Konfidence is pre-release software. Concepts and APIs are unstable and subject to change.
Skip to content

API Reference ​

Packages ​

konfidence.cloud/v1alpha1 ​

Package v1alpha1 contains API Schema definitions for the konfidence v1alpha1 API group.

Resource Types ​

ActivationTaskExecution ​

ActivationTaskExecution is the Schema for the ActivationTaskExecutions API

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringActivationTaskExecution
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec ActivationTaskExecutionSpecspec defines the desired state of ActivationTaskExecutionRequired: {}
status ActivationTaskExecutionStatusstatus defines the observed state of ActivationTaskExecutionOptional: {}

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: ActivationTaskExecution
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: activationtaskexecution-sample
spec:
  type: k8s-job
  spec: {
    "template": "refine-me"
  }
  vectorActivation: "activation-1"

ActivationTaskExecutionSpec ​

ActivationTaskExecutionSpec defines the desired state of ActivationTaskExecution

Appears in:

FieldDescriptionDefaultValidation
type string
spec RawExtension
vectorActivation stringVectorActivation is a temporary field that contains the name of the associated vectorActivation

ActivationTaskExecutionStatus ​

ActivationTaskExecutionStatus defines the observed state of ActivationTaskExecution.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array

ActivationTaskRegistration ​

ActivationTaskRegistration is the Schema for the activationtaskregistrations API

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringActivationTaskRegistration
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec ActivationTaskRegistrationSpecspec defines the desired state of ActivationTaskRegistrationRequired: {}
status ActivationTaskRegistrationStatusstatus defines the observed state of ActivationTaskRegistrationOptional: {}

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: ActivationTaskRegistration
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: activationtaskregistration-sample
spec:
  type: custom-k8s-activation
  spec: {}
  succeeds:
    - activation-A
    - activation-B
  precedes:
    - activation-C

ActivationTaskRegistrationSpec ​

ActivationTaskRegistrationSpec defines the desired state of ActivationTaskRegistration

Appears in:

FieldDescriptionDefaultValidation
type stringINSERT ADDITIONAL SPEC FIELDS - desired state of cluster
Important: Run "make" to regenerate code after modifying this file
The following markers will use OpenAPI v3 schema to validate the value
More info: https://book.kubebuilder.io/reference/markers/crd-validation.html
spec RawExtension
succeeds string array
precedes string array

ActivationTaskRegistrationStatus ​

ActivationTaskRegistrationStatus defines the observed state of ActivationTaskRegistration.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition arrayconditions represent the current state of the ActivationTaskRegistration resource.
Each condition has a unique type and reflects the status of a specific aspect of the resource.
Standard condition types include:
- "Available": the resource is fully functional
- "Progressing": the resource is being created or updated
- "Degraded": the resource failed to reach or maintain its desired state
The status of each condition is one of True, False, or Unknown.
Optional: {}

ArtifactDeployment ​

ArtifactDeployment is the Schema for the artifactdeployments API.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringArtifactDeployment
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec ArtifactDeploymentSpecSpec defines the desired state of the ArtifactDeployment and is immutable after it has been setOptional: {}
status ArtifactDeploymentStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: ArtifactDeployment
metadata:
  name: e9cea9b3764b9adda065f85acd63a42f04b69de2d42e9b7e4f9556913bb37abb
  namespace: default
spec:
  component:
    name: konfidence.cloud/podinfo-example
    resources:
      - content:
          helmChart: podinfo:6.9.1
          helmRepository: https://stefanprodan.github.io/podinfo
          type: helm
        name: sample-service-1-helm-chart
        type: helmChart
    version: 1.0.0
  manifest:
    allowReuse: true
    type: helm.konfidence.cloud
  taskManifests: [ ]

ArtifactDeploymentSpec ​

ArtifactDeploymentSpec defines the desired state of an ArtifactDeployment. It describes the artifact to be deployed, optional post-deployment tasks, and optional metadata derived from an OCM ComponentVersion. A deployer interprets the specification according to the artifact type in Manifest.Type.

Appears in:

FieldDescriptionDefaultValidation
manifest ArtifactManifestManifest contains information about the artifact itself and the deployer implementation responsible for handling it.
taskManifests TaskManifest arrayTaskManifests describes optional post-deployment tasks (commonly used for vector migrations such as database
schema updates). Tasks are executed after the artifact has been deployed and may form a dependency graph via
DependsOn.
component OCMComponentComponent contains OCM metadata associated with the artifact. This is a simplified mapping of the OCM ComponentVersion.

ArtifactDeploymentStatus ​

ArtifactDeploymentStatus defines the observed state of ArtifactDeployment.

Appears in:

FieldDescriptionDefaultValidation
observedGeneration integerObservedGeneration is the last observed generation.Optional: {}
conditions Condition arrayConditions describes the state of the deployment lifecycle. The following conditions are expected:
- ArtifactFetched: the artifact was successfully retrieved
- ArtifactDeployed: the artifact was successfully deployed
- AppHealthy: the deployer reports the workload as healthy
Conditions progress in a linear order:
ArtifactFetched -> ArtifactDeployed -> AppHealthy
Optional: {}
deploymentResult DeploymentResult arrayDeploymentResults captures structured outputs produced by the deployer during the deployment process—such as
computed DNS names, service endpoints, generated configuration, or other workload-specific details.
Results should be treated as immutable for a given generation and may be consumed by later stages of a vector
rollout (e.g., routing configuration).
Results are unique by (name, type).
Optional: {}

ArtifactManifest ​

ArtifactManifest describes the content of the artifact, thus it determines the deployer implementation responsible for handling it.

Appears in:

FieldDescriptionDefaultValidation
type stringType specifies the name of the DeploymentClass that should handle this artifact (e.g., "helm.konfidence.cloud").
This must match a DeploymentClass.metadata.name in the cluster.
Deployers implement their own interpretation of the artifact's contents.
allowReuse booleanAllowReuse indicates whether the deployed artifact instance may be shared across multiple VectorDeployments.
Reuse allows more efficient resource consumption but requires the artifact to be independent of vector-specific
runtime context.

Component ​

Component defines a component of a VectorTemplate. A struct is used for future expansion.

Appears in:

FieldDescriptionDefaultValidation
name string

ComponentDeploymentResults ​

Underlying type: DeploymentResult

ComponentDeploymentResults lists the deployment results emitted by a single component.

Validation:

  • MaxItems: 16

Appears in:

FieldDescriptionDefaultValidation
name stringName identifies the result.MaxLength: 253
type stringType describes the structure contained in Spec. Each deployer may define multiple result types.MaxLength: 63
spec RawExtensionSpec contains deployer-specific structured data. Its format is determined by the Type field.

