Application

Scope: Namespaced
Version: v1alpha1

Application represents a namespace-scoped application instance.

  • apiVersion
    string

    APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info in the Kubernetes documentation.

  • kind
    string

    Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info in the Kubernetes documentation.

  • metadata
    object
  • spec
    object

    Required value

    Defines the application configuration.

    • spec.packageName
      string

      Required value

      Name of the application package to install.

    • spec.packageRepositoryName
      string

      Name of the repository where the package is located. If not specified, the default repository is used.

    • spec.packageVersion
      string

      Required value

      Version of the application package to install.

    • spec.releaseChannel
      string

      Release channel for the application package.

    • spec.settings
      object

      Configuration settings for the application.

  • status
    object

    Application status.

    • status.conditions
      array of objects

      Conditions reflecting the latest observations of the application state.

      Condition describing one aspect of the current application state.

      • status.conditions.lastTransitionTime
        string

        Required value

        lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.

      • status.conditions.message
        string

        Required value

        message is a human readable message indicating details about the transition. This may be an empty string.

        Maximum length: 32768

      • status.conditions.observedGeneration
        integer

        observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.

        Allowed values: 0 <= X

      • status.conditions.reason
        string

        Required value

        reason contains a programmatic identifier indicating the reason for the condition’s last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.

        Pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$

        Length: 1..1024

      • status.conditions.status
        string

        Required value

        status of the condition, one of True, False, Unknown.

        Allowed values: True, False, Unknown

      • status.conditions.type
        string

        Required value

        type of condition in CamelCase or in foo.example.com/CamelCase.

        Pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$

        Maximum length: 316

    • status.currentVersion
      object

      Information about the currently installed version.

      • status.currentVersion.channel
        string

        Release channel from which the version was installed.

      • status.currentVersion.version
        string

        Semantic version of the installed application.

    • status.lastAppliedConfiguration
      object

      LastAppliedConfiguration is the effective settings (user configuration merged with config-schema defaults) that drove the most recent successful apply.

    • status.summary
      object

      Summary aggregates the high-level user-facing state, message and resolution hint for the application. The controller always populates it on reconcile — every application maps to exactly one lifecycle state — so it is the single source of truth for the UI; clients should not re-derive these values from the conditions. The pointer leaves it absent only before the first status computation.

      • status.summary.message
        string

        Message is a human-readable description of the current state.

      • status.summary.state
        string

        State is the high-level lifecycle state observed for the application. Always one of: Pending, Failed, Updating, Ready, Degraded, Suspended.

      • status.summary.tip
        string

        Tip is a human-readable instruction on how to resolve the current state. Empty when no action is required.

    • status.tracking
      object

      Nelm tracking.

ApplicationPackage

Scope: Cluster
Version: v1alpha1

ApplicationPackage represents information about available application package.

  • apiVersion
    string

    APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info in the Kubernetes documentation

  • kind
    string

    Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info in the Kubernetes documentation

  • metadata
    object
  • status
    object

    Application package status.

    • status.availableRepositories
      array of strings

      List of repository names where this application package is available.

    • status.usedBy
      array of objects

      Information about applications using this package.

      • status.usedBy.name
        string

        Name of the application instance.

      • status.usedBy.namespace
        string

        Namespace where the application is installed.

      • status.usedBy.version
        string

        Version of the package used by this application.

    • status.usedByCount
      integer

      Number of applications using this package.

ApplicationPackageVersion

Short names: apv

Scope: Cluster
Version: v1alpha1

ApplicationPackageVersion represents a version of an application package.

  • apiVersion
    string

    APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info in the Kubernetes documentation

  • kind
    string

    Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info in the Kubernetes documentation

  • metadata
    object
  • spec
    object

    Defines the application package version parameters.

    • spec.packageName
      string

      Name of the application package.

    • spec.packageRepositoryName
      string

      Name of the package repository containing the package.

    • spec.packageVersion
      string

      Version of the application package.

  • status
    object

    Application package version status.

    • status.conditions
      array of objects

      Conditions reflecting the latest observations of the package version state.

      Condition describing one aspect of the current package version state.

      • status.conditions.lastTransitionTime
        string

        Required value

        lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.

      • status.conditions.message
        string

        Required value

        message is a human readable message indicating details about the transition. This may be an empty string.

        Maximum length: 32768

      • status.conditions.observedGeneration
        integer

        observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.

        Allowed values: 0 <= X

      • status.conditions.reason
        string

        Required value

        reason contains a programmatic identifier indicating the reason for the condition’s last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.

        Pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$

        Length: 1..1024

      • status.conditions.status
        string

        Required value

        status of the condition, one of True, False, Unknown.

        Allowed values: True, False, Unknown

      • status.conditions.type
        string

        Required value

        type of condition in CamelCase or in foo.example.com/CamelCase.

        Pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$

        Maximum length: 316

    • status.packageMetadata
      object

      Metadata about the package such as description, requirements, etc.

      • status.packageMetadata.category
        string

        The category this package belongs to.

      • status.packageMetadata.changelog
        object

        Information about changes in this version.

        • status.packageMetadata.changelog.features
          array of strings

          List of new features in this version.

        • status.packageMetadata.changelog.fixes
          array of strings

          List of bug fixes in this version.

      • status.packageMetadata.description
        object

        Localized descriptions of the package.

        • status.packageMetadata.description.en
          string

          English description of the package.

        • status.packageMetadata.description.ru
          string

          Russian description of the package.

      • status.packageMetadata.licensing
        object

        Licensing information for different editions.

        • status.packageMetadata.licensing.editions
          object

          Licensing information for different package editions.

          • status.packageMetadata.licensing.editions.<KEY_NAME>
            object

            <KEY_NAME> — item (key) name.

            • status.packageMetadata.licensing.editions.<KEY_NAME>.available
              boolean

              Whether this edition is available for use.

      • status.packageMetadata.requirements
        object

        The system requirements for this package.

        • status.packageMetadata.requirements.deckhouse
          object

          Required Deckhouse Kubernetes Platform version.

          • status.packageMetadata.requirements.deckhouse.constraint
            string

            Semver constraint expression.

        • status.packageMetadata.requirements.kubernetes
          object

          Required Kubernetes version.

          • status.packageMetadata.requirements.kubernetes.constraint
            string

            Semver constraint expression.

        • status.packageMetadata.requirements.modules
          object

          Required modules, partitioned into mandatory, conditional, and anyOf dependencies.

          • status.packageMetadata.requirements.modules.anyOf
            array of objects

            AnyOf groups of alternative dependencies — at least one member of each group must be installed (and satisfy its constraint, if any) for the package to start. Groups are checker-only and add no edges to the dependency graph.

            PackageModuleGroup is a group of alternative module dependencies. At least one member must be installed (and satisfy its constraint, if any) for the package to start. The Name is required and surfaces in scheduler diagnostics; the Description is optional human-facing documentation.

            • status.packageMetadata.requirements.modules.anyOf.description
              string

              Human-readable description of the group’s purpose.

            • status.packageMetadata.requirements.modules.anyOf.modules
              array of objects

              Required value

              Alternative module dependencies in this group.

