123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135 |
- ---
- apiVersion: v1
- kind: ServiceAccount
- metadata:
- name: strimzi-cluster-operator
- labels:
- app: strimzi
- namespace: kafka
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkas.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: Kafka
- listKind: KafkaList
- singular: kafka
- plural: kafkas
- shortNames:
- - k
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Desired Kafka replicas
- description: The desired number of Kafka replicas in the cluster
- jsonPath: .spec.kafka.replicas
- type: integer
- - name: Desired ZK replicas
- description: The desired number of ZooKeeper replicas in the cluster
- jsonPath: .spec.zookeeper.replicas
- type: integer
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- - name: Warnings
- description: Warnings related to the custom resource
- jsonPath: '.status.conditions[?(@.type=="Warning")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- kafka:
- type: object
- properties:
- version:
- type: string
- description: >-
- The kafka broker version. Defaults to
- {DefaultKafkaVersion}. Consult the user documentation to
- understand the process required to upgrade or downgrade
- the version.
- replicas:
- type: integer
- minimum: 1
- description: The number of pods in the cluster.
- image:
- type: string
- description: >-
- The docker image for the pods. The default value depends
- on the configured `Kafka.spec.kafka.version`.
- listeners:
- type: array
- minItems: 1
- items:
- type: object
- properties:
- name:
- type: string
- pattern: '^[a-z0-9]{1,11}$'
- description: >-
- Name of the listener. The name will be used to
- identify the listener and the related Kubernetes
- objects. The name has to be unique within given a
- Kafka cluster. The name can consist of lowercase
- characters and numbers and be up to 11 characters
- long.
- port:
- type: integer
- minimum: 9092
- description: >-
- Port number used by the listener inside Kafka. The
- port number has to be unique within a given Kafka
- cluster. Allowed port numbers are 9092 and higher
- with the exception of ports 9404 and 9999, which
- are already used for Prometheus and JMX. Depending
- on the listener type, the port number might not be
- the same as the port number that connects Kafka
- clients.
- type:
- type: string
- enum:
- - internal
- - route
- - loadbalancer
- - nodeport
- - ingress
- - cluster-ip
- description: >
- Type of the listener. Currently the supported
- types are `internal`, `route`, `loadbalancer`,
- `nodeport` and `ingress`.
- * `internal` type exposes Kafka internally only
- within the Kubernetes cluster.
- * `route` type uses OpenShift Routes to expose
- Kafka.
- * `loadbalancer` type uses LoadBalancer type
- services to expose Kafka.
- * `nodeport` type uses NodePort type services to
- expose Kafka.
- * `ingress` type uses Kubernetes Nginx Ingress to
- expose Kafka with TLS passthrough.
- * `cluster-ip` type uses a per-broker `ClusterIP`
- service.
- tls:
- type: boolean
- description: >-
- Enables TLS encryption on the listener. This is a
- required property.
- authentication:
- type: object
- properties:
- accessTokenIsJwt:
- type: boolean
- description: >-
- Configure whether the access token is treated
- as JWT. This must be set to `false` if the
- authorization server returns opaque tokens.
- Defaults to `true`.
- checkAccessTokenType:
- type: boolean
- description: >-
- Configure whether the access token type check
- is performed or not. This should be set to
- `false` if the authorization server does not
- include 'typ' claim in JWT token. Defaults to
- `true`.
- checkAudience:
- type: boolean
- description: >-
- Enable or disable audience checking. Audience
- checks identify the recipients of tokens. If
- audience checking is enabled, the OAuth Client
- ID also has to be configured using the
- `clientId` property. The Kafka broker will
- reject tokens that do not have its `clientId`
- in their `aud` (audience) claim.Default value
- is `false`.
- checkIssuer:
- type: boolean
- description: >-
- Enable or disable issuer checking. By default
- issuer is checked using the value configured
- by `validIssuerUri`. Default value is `true`.
- clientAudience:
- type: string
- description: >-
- The audience to use when making requests to
- the authorization server's token endpoint.
- Used for inter-broker authentication and for
- configuring OAuth 2.0 over PLAIN using the
- `clientId` and `secret` method.
- clientId:
- type: string
- description: >-
- OAuth Client ID which the Kafka broker can use
- to authenticate against the authorization
- server and use the introspect endpoint URI.
- clientScope:
- type: string
- description: >-
- The scope to use when making requests to the
- authorization server's token endpoint. Used
- for inter-broker authentication and for
- configuring OAuth 2.0 over PLAIN using the
- `clientId` and `secret` method.
- clientSecret:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is
- stored in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret
- containing the secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the OAuth
- client secret which the Kafka broker can use
- to authenticate against the authorization
- server and use the introspect endpoint URI.
- connectTimeoutSeconds:
- type: integer
- description: >-
- The connect timeout in seconds when connecting
- to authorization server. If not set, the
- effective connect timeout is 60 seconds.
- customClaimCheck:
- type: string
- description: >-
- JsonPath filter query to be applied to the JWT
- token or to the response of the introspection
- endpoint for additional token validation. Not
- set by default.
- disableTlsHostnameVerification:
- type: boolean
- description: >-
- Enable or disable TLS hostname verification.
- Default value is `false`.
- enableECDSA:
- type: boolean
- description: >-
- Enable or disable ECDSA support by installing
- BouncyCastle crypto provider. ECDSA support is
- always enabled. The BouncyCastle libraries are
- no longer packaged with Strimzi. Value is
- ignored.
- enableMetrics:
- type: boolean
- description: >-
- Enable or disable OAuth metrics. Default value
- is `false`.
- enableOauthBearer:
- type: boolean
- description: >-
- Enable or disable OAuth authentication over
- SASL_OAUTHBEARER. Default value is `true`.
- enablePlain:
- type: boolean
- description: >-
- Enable or disable OAuth authentication over
- SASL_PLAIN. There is no re-authentication
- support when this mechanism is used. Default
- value is `false`.
- failFast:
- type: boolean
- description: >-
- Enable or disable termination of Kafka broker
- processes due to potentially recoverable
- runtime errors during startup. Default value
- is `true`.
- fallbackUserNameClaim:
- type: string
- description: >-
- The fallback username claim to be used for the
- user id if the claim specified by
- `userNameClaim` is not present. This is useful
- when `client_credentials` authentication only
- results in the client id being provided in
- another claim. It only takes effect if
- `userNameClaim` is set.
- fallbackUserNamePrefix:
- type: string
- description: >-
- The prefix to use with the value of
- `fallbackUserNameClaim` to construct the user
- id. This only takes effect if
- `fallbackUserNameClaim` is true, and the value
- is present for the claim. Mapping usernames
- and client ids into the same user id space is
- useful in preventing name collisions.
- groupsClaim:
- type: string
- description: >-
- JsonPath query used to extract groups for the
- user during authentication. Extracted groups
- can be used by a custom authorizer. By default
- no groups are extracted.
- groupsClaimDelimiter:
- type: string
- description: >-
- A delimiter used to parse groups when they are
- extracted as a single String value rather than
- a JSON array. Default value is ',' (comma).
- httpRetries:
- type: integer
- description: >-
- The maximum number of retries to attempt if an
- initial HTTP request fails. If not set, the
- default is to not attempt any retries.
- httpRetryPauseMs:
- type: integer
- description: >-
- The pause to take before retrying a failed
- HTTP request. If not set, the default is to
- not pause at all but to immediately repeat a
- request.
- introspectionEndpointUri:
- type: string
- description: >-
- URI of the token introspection endpoint which
- can be used to validate opaque non-JWT tokens.
- jwksEndpointUri:
- type: string
- description: >-
- URI of the JWKS certificate endpoint, which
- can be used for local JWT validation.
- jwksExpirySeconds:
- type: integer
- minimum: 1
- description: >-
- Configures how often are the JWKS certificates
- considered valid. The expiry interval has to
- be at least 60 seconds longer then the refresh
- interval specified in `jwksRefreshSeconds`.
- Defaults to 360 seconds.
- jwksIgnoreKeyUse:
- type: boolean
- description: >-
- Flag to ignore the 'use' attribute of `key`
- declarations in a JWKS endpoint response.
- Default value is `false`.
- jwksMinRefreshPauseSeconds:
- type: integer
- minimum: 0
- description: >-
- The minimum pause between two consecutive
- refreshes. When an unknown signing key is
- encountered the refresh is scheduled
- immediately, but will always wait for this
- minimum pause. Defaults to 1 second.
- jwksRefreshSeconds:
- type: integer
- minimum: 1
- description: >-
- Configures how often are the JWKS certificates
- refreshed. The refresh interval has to be at
- least 60 seconds shorter then the expiry
- interval specified in `jwksExpirySeconds`.
- Defaults to 300 seconds.
- listenerConfig:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Configuration to be used for a specific
- listener. All values are prefixed with
- listener.name._<listener_name>_.
- maxSecondsWithoutReauthentication:
- type: integer
- description: >-
- Maximum number of seconds the authenticated
- session remains valid without
- re-authentication. This enables Apache Kafka
- re-authentication feature, and causes sessions
- to expire when the access token expires. If
- the access token expires before max time or if
- max time is reached, the client has to
- re-authenticate, otherwise the server will
- drop the connection. Not set by default - the
- authenticated session does not expire when the
- access token expires. This option only applies
- to SASL_OAUTHBEARER authentication mechanism
- (when `enableOauthBearer` is `true`).
- readTimeoutSeconds:
- type: integer
- description: >-
- The read timeout in seconds when connecting to
- authorization server. If not set, the
- effective read timeout is 60 seconds.
- sasl:
- type: boolean
- description: Enable or disable SASL on this listener.
- secrets:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is
- stored in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret
- containing the secret value.
- required:
- - key
- - secretName
- description: >-
- Secrets to be mounted to
- /opt/kafka/custom-authn-secrets/custom-listener-_<listener_name>-<port>_/_<secret_name>_.
- tlsTrustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - secretName
- description: >-
- Trusted certificates for TLS connection to the
- OAuth server.
- tokenEndpointUri:
- type: string
- description: >-
- URI of the Token Endpoint to use with
- SASL_PLAIN mechanism when the client
- authenticates with `clientId` and a `secret`.
- If set, the client can authenticate over
- SASL_PLAIN by either setting `username` to
- `clientId`, and setting `password` to client
- `secret`, or by setting `username` to account
- username, and `password` to access token
- prefixed with `$accessToken:`. If this option
- is not set, the `password` is always
- interpreted as an access token (without a
- prefix), and `username` as the account
- username (a so called 'no-client-credentials'
- mode).
- type:
- type: string
- enum:
- - tls
- - scram-sha-512
- - oauth
- - custom
- description: >-
- Authentication type. `oauth` type uses SASL
- OAUTHBEARER Authentication. `scram-sha-512`
- type uses SASL SCRAM-SHA-512 Authentication.
- `tls` type uses TLS Client Authentication.
- `tls` type is supported only on TLS
- listeners.`custom` type allows for any
- authentication type to be used.
- userInfoEndpointUri:
- type: string
- description: >-
- URI of the User Info Endpoint to use as a
- fallback to obtaining the user id when the
- Introspection Endpoint does not return
- information that can be used for the user id.
- userNameClaim:
- type: string
- description: >-
- Name of the claim from the JWT authentication
- token, Introspection Endpoint response or User
- Info Endpoint response which will be used to
- extract the user id. Defaults to `sub`.
- validIssuerUri:
- type: string
- description: >-
- URI of the token issuer used for
- authentication.
- validTokenType:
- type: string
- description: >-
- Valid value for the `token_type` attribute
- returned by the Introspection Endpoint. No
- default value, and not checked by default.
- required:
- - type
- description: Authentication configuration for this listener.
- configuration:
- type: object
- properties:
- brokerCertChainAndKey:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- key:
- type: string
- description: The name of the private key in the Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - key
- - secretName
- description: >-
- Reference to the `Secret` which holds the
- certificate and private key pair which will be
- used for this listener. The certificate can
- optionally contain the whole chain. This field
- can be used only with listeners with enabled
- TLS encryption.
- externalTrafficPolicy:
- type: string
- enum:
- - Local
- - Cluster
- description: >-
- Specifies whether the service routes external
- traffic to node-local or cluster-wide
- endpoints. `Cluster` may cause a second hop to
- another node and obscures the client source
- IP. `Local` avoids a second hop for
- LoadBalancer and Nodeport type services and
- preserves the client source IP (when supported
- by the infrastructure). If unspecified,
- Kubernetes will use `Cluster` as the
- default.This field can be used only with
- `loadbalancer` or `nodeport` type listener.