ConnectionRef ​

ConnectionRef identifies a Secret or ConfigMap in the same namespace.

Appears in:

FieldDescriptionDefaultValidation
apiGroup stringAPIGroup is the group for the resource being referenced.
Defaults to the core API group ("") for Secret and ConfigMap.
For deployer-specific CRDs, set this to the appropriate API group.
Optional: {}
kind stringKind is the resource kind (e.g., "Secret", "ConfigMap", or a deployer-specific kind).MaxLength: 64
MinLength: 1
Required: {}
name stringName is the name of the referenced resource.MaxLength: 253
MinLength: 1
Required: {}

CredentialRef ​

CredentialRef references a Secret in the same namespace as the holding resource.

Appears in:

FieldDescriptionDefaultValidation
name stringMinLength: 1

Credentials ​

Credentials holds credentials for various purposes — for example OCM repository access and signing/verification key material.

Appears in:

FieldDescriptionDefaultValidation
ocm OCMCredentialsOptional: {}

DeploymentClass ​

DeploymentClass declares a deployment capability provided by a deployer (controller). It is a cluster-scoped resource installed by deployers to advertise their capabilities. Its immutable spec ensures that ownership of resources using the class cannot change on the fly. Its metadata.name is the deployment class identifier referenced by ArtifactDeployments and DeploymentTargets. The name must be unique across all DeploymentClasses in the cluster and should follow the pattern <class-name>.<vendor-domain> (e.g., helm.konfidence.cloud).

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringDeploymentClass
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec DeploymentClassSpec

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: DeploymentClass
metadata:
  name: kustomize.konfidence.cloud
spec:
  controller: konfidence.cloud/kubernetes-landscape-orchestrator

DeploymentClassSpec ​

DeploymentClassSpec defines the desired state of DeploymentClass. It is immutable because changing it requires transfer of deployment ownership to a different controller. This process is currently not well-supported and is therefor not recommended.

Appears in:

FieldDescriptionDefaultValidation
controller stringController is the name of the controller that implements this deployment class.
This identifies which operator/controller is responsible for reconciling
resources of this deployment class (e.g., "kubernetes-landscape-orchestrator").
MaxLength: 253
MinLength: 1
Required: {}

DeploymentResult ​

DeploymentResult contains a single output produced by a deployer. These results are used to transport information from the deployer to later phases of the vector lifecycle.

Appears in:

FieldDescriptionDefaultValidation
name stringName identifies the result.MaxLength: 253
type stringType describes the structure contained in Spec. Each deployer may define multiple result types.MaxLength: 63
spec RawExtensionSpec contains deployer-specific structured data. Its format is determined by the Type field.

DeploymentTarget ​

DeploymentTarget is the Schema for the deploymenttargets API. A DeploymentTarget configures a concrete deployment destination within a landscape for a specific deployment class. It is namespace-scoped and created in landscape namespaces. Multiple DeploymentTargets can exist in the same landscape, but their deployment class names must be unique within the namespace.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringDeploymentTarget
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec DeploymentTargetSpec
status DeploymentTargetStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: DeploymentTarget
metadata:
  name: production-kustomize
  namespace: kden-l-production-abc123
spec:
  deploymentClassName: kustomize.konfidence.cloud
  connection:
    type: kubeconfig
    ref:
      kind: Secret
      name: prod-cluster-kubeconfig

DeploymentTargetConnection ​

DeploymentTargetConnection defines connection information for a deployment target.

Appears in:

FieldDescriptionDefaultValidation
type stringType is a hint for how to interpret the connection reference. It is advisory
and informational only. The deployer controller interprets and enforces its meaning.
MaxLength: 64
MinLength: 1
Required: {}
ref ConnectionRefRef references a resource containing connection details. This can be a Secret, ConfigMap,
or a custom resource defined by the deployer. The deployer is responsible for interpreting
and validating the referenced resource.
Optional: {}

DeploymentTargetSpec ​

DeploymentTargetSpec defines the desired state of DeploymentTarget.

Appears in:

FieldDescriptionDefaultValidation
deploymentClassName stringDeploymentClassName references a DeploymentClass by its metadata.name. The referenced DeploymentClass determines
which controller is responsible for reconciling the DeploymentTarget resource. If there is no DeploymentClass
with that name, the DeploymentTarget will be marked as not ready. DeploymentClassName
is immutable because changing it would transfer ownership of the DeploymentTarget to a different controller.
There can only be one DeploymentTarget for a given deployment class in a landscape, so DeploymentClassName must be unique
across DeploymentTargets in the same landscape namespace. This restriction might be loosened in future releases of
Konfidence.
Required: {}
connection DeploymentTargetConnectionConnection defines how to connect to this deployment target.
The structure and interpretation of connection details is specific to the
deployment class and its implementing controller.
Required: {}

DeploymentTargetStatus ​

DeploymentTargetStatus defines the observed state of DeploymentTarget. The deployer controller responsible for this target's DeploymentClass is expected to set the Ready condition once it has accepted the resource. What "accepted" means is up to the deployer. It may include connectivity checks or simply validate the configuration.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition arrayOptional: {}

GlobMatch ​

Underlying type: string

GlobMatch is a claim-value match pattern using glob semantics, where "" matches any run of characters (for example "repo:konfidence-project/").

Validation:

  • MaxLength: 512

Appears in:

JWKSSubject ​

JWKSSubject matches a workload token issued by a trusted OIDC provider, narrowed to a required audience and at least one token claim.

Appears in:

FieldDescriptionDefaultValidation
endpoint stringEndpoint is the OIDC discovery endpoint (the provider's
".well-known/openid-configuration" URL) used to resolve the signing keys
that the presented token is verified against.
MaxLength: 2048
Pattern: ^https://.*$
audience stringAudience is the value the token's "aud" claim must carry. It is required
so that a token minted for a different service cannot be replayed against
Konfidence: the token is accepted only if it was issued for this audience.
MaxLength: 512
MinLength: 1
claims object (keys:string, values:GlobMatch)Claims narrows the match to tokens whose claims match the given patterns.
It maps a claim name (for example "sub", "repository" or "ref") to a
glob pattern the claim value must match; all listed claims must match
(AND). At least one claim is required so a subject cannot inadvertently
match every token a provider issues.
MaxProperties: 32
MinProperties: 1

Landscape ​

Landscape is the Schema for the landscapes API. A Landscape owns a dedicated namespace that serves as a deployment target for vectors. Landscapes must be created in project namespaces. The landscape name is capped at 46 characters so the derived namespace name stays within the 63-character Kubernetes limits.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringLandscape
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec LandscapeSpec
status LandscapeStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: Landscape
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: sample-landscape
  namespace: kden-p-sample-project  # Must be created in a project namespace
spec:
  displayName: Sample Development Landscape
  # namespace: my-custom-landscape-namespace  # overrides the default "kden-l-sample-landscape-<hash>"

LandscapeSpec ​

LandscapeSpec defines the desired state of Landscape.