              PackageModuleDependency is a single named module dependency with an optional semver constraint. An empty constraint means “any version”.

              • status.packageMetadata.requirements.modules.anyOf.modules.constraint
                string

                Semver constraint expression.

              • status.packageMetadata.requirements.modules.anyOf.modules.name
                string

                Required value

                Module name.

            • status.packageMetadata.requirements.modules.anyOf.name
              string

              Required value

              Stable identifier used by the scheduler in diagnostics.

          • status.packageMetadata.requirements.modules.conditional
            array of objects

            Conditional dependencies — not required to be present, but if installed must satisfy the constraint for the package to function correctly. Replaces the legacy “!optional” suffix from the v1 requirements format.

            PackageModuleDependency is a single named module dependency with an optional semver constraint. An empty constraint means “any version”.

            • status.packageMetadata.requirements.modules.conditional.constraint
              string

              Semver constraint expression.

            • status.packageMetadata.requirements.modules.conditional.name
              string

              Required value

              Module name.

          • status.packageMetadata.requirements.modules.mandatory
            array of objects

            Mandatory dependencies — must be present (and satisfy the constraint, if any) for the package to start.

            PackageModuleDependency is a single named module dependency with an optional semver constraint. An empty constraint means “any version”.

            • status.packageMetadata.requirements.modules.mandatory.constraint
              string

              Semver constraint expression.

            • status.packageMetadata.requirements.modules.mandatory.name
              string

              Required value

              Module name.

          • status.packageMetadata.requirements.modules.noneOf
            array of objects

            NoneOf groups of forbidden dependencies — no member of any group may be installed for the package to start. A member with no constraint is forbidden at any version; a member with a constraint is forbidden only at versions matching that constraint. Groups are checker-only and add no edges to the dependency graph.

            PackageModuleGroup is a group of alternative module dependencies. At least one member must be installed (and satisfy its constraint, if any) for the package to start. The Name is required and surfaces in scheduler diagnostics; the Description is optional human-facing documentation.

            • status.packageMetadata.requirements.modules.noneOf.description
              string

              Human-readable description of the group’s purpose.

            • status.packageMetadata.requirements.modules.noneOf.modules
              array of objects

              Required value

              Alternative module dependencies in this group.

              PackageModuleDependency is a single named module dependency with an optional semver constraint. An empty constraint means “any version”.

              • status.packageMetadata.requirements.modules.noneOf.modules.constraint
                string

                Semver constraint expression.

              • status.packageMetadata.requirements.modules.noneOf.modules.name
                string

                Required value

                Module name.

            • status.packageMetadata.requirements.modules.noneOf.name
              string

              Required value

              Stable identifier used by the scheduler in diagnostics.

      • status.packageMetadata.stage
        string

        The development stage of the package (e.g., alpha, beta, stable).

      • status.packageMetadata.versionCompatibilityRules
        object

        Version compatibility rules for upgrades and downgrades.

        • status.packageMetadata.versionCompatibilityRules.downgrade
          object

          Compatibility rules for downgrading from this version.

          • status.packageMetadata.versionCompatibilityRules.downgrade.allowSkipMajor
            integer

            How many major versions can be skipped.

          • status.packageMetadata.versionCompatibilityRules.downgrade.allowSkipMinor
            integer

            How many minor versions can be skipped.

          • status.packageMetadata.versionCompatibilityRules.downgrade.allowSkipPatches
            integer

            How many patch versions can be skipped.

          • status.packageMetadata.versionCompatibilityRules.downgrade.from
            string

            Starting version range for compatibility.

          • status.packageMetadata.versionCompatibilityRules.downgrade.maxRollback
            integer

            Maximum number of versions that can be rolled back.

          • status.packageMetadata.versionCompatibilityRules.downgrade.to
            string

            Ending version range for compatibility.

        • status.packageMetadata.versionCompatibilityRules.upgrade
          object

          Compatibility rules for upgrading to this version.

          • status.packageMetadata.versionCompatibilityRules.upgrade.allowSkipMajor
            integer

            How many major versions can be skipped.

          • status.packageMetadata.versionCompatibilityRules.upgrade.allowSkipMinor
            integer

            How many minor versions can be skipped.

          • status.packageMetadata.versionCompatibilityRules.upgrade.allowSkipPatches
            integer

            How many patch versions can be skipped.

          • status.packageMetadata.versionCompatibilityRules.upgrade.from
            string

            Starting version range for compatibility.

          • status.packageMetadata.versionCompatibilityRules.upgrade.maxRollback
            integer

            Maximum number of versions that can be rolled back.

          • status.packageMetadata.versionCompatibilityRules.upgrade.to
            string

            Ending version range for compatibility.

    • status.packageSchemas
      object

      Schemas for validating settings and values passed to the package.

      • status.packageSchemas.settingsSchema
        object

        SettingsSchema is the OpenAPI v3 schema used to validate the user-supplied settings of the package. Stored as an opaque object because its contents form a recursive JSON schema that cannot be expressed structurally in a CRD; the controller validates this subtree in Go when loading package metadata.

      • status.packageSchemas.valuesSchema
        object

        ValuesSchema is the OpenAPI v3 schema used to validate the effective values (defaults merged with settings) passed to the package’s hooks and charts. Stored as an opaque object because its contents form a recursive JSON schema that cannot be expressed structurally in a CRD; the controller validates this subtree in Go when loading package metadata.

    • status.usedBy
      array of objects

      Information about applications that are using this package version.

      • status.usedBy.name
        string

        Name of the application instance.

      • status.usedBy.namespace
        string

        Namespace where the application is installed.

    • status.usedByCount
      integer

      Number of applications using this package version.

ClusterConfiguration

Version: deckhouse.io/v1

General parameters of a cluster.

Defines, for example, network and CRI parameters, control plane version, etc. Some parameters can be changed after the cluster is bootstrapped, during its operation.

To change the ClusterConfiguration resource in a running cluster, run the following command:

d8 system edit cluster-configuration

Example:

apiVersion: deckhouse.io/v1
kind: ClusterConfiguration
podSubnetNodeCIDRPrefix: '24'
podSubnetCIDR: 10.244.0.0/16
serviceSubnetCIDR: 192.168.0.0/16
kubernetesVersion: '1.31'
clusterDomain: k8s.internal
clusterType: Cloud
cloud:
  prefix: k8s-dev
  provider: Yandex
proxy:
  httpProxy: https://user:password@proxy.company.my:8443
  httpsProxy: https://user:password@proxy.company.my:8443
  noProxy:
  - company.my
  • apiVersion
    string

    Required value

    Version of the Deckhouse API.

    Allowed values: deckhouse.io/v1, deckhouse.io/v1alpha1

  • cloud
    object

    Cloud provider-related settings (if the Cloud clusterType is used).

    • cloud.prefix
      string

      A prefix of the objects to be created in the cloud.

      Is used, for example, to distinguish objects created for different clusters, to configure routing, etc.

      Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$

    • cloud.provider
      string

      Required value

      Cloud provider.

      Allowed values: OpenStack, AWS, GCP, Yandex, vSphere, Azure, VCD, Zvirt, Dynamix, Huaweicloud, DVP

  • clusterDomain
    string

    Required value

    Cluster domain (used for local routing).

