The Deckhouse Platform installs CRDs but does not remove them when a module is disabled. If you no longer need the created CRDs, delete them.

The module lifecycle stage: General Availability

The module has requirements for installation

IngressIstioController

Scope: Cluster
Version: v1alpha1

  • spec
    object

    Required value

    • spec.hostPort
      object

      HostPort inlet settings.

      • spec.hostPort.httpPort
        integer

        Port for insecure HTTP connections.

        If the parameter is not set, the connection over HTTP cannot be established.

        This parameter is mandatory if httpsPort is not set.

        Example:

        httpPort: 80
        
      • spec.hostPort.httpsPort
        integer

        Port for secure HTTPS connections.

        If the parameter is not set, the connection over HTTPS cannot be established.

        This parameter is mandatory if httpPort is not set.

        Example:

        httpsPort: 443
        
    • spec.ingressGatewayClass
      string

      Required value

      Ingress gateway class is used by application Gateway resources for identifying the right Ingress gateway setup.

      The identification is organized by setting the spec.selector: istio.deckhouse.io/ingress-gateway-class: <ingressGatewayClass value>.

      This parameter does not change during the entire resource life.

      Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$

      Maximum length: 63

      Example:

      ingressGatewayClass: istio
      
    • spec.inlet
      string

      Required value

      The way traffic goes to cluster from the outer network.

      • LoadBalancer — Ingress controller is deployed and the service of LoadBalancer type is provisioned.
      • NodePort — Ingress controller is deployed and available through nodes’ ports via nodePort.
      • HostPort — Ingress controller is deployed and available through nodes’ ports via hostPort.

        Caution. There can be only one controller with this inlet type on a host.

      Allowed values: LoadBalancer, HostPort, NodePort

    • spec.loadBalancer
      object

      Not required value.

      A section of parameters of the LoadBalancer inlet.

      • spec.loadBalancer.annotations
        object

        Annotations to assign to the service for flexible configuration of the load balancer.

      • spec.loadBalancer.loadBalancerClass
        string

        Class of the load balancer for incoming network requests (passed to the spec.loadBalancerClass parameter of the provisioned service with the LoadBalancer type).

    • spec.networkTopology
      object

      Configures how the gateway extracts the client’s original attributes (e.g. the source IP address) when it is deployed behind other proxies or load balancers.

      See Configuring Gateway Network Topology in the Istio documentation.

      • spec.networkTopology.numTrustedProxies
        integer

        Number of trusted proxies deployed in front of the Istio gateway proxy.

        It is used to correctly extract the client address from the X-Forwarded-For header and populate the X-Envoy-External-Address header consumed by upstream services.

        For example, if there is a cloud load balancer and a reverse proxy in front of the gateway, set this to 2.

        It can be used with proxyProtocol. When both are configured and an incoming request contains an X-Forwarded-For header, Istio uses the trusted X-Forwarded-For chain in preference to the PROXY protocol attributes.

        Allowed values: 0 <= X

        Example:

        numTrustedProxies: 2
        
      • spec.networkTopology.proxyProtocol
        boolean

        Enables the PROXY protocol on the gateway’s TCP listeners, so that client attributes (such as the source IP) forwarded by an upstream L4/TCP load balancer are preserved.

        It can be used with numTrustedProxies. When both are configured and an incoming request contains an X-Forwarded-For header, Istio uses the trusted X-Forwarded-For chain in preference to the PROXY protocol attributes.

        Example:

        proxyProtocol: true
        
    • spec.nodePort
      object

      NodePort inlet settings.

      • spec.nodePort.httpPort
        integer

        Port for insecure HTTP connections.

        If the parameter is not set, the connection over HTTP cannot be established.

        This parameter is mandatory if httpsPort is not set.

        Example:

        httpPort: 30080
        
      • spec.nodePort.httpsPort
        integer

        Port for secure HTTPS connections.

        If the parameter is not set, the connection over HTTPS cannot be established.

        This parameter is mandatory if httpPort is not set.

        Example:

        httpsPort: 30443
        
    • spec.nodeSelector
      object

      The same as in the pods’ spec.nodeSelector parameter in Kubernetes.

      If the parameter is omitted or false, it will be determined automatically.

      Format: the standard nodeSelector list. Instance pods inherit this field as is.

    • spec.resourcesRequests
      object

      Settings for CPU and memory requests and limits by ingress gateway pods.

      If omitted, the built-in VPA mode defaults are used. In Static mode, requests are specified directly in static. In VPA mode, the VPA adjusts requests within the configured minimum and maximum bounds.

