The Deckhouse Platform installs CRDs but does not remove them when a module is disabled. If you no longer need the created CRDs, delete them.
The module lifecycle stage: General Availability
The module has requirements for installation
IngressIstioController
Scope: Cluster
Version: v1alpha1
- objectspec
Required value
- objectspec.hostPort
HostPortinlet settings.- integerspec.hostPort.httpPort
Port for insecure HTTP connections.
If the parameter is not set, the connection over HTTP cannot be established.
This parameter is mandatory if
httpsPortis not set.Example:
httpPort: 80 - integerspec.hostPort.httpsPort
Port for secure HTTPS connections.
If the parameter is not set, the connection over HTTPS cannot be established.
This parameter is mandatory if
httpPortis not set.Example:
httpsPort: 443
- stringspec.ingressGatewayClass
Required value
Ingress gateway class is used by application Gateway resources for identifying the right Ingress gateway setup.
The identification is organized by setting the spec.selector:
istio.deckhouse.io/ingress-gateway-class: <ingressGatewayClass value>.This parameter does not change during the entire resource life.
Pattern:
^[a-z0-9]([-a-z0-9]*[a-z0-9])?$Maximum length:
63Example:
ingressGatewayClass: istio - stringspec.inlet
Required value
The way traffic goes to cluster from the outer network.
LoadBalancer— Ingress controller is deployed and the service ofLoadBalancertype is provisioned.NodePort— Ingress controller is deployed and available through nodes’ ports vianodePort.-
HostPort— Ingress controller is deployed and available through nodes’ ports viahostPort.Caution. There can be only one controller with this inlet type on a host.
Allowed values:
LoadBalancer,HostPort,NodePort - objectspec.loadBalancer
Not required value.
A section of parameters of the
LoadBalancerinlet.- objectspec.loadBalancer.annotations
Annotations to assign to the service for flexible configuration of the load balancer.
- stringspec.loadBalancer.loadBalancerClass
Class of the load balancer for incoming network requests (passed to the
spec.loadBalancerClassparameter of the provisioned service with theLoadBalancertype).
- objectspec.networkTopology
Configures how the gateway extracts the client’s original attributes (e.g. the source IP address) when it is deployed behind other proxies or load balancers.
See Configuring Gateway Network Topology in the Istio documentation.
- integerspec.networkTopology.numTrustedProxies
Number of trusted proxies deployed in front of the Istio gateway proxy.
It is used to correctly extract the client address from the
X-Forwarded-Forheader and populate theX-Envoy-External-Addressheader consumed by upstream services.For example, if there is a cloud load balancer and a reverse proxy in front of the gateway, set this to
2.It can be used with
proxyProtocol. When both are configured and an incoming request contains anX-Forwarded-Forheader, Istio uses the trustedX-Forwarded-Forchain in preference to the PROXY protocol attributes.Allowed values:
0 <= XExample:
numTrustedProxies: 2 - booleanspec.networkTopology.proxyProtocol
Enables the PROXY protocol on the gateway’s TCP listeners, so that client attributes (such as the source IP) forwarded by an upstream L4/TCP load balancer are preserved.
It can be used with
numTrustedProxies. When both are configured and an incoming request contains anX-Forwarded-Forheader, Istio uses the trustedX-Forwarded-Forchain in preference to the PROXY protocol attributes.Example:
proxyProtocol: true
- objectspec.nodePort
NodePortinlet settings.- integerspec.nodePort.httpPort
Port for insecure HTTP connections.
If the parameter is not set, the connection over HTTP cannot be established.
This parameter is mandatory if
httpsPortis not set.Example:
httpPort: 30080 - integerspec.nodePort.httpsPort
Port for secure HTTPS connections.
If the parameter is not set, the connection over HTTPS cannot be established.
This parameter is mandatory if
httpPortis not set.Example:
httpsPort: 30443
- objectspec.nodeSelector
The same as in the pods’
spec.nodeSelectorparameter in Kubernetes.If the parameter is omitted or
false, it will be determined automatically.Format: the standard
nodeSelectorlist. Instance pods inherit this field as is. - objectspec.resourcesRequests
Settings for CPU and memory requests and limits by ingress gateway pods.
If omitted, the built-in VPA mode defaults are used. In
Staticmode, requests are specified directly instatic. InVPAmode, the VPA adjusts requests within the configured minimum and maximum bounds.- stringspec.resourcesRequests.mode
Required value
Resource management mode:
Static— allows you to specify requests directly in thestaticsection;VPA— uses VPA. You can configure this mode by modifying parameters in thevpasection.