    Please note: the domain must not match the domain used in the DNS name template in the publicDomainTemplate parameter. For example, you cannot set cluster Domain: cluster.local and publicDomainTemplate: %s.cluster.local at the same time.

    If you need to change a parameter in a running cluster, it is recommended to use instructions

    Default: cluster.local

  • clusterType
    string

    Required value

    Type of the cluster infrastructure:

    • Static — a cluster on bare metal (physical servers) or virtual machines. In the case of virtual machines, it is assumed that Deckhouse doesn’t have access to the API for managing virtual machines (they are managed by the administrator using the usual cloud infrastructure tools);
    • Cloud — a cluster deployed on the resources of a cloud infrastructure. This type implies that Deckhouse has access to the cloud infrastructure API for managing virtual machines.

    Allowed values: Cloud, Static

  • defaultCRI
    string

    The container runtime type that used on cluster nodes (NodeGroups) by default.

    If the value NotManaged is used, then Deckhouse does not manage the container runtime (and doesn’t install it). In this case, it is necessary to use images for NodeGroups on which the container runtime is already installed.

    If ContainerdV2 is set, CgroupsV2 will be used (providing improved security and resource management). To use ContainerdV2 as the container runtime, cluster nodes must meet the following requirements:

    • Support for CgroupsV2.
    • Linux kernel version 5.8 or newer, except for the ranges 6.12.0–6.12.28 or 6.14.0–6.14.6 (these versions are affected by CVE-2025-37999 in EROFS).
    • Systemd version 244 or newer.
    • Support for erofs kernel module.

    Default: Containerd

    Allowed values: Containerd, ContainerdV2, NotManaged

  • encryptionAlgorithm
    string

    Starting from version 1.31, kubeadm use the specified asymmetric encryption algorithm when generating keys and certificates for the following control-plane components:

    • apiserver
    • apiserver-kubelet-client
    • apiserver-etcd-client
    • front-proxy-client
    • etcd-server
    • etcd-peer
    • etcd-healthcheck-client

    Certificates for the components listed above will be reissued using the selected algorithm and key length.

    Warning. When reissuing certificates, the root certificate (CA) is not rotated. The root certificate is created with the selected algorithm only during the initial cluster bootstrap.

    Default: RSA-2048

    Allowed values: RSA-2048, RSA-3072, RSA-4096, ECDSA-P256

  • kind
    string

    Required value

    Allowed values: ClusterConfiguration

  • kubernetesVersion
    string

    Required value

    Kubernetes version (control plane components of the cluster).

    Changing a parameter in a running cluster will automatically update the cluster’s control plane version.

    If Automatic is specified, then the control plane version is used, which is considered stable at the moment. If the stable version of control plane is less than the maximum version that has ever been installed in the cluster, more than 1 minor version, then the version of the cluster will not be changed. The version may change when the minor version of the Deckhouse release is changed (see a corresponding release message).

    Allowed values: 1.31, 1.32, 1.33, 1.34, 1.35, Automatic

  • podSubnetCIDR
    string

    Required value

    Address space of the cluster’s Pods.

    Warning! Changing this parameter in a running cluster is extremely dangerous and can lead to complete cluster failure. The change is blocked by default. To bypass this protection, use dhctl config edit cluster-configuration --yes-i-am-sane-and-i-understand-what-i-am-doing command. However, it is strongly recommended to recreate the cluster instead of changing this parameter. See documentation for details.

  • podSubnetNodeCIDRPrefix
    string

    The prefix size of the Pod network allocated to each node.

    This parameter determines how many IP addresses are available for Pods on each individual node. For example, if podSubnetCIDR: 10.111.0.0/16 and podSubnetNodeCIDRPrefix: "24", each node will receive a /24 subnet (e.g., 10.111.0.0/24, 10.111.1.0/24, etc.), providing up to 254 IP addresses per node (253 usable for Pods, accounting for network and broadcast addresses).

    Calculation examples:

    • With /16 network and /24 prefix: maximum 256 nodes (2^(24-16) = 256)
    • With /16 network and /25 prefix: maximum 512 nodes, but only 126 IPs per node
    • Each Pod network IP can support up to 2 Pods (one running + one terminating)

    Warning! Changing this parameter in a running cluster is extremely dangerous and can lead to complete cluster failure. The change is blocked by default. To bypass this protection, use dhctl config edit cluster-configuration --yes-i-am-sane-and-i-understand-what-i-am-doing command. However, it is strongly recommended to recreate the cluster instead of changing this parameter. See documentation for details.

    Default: 24

  • proxy
    object

    Available in editions: BE, SE, SE+, EE

    Global proxy setup (mainly for working in air-gapped environments).

    The parameters described in this section will be translated into the environment variables HTTP_PROXY, HTTPS_PROXY, and NO_PROXY for all cluster nodes and Deckhouse components. This will result in HTTP(S) requests (curl, git, registry, etc.) to all resources not listed in the noProxy parameter being made through a proxy. Note that the podSubnetCIDR and serviceSubnetCIDR subnets, as well as the clusterDomain domain are added to noProxy automatically.

    Caution! To avoid using proxies in requests between pods and services located in the cluster node network, make sure you list all the host subnets in the noProxy parameter.

    • proxy.httpProxy
      string

      Available in editions: BE, SE, SE+, EE

      Proxy URL for HTTP requests.

      If necessary, specify the proxy server’s username, password, and port.

      Pattern: ^https?://([!*'();&=+$,/?%#\[\]0-9a-zA-Z\.\-\_]+(\:[!*'();:@&=+$,/?%#\[\]0-9a-zA-Z\.\-\_]+)?@)?[0-9a-zA-Z\.\-]+(\:[0-9]{1,5})?$

      Examples:

      httpProxy: http://proxy.company.my
      
      httpProxy: https://user:password@proxy.company.my:8443
      
      httpProxy: https://DOMAIN%5Cuser:password@proxy.company.my:8443
      
      httpProxy: https://user%40domain.local:password@proxy.company.my:8443
      
    • proxy.httpsProxy
      string

      Available in editions: BE, SE, SE+, EE

      Proxy URL for HTTPS requests.

      If necessary, specify the proxy server’s username, password, and port.

      Pattern: ^https?://([!*'();&=+$,/?%#\[\]0-9a-zA-Z\.\-\_]+(\:[!*'();:@&=+$,/?%#\[\]0-9a-zA-Z\.\-\_]+)?@)?[0-9a-zA-Z\.\-]+(\:[0-9]{1,5})?$

      Examples:

      httpsProxy: http://proxy.company.my
      
      httpsProxy: https://user:password@proxy.company.my:8443
      
      httpsProxy: https://DOMAIN%5Cuser:password@proxy.company.my:8443
      
      httpsProxy: https://user%40domain.local:password@proxy.company.my:8443
      
    • proxy.noProxy
      array of strings

      Available in editions: BE, SE, SE+, EE

      List of no proxy IP and domain entries.

      For wildcard domains, use a domain name with a dot prefix, e.g., “.example.com”.

