auth.nats.mikluko.io/v1beta1 #

The auth.nats.mikluko.io API group, owned by the auth controller.

KindDescription
NatsAccountNatsAccount is an account, its limits, and its exports and imports.
NatsOperatorNatsOperator is a NATS operator the auth controller signs for.
NatsSystemAccountNatsSystemAccount is a system account, signed only while a NatsOperator references it.
NatsUserNatsUser is a user of an account.

AccountJetStreamLimits #

AccountJetStreamLimits are an account’s JetStream limits.
Appears on: AccountLimits.

FieldTypeRequiredDescription
memoryStorageQuantityNoMemoryStorage is the memory store limit.
diskStorageQuantityNoDiskStorage is the file store limit.
streamsint64NoStreams is the maximum number of streams.
consumersint64NoConsumers is the maximum number of consumers.

AccountKind #

AccountKind is a kind that answers an account reference.
Type: string
Appears on: AccountReference.

ValueDescription
NatsAccount
NatsSystemAccount

AccountLimits #

AccountLimits are an account’s limits.
Appears on: NatsAccountSpec.

FieldTypeRequiredDescription
connectionsint64NoConnections is the maximum number of client connections.
subscriptionsint64NoSubscriptions is the maximum number of subscriptions.
payloadQuantityNoPayload is the maximum message payload.
jetstreamAccountJetStreamLimitsNoJetStream enables JetStream for the account, within these limits.

AccountReference #

AccountReference names a NatsAccount or a NatsSystemAccount.
Appears on: Export, Import, NatsUserSpec.

FieldTypeRequiredDescription
kindAccountKindYesKind of the account.
namestringYesName of the referenced object.
namespacestringNoNamespace of the referenced object, the referrer’s own when omitted. Another namespace is admitted only by a NatsReferenceGrant there.

ActivationState #

ActivationState is the state of an import’s activation token.
Type: string
Appears on: ImportStatus.

ValueDescription
SignedActivationSigned is an activation token the auth controller minted.

ConnectionType #

ConnectionType is a NATS connection type a user may connect as.
Type: string
Appears on: NatsUserSpec.

ValueDescription
STANDARD
WEBSOCKET
LEAFNODE
LEAFNODE_WS
MQTT
MQTT_WS
IN_PROCESS

DeletedAccount #

DeletedAccount is an account deleted from the resolvers.
Appears on: NatsOperatorStatus.

FieldTypeRequiredDescription
publicKeystringYesPublicKey of the account.
expiresTimeNoExpires is when the account’s last JWT expires; omitted, it never does.

Distribution #

Distribution is how many servers hold an account’s current JWT.
Appears on: NatsAccountStatus, NatsSystemAccountStatus.

FieldTypeRequiredDescription
serversint32NoServers is how many servers trust the account’s NATS operator.
currentint32NoCurrent is the number of servers holding the current JWT.
lastPushTimeTimeNoLastPushTime is when the JWT was last pushed.

Export #

Export is one export, or a preset expanding to several.
Appears on: NatsAccountSpec.

FieldTypeRequiredDescription
presetExportPresetNoPreset expands to a fixed set of exports.
namestringNoName is what imports name the export by.
typeExportTypeNoType is signed into the account JWT as the export’s type.
subjectstringNoSubject is signed into the account JWT as the export’s subject.
responseTypeResponseTypeNoResponseType of a service export, Singleton when omitted.
accessExportAccessNoAccess is Public when omitted; a Private export is importable only by its importers.
importers[]AccountReferenceNoImporters of a Private export, each minted an activation token.

ExportAccess #

ExportAccess is who may import an export.
Type: string
Appears on: Export.

ValueDescription
Public
Private

ExportPreset #

ExportPreset is a named set of exports.
Type: string
Appears on: Export.

ValueDescription
jetstream-stepdownExportPresetJetStreamStepdown exports the stream and consumer leader stepdown services, and imports them into the system account.

ExportType #

ExportType is the type of an export.
Type: string
Appears on: Export, ImportStatus.

ValueDescription
Stream
Service

IdentityKey #

IdentityKey is an identity key’s seed.
Appears on: Keys.

FieldTypeRequiredDescription
secretKeyRefSeedSecretKeySelectorYesSecretKeyRef selects the seed.

Import #

Import takes another account’s export by name.
Appears on: NatsAccountSpec.

FieldTypeRequiredDescription
accountRefAccountReferenceYesAccountRef names the exporting account.
exportstringYesExport is the name of the export taken.
localSubjectstringNoLocalSubject is where the import appears in this account, the exported subject when omitted.

ImportStatus #

ImportStatus is a resolved import.
Appears on: NatsAccountStatus.

FieldTypeRequiredDescription
exportstringNoExport is the export taken, as account/export, or namespace/account/export from another namespace.
subjectstringNoSubject is the exported subject.
localSubjectstringNoLocalSubject is where the import appears in this account.
typeExportTypeNoType is the type of the export taken.
activationActivationStateNoActivation is the state of the activation token of a Private export.

Keys #

Keys adopts existing seeds; omitted, the auth controller generates keys into Secrets that outlive the object.
Appears on: NatsAccountSpec, NatsOperatorSpec, NatsSystemAccountSpec.

FieldTypeRequiredDescription
identityIdentityKeyNoIdentity is the identity key’s seed.
signing[]SigningKeyNoSigning are the signing keys’ seeds.

NatsAccount #

NatsAccount is an account, its limits, and its exports and imports.

FieldTypeRequiredDescription
apiVersionstringYesauth.nats.mikluko.io/v1beta1
kindstringYesNatsAccount
metadataObjectMetaYes
specNatsAccountSpecYes
statusNatsAccountStatusNo

NatsAccountSpec #

NatsAccountSpec is the desired state of an account.
Appears on: NatsAccount.

FieldTypeRequiredDescription
operatorRefObjectReferenceYesOperatorRef names the NatsOperator that signs this account.
keysKeysNoKeys adopts existing seeds.
publicKeystringNoPublicKey is the account’s identity, keeping its identity key offline.
jwtTTLDurationNoJWTTTL is the account JWT’s lifetime, and the JWT is re-signed at half of it; 0 signs a JWT that never expires. Default: 48h.
limitsAccountLimitsNoLimits are signed into the account JWT; an omitted limit is unlimited.
exports[]ExportNoExports are what other accounts may import from this one.
imports[]ImportNoImports are exports of other accounts this one takes.

NatsAccountStatus #

NatsAccountStatus is the observed state of an account.
Appears on: NatsAccount.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, ReferencesResolved, Distributed, and where it applies RevocationsUnrecovered. Ready is False, reason PublicKeyInUse, while the NatsOperator’s NatsSystemAccount or another NatsAccount under it holds the account’s public key.
publicKeystringNoPublicKey is the account’s public key.
jwtstringNoJWT is the current account JWT; empty once the account is no longer admitted to its NatsOperator and the NatsOperator records its deletion.
jwtHashstringNoJWTHash identifies the current account JWT.
distributionDistributionNoDistribution is how many servers hold the current JWT.
revocations[]RevocationNoRevocations are the user keys the account JWT revokes.
imports[]ImportStatusNoImports are the resolved imports.

NatsOperator #

NatsOperator is a NATS operator the auth controller signs for.

FieldTypeRequiredDescription
apiVersionstringYesauth.nats.mikluko.io/v1beta1
kindstringYesNatsOperator
metadataObjectMetaYes
specNatsOperatorSpecYes
statusNatsOperatorStatusNo

NatsOperatorSpec #

NatsOperatorSpec is the desired state of a NATS operator.
Appears on: NatsOperator.

FieldTypeRequiredDescription
keysKeysNoKeys adopts existing seeds.
jwtstringNoJWT is a NATS operator JWT signed elsewhere, keeping the identity key offline.
systemAccountRefObjectReferenceYesSystemAccountRef names the NatsSystemAccount the NATS operator JWT names.

NatsOperatorStatus #

NatsOperatorStatus is the observed state of a NATS operator.
Appears on: NatsOperator.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, ReferencesResolved, RetiringKeysInUse, and where it applies RevocationsUnrecovered.
publicKeystringNoPublicKey is the identity key’s public key.
signingKeys[]stringNoSigningKeys are the signing keys’ public keys.
seedSecretsSeedSecretsNoSeedSecrets name the Secrets holding the generated seeds.
jwtstringNoJWT is the NATS operator JWT.
systemAccountSystemAccountStatusNoSystemAccount is the system account the NATS operator JWT names.
deletedAccounts[]DeletedAccountNoDeletedAccounts are the accounts deleted or no longer admitted while a server may hold a valid JWT for one; the delete is re-sent to each joining server until that JWT expires or an admitted account holds its key again.

NatsSystemAccount #

NatsSystemAccount is a system account, signed only while a NatsOperator references it.

