auth.nats.mikluko.io/v1beta1 #
The auth.nats.mikluko.io API group, owned by the auth controller.
| Kind | Description |
|---|---|
| NatsAccount | NatsAccount is an account, its limits, and its exports and imports. |
| NatsOperator | NatsOperator is a NATS operator the auth controller signs for. |
| NatsSystemAccount | NatsSystemAccount is a system account, signed only while a NatsOperator references it. |
| NatsUser | NatsUser is a user of an account. |
AccountJetStreamLimits #
AccountJetStreamLimits are an account’s JetStream limits.
Appears on: AccountLimits.
| Field | Type | Required | Description |
|---|---|---|---|
memoryStorage | Quantity | No | MemoryStorage is the memory store limit. |
diskStorage | Quantity | No | DiskStorage is the file store limit. |
streams | int64 | No | Streams is the maximum number of streams. |
consumers | int64 | No | Consumers is the maximum number of consumers. |
AccountKind #
AccountKind is a kind that answers an account reference.
Type: string
Appears on: AccountReference.
| Value | Description |
|---|---|
NatsAccount | |
NatsSystemAccount |
AccountLimits #
AccountLimits are an account’s limits.
Appears on: NatsAccountSpec.
| Field | Type | Required | Description |
|---|---|---|---|
connections | int64 | No | Connections is the maximum number of client connections. |
subscriptions | int64 | No | Subscriptions is the maximum number of subscriptions. |
payload | Quantity | No | Payload is the maximum message payload. |
jetstream | AccountJetStreamLimits | No | JetStream enables JetStream for the account, within these limits. |
AccountReference #
AccountReference names a NatsAccount or a NatsSystemAccount.
Appears on: Export, Import, NatsUserSpec.
| Field | Type | Required | Description |
|---|---|---|---|
kind | AccountKind | Yes | Kind of the account. |
name | string | Yes | Name of the referenced object. |
namespace | string | No | Namespace of the referenced object, the referrer’s own when omitted. Another namespace is admitted only by a NatsReferenceGrant there. |
ActivationState #
ActivationState is the state of an import’s activation token.
Type: string
Appears on: ImportStatus.
| Value | Description |
|---|---|
Signed | ActivationSigned is an activation token the auth controller minted. |
ConnectionType #
ConnectionType is a NATS connection type a user may connect as.
Type: string
Appears on: NatsUserSpec.
| Value | Description |
|---|---|
STANDARD | |
WEBSOCKET | |
LEAFNODE | |
LEAFNODE_WS | |
MQTT | |
MQTT_WS | |
IN_PROCESS |
DeletedAccount #
DeletedAccount is an account deleted from the resolvers.
Appears on: NatsOperatorStatus.
| Field | Type | Required | Description |
|---|---|---|---|
publicKey | string | Yes | PublicKey of the account. |
expires | Time | No | Expires is when the account’s last JWT expires; omitted, it never does. |
Distribution #
Distribution is how many servers hold an account’s current JWT.
Appears on: NatsAccountStatus, NatsSystemAccountStatus.
| Field | Type | Required | Description |
|---|---|---|---|
servers | int32 | No | Servers is how many servers trust the account’s NATS operator. |
current | int32 | No | Current is the number of servers holding the current JWT. |
lastPushTime | Time | No | LastPushTime is when the JWT was last pushed. |
Export #
Export is one export, or a preset expanding to several.
Appears on: NatsAccountSpec.
| Field | Type | Required | Description |
|---|---|---|---|
preset | ExportPreset | No | Preset expands to a fixed set of exports. |
name | string | No | Name is what imports name the export by. |
type | ExportType | No | Type is signed into the account JWT as the export’s type. |
subject | string | No | Subject is signed into the account JWT as the export’s subject. |
responseType | ResponseType | No | ResponseType of a service export, Singleton when omitted. |
access | ExportAccess | No | Access is Public when omitted; a Private export is importable only by its importers. |
importers | []AccountReference | No | Importers of a Private export, each minted an activation token. |
ExportAccess #
ExportAccess is who may import an export.
Type: string
Appears on: Export.
| Value | Description |
|---|---|
Public | |
Private |
ExportPreset #
ExportPreset is a named set of exports.
Type: string
Appears on: Export.
| Value | Description |
|---|---|
jetstream-stepdown | ExportPresetJetStreamStepdown exports the stream and consumer leader stepdown services, and imports them into the system account. |
ExportType #
ExportType is the type of an export.
Type: string
Appears on: Export, ImportStatus.
| Value | Description |
|---|---|
Stream | |
Service |
IdentityKey #
IdentityKey is an identity key’s seed.
Appears on: Keys.
| Field | Type | Required | Description |
|---|---|---|---|
secretKeyRef | SeedSecretKeySelector | Yes | SecretKeyRef selects the seed. |
Import #
Import takes another account’s export by name.
Appears on: NatsAccountSpec.
| Field | Type | Required | Description |
|---|---|---|---|
accountRef | AccountReference | Yes | AccountRef names the exporting account. |
export | string | Yes | Export is the name of the export taken. |
localSubject | string | No | LocalSubject is where the import appears in this account, the exported subject when omitted. |
ImportStatus #
ImportStatus is a resolved import.
Appears on: NatsAccountStatus.
| Field | Type | Required | Description |
|---|---|---|---|
export | string | No | Export is the export taken, as account/export, or namespace/account/export from another namespace. |
subject | string | No | Subject is the exported subject. |
localSubject | string | No | LocalSubject is where the import appears in this account. |
type | ExportType | No | Type is the type of the export taken. |
activation | ActivationState | No | Activation is the state of the activation token of a Private export. |
Keys #
Keys adopts existing seeds; omitted, the auth controller generates keys into Secrets that outlive the object.
Appears on: NatsAccountSpec, NatsOperatorSpec, NatsSystemAccountSpec.
| Field | Type | Required | Description |
|---|---|---|---|
identity | IdentityKey | No | Identity is the identity key’s seed. |
signing | []SigningKey | No | Signing are the signing keys’ seeds. |
NatsAccount #
NatsAccount is an account, its limits, and its exports and imports.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | auth.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsAccount |
metadata | ObjectMeta | Yes | |
spec | NatsAccountSpec | Yes | |
status | NatsAccountStatus | No |
NatsAccountSpec #
NatsAccountSpec is the desired state of an account.
Appears on: NatsAccount.
| Field | Type | Required | Description |
|---|---|---|---|
operatorRef | ObjectReference | Yes | OperatorRef names the NatsOperator that signs this account. |
keys | Keys | No | Keys adopts existing seeds. |
publicKey | string | No | PublicKey is the account’s identity, keeping its identity key offline. |
jwtTTL | Duration | No | JWTTTL is the account JWT’s lifetime, and the JWT is re-signed at half of it; 0 signs a JWT that never expires. Default: 48h. |
limits | AccountLimits | No | Limits are signed into the account JWT; an omitted limit is unlimited. |
exports | []Export | No | Exports are what other accounts may import from this one. |
imports | []Import | No | Imports are exports of other accounts this one takes. |
NatsAccountStatus #
NatsAccountStatus is the observed state of an account.
Appears on: NatsAccount.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, ReferencesResolved, Distributed, and where it applies RevocationsUnrecovered. Ready is False, reason PublicKeyInUse, while the NatsOperator’s NatsSystemAccount or another NatsAccount under it holds the account’s public key. |
publicKey | string | No | PublicKey is the account’s public key. |
jwt | string | No | JWT is the current account JWT; empty once the account is no longer admitted to its NatsOperator and the NatsOperator records its deletion. |
jwtHash | string | No | JWTHash identifies the current account JWT. |
distribution | Distribution | No | Distribution is how many servers hold the current JWT. |
revocations | []Revocation | No | Revocations are the user keys the account JWT revokes. |
imports | []ImportStatus | No | Imports are the resolved imports. |
NatsOperator #
NatsOperator is a NATS operator the auth controller signs for.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | auth.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsOperator |
metadata | ObjectMeta | Yes | |
spec | NatsOperatorSpec | Yes | |
status | NatsOperatorStatus | No |
NatsOperatorSpec #
NatsOperatorSpec is the desired state of a NATS operator.
Appears on: NatsOperator.
| Field | Type | Required | Description |
|---|---|---|---|
keys | Keys | No | Keys adopts existing seeds. |
jwt | string | No | JWT is a NATS operator JWT signed elsewhere, keeping the identity key offline. |
systemAccountRef | ObjectReference | Yes | SystemAccountRef names the NatsSystemAccount the NATS operator JWT names. |
NatsOperatorStatus #
NatsOperatorStatus is the observed state of a NATS operator.
Appears on: NatsOperator.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, ReferencesResolved, RetiringKeysInUse, and where it applies RevocationsUnrecovered. |
publicKey | string | No | PublicKey is the identity key’s public key. |
signingKeys | []string | No | SigningKeys are the signing keys’ public keys. |
seedSecrets | SeedSecrets | No | SeedSecrets name the Secrets holding the generated seeds. |
jwt | string | No | JWT is the NATS operator JWT. |
systemAccount | SystemAccountStatus | No | SystemAccount is the system account the NATS operator JWT names. |
deletedAccounts | []DeletedAccount | No | DeletedAccounts are the accounts deleted or no longer admitted while a server may hold a valid JWT for one; the delete is re-sent to each joining server until that JWT expires or an admitted account holds its key again. |
NatsSystemAccount #
NatsSystemAccount is a system account, signed only while a NatsOperator references it.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | auth.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsSystemAccount |
metadata | ObjectMeta | Yes | |
spec | NatsSystemAccountSpec | Yes | |
status | NatsSystemAccountStatus | No |
NatsSystemAccountSpec #
NatsSystemAccountSpec is the desired state of a system account.
