomic
- # The header field name. This will be canonicalized upon output, so case-variant names
# will be understood as the same header.
name: "<string>" # required
# The header field value
value: "<string>" # required
# Path to access on the HTTP server.
# path: "<string>"
# Scheme to use for connecting to the host. Defaults to HTTP.
# scheme: "<string>"
# Number of seconds after the container has started before liveness probes are initiated.
# More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# initialDelaySeconds: <int32>
# How often (in seconds) to perform the probe. Default to 10 seconds. Minimum value is 1.
# periodSeconds: <int32>
# Minimum consecutive successes for the probe to be considered successful after having
# failed. Defaults to 1. Must be 1 for liveness and startup. Minimum value is 1.
# successThreshold: <int32>
# TCPSocket specifies a connection to a TCP port.
tcpSocket: # optional
# Number or name of the port to access on the container. Number must be in the range 1 to
# 65535. Name must be an IANA_SVC_NAME.
port: <int-or-string> # required, intOrString
# Optional: Host name to connect to, defaults to the pod IP.
# host: "<string>"
# Optional duration in seconds the pod needs to terminate gracefully upon probe failure. The
# grace period is the duration in seconds after the processes running in the pod are sent a
# termination signal and the time when the processes are forcibly halted with a kill signal.
# Set this value longer than the expected cleanup time for your process. If this value is
# nil, the pod's terminationGracePeriodSeconds will be used. Otherwise, this value overrides
# the value provided by the pod spec. Value must be non-negative integer. The value zero
# indicates stop immediately via the kill signal (no opportunity to shut down). This is a
# beta field and requires enabling ProbeTerminationGracePeriod feature gate. Minimum value
# is 1. spec.terminationGracePeriodSeconds is used if unset.
# terminationGracePeriodSeconds: <int64>
# Number of seconds after which the probe times out. Defaults to 1 second. Minimum value is
# 1. More info:
# https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle#container-probes
# timeoutSeconds: <int32>
# Replicas is the desired number of Pods for this component. When scalingAdapter is enabled,
# this field is managed by the DynamoGraphDeploymentScalingAdapter and should not be modified
# directly.
# replicas: <int32> # minimum: 0
# Resources requested and limits for this component, including CPU, memory, GPUs/devices, and
# any runtime-specific resources.
resources: # optional
# Claims specifies resource claims for dynamic resource allocation
claims: # optional
- # Name must match the name of one entry in pod.spec.resourceClaims of the Pod where this