FieldTypeRequiredDescription
apiVersionstringYesauth.nats.mikluko.io/v1beta1
kindstringYesNatsSystemAccount
metadataObjectMetaYes
specNatsSystemAccountSpecYes
statusNatsSystemAccountStatusNo

NatsSystemAccountSpec #

NatsSystemAccountSpec is the desired state of a system account.
Appears on: NatsSystemAccount.

FieldTypeRequiredDescription
operatorRefObjectReferenceYesOperatorRef names the NatsOperator that signs this account.
keysKeysNoKeys adopts existing seeds.
publicKeystringNoPublicKey is the account’s identity, keeping its identity key offline.

NatsSystemAccountStatus #

NatsSystemAccountStatus is the observed state of a system account.
Appears on: NatsSystemAccount.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, ReferencesResolved, Distributed.
publicKeystringNoPublicKey is the account’s public key.
jwtHashstringNoJWTHash identifies the current account JWT.
distributionDistributionNoDistribution is how many servers hold the current JWT.
revocations[]RevocationNoRevocations are the user keys the account JWT revokes.

NatsUser #

NatsUser is a user of an account.

FieldTypeRequiredDescription
apiVersionstringYesauth.nats.mikluko.io/v1beta1
kindstringYesNatsUser
metadataObjectMetaYes
specNatsUserSpecYes
statusNatsUserStatusNo

NatsUserSpec #

NatsUserSpec is the desired state of a user.
Appears on: NatsUser.

FieldTypeRequiredDescription
accountRefAccountReferenceYesAccountRef names the account the user belongs to.
permissionsPermissionsNoPermissions are the user’s publish and subscribe permissions.
connectionTypes[]ConnectionTypeNoConnectionTypes restricts how the user may connect; empty allows any.
presetUserPresetNoPreset is a named permission set in place of Permissions and ConnectionTypes.
publicKeystringNoPublicKey is a key whose seed the client holds; the user then gets a signed JWT in status and no creds Secret.
credentialsCredentialsNoCredentials is where the user’s creds are written, in the shape a NatsConnection reads; deleted while no grant admits the user to its account.

NatsUserStatus #

NatsUserStatus is the observed state of a user.
Appears on: NatsUser.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, ReferencesResolved, and Distributed, only ever False, reason NoSystemConnection. Ready is False, reason PublicKeyInUse, while another NatsUser of the account holds spec.publicKey, and reason AccountNotAdmitted while no NatsReferenceGrant admits the NatsAccount to its NatsOperator.
publicKeystringNoPublicKey is the user’s public key.
jwtstringNoJWT is the user JWT, published for a user that brings its own key.
replacedKeys[]ReplacedKeyNoReplacedKeys are keys the user held before PublicKey, each revoked in its account from when it was replaced; one leaves the list once the account JWT revokes it.

Permissions #

Permissions are a user’s publish and subscribe permissions.
Appears on: NatsUserSpec.

FieldTypeRequiredDescription
publishSubjectPermissionsNoPublish are the subjects the user may publish to.
subscribeSubjectPermissionsNoSubscribe are the subjects the user may subscribe to.

ReplacedKey #

ReplacedKey is a user key replaced by another.
Appears on: NatsUserStatus.

FieldTypeRequiredDescription
publicKeystringYesPublicKey is the replaced key.
atTimeYesAt is when it was replaced.

ResponseType #

ResponseType is how a service export responds.
Type: string
Appears on: Export.

ValueDescription
Singleton
Stream
Chunked

Revocation #

Revocation is a user key an account revokes.
Appears on: NatsAccountStatus, NatsSystemAccountStatus.

FieldTypeRequiredDescription
publicKeystringYesPublicKey is the revoked user’s key.
atTimeYesAt revokes the user’s JWTs issued at or before it.
issuers[]stringNoIssuers are the account’s signing keys when the revocation was recorded, the keys that may have signed a revoked JWT. The revocation is dropped once none of them is among the account’s signing keys.

SeedSecretKeySelector #

SeedSecretKeySelector selects an nkey seed from a Secret in the referrer’s namespace.
Appears on: IdentityKey, SigningKey.

FieldTypeRequiredDescription
namestringYesName of a Secret in the referrer’s namespace.
keystringYesKey within the Secret.

SeedSecrets #

SeedSecrets name the Secrets holding generated seeds.
Appears on: NatsOperatorStatus.

FieldTypeRequiredDescription
identitystringNoIdentity names the identity seed’s Secret.
signing[]stringNoSigning name the signing seeds’ Secrets.

SigningKey #

SigningKey is a signing key’s seed.
Appears on: Keys.

FieldTypeRequiredDescription
namestringYesName identifies the key within the list.
secretKeyRefSeedSecretKeySelectorYesSecretKeyRef selects the seed.
retiringboolNoRetiring keeps the key listed, so what it signed stays valid, and signs nothing new with it. Nothing removes a retiring key from the list.

SubjectPermissions #

SubjectPermissions allow and deny subjects.
Appears on: Permissions.

FieldTypeRequiredDescription
allow[]stringNoAllow are the subjects permitted; empty, every subject is.
deny[]stringNoDeny are the subjects refused, even where Allow matches them.

SystemAccountStatus #

SystemAccountStatus is the system account a NATS operator JWT names.
Appears on: NatsOperatorStatus.

FieldTypeRequiredDescription
namestringNoName of the NatsSystemAccount spec.systemAccountRef resolves to.
publicKeystringNoPublicKey of the system account.
jwtstringNoJWT of the system account.

UserPreset #

UserPreset is a named permission set.
Type: string
Appears on: NatsUserSpec.

ValueDescription
cluster-controller
jetstream-controller
auth-controller
readonly
leafnode

cluster.nats.mikluko.io/v1beta1 #

The cluster.nats.mikluko.io API group, owned by the cluster controller.

KindDescription
NatsClusterNatsCluster is a NATS cluster the cluster controller deploys, one StatefulSet per server.

Auth #

Auth puts a NATS cluster under a NATS operator.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
trustRefObjectReferenceYesTrustRef names the NatsOperatorTrust holding the trust roots.
systemCredentialsCredentialsNoSystemCredentials are the system user the cluster controller connects as.
resolverResolverTypeNoResolver is the account resolver; the cluster controller renders Full when omitted, and Cache for a leaf that preloads no account.

CertManagerCertificate #

CertManagerCertificate is a certificate cert-manager issues.
Appears on: CertificateSource, ListenerTLS, RoutesTLS.

FieldTypeRequiredDescription
issuerRefIssuerReferenceYesIssuerRef is copied into the Certificate the cluster controller creates in the NatsCluster’s namespace.

CertificateSource #

CertificateSource names where a listener’s certificate comes from.
Appears on: ListenerTLS, RoutesTLS.

FieldTypeRequiredDescription
secretRefSecretReferenceNoSecretRef names a kubernetes.io/tls Secret.
certManagerCertManagerCertificateNoCertManager has cert-manager issue the certificate.

ConfigApplyMethod #

ConfigApplyMethod is how a rendered config reached the servers.
Type: string
Appears on: ConfigStatus.

ValueDescription
Reload
Restart

ConfigStatus #

ConfigStatus is the rendered config revision.
Appears on: NatsClusterStatus.

FieldTypeRequiredDescription
revisionstringNoRevision is a digest of the rendered config, StatefulSets and certificates; each server reports its own as config_revision.
appliedByConfigApplyMethodNoAppliedBy is how the revision is applied.
restartReasonstringNoRestartReason names what made a restart necessary.

EmbeddedObjectMetadata #

EmbeddedObjectMetadata is the metadata a template passes through.
Appears on: PodTemplate, VolumeClaimTemplate.

FieldTypeRequiredDescription
labelsmap[string]stringNoLabels added to the rendered object.
annotationsmap[string]stringNoAnnotations added to the rendered object.

Endpoints #

Endpoints are a NATS cluster’s addresses.
Appears on: NatsClusterStatus.

FieldTypeRequiredDescription
clientstringNoClient is the client URL.
monitorstringNoMonitor is the monitoring URL, on the headless Service.
gatewaystringNoGateway is the advertised gateway address.

Exporter #

Exporter is the prometheus-nats-exporter sidecar in every server’s pod, serving metrics on port 7777.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
enabledboolNoEnabled turns the sidecar off when false. Default: true.
imageExporterImageNoImage is the sidecar’s image.
from[]NetworkPolicyPeerNoFrom admits the metrics port from these peers besides the cluster controller’s namespace, under monitor.networkPolicy.
resourcesResourceRequirementsNoResources replaces the sidecar’s default requests, 10m CPU and 32Mi memory, and limits, 100m CPU and 128Mi memory.

ExporterImage #

ExporterImage names the prometheus-nats-exporter sidecar’s image.
Appears on: Exporter.

FieldTypeRequiredDescription
repositorystringNoRepository is the image repository; empty, it is natsio/prometheus-nats-exporter.
tagstringNoTag is the image tag; empty, it is the tag the cluster controller pins, with that tag’s digest unless repository or digest is set.
digeststringNoDigest pins the image to one manifest, rendered after the tag.