Appears on: NatsSystemAccount.
| Field | Type | Required | Description |
|---|---|---|---|
operatorRef | ObjectReference | Yes | OperatorRef names the NatsOperator that signs this account. |
keys | Keys | No | Keys adopts existing seeds. |
publicKey | string | No | PublicKey is the account’s identity, keeping its identity key offline. |
NatsSystemAccountStatus #
NatsSystemAccountStatus is the observed state of a system account.
Appears on: NatsSystemAccount.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, ReferencesResolved, Distributed. |
publicKey | string | No | PublicKey is the account’s public key. |
jwtHash | string | No | JWTHash identifies the current account JWT. |
distribution | Distribution | No | Distribution is how many servers hold the current JWT. |
revocations | []Revocation | No | Revocations are the user keys the account JWT revokes. |
NatsUser #
NatsUser is a user of an account.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | auth.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsUser |
metadata | ObjectMeta | Yes | |
spec | NatsUserSpec | Yes | |
status | NatsUserStatus | No |
NatsUserSpec #
NatsUserSpec is the desired state of a user.
Appears on: NatsUser.
| Field | Type | Required | Description |
|---|---|---|---|
accountRef | AccountReference | Yes | AccountRef names the account the user belongs to. |
permissions | Permissions | No | Permissions are the user’s publish and subscribe permissions. |
connectionTypes | []ConnectionType | No | ConnectionTypes restricts how the user may connect; empty allows any. |
preset | UserPreset | No | Preset is a named permission set in place of Permissions and ConnectionTypes. |
publicKey | string | No | PublicKey is a key whose seed the client holds; the user then gets a signed JWT in status and no creds Secret. |
credentials | Credentials | No | Credentials is where the user’s creds are written, in the shape a NatsConnection reads; deleted while no grant admits the user to its account. |
NatsUserStatus #
NatsUserStatus is the observed state of a user.
Appears on: NatsUser.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, ReferencesResolved, and Distributed, only ever False, reason NoSystemConnection. Ready is False, reason PublicKeyInUse, while another NatsUser of the account holds spec.publicKey, and reason AccountNotAdmitted while no NatsReferenceGrant admits the NatsAccount to its NatsOperator. |
publicKey | string | No | PublicKey is the user’s public key. |
jwt | string | No | JWT is the user JWT, published for a user that brings its own key. |
replacedKeys | []ReplacedKey | No | ReplacedKeys are keys the user held before PublicKey, each revoked in its account from when it was replaced; one leaves the list once the account JWT revokes it. |
Permissions #
Permissions are a user’s publish and subscribe permissions.
Appears on: NatsUserSpec.
| Field | Type | Required | Description |
|---|---|---|---|
publish | SubjectPermissions | No | Publish are the subjects the user may publish to. |
subscribe | SubjectPermissions | No | Subscribe are the subjects the user may subscribe to. |
ReplacedKey #
ReplacedKey is a user key replaced by another.
Appears on: NatsUserStatus.
| Field | Type | Required | Description |
|---|---|---|---|
publicKey | string | Yes | PublicKey is the replaced key. |
at | Time | Yes | At is when it was replaced. |
ResponseType #
ResponseType is how a service export responds.
Type: string
Appears on: Export.
| Value | Description |
|---|---|
Singleton | |
Stream | |
Chunked |
Revocation #
Revocation is a user key an account revokes.
Appears on: NatsAccountStatus, NatsSystemAccountStatus.
| Field | Type | Required | Description |
|---|---|---|---|
publicKey | string | Yes | PublicKey is the revoked user’s key. |
at | Time | Yes | At revokes the user’s JWTs issued at or before it. |
issuers | []string | No | Issuers are the account’s signing keys when the revocation was recorded, the keys that may have signed a revoked JWT. The revocation is dropped once none of them is among the account’s signing keys. |
SeedSecretKeySelector #
SeedSecretKeySelector selects an nkey seed from a Secret in the referrer’s namespace.
Appears on: IdentityKey, SigningKey.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name of a Secret in the referrer’s namespace. |
key | string | Yes | Key within the Secret. |
SeedSecrets #
SeedSecrets name the Secrets holding generated seeds.
Appears on: NatsOperatorStatus.
| Field | Type | Required | Description |
|---|---|---|---|
identity | string | No | Identity names the identity seed’s Secret. |
signing | []string | No | Signing name the signing seeds’ Secrets. |
SigningKey #
SigningKey is a signing key’s seed.
Appears on: Keys.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name identifies the key within the list. |
secretKeyRef | SeedSecretKeySelector | Yes | SecretKeyRef selects the seed. |
retiring | bool | No | Retiring keeps the key listed, so what it signed stays valid, and signs nothing new with it. Nothing removes a retiring key from the list. |
SubjectPermissions #
SubjectPermissions allow and deny subjects.
Appears on: Permissions.
| Field | Type | Required | Description |
|---|---|---|---|
allow | []string | No | Allow are the subjects permitted; empty, every subject is. |
deny | []string | No | Deny are the subjects refused, even where Allow matches them. |
SystemAccountStatus #
SystemAccountStatus is the system account a NATS operator JWT names.
Appears on: NatsOperatorStatus.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | Name of the NatsSystemAccount spec.systemAccountRef resolves to. |
publicKey | string | No | PublicKey of the system account. |
jwt | string | No | JWT of the system account. |
UserPreset #
UserPreset is a named permission set.
Type: string
Appears on: NatsUserSpec.
| Value | Description |
|---|---|
cluster-controller | |
jetstream-controller | |
auth-controller | |
readonly | |
leafnode |
cluster.nats.mikluko.io/v1beta1 #
The cluster.nats.mikluko.io API group, owned by the cluster controller.
| Kind | Description |
|---|---|
| NatsCluster | NatsCluster is a NATS cluster the cluster controller deploys, one StatefulSet per server. |
Auth #
Auth puts a NATS cluster under a NATS operator.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
trustRef | ObjectReference | Yes | TrustRef names the NatsOperatorTrust holding the trust roots. |
systemCredentials | Credentials | No | SystemCredentials are the system user the cluster controller connects as. |
resolver | ResolverType | No | Resolver is the account resolver; the cluster controller renders Full when omitted, and Cache for a leaf that preloads no account. |
CertManagerCertificate #
CertManagerCertificate is a certificate cert-manager issues.
Appears on: CertificateSource, ListenerTLS, RoutesTLS.
| Field | Type | Required | Description |
|---|---|---|---|
issuerRef | IssuerReference | Yes | IssuerRef is copied into the Certificate the cluster controller creates in the NatsCluster’s namespace. |
CertificateSource #
CertificateSource names where a listener’s certificate comes from.
Appears on: ListenerTLS, RoutesTLS.
| Field | Type | Required | Description |
|---|---|---|---|
secretRef | SecretReference | No | SecretRef names a kubernetes.io/tls Secret. |
certManager | CertManagerCertificate | No | CertManager has cert-manager issue the certificate. |
ConfigApplyMethod #
ConfigApplyMethod is how a rendered config reached the servers.
Type: string
Appears on: ConfigStatus.
| Value | Description |
|---|---|
Reload | |
Restart |
ConfigStatus #
ConfigStatus is the rendered config revision.
Appears on: NatsClusterStatus.
| Field | Type | Required | Description |
|---|---|---|---|
revision | string | No | Revision is a digest of the rendered config, StatefulSets and certificates; each server reports its own as config_revision. |
appliedBy | ConfigApplyMethod | No | AppliedBy is how the revision is applied. |
restartReason | string | No | RestartReason names what made a restart necessary. |
EmbeddedObjectMetadata #
EmbeddedObjectMetadata is the metadata a template passes through.
Appears on: PodTemplate, VolumeClaimTemplate.
| Field | Type | Required | Description |
|---|---|---|---|
labels | map[string]string | No | Labels added to the rendered object. |
annotations | map[string]string | No | Annotations added to the rendered object. |
Endpoints #
Endpoints are a NATS cluster’s addresses.
Appears on: NatsClusterStatus.
| Field | Type | Required | Description |
|---|---|---|---|
client | string | No | Client is the client URL. |
monitor | string | No | Monitor is the monitoring URL, on the headless Service. |
gateway | string | No | Gateway is the advertised gateway address. |
Exporter #
Exporter is the prometheus-nats-exporter sidecar in every server’s pod, serving metrics on port 7777.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
enabled | bool | No | Enabled turns the sidecar off when false. Default: true. |
image | ExporterImage | No | Image is the sidecar’s image. |
from | []NetworkPolicyPeer | No | From admits the metrics port from these peers besides the cluster controller’s namespace, under monitor.networkPolicy. |
resources | ResourceRequirements | No | Resources replaces the sidecar’s default requests, 10m CPU and 32Mi memory, and limits, 100m CPU and 128Mi memory. |
ExporterImage #
ExporterImage names the prometheus-nats-exporter sidecar’s image.