The transition rule catches namespace being set or unset after creation; changing a set namespace is caught by the field-level rule. The two rules are split to stay within the CEL cost budget of the schema.

Appears in:

FieldDescriptionDefaultValidation
displayName stringDisplayName is the human-readable name of the landscape, shown in user
interfaces. It does not affect the namespace name or any label, and it
may be changed at any time.
MaxLength: 253
MinLength: 1
Optional: {}
namespace stringNamespace overrides the name of the namespace created for this landscape.
When unset it defaults to kden-l-<landscape-name>-<hash>. It is
immutable once the Landscape exists, because the namespace and everything
it holds are bound to this name.
MaxLength: 63
Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
Optional: {}

LandscapeStatus ​

LandscapeStatus defines the observed state of Landscape.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array
namespace stringNamespace is the name of the namespace managed for this landscape.Optional: {}
projectName stringProjectName is the name of the project this landscape belongs to,
derived from the namespace where the Landscape CR was created.
Optional: {}

LocalArtifactDeploymentReference ​

LocalArtifactDeploymentReference holds a reference to an ArtifactDeployment in the same namespace.

Appears in:

FieldDescriptionDefaultValidation
name stringName is the name of the ArtifactDeployment. Required.
collisionCount integerCollisionCount salts the ArtifactDeployment name hash to recover from a
(rare) hash collision with a different artifact. nil and 0 both mean "no
salt" and yield the original, unsalted name. Once bumped it is permanent
for this artifact slot. Mirrors Deployment.Status.CollisionCount.
Optional: {}

LocalObjectReference ​

LocalObjectReference references an object by name within the same namespace as the parent.

Appears in:

FieldDescriptionDefaultValidation
name stringName of the referenced object.

LocalVectorAssignmentReference ​

LocalVectorAssignmentReference holds a reference to a VectorAssignment in the same namespace.

Appears in:

FieldDescriptionDefaultValidation
name stringName is the name of the VectorAssignment. Required.

LocalVectorDeploymentReference ​

LocalVectorDeploymentReference holds a reference to a VectorDeployment in the same namespace.

Appears in:

FieldDescriptionDefaultValidation
name stringName is the name of the VectorDeployment. Required.

OCMComponent ​

OCMComponent is a wrapper around the OCM ComponentVersion. It can be used to attach additional metadata to an ArtifactDeployment. The component may include one or more OCM resources.

Appears in:

FieldDescriptionDefaultValidation
name stringName is the OCM ComponentVersion name.
version stringVersion is the OCM ComponentVersion version.Optional: {}
resources OCMResource arrayResources contains OCM resources belonging to this component. The structure is intentionally generic to support
the requirements of deployers targeting different runtimes.
Optional: {}

OCMCredentials ​

OCMCredentials lists Secrets holding .ocmconfig or .dockerconfigjson data. All references are same-namespace.

Appears in:

FieldDescriptionDefaultValidation
refs CredentialRef arrayMinItems: 1

OCMResource ​

OCMResource represents a single resource of an OCM ComponentVersion. The content and type are deployer-specific and opaque to the API.

Appears in:

FieldDescriptionDefaultValidation
name stringName is the resource name.
content RawExtensionContent holds raw resource data, typically an embedded manifest, file, or
binary payload.
type stringType describes the resource type, following OCM conventions.

Project ​

Project is the Schema for the projects API. A Project owns a dedicated namespace that stores the project's resources. The project name is capped at 56 characters so the derived namespace name and label values stay within the 63-character Kubernetes limits.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringProject
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec ProjectSpec
status ProjectStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: Project
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: sample-project
spec:
  displayName: Sample Project
  # namespace: my-custom-namespace  # overrides the default "kden-p-sample-project"
  roleBindings:
    admin:
      - session:
          memberOf:
            - platform-admins
      - jwks:
          endpoint: https://token.actions.githubusercontent.com/.well-known/openid-configuration
          audience: https://konfidence.example/api
          claims:
            sub: repo:konfidence-project/konfidence:*
    pm:
      - session:
          memberOf:
            - sample-project-pms
    dev:
      - session:
          memberOf:
            - sample-project-devs

ProjectSpec ​

ProjectSpec defines the desired state of Project.

The transition rule catches namespace being set or unset after creation; changing a set namespace is caught by the field-level rule. The two rules are split to stay within the CEL cost budget of the schema.

Appears in:

FieldDescriptionDefaultValidation
displayName stringDisplayName is the human-readable name of the project, shown in user
interfaces. It does not affect the namespace name or any label, and it
may be changed at any time.
MaxLength: 253
MinLength: 1
Optional: {}
namespace stringNamespace overrides the name of the namespace created for this project.
When unset it defaults to kden-p-<project-name>. It is immutable
once the Project exists, because the namespace and everything it holds
are bound to this name.
MaxLength: 63
Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
Optional: {}
roleBindings object (keys:string, values:Subjects)RoleBindings grants project roles to callers. It maps a role name to the
list of subjects that hold that role; a caller holds the role if any
subject in the list matches (OR). The role names are a fixed, well-known
set for now (for example "admin", "pm", "dev"), but the field is a map so
the set can be extended without a schema change. See the Project
multi-tenancy ADR for the meaning of each role and the authorization flow.
RoleBindings is currently schema-only: no authorization is enforced yet.
MaxProperties: 32
Optional: {}

ProjectStatus ​

ProjectStatus defines the observed state of Project.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array
namespace stringNamespace is the name of the namespace managed for this project.Optional: {}

PromotionApproval ​

PromotionApproval records the granted approval.

Appears in:

FieldDescriptionDefaultValidation
approvedBy stringApprovedBy is the identity that granted the approval, as reported by the
konfidence API. The value is an opaque, arbitrary string (username,
email, subject, ...); it is recorded verbatim and never interpreted.
MinLength: 1
approvedAt TimeApprovedAt is the time the approval was granted.

PromotionSourceReference ​

PromotionSourceReference identifies the in-cluster resource whose current vector is promoted from. The source is resolved by the config reconciler, which pins the concrete vector into VectorPromotionSpec.Vector; the execution controller never reads it.