Gateway #

Gateway joins a NATS cluster into a supercluster.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
discoveryGatewayDiscoveryYesDiscovery is how remotes are rendered: Explicit as gateway remotes with reject_unknown on, Gossip as seeds with reject_unknown off.
remotes[]GatewayRemoteYesRemotes are every member of the supercluster; this NATS cluster’s own entry is skipped.
tlsListenerTLSNoTLS on the gateway listener. The certificate’s Secret must hold ca.crt, which peers are verified against both ways. Absent, the NatsCluster is refused with reason GatewayWithoutTLS unless the cluster controller runs with –allow-gateway-without-tls, and then gateways run in the clear.
serviceServiceTemplateNoService is the template of the external gateway Service.
advertisestringNoAdvertise is the host:port the servers advertise for gateways.

GatewayDiscovery #

GatewayDiscovery is how gateway remotes are rendered.
Type: string
Appears on: Gateway.

ValueDescription
Explicit
Gossip

GatewayRemote #

GatewayRemote is one member of a supercluster.
Appears on: Gateway.

FieldTypeRequiredDescription
namestringYesName is the member’s gateway name.
urlstringYesURL is where the member’s gateway is dialled; on this NATS cluster’s own entry, its host is a name on the gateway certificate.

GatewayStatus #

GatewayStatus is the connection to one supercluster member.
Appears on: NatsClusterStatus.

FieldTypeRequiredDescription
namestringYesName is the member’s gateway name.
connectedboolNoConnected reports whether the member is reachable.
inboundint32NoInbound is the number of inbound gateway connections.
outboundint32NoOutbound is the number of outbound gateway connections.

Image #

Image names the nats-server image of a NATS cluster’s servers.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
repositorystringNoRepository is the image repository; empty, it is nats.
digeststringNoDigest pins the image to one manifest, rendered after the tag.

IssuerReference #

IssuerReference names a cert-manager Issuer or ClusterIssuer.
Appears on: CertManagerCertificate.

FieldTypeRequiredDescription
namestringYesName of an Issuer in the NatsCluster’s namespace, or of a ClusterIssuer.
kindstringNoKind of the issuer, Issuer when omitted.
groupstringNoGroup of the issuer, cert-manager.io when omitted.

JetStream #

JetStream is the JetStream configuration of every server.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
domainstringNoDomain is the JetStream domain.
limitsJetStreamLimitsNoLimits override the store limits derived from resources and the volume size.
volumeClaimTemplateVolumeClaimTemplateNoVolumeClaimTemplate is each server’s file store volume; a change replaces servers one at a time.

JetStreamLimits #

JetStreamLimits are a server’s JetStream store limits.
Appears on: JetStream, JetStreamStatus.

FieldTypeRequiredDescription
maxMemoryStoreQuantityNoMaxMemoryStore is the memory store limit.
maxFileStoreQuantityNoMaxFileStore is the file store limit.

JetStreamStatus #

JetStreamStatus is a NATS cluster’s JetStream state.
Appears on: NatsClusterStatus.

FieldTypeRequiredDescription
metaLeaderstringNoMetaLeader is the server name of the meta group’s leader, empty while none is known.
limitsJetStreamLimitsNoLimits are the effective store limits.

LeafRemote #

LeafRemote is a hub a leaf dials, and the local account it binds. With neither localAccountTrustRef nor localSystemAccount it binds the global account.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
connectionRefObjectReferenceYesConnectionRef names the NatsConnection holding the hub’s URL, CA and credentials.
localAccountTrustRefObjectReferenceNoLocalAccountTrustRef names the NatsAccountTrust of the local account the remote binds.
localSystemAccountboolNoLocalSystemAccount binds the remote to the leaf’s system account.

LeafRemoteStatus #

LeafRemoteStatus is the connection to one hub.
Appears on: NatsClusterStatus.

FieldTypeRequiredDescription
connectionNamespacestringYesConnectionNamespace is the namespace of the remote’s NatsConnection.
connectionNamestringYesConnectionName is the name of the remote’s NatsConnection.
connectedint32NoConnected is the number of servers connected to the hub.
accountstringNoAccount is the public key of the hub account the credentials sign into.

Leafnodes #

Leafnodes is the hub side of leaf connections.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
tlsListenerTLSNoTLS on the leafnode listener; absent, leaf connections run in the clear.
serviceServiceTemplateNoService is the template of the external leafnode Service.
advertisestringNoAdvertise is the host:port the servers advertise for leaf connections.

ListenerTLS #

ListenerTLS is TLS on a listener that has it only when configured.
Appears on: Gateway, Leafnodes, NatsClusterSpec.

FieldTypeRequiredDescription
secretRefSecretReferenceNoSecretRef names a kubernetes.io/tls Secret.
certManagerCertManagerCertificateNoCertManager has cert-manager issue the certificate.

Monitor #

Monitor configures access to the monitoring port.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
networkPolicyboolNoNetworkPolicy renders a NetworkPolicy over the servers’ pods that admits the route port only from those pods, the monitoring port only from the cluster controller’s namespace, the metrics port from there and exporter.from, and the other rendered ports from anywhere; a port podTemplate adds is not admitted. Default: true.

NatsCluster #

NatsCluster is a NATS cluster the cluster controller deploys, one StatefulSet per server.

FieldTypeRequiredDescription
apiVersionstringYescluster.nats.mikluko.io/v1beta1
kindstringYesNatsCluster
metadataObjectMetaYes
specNatsClusterSpecYes
statusNatsClusterStatusNo

NatsClusterSpec #

NatsClusterSpec is the desired state of a NATS cluster.
Appears on: NatsCluster.

FieldTypeRequiredDescription
versionstringYesVersion is the nats-server version rendered for.
imageImageNoImage is the nats-server image; its tag is always Version.
replicasint32YesReplicas is the number of servers.
resourcesResourceRequirementsNoResources of the nats-server container. GOMEMLIMIT and the JetStream memory store derive from limits.memory.
jetstreamJetStreamNoJetStream enables JetStream on every server.
serverTagsmap[string]stringNoServerTags are rendered as key:value server tags.
podTemplatePodTemplateNoPodTemplate is merged into every server’s pod, over its security context and automountServiceAccountToken too: whoever may write a NatsCluster runs pods with any privilege its namespace admits. Its affinity, when set, replaces the rendered preferred anti-affinity across nodes.
exporterExporterNoExporter configures the prometheus-nats-exporter sidecar; absent, it runs.
monitorMonitorNoMonitor configures access to the monitoring port, 8222, which has no authentication.
tlsListenerTLSNoTLS on the client listener; absent, clients connect in the clear. The cluster controller verifies it against the Secret’s ca.crt, or the system roots without one.
routesRoutesNoRoutes configures the route listener; absent, route TLS is on and self-signed.
authAuthNoAuth puts the NATS cluster under a NATS operator; absent, servers run with no accounts and no client auth.
gatewayGatewayNoGateway joins the NATS cluster into a supercluster under its own name, the NatsCluster’s name.
leafnodesLeafnodesNoLeafnodes opens a listener for leaf connections.
leafRemotes[]LeafRemoteNoLeafRemotes are the hubs this NATS cluster dials as a leaf.
rolloutRolloutNoRollout steers the restarts a spec change rolls out one server at a time.

NatsClusterStatus #

NatsClusterStatus is the observed state of a NATS cluster.
Appears on: NatsCluster.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Settled, Progressing, Deleting, and where they apply GatewaysConnected and LeafnodesConnected.
versionstringNoVersion is the version every server has reached.
replicasint32NoReplicas is the number of servers.
readyReplicasint32NoReadyReplicas is the number of ready servers.
endpointsEndpointsNoEndpoints are the addresses clients and peers reach the NATS cluster at.
configConfigStatusNoConfig is the rendered config revision and how it was applied.
rolloutRolloutStatusNoRollout is the rollout in progress.
removals[]ServerRemovalNoRemovals are the servers whose removal or replacement has begun, and how far each has gone.
jetstreamJetStreamStatusNoJetStream is the JetStream state of the NATS cluster.
gateways[]GatewayStatusNoGateways are the connections to the other supercluster members.
leafRemotes[]LeafRemoteStatusNoLeafRemotes are the connections to hubs.
servers[]ServerStatusNoServers has one entry per server.

PodTemplate #

PodTemplate is merged into the pod the cluster controller renders.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
metadataEmbeddedObjectMetadataNo
specPodSpecNoSpec is a partial pod spec merged over the rendered one; the API server does not validate it.

RemovalPhase #

RemovalPhase is how far a server’s removal has gone.
Type: string
Appears on: ServerRemoval.