Appears on: Exporter.
| Field | Type | Required | Description |
|---|---|---|---|
repository | string | No | Repository is the image repository; empty, it is natsio/prometheus-nats-exporter. |
tag | string | No | Tag is the image tag; empty, it is the tag the cluster controller pins, with that tag’s digest unless repository or digest is set. |
digest | string | No | Digest pins the image to one manifest, rendered after the tag. |
Gateway #
Gateway joins a NATS cluster into a supercluster.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
discovery | GatewayDiscovery | Yes | Discovery is how remotes are rendered: Explicit as gateway remotes with reject_unknown on, Gossip as seeds with reject_unknown off. |
remotes | []GatewayRemote | Yes | Remotes are every member of the supercluster; this NATS cluster’s own entry is skipped. |
tls | ListenerTLS | No | TLS on the gateway listener. The certificate’s Secret must hold ca.crt, which peers are verified against both ways. Absent, the NatsCluster is refused with reason GatewayWithoutTLS unless the cluster controller runs with –allow-gateway-without-tls, and then gateways run in the clear. |
service | ServiceTemplate | No | Service is the template of the external gateway Service. |
advertise | string | No | Advertise is the host:port the servers advertise for gateways. |
GatewayDiscovery #
GatewayDiscovery is how gateway remotes are rendered.
Type: string
Appears on: Gateway.
| Value | Description |
|---|---|
Explicit | |
Gossip |
GatewayRemote #
GatewayRemote is one member of a supercluster.
Appears on: Gateway.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name is the member’s gateway name. |
url | string | Yes | URL is where the member’s gateway is dialled; on this NATS cluster’s own entry, its host is a name on the gateway certificate. |
GatewayStatus #
GatewayStatus is the connection to one supercluster member.
Appears on: NatsClusterStatus.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name is the member’s gateway name. |
connected | bool | No | Connected reports whether the member is reachable. |
inbound | int32 | No | Inbound is the number of inbound gateway connections. |
outbound | int32 | No | Outbound is the number of outbound gateway connections. |
Image #
Image names the nats-server image of a NATS cluster’s servers.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
repository | string | No | Repository is the image repository; empty, it is nats. |
digest | string | No | Digest pins the image to one manifest, rendered after the tag. |
IssuerReference #
IssuerReference names a cert-manager Issuer or ClusterIssuer.
Appears on: CertManagerCertificate.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name of an Issuer in the NatsCluster’s namespace, or of a ClusterIssuer. |
kind | string | No | Kind of the issuer, Issuer when omitted. |
group | string | No | Group of the issuer, cert-manager.io when omitted. |
JetStream #
JetStream is the JetStream configuration of every server.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
domain | string | No | Domain is the JetStream domain. |
limits | JetStreamLimits | No | Limits override the store limits derived from resources and the volume size. |
volumeClaimTemplate | VolumeClaimTemplate | No | VolumeClaimTemplate is each server’s file store volume; a change replaces servers one at a time. |
JetStreamLimits #
JetStreamLimits are a server’s JetStream store limits.
Appears on: JetStream, JetStreamStatus.
| Field | Type | Required | Description |
|---|---|---|---|
maxMemoryStore | Quantity | No | MaxMemoryStore is the memory store limit. |
maxFileStore | Quantity | No | MaxFileStore is the file store limit. |
JetStreamStatus #
JetStreamStatus is a NATS cluster’s JetStream state.
Appears on: NatsClusterStatus.
| Field | Type | Required | Description |
|---|---|---|---|
metaLeader | string | No | MetaLeader is the server name of the meta group’s leader, empty while none is known. |
limits | JetStreamLimits | No | Limits are the effective store limits. |
LeafRemote #
LeafRemote is a hub a leaf dials, and the local account it binds. With neither localAccountTrustRef nor localSystemAccount it binds the global account.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
connectionRef | ObjectReference | Yes | ConnectionRef names the NatsConnection holding the hub’s URL, CA and credentials. |
localAccountTrustRef | ObjectReference | No | LocalAccountTrustRef names the NatsAccountTrust of the local account the remote binds. |
localSystemAccount | bool | No | LocalSystemAccount binds the remote to the leaf’s system account. |
LeafRemoteStatus #
LeafRemoteStatus is the connection to one hub.
Appears on: NatsClusterStatus.
| Field | Type | Required | Description |
|---|---|---|---|
connectionNamespace | string | Yes | ConnectionNamespace is the namespace of the remote’s NatsConnection. |
connectionName | string | Yes | ConnectionName is the name of the remote’s NatsConnection. |
connected | int32 | No | Connected is the number of servers connected to the hub. |
account | string | No | Account is the public key of the hub account the credentials sign into. |
Leafnodes #
Leafnodes is the hub side of leaf connections.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
tls | ListenerTLS | No | TLS on the leafnode listener; absent, leaf connections run in the clear. |
service | ServiceTemplate | No | Service is the template of the external leafnode Service. |
advertise | string | No | Advertise is the host:port the servers advertise for leaf connections. |
ListenerTLS #
ListenerTLS is TLS on a listener that has it only when configured.
Appears on: Gateway, Leafnodes, NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
secretRef | SecretReference | No | SecretRef names a kubernetes.io/tls Secret. |
certManager | CertManagerCertificate | No | CertManager has cert-manager issue the certificate. |
Monitor #
Monitor configures access to the monitoring port.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
networkPolicy | bool | No | NetworkPolicy renders a NetworkPolicy over the servers’ pods that admits the route port only from those pods, the monitoring port only from the cluster controller’s namespace, the metrics port from there and exporter.from, and the other rendered ports from anywhere; a port podTemplate adds is not admitted. Default: true. |
NatsCluster #
NatsCluster is a NATS cluster the cluster controller deploys, one StatefulSet per server.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | cluster.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsCluster |
metadata | ObjectMeta | Yes | |
spec | NatsClusterSpec | Yes | |
status | NatsClusterStatus | No |
NatsClusterSpec #
NatsClusterSpec is the desired state of a NATS cluster.
Appears on: NatsCluster.
| Field | Type | Required | Description |
|---|---|---|---|
version | string | Yes | Version is the nats-server version rendered for. |
image | Image | No | Image is the nats-server image; its tag is always Version. |
replicas | int32 | Yes | Replicas is the number of servers. |
resources | ResourceRequirements | No | Resources of the nats-server container. GOMEMLIMIT and the JetStream memory store derive from limits.memory. |
jetstream | JetStream | No | JetStream enables JetStream on every server. |
serverTags | map[string]string | No | ServerTags are rendered as key:value server tags. |
podTemplate | PodTemplate | No | PodTemplate is merged into every server’s pod, over its security context and automountServiceAccountToken too: whoever may write a NatsCluster runs pods with any privilege its namespace admits. Its affinity, when set, replaces the rendered preferred anti-affinity across nodes. |
exporter | Exporter | No | Exporter configures the prometheus-nats-exporter sidecar; absent, it runs. |
monitor | Monitor | No | Monitor configures access to the monitoring port, 8222, which has no authentication. |
tls | ListenerTLS | No | TLS on the client listener; absent, clients connect in the clear. The cluster controller verifies it against the Secret’s ca.crt, or the system roots without one. |
routes | Routes | No | Routes configures the route listener; absent, route TLS is on and self-signed. |
auth | Auth | No | Auth puts the NATS cluster under a NATS operator; absent, servers run with no accounts and no client auth. |
gateway | Gateway | No | Gateway joins the NATS cluster into a supercluster under its own name, the NatsCluster’s name. |
leafnodes | Leafnodes | No | Leafnodes opens a listener for leaf connections. |
leafRemotes | []LeafRemote | No | LeafRemotes are the hubs this NATS cluster dials as a leaf. |
rollout | Rollout | No | Rollout steers the restarts a spec change rolls out one server at a time. |
NatsClusterStatus #
NatsClusterStatus is the observed state of a NATS cluster.
Appears on: NatsCluster.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Settled, Progressing, Deleting, and where they apply GatewaysConnected and LeafnodesConnected. |
version | string | No | Version is the version every server has reached. |
replicas | int32 | No | Replicas is the number of servers. |
readyReplicas | int32 | No | ReadyReplicas is the number of ready servers. |
endpoints | Endpoints | No | Endpoints are the addresses clients and peers reach the NATS cluster at. |
config | ConfigStatus | No | Config is the rendered config revision and how it was applied. |
rollout | RolloutStatus | No | Rollout is the rollout in progress. |
removals | []ServerRemoval | No | Removals are the servers whose removal or replacement has begun, and how far each has gone. |
jetstream | JetStreamStatus | No | JetStream is the JetStream state of the NATS cluster. |
gateways | []GatewayStatus | No | Gateways are the connections to the other supercluster members. |
leafRemotes | []LeafRemoteStatus | No | LeafRemotes are the connections to hubs. |
servers | []ServerStatus | No | Servers has one entry per server. |
PodTemplate #
PodTemplate is merged into the pod the cluster controller renders.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
metadata | EmbeddedObjectMetadata | No | |
spec | PodSpec | No | Spec is a partial pod spec merged over the rendered one; the API server does not validate it. |
RemovalPhase #
RemovalPhase is how far a server’s removal has gone.