Appears in:

FieldDescriptionDefaultValidation
kind stringKind is the kind of the source resource. A VectorTemplate source
promotes its latest assembled vector; a Stage source promotes the
vector currently configured on that stage (spec.vector). Whether the resulting promotion
requires approval is recorded on the promotion itself
(VectorPromotionSpec.RequireApproval); the controller defaults it
from the source kind.
Enum: [VectorTemplate Stage]
name stringName is the name of the source resource.MaxLength: 253
MinLength: 1
landscape stringLandscape is the metadata.name of the Landscape in the config's
namespace (not its managed namespace) whose namespace hosts the
referenced Stage. Required for Stage references; must be omitted
for VectorTemplate references, which are resolved in the config's
namespace.
MaxLength: 63
MinLength: 1
Optional: {}

PromotionTargetReference ​

PromotionTargetReference identifies the Stage whose spec.vector is the promotion target.

Appears in:

FieldDescriptionDefaultValidation
kind stringKind is the kind of the target resource. Only Stage is supported.Enum: [Stage]
name stringName is the name of the target Stage.MaxLength: 253
MinLength: 1
landscape stringLandscape is the metadata.name of the Landscape in the config's
namespace (not its managed namespace) whose namespace hosts the target
Stage.
MaxLength: 63
MinLength: 1

SessionSubject ​

SessionSubject matches an interactive user by group membership.

Appears in:

FieldDescriptionDefaultValidation
memberOf string arrayMemberOf lists the groups that grant the role. Membership in any one of
the listed groups is sufficient to match (OR).
MaxItems: 64
MinItems: 1
items:MaxLength: 253

Sign ​

Sign lists signatures the controller produces on every descriptor it writes. Absence on a spec disables signing.

Appears in:

FieldDescriptionDefaultValidation
signatures Signature arrayMinItems: 1

Signature ​

Signature pins parameters of one named signature on a component descriptor. Used both for verification (matched against the fetched descriptor) and for signing (overrides defaults of the emitted signature).

Appears in:

FieldDescriptionDefaultValidation
name stringName is the unique identifier for this signature.MinLength: 1
algorithm stringAlgorithm specifies the RSA signing algorithm.
When omitted, RSASSA-PSS is used.
Valid values: RSASSA-PSS, RSASSA-PKCS1-V1_5.
Optional: {}
signatureMediaType stringSignatureMediaType specifies the encoding format for the signature bytes.
When omitted, application/x-pem-file (PEM) is used.
Valid values: application/x-pem-file, application/vnd.ocm.signature.rsa.pss,
application/vnd.ocm.signature.rsa.
Optional: {}
hashAlgorithm stringHashAlgorithm specifies the digest algorithm used when hashing the component descriptor.
When omitted, SHA-256 is used.
Valid values: SHA-256, SHA-512.
Optional: {}
normalisationAlgorithm stringNormalisationAlgorithm specifies the normalisation scheme applied to the descriptor
before hashing.
When omitted, jsonNormalisation/v4alpha1 is used.
Valid values: jsonNormalisation/v4alpha1.
Optional: {}
issuer stringIssuer pins the expected certificate issuer DN for PEM-encoded signatures.
On the sign path the value is stamped into the descriptor alongside the signature,
so it is enforced automatically on the verify path even without an explicit pin here.
On the verify path, when set, this value overrides whatever the descriptor stored and
the handler rejects any signature whose leaf certificate issuer DN does not match.
When omitted on both paths the issuer field stays empty and no DN check is performed.
Must be non-empty when present.
Optional: {}

Stage ​

Stage is the Schema for the stages API.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringStage
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec StageSpec
status StageStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: Stage
metadata:
  name: stage-dev
spec:
  vector: https://registry.kdenv.lab/ocm/vector//common.konfidence.cloud/example/vector:0.0.1

StageReference ​

StageReference holds a reference to a Stage in the same namespace.

Appears in:

FieldDescriptionDefaultValidation
name stringName is the name of the Stage. Required.

StageSpec ​

StageSpec defines the desired state of Stage.

Appears in:

FieldDescriptionDefaultValidation
vector stringVector points to the OCM component version that contains the deployment vector for this stage.MinLength: 1
Optional: {}

StageStatus ​

StageStatus defines the observed state of Stage.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array
vectorHistory string array
latestVectorDeploymentRef TypedObjectReference
activeStageVersion StageVersionReferenceActiveStageVersion references the StageVersion whose vector is currently
active on this stage, mirrored from the stage's active StageVersionUsage.
Optional: {}

StageVersion ​

StageVersion is the Schema for the stageversions API

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringStageVersion
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec StageVersionSpecSpec defines the desired state of the StageVersion and is immutable after it has been setOptional: {}
Required: {}
status StageVersionStatusstatus defines the observed state of StageVersionOptional: {}

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: StageVersion
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: stageversion-dev-475124
  ownerReferences:
    - apiVersion: konfidence.cloud/v1alpha1
      kind: Stage
      name: stage-dev
      uid: # TODO: add owner uid here after creating Stage resource
spec:
  vector: https://registry.kdenv.lab/ocm/vector//common.konfidence.cloud/example/vector:0.0.1
  stageGeneration: 1
  stageRef:
    name: stage-dev

StageVersionReference ​

StageVersionReference holds a reference to a StageVersion in the same namespace.

Appears in:

FieldDescriptionDefaultValidation
name stringName is the name of the StageVersion. Required.

StageVersionSpec ​

StageVersionSpec defines the desired state of StageVersion

Appears in:

FieldDescriptionDefaultValidation
vector stringVector points to the OCM component version that contains the deployment vector for this stage.MinLength: 1
stageGeneration integerthe object generation of the stage that created this stage versionMinimum: 1
stageRef StageReferencestageRef references the Stage this StageVersion belongs to

StageVersionStatus ​

StageVersionStatus defines the observed state of StageVersion.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array

StageVersionUsage ​

StageVersionUsage is the Schema for the stageversionusages API

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringStageVersionUsage
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec StageVersionUsageSpecspec defines the desired state of StageVersionUsageExactlyOneOf: [stageVersionRef stageVersionSelector]
Required: {}
status StageVersionUsageStatusstatus defines the observed state of StageVersionUsageOptional: {}

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: StageVersionUsage
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: stageversionusage-sample
spec:
  reason: Target usage for stage 'stage-dev'
  stageVersionRef:
    name: stageversion-dev-475124

StageVersionUsageSpec ​

StageVersionUsageSpec defines the desired state of StageVersionUsage

Validation:

  • ExactlyOneOf: [stageVersionRef stageVersionSelector]

Appears in:

FieldDescriptionDefaultValidation
reason stringReason is human-readable description of why this StageVersion is in use, e.g. "executing vector migrations", "latest vector for stage xyz",Optional: {}
stageVersionRef StageVersionReferenceStageVersionRef references a stageVersionOptional: {}
stageVersionSelector LabelSelectorStageVersionSelector is a label selector to find a StageVersion when name is not provided.Optional: {}

StageVersionUsageStatus ​

StageVersionUsageStatus defines the observed state of StageVersionUsage.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array
resolvedStageVersions string arrayResolvedStageVersions contains the names of all resolved stageVersion resources specified by either stageVersionRef or StageVersionSelector

Subject ​

Subject identifies who is granted a role. Exactly one identity source (session or jwks) must be set.