Default:
VPAAllowed values:
VPA,Static - objectspec.resourcesRequests.static
Resource management options for the
Staticmode.- stringspec.resourcesRequests.static.cpu
Configuring CPU requests.
Default:
100m - stringspec.resourcesRequests.static.memory
Configuring memory requests.
Default:
128Mi
- objectspec.resourcesRequests.vpa
Resource management options for the
VPAmode.- objectspec.resourcesRequests.vpa.cpu
CPU-related VPA settings.
- stringspec.resourcesRequests.vpa.cpu.max
The maximum value that the VPA can set for the CPU requests.
Default:
1000m - stringspec.resourcesRequests.vpa.cpu.min
The minimum value that the VPA can set for the CPU requests.
Default:
100m
- objectspec.resourcesRequests.vpa.memory
Memory-related VPA settings.
- stringspec.resourcesRequests.vpa.memory.max
The maximum memory requests the VPA can set.
Default:
2000Mi - stringspec.resourcesRequests.vpa.memory.min
The minimum memory requests the VPA can set.
Default:
128Mi
- stringspec.resourcesRequests.vpa.mode
VPA operating mode.
-
Initial— VPA sets initial values for pod resource requests at pod creation time. Resource values are not changed automatically afterwards. -
InPlaceOrRecreate— VPA attempts to update pod resources in place when supported by the cluster. If in-place updates are not possible, the pod is recreated. -
Auto— VPA automatically recreates pods to apply updated resource values. This mode is considered legacy starting from Deckhouse version 1.75;InPlaceOrRecreateis recommended.
Default:
InitialAllowed values:
Initial,InPlaceOrRecreate,Auto -
- array of objectsspec.tolerations
The same as in the pods’
spec.tolerationsparameter in Kubernetes;If the parameter is omitted or
false, it will be determined automatically.Format: the standard toleration list. Instance pods inherit this field as is.
- stringspec.tolerations.effect
Allowed values:
NoSchedule,PreferNoSchedule,NoExecute - stringspec.tolerations.key
- stringspec.tolerations.operator
Default:
EqualAllowed values:
Exists,Equal - integerspec.tolerations.tolerationSeconds
- stringspec.tolerations.value
IstioFederation
Scope: Cluster
Version: v1alpha1
Custom resource for setting remote cluster as trusted one.
- objectspec
Required value
Available in editions: Ultimate/EE
- objectspec.metadata
- stringspec.metadata.ca
Available in editions: Ultimate/EE
Certificate for validation HTTPS endpoint with remote cluster metadata.
Example:
ca: "-----BEGIN CERTIFICATE----- ..... -----END CERTIFICATE-----" - booleanspec.metadata.insecureSkipVerify
Available in editions: Ultimate/EE
Skip validation certificate on HTTPS endpoint with remote cluster metadata.
Default:
falseExample:
insecureSkipVerify: true
- stringspec.metadataEndpoint
Required value
Available in editions: Ultimate/EE
HTTPS endpoint with remote cluster metadata.
Example:
metadataEndpoint: https://istio.k8s.example.com/metadata/ - stringspec.trustDomain
Required value
Available in editions: Ultimate/EE
The TrustDomain of the remote cluster.
A mandatory parameter, but it is not currently utilized, as Istio does not yet support mapping TrustDomain to a root Certificate Authority (CA).
Pattern:
^[0-9a-zA-Z._-]+$Example:
trustDomain: cluster.local
- objectstatus
- array of objectsstatus.conditions
Readiness of metadata exchange with the remote cluster.
PublicMetadataExchangeReady— remotepublic.jsonis reachable and valid.PrivateMetadataExchangeReady— remote private metadata is reachable and valid.DataplaneConnectionReady— cross-cluster dataplane health probe to the remotealliance-healthcheckservice succeeded.