      Caution. If the cluster is supposed to have pods interacting with services located in the cluster node network, then specify the list of subnets that are used on the nodes.

      • Element of the array
        string

        Pattern: ^[a-z0-9\-\./]+$

  • serviceSubnetCIDR
    string

    Required value

    Address space of the cluster’s services.

    Warning! Changing this parameter in a running cluster is extremely dangerous and can lead to complete cluster failure. The change is blocked by default. To bypass this protection, use dhctl config edit cluster-configuration --yes-i-am-sane-and-i-understand-what-i-am-doing command. However, it is strongly recommended to recreate the cluster instead of changing this parameter. See documentation for details.

CNIMigration

Short names: cnim

Scope: Cluster
Version: v1alpha1

Defines the configuration for CNI migration.

  • spec
    object

    Defines the desired state of CNI migration.

    • spec.targetCNI
      string

      The target CNI to migrate to.

  • status
    object

    Defines the observed state of CNI migration.

    • status.conditions
      array of objects

      Reflect the state of the migration as a whole.

      • status.conditions.lastTransitionTime
        string

        Required value

      • status.conditions.message
        string

        Required value

      • status.conditions.reason
        string

        Required value

      • status.conditions.status
        string

        Required value

      • status.conditions.type
        string

        Required value

    • status.currentCNI
      string

      The detected CNI from which the switch is being made.

    • status.failedSummary
      array of objects

      Details about nodes that failed the migration.

      • status.failedSummary.node
        string
      • status.failedSummary.reason
        string
    • status.nodesFailed
      integer

      The number of nodes where an error occurred.

    • status.nodesSucceeded
      integer

      The number of nodes that have successfully completed the current phase.

    • status.nodesTotal
      integer

      The total number of nodes involved in the migration.

    • status.phase
      string

      The current step of the migration process.

CNINodeMigration

Short names: cninm

Scope: Cluster
Version: v1alpha1

Defines the configuration for CNI migration on a specific node.

  • spec
    object

    Defines the desired state of CNI migration on a node.

  • status
    object

    Defines the observed state of CNI migration on a node.

    • status.conditions
      array of objects

      A list of conditions for this migration.

      • status.conditions.lastTransitionTime
        string

        Required value

      • status.conditions.message
        string

        Required value

      • status.conditions.reason
        string

        Required value

      • status.conditions.status
        string

        Required value

      • status.conditions.type
        string

        Required value

    • status.phase
      string

      The current phase of the migration on the node.

DeckhouseRelease

Scope: Cluster
Version: v1alpha1

Determines the state and parameters for applying a specific release (version) of the Deckhouse Kubernetes Platform (DKP) in the cluster.

DeckhouseRelease objects are automatically created by DKP upon the discovery of new DKP versions on the selected release channel. Modifying DeckhouseRelease enables the management of the process for applying the corresponding DKP version. More details about configuring DKP updates can be found in the documentation.

The current versions of DKP and modules by release channels can be found at releases.deckhouse.ru.

  • approved
    boolean

    Allows or disables manual updates.

    Used only if the deckhouse module is configured for manual update mode (update.mode parameter is set to Manual). Ignored if the update mode is set to Auto or AutoPatch.

    For more information on confirming manual updates, refer to the documentation.

    Default: false

  • spec
    object

    Required value

    • spec.applyAfter
      string

      Marks release as a part of canary-release. This release will be delayed until the specified time. If the release is waiting to be applied, check .status.message for the reason.

    • spec.changelog
      object

      A structure containing a list of DKP changes (and modules included in the DKP) of the release.

      For more information about DKP release changelogs, refer to Updating.

    • string

      Link to site with full changelog for this release.

    • spec.disruptions
      Deprecated
      array of strings

      Disruptive changes in the release.

    • spec.requirements
      object

      A structure containing a list of requirements for installing the release. It is used by the DKP core. If the requirements are not met, the release may be skipped or blocked from installation.

      Reports on unmet requirements can be found in the field .status.message of the DeckhouseRelease object.

    • spec.version
      string

      Required value

      DKP version.

      Example:

      version: v1.73.2
      
  • status
    object
    • status.approved
      boolean

      The status of the release’s readiness for deployment. It makes sense only for Manual updates (update.mode: Manual).

    • status.message
      string

      Detailed status or error message.

    • status.phase
      string

      Current status of the release.

      Allowed values: Pending, Deployed, Outdated, Suspended, Superseded, Skipped

    • status.transitionTime
      string

      Time of release status change.

InitConfiguration

Version: deckhouse.io/v1

Deckhouse configuration to start after installation.

Example:

apiVersion: deckhouse.io/v1
kind: InitConfiguration
deckhouse:
  imagesRepo: nexus.company.my/deckhouse/ee
  registryDockerCfg: eyJhdXRocyI6IHsgIm5leHVzLmNvbXBhbnkubXkiOiB7InVzZXJuYW1lIjoibmV4dXMtdXNlciIsInBhc3N3b3JkIjoibmV4dXMtcEBzc3cwcmQiLCJhdXRoIjoiYm1WNGRYTXRkWE5sY2pwdVpYaDFjeTF3UUhOemR6QnlaQW89In19fQo=
  registryScheme: HTTPS
  registryCA: |
    -----BEGIN CERTIFICATE-----
    ...
    -----END CERTIFICATE-----
  • apiVersion
    string

    Required value

    Version of the Deckhouse API.

    Allowed values: deckhouse.io/v1, deckhouse.io/v1alpha1

  • deckhouse
    Deprecated
    object

    Required value

    Initial parameters required to install Deckhouse.

    • deckhouse.devBranch
      Deprecated
      string

      The parameter is used for development needs. Will be replaced with the CLI-tools.

    • deckhouse.imagesRepo
      string

      Address of a container registry with Deckhouse images.

      Specify it if Deckhouse Enterprise Edition edition or third-party registry (e.g. proxy server in a closed environment) is used.

      The address matches the edition of Deckhouse used. The public container registry address for Deckhouse Enterprise Edition is registry.deckhouse.io/deckhouse/ee.

      Default: registry.deckhouse.io/deckhouse/ce

      Pattern: ^[0-9a-zA-Z\.\-]+(\:[0-9]{1,5})?(\/[0-9a-zA-Z\.\-\_\/]+)?$

    • deckhouse.registryCA
      string

      Root CA certificate to validate the container registry’s HTTPS certificate (if self-signed certificates are used).

    • deckhouse.registryDockerCfg
      string

      A Base64-encoded string from the Docker client configuration file (in Linux it is usually $HOME/.docker/config.json), for accessing a third-party container registry.

      For example, to access the container registry registry.company.my under the user user with the password P@ssw0rd it will be eyJhdXRocyI6eyJyZWdpc3RyeS5jb21wYW55Lm15Ijp7ImF1dGgiOiJkWE5sY2pwUVFITnpkekJ5WkFvPSJ9fX0K (string {"auths":{"registry.company.my":{"auth":"dXNlcjpQQHNzdzByZAo="}}} in Base64).

      Default:

      Example:

      registryDockerCfg: eyJhdXRocyI6IHsgInJlZ2lzdHJ5LmRlY2tob3VzZS5pbyI6IHt9fX0=
      
    • deckhouse.registryScheme
      string

      Registry access scheme (HTTP or HTTPS).

