API Reference
Packages
catalog.kbind.io/v1alpha1
Package v1alpha1 contains the catalog API for the kbind service layer: the Export and Collection kinds in the catalog.kbind.io group. The catalog is curation on top of the core's raw discovery — human-facing metadata and defaults that turn "a list of CRD names" into "a service you'd choose". These CRDs live on the provider and are read only by the gateway/UI/CLI; the konnector never sees them. See docs/proposals/v2-extended.md.
Resource Types
BindingDefaults
BindingDefaults are the binding fields an Export pre-fills in the generated bundle.
Appears in: - ExportSpec
| Field | Description | Default | Validation |
|---|---|---|---|
conflictPolicy ConflictPolicy |
conflictPolicy is the default conflict behavior for the generated ClusterBinding. |
Enum: [Fail Adopt] Optional: {} |
|
relatedResources RelatedResource array |
relatedResources are the related-resource selectors for the generated ClusterBinding. |
Optional: {} |
Collection
Collection groups Exports for UI/CLI browsing. Pure presentation; nothing binds to a Collection.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
catalog.kbind.io/v1alpha1 |
||
kind string |
Collection |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec CollectionSpec |
Required: {} Required: {} |
CollectionSpec
CollectionSpec is a titled grouping of Exports.
Appears in: - Collection
| Field | Description | Default | Validation |
|---|---|---|---|
title string |
title is the human-facing name of the group. | MinLength: 1 Required: {} Required: {} |
|
description string |
description explains the grouping. | Optional: {} |
|
exports ExportRef array |
exports lists the member Exports by name. | MinItems: 1 Required: {} Required: {} |
Export
Export is one curated offering in the provider's catalog: human-facing metadata plus defaults on top of one or more exported APIs. The catalog is derived-from-core-truth: an Export listing an API that is not actually exported (label/boundary) gets a condition and is hidden by the gateway — the export label remains the source of truth, the catalog is presentation and defaults. Lives on the provider; the konnector never sees it.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
catalog.kbind.io/v1alpha1 |
||
kind string |
Export |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec ExportSpec |
Required: {} Required: {} |
||
status ExportStatus |
Optional: {} |
ExportRef
ExportRef references an Export by name.
Appears in: - CollectionSpec
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
name of the Export. | MinLength: 1 Required: {} Required: {} |
ExportSpec
ExportSpec describes one offering.
Appears in: - Export
| Field | Description | Default | Validation |
|---|---|---|---|
title string |
title is the human-facing name of the offering. | MinLength: 1 Required: {} Required: {} |
|
description string |
description explains the offering to a human choosing it. | Optional: {} |
|
icon Icon |
icon optionally points at an icon for UIs. | Optional: {} |
|
docs string |
docs optionally links to the offering's documentation. | Optional: {} |
|
apis APIRef array |
apis lists the exported APIs a binding to this offering syncs, by CRD name on the provider (" |
MinItems: 1 Required: {} Required: {} |
|
defaults BindingDefaults |
defaults are copied into the generated ClusterBinding of the one-apply bundle. |
Optional: {} |
ExportStatus
ExportStatus is the observed state of an Export.
Appears in: - Export
| Field | Description | Default | Validation |
|---|---|---|---|
conditions Condition array |
conditions: Ready (all listed APIs are actually exported). | Optional: {} |
Icon
Icon points at an icon image for UIs.
Appears in: - ExportSpec
| Field | Description | Default | Validation |
|---|---|---|---|
url string |
url of the icon image. | MinLength: 1 Required: {} Required: {} |
core.kbind.io/v1alpha1
Package v1alpha1 contains the v2 "slim core" API for kbind: the Connection, ClusterBinding and Binding kinds in the core.kbind.io group. See docs/proposals/v2-slim-core.md for the design.
Resource Types
APIRef
APIRef identifies an exported API by its CRD name on the provider,
i.e. "
Appears in: - BindingSpec - ExportSpec - GrantSpec
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
name is the CRD name of the exported API, " |
MinLength: 1 Required: {} Required: {} |
Binding
Binding activates instance sync for one or more exported APIs within its own namespace. Namespaced, following the Role convention. It is the v2 answer to v1's informerScope: Namespaced. Where a ClusterBinding and a Binding cover the same API on the same connection, the ClusterBinding wins.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
core.kbind.io/v1alpha1 |
||
kind string |
Binding |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec BindingSpec |
Required: {} Required: {} |
||
status BindingStatus |
Optional: {} |
BindingSpec
BindingSpec is the spec shared by ClusterBinding and Binding. The only difference between the two kinds is scope (cluster-wide vs. one namespace), which is expressed by the kind, not by a field.