- stringstatus.conditions.lastProbeTime
Required value
- stringstatus.conditions.lastTransitionTime
Required value
- stringstatus.conditions.message
Required value
- stringstatus.conditions.reason
Required value
- stringstatus.conditions.status
Required value
Allowed values:
True,False,Unknown - stringstatus.conditions.type
Required value
- objectstatus.metadataCache
- objectstatus.metadataCache.private
- array of objectsstatus.metadataCache.private.ingressGateways
- stringstatus.metadataCache.private.ingressGateways.address
- integerstatus.metadataCache.private.ingressGateways.port
- array of objectsstatus.metadataCache.private.publicServices
- stringstatus.metadataCache.private.publicServices.hostname
- array of objectsstatus.metadataCache.private.publicServices.ports
- stringstatus.metadataCache.private.publicServices.ports.name
- integerstatus.metadataCache.private.publicServices.ports.port
- stringstatus.metadataCache.private.publicServices.ports.protocol
- objectstatus.metadataCache.public
- stringstatus.metadataCache.public.authnKeyPub
- stringstatus.metadataCache.public.clusterUUID
- stringstatus.metadataCache.public.rootCA
IstioMulticluster
Scope: Cluster
Version: v1alpha1
Custom resource for setting remote cluster as trusted one.
- objectspec
Required value
Available in editions: Ultimate/EE
- booleanspec.enableIngressGateway
Available in editions: Ultimate/EE
Using IngressGateway for accessing remote Pods.
If remote Pods are accessible directly from our cluster (flat network), it is efficient not to use extra hop.
Default:
true - objectspec.metadata
- stringspec.metadata.ca
Available in editions: Ultimate/EE
HTTPS certificate authority for remote cluster metadata.
- booleanspec.metadata.insecureSkipVerify
Available in editions: Ultimate/EE
HTTPS check or not for remote cluster metadata.
Default:
falseExample:
insecureSkipVerify: true
- stringspec.metadataEndpoint
Required value
Available in editions: Ultimate/EE
HTTPS endpoint with remote cluster metadata.
Example:
metadataEndpoint: https://istio.k8s.example.com/metadata/
- objectstatus
- array of objectsstatus.conditions
Readiness of metadata exchange with the remote cluster.
PublicMetadataExchangeReady— remotepublic.jsonis reachable and valid.PrivateMetadataExchangeReady— remote private metadata is reachable and valid.RemoteAPIServerReady— remote multicluster API host (apiHost) serves the authenticated/apiendpoint.DataplaneConnectionReady— cross-cluster dataplane health probe to the remotealliance-healthcheckservice succeeded.
- stringstatus.conditions.lastProbeTime
Required value
- stringstatus.conditions.lastTransitionTime
Required value
- stringstatus.conditions.message
Required value
- stringstatus.conditions.reason
Required value
- stringstatus.conditions.status
Required value
Allowed values:
True,False,Unknown - stringstatus.conditions.type
Required value
- objectstatus.metadataCache
- objectstatus.metadataCache.private
- stringstatus.metadataCache.private.apiHost
- stringstatus.metadataCache.private.ca
- array of objectsstatus.metadataCache.private.ingressGateways
- stringstatus.metadataCache.private.ingressGateways.address
- integerstatus.metadataCache.private.ingressGateways.port
- stringstatus.metadataCache.private.networkName
- objectstatus.metadataCache.public
- stringstatus.metadataCache.public.authnKeyPub
- stringstatus.metadataCache.public.clusterUUID
- stringstatus.metadataCache.public.rootCA
WaypointInstance
Short names: wpi
Scope: Namespaced
Version: v1alpha1
- objectmetadata
- stringmetadata.name
Pattern:
^[a-z0-9]([-a-z0-9]*[a-z0-9])?$Maximum length:
51
- objectspec
- objectspec.allowedRoutes
Configuration for restricting which Routes can attach to the Gateway.
- objectspec.allowedRoutes.namespaces
Configuration for restricting the namespaces of Routes that can attach to the Gateway.
- stringspec.allowedRoutes.namespaces.from
Specifies which namespaces are allowed to attach Routes to this Gateway.
Possible values:
All: Routes in all namespaces may be attached.Selector: Only Routes in namespaces matching theselectormay be attached.Same: Only Routes in the same namespace as the Gateway may be attached.
Default:
SameAllowed values:
All,Selector,Same - objectspec.allowedRoutes.namespaces.selector
Label selector for selecting namespaces.
Required when
fromisSelector.- array of objectsspec.allowedRoutes.namespaces.selector.matchExpressions
A list of label selector requirements.
- stringspec.allowedRoutes.namespaces.selector.matchExpressions.key
Required value
- stringspec.allowedRoutes.namespaces.selector.matchExpressions.operator
Required value
Allowed values:
In,NotIn,Exists,DoesNotExist - array of stringsspec.allowedRoutes.namespaces.selector.matchExpressions.values
- objectspec.allowedRoutes.namespaces.selector.matchLabels
A map of {key,value} pairs.