Type: string
Appears on: ServerRemoval.
| Value | Description |
|---|---|
Requested | RemovalRequested is a server replace-server named, waiting its turn. |
Evacuating | RemovalEvacuating is a server whose evacuation the meta leader accepted. |
Removed | RemovalRemoved is a server whose removal from the meta group was committed. |
Deleting | RemovalDeleting is a server whose StatefulSet, data volume claim and, beyond spec.replicas, ConfigMap are being deleted. A replaced server is not recreated until its claim is gone. |
Rejoining | RemovalRejoining is a server its replacement recreated, until the rollout gate next opens. |
ResolverType #
ResolverType is a NATS account resolver type.
Type: string
Appears on: Auth.
| Value | Description |
|---|---|
Full | |
Cache |
Rollout #
Rollout steers a NATS cluster’s one-server-at-a-time restarts.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
paused | bool | No | Paused stops a rollout before its next step. |
RolloutGate #
RolloutGate is what a rollout waits for.
Appears on: RolloutStatus.
| Field | Type | Required | Description |
|---|---|---|---|
waitingFor | string | No | WaitingFor names the condition the gate waits for. |
since | Time | No | Since is when the gate closed. |
RolloutStatus #
RolloutStatus is a rollout in progress.
Appears on: NatsClusterStatus.
| Field | Type | Required | Description |
|---|---|---|---|
targetRevision | string | No | TargetRevision is the config revision being rolled out. |
updated | []string | No | Updated are the servers on the target revision. |
current | string | No | Current is the server being updated. |
pending | []string | No | Pending are the servers still to update. |
gate | RolloutGate | No | Gate is what the rollout waits for before its next step. |
Routes #
Routes configures the route listener.
Appears on: NatsClusterSpec.
| Field | Type | Required | Description |
|---|---|---|---|
tls | RoutesTLS | No | TLS on routes. |
RoutesTLS #
RoutesTLS is route TLS: on unless disabled, self-signed unless a certificate is named.
Appears on: Routes.
| Field | Type | Required | Description |
|---|---|---|---|
enabled | bool | No | Enabled turns route TLS off when false. Default: true. |
secretRef | SecretReference | No | SecretRef names a kubernetes.io/tls Secret. |
certManager | CertManagerCertificate | No | CertManager has cert-manager issue the certificate. |
ServerRemoval #
ServerRemoval is one server’s removal.
Appears on: NatsClusterStatus.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name is the server_name. |
phase | RemovalPhase | Yes | Phase is how far the removal has gone. |
since | Time | No | Since is when the removal entered Phase. |
ServerStatus #
ServerStatus is one server’s state.
Appears on: NatsClusterStatus.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name is the server_name. |
version | string | No | Version is the nats-server version it runs. |
ready | bool | No | Ready reports whether its pod is Ready. |
configRevision | string | No | ConfigRevision is the config revision it reports. |
ServiceTemplate #
ServiceTemplate is the template of an external Service.
Appears on: Gateway, Leafnodes.
| Field | Type | Required | Description |
|---|---|---|---|
type | ServiceType | No | Type of the Service, ClusterIP when omitted. |
annotations | map[string]string | No | Annotations set on the Service. |
VolumeClaimTemplate #
VolumeClaimTemplate is a PersistentVolumeClaim template.
Appears on: JetStream.
| Field | Type | Required | Description |
|---|---|---|---|
metadata | EmbeddedObjectMetadata | No | |
spec | PersistentVolumeClaimSpec | Yes |
jetstream.nats.mikluko.io/v1beta1 #
The jetstream.nats.mikluko.io API group, owned by the JetStream controller.
| Kind | Description |
|---|---|
| NatsBalancer | NatsBalancer is an account balancer: it evens leaders and copies within the pools of one account, yielding to the system balancer. |
| NatsClusterEvacuation | NatsClusterEvacuation moves every stream, key-value bucket and object store in every account off one NATS cluster, save those whose resource sets placement.cluster: those naming it are reported as pinned, the rest left to their owners. |
| NatsConsumer | NatsConsumer is a JetStream consumer. |
| NatsKeyValue | NatsKeyValue is a JetStream key-value bucket. |
| NatsObjectStore | NatsObjectStore is a JetStream object store. |
| NatsStream | NatsStream is a JetStream stream. |
| NatsSystemBalancer | NatsSystemBalancer is the system balancer of one NATS cluster: it evens leaders and copies across its servers over every account. |
AckPolicy #
AckPolicy is how a consumer’s messages are acknowledged.
Type: string
Appears on: ConsumerConfig, NatsConsumerSpec.
| Value | Description |
|---|---|
None | |
All | |
Explicit |
AdoptionPolicy #
AdoptionPolicy is what the JetStream controller does with an object on the server that it does not own.
Type: string
Appears on: NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec, Policies.
| Value | Description |
|---|---|
Never | AdoptionNever creates the object, and goes Terminal on one it does not own. |
Adopt | AdoptionAdopt requires the object to exist and writes its config into spec. |
AdoptOrCreate | AdoptionAdoptOrCreate applies spec whether or not the object exists, and late-initializes omitted fields from the server. |
Capabilities #
Capabilities are the moves a system balancer can make.
Appears on: NatsSystemBalancerStatus.
| Field | Type | Required | Description |
|---|---|---|---|
placement | bool | No | Placement reports whether placement moves are possible. |
leader | LeaderCapability | No | Leader is Full when every account holding a stream carries the jetstream-stepdown export, None when none does, and Partial otherwise; unset while moves.leader is false. |
leaderReason | string | No | LeaderReason explains a leader capability short of Full. |
ConsumerConfig #
ConsumerConfig is nats.go’s jetstream.ConsumerConfig: a push consumer when DeliverSubject is set, a pull consumer otherwise. An omitted field takes the server’s value.
Appears on: NatsConsumerSpec.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | Name is the server-side durable name, metadata.name when omitted. |
description | string | No | |
deliverPolicy | DeliverPolicy | No | |
optStartSeq | int64 | No | |
optStartTime | Time | No | |
ackPolicy | AckPolicy | No | |
ackWait | Duration | No | |
maxDeliver | int64 | No | |
backOff | []Duration | No | |
filterSubject | string | No | |
filterSubjects | []string | No | |
replayPolicy | ReplayPolicy | No | |
rateLimit | int64 | No | RateLimit is in bits per second. |
sampleFrequency | string | No | |
maxWaiting | int64 | No | |
maxAckPending | int64 | No | |
flowControl | bool | No | |
headersOnly | bool | No | |
maxRequestBatch | int64 | No | |
maxRequestExpires | Duration | No | |
maxRequestMaxBytes | int64 | No | |
deliverSubject | string | No | |
deliverGroup | string | No | |
heartbeat | Duration | No | |
inactiveThreshold | Duration | No | |
replicas | int32 | No | |
memoryStorage | bool | No | |
metadata | map[string]string | No | Metadata is merged with the ownership marker, which the controller owns. |
pauseUntil | Time | No | |
priorityGroups | []string | No | |
priorityPolicy | PriorityPolicy | No | |
pinnedTTL | Duration | No |
ConsumerServerStatus #
ConsumerServerStatus is a consumer’s state as the server reports it.
Appears on: NatsConsumerStatus.
| Field | Type | Required | Description |
|---|---|---|---|
created | Time | No | Created is when the consumer was created on the server. |
leader | string | No | Leader is the server leading the consumer’s group. |
replicas | []ReplicaStatus | No | Replicas are the followers. |
DeletionPolicy #
DeletionPolicy is what deleting the resource does to the object on the server.
Type: string
Appears on: NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec.
| Value | Description |
|---|---|
Retain | |
Delete |
DeliverPolicy #
DeliverPolicy is where a consumer starts.
Type: string
Appears on: ConsumerConfig, NatsConsumerSpec.
| Value | Description |
|---|---|
All | |
Last | |
New | |
ByStartSequence | |
ByStartTime | |
LastPerSubject |
DiscardPolicy #
DiscardPolicy is what a full stream discards.
Type: string
Appears on: NatsStreamSpec, StreamConfig.
| Value | Description |
|---|---|
Old | |
New |
EvacuationSource #
EvacuationSource is the NATS cluster an evacuation empties.
Appears on: NatsClusterEvacuationSpec.
| Field | Type | Required | Description |
|---|---|---|---|
cluster | string | Yes | Cluster is the NATS cluster’s name. |
EvacuationTarget #
EvacuationTarget is where an evacuation moves streams.
Appears on: NatsClusterEvacuationSpec.
| Field | Type | Required | Description |
|---|---|---|---|
serverTags | []string | Yes | ServerTags must match servers of the target only; the evacuation refuses to start if a server of the source carries them. |
ExternalStream #
ExternalStream is the API and deliver prefixes of an origin in another account or domain.
Appears on: StreamSource.
| Field | Type | Required | Description |
|---|---|---|---|
apiPrefix | string | Yes | APIPrefix is the JetStream API prefix. |
deliverPrefix | string | No | DeliverPrefix is the deliver subject prefix. |
KeyValueConfig #
KeyValueConfig is nats.go’s KeyValueConfig, with the bucket under Name. An omitted field takes the server’s value.
Appears on: NatsKeyValueSpec.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | Name is the bucket, metadata.name when omitted. |
description | string | No | |
maxValueSize | Quantity | No | |
history | int32 | No | |
ttl | Duration | No | |
maxBytes | Quantity | No | |
storage | StorageType | No | Storage is immutable. |
replicas | int32 | No | |
placement | Placement | No | |
republish | Republish | No | |
mirror | StreamSource | No | |
sources | []StreamSource | No | |
compression | bool | No | |
limitMarkerTTL | Duration | No | |
metadata | map[string]string | No | Metadata is merged with the ownership marker, which the controller owns. |
LeaderCapability #
LeaderCapability is how far a system balancer can make leader moves.
