Skip to content

GET Configuration Specification.

GET
/api/config/namespaces/{namespace}/k8s_pod_security_policys/{name}
curl --request GET \
--url 'https://example-corp.console.ves.volterra.io/api/v1/api/production/us-east-1/namespaces/default/api/config/namespaces/example/k8s_pod_security_policys/example?response_format=GET_RSP_FORMAT_DEFAULT' \
--header 'Authorization: <Authorization>'

GET k8s_pod_security_policy will GET the object from the storage backend for namespace metadata.namespace.

Examples of this operation.

namespace
required
string

Namespace The namespace in which the configuration object is present.

name
required
string

Name The name of the configuration object to be fetched.

response_format
string
default: GET_RSP_FORMAT_DEFAULT
Allowed values: GET_RSP_FORMAT_DEFAULT GET_RSP_FORMAT_FOR_CREATE GET_RSP_FORMAT_FOR_REPLACE GET_RSP_FORMAT_STATUS GET_RSP_FORMAT_READ GET_RSP_FORMAT_REFERRING_OBJECTS GET_RSP_FORMAT_BROKEN_REFERENCES

The format in which the configuration object is to be fetched. This could be for example

  • in GetSpec form for the contents of object
  • in CreateRequest form to create a new similar object
  • to ReplaceRequest form to replace changeable values

Default format of returned resource Response should be in CreateRequest format Response should be in ReplaceRequest format Response should be in StatusObject(s) format Response should be in format of GetSpecType Response should have other objects referring to this object Response should have deleted and disabled objects referrred by this object.

A successful response.

Media typeapplication/json
GetResponse is the shape of a read k8s_pod_security_policy

This is the output message of the ‘GET’ RPC.

object
create_form
object
metadata
object
annotations
annotations

Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects.

object
description
description

Human readable description for the object.

string
>= 21 characters <= 1200 characters
disable
disable

A value of true will administratively disable the object.

boolean format: boolean
labels
labels

Map of string keys and values that can be used to organize and categorize (scope and select) objects as chosen by the user. Values specified here will be used by selector expression.

object
name
name

This is the name of configuration object. It has to be unique within the namespace. It can only be specified during create API and cannot be changed during replace API. The value of name has to follow DNS-1035 format. Required: YES.

string
>= 6 characters <= 1024 characters
namespace
namespace

This defines the workspace within which each the configuration object is to be created. Must be a DNS_LABEL format. For a namespace object itself, namespace value will be ""

string
>= 6 characters <= 1024 characters
spec
object
psp_spec
object
allow_privilege_escalation
Allow Privilege Escalation

Pod can request to privilege escalation.

boolean format: boolean
allowed_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
allowed_csi_drivers
Allowed CSI drivers

Restrict the available CSI drivers for POD, default all drivers are available.

Array<string>
<= 8 items
allowed_flex_volumes
Allowed Flex Volumes

Restrict list of Flex volumes, default all volumes are allowed.

Array<string>
<= 8 items
allowed_host_paths
Allowed Host Paths

Restrict list of host paths, default all host paths are allowed.

Array<object>
<= 8 items
Host Path

Host path and read/write or read-only.

object
path_prefix
Host Path Prefix

Host path prefix is the path prefix that the host volume must match. It does not support *. Required: YES.

string
>= 1 characters <= 128 characters
read_only
Read Only

This volume will be allowed to mount read only.

boolean format: boolean
allowed_proc_mounts
Allowed Proc Mounts

Allowed list of proc mounts, empty list allows default proc mounts.

Array<string>
<= 8 items
allowed_unsafe_sysctls
Allowed Unsafe Sysctls

Allowed list of unsafe sysctls, empty list allows none. Supports prefix reg-ex.

Array<string>
<= 16 items
default_allow_privilege_escalation
Default Allow Privilege Escalation

Pod has permission for privilege escalation by default.

boolean format: boolean
default_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
drop_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
forbidden_sysctls
Forbidden Sysctls

Forbidden list of sysctls, empty list forbids none. Supports prefix reg-ex.