ValueDescription
RequestedRemovalRequested is a server replace-server named, waiting its turn.
EvacuatingRemovalEvacuating is a server whose evacuation the meta leader accepted.
RemovedRemovalRemoved is a server whose removal from the meta group was committed.
DeletingRemovalDeleting is a server whose StatefulSet, data volume claim and, beyond spec.replicas, ConfigMap are being deleted. A replaced server is not recreated until its claim is gone.
RejoiningRemovalRejoining is a server its replacement recreated, until the rollout gate next opens.

ResolverType #

ResolverType is a NATS account resolver type.
Type: string
Appears on: Auth.

ValueDescription
Full
Cache

Rollout #

Rollout steers a NATS cluster’s one-server-at-a-time restarts.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
pausedboolNoPaused stops a rollout before its next step.

RolloutGate #

RolloutGate is what a rollout waits for.
Appears on: RolloutStatus.

FieldTypeRequiredDescription
waitingForstringNoWaitingFor names the condition the gate waits for.
sinceTimeNoSince is when the gate closed.

RolloutStatus #

RolloutStatus is a rollout in progress.
Appears on: NatsClusterStatus.

FieldTypeRequiredDescription
targetRevisionstringNoTargetRevision is the config revision being rolled out.
updated[]stringNoUpdated are the servers on the target revision.
currentstringNoCurrent is the server being updated.
pending[]stringNoPending are the servers still to update.
gateRolloutGateNoGate is what the rollout waits for before its next step.

Routes #

Routes configures the route listener.
Appears on: NatsClusterSpec.

FieldTypeRequiredDescription
tlsRoutesTLSNoTLS on routes.

RoutesTLS #

RoutesTLS is route TLS: on unless disabled, self-signed unless a certificate is named.
Appears on: Routes.

FieldTypeRequiredDescription
enabledboolNoEnabled turns route TLS off when false. Default: true.
secretRefSecretReferenceNoSecretRef names a kubernetes.io/tls Secret.
certManagerCertManagerCertificateNoCertManager has cert-manager issue the certificate.

ServerRemoval #

ServerRemoval is one server’s removal.
Appears on: NatsClusterStatus.

FieldTypeRequiredDescription
namestringYesName is the server_name.
phaseRemovalPhaseYesPhase is how far the removal has gone.
sinceTimeNoSince is when the removal entered Phase.

ServerStatus #

ServerStatus is one server’s state.
Appears on: NatsClusterStatus.

FieldTypeRequiredDescription
namestringYesName is the server_name.
versionstringNoVersion is the nats-server version it runs.
readyboolNoReady reports whether its pod is Ready.
configRevisionstringNoConfigRevision is the config revision it reports.

ServiceTemplate #

ServiceTemplate is the template of an external Service.
Appears on: Gateway, Leafnodes.

FieldTypeRequiredDescription
typeServiceTypeNoType of the Service, ClusterIP when omitted.
annotationsmap[string]stringNoAnnotations set on the Service.

VolumeClaimTemplate #

VolumeClaimTemplate is a PersistentVolumeClaim template.
Appears on: JetStream.

FieldTypeRequiredDescription
metadataEmbeddedObjectMetadataNo
specPersistentVolumeClaimSpecYes

jetstream.nats.mikluko.io/v1beta1 #

The jetstream.nats.mikluko.io API group, owned by the JetStream controller.

KindDescription
NatsBalancerNatsBalancer is an account balancer: it evens leaders and copies within the pools of one account, yielding to the system balancer.
NatsClusterEvacuationNatsClusterEvacuation moves every stream, key-value bucket and object store in every account off one NATS cluster, save those whose resource sets placement.cluster: those naming it are reported as pinned, the rest left to their owners.
NatsConsumerNatsConsumer is a JetStream consumer.
NatsKeyValueNatsKeyValue is a JetStream key-value bucket.
NatsObjectStoreNatsObjectStore is a JetStream object store.
NatsStreamNatsStream is a JetStream stream.
NatsSystemBalancerNatsSystemBalancer is the system balancer of one NATS cluster: it evens leaders and copies across its servers over every account.

AckPolicy #

AckPolicy is how a consumer’s messages are acknowledged.
Type: string
Appears on: ConsumerConfig, NatsConsumerSpec.

ValueDescription
None
All
Explicit

AdoptionPolicy #

AdoptionPolicy is what the JetStream controller does with an object on the server that it does not own.
Type: string
Appears on: NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec, Policies.

ValueDescription
NeverAdoptionNever creates the object, and goes Terminal on one it does not own.
AdoptAdoptionAdopt requires the object to exist and writes its config into spec.
AdoptOrCreateAdoptionAdoptOrCreate applies spec whether or not the object exists, and late-initializes omitted fields from the server.

Capabilities #

Capabilities are the moves a system balancer can make.
Appears on: NatsSystemBalancerStatus.

FieldTypeRequiredDescription
placementboolNoPlacement reports whether placement moves are possible.
leaderLeaderCapabilityNoLeader is Full when every account holding a stream carries the jetstream-stepdown export, None when none does, and Partial otherwise; unset while moves.leader is false.
leaderReasonstringNoLeaderReason explains a leader capability short of Full.

ConsumerConfig #

ConsumerConfig is nats.go’s jetstream.ConsumerConfig: a push consumer when DeliverSubject is set, a pull consumer otherwise. An omitted field takes the server’s value.
Appears on: NatsConsumerSpec.

FieldTypeRequiredDescription
namestringNoName is the server-side durable name, metadata.name when omitted.
descriptionstringNo
deliverPolicyDeliverPolicyNo
optStartSeqint64No
optStartTimeTimeNo
ackPolicyAckPolicyNo
ackWaitDurationNo
maxDeliverint64No
backOff[]DurationNo
filterSubjectstringNo
filterSubjects[]stringNo
replayPolicyReplayPolicyNo
rateLimitint64NoRateLimit is in bits per second.
sampleFrequencystringNo
maxWaitingint64No
maxAckPendingint64No
flowControlboolNo
headersOnlyboolNo
maxRequestBatchint64No
maxRequestExpiresDurationNo
maxRequestMaxBytesint64No
deliverSubjectstringNo
deliverGroupstringNo
heartbeatDurationNo
inactiveThresholdDurationNo
replicasint32No
memoryStorageboolNo
metadatamap[string]stringNoMetadata is merged with the ownership marker, which the controller owns.
pauseUntilTimeNo
priorityGroups[]stringNo
priorityPolicyPriorityPolicyNo
pinnedTTLDurationNo

ConsumerServerStatus #

ConsumerServerStatus is a consumer’s state as the server reports it.
Appears on: NatsConsumerStatus.

FieldTypeRequiredDescription
createdTimeNoCreated is when the consumer was created on the server.
leaderstringNoLeader is the server leading the consumer’s group.
replicas[]ReplicaStatusNoReplicas are the followers.

DeletionPolicy #

DeletionPolicy is what deleting the resource does to the object on the server.
Type: string
Appears on: NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec.

ValueDescription
Retain
Delete

DeliverPolicy #

DeliverPolicy is where a consumer starts.
Type: string
Appears on: ConsumerConfig, NatsConsumerSpec.

ValueDescription
All
Last
New
ByStartSequence
ByStartTime
LastPerSubject

DiscardPolicy #

DiscardPolicy is what a full stream discards.
Type: string
Appears on: NatsStreamSpec, StreamConfig.

ValueDescription
Old
New

EvacuationSource #

EvacuationSource is the NATS cluster an evacuation empties.
Appears on: NatsClusterEvacuationSpec.

FieldTypeRequiredDescription
clusterstringYesCluster is the NATS cluster’s name.

EvacuationTarget #

EvacuationTarget is where an evacuation moves streams.
Appears on: NatsClusterEvacuationSpec.

FieldTypeRequiredDescription
serverTags[]stringYesServerTags must match servers of the target only; the evacuation refuses to start if a server of the source carries them.

ExternalStream #

ExternalStream is the API and deliver prefixes of an origin in another account or domain.
Appears on: StreamSource.

FieldTypeRequiredDescription
apiPrefixstringYesAPIPrefix is the JetStream API prefix.
deliverPrefixstringNoDeliverPrefix is the deliver subject prefix.

KeyValueConfig #

KeyValueConfig is nats.go’s KeyValueConfig, with the bucket under Name. An omitted field takes the server’s value.
Appears on: NatsKeyValueSpec.

FieldTypeRequiredDescription
namestringNoName is the bucket, metadata.name when omitted.
descriptionstringNo
maxValueSizeQuantityNo
historyint32No
ttlDurationNo
maxBytesQuantityNo
storageStorageTypeNoStorage is immutable.
replicasint32No
placementPlacementNo
republishRepublishNo
mirrorStreamSourceNo
sources[]StreamSourceNo
compressionboolNo
limitMarkerTTLDurationNo
metadatamap[string]stringNoMetadata is merged with the ownership marker, which the controller owns.

LeaderCapability #

LeaderCapability is how far a system balancer can make leader moves.
Type: string
Appears on: Capabilities.