      • spec.resourcesRequests.mode
        string

        Required value

        Resource management mode:

        • Static — allows you to specify requests directly in the static section;
        • VPA — uses VPA. You can configure this mode by modifying parameters in the vpa section.

        Default: VPA

        Allowed values: VPA, Static

      • spec.resourcesRequests.static
        object

        Resource management options for the Static mode.

        • spec.resourcesRequests.static.cpu
          string

          Configuring CPU requests.

          Default: 100m

        • spec.resourcesRequests.static.memory
          string

          Configuring memory requests.

          Default: 128Mi

      • spec.resourcesRequests.vpa
        object

        Resource management options for the VPA mode.

        • spec.resourcesRequests.vpa.cpu
          object

          CPU-related VPA settings.

          • spec.resourcesRequests.vpa.cpu.max
            string

            The maximum value that the VPA can set for the CPU requests.

            Default: 1000m

          • spec.resourcesRequests.vpa.cpu.min
            string

            The minimum value that the VPA can set for the CPU requests.

            Default: 100m

        • spec.resourcesRequests.vpa.memory
          object

          Memory-related VPA settings.

          • spec.resourcesRequests.vpa.memory.max
            string

            The maximum memory requests the VPA can set.

            Default: 2000Mi

          • spec.resourcesRequests.vpa.memory.min
            string

            The minimum memory requests the VPA can set.

            Default: 128Mi

        • spec.resourcesRequests.vpa.mode
          string

          VPA operating mode.

          • Initial — VPA sets initial values for pod resource requests at pod creation time. Resource values are not changed automatically afterwards.

          • InPlaceOrRecreate — VPA attempts to update pod resources in place when supported by the cluster. If in-place updates are not possible, the pod is recreated.

          • Auto — VPA automatically recreates pods to apply updated resource values. This mode is considered legacy starting from Deckhouse version 1.75; InPlaceOrRecreate is recommended.

          Default: Initial

          Allowed values: Initial, InPlaceOrRecreate, Auto

    • spec.tolerations
      array of objects

      The same as in the pods’ spec.tolerations parameter in Kubernetes;

      If the parameter is omitted or false, it will be determined automatically.

      Format: the standard toleration list. Instance pods inherit this field as is.

      • spec.tolerations.effect
        string

        Allowed values: NoSchedule, PreferNoSchedule, NoExecute

      • spec.tolerations.key
        string
      • spec.tolerations.operator
        string

        Default: Equal

        Allowed values: Exists, Equal

      • spec.tolerations.tolerationSeconds
        integer
      • spec.tolerations.value
        string

IstioFederation

Scope: Cluster
Version: v1alpha1

Custom resource for setting remote cluster as trusted one.

  • spec
    object

    Required value

    Available in editions: Ultimate/EE

    • spec.metadata
      object
      • spec.metadata.ca
        string

        Available in editions: Ultimate/EE

        Certificate for validation HTTPS endpoint with remote cluster metadata.

        Example:

        ca: "-----BEGIN CERTIFICATE----- ..... -----END CERTIFICATE-----"
        
      • spec.metadata.insecureSkipVerify
        boolean

        Available in editions: Ultimate/EE

        Skip validation certificate on HTTPS endpoint with remote cluster metadata.

        Default: false

        Example:

        insecureSkipVerify: true
        
    • spec.metadataEndpoint
      string

      Required value

      Available in editions: Ultimate/EE

      HTTPS endpoint with remote cluster metadata.

      Example:

      metadataEndpoint: https://istio.k8s.example.com/metadata/
      
    • spec.trustDomain
      string

      Required value

      Available in editions: Ultimate/EE

      The TrustDomain of the remote cluster.

      A mandatory parameter, but it is not currently utilized, as Istio does not yet support mapping TrustDomain to a root Certificate Authority (CA).

      Pattern: ^[0-9a-zA-Z._-]+$

      Example:

      trustDomain: cluster.local
      
  • status
    object
    • status.conditions
      array of objects

      Readiness of metadata exchange with the remote cluster.

      • PublicMetadataExchangeReady — remote public.json is reachable and valid.
      • PrivateMetadataExchangeReady — remote private metadata is reachable and valid.
      • DataplaneConnectionReady — cross-cluster dataplane health probe to the remote alliance-healthcheck service succeeded.
      • status.conditions.lastProbeTime
        string