Array<string>
<= 16 items
fs_group_strategy_options
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
host_ipc
Host IPC

Host IPC determines if the policy allows the use of host IPC in the pod spec.

boolean format: boolean
host_network
Host Network

Host Network determines if the policy allows the use of host network in the pod spec.

boolean format: boolean
host_pid
Host PID

Host PID determines if the policy allows the use of host PID in the pod spec.

boolean format: boolean
host_port_ranges
Host Port Ranges

Host port ranges determines which ports ranges are allowed to be exposed.

string
<= 1024 characters
no_allowed_capabilities
object
no_default_capabilities
object
no_drop_capabilities
object
no_fs_groups
object
no_run_as_group
object
no_run_as_user
object
no_runtime_class
object
no_se_linux_options
object
no_supplemental_groups
object
privileged
Privileged

Privileged determines if a pod can request to be run as privileged.

boolean format: boolean
read_only_root_filesystem
Read Only Root Filesystem

Containers can only run with read only root filesystem.

boolean format: boolean
run_as_group
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
run_as_user
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
supplemental_groups
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
volumes
Volumes

Allow List of volume plugins. Empty no volumes are allowed.

Array<string>
<= 8 items
yaml

Exclusive with [psp_spec] K8s YAML for Pod Security Policy.

string
<= 4096 characters
deleted_referred_objects
deleted_referred_objects

The set of deleted objects that are referred by this object.

Array<object>
ObjectRefType

This type establishes a ‘direct reference’ from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name for public API and Uid for private API This type of reference is called direct because the relation is explicit and concrete (as opposed to selector reference which builds a group based on labels of selectee objects)

object
kind
kind

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then kind will hold the referred object’s kind (e.g. “route”)

string
>= 12 characters <= 1024 characters
name
name

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name.

string
>= 6 characters <= 1024 characters
namespace
namespace

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace.

string
>= 6 characters <= 1024 characters
tenant
tenant

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant.

string
>= 6 characters <= 1024 characters
uid
uid

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then uid will hold the referred object’s(e.g. Route’s) uid.

string format: uuid
>= 36 characters <= 1024 characters
disabled_referred_objects
disabled_referred_objects

The set of deleted objects that are referred by this object.

Array<object>
ObjectRefType

This type establishes a ‘direct reference’ from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name for public API and Uid for private API This type of reference is called direct because the relation is explicit and concrete (as opposed to selector reference which builds a group based on labels of selectee objects)

object
kind
kind

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then kind will hold the referred object’s kind (e.g. “route”)

string
>= 12 characters <= 1024 characters
name
name

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name.

string
>= 6 characters <= 1024 characters
namespace
namespace

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace.

string
>= 6 characters <= 1024 characters
tenant
tenant

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant.

string
>= 6 characters <= 1024 characters
uid
uid

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then uid will hold the referred object’s(e.g. Route’s) uid.

string format: uuid
>= 36 characters <= 1024 characters
metadata
object
annotations
annotations

Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects.

object
description
description

Human readable description for the object.

string
>= 21 characters <= 1200 characters
disable
disable

A value of true will administratively disable the object.

boolean format: boolean
labels
labels

Map of string keys and values that can be used to organize and categorize (scope and select) objects as chosen by the user. Values specified here will be used by selector expression.

object
name
name

This is the name of configuration object. It has to be unique within the namespace. It can only be specified during create API and cannot be changed during replace API. The value of name has to follow DNS-1035 format. Required: YES.

string
>= 6 characters <= 1024 characters
namespace
namespace

This defines the workspace within which each the configuration object is to be created. Must be a DNS_LABEL format. For a namespace object itself, namespace value will be ""

string
>= 6 characters <= 1024 characters
referring_objects
referring_objects

The set of objects that are referring to this object in their spec.