Type: string
Appears on: Capabilities.
| Value | Description |
|---|---|
Full | |
Partial | |
None |
Move #
Move is a leader or placement move.
Appears on: NatsBalancerStatus, NatsSystemBalancerStatus.
| Field | Type | Required | Description |
|---|---|---|---|
kind | MoveKind | No | Kind is Leader for a leader move, Placement for a placement move. |
account | string | No | Account is the public key of the account whose stream moved. |
stream | string | No | Stream is the name of the stream moved, or of the stream whose consumer’s leader moved. |
consumer | string | No | Consumer is the name of the consumer whose leader moved; empty on a stream’s move. |
from | string | No | From is the server moved off. |
to | string | No | To is the server moved to. |
time | Time | No | Time the move was requested. |
MoveKind #
MoveKind is a kind of balancer move.
Type: string
Appears on: Move.
| Value | Description |
|---|---|
Leader | |
Placement |
Moves #
Moves selects the kinds of move a balancer makes.
Appears on: NatsBalancerSpec, NatsSystemBalancerSpec.
| Field | Type | Required | Description |
|---|---|---|---|
leader | bool | No | Leader enables leader moves. Default: true. |
placement | bool | No | Placement enables placement moves. Default: false. |
NatsBalancer #
NatsBalancer is an account balancer: it evens leaders and copies within the pools of one account, yielding to the system balancer.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | jetstream.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsBalancer |
metadata | ObjectMeta | Yes | |
spec | NatsBalancerSpec | Yes | |
status | NatsBalancerStatus | No |
NatsBalancerSpec #
NatsBalancerSpec is the desired state of an account balancer.
Appears on: NatsBalancer.
| Field | Type | Required | Description |
|---|---|---|---|
connectionRef | ObjectReference | Yes | ConnectionRef names the NatsConnection whose credentials decide the account. |
pools | []Pool | No | Pools are judged apart; a stream matching several belongs to the first. With none declared the account is one pool. |
moves | Moves | No | Moves selects the kinds of move made. Default: {}. |
interval | Duration | No | Interval is the least time between two moves, 1m when omitted. |
NatsBalancerStatus #
NatsBalancerStatus is the observed state of an account balancer.
Appears on: NatsBalancer.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Holding, Overlapping. |
pools | []PoolStatus | No | Pools report each pool’s evenness. |
lastMove | Move | No | LastMove is the last move made; the next waits for spec.interval after its time. |
NatsClusterEvacuation #
NatsClusterEvacuation moves every stream, key-value bucket and object store in every account off one NATS cluster, save those whose resource sets placement.cluster: those naming it are reported as pinned, the rest left to their owners.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | jetstream.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsClusterEvacuation |
metadata | ObjectMeta | Yes | |
spec | NatsClusterEvacuationSpec | Yes | |
status | NatsClusterEvacuationStatus | No |
NatsClusterEvacuationSpec #
NatsClusterEvacuationSpec is the desired state of an evacuation.
Appears on: NatsClusterEvacuation.
| Field | Type | Required | Description |
|---|---|---|---|
connectionRef | ObjectReference | Yes | ConnectionRef names a NatsConnection with system credentials; it is immutable. |
from | EvacuationSource | Yes | From is the NATS cluster emptied; it is immutable. |
to | EvacuationTarget | Yes | To is where the streams are moved; it is immutable. |
NatsClusterEvacuationStatus #
NatsClusterEvacuationStatus is the observed state of an evacuation.
Appears on: NatsClusterEvacuation.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Progressing. |
moved | int32 | No | Moved is the number of streams moved. |
inFlight | int32 | No | InFlight is the number of moves in progress. |
requested | []RequestedMove | No | Requested are the moves requested that the source NATS cluster has not yet seen complete; deleting the evacuation cancels them. |
remaining | int32 | No | Remaining is the number of streams still to leave the source NATS cluster: in flight, waiting for a slot, or refused by the server in the last pass. Pinned streams and streams left for their owners are not counted. |
pinned | []PinnedObject | No | Pinned are the resources left in place; the evacuation is not Ready while any remains. |
stalePlacement | []ServerStream | No | StalePlacement are the streams moved that no resource owns and whose config still names the source NATS cluster, so an update that changes their placement returns them to it. |
NatsConsumer #
NatsConsumer is a JetStream consumer.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | jetstream.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsConsumer |
metadata | ObjectMeta | Yes | |
spec | NatsConsumerSpec | Yes | |
status | NatsConsumerStatus | No |
NatsConsumerSpec #
NatsConsumerSpec is the desired state of a consumer. deliverPolicy, ackPolicy, replayPolicy, optStartSeq, optStartTime, heartbeat, flowControl and maxWaiting are immutable unless recreateOnImmutableChange is set. The fields of the inlined ConsumerConfig mirror nats.go’s jetstream.ConsumerConfig and mean what their like-named fields there mean: https://pkg.go.dev/github.com/nats-io/nats.go/jetstream#ConsumerConfig.
Appears on: NatsConsumer.
| Field | Type | Required | Description |
|---|---|---|---|
connectionRef | ObjectReference | No | ConnectionRef names the NatsConnection whose credentials decide the account, the stream’s own when StreamRef is set and this is omitted; it is immutable. |
stream | string | No | Stream is the server-side name of a stream with no resource; it is immutable. |
streamRef | ObjectReference | No | StreamRef names the NatsStream the consumer waits for and consumes; it is immutable. |
adoptionPolicy | AdoptionPolicy | No | AdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never. |
terminalPolicy | TerminalPolicy | No | TerminalPolicy is what a Terminal condition waits for. Default: Hold. |
deletionPolicy | DeletionPolicy | No | DeletionPolicy is what deleting the resource does to the consumer. Default: Delete. |
recreateOnImmutableChange | bool | No | RecreateOnImmutableChange lets an immutable field change, by deleting and recreating the consumer, which discards its delivery state. |
name | string | No | Name is the server-side durable name, metadata.name when omitted. |
description | string | No | |
deliverPolicy | DeliverPolicy | No | |
optStartSeq | int64 | No | |
optStartTime | Time | No | |
ackPolicy | AckPolicy | No | |
ackWait | Duration | No | |
maxDeliver | int64 | No | |
backOff | []Duration | No | |
filterSubject | string | No | |
filterSubjects | []string | No | |
replayPolicy | ReplayPolicy | No | |
rateLimit | int64 | No | RateLimit is in bits per second. |
sampleFrequency | string | No | |
maxWaiting | int64 | No | |
maxAckPending | int64 | No | |
flowControl | bool | No | |
headersOnly | bool | No | |
maxRequestBatch | int64 | No | |
maxRequestExpires | Duration | No | |
maxRequestMaxBytes | int64 | No | |
deliverSubject | string | No | |
deliverGroup | string | No | |
heartbeat | Duration | No | |
inactiveThreshold | Duration | No | |
replicas | int32 | No | |
memoryStorage | bool | No | |
metadata | map[string]string | No | Metadata is merged with the ownership marker, which the controller owns. |
pauseUntil | Time | No | |
priorityGroups | []string | No | |
priorityPolicy | PriorityPolicy | No | |
pinnedTTL | Duration | No |
NatsConsumerStatus #
NatsConsumerStatus is the observed state of a consumer.
Appears on: NatsConsumer.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Synced, Terminal, Adopted. |
lastSyncedTime | Time | No | LastSyncedTime is when the server object was last compared to spec. |
nextCheckTime | Time | No | NextCheckTime is when a Terminal condition under the Retry policy is next rechecked. |
ownership | Ownership | No | Ownership is the ownership marker on the server object. |
server | ConsumerServerStatus | No | Server is the consumer’s state on the server. |
NatsKeyValue #
NatsKeyValue is a JetStream key-value bucket.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | jetstream.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsKeyValue |
metadata | ObjectMeta | Yes | |
spec | NatsKeyValueSpec | Yes | |
status | NatsKeyValueStatus | No |
NatsKeyValueSpec #
NatsKeyValueSpec is the desired state of a key-value bucket. The fields of the inlined KeyValueConfig mirror nats.go’s jetstream.KeyValueConfig and mean what their like-named fields there mean: https://pkg.go.dev/github.com/nats-io/nats.go/jetstream#KeyValueConfig.
Appears on: NatsKeyValue.
| Field | Type | Required | Description |
|---|---|---|---|
connectionRef | ObjectReference | Yes | ConnectionRef names the NatsConnection whose credentials decide the account; it is immutable. |
adoptionPolicy | AdoptionPolicy | No | AdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never. |
terminalPolicy | TerminalPolicy | No | TerminalPolicy is what a Terminal condition waits for. Default: Hold. |
deletionPolicy | DeletionPolicy | No | DeletionPolicy is what deleting the resource does to the bucket. Default: Retain. |
name | string | No | Name is the bucket, metadata.name when omitted. |
description | string | No | |
maxValueSize | Quantity | No | |
history | int32 | No | |
ttl | Duration | No | |
maxBytes | Quantity | No | |
storage | StorageType | No | Storage is immutable. |
replicas | int32 | No | |
placement | Placement | No | |
republish | Republish | No | |
mirror | StreamSource | No | |
sources | []StreamSource | No | |
compression | bool | No | |
limitMarkerTTL | Duration | No | |
metadata | map[string]string | No | Metadata is merged with the ownership marker, which the controller owns. |
NatsKeyValueStatus #
NatsKeyValueStatus is the observed state of a key-value bucket.