- loadBalancerSourceRanges:
- type: array
- items:
- type: string
- description: >-
- A list of CIDR ranges (for example
- `10.0.0.0/8` or `130.211.204.1/32`) from which
- clients can connect to load balancer type
- listeners. If supported by the platform,
- traffic through the loadbalancer is restricted
- to the specified CIDR ranges. This field is
- applicable only for loadbalancer type services
- and is ignored if the cloud provider does not
- support the feature. This field can be used
- only with `loadbalancer` type listener.
- bootstrap:
- type: object
- properties:
- alternativeNames:
- type: array
- items:
- type: string
- description: >-
- Additional alternative names for the
- bootstrap service. The alternative names
- will be added to the list of subject
- alternative names of the TLS certificates.
- host:
- type: string
- description: >-
- The bootstrap host. This field will be
- used in the Ingress resource or in the
- Route resource to specify the desired
- hostname. This field can be used only with
- `route` (optional) or `ingress` (required)
- type listeners.
- nodePort:
- type: integer
- description: >-
- Node port for the bootstrap service. This
- field can be used only with `nodeport`
- type listener.
- loadBalancerIP:
- type: string
- description: >-
- The loadbalancer is requested with the IP
- address specified in this field. This
- feature depends on whether the underlying
- cloud provider supports specifying the
- `loadBalancerIP` when a load balancer is
- created. This field is ignored if the
- cloud provider does not support the
- feature.This field can be used only with
- `loadbalancer` type listener.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations that will be added to the
- `Ingress`, `Route`, or `Service` resource.
- You can use this field to configure DNS
- providers such as External DNS. This field
- can be used only with `loadbalancer`,
- `nodeport`, `route`, or `ingress` type
- listeners.
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Labels that will be added to the
- `Ingress`, `Route`, or `Service` resource.
- This field can be used only with
- `loadbalancer`, `nodeport`, `route`, or
- `ingress` type listeners.
- description: Bootstrap configuration.
- brokers:
- type: array
- items:
- type: object
- properties:
- broker:
- type: integer
- description: >-
- ID of the kafka broker (broker
- identifier). Broker IDs start from 0 and
- correspond to the number of broker
- replicas.
- advertisedHost:
- type: string
- description: >-
- The host name which will be used in the
- brokers' `advertised.brokers`.
- advertisedPort:
- type: integer
- description: >-
- The port number which will be used in
- the brokers' `advertised.brokers`.
- host:
- type: string
- description: >-
- The broker host. This field will be used
- in the Ingress resource or in the Route
- resource to specify the desired
- hostname. This field can be used only
- with `route` (optional) or `ingress`
- (required) type listeners.
- nodePort:
- type: integer
- description: >-
- Node port for the per-broker service.
- This field can be used only with
- `nodeport` type listener.
- loadBalancerIP:
- type: string
- description: >-
- The loadbalancer is requested with the
- IP address specified in this field. This
- feature depends on whether the
- underlying cloud provider supports
- specifying the `loadBalancerIP` when a
- load balancer is created. This field is
- ignored if the cloud provider does not
- support the feature.This field can be
- used only with `loadbalancer` type
- listener.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations that will be added to the
- `Ingress` or `Service` resource. You can
- use this field to configure DNS
- providers such as External DNS. This
- field can be used only with
- `loadbalancer`, `nodeport`, or `ingress`
- type listeners.
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Labels that will be added to the
- `Ingress`, `Route`, or `Service`
- resource. This field can be used only
- with `loadbalancer`, `nodeport`,
- `route`, or `ingress` type listeners.
- required:
- - broker
- description: Per-broker configurations.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the
- service. Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP
- family on single-stack clusters.
- `RequireDualStack` fails unless there are two
- IP families on dual-stack configured clusters.
- If unspecified, Kubernetes will choose the
- default value based on the service type.
- Available on Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the
- default value based on the `ipFamilyPolicy`
- setting. Available on Kubernetes 1.20 and
- newer.
- createBootstrapService:
- type: boolean
- description: >-
- Whether to create the bootstrap service or
- not. The bootstrap service is created by
- default (if not specified differently). This
- field can be used with the `loadBalancer` type
- listener.
- class:
- type: string
- description: >-
- Configures a specific class for `Ingress` and
- `LoadBalancer` that defines which controller
- will be used. This field can only be used with
- `ingress` and `loadbalancer` type listeners.
- If not specified, the default controller is
- used. For an `ingress` listener, set the
- `ingressClassName` property in the `Ingress`
- resources. For a `loadbalancer` listener, set
- the `loadBalancerClass` property in the
- `Service` resources.
- finalizers:
- type: array
- items:
- type: string
- description: >-
- A list of finalizers which will be configured
- for the `LoadBalancer` type Services created
- for this listener. If supported by the
- platform, the finalizer
- `service.kubernetes.io/load-balancer-cleanup`
- to make sure that the external load balancer
- is deleted together with the service.For more
- information, see
- https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#garbage-collecting-load-balancers.
- This field can be used only with
- `loadbalancer` type listeners.
- maxConnectionCreationRate:
- type: integer
- description: >-
- The maximum connection creation rate we allow
- in this listener at any time. New connections
- will be throttled if the limit is reached.
- maxConnections:
- type: integer
- description: >-
- The maximum number of connections we allow for
- this listener in the broker at any time. New
- connections are blocked if the limit is
- reached.
- preferredNodePortAddressType:
- type: string
- enum:
- - ExternalIP
- - ExternalDNS
- - InternalIP
- - InternalDNS
- - Hostname
- description: >-
- Defines which address type should be used as
- the node address. Available types are:
- `ExternalDNS`, `ExternalIP`, `InternalDNS`,
- `InternalIP` and `Hostname`. By default, the
- addresses will be used in the following order
- (the first one found will be used):
- * `ExternalDNS`
- * `ExternalIP`
- * `InternalDNS`
- * `InternalIP`
- * `Hostname`
- This field is used to select the preferred
- address type, which is checked first. If no
- address is found for this address type, the
- other types are checked in the default order.
- This field can only be used with `nodeport`
- type listener.
- useServiceDnsDomain:
- type: boolean
- description: >-
- Configures whether the Kubernetes service DNS
- domain should be used or not. If set to
- `true`, the generated addresses will contain
- the service DNS domain suffix (by default
- `.cluster.local`, can be configured using
- environment variable
- `KUBERNETES_SERVICE_DNS_DOMAIN`). Defaults to
- `false`.This field can be used only with
- `internal` and `cluster-ip` type listeners.
- description: Additional listener configuration.
- networkPolicyPeers:
- type: array
- items:
- type: object
- properties:
- ipBlock:
- type: object
- properties:
- cidr:
- type: string
- except:
- type: array
- items:
- type: string
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- podSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- List of peers which should be able to connect to
- this listener. Peers in this list are combined
- using a logical OR operation. If this field is
- empty or missing, all connections will be allowed
- for this listener. If this field is present and
- contains at least one item, the listener only
- allows the traffic which matches at least one item
- in this list.
- required:
- - name
- - port
- - type
- - tls
- description: Configures listeners of Kafka brokers.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Kafka broker config properties with the following
- prefixes cannot be set: listeners, advertised., broker.,
- listener., host.name, port, inter.broker.listener.name,
- sasl., ssl., security., password., log.dir,
- zookeeper.connect, zookeeper.set.acl, zookeeper.ssl,
- zookeeper.clientCnxnSocket, authorizer., super.user,
- cruise.control.metrics.topic,
- cruise.control.metrics.reporter.bootstrap.servers,node.id,
- process.roles, controller. (with the exception of:
- zookeeper.connection.timeout.ms,
- sasl.server.max.receive.size,ssl.cipher.suites,
- ssl.protocol, ssl.enabled.protocols,
- ssl.secure.random.implementation,cruise.control.metrics.topic.num.partitions,
- cruise.control.metrics.topic.replication.factor,
- cruise.control.metrics.topic.retention.ms,cruise.control.metrics.topic.auto.create.retries,
- cruise.control.metrics.topic.auto.create.timeout.ms,cruise.control.metrics.topic.min.insync.replicas,controller.quorum.election.backoff.max.ms,
- controller.quorum.election.timeout.ms,
- controller.quorum.fetch.timeout.ms).
- storage:
- type: object
- properties:
- class:
- type: string
- description: >-
- The storage class to use for dynamic volume
- allocation.
- deleteClaim:
- type: boolean
- description: >-
- Specifies if the persistent volume claim has to be
- deleted when the cluster is un-deployed.
- id:
- type: integer
- minimum: 0
- description: >-
- Storage identification number. It is mandatory only
- for storage volumes defined in a storage of type
- 'jbod'.
- overrides:
- type: array
- items:
- type: object
- properties:
- class:
- type: string
- description: >-
- The storage class to use for dynamic volume
- allocation for this broker.
- broker:
- type: integer
- description: Id of the kafka broker (broker identifier).
- description: >-
- Overrides for individual brokers. The `overrides`
- field allows to specify a different configuration
- for different brokers.
- selector:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Specifies a specific persistent volume to use. It
- contains key:value pairs representing labels for
- selecting such a volume.
- size:
- type: string
- description: >-
- When type=persistent-claim, defines the size of the
- persistent volume claim (i.e 1Gi). Mandatory when
- type=persistent-claim.
- sizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- When type=ephemeral, defines the total amount of
- local storage required for this EmptyDir volume (for
- example 1Gi).
- type:
- type: string
- enum:
- - ephemeral
- - persistent-claim
- - jbod
- description: >-
- Storage type, must be either 'ephemeral',
- 'persistent-claim', or 'jbod'.
- volumes:
- type: array
- items:
- type: object
- properties:
- class:
- type: string
- description: >-
- The storage class to use for dynamic volume
- allocation.
- deleteClaim:
- type: boolean
- description: >-
- Specifies if the persistent volume claim has
- to be deleted when the cluster is un-deployed.
- id:
- type: integer
- minimum: 0
- description: >-
- Storage identification number. It is mandatory
- only for storage volumes defined in a storage
- of type 'jbod'.
- overrides:
- type: array
- items:
- type: object
- properties:
- class:
- type: string
- description: >-
- The storage class to use for dynamic
- volume allocation for this broker.
- broker:
- type: integer
- description: >-
- Id of the kafka broker (broker
- identifier).
- description: >-
- Overrides for individual brokers. The
- `overrides` field allows to specify a
- different configuration for different brokers.
- selector:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Specifies a specific persistent volume to use.
- It contains key:value pairs representing
- labels for selecting such a volume.
- size:
- type: string
- description: >-
- When type=persistent-claim, defines the size
- of the persistent volume claim (i.e 1Gi).
- Mandatory when type=persistent-claim.
- sizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- When type=ephemeral, defines the total amount
- of local storage required for this EmptyDir
- volume (for example 1Gi).
- type:
- type: string
- enum:
- - ephemeral
- - persistent-claim
- description: >-
- Storage type, must be either 'ephemeral' or
- 'persistent-claim'.
- required:
- - type
- description: >-
- List of volumes as Storage objects representing the
- JBOD disks array.
- required:
- - type
- description: Storage configuration (disk). Cannot be updated.
- authorization:
- type: object
- properties:
- allowOnError:
- type: boolean
- description: >-
- Defines whether a Kafka client should be allowed or
- denied by default when the authorizer fails to query
- the Open Policy Agent, for example, when it is
- temporarily unavailable). Defaults to `false` - all
- actions will be denied.
- authorizerClass:
- type: string
- description: >-
- Authorization implementation class, which must be
- available in classpath.
- clientId:
- type: string
- description: >-
- OAuth Client ID which the Kafka client can use to
- authenticate against the OAuth server and use the
- token endpoint URI.
- connectTimeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The connect timeout in seconds when connecting to
- authorization server. If not set, the effective
- connect timeout is 60 seconds.
- delegateToKafkaAcls:
- type: boolean
- description: >-
- Whether authorization decision should be delegated
- to the 'Simple' authorizer if DENIED by Keycloak
- Authorization Services policies. Default value is
- `false`.
- disableTlsHostnameVerification:
- type: boolean
- description: >-
- Enable or disable TLS hostname verification. Default
- value is `false`.