      Default: HTTPS

      Allowed values: HTTP, HTTPS

  • kind
    string

    Required value

    Allowed values: InitConfiguration

Module

Scope: Cluster
Version: v1alpha1

Describes the module’s status in the cluster. The Module object is created automatically after configuring the ModuleSource and successfully completing synchronization.

  • properties
    object
    • properties.accessibility
      object

      Module accessibility settings.

      • properties.accessibility.editions
        object

        Module operation settings in Deckhouse editions.

        • properties.accessibility.editions.<KEY_NAME>
          object

          <KEY_NAME> — item (key) name.

          • properties.accessibility.editions.<KEY_NAME>.available
            boolean
          • properties.accessibility.editions.<KEY_NAME>.enabledInBundles
            array of strings
    • properties.availableSources
      array of strings

      Available sources for downloading the module.

    • properties.critical
      boolean

      Indicates whether the module critical or not.

    • properties.disableOptions
      object

      Parameters of module disable protection.

      • properties.disableOptions.confirmation
        boolean
      • properties.disableOptions.message
        string
    • properties.exclusiveGroup
      string

      Indicates the group where only one module can be active at a time.

    • properties.namespace
      string

      Module namespace.

    • properties.releaseChannel
      string

      Module release channel.

    • properties.requirements
      object

      Module dependencies, a set of requirements that must be met for Deckhouse Kubernetes Platform (DKP) to run the module.

      • properties.requirements.bootstrapped
        string

        Required cluster installation status (for built-in DKP modules only).

      • properties.requirements.deckhouse
        string

        Required Deckhouse version.

      • properties.requirements.kubernetes
        string

        Required Kubernetes version.

      • properties.requirements.modules
        object

        A list of other enabled modules required for the module.

    • properties.source
      string

      Source the module was downloaded from (otherwise will be blank).

    • properties.stage
      string

      Current stage of the module lifecycle.

    • properties.subsystems
      array of strings

      Module subsystems.

    • properties.updatePolicy
      string

      Module update policy.

    • properties.version
      string

      Module version.

    • properties.weight
      integer

      Module weight (priority).

  • status
    object
    • status.conditions
      array of objects
      • status.conditions.lastProbeTime
        string
      • status.conditions.lastTransitionTime
        string
      • status.conditions.message
        string
      • status.conditions.reason
        string
      • status.conditions.status
        string
      • status.conditions.type
        string
    • status.hooksState
      string

      Hooks status report.

    • status.phase
      string

      Module phase.

      Allowed values: Unavailable, Available, Downloading, DownloadingError, Reconciling, Installing, HooksDisabled, WaitSyncTasks, Downloaded, Conflict, Ready, Error

ModuleConfig

Short names: mc

Scope: Cluster
Version: v1alpha1

Defines the configuration of the Deckhouse Kubernetes Platform module (module parameters). The name of the ModuleConfig resource must match the name of the module (for example, control-plane-manager for the control-plane-manager module).

Example:

apiVersion: deckhouse.io/v1alpha1
kind: ModuleConfig
metadata:
  name: module-1
spec:
  enabled: true
  settings: {}
  version: 1
  • spec
    object

    Required value

    • spec.enabled
      boolean

      Enables or disables the module.

      Example:

      enabled: false
      
    • spec.maintenance
      string

      Defines the module maintenance mode.

      • NoResourceReconciliation: A mode for developing or tweaking the module.

        In this mode:

        • Configuration or hook changes are not reconciled, which prevents resources from being updated automatically.
        • Resource monitoring is disabled, which prevents deleted resources from being restored.
        • All the module’s resources are labeled with maintenance: NoResourceReconciliation.
        • The ModuleIsInMaintenanceMode alert is triggered.

      Allowed values: NoResourceReconciliation

      Example:

      maintenance: NoResourceReconciliation
      
    • spec.settings
      object

      Module settings.

    • spec.source
      string

      The source of the module it provided by one (otherwise empty).

    • spec.updatePolicy
      string

      Module update policy.

      Example:

      updatePolicy: test-alpha
      
    • spec.version
      number

      Version of settings schema.

      Example:

      version: 1
      
  • status
    object
    • status.message
      string

      Additional information

    • status.version
      string

      Version of settings schema in use

ModuleDocumentation

Scope: Cluster
Version: v1alpha1

Defines the rendering configuration of the Deckhouse module documentation.

Deckhouse creates ModuleDocumentation resources by itself.

  • spec
    object

    Required value

    • spec.checksum
      string

      Module version checksum.

    • spec.path
      string

      Path to the module version.

    • spec.version
      string

      Required value

      Module version.

      Example:

      version: v1.0.0
      
  • status
    object
    • status.conditions
      array of objects
      • status.conditions.address
        string
      • status.conditions.checksum
        string
      • status.conditions.lastTransitionTime
        string
      • status.conditions.message
        string
      • status.conditions.type
        string
      • status.conditions.version
        string
    • status.result
      string

ModulePullOverride

Short names: mpo

Scope: Cluster

  • v1alpha2
  • v1alpha1

Defines the resource configuration for downloading specific versions of Deckhouse modules.

Caution. This resource is intended for development and debugging environments only. Using it in production clusters is not recommended. Support for the resource might be removed in future Deckhouse Kubernetes Platform versions.

  • spec
    object

    Required value

    • spec.imageTag
      string

      Required value

      Module container image tag, which will be pulled.

    • spec.rollback
      boolean

      Indicates whether the module release should be rollback after deleting mpo.

      Default: false

    • spec.scanInterval
      string

      Scan interval for checking the image digest. If the digest changes, the module is updated. Supported units: h, m, s.

      Default: 15s

      Pattern: ^(\d+h)?(\d+m)?(\d+s)?$

  • status
    object
    • status.imageDigest
      string

      Digest of the module image.

    • status.message
      string

      Details of the resource status.

    • status.updatedAt
      string

      When the module was last updated.

    • status.weight
      integer

      Module weight.

Deprecated resource. Support for the resource might be removed in a later release.

Defines the configuration.

  • spec
    object

    Required value

    • spec.imageTag
      string

      Required value

      Module container image tag, which will be pulled.

    • spec.rollback
      boolean

      Indicates whether the module release should be rollback after deleting ModulePullOverride.

      Default: false

    • spec.scanInterval
      string

      Scan interval for checking the image digest. If the digest changes, the module is updated. Supported units: h, m, s.

      Default: 15s

      Pattern: ^(\d+h)?(\d+m)?(\d+s)?$

    • spec.source
      string

      Required value

      Reference to the ModuleSource with the module.

  • status
    object
    • status.imageDigest
      string

      Digest of the module image.

    • status.message
      string

      Details of the resource status.

    • status.updatedAt
      string

      When the module was last updated.

    • status.weight
      integer

      Module weight.

ModuleRelease

Short names: mr

Scope: Cluster
Version: v1alpha1

Defines the configuration for a Deckhouse release.

ModuleRelease resources are created by Deckhouse.