Array<object>
ObjectRefType

This type establishes a ‘direct reference’ from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name for public API and Uid for private API This type of reference is called direct because the relation is explicit and concrete (as opposed to selector reference which builds a group based on labels of selectee objects)

object
kind
kind

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then kind will hold the referred object’s kind (e.g. “route”)

string
>= 12 characters <= 1024 characters
name
name

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name.

string
>= 6 characters <= 1024 characters
namespace
namespace

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace.

string
>= 6 characters <= 1024 characters
tenant
tenant

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant.

string
>= 6 characters <= 1024 characters
uid
uid

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then uid will hold the referred object’s(e.g. Route’s) uid.

string format: uuid
>= 36 characters <= 1024 characters
replace_form
object
metadata
object
annotations
annotations

Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects.

object
description
description

Human readable description for the object.

string
>= 21 characters <= 1200 characters
disable
disable

A value of true will administratively disable the object.

boolean format: boolean
labels
labels

Map of string keys and values that can be used to organize and categorize (scope and select) objects as chosen by the user. Values specified here will be used by selector expression.

object
name
name

This is the name of configuration object. It has to be unique within the namespace. It can only be specified during create API and cannot be changed during replace API. The value of name has to follow DNS-1035 format. Required: YES.

string
>= 6 characters <= 1024 characters
namespace
namespace

This defines the workspace within which each the configuration object is to be created. Must be a DNS_LABEL format. For a namespace object itself, namespace value will be ""

string
>= 6 characters <= 1024 characters
spec
object
psp_spec
object
allow_privilege_escalation
Allow Privilege Escalation

Pod can request to privilege escalation.

boolean format: boolean
allowed_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
allowed_csi_drivers
Allowed CSI drivers

Restrict the available CSI drivers for POD, default all drivers are available.

Array<string>
<= 8 items
allowed_flex_volumes
Allowed Flex Volumes

Restrict list of Flex volumes, default all volumes are allowed.

Array<string>
<= 8 items
allowed_host_paths
Allowed Host Paths

Restrict list of host paths, default all host paths are allowed.

Array<object>
<= 8 items
Host Path

Host path and read/write or read-only.

object
path_prefix
Host Path Prefix

Host path prefix is the path prefix that the host volume must match. It does not support *. Required: YES.

string
>= 1 characters <= 128 characters
read_only
Read Only

This volume will be allowed to mount read only.

boolean format: boolean
allowed_proc_mounts
Allowed Proc Mounts

Allowed list of proc mounts, empty list allows default proc mounts.

Array<string>
<= 8 items
allowed_unsafe_sysctls
Allowed Unsafe Sysctls

Allowed list of unsafe sysctls, empty list allows none. Supports prefix reg-ex.

Array<string>
<= 16 items
default_allow_privilege_escalation
Default Allow Privilege Escalation

Pod has permission for privilege escalation by default.

boolean format: boolean
default_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
drop_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
forbidden_sysctls
Forbidden Sysctls

Forbidden list of sysctls, empty list forbids none. Supports prefix reg-ex.

Array<string>
<= 16 items
fs_group_strategy_options
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
host_ipc
Host IPC

Host IPC determines if the policy allows the use of host IPC in the pod spec.

boolean format: boolean
host_network
Host Network

Host Network determines if the policy allows the use of host network in the pod spec.

boolean format: boolean
host_pid
Host PID

Host PID determines if the policy allows the use of host PID in the pod spec.

boolean format: boolean
host_port_ranges
Host Port Ranges

Host port ranges determines which ports ranges are allowed to be exposed.

string
<= 1024 characters
no_allowed_capabilities
object
no_default_capabilities
object
no_drop_capabilities
object
no_fs_groups
object
no_run_as_group
object
no_run_as_user
object
no_runtime_class
object
no_se_linux_options
object
no_supplemental_groups
object
privileged
Privileged

Privileged determines if a pod can request to be run as privileged.

boolean format: boolean
read_only_root_filesystem
Read Only Root Filesystem

Containers can only run with read only root filesystem.

boolean format: boolean
run_as_group
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
run_as_user
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
supplemental_groups
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
volumes
Volumes

Allow List of volume plugins. Empty no volumes are allowed.