ValueDescription
Full
Partial
None

Move #

Move is a leader or placement move.
Appears on: NatsBalancerStatus, NatsSystemBalancerStatus.

FieldTypeRequiredDescription
kindMoveKindNoKind is Leader for a leader move, Placement for a placement move.
accountstringNoAccount is the public key of the account whose stream moved.
streamstringNoStream is the name of the stream moved, or of the stream whose consumer’s leader moved.
consumerstringNoConsumer is the name of the consumer whose leader moved; empty on a stream’s move.
fromstringNoFrom is the server moved off.
tostringNoTo is the server moved to.
timeTimeNoTime the move was requested.

MoveKind #

MoveKind is a kind of balancer move.
Type: string
Appears on: Move.

ValueDescription
Leader
Placement

Moves #

Moves selects the kinds of move a balancer makes.
Appears on: NatsBalancerSpec, NatsSystemBalancerSpec.

FieldTypeRequiredDescription
leaderboolNoLeader enables leader moves. Default: true.
placementboolNoPlacement enables placement moves. Default: false.

NatsBalancer #

NatsBalancer is an account balancer: it evens leaders and copies within the pools of one account, yielding to the system balancer.

FieldTypeRequiredDescription
apiVersionstringYesjetstream.nats.mikluko.io/v1beta1
kindstringYesNatsBalancer
metadataObjectMetaYes
specNatsBalancerSpecYes
statusNatsBalancerStatusNo

NatsBalancerSpec #

NatsBalancerSpec is the desired state of an account balancer.
Appears on: NatsBalancer.

FieldTypeRequiredDescription
connectionRefObjectReferenceYesConnectionRef names the NatsConnection whose credentials decide the account.
pools[]PoolNoPools are judged apart; a stream matching several belongs to the first. With none declared the account is one pool.
movesMovesNoMoves selects the kinds of move made. Default: {}.
intervalDurationNoInterval is the least time between two moves, 1m when omitted.

NatsBalancerStatus #

NatsBalancerStatus is the observed state of an account balancer.
Appears on: NatsBalancer.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Holding, Overlapping.
pools[]PoolStatusNoPools report each pool’s evenness.
lastMoveMoveNoLastMove is the last move made; the next waits for spec.interval after its time.

NatsClusterEvacuation #

NatsClusterEvacuation moves every stream, key-value bucket and object store in every account off one NATS cluster, save those whose resource sets placement.cluster: those naming it are reported as pinned, the rest left to their owners.

FieldTypeRequiredDescription
apiVersionstringYesjetstream.nats.mikluko.io/v1beta1
kindstringYesNatsClusterEvacuation
metadataObjectMetaYes
specNatsClusterEvacuationSpecYes
statusNatsClusterEvacuationStatusNo

NatsClusterEvacuationSpec #

NatsClusterEvacuationSpec is the desired state of an evacuation.
Appears on: NatsClusterEvacuation.

FieldTypeRequiredDescription
connectionRefObjectReferenceYesConnectionRef names a NatsConnection with system credentials; it is immutable.
fromEvacuationSourceYesFrom is the NATS cluster emptied; it is immutable.
toEvacuationTargetYesTo is where the streams are moved; it is immutable.

NatsClusterEvacuationStatus #

NatsClusterEvacuationStatus is the observed state of an evacuation.
Appears on: NatsClusterEvacuation.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Progressing.
movedint32NoMoved is the number of streams moved.
inFlightint32NoInFlight is the number of moves in progress.
requested[]RequestedMoveNoRequested are the moves requested that the source NATS cluster has not yet seen complete; deleting the evacuation cancels them.
remainingint32NoRemaining is the number of streams still to leave the source NATS cluster: in flight, waiting for a slot, or refused by the server in the last pass. Pinned streams and streams left for their owners are not counted.
pinned[]PinnedObjectNoPinned are the resources left in place; the evacuation is not Ready while any remains.
stalePlacement[]ServerStreamNoStalePlacement are the streams moved that no resource owns and whose config still names the source NATS cluster, so an update that changes their placement returns them to it.

NatsConsumer #

NatsConsumer is a JetStream consumer.

FieldTypeRequiredDescription
apiVersionstringYesjetstream.nats.mikluko.io/v1beta1
kindstringYesNatsConsumer
metadataObjectMetaYes
specNatsConsumerSpecYes
statusNatsConsumerStatusNo

NatsConsumerSpec #

NatsConsumerSpec is the desired state of a consumer. deliverPolicy, ackPolicy, replayPolicy, optStartSeq, optStartTime, heartbeat, flowControl and maxWaiting are immutable unless recreateOnImmutableChange is set. The fields of the inlined ConsumerConfig mirror nats.go’s jetstream.ConsumerConfig and mean what their like-named fields there mean: https://pkg.go.dev/github.com/nats-io/nats.go/jetstream#ConsumerConfig.
Appears on: NatsConsumer.

FieldTypeRequiredDescription
connectionRefObjectReferenceNoConnectionRef names the NatsConnection whose credentials decide the account, the stream’s own when StreamRef is set and this is omitted; it is immutable.
streamstringNoStream is the server-side name of a stream with no resource; it is immutable.
streamRefObjectReferenceNoStreamRef names the NatsStream the consumer waits for and consumes; it is immutable.
adoptionPolicyAdoptionPolicyNoAdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never.
terminalPolicyTerminalPolicyNoTerminalPolicy is what a Terminal condition waits for. Default: Hold.
deletionPolicyDeletionPolicyNoDeletionPolicy is what deleting the resource does to the consumer. Default: Delete.
recreateOnImmutableChangeboolNoRecreateOnImmutableChange lets an immutable field change, by deleting and recreating the consumer, which discards its delivery state.
namestringNoName is the server-side durable name, metadata.name when omitted.
descriptionstringNo
deliverPolicyDeliverPolicyNo
optStartSeqint64No
optStartTimeTimeNo
ackPolicyAckPolicyNo
ackWaitDurationNo
maxDeliverint64No
backOff[]DurationNo
filterSubjectstringNo
filterSubjects[]stringNo
replayPolicyReplayPolicyNo
rateLimitint64NoRateLimit is in bits per second.
sampleFrequencystringNo
maxWaitingint64No
maxAckPendingint64No
flowControlboolNo
headersOnlyboolNo
maxRequestBatchint64No
maxRequestExpiresDurationNo
maxRequestMaxBytesint64No
deliverSubjectstringNo
deliverGroupstringNo
heartbeatDurationNo
inactiveThresholdDurationNo
replicasint32No
memoryStorageboolNo
metadatamap[string]stringNoMetadata is merged with the ownership marker, which the controller owns.
pauseUntilTimeNo
priorityGroups[]stringNo
priorityPolicyPriorityPolicyNo
pinnedTTLDurationNo

NatsConsumerStatus #

NatsConsumerStatus is the observed state of a consumer.
Appears on: NatsConsumer.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Synced, Terminal, Adopted.
lastSyncedTimeTimeNoLastSyncedTime is when the server object was last compared to spec.
nextCheckTimeTimeNoNextCheckTime is when a Terminal condition under the Retry policy is next rechecked.
ownershipOwnershipNoOwnership is the ownership marker on the server object.
serverConsumerServerStatusNoServer is the consumer’s state on the server.

NatsKeyValue #

NatsKeyValue is a JetStream key-value bucket.

FieldTypeRequiredDescription
apiVersionstringYesjetstream.nats.mikluko.io/v1beta1
kindstringYesNatsKeyValue
metadataObjectMetaYes
specNatsKeyValueSpecYes
statusNatsKeyValueStatusNo

NatsKeyValueSpec #

NatsKeyValueSpec is the desired state of a key-value bucket. The fields of the inlined KeyValueConfig mirror nats.go’s jetstream.KeyValueConfig and mean what their like-named fields there mean: https://pkg.go.dev/github.com/nats-io/nats.go/jetstream#KeyValueConfig.
Appears on: NatsKeyValue.

FieldTypeRequiredDescription
connectionRefObjectReferenceYesConnectionRef names the NatsConnection whose credentials decide the account; it is immutable.
adoptionPolicyAdoptionPolicyNoAdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never.
terminalPolicyTerminalPolicyNoTerminalPolicy is what a Terminal condition waits for. Default: Hold.
deletionPolicyDeletionPolicyNoDeletionPolicy is what deleting the resource does to the bucket. Default: Retain.
namestringNoName is the bucket, metadata.name when omitted.
descriptionstringNo
maxValueSizeQuantityNo
historyint32No
ttlDurationNo
maxBytesQuantityNo
storageStorageTypeNoStorage is immutable.
replicasint32No
placementPlacementNo
republishRepublishNo
mirrorStreamSourceNo
sources[]StreamSourceNo
compressionboolNo
limitMarkerTTLDurationNo
metadatamap[string]stringNoMetadata is merged with the ownership marker, which the controller owns.