- enableMetrics:
- type: boolean
- description: >-
- Enable or disable OAuth metrics. Default value is
- `false`.
- expireAfterMs:
- type: integer
- description: >-
- The expiration of the records kept in the local
- cache to avoid querying the Open Policy Agent for
- every request. Defines how often the cached
- authorization decisions are reloaded from the Open
- Policy Agent server. In milliseconds. Defaults to
- `3600000`.
- grantsRefreshPeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The time between two consecutive grants refresh runs
- in seconds. The default value is 60.
- grantsRefreshPoolSize:
- type: integer
- minimum: 1
- description: >-
- The number of threads to use to refresh grants for
- active sessions. The more threads, the more
- parallelism, so the sooner the job completes.
- However, using more threads places a heavier load on
- the authorization server. The default value is 5.
- httpRetries:
- type: integer
- minimum: 0
- description: >-
- The maximum number of retries to attempt if an
- initial HTTP request fails. If not set, the default
- is to not attempt any retries.
- initialCacheCapacity:
- type: integer
- description: >-
- Initial capacity of the local cache used by the
- authorizer to avoid querying the Open Policy Agent
- for every request Defaults to `5000`.
- maximumCacheSize:
- type: integer
- description: >-
- Maximum capacity of the local cache used by the
- authorizer to avoid querying the Open Policy Agent
- for every request. Defaults to `50000`.
- readTimeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The read timeout in seconds when connecting to
- authorization server. If not set, the effective read
- timeout is 60 seconds.
- superUsers:
- type: array
- items:
- type: string
- description: >-
- List of super users, which are user principals with
- unlimited access rights.
- supportsAdminApi:
- type: boolean
- description: >-
- Indicates whether the custom authorizer supports the
- APIs for managing ACLs using the Kafka Admin API.
- Defaults to `false`.
- tlsTrustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - secretName
- description: >-
- Trusted certificates for TLS connection to the OAuth
- server.
- tokenEndpointUri:
- type: string
- description: Authorization server token endpoint URI.
- type:
- type: string
- enum:
- - simple
- - opa
- - keycloak
- - custom
- description: >-
- Authorization type. Currently, the supported types
- are `simple`, `keycloak`, `opa` and `custom`.
- `simple` authorization type uses Kafka's
- `kafka.security.authorizer.AclAuthorizer` class for
- authorization. `keycloak` authorization type uses
- Keycloak Authorization Services for authorization.
- `opa` authorization type uses Open Policy Agent
- based authorization.`custom` authorization type uses
- user-provided implementation for authorization.
- url:
- type: string
- example: 'http://opa:8181/v1/data/kafka/authz/allow'
- description: >-
- The URL used to connect to the Open Policy Agent
- server. The URL has to include the policy which will
- be queried by the authorizer. This option is
- required.
- required:
- - type
- description: Authorization configuration for Kafka brokers.
- rack:
- type: object
- properties:
- topologyKey:
- type: string
- example: topology.kubernetes.io/zone
- description: >-
- A key that matches labels assigned to the Kubernetes
- cluster nodes. The value of the label is used to set
- a broker's `broker.rack` config, and the
- `client.rack` config for Kafka Connect or
- MirrorMaker 2.
- required:
- - topologyKey
- description: Configuration of the `broker.rack` broker config.
- brokerRackInitImage:
- type: string
- description: >-
- The image of the init container used for initializing
- the `broker.rack`.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults
- to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default
- to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults
- to 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default
- to 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults
- to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default
- to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults
- to 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default
- to 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging is
- enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will be
- passed using the `-D` option to the JVM.
- description: JVM Options for pods.
- jmxOptions:
- type: object
- properties:
- authentication:
- type: object
- properties:
- type:
- type: string
- enum:
- - password
- description: >-
- Authentication type. Currently the only
- supported types are `password`.`password` type
- creates a username and protected port with no
- TLS.
- required:
- - type
- description: >-
- Authentication configuration for connecting to the
- JMX port.
- description: JMX Options for Kafka brokers.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- metricsConfig:
- type: object
- properties:
- type:
- type: string
- enum:
- - jmxPrometheusExporter
- description: >-
- Metrics type. Only 'jmxPrometheusExporter' supported
- currently.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing
- the configuration.
- description: >-
- ConfigMap entry where the Prometheus JMX Exporter
- configuration is stored. For details of the
- structure of this configuration, see the
- {JMXExporter}.
- required:
- - type
- - valueFrom
- description: Metrics configuration.
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: 'Logging type, must be either ''inline'' or ''external''.'
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing
- the configuration.
- description: >-
- `ConfigMap` entry where the logging configuration is
- stored.
- required:
- - type
- description: Logging configuration for Kafka.
- template:
- type: object
- properties:
- statefulset:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- podManagementPolicy:
- type: string
- enum:
- - OrderedReady
- - Parallel
- description: >-
- PodManagementPolicy which will be used for this
- StatefulSet. Valid values are `Parallel` and
- `OrderedReady`. Defaults to `Parallel`.
- description: Template for Kafka `StatefulSet`.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same
- namespace to use for pulling any of the images
- used by this Pod. When the
- `STRIMZI_IMAGE_PULL_SECRETS` environment
- variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only
- the `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is
- ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and
- common container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds
- after the processes running in the pod are sent
- a termination signal, and the time when the
- processes are forcibly halted with a kill
- signal. Set this value to longer than the
- expected cleanup time for your process. Value
- must be a non-negative integer. A zero value
- indicates delete immediately. You might need to
- increase the grace period for very large Kafka
- clusters, so that the Kafka brokers have enough
- time to transfer their work to another broker
- before they are terminated. Defaults to 30
- seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler
- will be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an
- optional list of hosts and IPs that will be
- injected into the Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir
- volume (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services
- should be injected into Pod's environment
- variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for Kafka `Pods`.
- bootstrapService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the
- service. Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP
- family on single-stack clusters.
- `RequireDualStack` fails unless there are two IP
- families on dual-stack configured clusters. If
- unspecified, Kubernetes will choose the default
- value based on the service type. Available on
- Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for Kafka bootstrap `Service`.
- brokersService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the
- service. Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP
- family on single-stack clusters.
- `RequireDualStack` fails unless there are two IP
- families on dual-stack configured clusters. If
- unspecified, Kubernetes will choose the default
- value based on the service type. Available on
- Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for Kafka broker `Service`.
- externalBootstrapService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for Kafka external bootstrap `Service`.
- perPodService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: >-
- Template for Kafka per-pod `Services` used for
- access from outside of Kubernetes.
- externalBootstrapRoute:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for Kafka external bootstrap `Route`.
- perPodRoute:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: >-
- Template for Kafka per-pod `Routes` used for access
- from outside of OpenShift.
- externalBootstrapIngress:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for Kafka external bootstrap `Ingress`.
- perPodIngress:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: >-
- Template for Kafka per-pod `Ingress` used for access
- from outside of Kubernetes.
- persistentVolumeClaim:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for all Kafka `PersistentVolumeClaims`.
- podDisruptionBudget:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- maxUnavailable:
- type: integer
- minimum: 0
- description: >-
- Maximum number of unavailable pods to allow
- automatic Pod eviction. A Pod eviction is
- allowed when the `maxUnavailable` number of pods
- or fewer are unavailable after the eviction.
- Setting this value to 0 prevents all voluntary
- evictions, so the pods must be evicted manually.
- Defaults to 1.
- description: Template for Kafka `PodDisruptionBudget`.
- kafkaContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka broker container.
- initContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka init container.
- clusterCaCert:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: >-
- Template for Secret with Kafka Cluster certificate
- public key.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka service account.
- jmxSecret:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: >-
- Template for Secret of the Kafka Cluster JMX
- authentication.
- clusterRoleBinding:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka ClusterRoleBinding.
- podSet:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for Kafka `StrimziPodSet` resource.
- description: >-
- Template for Kafka cluster resources. The template
- allows users to specify how the Kubernetes resources are
- generated.
- required:
- - replicas
- - listeners
- - storage
- description: Configuration of the Kafka cluster.
- zookeeper:
- type: object
- properties:
- replicas:
- type: integer
- minimum: 1
- description: The number of pods in the cluster.
- image:
- type: string
- description: The docker image for the pods.
- storage:
- type: object
- properties:
- class:
- type: string
- description: >-
- The storage class to use for dynamic volume
- allocation.
- deleteClaim:
- type: boolean
- description: >-
- Specifies if the persistent volume claim has to be
- deleted when the cluster is un-deployed.
- id:
- type: integer
- minimum: 0
- description: >-
- Storage identification number. It is mandatory only
- for storage volumes defined in a storage of type
- 'jbod'.
- overrides:
- type: array
- items:
- type: object
- properties:
- class:
- type: string
- description: >-
- The storage class to use for dynamic volume
- allocation for this broker.
- broker:
- type: integer
- description: Id of the kafka broker (broker identifier).
- description: >-
- Overrides for individual brokers. The `overrides`
- field allows to specify a different configuration
- for different brokers.
- selector:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Specifies a specific persistent volume to use. It
- contains key:value pairs representing labels for
- selecting such a volume.
- size:
- type: string
- description: >-
- When type=persistent-claim, defines the size of the
- persistent volume claim (i.e 1Gi). Mandatory when
- type=persistent-claim.
- sizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- When type=ephemeral, defines the total amount of
- local storage required for this EmptyDir volume (for
- example 1Gi).
- type:
- type: string
- enum:
- - ephemeral
- - persistent-claim
- description: >-
- Storage type, must be either 'ephemeral' or
- 'persistent-claim'.
- required:
- - type
- description: Storage configuration (disk). Cannot be updated.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The ZooKeeper broker config. Properties with the
- following prefixes cannot be set: server., dataDir,
- dataLogDir, clientPort, authProvider, quorum.auth,
- requireClientAuthScheme, snapshot.trust.empty,
- standaloneEnabled, reconfigEnabled,
- 4lw.commands.whitelist, secureClientPort, ssl.,
- serverCnxnFactory, sslQuorum (with the exception of:
- ssl.protocol, ssl.quorum.protocol, ssl.enabledProtocols,
- ssl.quorum.enabledProtocols, ssl.ciphersuites,
- ssl.quorum.ciphersuites, ssl.hostnameVerification,
- ssl.quorum.hostnameVerification).
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults
- to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default
- to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults
- to 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default
- to 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults
- to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default
- to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults
- to 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default
- to 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging is
- enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will be
- passed using the `-D` option to the JVM.
- description: JVM Options for pods.
- jmxOptions:
- type: object
- properties:
- authentication:
- type: object
- properties:
- type:
- type: string
- enum:
- - password
- description: >-
- Authentication type. Currently the only
- supported types are `password`.`password` type
- creates a username and protected port with no
- TLS.
- required:
- - type
- description: >-
- Authentication configuration for connecting to the
- JMX port.
- description: JMX Options for Zookeeper nodes.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- metricsConfig:
- type: object
- properties:
- type:
- type: string
- enum:
- - jmxPrometheusExporter
- description: >-
- Metrics type. Only 'jmxPrometheusExporter' supported
- currently.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing
- the configuration.
- description: >-
- ConfigMap entry where the Prometheus JMX Exporter
- configuration is stored. For details of the
- structure of this configuration, see the
- {JMXExporter}.
- required:
- - type
- - valueFrom
- description: Metrics configuration.
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: 'Logging type, must be either ''inline'' or ''external''.'
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing
- the configuration.
- description: >-
- `ConfigMap` entry where the logging configuration is
- stored.
- required:
- - type
- description: Logging configuration for ZooKeeper.
- template:
- type: object
- properties:
- statefulset:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- podManagementPolicy:
- type: string
- enum:
- - OrderedReady
- - Parallel
- description: >-
- PodManagementPolicy which will be used for this
- StatefulSet. Valid values are `Parallel` and
- `OrderedReady`. Defaults to `Parallel`.
- description: Template for ZooKeeper `StatefulSet`.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same
- namespace to use for pulling any of the images
- used by this Pod. When the
- `STRIMZI_IMAGE_PULL_SECRETS` environment
- variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only
- the `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is
- ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and
- common container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds
- after the processes running in the pod are sent
- a termination signal, and the time when the
- processes are forcibly halted with a kill
- signal. Set this value to longer than the
- expected cleanup time for your process. Value
- must be a non-negative integer. A zero value
- indicates delete immediately. You might need to
- increase the grace period for very large Kafka
- clusters, so that the Kafka brokers have enough
- time to transfer their work to another broker
- before they are terminated. Defaults to 30
- seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler
- will be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an
- optional list of hosts and IPs that will be
- injected into the Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir
- volume (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services
- should be injected into Pod's environment
- variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for ZooKeeper `Pods`.