Array<string>
<= 8 items
yaml

Exclusive with [psp_spec] K8s YAML for Pod Security Policy.

string
<= 4096 characters
spec
object
psp_spec
object
allow_privilege_escalation
Allow Privilege Escalation

Pod can request to privilege escalation.

boolean format: boolean
allowed_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
allowed_csi_drivers
Allowed CSI drivers

Restrict the available CSI drivers for POD, default all drivers are available.

Array<string>
<= 8 items
allowed_flex_volumes
Allowed Flex Volumes

Restrict list of Flex volumes, default all volumes are allowed.

Array<string>
<= 8 items
allowed_host_paths
Allowed Host Paths

Restrict list of host paths, default all host paths are allowed.

Array<object>
<= 8 items
Host Path

Host path and read/write or read-only.

object
path_prefix
Host Path Prefix

Host path prefix is the path prefix that the host volume must match. It does not support *. Required: YES.

string
>= 1 characters <= 128 characters
read_only
Read Only

This volume will be allowed to mount read only.

boolean format: boolean
allowed_proc_mounts
Allowed Proc Mounts

Allowed list of proc mounts, empty list allows default proc mounts.

Array<string>
<= 8 items
allowed_unsafe_sysctls
Allowed Unsafe Sysctls

Allowed list of unsafe sysctls, empty list allows none. Supports prefix reg-ex.

Array<string>
<= 16 items
default_allow_privilege_escalation
Default Allow Privilege Escalation

Pod has permission for privilege escalation by default.

boolean format: boolean
default_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
drop_capabilities
object
capabilities
Capability List

List of capabilities that docker container has. Required: YES.

Array<string>
>= 1 items <= 64 items
forbidden_sysctls
Forbidden Sysctls

Forbidden list of sysctls, empty list forbids none. Supports prefix reg-ex.

Array<string>
<= 16 items
fs_group_strategy_options
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
host_ipc
Host IPC

Host IPC determines if the policy allows the use of host IPC in the pod spec.

boolean format: boolean
host_network
Host Network

Host Network determines if the policy allows the use of host network in the pod spec.

boolean format: boolean
host_pid
Host PID

Host PID determines if the policy allows the use of host PID in the pod spec.

boolean format: boolean
host_port_ranges
Host Port Ranges

Host port ranges determines which ports ranges are allowed to be exposed.

string
<= 1024 characters
no_allowed_capabilities
object
no_default_capabilities
object
no_drop_capabilities
object
no_fs_groups
object
no_run_as_group
object
no_run_as_user
object
no_runtime_class
object
no_se_linux_options
object
no_supplemental_groups
object
privileged
Privileged

Privileged determines if a pod can request to be run as privileged.

boolean format: boolean
read_only_root_filesystem
Read Only Root Filesystem

Containers can only run with read only root filesystem.

boolean format: boolean
run_as_group
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
run_as_user
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
supplemental_groups
object
id_ranges
ID Ranges

List of range of ID(s)

Array<object>
<= 16 items
IDRangeType
object
max_id
Ending ID

Ending(maximum) ID for for ID range Required: YES.

integer format: int64
min_id
Starting ID

Starting(minimum) ID for for ID range Required: YES.

integer format: int64
rule
Rule

Rule indicated how the FS group ID range is used.

string
>= 1 characters <= 128 characters
volumes
Volumes

Allow List of volume plugins. Empty no volumes are allowed.

Array<string>
<= 8 items
yaml

Exclusive with [psp_spec] K8s YAML for Pod Security Policy.

string
<= 4096 characters
status
status

The status reported by different services for this configuration object.