NatsKeyValueStatus #

NatsKeyValueStatus is the observed state of a key-value bucket.
Appears on: NatsKeyValue.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Synced, Terminal, Adopted.
lastSyncedTimeTimeNoLastSyncedTime is when the server object was last compared to spec.
nextCheckTimeTimeNoNextCheckTime is when a Terminal condition under the Retry policy is next rechecked.
ownershipOwnershipNoOwnership is the ownership marker on the server object.
serverStreamServerStatusNoServer is the bucket’s stream state on the server.

NatsObjectStore #

NatsObjectStore is a JetStream object store.

FieldTypeRequiredDescription
apiVersionstringYesjetstream.nats.mikluko.io/v1beta1
kindstringYesNatsObjectStore
metadataObjectMetaYes
specNatsObjectStoreSpecYes
statusNatsObjectStoreStatusNo

NatsObjectStoreSpec #

NatsObjectStoreSpec is the desired state of an object store. The fields of the inlined ObjectStoreConfig mirror nats.go’s jetstream.ObjectStoreConfig and mean what their like-named fields there mean: https://pkg.go.dev/github.com/nats-io/nats.go/jetstream#ObjectStoreConfig.
Appears on: NatsObjectStore.

FieldTypeRequiredDescription
connectionRefObjectReferenceYesConnectionRef names the NatsConnection whose credentials decide the account; it is immutable.
adoptionPolicyAdoptionPolicyNoAdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never.
terminalPolicyTerminalPolicyNoTerminalPolicy is what a Terminal condition waits for. Default: Hold.
deletionPolicyDeletionPolicyNoDeletionPolicy is what deleting the resource does to the object store. Default: Retain.
namestringNoName is the bucket, metadata.name when omitted.
descriptionstringNo
ttlDurationNo
maxBytesQuantityNo
storageStorageTypeNoStorage is immutable.
replicasint32No
placementPlacementNo
compressionboolNo
metadatamap[string]stringNoMetadata is merged with the ownership marker, which the controller owns.

NatsObjectStoreStatus #

NatsObjectStoreStatus is the observed state of an object store.
Appears on: NatsObjectStore.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Synced, Terminal, Adopted.
lastSyncedTimeTimeNoLastSyncedTime is when the server object was last compared to spec.
nextCheckTimeTimeNoNextCheckTime is when a Terminal condition under the Retry policy is next rechecked.
ownershipOwnershipNoOwnership is the ownership marker on the server object.
serverStreamServerStatusNoServer is the object store’s stream state on the server.

NatsStream #

NatsStream is a JetStream stream.

FieldTypeRequiredDescription
apiVersionstringYesjetstream.nats.mikluko.io/v1beta1
kindstringYesNatsStream
metadataObjectMetaYes
specNatsStreamSpecYes
statusNatsStreamStatusNo

NatsStreamSpec #

NatsStreamSpec is the desired state of a stream. The fields of the inlined StreamConfig mirror nats.go’s jetstream.StreamConfig and mean what their like-named fields there mean: https://pkg.go.dev/github.com/nats-io/nats.go/jetstream#StreamConfig.
Appears on: NatsStream.

FieldTypeRequiredDescription
connectionRefObjectReferenceYesConnectionRef names the NatsConnection whose credentials decide the account; it is immutable.
adoptionPolicyAdoptionPolicyNoAdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never.
terminalPolicyTerminalPolicyNoTerminalPolicy is what a Terminal condition waits for. Default: Hold.
deletionPolicyDeletionPolicyNoDeletionPolicy is what deleting the resource does to the stream. Default: Retain.
namestringNoName is the server-side stream name, metadata.name when omitted.
descriptionstringNo
subjects[]stringNo
retentionRetentionPolicyNoRetention cannot change to or from WorkQueue.
maxConsumersint64No
maxMsgsint64No
maxBytesQuantityNo
discardDiscardPolicyNo
discardNewPerSubjectboolNo
maxAgeDurationNo
maxMsgsPerSubjectint64No
maxMsgSizeQuantityNo
storageStorageTypeNoStorage is immutable.
replicasint32No
noAckboolNo
duplicatesDurationNo
placementPlacementNoPlacement pins the stream; changing placement.cluster moves it to that NATS cluster.
mirrorStreamSourceNoMirror cannot change once set; omitting it leaves the server’s mirror in place.
sources[]StreamSourceNo
sealedboolNoSealed cannot be unset.
denyDeleteboolNoDenyDelete cannot be unset.
denyPurgeboolNoDenyPurge cannot be unset.
allowRollupboolNo
compressionStoreCompressionNo
firstSeqint64No
subjectTransformSubjectTransformNo
republishRepublishNo
allowDirectboolNo
mirrorDirectboolNo
consumerLimitsStreamConsumerLimitsNo
metadatamap[string]stringNoMetadata is merged with the ownership marker, which the controller owns.
allowMsgTTLboolNoAllowMsgTTL cannot be unset.
subjectDeleteMarkerTTLDurationNo
allowMsgCounterboolNoAllowMsgCounter is immutable.
allowAtomicPublishboolNo
allowMsgSchedulesboolNoAllowMsgSchedules cannot be unset.
persistModePersistModeNoPersistMode is immutable.
allowBatchPublishboolNo

NatsStreamStatus #

NatsStreamStatus is the observed state of a stream.
Appears on: NatsStream.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Synced, Terminal, Adopted.
lastSyncedTimeTimeNoLastSyncedTime is when the server object was last compared to spec.
nextCheckTimeTimeNoNextCheckTime is when a Terminal condition under the Retry policy is next rechecked.
ownershipOwnershipNoOwnership is the ownership marker on the server object.
serverStreamServerStatusNoServer is the stream’s state on the server.
transferStreamTransferNoTransfer is a move to another NATS cluster in progress.

NatsSystemBalancer #

NatsSystemBalancer is the system balancer of one NATS cluster: it evens leaders and copies across its servers over every account.

FieldTypeRequiredDescription
apiVersionstringYesjetstream.nats.mikluko.io/v1beta1
kindstringYesNatsSystemBalancer
metadataObjectMetaYes
specNatsSystemBalancerSpecYes
statusNatsSystemBalancerStatusNo

NatsSystemBalancerSpec #

NatsSystemBalancerSpec is the desired state of a system balancer.
Appears on: NatsSystemBalancer.

FieldTypeRequiredDescription
connectionRefObjectReferenceYesConnectionRef names a NatsConnection with system credentials.
movesMovesNoMoves selects the kinds of move made. Default: {}.
intervalDurationNoInterval is the least time between two moves, 1m when omitted.

NatsSystemBalancerStatus #

NatsSystemBalancerStatus is the observed state of a system balancer.
Appears on: NatsSystemBalancer.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Holding.
capabilitiesCapabilitiesNoCapabilities are the moves the balancer can make.
servers[]ServerLoadNoServers report each server’s load.
skewSkewNoSkew is the spread across servers.
lastMoveMoveNoLastMove is the last move made.
pending[]MoveNoPending are moves requested and not yet complete.

ObjectStoreConfig #

ObjectStoreConfig is nats.go’s ObjectStoreConfig, with the bucket under Name. An omitted field takes the server’s value.
Appears on: NatsObjectStoreSpec.

FieldTypeRequiredDescription
namestringNoName is the bucket, metadata.name when omitted.
descriptionstringNo
ttlDurationNo
maxBytesQuantityNo
storageStorageTypeNoStorage is immutable.
replicasint32No
placementPlacementNo
compressionboolNo
metadatamap[string]stringNoMetadata is merged with the ownership marker, which the controller owns.

Ownership #

Ownership is the marker naming the resource that owns an object on the server.
Appears on: NatsConsumerStatus, NatsKeyValueStatus, NatsObjectStoreStatus, NatsStreamStatus, SyncStatus.

FieldTypeRequiredDescription
originOwnershipOriginNoOrigin is how the object came to be owned.
uidUIDNoUID is the owning resource’s UID, as written in the object’s metadata.

OwnershipOrigin #

OwnershipOrigin is how the controller came to own an object.
Type: string
Appears on: Ownership.

ValueDescription
Created
Adopted

PersistMode #

PersistMode is a stream’s persistence mode.
Type: string
Appears on: NatsStreamSpec, StreamConfig.

ValueDescription
Default
Async

PinnedObject #

PinnedObject is a resource whose own spec pins the source NATS cluster.
Appears on: NatsClusterEvacuationStatus.

FieldTypeRequiredDescription
kindstringYesKind is NatsStream, NatsKeyValue or NatsObjectStore.
namespacestringYesNamespace of the resource.
namestringYesName of the resource.

Placement #

Placement is where a stream’s replicas are placed.
Appears on: KeyValueConfig, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec, ObjectStoreConfig, StreamConfig.

FieldTypeRequiredDescription
clusterstringNoCluster is the NATS cluster the replicas are placed in.
tags[]stringNoTags are server tags every replica’s server carries.
preferredstringNoPreferred is the server preferred as leader.