Appears in: - Binding - ClusterBinding
| Field | Description | Default | Validation |
|---|---|---|---|
connectionRef ConnectionRef |
connectionRef points at the Connection that provides the provider link and credentials for the listed APIs. |
Required: {} Required: {} |
|
apis APIRef array |
apis lists one or more exported CRDs to sync, by CRD name on the provider. | MinItems: 1 Required: {} Required: {} |
|
conflictPolicy ConflictPolicy |
conflictPolicy controls what happens when a target object already exists. Fail (default) leaves a foreign object untouched and records a conflict; Adopt takes ownership of an un-owned object. Adopt never steals an object already carrying another binding's/consumer's markers. |
Fail | Enum: [Fail Adopt] |
relatedResources RelatedResource array |
relatedResources are Secrets/ConfigMaps synced alongside instances of the bound APIs. Not yet synced in the alpha POC. |
Optional: {} |
BindingStatus
BindingStatus is the observed state shared by ClusterBinding and Binding.
Appears in: - Binding - ClusterBinding
| Field | Description | Default | Validation |
|---|---|---|---|
boundAPIs BoundAPI array |
boundAPIs is per-API observed state. | Optional: {} |
|
conditions Condition array |
conditions: Connected, Synced, Conflicts, PermissionDenied, Ready. | Optional: {} |
BoundAPI
BoundAPI is the per-API observed state recorded on a binding's status.
Appears in: - BindingStatus
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
name is the CRD name of the bound API, " |
||
crdHash string |
crdHash is a hash of the schema currently applied on the consumer for this API. Empty until the schema has been installed. |
Optional: {} |
|
conflictCount integer |
conflictCount is the number of objects skipped due to foreign ownership. Per-object detail lives on each object's own condition, not here. |
Optional: {} |
ClusterBinding
ClusterBinding activates instance sync for one or more exported APIs cluster-wide. Cluster-scoped, following the ClusterRole convention.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
core.kbind.io/v1alpha1 |
||
kind string |
ClusterBinding |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec BindingSpec |
Required: {} Required: {} |
||
status BindingStatus |
Optional: {} |
ConflictPolicy
Underlying type: string
ConflictPolicy is the behavior for pre-existing target objects.
Appears in: - BindingDefaults - BindingSpec - GrantSpec
| Field | Description |
|---|---|
Fail |
ConflictPolicyFail leaves a foreign target object untouched and records the collision as a conflict. This is the default. |
Adopt |
ConflictPolicyAdopt takes ownership of an un-owned target object. |
Connection
Connection is the link to one provider cluster. It owns the credentials and schema delivery, and surfaces what the provider exports. Cluster-scoped.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
core.kbind.io/v1alpha1 |
||
kind string |
Connection |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec ConnectionSpec |
Required: {} Required: {} |
||
status ConnectionStatus |
Optional: {} |
ConnectionRef
ConnectionRef references a Connection by name. Connection is cluster-scoped, so no namespace is needed.
Appears in: - BindingSpec
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
name of the Connection. | MinLength: 1 Required: {} Required: {} |
ConnectionSpec
ConnectionSpec defines the desired provider link.
Appears in: - Connection
| Field | Description | Default | Validation |
|---|---|---|---|
kubeconfigSecretRef SecretKeyRef |
kubeconfigSecretRef points at the Secret holding the provider kubeconfig. Immutable. The only credential reference in the core. |
Required: {} Required: {} |
|
schema SchemaPolicy |
schema controls how exported APIs reach the consumer. | { } | Optional: {} |
autoBind boolean |
autoBind, when true, makes the konnector maintain a managed ClusterBinding (named after this Connection) covering all exported APIs. |
false |
ConnectionStatus
ConnectionStatus is the observed state of a Connection.