  • spec
    object

    Required value

    • spec.applyAfter
      string

      Time until which the release will be delayed.

    • spec.changelog
      object

      Release’s changelog for the module.

    • spec.moduleName
      string

      Required value

      Module name.

    • spec.requirements
      object

      Release dependencies, a set of requirements that must be met for Deckhouse Kubernetes Platform to run the module release.

      • spec.requirements.deckhouse
        string

        Required Deckhouse version.

      • spec.requirements.kubernetes
        string

        Required Kubernetes version.

      • spec.requirements.modules
        object

        A list of other modules required for the module release. Ensure the modules are enabled.

    • spec.update
      object

      Optional transition rules.

      • spec.update.versions
        array of objects

        List of fromto transition rules that allow skipping step-by-step updates. If the current installed module version (status Deployed) is not lower than from, and the cluster has a release whose version matches to, the controller will skip intermediate releases and update the module to the version from to. The to value can specify a minor line (X.Y — the latest available X.Y.Z will be selected). The rule is specified in the constrained release — the one whose version matches to.

        • spec.update.versions.from
          string

          Required value

          The minimum version from which the transition is allowed (format X.Y).

        • spec.update.versions.to
          string

          Required value

          The end version of the range — a minor line (X.Y).

    • spec.version
      string

      Required value

      Module version.

      Example:

      version: v1.0.0
      
    • spec.weight
      integer

      Module weight (priority).

  • status
    object
    • status.approved
      boolean

      Status indicating that the release is ready for deployment. For the Manual update mode only (update.mode: Manual).

    • status.message
      string

      Detailed status or error message.

    • status.phase
      string

      Current status of the release.

      Allowed values: Pending, Deployed, Superseded, Suspended, Skipped, Terminating

    • status.pullDuration
      string

      Module loading duration.

    • status.size
      integer

      Size of the module image.

    • status.transitionTime
      string

      Time of release status change.

ModuleSettingsDefinition

Scope: Cluster
Version: v1alpha1

It displays module settings. Defines a list of module settings versions.

  • spec
    object

    Required value

    Specification of the module settings.

    • spec.versions
      array of objects

      List of module settings versions. Each version includes a name and a schema.

      • spec.versions.conversions
        array of objects

        List of conversion rules for this version.

        A single conversion rule with expressions and descriptions.

        • spec.versions.conversions.descriptions
          object

          Localized descriptions of the conversion.

          • spec.versions.conversions.descriptions.en
            string

            English description of the conversion.

          • spec.versions.conversions.descriptions.ru
            string

            Russian description of the conversion.

        • spec.versions.conversions.expr
          array of strings

          Array of jq expressions to transform settings.

      • spec.versions.name
        string

        Required value

        Module settings version.

      • spec.versions.schema
        object

        Settings schema for the given module version.

ModuleSource

Short names: ms

Scope: Cluster
Version: v1alpha1

Defines the configuration of a source of Deckhouse modules.

For more information about installing the module from the source, see the section “Running the module in the DKP cluster”.

Example:

apiVersion: deckhouse.io/v1alpha1
kind: ModuleSource
metadata:
  name: example
spec:
  registry:
    repo: registry.example.io/modules-source
    dockerCfg: "<base64 encoded credentials>"
  • spec
    object

    Required value

    • spec.registry
      object

      Required value

      • spec.registry.ca
        string

        Root CA certificate (PEM format) to validate the registry’s HTTPS certificate (if self-signed certificates are used).

        Creating a ModuleSource resource with the CA certificate spec will cause the container to restart on all nodes.

      • spec.registry.dockerCfg
        string

        Container registry access token in Base64. If using anonymous access to the container registry, do not fill in this field.

      • spec.registry.repo
        string

        Required value

        URL of the container registry.

        Example:

        repo: registry.example.io/deckhouse/modules
        
      • spec.registry.scheme
        string

        Protocol to access the registry.

        Default: HTTPS

        Allowed values: HTTP, HTTPS

    • spec.releaseChannel
      Deprecated
      string

      Desirable default release channel for modules in the current source.

    • spec.scanInterval
      string

      Interval for registry scan.

      Defines the frequency of checking the container registry for new modules and their versions.

      Default: 3m

      Pattern: ^(\d+h)?(\d+m)?(\d+s)?$

      Examples:

      scanInterval: 5m
      
      scanInterval: 1h
      
      scanInterval: 6h30m
      
  • status
    object
    • status.message
      string
    • status.modules
      array of objects

      The list of modules available from the source and their update policies.

      • status.modules.checksum
        string

        The module checksum.

      • status.modules.error
        string

        The module processing error.

      • status.modules.name
        string

        The module name.

      • status.modules.overridden
        boolean

        If ModulePullOverride for this module exists.

      • status.modules.policy
        string

        The module policy name.

      • status.modules.pullError
        string

        The module pull error.

      • status.modules.version
        string

        The module version.

    • status.modulesCount
      integer

      The number of modules available.

    • status.phase
      string

      The current phase.

      Allowed values: Active, Terminating

    • status.syncTime
      string

      When the repository was synchronized.

ModuleUpdatePolicy

Short names: mup

Scope: Cluster

  • v1alpha2
  • v1alpha1

Defines the update settings for a module’s release.

Example:

apiVersion: deckhouse.io/v1alpha2
kind: ModuleUpdatePolicy
metadata:
  name: example-update-policy
spec:
  releaseChannel: Alpha
  update:
    mode: Auto
    windows:
    - days:
      - Mon
      - Wed
      from: '13:30'
      to: '14:00'
  • spec
    object

    Required value

    • spec.releaseChannel
      string

      Desirable module release channel.

      The order in which the stability of the release channel increases (from less stable to more stable): Alpha, Beta, EarlyAccess, Stable, RockSolid.

      Default: Stable

      Allowed values: Alpha, Beta, EarlyAccess, Stable, RockSolid, Lts

    • spec.update
      object

      Required value

      Update settings for target modules.

      • spec.update.mode
        string

        Modules version update mode (release change).

        • AutoPatch — automatic update mode for patch releases.

          To change a minor version (for example, from v1.15.* to v1.16.*), confirmation is required.

          A patch version update (for example, from v1.16.1 to v1.16.2) is applied according to the update windows, if they are set.

        • Auto — all updates are applied automatically.

          Modules minor version updates (for example, from v1.15.* to v1.16.*) and patch version updates (for example, from v1.16.1 to v1.16.2) are applied according to the update windows or (if no update windows are set) as they appear on the corresponding release channel;

        • Manual — confirmation is required for updating both minor and patch versions.

        To confirm the update, add the modules.deckhouse.io/approved="true" annotation to the corresponding ModuleRelease resource.

        Default: Auto

        Allowed values: Auto, Manual, AutoPatch

      • spec.update.windows
        array of objects

        Modules update timetable.

        • spec.update.windows.days
          array of strings

          The days of the week on which the update window is applied.

          Examples:

          days: Mon
          
          days: Wed
          
          • Element of the array
            string

            Day of the week.

            Allowed values: Mon, Tue, Wed, Thu, Fri, Sat, Sun

            Example:

            Mon
            
        • spec.update.windows.from
          string

          Required value

          Start time of the update window (UTC timezone).