Appears on: NatsKeyValue.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Synced, Terminal, Adopted. |
lastSyncedTime | Time | No | LastSyncedTime is when the server object was last compared to spec. |
nextCheckTime | Time | No | NextCheckTime is when a Terminal condition under the Retry policy is next rechecked. |
ownership | Ownership | No | Ownership is the ownership marker on the server object. |
server | StreamServerStatus | No | Server is the bucket’s stream state on the server. |
NatsObjectStore #
NatsObjectStore is a JetStream object store.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | jetstream.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsObjectStore |
metadata | ObjectMeta | Yes | |
spec | NatsObjectStoreSpec | Yes | |
status | NatsObjectStoreStatus | No |
NatsObjectStoreSpec #
NatsObjectStoreSpec is the desired state of an object store. The fields of the inlined ObjectStoreConfig mirror nats.go’s jetstream.ObjectStoreConfig and mean what their like-named fields there mean: https://pkg.go.dev/github.com/nats-io/nats.go/jetstream#ObjectStoreConfig.
Appears on: NatsObjectStore.
| Field | Type | Required | Description |
|---|---|---|---|
connectionRef | ObjectReference | Yes | ConnectionRef names the NatsConnection whose credentials decide the account; it is immutable. |
adoptionPolicy | AdoptionPolicy | No | AdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never. |
terminalPolicy | TerminalPolicy | No | TerminalPolicy is what a Terminal condition waits for. Default: Hold. |
deletionPolicy | DeletionPolicy | No | DeletionPolicy is what deleting the resource does to the object store. Default: Retain. |
name | string | No | Name is the bucket, metadata.name when omitted. |
description | string | No | |
ttl | Duration | No | |
maxBytes | Quantity | No | |
storage | StorageType | No | Storage is immutable. |
replicas | int32 | No | |
placement | Placement | No | |
compression | bool | No | |
metadata | map[string]string | No | Metadata is merged with the ownership marker, which the controller owns. |
NatsObjectStoreStatus #
NatsObjectStoreStatus is the observed state of an object store.
Appears on: NatsObjectStore.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Synced, Terminal, Adopted. |
lastSyncedTime | Time | No | LastSyncedTime is when the server object was last compared to spec. |
nextCheckTime | Time | No | NextCheckTime is when a Terminal condition under the Retry policy is next rechecked. |
ownership | Ownership | No | Ownership is the ownership marker on the server object. |
server | StreamServerStatus | No | Server is the object store’s stream state on the server. |
NatsStream #
NatsStream is a JetStream stream.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | jetstream.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsStream |
metadata | ObjectMeta | Yes | |
spec | NatsStreamSpec | Yes | |
status | NatsStreamStatus | No |
NatsStreamSpec #
NatsStreamSpec is the desired state of a stream. The fields of the inlined StreamConfig mirror nats.go’s jetstream.StreamConfig and mean what their like-named fields there mean: https://pkg.go.dev/github.com/nats-io/nats.go/jetstream#StreamConfig.
Appears on: NatsStream.
| Field | Type | Required | Description |
|---|---|---|---|
connectionRef | ObjectReference | Yes | ConnectionRef names the NatsConnection whose credentials decide the account; it is immutable. |
adoptionPolicy | AdoptionPolicy | No | AdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never. |
terminalPolicy | TerminalPolicy | No | TerminalPolicy is what a Terminal condition waits for. Default: Hold. |
deletionPolicy | DeletionPolicy | No | DeletionPolicy is what deleting the resource does to the stream. Default: Retain. |
name | string | No | Name is the server-side stream name, metadata.name when omitted. |
description | string | No | |
subjects | []string | No | |
retention | RetentionPolicy | No | Retention cannot change to or from WorkQueue. |
maxConsumers | int64 | No | |
maxMsgs | int64 | No | |
maxBytes | Quantity | No | |
discard | DiscardPolicy | No | |
discardNewPerSubject | bool | No | |
maxAge | Duration | No | |
maxMsgsPerSubject | int64 | No | |
maxMsgSize | Quantity | No | |
storage | StorageType | No | Storage is immutable. |
replicas | int32 | No | |
noAck | bool | No | |
duplicates | Duration | No | |
placement | Placement | No | Placement pins the stream; changing placement.cluster moves it to that NATS cluster. |
mirror | StreamSource | No | Mirror cannot change once set; omitting it leaves the server’s mirror in place. |
sources | []StreamSource | No | |
sealed | bool | No | Sealed cannot be unset. |
denyDelete | bool | No | DenyDelete cannot be unset. |
denyPurge | bool | No | DenyPurge cannot be unset. |
allowRollup | bool | No | |
compression | StoreCompression | No | |
firstSeq | int64 | No | |
subjectTransform | SubjectTransform | No | |
republish | Republish | No | |
allowDirect | bool | No | |
mirrorDirect | bool | No | |
consumerLimits | StreamConsumerLimits | No | |
metadata | map[string]string | No | Metadata is merged with the ownership marker, which the controller owns. |
allowMsgTTL | bool | No | AllowMsgTTL cannot be unset. |
subjectDeleteMarkerTTL | Duration | No | |
allowMsgCounter | bool | No | AllowMsgCounter is immutable. |
allowAtomicPublish | bool | No | |
allowMsgSchedules | bool | No | AllowMsgSchedules cannot be unset. |
persistMode | PersistMode | No | PersistMode is immutable. |
allowBatchPublish | bool | No |
NatsStreamStatus #
NatsStreamStatus is the observed state of a stream.
Appears on: NatsStream.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Synced, Terminal, Adopted. |
lastSyncedTime | Time | No | LastSyncedTime is when the server object was last compared to spec. |
nextCheckTime | Time | No | NextCheckTime is when a Terminal condition under the Retry policy is next rechecked. |
ownership | Ownership | No | Ownership is the ownership marker on the server object. |
server | StreamServerStatus | No | Server is the stream’s state on the server. |
transfer | StreamTransfer | No | Transfer is a move to another NATS cluster in progress. |
NatsSystemBalancer #
NatsSystemBalancer is the system balancer of one NATS cluster: it evens leaders and copies across its servers over every account.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | jetstream.nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsSystemBalancer |
metadata | ObjectMeta | Yes | |
spec | NatsSystemBalancerSpec | Yes | |
status | NatsSystemBalancerStatus | No |
NatsSystemBalancerSpec #
NatsSystemBalancerSpec is the desired state of a system balancer.
Appears on: NatsSystemBalancer.
| Field | Type | Required | Description |
|---|---|---|---|
connectionRef | ObjectReference | Yes | ConnectionRef names a NatsConnection with system credentials. |
moves | Moves | No | Moves selects the kinds of move made. Default: {}. |
interval | Duration | No | Interval is the least time between two moves, 1m when omitted. |
NatsSystemBalancerStatus #
NatsSystemBalancerStatus is the observed state of a system balancer.
Appears on: NatsSystemBalancer.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Holding. |
capabilities | Capabilities | No | Capabilities are the moves the balancer can make. |
servers | []ServerLoad | No | Servers report each server’s load. |
skew | Skew | No | Skew is the spread across servers. |
lastMove | Move | No | LastMove is the last move made. |
pending | []Move | No | Pending are moves requested and not yet complete. |
ObjectStoreConfig #
ObjectStoreConfig is nats.go’s ObjectStoreConfig, with the bucket under Name. An omitted field takes the server’s value.
Appears on: NatsObjectStoreSpec.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | Name is the bucket, metadata.name when omitted. |
description | string | No | |
ttl | Duration | No | |
maxBytes | Quantity | No | |
storage | StorageType | No | Storage is immutable. |
replicas | int32 | No | |
placement | Placement | No | |
compression | bool | No | |
metadata | map[string]string | No | Metadata is merged with the ownership marker, which the controller owns. |
Ownership #
Ownership is the marker naming the resource that owns an object on the server.
Appears on: NatsConsumerStatus, NatsKeyValueStatus, NatsObjectStoreStatus, NatsStreamStatus, SyncStatus.
| Field | Type | Required | Description |
|---|---|---|---|
origin | OwnershipOrigin | No | Origin is how the object came to be owned. |
uid | UID | No | UID is the owning resource’s UID, as written in the object’s metadata. |
OwnershipOrigin #
OwnershipOrigin is how the controller came to own an object.
Type: string
Appears on: Ownership.
| Value | Description |
|---|---|
Created | |
Adopted |
PersistMode #
PersistMode is a stream’s persistence mode.
Type: string
Appears on: NatsStreamSpec, StreamConfig.
| Value | Description |
|---|---|
Default | |
Async |
PinnedObject #
PinnedObject is a resource whose own spec pins the source NATS cluster.
Appears on: NatsClusterEvacuationStatus.
| Field | Type | Required | Description |
|---|---|---|---|
kind | string | Yes | Kind is NatsStream, NatsKeyValue or NatsObjectStore. |
namespace | string | Yes | Namespace of the resource. |
name | string | Yes | Name of the resource. |
Placement #
Placement is where a stream’s replicas are placed.