- clientService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the
- service. Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP
- family on single-stack clusters.
- `RequireDualStack` fails unless there are two IP
- families on dual-stack configured clusters. If
- unspecified, Kubernetes will choose the default
- value based on the service type. Available on
- Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for ZooKeeper client `Service`.
- nodesService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the
- service. Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP
- family on single-stack clusters.
- `RequireDualStack` fails unless there are two IP
- families on dual-stack configured clusters. If
- unspecified, Kubernetes will choose the default
- value based on the service type. Available on
- Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for ZooKeeper nodes `Service`.
- persistentVolumeClaim:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for all ZooKeeper `PersistentVolumeClaims`.
- podDisruptionBudget:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- maxUnavailable:
- type: integer
- minimum: 0
- description: >-
- Maximum number of unavailable pods to allow
- automatic Pod eviction. A Pod eviction is
- allowed when the `maxUnavailable` number of pods
- or fewer are unavailable after the eviction.
- Setting this value to 0 prevents all voluntary
- evictions, so the pods must be evicted manually.
- Defaults to 1.
- description: Template for ZooKeeper `PodDisruptionBudget`.
- zookeeperContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the ZooKeeper container.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the ZooKeeper service account.
- jmxSecret:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: >-
- Template for Secret of the Zookeeper Cluster JMX
- authentication.
- podSet:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for ZooKeeper `StrimziPodSet` resource.
- description: >-
- Template for ZooKeeper cluster resources. The template
- allows users to specify how the Kubernetes resources are
- generated.
- required:
- - replicas
- - storage
- description: Configuration of the ZooKeeper cluster.
- entityOperator:
- type: object
- properties:
- topicOperator:
- type: object
- properties:
- watchedNamespace:
- type: string
- description: The namespace the Topic Operator should watch.
- image:
- type: string
- description: The image to use for the Topic Operator.
- reconciliationIntervalSeconds:
- type: integer
- minimum: 0
- description: Interval between periodic reconciliations.
- zookeeperSessionTimeoutSeconds:
- type: integer
- minimum: 0
- description: Timeout for the ZooKeeper session.
- startupProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod startup checking.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- topicMetadataMaxAttempts:
- type: integer
- minimum: 0
- description: The number of attempts at getting topic metadata.
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: >-
- Logging type, must be either 'inline' or
- 'external'.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap
- containing the configuration.
- description: >-
- `ConfigMap` entry where the logging
- configuration is stored.
- required:
- - type
- description: Logging configuration.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging
- is enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will
- be passed using the `-D` option to the JVM.
- description: JVM Options for pods.
- description: Configuration of the Topic Operator.
- userOperator:
- type: object
- properties:
- watchedNamespace:
- type: string
- description: The namespace the User Operator should watch.
- image:
- type: string
- description: The image to use for the User Operator.
- reconciliationIntervalSeconds:
- type: integer
- minimum: 0
- description: Interval between periodic reconciliations.
- zookeeperSessionTimeoutSeconds:
- type: integer
- minimum: 0
- description: Timeout for the ZooKeeper session.
- secretPrefix:
- type: string
- description: >-
- The prefix that will be added to the KafkaUser name
- to be used as the Secret name.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: >-
- Logging type, must be either 'inline' or
- 'external'.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap
- containing the configuration.
- description: >-
- `ConfigMap` entry where the logging
- configuration is stored.
- required:
- - type
- description: Logging configuration.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging
- is enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will
- be passed using the `-D` option to the JVM.
- description: JVM Options for pods.
- description: Configuration of the User Operator.
- tlsSidecar:
- type: object
- properties:
- image:
- type: string
- description: The docker image for the container.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- logLevel:
- type: string
- enum:
- - emerg
- - alert
- - crit
- - err
- - warning
- - notice
- - info
- - debug
- description: >-
- The log level for the TLS sidecar. Default value is
- `notice`.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- description: TLS sidecar configuration.
- template:
- type: object
- properties:
- deployment:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- deploymentStrategy:
- type: string
- enum:
- - RollingUpdate
- - Recreate
- description: >-
- Pod replacement strategy for deployment
- configuration changes. Valid values are
- `RollingUpdate` and `Recreate`. Defaults to
- `RollingUpdate`.
- description: Template for Entity Operator `Deployment`.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same
- namespace to use for pulling any of the images
- used by this Pod. When the
- `STRIMZI_IMAGE_PULL_SECRETS` environment
- variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only
- the `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is
- ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and
- common container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds
- after the processes running in the pod are sent
- a termination signal, and the time when the
- processes are forcibly halted with a kill
- signal. Set this value to longer than the
- expected cleanup time for your process. Value
- must be a non-negative integer. A zero value
- indicates delete immediately. You might need to
- increase the grace period for very large Kafka
- clusters, so that the Kafka brokers have enough
- time to transfer their work to another broker
- before they are terminated. Defaults to 30
- seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler
- will be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an
- optional list of hosts and IPs that will be
- injected into the Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir
- volume (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services
- should be injected into Pod's environment
- variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for Entity Operator `Pods`.
- topicOperatorContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Entity Topic Operator container.
- userOperatorContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Entity User Operator container.
- tlsSidecarContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: >-
- Template for the Entity Operator TLS sidecar
- container.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the Entity Operator service account.
- entityOperatorRole:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the Entity Operator Role.
- topicOperatorRoleBinding:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the Entity Topic Operator RoleBinding.
- userOperatorRoleBinding:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the Entity Topic Operator RoleBinding.
- description: >-
- Template for Entity Operator resources. The template
- allows users to specify how a `Deployment` and `Pod` is
- generated.
- description: Configuration of the Entity Operator.
- clusterCa:
- type: object
- properties:
- generateCertificateAuthority:
- type: boolean
- description: >-
- If true then Certificate Authority certificates will be
- generated automatically. Otherwise the user will need to
- provide a Secret with the CA certificate. Default is
- true.
- generateSecretOwnerReference:
- type: boolean
- description: >-
- If `true`, the Cluster and Client CA Secrets are
- configured with the `ownerReference` set to the `Kafka`
- resource. If the `Kafka` resource is deleted when
- `true`, the CA Secrets are also deleted. If `false`, the
- `ownerReference` is disabled. If the `Kafka` resource is
- deleted when `false`, the CA Secrets are retained and
- available for reuse. Default is `true`.
- validityDays:
- type: integer
- minimum: 1
- description: >-
- The number of days generated certificates should be
- valid for. The default is 365.
- renewalDays:
- type: integer
- minimum: 1
- description: >-
- The number of days in the certificate renewal period.
- This is the number of days before the a certificate
- expires during which renewal actions may be performed.
- When `generateCertificateAuthority` is true, this will
- cause the generation of a new certificate. When
- `generateCertificateAuthority` is true, this will cause
- extra logging at WARN level about the pending
- certificate expiry. Default is 30.
- certificateExpirationPolicy:
- type: string
- enum:
- - renew-certificate
- - replace-key
- description: >-
- How should CA certificate expiration be handled when
- `generateCertificateAuthority=true`. The default is for
- a new CA certificate to be generated reusing the
- existing private key.
- description: Configuration of the cluster certificate authority.
- clientsCa:
- type: object
- properties:
- generateCertificateAuthority:
- type: boolean
- description: >-
- If true then Certificate Authority certificates will be
- generated automatically. Otherwise the user will need to
- provide a Secret with the CA certificate. Default is
- true.
- generateSecretOwnerReference:
- type: boolean
- description: >-
- If `true`, the Cluster and Client CA Secrets are
- configured with the `ownerReference` set to the `Kafka`
- resource. If the `Kafka` resource is deleted when
- `true`, the CA Secrets are also deleted. If `false`, the
- `ownerReference` is disabled. If the `Kafka` resource is
- deleted when `false`, the CA Secrets are retained and
- available for reuse. Default is `true`.
- validityDays:
- type: integer
- minimum: 1
- description: >-
- The number of days generated certificates should be
- valid for. The default is 365.
- renewalDays:
- type: integer
- minimum: 1
- description: >-
- The number of days in the certificate renewal period.
- This is the number of days before the a certificate
- expires during which renewal actions may be performed.
- When `generateCertificateAuthority` is true, this will
- cause the generation of a new certificate. When
- `generateCertificateAuthority` is true, this will cause
- extra logging at WARN level about the pending
- certificate expiry. Default is 30.
- certificateExpirationPolicy:
- type: string
- enum:
- - renew-certificate
- - replace-key
- description: >-
- How should CA certificate expiration be handled when
- `generateCertificateAuthority=true`. The default is for
- a new CA certificate to be generated reusing the
- existing private key.
- description: Configuration of the clients certificate authority.
- cruiseControl:
- type: object
- properties:
- image:
- type: string
- description: The docker image for the pods.
- tlsSidecar:
- type: object
- properties:
- image:
- type: string
- description: The docker image for the container.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- logLevel:
- type: string
- enum:
- - emerg
- - alert
- - crit
- - err
- - warning
- - notice
- - info
- - debug
- description: >-
- The log level for the TLS sidecar. Default value is
- `notice`.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded.
- Defaults to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is
- first checked. Default to 15 seconds. Minimum
- value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe.
- Default to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to
- be considered successful after having failed.
- Defaults to 1. Must be 1 for liveness. Minimum
- value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check.
- Default to 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- description: TLS sidecar configuration.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- CPU and memory resources to reserve for the Cruise
- Control container.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults
- to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default
- to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults
- to 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default
- to 5 seconds. Minimum value is 1.
- description: Pod liveness checking for the Cruise Control container.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults
- to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default
- to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults
- to 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default
- to 5 seconds. Minimum value is 1.
- description: Pod readiness checking for the Cruise Control container.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging is
- enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will be
- passed using the `-D` option to the JVM.
- description: JVM Options for the Cruise Control container.
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: 'Logging type, must be either ''inline'' or ''external''.'
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing
- the configuration.
- description: >-
- `ConfigMap` entry where the logging configuration is
- stored.
- required:
- - type
- description: Logging configuration (Log4j 2) for Cruise Control.
- template:
- type: object
- properties:
- deployment:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- deploymentStrategy:
- type: string
- enum:
- - RollingUpdate
- - Recreate
- description: >-
- Pod replacement strategy for deployment
- configuration changes. Valid values are
- `RollingUpdate` and `Recreate`. Defaults to
- `RollingUpdate`.
- description: Template for Cruise Control `Deployment`.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same
- namespace to use for pulling any of the images
- used by this Pod. When the
- `STRIMZI_IMAGE_PULL_SECRETS` environment
- variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only
- the `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is
- ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and
- common container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds
- after the processes running in the pod are sent
- a termination signal, and the time when the
- processes are forcibly halted with a kill
- signal. Set this value to longer than the
- expected cleanup time for your process. Value
- must be a non-negative integer. A zero value
- indicates delete immediately. You might need to
- increase the grace period for very large Kafka
- clusters, so that the Kafka brokers have enough
- time to transfer their work to another broker
- before they are terminated. Defaults to 30
- seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler
- will be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an
- optional list of hosts and IPs that will be
- injected into the Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir
- volume (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services
- should be injected into Pod's environment
- variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for Cruise Control `Pods`.
- apiService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the
- service. Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP
- family on single-stack clusters.
- `RequireDualStack` fails unless there are two IP
- families on dual-stack configured clusters. If
- unspecified, Kubernetes will choose the default
- value based on the service type. Available on
- Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for Cruise Control API `Service`.
- podDisruptionBudget:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- maxUnavailable:
- type: integer
- minimum: 0
- description: >-
- Maximum number of unavailable pods to allow
- automatic Pod eviction. A Pod eviction is
- allowed when the `maxUnavailable` number of pods
- or fewer are unavailable after the eviction.
- Setting this value to 0 prevents all voluntary
- evictions, so the pods must be evicted manually.
- Defaults to 1.
- description: Template for Cruise Control `PodDisruptionBudget`.
- cruiseControlContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Cruise Control container.
- tlsSidecarContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: >-
- Template for the Cruise Control TLS sidecar
- container.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the Cruise Control service account.
- description: >-
- Template to specify how Cruise Control resources,
- `Deployments` and `Pods`, are generated.
- brokerCapacity:
- type: object
- properties:
- disk:
- type: string
- pattern: '^[0-9]+([.][0-9]*)?([KMGTPE]i?|e[0-9]+)?$'
- description: >-
- Broker capacity for disk in bytes. Use a number
- value with either standard Kubernetes byte units (K,
- M, G, or T), their bibyte (power of two) equivalents
- (Ki, Mi, Gi, or Ti), or a byte value with or without
- E notation. For example, 100000M, 100000Mi,
- 104857600000, or 1e+11.
- cpuUtilization:
- type: integer
- minimum: 0
- maximum: 100
- description: >-
- Broker capacity for CPU resource utilization as a
- percentage (0 - 100).
- cpu:
- type: string
- pattern: '^[0-9]+([.][0-9]{0,3}|[m]?)$'
- description: >-
- Broker capacity for CPU resource in cores or
- millicores. For example, 1, 1.500, 1500m. For more
- information on valid CPU resource units see
- https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu.
- inboundNetwork:
- type: string
- pattern: '^[0-9]+([KMG]i?)?B/s$'
- description: >-
- Broker capacity for inbound network throughput in
- bytes per second. Use an integer value with standard
- Kubernetes byte units (K, M, G) or their bibyte
- (power of two) equivalents (Ki, Mi, Gi) per second.
- For example, 10000KiB/s.
- outboundNetwork:
- type: string
- pattern: '^[0-9]+([KMG]i?)?B/s$'
- description: >-
- Broker capacity for outbound network throughput in
- bytes per second. Use an integer value with standard
- Kubernetes byte units (K, M, G) or their bibyte
- (power of two) equivalents (Ki, Mi, Gi) per second.
- For example, 10000KiB/s.
- overrides:
- type: array
- items:
- type: object
- properties:
- brokers:
- type: array
- items:
- type: integer
- description: List of Kafka brokers (broker identifiers).
- cpu:
- type: string
- pattern: '^[0-9]+([.][0-9]{0,3}|[m]?)$'
- description: >-
- Broker capacity for CPU resource in cores or
- millicores. For example, 1, 1.500, 1500m. For
- more information on valid CPU resource units
- see
- https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu.
- inboundNetwork:
- type: string
- pattern: '^[0-9]+([KMG]i?)?B/s$'
- description: >-
- Broker capacity for inbound network throughput
- in bytes per second. Use an integer value with
- standard Kubernetes byte units (K, M, G) or
- their bibyte (power of two) equivalents (Ki,
- Mi, Gi) per second. For example, 10000KiB/s.
- outboundNetwork:
- type: string
- pattern: '^[0-9]+([KMG]i?)?B/s$'
- description: >-
- Broker capacity for outbound network
- throughput in bytes per second. Use an integer
- value with standard Kubernetes byte units (K,
- M, G) or their bibyte (power of two)
- equivalents (Ki, Mi, Gi) per second. For
- example, 10000KiB/s.
- required:
- - brokers
- description: >-
- Overrides for individual brokers. The `overrides`
- property lets you specify a different capacity
- configuration for different brokers.
- description: The Cruise Control `brokerCapacity` configuration.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Cruise Control configuration. For a full list of
- configuration options refer to
- https://github.com/linkedin/cruise-control/wiki/Configurations.
- Note that properties with the following prefixes cannot
- be set: bootstrap.servers, client.id, zookeeper.,
- network., security.,
- failed.brokers.zk.path,webserver.http.,
- webserver.api.urlprefix, webserver.session.path,
- webserver.accesslog., two.step.,
- request.reason.required,metric.reporter.sampler.bootstrap.servers,
- capacity.config.file, self.healing., ssl.,
- kafka.broker.failure.detection.enable,
- topic.config.provider.class (with the exception of:
- ssl.cipher.suites, ssl.protocol, ssl.enabled.protocols,
- webserver.http.cors.enabled, webserver.http.cors.origin,
- webserver.http.cors.exposeheaders,
- webserver.security.enable, webserver.ssl.enable).
- metricsConfig:
- type: object
- properties:
- type:
- type: string
- enum:
- - jmxPrometheusExporter
- description: >-
- Metrics type. Only 'jmxPrometheusExporter' supported
- currently.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing
- the configuration.
- description: >-
- ConfigMap entry where the Prometheus JMX Exporter
- configuration is stored. For details of the
- structure of this configuration, see the
- {JMXExporter}.
- required:
- - type
- - valueFrom
- description: Metrics configuration.
- description: >-
- Configuration for Cruise Control deployment. Deploys a
- Cruise Control instance when specified.
- jmxTrans:
- type: object
- properties:
- image:
- type: string
- description: The image to use for the JmxTrans.
- outputDefinitions:
- type: array
- items:
- type: object
- properties:
- outputType:
- type: string
- description: >-
- Template for setting the format of the data that
- will be pushed.For more information see
- https://github.com/jmxtrans/jmxtrans/wiki/OutputWriters[JmxTrans
- OutputWriters].
- host:
- type: string
- description: >-
- The DNS/hostname of the remote host that the data
- is pushed to.
- port:
- type: integer
- description: >-
- The port of the remote host that the data is
- pushed to.
- flushDelayInSeconds:
- type: integer
- description: >-
- How many seconds the JmxTrans waits before pushing
- a new set of data out.
- typeNames:
- type: array
- items:
- type: string
- description: >-
- Template for filtering data to be included in
- response to a wildcard query. For more information
- see
- https://github.com/jmxtrans/jmxtrans/wiki/Queries[JmxTrans
- queries].
- name:
- type: string
- description: >-
- Template for setting the name of the output
- definition. This is used to identify where to send
- the results of queries should be sent.
- required:
- - outputType
- - name
- description: >-
- Defines the output hosts that will be referenced later
- on. For more information on these properties see,
- xref:type-JmxTransOutputDefinitionTemplate-reference[`JmxTransOutputDefinitionTemplate`
- schema reference].
- logLevel:
- type: string
- description: >-
- Sets the logging level of the JmxTrans deployment.For
- more information see,
- https://github.com/jmxtrans/jmxtrans-agent/wiki/Troubleshooting[JmxTrans
- Logging Level].
- kafkaQueries:
- type: array
- items:
- type: object
- properties:
- targetMBean:
- type: string
- description: >-
- If using wildcards instead of a specific MBean
- then the data is gathered from multiple MBeans.
- Otherwise if specifying an MBean then data is
- gathered from that specified MBean.
- attributes:
- type: array
- items:
- type: string
- description: >-
- Determine which attributes of the targeted MBean
- should be included.
- outputs:
- type: array
- items:
- type: string
- description: >-
- List of the names of output definitions specified
- in the spec.kafka.jmxTrans.outputDefinitions that
- have defined where JMX metrics are pushed to, and
- in which data format.
- required:
- - targetMBean
- - attributes
- - outputs
- description: >-
- Queries to send to the Kafka brokers to define what data
- should be read from each broker. For more information on
- these properties see,
- xref:type-JmxTransQueryTemplate-reference[`JmxTransQueryTemplate`
- schema reference].
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- template:
- type: object
- properties:
- deployment:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- deploymentStrategy:
- type: string
- enum:
- - RollingUpdate
- - Recreate
- description: >-
- Pod replacement strategy for deployment
- configuration changes. Valid values are
- `RollingUpdate` and `Recreate`. Defaults to
- `RollingUpdate`.
- description: Template for JmxTrans `Deployment`.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same
- namespace to use for pulling any of the images
- used by this Pod. When the
- `STRIMZI_IMAGE_PULL_SECRETS` environment
- variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only
- the `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is
- ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and
- common container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds
- after the processes running in the pod are sent
- a termination signal, and the time when the
- processes are forcibly halted with a kill
- signal. Set this value to longer than the
- expected cleanup time for your process. Value
- must be a non-negative integer. A zero value
- indicates delete immediately. You might need to
- increase the grace period for very large Kafka
- clusters, so that the Kafka brokers have enough
- time to transfer their work to another broker
- before they are terminated. Defaults to 30
- seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler
- will be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an
- optional list of hosts and IPs that will be
- injected into the Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir
- volume (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services
- should be injected into Pod's environment
- variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for JmxTrans `Pods`.
- container:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for JmxTrans container.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the JmxTrans service account.
- description: Template for JmxTrans resources.
- required:
- - outputDefinitions
- - kafkaQueries
- description: >-
- As of Strimzi 0.35.0, JMXTrans is not supported anymore and
- this option is ignored.
- kafkaExporter:
- type: object
- properties:
- image:
- type: string
- description: The docker image for the pods.
- groupRegex:
- type: string
- description: >-
- Regular expression to specify which consumer groups to
- collect. Default value is `.*`.
- topicRegex:
- type: string
- description: >-
- Regular expression to specify which topics to collect.
- Default value is `.*`.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- logging:
- type: string
- description: >-
- Only log messages with the given severity or above.
- Valid levels: [`info`, `debug`, `trace`]. Default log
- level is `info`.
- enableSaramaLogging:
- type: boolean
- description: >-
- Enable Sarama logging, a Go client library used by the
- Kafka Exporter.
- template:
- type: object
- properties:
- deployment:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- deploymentStrategy:
- type: string
- enum:
- - RollingUpdate
- - Recreate
- description: >-
- Pod replacement strategy for deployment
- configuration changes. Valid values are
- `RollingUpdate` and `Recreate`. Defaults to
- `RollingUpdate`.
- description: Template for Kafka Exporter `Deployment`.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same
- namespace to use for pulling any of the images
- used by this Pod. When the
- `STRIMZI_IMAGE_PULL_SECRETS` environment
- variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only
- the `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is
- ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and
- common container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds
- after the processes running in the pod are sent
- a termination signal, and the time when the
- processes are forcibly halted with a kill
- signal. Set this value to longer than the
- expected cleanup time for your process. Value
- must be a non-negative integer. A zero value
- indicates delete immediately. You might need to
- increase the grace period for very large Kafka
- clusters, so that the Kafka brokers have enough
- time to transfer their work to another broker
- before they are terminated. Defaults to 30
- seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler
- will be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an
- optional list of hosts and IPs that will be
- injected into the Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir
- volume (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services
- should be injected into Pod's environment
- variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for Kafka Exporter `Pods`.
- service:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for Kafka Exporter `Service`.
- container:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to
- the container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka Exporter container.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Annotations added to the Kubernetes
- resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Exporter service account.
- description: Customization of deployment templates and pods.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults
- to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default
- to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults
- to 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default
- to 5 seconds. Minimum value is 1.
- description: Pod liveness check.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults
- to 3. Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default
- to 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults
- to 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default
- to 5 seconds. Minimum value is 1.
- description: Pod readiness check.
- description: >-
- Configuration of the Kafka Exporter. Kafka Exporter can
- provide additional metrics, for example lag of consumer
- group at topic/partition.
- maintenanceTimeWindows:
- type: array
- items:
- type: string
- description: >-
- A list of time windows for maintenance tasks (that is,
- certificates renewal). Each time window is defined by a cron
- expression.
- required:
- - kafka
- - zookeeper
- description: >-
- The specification of the Kafka and ZooKeeper clusters, and Topic
- Operator.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- listeners:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- *The `type` property has been deprecated, and should
- now be configured using `name`.* The name of the
- listener.
- name:
- type: string
- description: The name of the listener.
- addresses:
- type: array
- items:
- type: object
- properties:
- host:
- type: string
- description: >-
- The DNS name or IP address of the Kafka
- bootstrap service.
- port:
- type: integer
- description: The port of the Kafka bootstrap service.
- description: A list of the addresses for this listener.
- bootstrapServers:
- type: string
- description: >-
- A comma-separated list of `host:port` pairs for
- connecting to the Kafka cluster using this listener.
- certificates:
- type: array
- items:
- type: string
- description: >-
- A list of TLS certificates which can be used to verify
- the identity of the server when connecting to the
- given listener. Set only for `tls` and `external`
- listeners.
- description: Addresses of the internal and external listeners.
- clusterId:
- type: string
- description: Kafka cluster Id.
- description: >-
- The status of the Kafka and ZooKeeper clusters, and Topic
- Operator.