A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions with operator
Inand the values array containing only the value.
- objectspec.nodeSelector
Node selector for waypoint proxy pods.
- objectspec.replicasManagement
Replication management settings and scaling for the waypoint instance.
- objectspec.replicasManagement.hpa
Options for replicas management for the
HPAmode.- integerspec.replicasManagement.hpa.maxReplicas
The upper limit for the number of replicas to which the HPA can scale up.
Allowed values:
1 <= X - array of objectsspec.replicasManagement.hpa.metrics
The HPA will use these metrics to decide whether to increase or decrease the number of replicas.
- integerspec.replicasManagement.hpa.metrics.targetAverageUtilization
Required value
The target value of the average resource metric across all relevant pods, represented as a percentage of the requested value.
Allowed values:
1 <= X <= 100 - stringspec.replicasManagement.hpa.metrics.type
Required value
Metric type.
Allowed values:
CPU
- integerspec.replicasManagement.hpa.minReplicas
The lower limit for the number of replicas to which the HPA can scale down.
Allowed values:
1 <= X
- stringspec.replicasManagement.mode
Replicas management mode.
Possible values:
Static: the mode where the number of replicas is specified explicitly.HPA: the mode where the number of replicas is calculated automatically using HPA based on CPU usage.
Default:
StaticAllowed values:
Static,HPA - objectspec.replicasManagement.static
Options for replicas management for the
Staticmode.- integerspec.replicasManagement.static.replicas
Desired number of replicas.
Allowed values:
1 <= X
- objectspec.resourcesManagement
CPU and memory request and limit settings for the waypoint Pods.
- stringspec.resourcesManagement.mode
Resource management mode.
Default:
VPAAllowed values:
VPA,Static - objectspec.resourcesManagement.static
Static mode settings.
- objectspec.resourcesManagement.static.limits
Resource limits.
- stringspec.resourcesManagement.static.limits.cpu
CPU limits.
- stringspec.resourcesManagement.static.limits.memory
Memory limits.
- objectspec.resourcesManagement.static.requests
Resource requests.
- stringspec.resourcesManagement.static.requests.cpu
CPU requests.
Default:
100m - stringspec.resourcesManagement.static.requests.memory
Memory requests.
Default:
128Mi
- objectspec.resourcesManagement.vpa
Resource management settings for the VPA mode.
- objectspec.resourcesManagement.vpa.cpu
CPU-related VPA settings.
- numberspec.resourcesManagement.vpa.cpu.limitRatio
The CPU limits/requests ratio.
If set, the limits are calculated based on the requests and the specified ratio.
- stringspec.resourcesManagement.vpa.cpu.max
Maximum value of allowed CPU requests to be submitted by the VPA.
Default:
1000m - stringspec.resourcesManagement.vpa.cpu.min
Minimum value of allowed CPU requests to be submitted by the VPA.
Default:
100m
- objectspec.resourcesManagement.vpa.memory
Memory-related VPA settings.
- numberspec.resourcesManagement.vpa.memory.limitRatio
The memory limits/requests ratio.
If set, the limits are calculated based on the requests and the specified ratio.
- stringspec.resourcesManagement.vpa.memory.max
Maximum value of allowed memory requests to be submitted by the VPA.
Default:
2000Mi - stringspec.resourcesManagement.vpa.memory.min
Minimum value of allowed memory requests to be submitted by the VPA.
Default:
128Mi
- stringspec.resourcesManagement.vpa.mode
VPA operating mode.
Default:
InPlaceOrRecreateAllowed values:
Initial,InPlaceOrRecreate
- array of objectsspec.tolerations
Tolerations for waypoint proxy pods.
- stringspec.tolerations.effect
Allowed values:
NoSchedule,PreferNoSchedule,NoExecute - stringspec.tolerations.key
- stringspec.tolerations.operator
Default:
EqualAllowed values:
Exists,Equal - integerspec.tolerations.tolerationSeconds
- stringspec.tolerations.value
- stringspec.waypointFor
Controls the
istio.io/waypoint-forlabel on all managed resources.Default:
AllAllowed values:
All,Service,Workload
- objectstatus
- integerstatus.observedGeneration
Allowed values:
0 <= X - booleanstatus.synced
True when desired and actual resources are in sync.