Appears on: KeyValueConfig, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec, ObjectStoreConfig, StreamConfig.
| Field | Type | Required | Description |
|---|---|---|---|
cluster | string | No | Cluster is the NATS cluster the replicas are placed in. |
tags | []string | No | Tags are server tags every replica’s server carries. |
preferred | string | No | Preferred is the server preferred as leader. |
Policies #
Policies are the lifecycle policies every JetStream resource carries beside its deletion policy, whose default differs by kind.
Appears on: NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec.
| Field | Type | Required | Description |
|---|---|---|---|
adoptionPolicy | AdoptionPolicy | No | AdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never. |
terminalPolicy | TerminalPolicy | No | TerminalPolicy is what a Terminal condition waits for. Default: Hold. |
Pool #
Pool is a declared group of streams balanced apart from the account’s others.
Appears on: NatsBalancerSpec.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name is unique among the balancer’s pools and appears in status.pools. |
selector | LabelSelector | Yes | Selector matches NatsStream, NatsKeyValue and NatsObjectStore resources in the balancer’s namespace by label. |
PoolStatus #
PoolStatus is one pool’s evenness.
Appears on: NatsBalancerStatus.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name of the pool; the default pool is “(default)”. |
streams | int32 | No | Streams is the number of streams in the pool. |
leaderSkew | int32 | No | LeaderSkew is the spread of leader counts across servers. |
PriorityPolicy #
PriorityPolicy is how a pull consumer picks among waiting clients.
Type: string
Appears on: ConsumerConfig, NatsConsumerSpec.
| Value | Description |
|---|---|
None | |
Overflow | |
PinnedClient | |
Prioritized |
ReplayPolicy #
ReplayPolicy is the pace a consumer replays at.
Type: string
Appears on: ConsumerConfig, NatsConsumerSpec.
| Value | Description |
|---|---|
Instant | |
Original |
ReplicaStatus #
ReplicaStatus is one replica of a Raft group.
Appears on: ConsumerServerStatus, StreamServerStatus, StreamTransfer.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name is the server_name of the server holding the replica. |
current | bool | No | Current reports whether the replica is current. |
lag | int64 | No | Lag is how many operations the replica is behind. |
Republish #
Republish republishes stored messages.
Appears on: KeyValueConfig, NatsKeyValueSpec, NatsStreamSpec, StreamConfig.
| Field | Type | Required | Description |
|---|---|---|---|
source | string | No | Source is the server’s src, the stored subjects republished. |
destination | string | Yes | Destination is the server’s dest, the subject they are republished to. |
headersOnly | bool | No | HeadersOnly republishes headers without the payload. |
RequestedMove #
RequestedMove is a stream an evacuation asked the server to move.
Appears on: NatsClusterEvacuationStatus.
| Field | Type | Required | Description |
|---|---|---|---|
account | string | Yes | Account is the account’s public key. |
stream | string | Yes | Stream is the stream’s server-side name. |
time | Time | Yes | Time the move was last requested. |
RetentionPolicy #
RetentionPolicy is a stream’s retention policy.
Type: string
Appears on: NatsStreamSpec, StreamConfig.
| Value | Description |
|---|---|
Limits | |
Interest | |
WorkQueue |
ServerLoad #
ServerLoad is one server’s share of leaders and replicas.
Appears on: NatsSystemBalancerStatus.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name is the server’s server_name. |
leaders | int32 | No | Leaders is the number of Raft groups the server leads. |
replicas | int32 | No | Replicas is the number of replicas the server holds. |
ServerStream #
ServerStream names a stream on the server.
Appears on: NatsClusterEvacuationStatus.
| Field | Type | Required | Description |
|---|---|---|---|
account | string | Yes | Account is the account’s public key. |
name | string | Yes | Name is the stream’s server-side name. |
Skew #
Skew is the spread between the most and least loaded servers.
Appears on: NatsSystemBalancerStatus.
| Field | Type | Required | Description |
|---|---|---|---|
leaders | int32 | No | Leaders is the spread of leader counts. |
replicas | int32 | No | Replicas is the spread of replica counts. |
StorageType #
StorageType is a JetStream storage backend.
Type: string
Appears on: KeyValueConfig, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec, ObjectStoreConfig, StreamConfig.
| Value | Description |
|---|---|
File | |
Memory |
StoreCompression #
StoreCompression is a stream’s storage compression.
Type: string
Appears on: NatsStreamSpec, StreamConfig.
| Value | Description |
|---|---|
None | |
S2 |
StreamConfig #
StreamConfig is nats.go’s jetstream.StreamConfig. An omitted field takes the server’s value, and the immutability rules compare a field only where both the old and the new spec set it.
Appears on: NatsStreamSpec.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | Name is the server-side stream name, metadata.name when omitted. |
description | string | No | |
subjects | []string | No | |
retention | RetentionPolicy | No | Retention cannot change to or from WorkQueue. |
maxConsumers | int64 | No | |
maxMsgs | int64 | No | |
maxBytes | Quantity | No | |
discard | DiscardPolicy | No | |
discardNewPerSubject | bool | No | |
maxAge | Duration | No | |
maxMsgsPerSubject | int64 | No | |
maxMsgSize | Quantity | No | |
storage | StorageType | No | Storage is immutable. |
replicas | int32 | No | |
noAck | bool | No | |
duplicates | Duration | No | |
placement | Placement | No | Placement pins the stream; changing placement.cluster moves it to that NATS cluster. |
mirror | StreamSource | No | Mirror cannot change once set; omitting it leaves the server’s mirror in place. |
sources | []StreamSource | No | |
sealed | bool | No | Sealed cannot be unset. |
denyDelete | bool | No | DenyDelete cannot be unset. |
denyPurge | bool | No | DenyPurge cannot be unset. |
allowRollup | bool | No | |
compression | StoreCompression | No | |
firstSeq | int64 | No | |
subjectTransform | SubjectTransform | No | |
republish | Republish | No | |
allowDirect | bool | No | |
mirrorDirect | bool | No | |
consumerLimits | StreamConsumerLimits | No | |
metadata | map[string]string | No | Metadata is merged with the ownership marker, which the controller owns. |
allowMsgTTL | bool | No | AllowMsgTTL cannot be unset. |
subjectDeleteMarkerTTL | Duration | No | |
allowMsgCounter | bool | No | AllowMsgCounter is immutable. |
allowAtomicPublish | bool | No | |
allowMsgSchedules | bool | No | AllowMsgSchedules cannot be unset. |
persistMode | PersistMode | No | PersistMode is immutable. |
allowBatchPublish | bool | No |
StreamConsumerLimits #
StreamConsumerLimits are defaults for the stream’s consumers.
Appears on: NatsStreamSpec, StreamConfig.
| Field | Type | Required | Description |
|---|---|---|---|
inactiveThreshold | Duration | No | |
maxAckPending | int64 | No |
StreamConsumerSource #
StreamConsumerSource is a durable consumer used for sourcing.
Appears on: StreamSource.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | Name is the server’s consumer name. |
deliverSubject | string | No | DeliverSubject is the server’s deliver_subject. |
StreamServerStatus #
StreamServerStatus is a stream’s state as the server reports it.
Appears on: NatsKeyValueStatus, NatsObjectStoreStatus, NatsStreamStatus.
| Field | Type | Required | Description |
|---|---|---|---|
created | Time | No | Created is when the stream was created on the server. |
leader | string | No | Leader is the server leading the stream’s group. |
replicas | []ReplicaStatus | No | Replicas are the followers. |
messages | int64 | No | Messages is the number of messages stored. |
bytes | Quantity | No | Bytes is the size of the messages stored. |
StreamSource #
StreamSource is a stream a mirror or source copies from.
Appears on: KeyValueConfig, NatsKeyValueSpec, NatsStreamSpec, StreamConfig.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name is the origin stream’s server-side name. |
optStartSeq | int64 | No | OptStartSeq is the origin sequence to start at. |
optStartTime | Time | No | OptStartTime is the origin time to start at. |
filterSubject | string | No | FilterSubject filters the origin’s messages. |
subjectTransforms | []SubjectTransform | No | SubjectTransforms filter and transform the origin’s subjects. |
external | ExternalStream | No | External qualifies an origin in another account or domain. |
consumer | StreamConsumerSource | No | Consumer is a durable consumer on the origin used for sourcing. |
StreamTransfer #
StreamTransfer is a stream’s move between NATS clusters.
Appears on: NatsStreamStatus.
| Field | Type | Required | Description |
|---|---|---|---|
from | string | No | From is the NATS cluster the stream leaves. |
to | string | No | To is the NATS cluster the stream moves to. |
started | Time | No | Started is when the move began. |
replicas | []ReplicaStatus | No | Replicas are the new replicas. |
consumers | TransferConsumers | No | Consumers is how many of the stream’s consumers have moved. |
SubjectTransform #
SubjectTransform maps a source subject to a destination subject.
Appears on: NatsStreamSpec, StreamConfig, StreamSource.
| Field | Type | Required | Description |
|---|---|---|---|
source | string | No | Source is the server’s src, the subjects transformed. |
destination | string | Yes | Destination is the server’s dest, the subject they become. |
SyncStatus #
SyncStatus is the status every JetStream object resource reports.