# field is used. It makes that resource available inside a container.
name: "<string>" # required
# Request is the name chosen for a request in the referenced claim. If empty, everything
# from the claim is made available, otherwise only the result of this request.
# request: "<string>"
# Limits specifies the maximum resources allowed for the component
# limits:
# CPU specifies the CPU resource request/limit (e.g., "1000m", "2")
# cpu: "<string>"
# Custom specifies additional custom resource requests/limits
# custom:
# <key>: "<string>"
# GPU indicates the number of GPUs to request. Total number of GPUs is NumberOfNodes * GPU
# in case of multinode deployment.
# gpu: "<string>"
# GPUType can specify a custom GPU type, e.g. "gpu.intel.com/xe" By default if not
# specified, the GPU type is "nvidia.com/gpu"
# gpuType: "<string>"
# Memory specifies the memory resource request/limit (e.g., "4Gi", "8Gi")
# memory: "<string>"
# Requests specifies the minimum resources required by the component
# requests:
# CPU specifies the CPU resource request/limit (e.g., "1000m", "2")
# cpu: "<string>"
# Custom specifies additional custom resource requests/limits
# custom:
# <key>: "<string>"
# GPU indicates the number of GPUs to request. Total number of GPUs is NumberOfNodes * GPU
# in case of multinode deployment.
# gpu: "<string>"
# GPUType can specify a custom GPU type, e.g. "gpu.intel.com/xe" By default if not
# specified, the GPU type is "nvidia.com/gpu"
# gpuType: "<string>"
# Memory specifies the memory resource request/limit (e.g., "4Gi", "8Gi")
# memory: "<string>"
# ScalingAdapter configures whether this service uses the DynamoGraphDeploymentScalingAdapter.
# When enabled, replicas are managed via DGDSA and external autoscalers can scale the service
# using the Scale subresource. When disabled, replicas can be modified directly.
# scalingAdapter:
# Enabled indicates whether the ScalingAdapter should be enabled for this service. When
# true, a DGDSA is created and owns the replicas field. When false (default), no DGDSA is
# created and replicas can be modified directly in the DGD.
# enabled: false # default
# The name of the component
# serviceName: "<string>"
# SharedMemory controls the tmpfs mounted at /dev/shm (enable/disable and size).
# sharedMemory:
# Disabled, when true, opts out of mounting a shared-memory medium for the component. When
# false (or unset), shared memory is enabled and Size is required (enforced by the
# validating webhook). Size is ignored when Disabled is true.
# disabled: <boolean>
# size: <int-or-string> # intOrString
# SubComponentType indicates the sub-role of this component (for example, "prefill").
# subComponentType: "<string>"
# TopologyConstraint for this service. packDomain is required. When both this and
# spec.topologyConstraint.packDomain are set, packDomain must be narrower than or equal to the
# spec-level packDomain.
topologyConstraint: # optional
# PackDomain is the topology domain to pack pods within. Must match a domain defined in the
# referenced ClusterTopology CR.
packDomain: "<string>" # required
# VolumeMounts references PVCs defined at the top level for volumes to be mounted by the
# component.
volumeMounts: # optional
- # Name references a PVC name defined in the top-level PVCs map
name: "<string>" # required
# MountPoint specifies where to mount the volume. If useAsCompilationCache is true and
# mountPoint is not specified, a backend-specific default will be used.
# mountPoint: "<string>"
# UseAsCompilationCache indicates this volume should be used as a compilation cache. When
# true, backend-specific environment variables will be set and default mount points may be
# used.
# useAsCompilationCache: false # default
# TopologyConstraint is the deployment-level topology constraint. When set, topologyProfile is
# required and names the ClusterTopology CR to use. packDomain is optional here — it can be
# omitted when only services carry constraints. Services without their own topologyConstraint
# inherit from this value.
topologyConstraint: # optional
# TopologyProfile is the name of the ClusterTopology CR that defines the topology hierarchy for
# this deployment.
topologyProfile: "<string>" # required, minLength: 1
# PackDomain is the default topology domain to pack pods within. Optional — omit when only
# services carry constraints.
# packDomain: "<string>"
# Status reflects the current observed state of this graph deployment.
status: # optional
# State is a high-level textual status of the graph deployment lifecycle.
state: "initializing" # default, required, enum: "pending" | "successful" | "failed"
# Checkpoints contains per-service checkpoint status information. The map key is the service name
# from spec.services.
# checkpoints:
# ServiceCheckpointStatus contains checkpoint information for a single service.
# <key>:
# CheckpointID is the artifact ID used by the snapshot protocol
# checkpointID: "<string>"
# CheckpointName is the name of the associated Checkpoint CR
# checkpointName: "<string>"
# IdentityHash is the computed hash of the checkpoint identity Deprecated: automatic
# checkpoints use CheckpointID. This field is retained for older status consumers.
# identityHash: "<string>"
# Ready indicates the checkpoint artifact is ready for future pods to restore.
# ready: <boolean>
# Conditions contains the latest observed conditions of the graph deployment. The slice is merged
# by type on patch updates.
conditions: # optional
- # lastTransitionTime is the last time the condition transitioned from one status to another.
# This should be when the underlying condition changed. If that is not known, then using the
# time when the API field changed is acceptable.
lastTransitionTime: "<string>" # required
# message is a human readable message indicating details about the transition. This may be an
# empty string.
message: "<string>" # required, maxLength: 32768
# reason contains a programmatic identifier indicating the reason for the condition's last
# transition. Producers of specific condition types may define expected values and meanings
# for this field, and whether the values are considered a guaranteed API. The value should be
# a CamelCase string. This field may not be empty.
reason: "<string>" # required, minLength: 1, maxLength: 1024
# status of the condition, one of True, False, Unknown.
status: "True" # required, enum: "False" | "Unknown"
# type of condition in CamelCase or in foo.example.com/CamelCase.
type: "<string>" # required, maxLength: 316
# observedGeneration represents the .metadata.generation that the condition was set based
# upon. For instance, if .metadata.generation is currently 12, but the
# .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to
# the current state of the instance.
# observedGeneration: <int64> # minimum: 0
# ObservedGeneration is the most recent generation observed by the controller.
# observedGeneration: <int64>
# Restart contains the status of the restart of the graph deployment.
# restart:
# InProgress contains the names of the services that are currently being restarted.
# inProgress:
# - "<string>"
# ObservedID is the restart ID that has been observed and is being processed. Matches the
# Restart.ID field in the spec.
# observedID: "<string>"
# Phase is the phase of the restart.
# phase: "<string>"
# RollingUpdate tracks the progress of operator manged rolling updates. Currently only supported
# for singl-node, non-Grove deployments (DCD/Deployment).
# rollingUpdate:
# EndTime is when the rolling update completed (successfully or failed).
# endTime: "<string>"
# Phase indicates the current phase of the rolling update.
# phase: "Pending" # enum: "InProgress" | "Completed" | "Failed" | ""
# StartTime is when the rolling update began.
# startTime: "<string>"
# UpdatedServices is the list of services that have completed the rolling update. A service is
# considered updated when its new replicas are all ready and old replicas are fully scaled down.
# Only services of componentType Worker (or Prefill/Decode) are considered.
# updatedServices:
# - "<string>"
# Services contains per-service replica status information. The map key is the service name from
# spec.services.
services: # optional
# ServiceReplicaStatus contains replica information for a single service.
<key>: # optional
# ComponentKind is the underlying resource kind (e.g., "PodClique", "PodCliqueScalingGroup",
# "Deployment", "LeaderWorkerSet").
componentKind: "PodClique" # required, enum: "PodCliqueScalingGroup" | "Deployment" |
# "LeaderWorkerSet"
# ComponentName is the name of the primary underlying resource. DEPRECATED: Use ComponentNames
# instead. This field will be removed in a future release. During rolling updates, this
# reflects the new (target) component name.
componentName: "<string>" # required
# Replicas is the total number of non-terminated replicas. Required for all component kinds.
replicas: <int32> # required, minimum: 0
# UpdatedReplicas is the number of replicas at the current/desired revision. Required for all
# component kinds.
updatedReplicas: <int32> # required, minimum: 0
# AvailableReplicas is the number of available replicas. For Deployment: replicas ready for >=
# minReadySeconds. For PodCliqueScalingGroup: replicas where all constituent PodCliques have
# >= MinAvailable ready pods. Not available for PodClique or LeaderWorkerSet. When nil, the
# field is omitted from the API response.
# availableReplicas: <int32> # minimum: 0
# ComponentNames is the list of underlying resource names for this service. During normal
# operation, this contains a single name. During rolling updates, this contains both old and
# new component names.
# componentNames:
# - "<string>"
# ReadyReplicas is the number of ready replicas. Populated for PodClique, Deployment, and
# LeaderWorkerSet. Not available for PodCliqueScalingGroup. When nil, the field is omitted
# from the API response.
# readyReplicas: <int32> # minimum: 0