          Should be less than the end time of the update window.

          Pattern: ^(?:\d|[01]\d|2[0-3]):[0-5]\d$

          Example:

          from: '13:00'
          
        • spec.update.windows.to
          string

          Required value

          End time of the update window (UTC timezone).

          Should be more than the start time of the update window.

          Pattern: ^(?:\d|[01]\d|2[0-3]):[0-5]\d$

          Example:

          to: '18:30'
          

Deprecated resource. Support for the resource might be removed in a later release.

Defines the update settings for a module’s release.

Example:

apiVersion: deckhouse.io/v1alpha1
kind: ModuleUpdatePolicy
metadata:
  name: example-update-policy
spec:
  moduleReleaseSelector:
    labelSelector:
      matchLabels:
        source: example
        module: module-1
  releaseChannel: Alpha
  update:
    mode: Auto
    windows:
    - days:
      - Mon
      - Wed
      from: '13:30'
      to: '14:00'
  • spec
    object

    Required value

    • spec.moduleReleaseSelector
      object

      Required value

      Selects target modules to apply update settings to.

      • spec.moduleReleaseSelector.labelSelector
        object

        Required value

        Label-selector-based filter to match target modules.

        If both matchExpressions and matchLabels parameters are set, their requirements are ANDed together — they must all be satisfied in order to match. If multiple matchExpression conditions are provided, they all must be satisfied in order to match.

        • spec.moduleReleaseSelector.labelSelector.matchExpressions
          array of objects

          An array of set-based expressions.

          • spec.moduleReleaseSelector.labelSelector.matchExpressions.key
            string

            Required value

            A label name.

          • spec.moduleReleaseSelector.labelSelector.matchExpressions.operator
            string

            Required value

            A comparison operator.

            Allowed values: In, NotIn, Exists, DoesNotExist

          • spec.moduleReleaseSelector.labelSelector.matchExpressions.values
            array of strings

            A label value.

        • spec.moduleReleaseSelector.labelSelector.matchLabels
          object

          A number of equality-based label filters.

          Example:

          matchLabels:
            source: deckhouse
            module: deckhouse-admin
          
    • spec.releaseChannel
      string

      Desirable module release channel.

      The order in which the stability of the release channel increases (from less stable to more stable): Alpha, Beta, EarlyAccess, Stable, RockSolid.

      Default: Stable

      Allowed values: Alpha, Beta, EarlyAccess, Stable, RockSolid

    • spec.update
      object

      Required value

      Update settings for target modules.

      • spec.update.mode
        string

        Modules version update mode (release change).

        • AutoPatch — automatic update mode for patch releases.

          To change a minor version (for example, from v1.15.* to v1.16.*), confirmation is required.

          A patch version update (for example, from v1.16.1 to v1.16.2) is applied according to the update windows, if they are set.

        • Auto — all updates are applied automatically.

          Modules minor version updates (for example, from v1.15.* to v1.16.*) and patch version updates (for example, from v1.16.1 to v1.16.2) are applied according to the update windows or (if no update windows are set) as they appear on the corresponding release channel;

        • Manual — confirmation is required for updating both minor and patch versions.

        To confirm the update, add the modules.deckhouse.io/approved="true" annotation to the corresponding ModuleRelease resource.

        • Ignore — updates are ignored.

        Default: AutoPatch

        Allowed values: Auto, Manual, Ignore, AutoPatch

      • spec.update.windows
        array of objects

        Modules update timetable.

        • spec.update.windows.days
          array of strings

          The days of the week on which the update window is applied.

          Examples:

          days: Mon
          
          days: Wed
          
          • Element of the array
            string

            Day of the week.

            Allowed values: Mon, Tue, Wed, Thu, Fri, Sat, Sun

            Example:

            Mon
            
        • spec.update.windows.from
          string

          Required value

          Start time of the update window (UTC timezone).

          Should be less than the end time of the update window.

          Pattern: ^(?:\d|[01]\d|2[0-3]):[0-5]\d$

          Example:

          from: '13:00'
          
        • spec.update.windows.to
          string

          Required value

          End time of the update window (UTC timezone).

          Should be more than the start time of the update window.

          Pattern: ^(?:\d|[01]\d|2[0-3]):[0-5]\d$

          Example:

          to: '18:30'
          

PackageRepository

Scope: Cluster
Version: v1alpha1

PackageRepository is a source of packages for Deckhouse Kubernetes Platform.

  • apiVersion
    string

    APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info in the Kubernetes documentation.

  • kind
    string

    Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info in the Kubernetes documentation.

  • metadata
    object
  • spec
    object

    Required value

    Defines the package repository configuration.

    • spec.registry
      object

      Required value

      Configuration for accessing the container registry with packages.

      • spec.registry.ca
        string

        Root CA certificate (PEM format) used to verify the container registry certificate over HTTPS (if the container registry uses self-signed SSL certificates).

      • spec.registry.dockerCfg
        string

        Container registry access token in Base64 (~/.docker/config.json format). Leave this field empty if anonymous access to the container registry is used.

      • spec.registry.login
        string

        Username for authenticating to the container registry.

      • spec.registry.password
        string

        Password for authenticating to the container registry.

      • spec.registry.repo
        string

        Required value

        Address of the package repository in the container registry.

      • spec.registry.scheme
        string

        Protocol for accessing the repository (for example, https).

    • spec.scanInterval
      string

      Interval for container registry scan.

      Defines the frequency of checking the container registry for new packages.

      Default: 6h

      Pattern: ^(\d+h)?(\d+m)?(\d+s)?$

      Examples:

      scanInterval: 5m
      
      scanInterval: 1h
      
      scanInterval: 6h30m
      
  • status
    object

    Package repository status.

    • status.conditions
      array of objects

      Conditions reflecting the latest observations of the repository state.

      Condition describing one aspect of the current repository state.

      • status.conditions.lastTransitionTime
        string

        Required value

        lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.

      • status.conditions.message
        string

        Required value

        message is a human readable message indicating details about the transition. This may be an empty string.

        Maximum length: 32768

      • status.conditions.observedGeneration
        integer

        observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.

        Allowed values: 0 <= X

      • status.conditions.reason
        string

        Required value

        reason contains a programmatic identifier indicating the reason for the condition’s last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.

        Pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$

        Length: 1..1024

      • status.conditions.status
        string

        Required value

        status of the condition, one of True, False, Unknown.

        Allowed values: True, False, Unknown

      • status.conditions.type
        string

        Required value

        type of condition in CamelCase or in foo.example.com/CamelCase.

        Pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$

        Maximum length: 316

    • status.lastChangeTime
      string

      Time of the most recent scan that found at least one new version. Scans that found nothing new do not advance this timestamp.

    • status.lastNewVersions
      integer

      Number of new versions found by the most recent scan. Set to zero when the last scan found nothing new.

    • status.lastScanTime
      string

      Time of the most recent scan of any outcome.

    • status.message
      string

      Human-readable message about the repository status.

    • status.packages
      array of objects

      List of packages available in this repository.

      • status.packages.name
        string

        Required value

        Name of the package.

      • status.packages.type
        string

        Required value

        Type of the package.