        Required value

      • status.conditions.lastTransitionTime
        string

        Required value

      • status.conditions.message
        string

        Required value

      • status.conditions.reason
        string

        Required value

      • status.conditions.status
        string

        Required value

        Allowed values: True, False, Unknown

      • status.conditions.type
        string

        Required value

    • status.metadataCache
      object
      • status.metadataCache.private
        object
        • status.metadataCache.private.ingressGateways
          array of objects
          • status.metadataCache.private.ingressGateways.address
            string
          • status.metadataCache.private.ingressGateways.port
            integer
        • status.metadataCache.private.publicServices
          array of objects
          • status.metadataCache.private.publicServices.hostname
            string
          • status.metadataCache.private.publicServices.ports
            array of objects
            • status.metadataCache.private.publicServices.ports.name
              string
            • status.metadataCache.private.publicServices.ports.port
              integer
            • status.metadataCache.private.publicServices.ports.protocol
              string
      • status.metadataCache.public
        object
        • status.metadataCache.public.authnKeyPub
          string
        • status.metadataCache.public.clusterUUID
          string
        • status.metadataCache.public.rootCA
          string

IstioMulticluster

Scope: Cluster
Version: v1alpha1

Custom resource for setting remote cluster as trusted one.

  • spec
    object

    Required value

    Available in editions: Ultimate/EE

    • spec.enableIngressGateway
      boolean

      Available in editions: Ultimate/EE

      Using IngressGateway for accessing remote Pods.

      If remote Pods are accessible directly from our cluster (flat network), it is efficient not to use extra hop.

      Default: true

    • spec.metadata
      object
      • spec.metadata.ca
        string

        Available in editions: Ultimate/EE

        HTTPS certificate authority for remote cluster metadata.

      • spec.metadata.insecureSkipVerify
        boolean

        Available in editions: Ultimate/EE

        HTTPS check or not for remote cluster metadata.

        Default: false

        Example:

        insecureSkipVerify: true
        
    • spec.metadataEndpoint
      string

      Required value

      Available in editions: Ultimate/EE

      HTTPS endpoint with remote cluster metadata.

      Example:

      metadataEndpoint: https://istio.k8s.example.com/metadata/
      
  • status
    object
    • status.conditions
      array of objects

      Readiness of metadata exchange with the remote cluster.

      • PublicMetadataExchangeReady — remote public.json is reachable and valid.
      • PrivateMetadataExchangeReady — remote private metadata is reachable and valid.
      • RemoteAPIServerReady — remote multicluster API host (apiHost) serves the authenticated /api endpoint.
      • DataplaneConnectionReady — cross-cluster dataplane health probe to the remote alliance-healthcheck service succeeded.
      • status.conditions.lastProbeTime
        string

        Required value

      • status.conditions.lastTransitionTime
        string

        Required value

      • status.conditions.message
        string

        Required value

      • status.conditions.reason
        string

        Required value

      • status.conditions.status
        string

        Required value

        Allowed values: True, False, Unknown

      • status.conditions.type
        string

        Required value

    • status.metadataCache
      object
      • status.metadataCache.private
        object
        • status.metadataCache.private.apiHost
          string
        • status.metadataCache.private.ca
          string
        • status.metadataCache.private.ingressGateways
          array of objects
          • status.metadataCache.private.ingressGateways.address
            string
          • status.metadataCache.private.ingressGateways.port
            integer
        • status.metadataCache.private.networkName
          string
      • status.metadataCache.public
        object
        • status.metadataCache.public.authnKeyPub
          string
        • status.metadataCache.public.clusterUUID
          string
        • status.metadataCache.public.rootCA
          string

WaypointInstance

Short names: wpi

Scope: Namespaced
Version: v1alpha1

  • metadata
    object
    • metadata.name
      string

      Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$

      Maximum length: 51

  • spec
    object
    • spec.allowedRoutes
      object

      Configuration for restricting which Routes can attach to the Gateway.

      • spec.allowedRoutes.namespaces
        object

        Configuration for restricting the namespaces of Routes that can attach to the Gateway.

        • spec.allowedRoutes.namespaces.from
          string

          Specifies which namespaces are allowed to attach Routes to this Gateway.

          Possible values:

          • All: Routes in all namespaces may be attached.
          • Selector: Only Routes in namespaces matching the selector may be attached.
          • Same: Only Routes in the same namespace as the Gateway may be attached.

          Default: Same

          Allowed values: All, Selector, Same

        • spec.allowedRoutes.namespaces.selector
          object

          Label selector for selecting namespaces.

          Required when from is Selector.

          • spec.allowedRoutes.namespaces.selector.matchExpressions
            array of objects

            A list of label selector requirements.

            • spec.allowedRoutes.namespaces.selector.matchExpressions.key
              string

              Required value

            • spec.allowedRoutes.namespaces.selector.matchExpressions.operator
              string

              Required value

              Allowed values: In, NotIn, Exists, DoesNotExist

            • spec.allowedRoutes.namespaces.selector.matchExpressions.values
              array of strings
          • spec.allowedRoutes.namespaces.selector.matchLabels
            object

            A map of {key,value} pairs.