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: strimzi-cluster-operator-global
- labels:
- app: strimzi
- rules:
- - apiGroups:
- - rbac.authorization.k8s.io
- resources:
- - clusterrolebindings
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - storage.k8s.io
- resources:
- - storageclasses
- verbs:
- - get
- - apiGroups:
- - ''
- resources:
- - nodes
- verbs:
- - list
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
- name: strimzi-cluster-operator-leader-election
- labels:
- app: strimzi
- namespace: kafka
- subjects:
- - kind: ServiceAccount
- name: strimzi-cluster-operator
- namespace: kafka
- roleRef:
- kind: ClusterRole
- name: strimzi-cluster-operator-leader-election
- apiGroup: rbac.authorization.k8s.io
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: strimzi-cluster-operator-leader-election
- labels:
- app: strimzi
- rules:
- - apiGroups:
- - coordination.k8s.io
- resources:
- - leases
- verbs:
- - create
- - apiGroups:
- - coordination.k8s.io
- resources:
- - leases
- resourceNames:
- - strimzi-cluster-operator
- verbs:
- - get
- - list
- - watch
- - delete
- - patch
- - update
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: strimzi-entity-operator
- labels:
- app: strimzi
- rules:
- - apiGroups:
- - kafka.strimzi.io
- resources:
- - kafkatopics
- - kafkatopics/status
- - kafkausers
- - kafkausers/status
- verbs:
- - get
- - list
- - watch
- - create
- - patch
- - update
- - delete
- - apiGroups:
- - ''
- resources:
- - events
- verbs:
- - create
- - apiGroups:
- - ''
- resources:
- - secrets
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: strimzi-cluster-operator-watched
- labels:
- app: strimzi
- rules:
- - apiGroups:
- - ''
- resources:
- - pods
- verbs:
- - watch
- - list
- - apiGroups:
- - kafka.strimzi.io
- resources:
- - kafkas
- - kafkas/status
- - kafkaconnects
- - kafkaconnects/status
- - kafkaconnectors
- - kafkaconnectors/status
- - kafkamirrormakers
- - kafkamirrormakers/status
- - kafkabridges
- - kafkabridges/status
- - kafkamirrormaker2s
- - kafkamirrormaker2s/status
- - kafkarebalances
- - kafkarebalances/status
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - core.strimzi.io
- resources:
- - strimzipodsets
- - strimzipodsets/status
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: strimzi-kafka-broker
- labels:
- app: strimzi
- rules:
- - apiGroups:
- - ''
- resources:
- - nodes
- verbs:
- - get
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkamirrormaker2s.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: KafkaMirrorMaker2
- listKind: KafkaMirrorMaker2List
- singular: kafkamirrormaker2
- plural: kafkamirrormaker2s
- shortNames:
- - kmm2
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- scale:
- specReplicasPath: .spec.replicas
- statusReplicasPath: .status.replicas
- labelSelectorPath: .status.labelSelector
- additionalPrinterColumns:
- - name: Desired replicas
- description: The desired number of Kafka MirrorMaker 2 replicas
- jsonPath: .spec.replicas
- type: integer
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- version:
- type: string
- description: >-
- The Kafka Connect version. Defaults to
- {DefaultKafkaVersion}. Consult the user documentation to
- understand the process required to upgrade or downgrade the
- version.
- replicas:
- type: integer
- description: >-
- The number of pods in the Kafka Connect group. Defaults to
- `3`.
- image:
- type: string
- description: The docker image for the pods.
- connectCluster:
- type: string
- description: >-
- The cluster alias used for Kafka Connect. The alias must
- match a cluster in the list at `spec.clusters`.
- clusters:
- type: array
- items:
- type: object
- properties:
- alias:
- type: string
- pattern: '^[a-zA-Z0-9\._\-]{1,100}$'
- description: Alias used to reference the Kafka cluster.
- bootstrapServers:
- type: string
- description: >-
- A comma-separated list of `host:port` pairs for
- establishing the connection to the Kafka cluster.
- tls:
- type: object
- properties:
- trustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - secretName
- description: Trusted certificates for TLS connection.
- description: >-
- TLS configuration for connecting MirrorMaker 2
- connectors to a cluster.
- authentication:
- type: object
- properties:
- accessToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing
- the secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the access
- token which was obtained from the authorization
- server.
- accessTokenIsJwt:
- type: boolean
- description: >-
- Configure whether access token should be treated
- as JWT. This should be set to `false` if the
- authorization server returns opaque tokens.
- Defaults to `true`.
- audience:
- type: string
- description: >-
- OAuth audience to use when authenticating against
- the authorization server. Some authorization
- servers require the audience to be explicitly set.
- The possible values depend on how the
- authorization server is configured. By default,
- `audience` is not specified when performing the
- token endpoint request.
- certificateAndKey:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- key:
- type: string
- description: The name of the private key in the Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - key
- - secretName
- description: >-
- Reference to the `Secret` which holds the
- certificate and private key pair.
- clientId:
- type: string
- description: >-
- OAuth Client ID which the Kafka client can use to
- authenticate against the OAuth server and use the
- token endpoint URI.
- clientSecret:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing
- the secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the OAuth
- client secret which the Kafka client can use to
- authenticate against the OAuth server and use the
- token endpoint URI.
- connectTimeoutSeconds:
- type: integer
- description: >-
- The connect timeout in seconds when connecting to
- authorization server. If not set, the effective
- connect timeout is 60 seconds.
- disableTlsHostnameVerification:
- type: boolean
- description: >-
- Enable or disable TLS hostname verification.
- Default value is `false`.
- enableMetrics:
- type: boolean
- description: >-
- Enable or disable OAuth metrics. Default value is
- `false`.
- httpRetries:
- type: integer
- description: >-
- The maximum number of retries to attempt if an
- initial HTTP request fails. If not set, the
- default is to not attempt any retries.
- httpRetryPauseMs:
- type: integer
- description: >-
- The pause to take before retrying a failed HTTP
- request. If not set, the default is to not pause
- at all but to immediately repeat a request.
- maxTokenExpirySeconds:
- type: integer
- description: >-
- Set or limit time-to-live of the access tokens to
- the specified number of seconds. This should be
- set if the authorization server returns opaque
- tokens.
- passwordSecret:
- type: object
- properties:
- password:
- type: string
- description: >-
- The name of the key in the Secret under which
- the password is stored.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- password.
- required:
- - password
- - secretName
- description: >-
- Reference to the `Secret` which holds the
- password.
- readTimeoutSeconds:
- type: integer
- description: >-
- The read timeout in seconds when connecting to
- authorization server. If not set, the effective
- read timeout is 60 seconds.
- refreshToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing
- the secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the refresh
- token which can be used to obtain access token
- from the authorization server.
- scope:
- type: string
- description: >-
- OAuth scope to use when authenticating against the
- authorization server. Some authorization servers
- require this to be set. The possible values depend
- on how authorization server is configured. By
- default `scope` is not specified when doing the
- token endpoint request.
- tlsTrustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - secretName
- description: >-
- Trusted certificates for TLS connection to the
- OAuth server.
- tokenEndpointUri:
- type: string
- description: Authorization server token endpoint URI.
- type:
- type: string
- enum:
- - tls
- - scram-sha-256
- - scram-sha-512
- - plain
- - oauth
- description: >-
- Authentication type. Currently the supported types
- are `tls`, `scram-sha-256`, `scram-sha-512`,
- `plain`, and 'oauth'. `scram-sha-256` and
- `scram-sha-512` types use SASL SCRAM-SHA-256 and
- SASL SCRAM-SHA-512 Authentication, respectively.
- `plain` type uses SASL PLAIN Authentication.
- `oauth` type uses SASL OAUTHBEARER Authentication.
- The `tls` type uses TLS Client Authentication. The
- `tls` type is supported only over TLS connections.
- username:
- type: string
- description: Username used for the authentication.
- required:
- - type
- description: >-
- Authentication configuration for connecting to the
- cluster.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The MirrorMaker 2 cluster config. Properties with the
- following prefixes cannot be set: ssl., sasl.,
- security., listeners, plugin.path, rest.,
- bootstrap.servers, consumer.interceptor.classes,
- producer.interceptor.classes (with the exception of:
- ssl.endpoint.identification.algorithm,
- ssl.cipher.suites, ssl.protocol,
- ssl.enabled.protocols).
- required:
- - alias
- - bootstrapServers
- description: Kafka clusters for mirroring.
- mirrors:
- type: array
- items:
- type: object
- properties:
- sourceCluster:
- type: string
- description: >-
- The alias of the source cluster used by the Kafka
- MirrorMaker 2 connectors. The alias must match a
- cluster in the list at `spec.clusters`.
- targetCluster:
- type: string
- description: >-
- The alias of the target cluster used by the Kafka
- MirrorMaker 2 connectors. The alias must match a
- cluster in the list at `spec.clusters`.
- sourceConnector:
- type: object
- properties:
- tasksMax:
- type: integer
- minimum: 1
- description: >-
- The maximum number of tasks for the Kafka
- Connector.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Kafka Connector configuration. The following
- properties cannot be set: connector.class,
- tasks.max.
- autoRestart:
- type: object
- properties:
- enabled:
- type: boolean
- description: >-
- Whether automatic restart for failed
- connectors and tasks should be enabled or
- disabled.
- description: >-
- Automatic restart of connector and tasks
- configuration.
- pause:
- type: boolean
- description: >-
- Whether the connector should be paused. Defaults
- to false.
- description: >-
- The specification of the Kafka MirrorMaker 2 source
- connector.
- heartbeatConnector:
- type: object
- properties:
- tasksMax:
- type: integer
- minimum: 1
- description: >-
- The maximum number of tasks for the Kafka
- Connector.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Kafka Connector configuration. The following
- properties cannot be set: connector.class,
- tasks.max.
- autoRestart:
- type: object
- properties:
- enabled:
- type: boolean
- description: >-
- Whether automatic restart for failed
- connectors and tasks should be enabled or
- disabled.
- description: >-
- Automatic restart of connector and tasks
- configuration.
- pause:
- type: boolean
- description: >-
- Whether the connector should be paused. Defaults
- to false.
- description: >-
- The specification of the Kafka MirrorMaker 2 heartbeat
- connector.
- checkpointConnector:
- type: object
- properties:
- tasksMax:
- type: integer
- minimum: 1
- description: >-
- The maximum number of tasks for the Kafka
- Connector.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Kafka Connector configuration. The following
- properties cannot be set: connector.class,
- tasks.max.
- autoRestart:
- type: object
- properties:
- enabled:
- type: boolean
- description: >-
- Whether automatic restart for failed
- connectors and tasks should be enabled or
- disabled.
- description: >-
- Automatic restart of connector and tasks
- configuration.
- pause:
- type: boolean
- description: >-
- Whether the connector should be paused. Defaults
- to false.
- description: >-
- The specification of the Kafka MirrorMaker 2
- checkpoint connector.
- topicsPattern:
- type: string
- description: >-
- A regular expression matching the topics to be
- mirrored, for example, "topic1\|topic2\|topic3".
- Comma-separated lists are also supported.
- topicsBlacklistPattern:
- type: string
- description: >-
- A regular expression matching the topics to exclude
- from mirroring. Comma-separated lists are also
- supported.
- topicsExcludePattern:
- type: string
- description: >-
- A regular expression matching the topics to exclude
- from mirroring. Comma-separated lists are also
- supported.
- groupsPattern:
- type: string
- description: >-
- A regular expression matching the consumer groups to
- be mirrored. Comma-separated lists are also supported.
- groupsBlacklistPattern:
- type: string
- description: >-
- A regular expression matching the consumer groups to
- exclude from mirroring. Comma-separated lists are also
- supported.
- groupsExcludePattern:
- type: string
- description: >-
- A regular expression matching the consumer groups to
- exclude from mirroring. Comma-separated lists are also
- supported.
- required:
- - sourceCluster
- - targetCluster
- description: Configuration of the MirrorMaker 2 connectors.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The maximum limits for CPU and memory resources and the
- requested initial resources.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults to 3.
- Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default to
- 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults to
- 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default to
- 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults to 3.
- Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default to
- 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults to
- 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default to
- 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging is
- enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will be
- passed using the `-D` option to the JVM.
- description: JVM Options for pods.
- jmxOptions:
- type: object
- properties:
- authentication:
- type: object
- properties:
- type:
- type: string
- enum:
- - password
- description: >-
- Authentication type. Currently the only supported
- types are `password`.`password` type creates a
- username and protected port with no TLS.