    • status.packagesCount
      integer

      Total number of packages in this repository.

    • status.partialScanAvailable
      boolean

      Indicates whether the container registry supports pagination when listing tags.

    • status.phase
      string

      Current phase of the repository.

PackageRepositoryOperation

Short names: pro

Scope: Cluster
Version: v1alpha1

PackageRepositoryOperation represents an operation to scan/update a package repository.

  • apiVersion
    string

    APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info in the Kubernetes documentation

  • kind
    string

    Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info in the Kubernetes documentation

  • metadata
    object
  • spec
    object

    Required value

    Defines parameters for the package repository operation.

    • spec.packageRepositoryName
      string

      Required value

      Name of the package repository to operate on.

    • spec.type
      string

      Required value

      Type of operation to perform.

      Allowed values: Update

    • spec.update
      object

      Configuration for update operations.

      • spec.update.fullScan
        boolean

        Whether to perform a full scan of the repository.

      • spec.update.timeout
        string

        Timeout for the operation.

  • status
    object

    Package repository operation status.

    • status.completionTime
      string

      Time when the operation completed.

    • status.conditions
      array of objects

      Conditions reflecting the latest observations of the operation state. The operation phase is determined by the Completed condition: while its status is False, the operation is in one of the intermediate phases (Discover, Processing); when the status is True, the operation has finished with reason Succeeded or Failed.

      Condition describing one aspect of the current operation state.

      • status.conditions.lastTransitionTime
        string

        Required value

        lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.

      • status.conditions.message
        string

        Required value

        message is a human readable message indicating details about the transition. This may be an empty string.

        Maximum length: 32768

      • status.conditions.observedGeneration
        integer

        observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.

        Allowed values: 0 <= X

      • status.conditions.reason
        string

        Required value

        Programmatic identifier for the reason of the condition’s last transition. For the Completed condition, the values are: Discover, Processing, Succeeded, Failed.

        Pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$

        Length: 1..1024

      • status.conditions.status
        string

        Required value

        status of the condition, one of True, False, Unknown.

        Allowed values: True, False, Unknown

      • status.conditions.type
        string

        Required value

        Condition type. This resource uses the Completed condition, which reflects whether the operation has reached a terminal phase.

        Pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$

        Maximum length: 316

    • status.packages
      object

      Information about packages processed during the operation.

      • status.packages.discovered
        array of objects

        List of packages discovered during the operation.

        • status.packages.discovered.name
          string

          Required value

          Name of the discovered package.

      • status.packages.failed
        array of objects

        List of packages that failed processing.

        • status.packages.failed.errors
          array of objects

          Required value

          List of errors encountered while processing this package.

          • status.packages.failed.errors.message
            string

            Required value

            Message of the error.

          • status.packages.failed.errors.version
            string

            Required value

            Version of the package that failed.

        • status.packages.failed.name
          string

          Required value

          Name of the package that failed.

      • status.packages.newVersionsOverall
        integer

        Total number of newly found versions across all packages in this operation.

        A version is counted as new if its ApplicationPackageVersion or ModulePackageVersion did not exist in the cluster, or (ApplicationPackageVersion only) existed with the “not in registry” mark and its image was found in the registry during this operation.

      • status.packages.processed
        array of objects

        List of packages successfully processed.

        • status.packages.processed.foundVersions
          integer

          Number of versions found during this operation.

        • status.packages.processed.name
          string

          Required value

          Name of the processed package.

        • status.packages.processed.newVersions
          integer

          Number of newly found versions during this operation.

          A version is counted as new if its ApplicationPackageVersion or ModulePackageVersion did not exist in the cluster, or (ApplicationPackageVersion only) existed with the “not in registry” mark and its image was found in the registry during this operation.

        • status.packages.processed.type
          string

          Type of the package.

      • status.packages.processedOverall
        integer

        Total number of packages processed.

      • status.packages.total
        integer

        Total number of packages found.

    • status.startTime
      string

      Time when the operation started.

SSHConfig

Version: dhctl.deckhouse.io/v1

General dhctl SSH config.

Example:

apiVersion: dhctl.deckhouse.io/v1
kind: SSHConfig
sshUser: user
sshPort: 22
sshExtraArgs: "-vvv"
sshAgentPrivateKeys:
- key: "<ssh-private-key>"
  • apiVersion
    string

    Version of the Deckhouse API.

    Allowed values: dhctl.deckhouse.io/v1

  • kind
    string

    Allowed values: SSHConfig

  • legacyMode
    boolean

    Switch to legacy SSH mode (clissh).

  • modernMode
    boolean

    Switch to modern SSH mode (gossh).

  • sshAgentPrivateKeys
    array of objects
    • sshAgentPrivateKeys.key
      string

      Required value

      Private SSH key.

    • sshAgentPrivateKeys.passphrase
      string

      Password for SSH key.

  • sshBastionHost
    string

    SSH bastion host.

  • sshBastionPassword
    string

    A password for the bastion user.

  • sshBastionPort
    integer

    Port of SSH bastion.

  • sshBastionUser
    string

    Username for bastion.

  • sshExtraArgs
    string

    Additional arguments for SSH connection.

  • sshPort
    integer

    SSH port.

  • sshUser
    string

    SSH username.

  • sudoPassword
    string

    A sudo password for the user.

SSHHost

Version: dhctl.deckhouse.io/v1

General dhctl SSH host config.

Example:

apiVersion: dhctl.deckhouse.io/v1
kind: SSHHost
host: 172.16.0.0
  • apiVersion
    string

    Required value

    Version of the Deckhouse API.

    Allowed values: dhctl.deckhouse.io/v1

  • host
    string

    Required value

    Host.

  • kind
    string

    Required value

    Allowed values: SSHHost

StaticClusterConfiguration

Version: deckhouse.io/v1

Parameters of a static (bare metal) cluster.

To change the StaticClusterConfiguration resource in a running cluster, run the following command:

d8 system edit static-cluster-configuration

Example:

apiVersion: deckhouse.io/v1
kind: StaticClusterConfiguration
internalNetworkCIDRs:
- 10.244.0.0/16
- 10.50.0.0/16
  • apiVersion
    string

    Required value

    Version of the Deckhouse API.

    Allowed values: deckhouse.io/v1, deckhouse.io/v1alpha1

  • internalNetworkCIDRs
    array of strings

    List of internal cluster networks.

    Internal cluster networks connect Kubernetes components (kube-apiserver, kubelet, etc.).

    The parameter is mandatory in the following cases:

    • Cluster nodes have more than one network interface
    • The cluster is deployed inside a Deckhouse Virtualization Platform

    When changing the value, subnets in the new list must include IP addresses of currently joined nodes.

    Example:

    internalNetworkCIDRs:
    - 192.168.42.0/24
    - 172.16.16.0/24
    
    • Element of the array
      string

      Pattern: ^(([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])\.){3}([0-9]|[1-9][0-9]|1[0-9]{2}|2[0-4][0-9]|25[0-5])(\/(3[0-2]|[1-2][0-9]|[0-9]))$

  • kind
    string

    Required value

    Allowed values: StaticClusterConfiguration