Appears in: - Connection
| Field | Description | Default | Validation |
|---|---|---|---|
remoteClusterUID string |
remoteClusterUID is the identity of the provider cluster, pinned on first connect and immutable thereafter. A Secret later pointing at a different cluster is rejected rather than silently re-homing synced objects. |
Optional: {} |
|
localClusterUID string |
localClusterUID is the identity of the consumer cluster, pinned on first connect and immutable thereafter. |
Optional: {} |
|
activeSchemaSource SchemaSource |
activeSchemaSource is the schema source actually in effect after resolving "Auto" (CRD or OpenAPI). The binding uses it to decide whether the Connection already installed the CRDs (OpenAPI) or it should pull them (CRD). |
Optional: {} |
|
exportedAPIs ExportedAPI array |
exportedAPIs is the discovery result: APIs exported to these credentials. | Optional: {} |
|
conditions Condition array |
conditions: SecretValid, Connected, SchemaInSync, Ready. | Optional: {} |
ExportedAPI
ExportedAPI describes one API the provider exports to these credentials.
Appears in: - ConnectionStatus
| Field | Description | Default | Validation |
|---|---|---|---|
name string |
name is the CRD name of the exported API, " |
||
group string |
group of the exported API. | ||
resource string |
resource is the plural resource name of the exported API. | ||
scope ResourceScope |
scope is whether the API is Namespaced or Cluster scoped. | ||
versions string array |
versions are the served versions of the exported API. |
PullPolicy
Underlying type: string
PullPolicy selects which exported APIs are installed on the consumer.
Appears in: - SchemaPolicy
| Field | Description |
|---|---|
Bound |
PullPolicyBound installs only APIs referenced by a binding. |
All |
PullPolicyAll installs every exported API. |
None |
PullPolicyNone never installs CRDs. |
RelatedResource
RelatedResource selects auxiliary objects (Secrets/ConfigMaps) to sync alongside the bound instances.
Appears in: - BindingDefaults - BindingSpec - GrantSpec
| Field | Description | Default | Validation |
|---|---|---|---|
group string |
group of the related resource. Empty string for the core group. | ||
resource string |
resource is the plural resource name. Only "secrets" and "configmaps" are permitted in core. |
Enum: [secrets configmaps] Required: {} Required: {} |
|
direction SyncDirection |
direction the related resource flows. | Enum: [FromProvider FromConsumer] Required: {} Required: {} |
|
selector RelatedResourceSelector |
selector restricts which objects are synced. Only labelSelector and named selectors are supported in core (no JSONPath reference-following). |
Optional: {} |
RelatedResourceSelector
RelatedResourceSelector restricts which related objects are synced.
Appears in: - RelatedResource
| Field | Description | Default | Validation |
|---|---|---|---|
labelSelector LabelSelector |
labelSelector selects related objects by label. | Optional: {} |
|
names string array |
names selects related objects by exact name. | Optional: {} |
SchemaPolicy
SchemaPolicy controls schema source, pull and update behavior.
Appears in: - ConnectionSpec
| Field | Description | Default | Validation |
|---|---|---|---|
source SchemaSource |
source selects how schemas are obtained: Auto - CRD if readable on the provider, else OpenAPI (default). CRD - read apiextensions CRDs verbatim. OpenAPI - synthesize CRDs from discovery + /openapi/v3. |
Auto | Enum: [Auto CRD OpenAPI] |
pullPolicy PullPolicy |
pullPolicy selects which exported APIs are installed: Bound - only APIs referenced by a Binding/ClusterBinding (default). All - every exported API readable by the credentials. None - never install CRDs (user/extension manages them). |
Bound | Enum: [Bound All None] |
updatePolicy UpdatePolicy |
updatePolicy selects whether installed schemas follow provider changes: Always - follow provider schema changes (default). Once - pin at first pull. |
Always | Enum: [Always Once] |
SchemaSource
Underlying type: string
SchemaSource selects how schemas are obtained from the provider.
Appears in: - ConnectionStatus - SchemaPolicy
| Field | Description |
|---|---|
Auto |
SchemaSourceAuto probes CRD first, falls back to OpenAPI. |
CRD |
SchemaSourceCRD reads apiextensions CRDs from the provider. |
OpenAPI |
SchemaSourceOpenAPI synthesizes CRDs from discovery + /openapi/v3. |
SecretKeyRef
SecretKeyRef references a key within a Secret. The Secret must live in the konnector's designated namespace; a cluster-scoped Connection may not reach into arbitrary namespaces (privilege-escalation guard, see proposal F1).