Policies #

Policies are the lifecycle policies every JetStream resource carries beside its deletion policy, whose default differs by kind.
Appears on: NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec.

FieldTypeRequiredDescription
adoptionPolicyAdoptionPolicyNoAdoptionPolicy is what happens to an object of the same name the controller does not own. Default: Never.
terminalPolicyTerminalPolicyNoTerminalPolicy is what a Terminal condition waits for. Default: Hold.

Pool #

Pool is a declared group of streams balanced apart from the account’s others.
Appears on: NatsBalancerSpec.

FieldTypeRequiredDescription
namestringYesName is unique among the balancer’s pools and appears in status.pools.
selectorLabelSelectorYesSelector matches NatsStream, NatsKeyValue and NatsObjectStore resources in the balancer’s namespace by label.

PoolStatus #

PoolStatus is one pool’s evenness.
Appears on: NatsBalancerStatus.

FieldTypeRequiredDescription
namestringYesName of the pool; the default pool is “(default)”.
streamsint32NoStreams is the number of streams in the pool.
leaderSkewint32NoLeaderSkew is the spread of leader counts across servers.

PriorityPolicy #

PriorityPolicy is how a pull consumer picks among waiting clients.
Type: string
Appears on: ConsumerConfig, NatsConsumerSpec.

ValueDescription
None
Overflow
PinnedClient
Prioritized

ReplayPolicy #

ReplayPolicy is the pace a consumer replays at.
Type: string
Appears on: ConsumerConfig, NatsConsumerSpec.

ValueDescription
Instant
Original

ReplicaStatus #

ReplicaStatus is one replica of a Raft group.
Appears on: ConsumerServerStatus, StreamServerStatus, StreamTransfer.

FieldTypeRequiredDescription
namestringYesName is the server_name of the server holding the replica.
currentboolNoCurrent reports whether the replica is current.
lagint64NoLag is how many operations the replica is behind.

Republish #

Republish republishes stored messages.
Appears on: KeyValueConfig, NatsKeyValueSpec, NatsStreamSpec, StreamConfig.

FieldTypeRequiredDescription
sourcestringNoSource is the server’s src, the stored subjects republished.
destinationstringYesDestination is the server’s dest, the subject they are republished to.
headersOnlyboolNoHeadersOnly republishes headers without the payload.

RequestedMove #

RequestedMove is a stream an evacuation asked the server to move.
Appears on: NatsClusterEvacuationStatus.

FieldTypeRequiredDescription
accountstringYesAccount is the account’s public key.
streamstringYesStream is the stream’s server-side name.
timeTimeYesTime the move was last requested.

RetentionPolicy #

RetentionPolicy is a stream’s retention policy.
Type: string
Appears on: NatsStreamSpec, StreamConfig.

ValueDescription
Limits
Interest
WorkQueue

ServerLoad #

ServerLoad is one server’s share of leaders and replicas.
Appears on: NatsSystemBalancerStatus.

FieldTypeRequiredDescription
namestringYesName is the server’s server_name.
leadersint32NoLeaders is the number of Raft groups the server leads.
replicasint32NoReplicas is the number of replicas the server holds.

ServerStream #

ServerStream names a stream on the server.
Appears on: NatsClusterEvacuationStatus.

FieldTypeRequiredDescription
accountstringYesAccount is the account’s public key.
namestringYesName is the stream’s server-side name.

Skew #

Skew is the spread between the most and least loaded servers.
Appears on: NatsSystemBalancerStatus.

FieldTypeRequiredDescription
leadersint32NoLeaders is the spread of leader counts.
replicasint32NoReplicas is the spread of replica counts.

StorageType #

StorageType is a JetStream storage backend.
Type: string
Appears on: KeyValueConfig, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec, ObjectStoreConfig, StreamConfig.

ValueDescription
File
Memory

StoreCompression #

StoreCompression is a stream’s storage compression.
Type: string
Appears on: NatsStreamSpec, StreamConfig.

ValueDescription
None
S2

StreamConfig #

StreamConfig is nats.go’s jetstream.StreamConfig. An omitted field takes the server’s value, and the immutability rules compare a field only where both the old and the new spec set it.
Appears on: NatsStreamSpec.

FieldTypeRequiredDescription
namestringNoName is the server-side stream name, metadata.name when omitted.
descriptionstringNo
subjects[]stringNo
retentionRetentionPolicyNoRetention cannot change to or from WorkQueue.
maxConsumersint64No
maxMsgsint64No
maxBytesQuantityNo
discardDiscardPolicyNo
discardNewPerSubjectboolNo
maxAgeDurationNo
maxMsgsPerSubjectint64No
maxMsgSizeQuantityNo
storageStorageTypeNoStorage is immutable.
replicasint32No
noAckboolNo
duplicatesDurationNo
placementPlacementNoPlacement pins the stream; changing placement.cluster moves it to that NATS cluster.
mirrorStreamSourceNoMirror cannot change once set; omitting it leaves the server’s mirror in place.
sources[]StreamSourceNo
sealedboolNoSealed cannot be unset.
denyDeleteboolNoDenyDelete cannot be unset.
denyPurgeboolNoDenyPurge cannot be unset.
allowRollupboolNo
compressionStoreCompressionNo
firstSeqint64No
subjectTransformSubjectTransformNo
republishRepublishNo
allowDirectboolNo
mirrorDirectboolNo
consumerLimitsStreamConsumerLimitsNo
metadatamap[string]stringNoMetadata is merged with the ownership marker, which the controller owns.
allowMsgTTLboolNoAllowMsgTTL cannot be unset.
subjectDeleteMarkerTTLDurationNo
allowMsgCounterboolNoAllowMsgCounter is immutable.
allowAtomicPublishboolNo
allowMsgSchedulesboolNoAllowMsgSchedules cannot be unset.
persistModePersistModeNoPersistMode is immutable.
allowBatchPublishboolNo

StreamConsumerLimits #

StreamConsumerLimits are defaults for the stream’s consumers.
Appears on: NatsStreamSpec, StreamConfig.

FieldTypeRequiredDescription
inactiveThresholdDurationNo
maxAckPendingint64No

StreamConsumerSource #

StreamConsumerSource is a durable consumer used for sourcing.
Appears on: StreamSource.

FieldTypeRequiredDescription
namestringNoName is the server’s consumer name.
deliverSubjectstringNoDeliverSubject is the server’s deliver_subject.

StreamServerStatus #

StreamServerStatus is a stream’s state as the server reports it.
Appears on: NatsKeyValueStatus, NatsObjectStoreStatus, NatsStreamStatus.

FieldTypeRequiredDescription
createdTimeNoCreated is when the stream was created on the server.
leaderstringNoLeader is the server leading the stream’s group.
replicas[]ReplicaStatusNoReplicas are the followers.
messagesint64NoMessages is the number of messages stored.
bytesQuantityNoBytes is the size of the messages stored.

StreamSource #

StreamSource is a stream a mirror or source copies from.
Appears on: KeyValueConfig, NatsKeyValueSpec, NatsStreamSpec, StreamConfig.

FieldTypeRequiredDescription
namestringYesName is the origin stream’s server-side name.
optStartSeqint64NoOptStartSeq is the origin sequence to start at.
optStartTimeTimeNoOptStartTime is the origin time to start at.
filterSubjectstringNoFilterSubject filters the origin’s messages.
subjectTransforms[]SubjectTransformNoSubjectTransforms filter and transform the origin’s subjects.
externalExternalStreamNoExternal qualifies an origin in another account or domain.
consumerStreamConsumerSourceNoConsumer is a durable consumer on the origin used for sourcing.

StreamTransfer #

StreamTransfer is a stream’s move between NATS clusters.
Appears on: NatsStreamStatus.

FieldTypeRequiredDescription
fromstringNoFrom is the NATS cluster the stream leaves.
tostringNoTo is the NATS cluster the stream moves to.
startedTimeNoStarted is when the move began.
replicas[]ReplicaStatusNoReplicas are the new replicas.
consumersTransferConsumersNoConsumers is how many of the stream’s consumers have moved.

SubjectTransform #

SubjectTransform maps a source subject to a destination subject.
Appears on: NatsStreamSpec, StreamConfig, StreamSource.

FieldTypeRequiredDescription
sourcestringNoSource is the server’s src, the subjects transformed.
destinationstringYesDestination is the server’s dest, the subject they become.

SyncStatus #

SyncStatus is the status every JetStream object resource reports.
Appears on: NatsConsumerStatus, NatsKeyValueStatus, NatsObjectStoreStatus, NatsStreamStatus.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the status describes.
conditions[]ConditionNoConditions: Ready, Synced, Terminal, Adopted.
lastSyncedTimeTimeNoLastSyncedTime is when the server object was last compared to spec.
nextCheckTimeTimeNoNextCheckTime is when a Terminal condition under the Retry policy is next rechecked.
ownershipOwnershipNoOwnership is the ownership marker on the server object.