Appears in:

FieldDescriptionDefaultValidation
session SessionSubjectSession matches an interactively authenticated user by group membership,
for example a person signed in through the identity provider.
Optional: {}
jwks JWKSSubjectJWKS matches a workload identity presenting a token signed by a trusted
OIDC provider, for example a CI pipeline's OIDC token.
Optional: {}

Subjects ​

Underlying type: Subject

Subjects is the list of subjects that hold a role. A caller holds the role if any subject matches (OR).

Validation:

  • MaxItems: 32
  • MinItems: 1

Appears in:

FieldDescriptionDefaultValidation
session SessionSubjectSession matches an interactively authenticated user by group membership,
for example a person signed in through the identity provider.
Optional: {}
jwks JWKSSubjectJWKS matches a workload identity presenting a token signed by a trusted
OIDC provider, for example a CI pipeline's OIDC token.
Optional: {}

TaskExecution ​

TaskExecution is the Schema for the taskexecutions API

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringTaskExecution
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec TaskExecutionSpecspec defines the desired state of TaskExecutionRequired: {}
status TaskExecutionStatusstatus defines the observed state of TaskExecutionOptional: {}

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: TaskExecution
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: taskexecution-sample
spec:
  name: service2-task-1
  type: k8s-job
  dependsOn: [ ]
  spec: {
    "template": {
      "spec": {
        "containers": [
          {
            "name": "service1-task-1-container",
            "image": "registry.kdenv.lab/docker/sample-project/service1-task-1:0.0.1",
            "command": [
              "echo",
              "I am task 1 of service 1"
            ]
          }
        ]
      },
      "restartPolicy": "Never"
    },
    "backoffLimit": 4
  }

TaskExecutionSpec ​

TaskExecutionSpec defines the desired state of TaskExecution

Appears in:

FieldDescriptionDefaultValidation
name string
type string
dependsOn string array
spec RawExtension

TaskExecutionStatus ​

TaskExecutionStatus defines the observed state of TaskExecution.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array

TaskManifest ​

TaskManifest defines a post-deployment task that is executed after the artifact has been deployed. Tasks are commonly used for vector migrations (such as database schema changes) but may represent any post-deployment action.

Tasks form a directed acyclic graph (DAG) at the vector level rather than only within a single ArtifactDeployment. A task may depend on tasks belonging to other microservices or artifacts in the same VectorDeployment. These cross-artifact dependencies allow defining a globally ordered migration or transformation workflow.

The controller responsible for the task type interprets the Spec field and performs the execution once all declared dependencies have completed successfully.

Appears in:

FieldDescriptionDefaultValidation
name stringName uniquely identifies this task within the entire vector. This name may be referenced by other tasks across
different artifacts.
type stringType specifies the task controller or execution runtime (e.g. "k8s-job", or any custom task runtime). Different
task types correspond to different task controllers, each interpreting the Spec field according to their own semantics.
dependsOn string arrayDependsOn lists names of other tasks that must complete before this task may run. Dependencies may reference
tasks within the same artifact or any other artifact that participates in the same VectorDeployment, allowing the
formation of a vector-wide DAG.
Optional: {}
spec RawExtensionSpec contains task-specific configuration. The structure depends on the task Type and is interpreted by the
corresponding task controller.

VectorActivation ​

VectorActivation is the Schema for the vectoractivations API

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringVectorActivation
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec VectorActivationSpecspec defines the desired state of VectorActivationRequired: {}
status VectorActivationStatusstatus defines the observed state of VectorActivationOptional: {}

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: VectorActivation
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: vectoractivation-sample
  ownerReferences:
    - apiVersion: konfidence.cloud/v1alpha1
      kind: StageVersion
      name: <OWNER-NAME> # TODO: add stage version name here
      uid: <OWNER-UID>‚ # TODO: add stage version uid here
spec:
  # TODO: clarify if stageVersion is required here since it is also in OwnerReferences
  stage: stage-dev
  stageVersion: <STAGE-VERSION-NAME> # TODO: add stage version name here
  vector: https://registry.kdenv.lab/ocm/vector//common.konfidence.cloud/example/vector:0.0.1
  vectorDeployment: common.konfidence.cloud.example.vector-0.0.1

VectorActivationSpec ​

VectorActivationSpec defines the desired state of VectorActivation

Appears in:

FieldDescriptionDefaultValidation
stage string
stageVersion string
vector stringVector points to the OCM component version that contains the deployment vector for this stage.
vectorDeployment string

VectorActivationStatus ​

VectorActivationStatus defines the observed state of VectorActivation.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array

VectorAssignment ​

VectorAssignment is the Schema for the vectorassignments API.

A VectorAssignment represents a single binding between a VectorDeployment and an ArtifactDeployment. It enables an n:m mapping where a single artifact may be reused across multiple vectors. These objects are automatically managed by the vector-deployment-controller and reconciled by deployers to apply vector-specific configuration.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringVectorAssignment
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec VectorAssignmentSpecSpec defines the desired state of the VectorAssignment and is immutable after it has been setOptional: {}
status VectorAssignmentStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: VectorAssignment
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: vectorassignment-sample
spec:
  manifest:
    type: helm.konfidence.cloud
    allowReuse: true
  artifactDeploymentRef:
    name: artifactdeployment-1
  vectorDeploymentRef:
    name: vectordeployment-1

VectorAssignmentSpec ​

VectorAssignmentSpec defines the desired state of a VectorAssignment.

A VectorAssignment represents one logical binding between a VectorDeployment and an ArtifactDeployment. Since a single artifact may be reused across multiple vectors, an n:m relationship exists between vectors and artifacts. VectorAssignment creates a concrete instance of that relationship.

VectorAssignment resources are created automatically during vector rollouts and are typically not authored by users. Deployer implementations reconcile the VectorAssignment to perform vector-specific configuration based on the artifact selected for this vector.

The VectorAssignmentSpec is immutable. If an artifact is replaced or added to a different vector, the old VectorAssignment is deleted and a new one created.