Appears in: - ConnectionSpec
| Field | Description | Default | Validation |
|---|---|---|---|
namespace string |
namespace of the Secret. Must be the konnector's designated namespace. | MinLength: 1 Required: {} Required: {} |
|
name string |
name of the Secret. | MinLength: 1 Required: {} Required: {} |
|
key string |
key within the Secret holding the kubeconfig. | kubeconfig |
SyncDirection
Underlying type: string
SyncDirection is the direction a related resource is synced.
Appears in: - RelatedResource
| Field | Description |
|---|---|
FromProvider |
FromProvider syncs the related resource provider -> consumer. |
FromConsumer |
FromConsumer syncs the related resource consumer -> provider. |
UpdatePolicy
Underlying type: string
UpdatePolicy selects whether installed schemas track provider changes.
Appears in: - SchemaPolicy
| Field | Description |
|---|---|
Always |
UpdatePolicyAlways follows provider schema changes. |
Once |
UpdatePolicyOnce pins the schema at first pull. |
iam.kbind.io/v1alpha1
Package v1alpha1 contains the issuance/identity API for the kbind service layer: the Grant kind in the iam.kbind.io group. A Grant is the typed record of "identity X was issued credentials Y for export Z" — the anchor for revocation, audit and the reaper. Kept out of catalog.kbind.io so that group stays purely presentation+defaults. Lives on the provider; the konnector never sees it. See docs/proposals/v2-extended.md.
Resource Types
Grant
Grant records that an identity was issued credentials for an export. The gateway creates it with the export's API list and defaults resolved in (issuance is a stable record even if the catalog entry changes later); the issuer controller provisions the tenancy boundary, ServiceAccount, RBAC and token from the spec and reports the artifacts in status. Deleting the Grant revokes: the issuer's cleanup finalizer unwinds everything it provisioned.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string |
iam.kbind.io/v1alpha1 |
||
kind string |
Grant |
||
metadata ObjectMeta |
Refer to Kubernetes API documentation for fields of metadata. |
||
spec GrantSpec |
Required: {} Required: {} |
||
status GrantStatus |
Optional: {} |
GrantSpec
GrantSpec is the issuance request/record.
Appears in: - Grant
| Field | Description | Default | Validation |
|---|---|---|---|
identity Identity |
identity is who the credentials were issued to. | Required: {} Required: {} |
|
exportName string |
exportName records which catalog Export this Grant was issued for. | MinLength: 1 Required: {} Required: {} |
|
apis APIRef array |
apis is the export's API list resolved at issuance time, by CRD name on the provider (" these. |
MinItems: 1 Required: {} Required: {} |
|
conflictPolicy ConflictPolicy |
conflictPolicy is the export's default conflict policy resolved at issuance time, copied into the generated bundle's ClusterBinding. |
Enum: [Fail Adopt] Optional: {} |
|
relatedResources RelatedResource array |
relatedResources are the export's related-resource selectors resolved at issuance time. They flow into the bundle's ClusterBinding and widen the issued RBAC (secrets/configmaps in the declared direction). |
Optional: {} |
GrantStatus
GrantStatus reports what the issuer provisioned.
Appears in: - Grant
| Field | Description | Default | Validation |
|---|---|---|---|
namespace string |
namespace is the per-consumer tenancy boundary on the provider. | Optional: {} |
|
serviceAccount string |
serviceAccount is the name of the issued ServiceAccount (in namespace). | Optional: {} |
|
tokenSecret string |
tokenSecret is the name of the long-lived SA token Secret (in namespace). The gateway reads it to assemble the bundle's kubeconfig. |
Optional: {} |
|
conditions Condition array |
conditions: Ready (credentials provisioned and token populated). | Optional: {} |
Identity
Identity is the consumer identity credentials were issued to. The tenancy key is issuer+"/"+subject, so the same human gets the same boundary on re-bind.
Appears in: - GrantSpec
| Field | Description | Default | Validation |
|---|---|---|---|
subject string |
subject is the stable identity key, " |
MinLength: 1 Required: {} Required: {} |
|
displayName string |
displayName is a human-facing name (e.g. email), informational only. | Optional: {} |
|
groups string array |
groups the identity carried at issuance, informational only. | Optional: {} |