- required:
- - type
- description: >-
- Authentication configuration for connecting to the JMX
- port.
- description: JMX Options.
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: 'Logging type, must be either ''inline'' or ''external''.'
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing the
- configuration.
- description: >-
- `ConfigMap` entry where the logging configuration is
- stored.
- required:
- - type
- description: Logging configuration for Kafka Connect.
- clientRackInitImage:
- type: string
- description: >-
- The image of the init container used for initializing the
- `client.rack`.
- rack:
- type: object
- properties:
- topologyKey:
- type: string
- example: topology.kubernetes.io/zone
- description: >-
- A key that matches labels assigned to the Kubernetes
- cluster nodes. The value of the label is used to set a
- broker's `broker.rack` config, and the `client.rack`
- config for Kafka Connect or MirrorMaker 2.
- required:
- - topologyKey
- description: >-
- Configuration of the node label which will be used as the
- `client.rack` consumer configuration.
- tracing:
- type: object
- properties:
- type:
- type: string
- enum:
- - jaeger
- - opentelemetry
- description: >-
- Type of the tracing used. Currently the only supported
- types are `jaeger` for OpenTracing (Jaeger) tracing and
- `opentelemetry` for OpenTelemetry tracing. The
- OpenTracing (Jaeger) tracing is deprecated.
- required:
- - type
- description: The configuration of tracing in Kafka Connect.
- template:
- type: object
- properties:
- deployment:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- deploymentStrategy:
- type: string
- enum:
- - RollingUpdate
- - Recreate
- description: >-
- Pod replacement strategy for deployment
- configuration changes. Valid values are
- `RollingUpdate` and `Recreate`. Defaults to
- `RollingUpdate`.
- description: Template for Kafka Connect `Deployment`.
- podSet:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for Kafka Connect `StrimziPodSet` resource.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same namespace
- to use for pulling any of the images used by this
- Pod. When the `STRIMZI_IMAGE_PULL_SECRETS`
- environment variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only the
- `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and common
- container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds after
- the processes running in the pod are sent a
- termination signal, and the time when the processes
- are forcibly halted with a kill signal. Set this
- value to longer than the expected cleanup time for
- your process. Value must be a non-negative integer.
- A zero value indicates delete immediately. You might
- need to increase the grace period for very large
- Kafka clusters, so that the Kafka brokers have
- enough time to transfer their work to another broker
- before they are terminated. Defaults to 30 seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler will
- be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an optional
- list of hosts and IPs that will be injected into the
- Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir volume
- (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services should
- be injected into Pod's environment variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for Kafka Connect `Pods`.
- apiService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the service.
- Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP family
- on single-stack clusters. `RequireDualStack` fails
- unless there are two IP families on dual-stack
- configured clusters. If unspecified, Kubernetes will
- choose the default value based on the service type.
- Available on Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for Kafka Connect API `Service`.
- headlessService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the service.
- Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP family
- on single-stack clusters. `RequireDualStack` fails
- unless there are two IP families on dual-stack
- configured clusters. If unspecified, Kubernetes will
- choose the default value based on the service type.
- Available on Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for Kafka Connect headless `Service`.
- connectContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka Connect container.
- initContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka init container.
- podDisruptionBudget:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- maxUnavailable:
- type: integer
- minimum: 0
- description: >-
- Maximum number of unavailable pods to allow
- automatic Pod eviction. A Pod eviction is allowed
- when the `maxUnavailable` number of pods or fewer
- are unavailable after the eviction. Setting this
- value to 0 prevents all voluntary evictions, so the
- pods must be evicted manually. Defaults to 1.
- description: Template for Kafka Connect `PodDisruptionBudget`.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Connect service account.
- clusterRoleBinding:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Connect ClusterRoleBinding.
- buildPod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same namespace
- to use for pulling any of the images used by this
- Pod. When the `STRIMZI_IMAGE_PULL_SECRETS`
- environment variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only the
- `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and common
- container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds after
- the processes running in the pod are sent a
- termination signal, and the time when the processes
- are forcibly halted with a kill signal. Set this
- value to longer than the expected cleanup time for
- your process. Value must be a non-negative integer.
- A zero value indicates delete immediately. You might
- need to increase the grace period for very large
- Kafka clusters, so that the Kafka brokers have
- enough time to transfer their work to another broker
- before they are terminated. Defaults to 30 seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler will
- be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an optional
- list of hosts and IPs that will be injected into the
- Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir volume
- (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services should
- be injected into Pod's environment variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: >-
- Template for Kafka Connect Build `Pods`. The build pod
- is used only on Kubernetes.
- buildContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: >-
- Template for the Kafka Connect Build container. The
- build container is used only on Kubernetes.
- buildConfig:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- pullSecret:
- type: string
- description: >-
- Container Registry Secret with the credentials for
- pulling the base image.
- description: >-
- Template for the Kafka Connect BuildConfig used to build
- new container images. The BuildConfig is used only on
- OpenShift.
- buildServiceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Connect Build service account.
- jmxSecret:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: >-
- Template for Secret of the Kafka Connect Cluster JMX
- authentication.
- description: >-
- Template for Kafka Connect and Kafka Mirror Maker 2
- resources. The template allows users to specify how the
- `Deployment`, `Pods` and `Service` are generated.
- externalConfiguration:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- Name of the environment variable which will be
- passed to the Kafka Connect pods. The name of the
- environment variable cannot start with `KAFKA_` or
- `STRIMZI_`.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: Reference to a key in a ConfigMap.
- secretKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: Reference to a key in a Secret.
- description: >-
- Value of the environment variable which will be
- passed to the Kafka Connect pods. It can be passed
- either as a reference to Secret or ConfigMap
- field. The field has to specify exactly one Secret
- or ConfigMap.
- required:
- - name
- - valueFrom
- description: >-
- Makes data from a Secret or ConfigMap available in the
- Kafka Connect pods as environment variables.
- volumes:
- type: array
- items:
- type: object
- properties:
- configMap:
- type: object
- properties:
- defaultMode:
- type: integer
- items:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- mode:
- type: integer
- path:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to a key in a ConfigMap. Exactly one
- Secret or ConfigMap has to be specified.
- name:
- type: string
- description: >-
- Name of the volume which will be added to the
- Kafka Connect pods.
- secret:
- type: object
- properties:
- defaultMode:
- type: integer
- items:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- mode:
- type: integer
- path:
- type: string
- optional:
- type: boolean
- secretName:
- type: string
- description: >-
- Reference to a key in a Secret. Exactly one Secret
- or ConfigMap has to be specified.
- required:
- - name
- description: >-
- Makes data from a Secret or ConfigMap available in the
- Kafka Connect pods as volumes.
- description: >-
- Pass data from Secrets or ConfigMaps to the Kafka Connect
- pods and use them to configure connectors.
- metricsConfig:
- type: object
- properties:
- type:
- type: string
- enum:
- - jmxPrometheusExporter
- description: >-
- Metrics type. Only 'jmxPrometheusExporter' supported
- currently.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing the
- configuration.
- description: >-
- ConfigMap entry where the Prometheus JMX Exporter
- configuration is stored. For details of the structure of
- this configuration, see the {JMXExporter}.
- required:
- - type
- - valueFrom
- description: Metrics configuration.
- required:
- - connectCluster
- description: The specification of the Kafka MirrorMaker 2 cluster.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- url:
- type: string
- description: >-
- The URL of the REST API endpoint for managing and monitoring
- Kafka Connect connectors.
- autoRestartStatuses:
- type: array
- items:
- type: object
- properties:
- count:
- type: integer
- description: >-
- The number of times the connector or task is
- restarted.
- connectorName:
- type: string
- description: The name of the connector being restarted.
- lastRestartTimestamp:
- type: string
- description: >-
- The last time the automatic restart was attempted. The
- required format is 'yyyy-MM-ddTHH:mm:ssZ' in the UTC
- time zone.
- description: List of MirrorMaker 2 connector auto restart statuses.
- connectorPlugins:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The type of the connector plugin. The available types
- are `sink` and `source`.
- version:
- type: string
- description: The version of the connector plugin.
- class:
- type: string
- description: The class of the connector plugin.
- description: >-
- The list of connector plugins available in this Kafka
- Connect deployment.
- connectors:
- type: array
- items:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- List of MirrorMaker 2 connector statuses, as reported by the
- Kafka Connect REST API.
- labelSelector:
- type: string
- description: Label selector for pods providing this resource.
- replicas:
- type: integer
- description: >-
- The current number of pods being used to provide this
- resource.
- description: The status of the Kafka MirrorMaker 2 cluster.
- ---
- kind: ConfigMap
- apiVersion: v1
- metadata:
- name: strimzi-cluster-operator
- labels:
- app: strimzi
- namespace: kafka
- data:
- log4j2.properties: >
- name = COConfig
- monitorInterval = 30
- appender.console.type = Console
- appender.console.name = STDOUT
- appender.console.layout.type = PatternLayout
- appender.console.layout.pattern = %d{yyyy-MM-dd HH:mm:ss} %-5p %c{1}:%L -
- %m%n
- rootLogger.level = ${env:STRIMZI_LOG_LEVEL:-INFO}
- rootLogger.appenderRefs = stdout
- rootLogger.appenderRef.console.ref = STDOUT
- # Kafka AdminClient logging is a bit noisy at INFO level
- logger.kafka.name = org.apache.kafka
- logger.kafka.level = WARN
- # Zookeeper is very verbose even on INFO level -> We set it to WARN by
- default
- logger.zookeepertrustmanager.name = org.apache.zookeeper
- logger.zookeepertrustmanager.level = WARN
- # Keeps separate level for Netty logging -> to not be changed by the root
- logger
- logger.netty.name = io.netty
- logger.netty.level = INFO
- # Keeps separate log level for OkHttp client
- logger.okhttp3.name = okhttp3
- logger.okhttp3.level = INFO
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
- name: strimzi-cluster-operator-kafka-client-delegation
- labels:
- app: strimzi
- subjects:
- - kind: ServiceAccount
- name: strimzi-cluster-operator
- namespace: kafka
- roleRef:
- kind: ClusterRole
- name: strimzi-kafka-client
- apiGroup: rbac.authorization.k8s.io
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
- name: strimzi-cluster-operator
- labels:
- app: strimzi
- subjects:
- - kind: ServiceAccount
- name: strimzi-cluster-operator
- namespace: kafka
- roleRef:
- kind: ClusterRole
- name: strimzi-cluster-operator-global
- apiGroup: rbac.authorization.k8s.io
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkarebalances.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: KafkaRebalance
- listKind: KafkaRebalanceList
- singular: kafkarebalance
- plural: kafkarebalances
- shortNames:
- - kr
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Cluster
- description: The name of the Kafka cluster this resource rebalances
- jsonPath: .metadata.labels.strimzi\.io/cluster
- type: string
- - name: PendingProposal
- description: A proposal has been requested from Cruise Control
- jsonPath: '.status.conditions[?(@.type=="PendingProposal")].status'
- type: string
- - name: ProposalReady
- description: A proposal is ready and waiting for approval
- jsonPath: '.status.conditions[?(@.type=="ProposalReady")].status'
- type: string
- - name: Rebalancing
- description: Cruise Control is doing the rebalance
- jsonPath: '.status.conditions[?(@.type=="Rebalancing")].status'
- type: string
- - name: Ready
- description: The rebalance is complete
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- - name: NotReady
- description: There is an error on the custom resource
- jsonPath: '.status.conditions[?(@.type=="NotReady")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- mode:
- type: string
- enum:
- - full
- - add-brokers
- - remove-brokers
- description: >
- Mode to run the rebalancing. The supported modes are `full`,
- `add-brokers`, `remove-brokers`.
- If not specified, the `full` mode is used by default.
- * `full` mode runs the rebalancing across all the brokers in
- the cluster.
- * `add-brokers` mode can be used after scaling up the
- cluster to move some replicas to the newly added brokers.
- * `remove-brokers` mode can be used before scaling down the
- cluster to move replicas out of the brokers to be removed.
- brokers:
- type: array
- items:
- type: integer
- description: >-
- The list of newly added brokers in case of scaling up or the
- ones to be removed in case of scaling down to use for
- rebalancing. This list can be used only with rebalancing
- mode `add-brokers` and `removed-brokers`. It is ignored with
- `full` mode.