Appears in:

FieldDescriptionDefaultValidation
manifest ArtifactManifestManifest contains the ArtifactManifest describing the artifact to be assigned to the vector. This duplicates the
manifest stored in the ArtifactDeployment for efficiency: deployers often need to filter or select assignments
by artifact type, and embedding the manifest avoids repeated API lookups.
artifactDeploymentRef LocalArtifactDeploymentReferenceArtifactDeploymentRef references the ArtifactDeployment instance that is associated with the vector. The
referenced artifact must exist in the same namespace as this VectorAssignment.
vectorDeploymentRef LocalVectorDeploymentReferenceVectorDeploymentRef references the VectorDeployment that this artifact is assigned to. This creates the explicit
mapping "artifact X belongs to vector Y".

VectorAssignmentStatus ​

VectorAssignmentStatus defines the observed state of a VectorAssignment.

A VectorAssignment progresses through a simple lifecycle driven by the deployer:

  1. VectorAssignment is created by the vector-deployment-controller.
  2. deployer reconciles it and configures vector-specific integration
  3. VectorAssignmentReadyCondition is set to True

Appears in:

FieldDescriptionDefaultValidation
conditions Condition arrayConditions describes the latest observed state of the assignment. The primary condition is
VectorAssignmentReadyCondition, which becomes True once the deployer has finished processing the VectorAssignment.
Optional: {}

VectorConfig ​

VectorConfig defines feature flags and authored configuration values for a vector.

Appears in:

FieldDescriptionDefaultValidation
features RawExtensionFeatures define the feature flags.
authored RawExtensionAuthored define the authored configuration values.

VectorData ​

VectorData is the schema for the vectordata API.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringVectorData
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec VectorDataSpecOptional: {}
status VectorDataStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: VectorData
metadata:
  name: vectordata-sample
spec:
  features:
    checkout-v2:
      enabled: true
  authored:
    replicas: 3
  deploymentResults:
    https://registry.kdenv.lab/ocm/vector//common.konfidence.cloud/example/vector/service1:
      - name: candidates
        type: http-k8s-service
        spec:
          namespace: dev
          k8sName: candidates
          servicePorts:
            - name: http
              port: 80

VectorDataSpec ​

VectorDataSpec is the LCP→landscape-orchestrator contract for vector-scoped data. The vector deployment controller resolves the OCM envelope {features, authored} and aggregates per-AD DeploymentResults; the landscape orchestrator materialises the payload on its target runtime (ConfigMap on K8s, etc.).

Appears in:

FieldDescriptionDefaultValidation
features RawExtensionFeatures carries the optional "features" subset of the OCM envelope, verbatim JSON.Optional: {}
authored RawExtensionAuthored carries the optional "authored" subset of the OCM envelope, verbatim JSON.Optional: {}
deploymentResults object (keys:string, values:ComponentDeploymentResults)DeploymentResults aggregated from underlying ArtifactDeployments, keyed by artifact
component name; the value lists every result emitted by that component. Within a
component's list, results are unique by (name, type).
MaxProperties: 64
Optional: {}

VectorDataStatus ​

Appears in:

FieldDescriptionDefaultValidation
conditions Condition arrayOptional: {}

VectorDeployment ​

VectorDeployment is the Schema for the vectordeployments API.

VectorDeployment represents the deployment of an immutable vector of artifacts into a specific environment or stage.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringVectorDeployment
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec VectorDeploymentSpecSpec defines the desired state of the VectorDeployment and is immutable after it has been setOptional: {}
status VectorDeploymentStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: VectorDeployment
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: common.konfidence.cloud.example.vector-0.0.1
spec:
  vector: https://registry.konfidence.cloud/ocm/vector//common.konfidence.cloud/example/vector:0.0.1

VectorDeploymentSpec ​

VectorDeploymentSpec defines the desired state of a VectorDeployment.

A VectorDeployment references a deployment vector stored as an OCM ComponentVersion in an OCI registry. The vector describes a complete, immutable set of artifacts and versions that should be deployed as a unit.

The value must always be a fully qualified OCI URL and must resolve to a valid OCM ComponentVersion. The VectorDeployment spec is intended to be immutable. Any substantive change should result in a new VectorDeployment instance rather than updating an existing one.

Appears in:

FieldDescriptionDefaultValidation
vector stringVector is a fully qualified URL pointing to an OCM ComponentVersion stored in an OCI registry. The referenced
component contains the deployment vector, which includes the complete list of artifacts and their versions.

VectorDeploymentStatus ​

VectorDeploymentStatus represents the observed state of a VectorDeployment as it progresses through the deployment lifecycle.

The lifecycle consists of:

  1. Pulling the vector from the OCI registry and parsing its contents -> VectorDownloadedCondition
  2. Creating (or re-using) one ArtifactDeployment per artifact in the vector -> ArtifactDeploymentsCreatedCondition
  3. Waiting until all ArtifactDeployments have successfully deployed -> VectorDeployedCondition
  4. Creating all VectorAssignment resources associated with this vector -> VectorAssignmentsCreatedCondition
  5. Creating the VectorData CR with the resolved authored configuration + aggregated DeploymentResults; the runtime-specific implementor then materialises it (e.g. as a ConfigMap on Kubernetes) -> VectorDataCreatedCondition
  6. Marking the vector as ready for use once VectorData reports its own Ready=True -> VectorReadyCondition

Appears in:

FieldDescriptionDefaultValidation
conditions Condition arrayConditions represents the current set of status conditions for this vector
deployment. These conditions track progress through the lifecycle stages.
resolvedVectorOcm stringResolvedVectorOcm contains the fully materialized content of the OCM ComponentVersion after it has been
downloaded and resolved from the OCI registry. Unlike the Spec.Vector value, which is only a reference (URL),
this field stores the actual resolved vector content as provided by OCM, including all artifacts and metadata.
It is not a reference but the inlined representation of the component version at reconciliation time.
resultingVectorData LocalObjectReferenceResultingVectorData records the name of the VectorData object created for this VectorDeployment. The VectorData
CR is the contract between the vector deployment controller (which resolves the OCM payload) and the runtime-specific implementor
(which materialises it on the target runtime). The field is empty until step 5 of the lifecycle has produced the
CR. Names are stable across reconciliations.
resultingArtifactDeployments object (keys:string, values:LocalArtifactDeploymentReference)ResultingArtifactDeployments lists the ArtifactDeployment resources created (or re-used) for this vector. The
map key is the component name of the artifact as defined inside the vector. Keys remain stable across
reconciliations and re-creations.
resultingVectorAssignments object (keys:string, values:LocalVectorAssignmentReference)ResultingVectorAssignments lists all VectorAssignment resources created for this vector. VectorAssignments are
not re-used like ArtifactDeployments, but instead each VectorDeployment results in a complete new set of
assignments.
The map key is the component name of the artifact. Keys are stable across reconcilations.
deploymentResults object (keys:string, values:ComponentDeploymentResults)DeploymentResults exposes an aggregated view of the deployment results produced
by all underlying ArtifactDeployments. The map key is the artifact component name;
the value lists every result emitted by that ArtifactDeployment. Within a component's
list, results are unique by (name, type).
MaxProperties: 64