Array<object>
>= 17 characters <= 17 characters
Status for K8s Pod Security Policy

Most recently observed status of object.

object
conditions
conditions

Conditions.

Array<object>
ConditionType

Conditions are used in the object status to describe the current state of the object, e.g. Ready, Succeeded, etc.

object
hostname
hostname

Hostname of the instance of the site that sent the status.

string
<= 1024 characters
last_update_time
last_update_time

Last time the condition was updated.

string format: date-time
<= 1024 characters
reason
reason

X-reason: “Insufficient memory in data plane” A human readable string explaining the reason for reaching this condition.

string
>= 27 characters <= 1024 characters
service_name
service name

Name of the service that sent the status.

string
<= 1024 characters
status
status

Status of the condition “Success” Validtion has succeded. Requested operation was successful. “Failed” Validation has failed. “Incomplete” Validation of configuration has failed due to missing configuration. “Installed” Validation has passed and configuration has been installed in data path or K8s “Down” Configuration is operationally down. E.g. Down interface “Disabled” Configuration is administratively disabled i.e. objectmetatype.disable = true. “NotApplicable” Configuration is not applicable e.g. Tenant service_policy_set(s) in system namespace are not applicable on REs.

string
>= 17 characters <= 1024 characters
type
type

Type of the condition “Validation” represents validation user given configuration object “Operational” represents operational status of a given configuration object.

string
<= 1024 characters
metadata
object
creation_timestamp
creation_timestamp

Creation_timestamp is when the status object was created. It is used to find/tie-break for latest status object from same origin.

string format: date-time
<= 1024 characters
creator_class
creator_class

Class of creator which created this StatusObject. This will be service’s DNS FQDN. This will be set by the system based on client certificate information.

string
<= 1024 characters
creator_id
creator_id

ID of creator which created this StatusObject. This will be a concrete identifier for service (e.g. Identifying the environment also). This will be set by the system based on client certificate information.

string
<= 1024 characters
publish
string
default: STATUS_DO_NOT_PUBLISH
Allowed values: STATUS_DO_NOT_PUBLISH STATUS_PUBLISH
status_id
status_id

Status_id is a field used by the generator to distinguish (if necessary) between two status objects for the same config object from the same site and same service and potentially same daemon(creator-ID)

string
<= 1024 characters
uid
uid

Uid is the unique in time and space value for a StatusObject.

string format: uuid
>= 36 characters <= 1024 characters
vtrp_id
vtrp_id

Origin of this status exchanged by VTRP.

string
<= 1024 characters
vtrp_stale
vtrp_stale

Indicate whether mars deems this object to be stale via graceful restart timer information.

boolean format: boolean
object_refs
object_refs

Object reference.

Array<object>
ObjectRefType

This type establishes a ‘direct reference’ from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name for public API and Uid for private API This type of reference is called direct because the relation is explicit and concrete (as opposed to selector reference which builds a group based on labels of selectee objects)

object
kind
kind

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then kind will hold the referred object’s kind (e.g. “route”)

string
>= 12 characters <= 1024 characters
name
name

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name.

string
>= 6 characters <= 1024 characters
namespace
namespace

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace.

string
>= 6 characters <= 1024 characters
tenant
tenant

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant.

string
>= 6 characters <= 1024 characters
uid
uid

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then uid will hold the referred object’s(e.g. Route’s) uid.

string format: uuid
>= 36 characters <= 1024 characters
system_metadata
object
creation_timestamp
creation_timestamp

CreationTimestamp is a timestamp representing the server time when this object was created. It is not guaranteed to be set in happens-before order across separate operations. Clients may not set this value. It is represented in RFC3339 form and is in UTC.

string format: date-time
<= 1024 characters
creator_class
creator_class

A value identifying the class of the user or service which created this configuration object.