Appears on: NatsConsumerStatus, NatsKeyValueStatus, NatsObjectStoreStatus, NatsStreamStatus.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the status describes. |
conditions | []Condition | No | Conditions: Ready, Synced, Terminal, Adopted. |
lastSyncedTime | Time | No | LastSyncedTime is when the server object was last compared to spec. |
nextCheckTime | Time | No | NextCheckTime is when a Terminal condition under the Retry policy is next rechecked. |
ownership | Ownership | No | Ownership is the ownership marker on the server object. |
TerminalPolicy #
TerminalPolicy is what a Terminal condition waits for.
Type: string
Appears on: NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec, Policies.
| Value | Description |
|---|---|
Hold | TerminalHold waits for an edit to the resource. |
Retry | TerminalRetry rechecks every resync period. |
TransferConsumers #
TransferConsumers counts the consumers moved with a stream.
Appears on: StreamTransfer.
| Field | Type | Required | Description |
|---|---|---|---|
moved | int32 | No | Moved counts the stream’s consumers led from the target NATS cluster with no move left in flight. |
total | int32 | No | Total counts every consumer of the stream. |
nats.mikluko.io/v1beta1 #
The nats.mikluko.io API group: the kinds more than one controller reads, which are connections, trust copies and reference grants.
| Kind | Description |
|---|---|
| NatsAccountTrust | NatsAccountTrust is an account a leaf binds a remote to. |
| NatsConnection | NatsConnection is an address and an identity on a NATS cluster, managed or not; the only way the JetStream controller reaches one. |
| NatsOperatorTrust | NatsOperatorTrust is the trust roots a NatsCluster boots from: the NATS operator JWT and system account JWT. |
| NatsReferenceGrant | NatsReferenceGrant admits references into its own namespace from the namespaces it lists. Admitting a NatsCluster to a NatsConnection hands that connection’s credentials to the NatsCluster’s namespace. |
CA #
CA is where a CA bundle is read from.
Appears on: ConnectionTLS.
| Field | Type | Required | Description |
|---|---|---|---|
secretKeyRef | CASecretKeySelector | Yes | SecretKeyRef selects the CA bundle. |
CASecretKeySelector #
CASecretKeySelector selects a PEM CA bundle from a Secret in the referrer’s namespace.
Appears on: CA.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name of a Secret in the referrer’s namespace. |
key | string | No | Key within the Secret. Default: ca.crt. |
ConnectionTLS #
ConnectionTLS is the client side of TLS toward NATS servers.
Appears on: NatsConnectionSpec.
| Field | Type | Required | Description |
|---|---|---|---|
ca | CA | No | CA verifies the servers’ certificates. |
Credentials #
Credentials is where a NATS creds file is read from or written to.
Appears on: Auth, NatsConnectionSpec, NatsUserSpec.
| Field | Type | Required | Description |
|---|---|---|---|
secretKeyRef | CredentialsSecretKeySelector | Yes | SecretKeyRef selects the creds file. |
CredentialsSecretKeySelector #
CredentialsSecretKeySelector selects a NATS creds file from a Secret in the referrer’s namespace.
Appears on: Credentials.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name of a Secret in the referrer’s namespace. |
key | string | No | Key within the Secret. Default: user.creds. |
NatsAccountTrust #
NatsAccountTrust is an account a leaf binds a remote to.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsAccountTrust |
metadata | ObjectMeta | Yes | |
spec | NatsAccountTrustSpec | Yes | |
status | NatsAccountTrustStatus | No |
NatsAccountTrustSpec #
NatsAccountTrustSpec names an account either by reference to a live NatsAccount or by its literal public key.
Appears on: NatsAccountTrust.
| Field | Type | Required | Description |
|---|---|---|---|
accountRef | ObjectReference | No | AccountRef names a NatsAccount in this Kubernetes cluster; the auth controller then writes its public key and JWT into this object’s status. |
publicKey | string | No | PublicKey is the account’s public key. |
jwt | string | No | JWT is the account JWT a leaf preloads. |
NatsAccountTrustStatus #
NatsAccountTrustStatus is the observed state of a NatsAccountTrust.
Appears on: NatsAccountTrust.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the conditions describe. |
conditions | []Condition | No | Conditions describe the trust object’s state. |
publicKey | string | No | PublicKey is the referenced account’s public key, written by the auth controller in the reference form. |
jwt | string | No | JWT is the referenced account’s JWT, written by the auth controller in the reference form. |
NatsConnection #
NatsConnection is an address and an identity on a NATS cluster, managed or not; the only way the JetStream controller reaches one.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsConnection |
metadata | ObjectMeta | Yes | |
spec | NatsConnectionSpec | Yes | |
status | NatsConnectionStatus | No |
NatsConnectionSpec #
NatsConnectionSpec is how a NATS cluster is reached and whom as.
Appears on: NatsConnection.
| Field | Type | Required | Description |
|---|---|---|---|
servers | []string | Yes | Servers are the NATS URLs to dial. |
tls | ConnectionTLS | No | TLS configures the client side of TLS toward the servers. |
credentials | Credentials | No | Credentials decide the account the connection lands in; without them it lands wherever the server puts an unauthenticated client. |
NatsConnectionStatus #
NatsConnectionStatus is the observed state of a NatsConnection.
Appears on: NatsConnection.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the conditions describe. |
conditions | []Condition | No | Conditions describe the connection’s state. |
NatsOperatorTrust #
NatsOperatorTrust is the trust roots a NatsCluster boots from: the NATS operator JWT and system account JWT.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsOperatorTrust |
metadata | ObjectMeta | Yes | |
spec | NatsOperatorTrustSpec | Yes | |
status | NatsOperatorTrustStatus | No |
NatsOperatorTrustSpec #
NatsOperatorTrustSpec holds trust roots either by reference to a live NatsOperator or as literal JWTs.
Appears on: NatsOperatorTrust.
| Field | Type | Required | Description |
|---|---|---|---|
operatorRef | ObjectReference | No | OperatorRef names a NatsOperator in this Kubernetes cluster; the auth controller then writes its JWTs into this object’s status. |
operatorJWT | string | No | OperatorJWT is the NATS operator JWT. |
systemAccountJWT | string | No | SystemAccountJWT is the system account JWT. |
NatsOperatorTrustStatus #
NatsOperatorTrustStatus is the observed state of a NatsOperatorTrust.
Appears on: NatsOperatorTrust.
| Field | Type | Required | Description |
|---|---|---|---|
observedGeneration | int64 | No | ObservedGeneration is the generation the conditions describe. |
conditions | []Condition | No | Conditions describe the trust object’s state. |
operatorJWT | string | No | OperatorJWT is the referenced NATS operator’s JWT, written by the auth controller in the reference form. |
systemAccountJWT | string | No | SystemAccountJWT is the referenced NATS operator’s system account JWT, written by the auth controller in the reference form. |
NatsReferenceGrant #
NatsReferenceGrant admits references into its own namespace from the namespaces it lists. Admitting a NatsCluster to a NatsConnection hands that connection’s credentials to the NatsCluster’s namespace.
| Field | Type | Required | Description |
|---|---|---|---|
apiVersion | string | Yes | nats.mikluko.io/v1beta1 |
kind | string | Yes | NatsReferenceGrant |
metadata | ObjectMeta | Yes | |
spec | NatsReferenceGrantSpec | Yes |
NatsReferenceGrantSpec #
NatsReferenceGrantSpec lists who may reference what in the grant’s namespace.
Appears on: NatsReferenceGrant.
| Field | Type | Required | Description |
|---|---|---|---|
from | []ReferenceGrantFrom | Yes | From are the referrers admitted. |
to | []ReferenceGrantTo | Yes | To are the objects in this namespace they may reference. |
ObjectReference #
ObjectReference names an object whose kind the referring field fixes.
Appears on: AccountReference, Auth, LeafRemote, NatsAccountSpec, NatsAccountTrustSpec, NatsBalancerSpec, NatsClusterEvacuationSpec, NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsOperatorSpec, NatsOperatorTrustSpec, NatsStreamSpec, NatsSystemAccountSpec, NatsSystemBalancerSpec.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name of the referenced object. |
namespace | string | No | Namespace of the referenced object, the referrer’s own when omitted. Another namespace is admitted only by a NatsReferenceGrant there. |
ReferenceGrantFrom #
ReferenceGrantFrom names a kind of referrer in one namespace.
Appears on: NatsReferenceGrantSpec.
| Field | Type | Required | Description |
|---|---|---|---|
group | string | Yes | Group is the referrer’s API group, matched exactly, such as cluster.nats.mikluko.io. |
kind | string | Yes | Kind is the referrer’s kind, matched exactly, such as NatsCluster. |
namespace | string | Yes | Namespace the referrers live in, matched exactly. |
ReferenceGrantTo #
ReferenceGrantTo names a kind of object in the grant’s namespace.
Appears on: NatsReferenceGrantSpec.
| Field | Type | Required | Description |
|---|---|---|---|
group | string | Yes | Group is the referenced object’s API group, matched exactly, such as nats.mikluko.io. |
kind | string | Yes | Kind is the referenced object’s kind, matched exactly, such as NatsConnection. |
name | string | No | Name of the referenced object; omitted, every object of the kind. |
SecretReference #
SecretReference names a Secret in the referrer’s namespace.
Appears on: CertificateSource, ListenerTLS, RoutesTLS.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Name of a Secret in the referrer’s namespace. |