VectorMigration ​

VectorMigration is the Schema for the vectormigrations API

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringVectorMigration
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec VectorMigrationSpecspec defines the desired state of VectorMigrationRequired: {}
status VectorMigrationStatusstatus defines the observed state of VectorMigrationOptional: {}

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: VectorMigration
metadata:
  labels:
    app.kubernetes.io/name: crds
  name: vectormigration-dev-985434
spec:
  stageVersion: stageversion-dev-475124
  vector: https://registry.konfidence.cloud/ocm/vector//common.konfidence.cloud/example/vector:0.0.1

VectorMigrationSpec ​

VectorMigrationSpec defines the desired state of VectorMigration

Appears in:

FieldDescriptionDefaultValidation
stageVersion string
vector stringVector points to the OCM component version that contains the deployment vector for this stage.

VectorMigrationStatus ​

VectorMigrationStatus defines the observed state of VectorMigration.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array

VectorPromotion ​

VectorPromotion triggers a one-time execution of a promotion flow defined by a VectorPromotionConfig.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringVectorPromotion
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec VectorPromotionSpec
status VectorPromotionStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: VectorPromotion
metadata:
  namespace: default
  name: sample-vector-promotion
spec:
  vectorPromotionConfigName: sample-promotion-config
  source:
    kind: VectorTemplate
    name: sample-vector-template
  target:
    kind: Stage
    name: sample-stage
    landscape: sample-landscape
  vector: registry.kdenv.lab/sample-project//konfidence-project.com/constructed-vector:2026.8.5-090000000Z
  requireApproval: false
  sequence: 1
  ttlAfterFinished: 1h

VectorPromotionConfig ​

VectorPromotionConfig describes a promotion flow for a vector between a source and a target.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringVectorPromotionConfig
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
spec VectorPromotionConfigSpecSpec defines the desired state of the VectorPromotionConfig.Optional: {}
status VectorPromotionConfigStatus

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: VectorPromotionConfig
metadata:
  namespace: kden-p-sample
  name: sample-promotion-config
spec:
  source:
    kind: VectorTemplate
    name: sample-vector-template
  target:
    kind: Stage
    name: sample-stage
    landscape: sample-landscape
  ttlAfterFinished: 1h

VectorPromotionConfigSpec ​

VectorPromotionConfigSpec defines the desired state of VectorPromotionConfig.

Appears in:

FieldDescriptionDefaultValidation
source PromotionSourceReferenceSource references the resource to promote from.
target PromotionTargetReferenceTarget references the Stage to promote to.
ttlAfterFinished DurationTTLAfterFinished will be copied onto every VectorPromotion the drift
controller creates for this config. See
VectorPromotionSpec.TTLAfterFinished.
Optional: {}
keepLastPromotions integerKeepLastPromotions bounds how many terminal VectorPromotions are
retained per config; the oldest beyond the bound are deleted. Retention
by count keeps an audit trail even when ttlAfterFinished is short.
Non-terminal promotions are never deleted and do not count toward the
bound.
10Minimum: 0
Optional: {}

VectorPromotionConfigStatus ​

VectorPromotionConfigStatus defines the observed state of VectorPromotionConfig.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition arrayConditions reports on the config itself, e.g. whether its references
resolve to existing resources. Promotion results are reported separately
in LastPromotionConditions.
lastPromotionConditions Condition arrayLastPromotionConditions contains the result of the most recent VectorPromotion execution
lastSuccessfulPromotionConditions Condition arrayLastSuccessfulPromotionConditions contains the result of the most recent VectorPromotion execution, that was successful
sequence integerSequence is the monotonic counter of promotions created for this config.
The config reconciler increments it and stamps the value into each
created promotion's spec.sequence.
Optional: {}

VectorPromotionSpec ​

VectorPromotionSpec defines the desired state of VectorPromotion.

Appears in:

FieldDescriptionDefaultValidation
vectorPromotionConfigName stringVectorPromotionConfigName is the name of the VectorPromotionConfig that defines the promotion flow to execute.MinLength: 1
source PromotionSourceReferenceSource is a snapshot of the config's source reference at creation time,
recorded so a promotion is self-describing.
target PromotionTargetReferenceTarget is a snapshot of the config's target reference at creation time.
Execution resolves and writes this target: approving a promotion approves
exactly this destination, regardless of later config edits.
vector stringVector is the concrete OCM component version reference
(<registry>//<component>:<version>) pinned when the promotion was created.
MinLength: 1
requireApproval booleanRequireApproval is true when the promotion must be approved before
execution; false means the promotion is approved automatically. It is
independent of the source kind: the config controller defaults it to
true for Stage sources, but any combination is valid.
falseOptional: {}
ttlAfterFinished DurationTTLAfterFinished defines how long the VectorPromotion should be kept after completion.
Once the TTL expires after the promotion reaches a terminal state (Completed or Failed),
the resource is eligible for automatic deletion. If no TTL is set, no deletion happens.
Optional: {}
sequence integerSequence is a monotonic ordinal assigned by the creator (the config
reconciler, from the config's status.sequence). It is the sole
ordering between promotions of the same config; creation timestamps
only have second resolution and are never consulted.
Minimum: 0

VectorPromotionState ​

Underlying type: string

VectorPromotionState summarizes the promotion lifecycle for display. Conditions are the source of truth; the state is derived from them.

Appears in:

FieldDescription
WaitingPromotionStateWaiting means at least one gate is still open: the
promotion requires approval and has not been approved yet.
ReadyPromotionStateReady means every gate has passed and the promotion is
queued for execution. Promotions that require no approval are Ready
from their first reconcile.
InProgressPromotionStateInProgress means the promotion is executing.
BlockedPromotionStateBlocked means the promotion is ready but cannot execute
because its target does not resolve; see the config's Ready condition.
SucceededPromotionStateSucceeded means the promotion completed successfully.
FailedPromotionStateFailed means the promotion reached a terminal state without success.
SupersededPromotionStateSuperseded means a newer promotion replaced this one.
Superseded promotions are locked: they can never be approved or
executed afterwards. The newer promotion is the one to act on.