TerminalPolicy #

TerminalPolicy is what a Terminal condition waits for.
Type: string
Appears on: NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsStreamSpec, Policies.

ValueDescription
HoldTerminalHold waits for an edit to the resource.
RetryTerminalRetry rechecks every resync period.

TransferConsumers #

TransferConsumers counts the consumers moved with a stream.
Appears on: StreamTransfer.

FieldTypeRequiredDescription
movedint32NoMoved counts the stream’s consumers led from the target NATS cluster with no move left in flight.
totalint32NoTotal counts every consumer of the stream.

nats.mikluko.io/v1beta1 #

The nats.mikluko.io API group: the kinds more than one controller reads, which are connections, trust copies and reference grants.

KindDescription
NatsAccountTrustNatsAccountTrust is an account a leaf binds a remote to.
NatsConnectionNatsConnection is an address and an identity on a NATS cluster, managed or not; the only way the JetStream controller reaches one.
NatsOperatorTrustNatsOperatorTrust is the trust roots a NatsCluster boots from: the NATS operator JWT and system account JWT.
NatsReferenceGrantNatsReferenceGrant admits references into its own namespace from the namespaces it lists. Admitting a NatsCluster to a NatsConnection hands that connection’s credentials to the NatsCluster’s namespace.

CA #

CA is where a CA bundle is read from.
Appears on: ConnectionTLS.

FieldTypeRequiredDescription
secretKeyRefCASecretKeySelectorYesSecretKeyRef selects the CA bundle.

CASecretKeySelector #

CASecretKeySelector selects a PEM CA bundle from a Secret in the referrer’s namespace.
Appears on: CA.

FieldTypeRequiredDescription
namestringYesName of a Secret in the referrer’s namespace.
keystringNoKey within the Secret. Default: ca.crt.

ConnectionTLS #

ConnectionTLS is the client side of TLS toward NATS servers.
Appears on: NatsConnectionSpec.

FieldTypeRequiredDescription
caCANoCA verifies the servers’ certificates.

Credentials #

Credentials is where a NATS creds file is read from or written to.
Appears on: Auth, NatsConnectionSpec, NatsUserSpec.

FieldTypeRequiredDescription
secretKeyRefCredentialsSecretKeySelectorYesSecretKeyRef selects the creds file.

CredentialsSecretKeySelector #

CredentialsSecretKeySelector selects a NATS creds file from a Secret in the referrer’s namespace.
Appears on: Credentials.

FieldTypeRequiredDescription
namestringYesName of a Secret in the referrer’s namespace.
keystringNoKey within the Secret. Default: user.creds.

NatsAccountTrust #

NatsAccountTrust is an account a leaf binds a remote to.

FieldTypeRequiredDescription
apiVersionstringYesnats.mikluko.io/v1beta1
kindstringYesNatsAccountTrust
metadataObjectMetaYes
specNatsAccountTrustSpecYes
statusNatsAccountTrustStatusNo

NatsAccountTrustSpec #

NatsAccountTrustSpec names an account either by reference to a live NatsAccount or by its literal public key.
Appears on: NatsAccountTrust.

FieldTypeRequiredDescription
accountRefObjectReferenceNoAccountRef names a NatsAccount in this Kubernetes cluster; the auth controller then writes its public key and JWT into this object’s status.
publicKeystringNoPublicKey is the account’s public key.
jwtstringNoJWT is the account JWT a leaf preloads.

NatsAccountTrustStatus #

NatsAccountTrustStatus is the observed state of a NatsAccountTrust.
Appears on: NatsAccountTrust.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the conditions describe.
conditions[]ConditionNoConditions describe the trust object’s state.
publicKeystringNoPublicKey is the referenced account’s public key, written by the auth controller in the reference form.
jwtstringNoJWT is the referenced account’s JWT, written by the auth controller in the reference form.

NatsConnection #

NatsConnection is an address and an identity on a NATS cluster, managed or not; the only way the JetStream controller reaches one.

FieldTypeRequiredDescription
apiVersionstringYesnats.mikluko.io/v1beta1
kindstringYesNatsConnection
metadataObjectMetaYes
specNatsConnectionSpecYes
statusNatsConnectionStatusNo

NatsConnectionSpec #

NatsConnectionSpec is how a NATS cluster is reached and whom as.
Appears on: NatsConnection.

FieldTypeRequiredDescription
servers[]stringYesServers are the NATS URLs to dial.
tlsConnectionTLSNoTLS configures the client side of TLS toward the servers.
credentialsCredentialsNoCredentials decide the account the connection lands in; without them it lands wherever the server puts an unauthenticated client.

NatsConnectionStatus #

NatsConnectionStatus is the observed state of a NatsConnection.
Appears on: NatsConnection.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the conditions describe.
conditions[]ConditionNoConditions describe the connection’s state.

NatsOperatorTrust #

NatsOperatorTrust is the trust roots a NatsCluster boots from: the NATS operator JWT and system account JWT.

FieldTypeRequiredDescription
apiVersionstringYesnats.mikluko.io/v1beta1
kindstringYesNatsOperatorTrust
metadataObjectMetaYes
specNatsOperatorTrustSpecYes
statusNatsOperatorTrustStatusNo

NatsOperatorTrustSpec #

NatsOperatorTrustSpec holds trust roots either by reference to a live NatsOperator or as literal JWTs.
Appears on: NatsOperatorTrust.

FieldTypeRequiredDescription
operatorRefObjectReferenceNoOperatorRef names a NatsOperator in this Kubernetes cluster; the auth controller then writes its JWTs into this object’s status.
operatorJWTstringNoOperatorJWT is the NATS operator JWT.
systemAccountJWTstringNoSystemAccountJWT is the system account JWT.

NatsOperatorTrustStatus #

NatsOperatorTrustStatus is the observed state of a NatsOperatorTrust.
Appears on: NatsOperatorTrust.

FieldTypeRequiredDescription
observedGenerationint64NoObservedGeneration is the generation the conditions describe.
conditions[]ConditionNoConditions describe the trust object’s state.
operatorJWTstringNoOperatorJWT is the referenced NATS operator’s JWT, written by the auth controller in the reference form.
systemAccountJWTstringNoSystemAccountJWT is the referenced NATS operator’s system account JWT, written by the auth controller in the reference form.

NatsReferenceGrant #

NatsReferenceGrant admits references into its own namespace from the namespaces it lists. Admitting a NatsCluster to a NatsConnection hands that connection’s credentials to the NatsCluster’s namespace.

FieldTypeRequiredDescription
apiVersionstringYesnats.mikluko.io/v1beta1
kindstringYesNatsReferenceGrant
metadataObjectMetaYes
specNatsReferenceGrantSpecYes

NatsReferenceGrantSpec #

NatsReferenceGrantSpec lists who may reference what in the grant’s namespace.
Appears on: NatsReferenceGrant.

FieldTypeRequiredDescription
from[]ReferenceGrantFromYesFrom are the referrers admitted.
to[]ReferenceGrantToYesTo are the objects in this namespace they may reference.

ObjectReference #

ObjectReference names an object whose kind the referring field fixes.
Appears on: AccountReference, Auth, LeafRemote, NatsAccountSpec, NatsAccountTrustSpec, NatsBalancerSpec, NatsClusterEvacuationSpec, NatsConsumerSpec, NatsKeyValueSpec, NatsObjectStoreSpec, NatsOperatorSpec, NatsOperatorTrustSpec, NatsStreamSpec, NatsSystemAccountSpec, NatsSystemBalancerSpec.

FieldTypeRequiredDescription
namestringYesName of the referenced object.
namespacestringNoNamespace of the referenced object, the referrer’s own when omitted. Another namespace is admitted only by a NatsReferenceGrant there.

ReferenceGrantFrom #

ReferenceGrantFrom names a kind of referrer in one namespace.
Appears on: NatsReferenceGrantSpec.

FieldTypeRequiredDescription
groupstringYesGroup is the referrer’s API group, matched exactly, such as cluster.nats.mikluko.io.
kindstringYesKind is the referrer’s kind, matched exactly, such as NatsCluster.
namespacestringYesNamespace the referrers live in, matched exactly.

ReferenceGrantTo #

ReferenceGrantTo names a kind of object in the grant’s namespace.
Appears on: NatsReferenceGrantSpec.

FieldTypeRequiredDescription
groupstringYesGroup is the referenced object’s API group, matched exactly, such as nats.mikluko.io.
kindstringYesKind is the referenced object’s kind, matched exactly, such as NatsConnection.
namestringNoName of the referenced object; omitted, every object of the kind.

SecretReference #

SecretReference names a Secret in the referrer’s namespace.
Appears on: CertificateSource, ListenerTLS, RoutesTLS.

FieldTypeRequiredDescription
namestringYesName of a Secret in the referrer’s namespace.