            A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions with operator In and the values array containing only the value.

    • spec.nodeSelector
      object

      Node selector for waypoint proxy pods.

    • spec.replicasManagement
      object

      Replication management settings and scaling for the waypoint instance.

      • spec.replicasManagement.hpa
        object

        Options for replicas management for the HPA mode.

        • spec.replicasManagement.hpa.maxReplicas
          integer

          The upper limit for the number of replicas to which the HPA can scale up.

          Allowed values: 1 <= X

        • spec.replicasManagement.hpa.metrics
          array of objects

          The HPA will use these metrics to decide whether to increase or decrease the number of replicas.

          • spec.replicasManagement.hpa.metrics.targetAverageUtilization
            integer

            Required value

            The target value of the average resource metric across all relevant pods, represented as a percentage of the requested value.

            Allowed values: 1 <= X <= 100

          • spec.replicasManagement.hpa.metrics.type
            string

            Required value

            Metric type.

            Allowed values: CPU

        • spec.replicasManagement.hpa.minReplicas
          integer

          The lower limit for the number of replicas to which the HPA can scale down.

          Allowed values: 1 <= X

      • spec.replicasManagement.mode
        string

        Replicas management mode.

        Possible values:

        • Static: the mode where the number of replicas is specified explicitly.
        • HPA: the mode where the number of replicas is calculated automatically using HPA based on CPU usage.

        Default: Static

        Allowed values: Static, HPA

      • spec.replicasManagement.static
        object

        Options for replicas management for the Static mode.

        • spec.replicasManagement.static.replicas
          integer

          Desired number of replicas.

          Allowed values: 1 <= X

    • spec.resourcesManagement
      object

      CPU and memory request and limit settings for the waypoint Pods.

      • spec.resourcesManagement.mode
        string

        Resource management mode.

        Default: VPA

        Allowed values: VPA, Static

      • spec.resourcesManagement.static
        object

        Static mode settings.

        • spec.resourcesManagement.static.limits
          object

          Resource limits.

          • spec.resourcesManagement.static.limits.cpu
            string

            CPU limits.

          • spec.resourcesManagement.static.limits.memory
            string

            Memory limits.

        • spec.resourcesManagement.static.requests
          object

          Resource requests.

          • spec.resourcesManagement.static.requests.cpu
            string

            CPU requests.

            Default: 100m

          • spec.resourcesManagement.static.requests.memory
            string

            Memory requests.

            Default: 128Mi

      • spec.resourcesManagement.vpa
        object

        Resource management settings for the VPA mode.

        • spec.resourcesManagement.vpa.cpu
          object

          CPU-related VPA settings.

          • spec.resourcesManagement.vpa.cpu.limitRatio
            number

            The CPU limits/requests ratio.

            If set, the limits are calculated based on the requests and the specified ratio.

          • spec.resourcesManagement.vpa.cpu.max
            string

            Maximum value of allowed CPU requests to be submitted by the VPA.

            Default: 1000m

          • spec.resourcesManagement.vpa.cpu.min
            string

            Minimum value of allowed CPU requests to be submitted by the VPA.

            Default: 100m

        • spec.resourcesManagement.vpa.memory
          object

          Memory-related VPA settings.

          • spec.resourcesManagement.vpa.memory.limitRatio
            number

            The memory limits/requests ratio.

            If set, the limits are calculated based on the requests and the specified ratio.

          • spec.resourcesManagement.vpa.memory.max
            string

            Maximum value of allowed memory requests to be submitted by the VPA.

            Default: 2000Mi

          • spec.resourcesManagement.vpa.memory.min
            string

            Minimum value of allowed memory requests to be submitted by the VPA.

            Default: 128Mi

        • spec.resourcesManagement.vpa.mode
          string

          VPA operating mode.

          Default: InPlaceOrRecreate

          Allowed values: Initial, InPlaceOrRecreate

    • spec.tolerations
      array of objects

      Tolerations for waypoint proxy pods.

      • spec.tolerations.effect
        string

        Allowed values: NoSchedule, PreferNoSchedule, NoExecute

      • spec.tolerations.key
        string
      • spec.tolerations.operator
        string

        Default: Equal

        Allowed values: Exists, Equal

      • spec.tolerations.tolerationSeconds
        integer
      • spec.tolerations.value
        string
    • spec.waypointFor
      string

      Controls the istio.io/waypoint-for label on all managed resources.

      Default: All

      Allowed values: All, Service, Workload

  • status
    object
    • status.observedGeneration
      integer

      Allowed values: 0 <= X

    • status.synced
      boolean

      True when desired and actual resources are in sync.