string
<= 1024 characters
creator_id
creator_id

A value identifying the exact user or service that created this configuration object.

string
<= 1024 characters
deletion_timestamp
deletion_timestamp

DeletionTimestamp is RFC 3339 date and time at which this resource will be deleted. This field is set by the server when a graceful deletion is requested by the user, and is not directly settable by a client. The resource is expected to be deleted (no longer visible from resource lists, and not reachable by name) after the time in this field, once the finalizers list is empty. As long as the finalizers list contains items, deletion is blocked. Once the deletionTimestamp is set, this value may not be unset or be set further into the future, although it may be shortened or the resource may be deleted prior to this time. For example, a user may request that a pod is deleted in 30 seconds. The Kubelet will react by sending a graceful termination signal to the containers in the pod. After that 30 seconds, the Kubelet will send a hard termination signal (SIGKILL) to the container and after cleanup, remove the pod from the API. In the presence of network partitions, this object may still exist after this timestamp, until an administrator or automated process can determine the resource is fully terminated. If not set, graceful deletion of the object has not been requested.

Populated by the system when a graceful deletion is requested. Read-only.

string format: date-time
<= 1024 characters
finalizers
finalizers

Must be empty before the object is deleted from the registry. Each entry is an identifier for the responsible component that will remove the entry from the list. If the deletionTimestamp of the object is non-nil, entries in this list can only be removed.

Array<string>
initializers
object
pending
pending

Pending is a list of initializers that must execute in order before this object is initialized. When the last pending initializer is removed, and no failing result is set, the initializers struct will be set to nil and the object is considered as initialized and visible to all clients.

Array<object>
InitializerType

Initializer is information about an initializer that has not yet completed.

object
name
name

Name of the service that is responsible for initializing this object.

string
>= 6 characters <= 1024 characters
result
object
code
code

Suggested HTTP return code for this status, 0 if not set.

integer format: int32
reason
reason

A human-readable description of why this operation is in the “Failure” status. If this value is empty there is no information available.

string
>= 27 characters <= 1024 characters
status
status

Status of the operation. One of: “Success” or “Failure”.

string
>= 17 characters <= 1024 characters
labels
labels

Map of string keys and values that can be used to organize and categorize (scope and select) objects as chosen by the operator or software. Values here can be interpreted by software(backend or frontend) to enable certain behavior e.g. Things marked as soft-deleted(restorable).

object
modification_timestamp
modification_timestamp

ModificationTimestamp is a timestamp representing the server time when this object was last modified.

string format: date-time
<= 1024 characters
object_index
object_index

Unique index for the object. Some objects need a unique integer index to be allocated for each object type. This field will be populated for all objects that need it and will be zero otherwise.

integer format: int64
owner_view
object
kind
kind

Kind of the view object.

string
>= 12 characters <= 1024 characters
name
name

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name.

string
>= 6 characters <= 1024 characters
namespace
namespace

When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace.

string
>= 6 characters <= 1024 characters
uid
uid

UID of the view object.

string format: uuid
>= 36 characters <= 1024 characters
tenant
tenant

Tenant to which this configuration object belongs to. The value for this is found from presented credentials.

string
>= 6 characters <= 1024 characters
uid
uid

Uid is the unique in time and space value for this object. It is generated by the server on successful creation of an object and is not allowed to change on Replace API. The value of is taken from uid field of ObjectMetaType, if provided.

string format: uuid
>= 36 characters <= 1024 characters
Example
{
"status": [
{
"metadata": {
"publish": "STATUS_DO_NOT_PUBLISH"
}
}
]
}

Returned when operation is not authorized.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when there is no permission to access resource.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when resource is not found.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation on resource is conflicting with current value.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation has been rejected as it is happening too frequently.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server encountered an error in processing API.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when service is unavailable temporarily.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server timed out processing request.

Media typeapplication/json
string format: string
Examplegenerated
example