VectorPromotionStatus ​

VectorPromotionStatus defines the observed state of VectorPromotion.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array
state VectorPromotionStateState summarizes Conditions for display. Conditions are the source of
truth; State is recomputed whenever conditions are written. Superseded
is a locked terminal state: a superseded promotion can never be
approved or executed afterwards, only its successor can.
Enum: [Waiting Ready InProgress Blocked Succeeded Failed Superseded]
Optional: {}
approval PromotionApprovalApproval records the granted approval. A promotion is approved at most
once; re-approval attempts are rejected.
Optional: {}
promotedStageRef TypedObjectReferencePromotedStageRef records the Stage this promotion actually wrote its
vector to, so the promotion is self-describing even after the config
changed or was deleted.
Optional: {}

VectorTemplate ​

VectorTemplate represents a template for assembling OCM components into an OCM component that represents a vector.

Appears in:

FieldDescriptionDefaultValidation
apiVersion stringkonfidence.cloud/v1alpha1
kind stringVectorTemplate
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Optional: {}
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Optional: {}
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec VectorTemplateSpecspec defines the desired state of VectorTemplateRequired: {}
status VectorTemplateStatusstatus defines the observed state of VectorTemplateOptional: {}

Example ​

yaml
apiVersion: konfidence.cloud/v1alpha1
kind: VectorTemplate
metadata:
  namespace: dev
  name: shopping-app
spec:
  # How often the assembly controller checks for drift. Optional; defaults to the
  # controller's built-in interval when omitted.
  reconcileInterval: 10m
  # Target OCM component the assembled vector is uploaded to. Must NOT carry a
  # version — the controller generates the assembled vector's version.
  # This is the full "shopping app" vector: base platform + application tier.
  uploadTarget: registry.kdenv.lab/shop//shop.example.com/vector/shopping-app
  # Optional base: the most recently assembled vector of the referenced
  # VectorTemplate is used as the base layer for this vector's assembly.
  # The base carries the shared platform services (identity, config, gateway,
  # notifications) that every environment inherits.
  base:
    kind: VectorTemplate
    name: shopping-app-base
  # Components pulled into the vector (at least one required). Each reference must
  # carry a version — a semantic version or a moving alias such as `stable`.
  # The application tier of the shop, layered on top of the base platform.
  components:
    - name: registry.kdenv.lab/shop//shop.example.com/storefront/web-bff:stable
    - name: registry.kdenv.lab/shop//shop.example.com/catalog/product-service:stable
    - name: registry.kdenv.lab/shop//shop.example.com/catalog/search-service:stable
    - name: registry.kdenv.lab/shop//shop.example.com/catalog/recommendation-service:stable
    - name: registry.kdenv.lab/shop//shop.example.com/cart/cart-service:stable
    - name: registry.kdenv.lab/shop//shop.example.com/checkout/checkout-service:stable
    - name: registry.kdenv.lab/shop//shop.example.com/checkout/payment-service:stable
    - name: registry.kdenv.lab/shop//shop.example.com/order/order-service:stable
    - name: registry.kdenv.lab/shop//shop.example.com/inventory/inventory-service:stable
    - name: registry.kdenv.lab/shop//shop.example.com/fulfilment/shipping-service:stable
  # Credentials for OCM repository access and signing/verification key material.
  # There is no separate signing/verify credential field: the controller feeds
  # these same refs to the OCI client, the signer, and the verifier. Each ref is
  # a same-namespace Secret holding .ocmconfig (which may carry RSA consumer
  # entries for signing/verify keys) or .dockerconfigjson data.
  credentials:
    ocm:
      refs:
        - name: registry-credentials
        - name: signing-keys
  # Verify every artifact pulled into the assembly against these candidate
  # signatures. Omit to disable artifact verification.
  verifyArtifacts:
    signatures:
      - name: konfidence
  # Verify any fetched vector (base or a pre-existing upload target) against
  # these candidate signatures. Omit to disable vector verification.
  verifyVector:
    signatures:
      - name: konfidence
  # Signatures the controller produces on the emitted vector. Omit to disable
  # signing. Algorithm/hash/media type default when unset.
  signVector:
    signatures:
      - name: konfidence
        algorithm: RSASSA-PSS
        hashAlgorithm: SHA-256
  # Feature flags and authored configuration baked into the vector.
  vectorConfig:
    features:
      express-checkout:
        enabled: true
      recommendations:
        enabled: true
    authored:
      storefrontReplicas: 3
      currency: EUR

VectorTemplateReference ​

VectorTemplateReference holds a reference to a VectorTemplate in the same namespace, used as the base of another VectorTemplate.

Appears in:

FieldDescriptionDefaultValidation
kind stringKind is the kind of the referenced object. Only VectorTemplate is supported for now.VectorTemplateEnum: [VectorTemplate]
name stringName is the name of the referenced VectorTemplate. Required.MinLength: 1

VectorTemplateSpec ​

VectorTemplateSpec defines the desired state of VectorTemplate. VectorTemplateSpec defines the components of which a vector is composed. From a VectorTemplate an OCM component is created which contains the latest version of all listed components.

Appears in:

FieldDescriptionDefaultValidation
reconcileInterval DurationReconcileInterval defines how often the assembly controller should check for drift.
If not set, the controller's default reconcile interval will be used.
Optional: {}
uploadTarget stringUploadTarget defines the target OCM component where the assembled vector will be uploaded.
base VectorTemplateReferenceBase references another VectorTemplate whose most recently assembled vector
(status.latestVector) is used as the base for this vector's assembly.
Optional: {}
Optional: {}
components Component arrayComponents lists the components to be included in the vector.MinItems: 1
credentials CredentialsCredentials supplies credentials for OCM repositories
and signing/verification key material.
Optional: {}
verifyArtifacts VerifyVerifyArtifacts lists candidate signatures evaluated against every
artifact pulled into the assembly. Absence disables artifact
verification.
Optional: {}
verifyVector VerifyVerifyVector lists candidate signatures evaluated against any
vector the assembly fetches (base or pre-existing upload target).
Absence disables vector verification.
Optional: {}
signVector SignSignVector lists signatures the controller produces on the emitted
vector. Absence disables signing.
Optional: {}
vectorConfig VectorConfigOptional: {}

VectorTemplateStatus ​

VectorTemplateStatus defines the observed state of VectorTemplate.

Appears in:

FieldDescriptionDefaultValidation
conditions Condition array
latestVector stringLatestVector is the concrete OCM component version of the most recently
assembled vector, in the form <repository>//<component>:<version>. It is
empty until the first successful assembly.
Optional: {}

Verify ​

Verify lists candidate signatures evaluated against every fetched descriptor. Absence on a spec disables verification.

Appears in:

FieldDescriptionDefaultValidation
signatures Signature arrayMinItems: 1
EU and German government funding logos

Funded by the European Union – NextGenerationEU.

The views and opinions expressed are solely those of the author(s) and do not necessarily reflect the views of the European Union or the European Commission. Neither the European Union nor the European Commission can be held responsible for them.