- goals:
- type: array
- items:
- type: string
- description: >-
- A list of goals, ordered by decreasing priority, to use for
- generating and executing the rebalance proposal. The
- supported goals are available at
- https://github.com/linkedin/cruise-control#goals. If an
- empty goals list is provided, the goals declared in the
- default.goals Cruise Control configuration parameter are
- used.
- skipHardGoalCheck:
- type: boolean
- description: >-
- Whether to allow the hard goals specified in the Kafka CR to
- be skipped in optimization proposal generation. This can be
- useful when some of those hard goals are preventing a
- balance solution being found. Default is false.
- rebalanceDisk:
- type: boolean
- description: >-
- Enables intra-broker disk balancing, which balances disk
- space utilization between disks on the same broker. Only
- applies to Kafka deployments that use JBOD storage with
- multiple disks. When enabled, inter-broker balancing is
- disabled. Default is false.
- excludedTopics:
- type: string
- description: >-
- A regular expression where any matching topics will be
- excluded from the calculation of optimization proposals.
- This expression will be parsed by the
- java.util.regex.Pattern class; for more information on the
- supported format consult the documentation for that class.
- concurrentPartitionMovementsPerBroker:
- type: integer
- minimum: 0
- description: >-
- The upper bound of ongoing partition replica movements going
- into/out of each broker. Default is 5.
- concurrentIntraBrokerPartitionMovements:
- type: integer
- minimum: 0
- description: >-
- The upper bound of ongoing partition replica movements
- between disks within each broker. Default is 2.
- concurrentLeaderMovements:
- type: integer
- minimum: 0
- description: >-
- The upper bound of ongoing partition leadership movements.
- Default is 1000.
- replicationThrottle:
- type: integer
- minimum: 0
- description: >-
- The upper bound, in bytes per second, on the bandwidth used
- to move replicas. There is no limit by default.
- replicaMovementStrategies:
- type: array
- items:
- type: string
- description: >-
- A list of strategy class names used to determine the
- execution order for the replica movements in the generated
- optimization proposal. By default
- BaseReplicaMovementStrategy is used, which will execute the
- replica movements in the order that they were generated.
- description: The specification of the Kafka rebalance.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- sessionId:
- type: string
- description: >-
- The session identifier for requests to Cruise Control
- pertaining to this KafkaRebalance resource. This is used by
- the Kafka Rebalance operator to track the status of ongoing
- rebalancing operations.
- optimizationResult:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A JSON object describing the optimization result.
- description: The status of the Kafka rebalance.
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: strimzi-cluster-operator-namespaced
- labels:
- app: strimzi
- rules:
- - apiGroups:
- - rbac.authorization.k8s.io
- resources:
- - rolebindings
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - rbac.authorization.k8s.io
- resources:
- - roles
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - ''
- resources:
- - pods
- - serviceaccounts
- - configmaps
- - services
- - endpoints
- - secrets
- - persistentvolumeclaims
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - apps
- resources:
- - deployments
- - deployments/scale
- - deployments/status
- - statefulsets
- - replicasets
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - ''
- - events.k8s.io
- resources:
- - events
- verbs:
- - create
- - apiGroups:
- - build.openshift.io
- resources:
- - buildconfigs
- - buildconfigs/instantiate
- - builds
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - networking.k8s.io
- resources:
- - networkpolicies
- - ingresses
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - route.openshift.io
- resources:
- - routes
- - routes/custom-host
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- - apiGroups:
- - image.openshift.io
- resources:
- - imagestreams
- verbs:
- - get
- - apiGroups:
- - policy
- resources:
- - poddisruptionbudgets
- verbs:
- - get
- - list
- - watch
- - create
- - delete
- - patch
- - update
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
- name: strimzi-cluster-operator-entity-operator-delegation
- labels:
- app: strimzi
- namespace: kafka
- subjects:
- - kind: ServiceAccount
- name: strimzi-cluster-operator
- namespace: kafka
- roleRef:
- kind: ClusterRole
- name: strimzi-entity-operator
- apiGroup: rbac.authorization.k8s.io
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkaconnects.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: KafkaConnect
- listKind: KafkaConnectList
- singular: kafkaconnect
- plural: kafkaconnects
- shortNames:
- - kc
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- scale:
- specReplicasPath: .spec.replicas
- statusReplicasPath: .status.replicas
- labelSelectorPath: .status.labelSelector
- additionalPrinterColumns:
- - name: Desired replicas
- description: The desired number of Kafka Connect replicas
- jsonPath: .spec.replicas
- type: integer
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- version:
- type: string
- description: >-
- The Kafka Connect version. Defaults to
- {DefaultKafkaVersion}. Consult the user documentation to
- understand the process required to upgrade or downgrade the
- version.
- replicas:
- type: integer
- description: >-
- The number of pods in the Kafka Connect group. Defaults to
- `3`.
- image:
- type: string
- description: The docker image for the pods.
- bootstrapServers:
- type: string
- description: >-
- Bootstrap servers to connect to. This should be given as a
- comma separated list of _<hostname>_:_<port>_ pairs.
- tls:
- type: object
- properties:
- trustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: The name of the file certificate in the Secret.
- secretName:
- type: string
- description: The name of the Secret containing the certificate.
- required:
- - certificate
- - secretName
- description: Trusted certificates for TLS connection.
- description: TLS configuration.
- authentication:
- type: object
- properties:
- accessToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored in
- the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the access token
- which was obtained from the authorization server.
- accessTokenIsJwt:
- type: boolean
- description: >-
- Configure whether access token should be treated as JWT.
- This should be set to `false` if the authorization
- server returns opaque tokens. Defaults to `true`.
- audience:
- type: string
- description: >-
- OAuth audience to use when authenticating against the
- authorization server. Some authorization servers require
- the audience to be explicitly set. The possible values
- depend on how the authorization server is configured. By
- default, `audience` is not specified when performing the
- token endpoint request.
- certificateAndKey:
- type: object
- properties:
- certificate:
- type: string
- description: The name of the file certificate in the Secret.
- key:
- type: string
- description: The name of the private key in the Secret.
- secretName:
- type: string
- description: The name of the Secret containing the certificate.
- required:
- - certificate
- - key
- - secretName
- description: >-
- Reference to the `Secret` which holds the certificate
- and private key pair.
- clientId:
- type: string
- description: >-
- OAuth Client ID which the Kafka client can use to
- authenticate against the OAuth server and use the token
- endpoint URI.
- clientSecret:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored in
- the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the OAuth client
- secret which the Kafka client can use to authenticate
- against the OAuth server and use the token endpoint URI.
- connectTimeoutSeconds:
- type: integer
- description: >-
- The connect timeout in seconds when connecting to
- authorization server. If not set, the effective connect
- timeout is 60 seconds.
- disableTlsHostnameVerification:
- type: boolean
- description: >-
- Enable or disable TLS hostname verification. Default
- value is `false`.
- enableMetrics:
- type: boolean
- description: >-
- Enable or disable OAuth metrics. Default value is
- `false`.
- httpRetries:
- type: integer
- description: >-
- The maximum number of retries to attempt if an initial
- HTTP request fails. If not set, the default is to not
- attempt any retries.
- httpRetryPauseMs:
- type: integer
- description: >-
- The pause to take before retrying a failed HTTP request.
- If not set, the default is to not pause at all but to
- immediately repeat a request.
- maxTokenExpirySeconds:
- type: integer
- description: >-
- Set or limit time-to-live of the access tokens to the
- specified number of seconds. This should be set if the
- authorization server returns opaque tokens.
- passwordSecret:
- type: object
- properties:
- password:
- type: string
- description: >-
- The name of the key in the Secret under which the
- password is stored.
- secretName:
- type: string
- description: The name of the Secret containing the password.
- required:
- - password
- - secretName
- description: Reference to the `Secret` which holds the password.
- readTimeoutSeconds:
- type: integer
- description: >-
- The read timeout in seconds when connecting to
- authorization server. If not set, the effective read
- timeout is 60 seconds.
- refreshToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored in
- the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the refresh token
- which can be used to obtain access token from the
- authorization server.
- scope:
- type: string
- description: >-
- OAuth scope to use when authenticating against the
- authorization server. Some authorization servers require
- this to be set. The possible values depend on how
- authorization server is configured. By default `scope`
- is not specified when doing the token endpoint request.
- tlsTrustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: The name of the file certificate in the Secret.
- secretName:
- type: string
- description: The name of the Secret containing the certificate.
- required:
- - certificate
- - secretName
- description: >-
- Trusted certificates for TLS connection to the OAuth
- server.
- tokenEndpointUri:
- type: string
- description: Authorization server token endpoint URI.
- type:
- type: string
- enum:
- - tls
- - scram-sha-256
- - scram-sha-512
- - plain
- - oauth
- description: >-
- Authentication type. Currently the supported types are
- `tls`, `scram-sha-256`, `scram-sha-512`, `plain`, and
- 'oauth'. `scram-sha-256` and `scram-sha-512` types use
- SASL SCRAM-SHA-256 and SASL SCRAM-SHA-512
- Authentication, respectively. `plain` type uses SASL
- PLAIN Authentication. `oauth` type uses SASL OAUTHBEARER
- Authentication. The `tls` type uses TLS Client
- Authentication. The `tls` type is supported only over
- TLS connections.
- username:
- type: string
- description: Username used for the authentication.
- required:
- - type
- description: Authentication configuration for Kafka Connect.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Kafka Connect configuration. Properties with the
- following prefixes cannot be set: ssl., sasl., security.,
- listeners, plugin.path, rest., bootstrap.servers,
- consumer.interceptor.classes, producer.interceptor.classes
- (with the exception of:
- ssl.endpoint.identification.algorithm, ssl.cipher.suites,
- ssl.protocol, ssl.enabled.protocols).
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The maximum limits for CPU and memory resources and the
- requested initial resources.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults to 3.
- Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default to
- 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults to
- 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default to
- 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults to 3.
- Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default to
- 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults to
- 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default to
- 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging is
- enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will be
- passed using the `-D` option to the JVM.
- description: JVM Options for pods.
- jmxOptions:
- type: object
- properties:
- authentication:
- type: object
- properties:
- type:
- type: string
- enum:
- - password
- description: >-
- Authentication type. Currently the only supported
- types are `password`.`password` type creates a
- username and protected port with no TLS.
- required:
- - type
- description: >-
- Authentication configuration for connecting to the JMX
- port.
- description: JMX Options.
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: 'Logging type, must be either ''inline'' or ''external''.'
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing the
- configuration.
- description: >-
- `ConfigMap` entry where the logging configuration is
- stored.
- required:
- - type
- description: Logging configuration for Kafka Connect.
- clientRackInitImage:
- type: string
- description: >-
- The image of the init container used for initializing the
- `client.rack`.
- rack:
- type: object
- properties:
- topologyKey:
- type: string
- example: topology.kubernetes.io/zone
- description: >-
- A key that matches labels assigned to the Kubernetes
- cluster nodes. The value of the label is used to set a
- broker's `broker.rack` config, and the `client.rack`
- config for Kafka Connect or MirrorMaker 2.
- required:
- - topologyKey
- description: >-
- Configuration of the node label which will be used as the
- `client.rack` consumer configuration.
- tracing:
- type: object
- properties:
- type:
- type: string
- enum:
- - jaeger
- - opentelemetry
- description: >-
- Type of the tracing used. Currently the only supported
- types are `jaeger` for OpenTracing (Jaeger) tracing and
- `opentelemetry` for OpenTelemetry tracing. The
- OpenTracing (Jaeger) tracing is deprecated.
- required:
- - type
- description: The configuration of tracing in Kafka Connect.
- template:
- type: object
- properties:
- deployment:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- deploymentStrategy:
- type: string
- enum:
- - RollingUpdate
- - Recreate
- description: >-
- Pod replacement strategy for deployment
- configuration changes. Valid values are
- `RollingUpdate` and `Recreate`. Defaults to
- `RollingUpdate`.
- description: Template for Kafka Connect `Deployment`.
- podSet:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for Kafka Connect `StrimziPodSet` resource.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same namespace
- to use for pulling any of the images used by this
- Pod. When the `STRIMZI_IMAGE_PULL_SECRETS`
- environment variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only the
- `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and common
- container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds after
- the processes running in the pod are sent a
- termination signal, and the time when the processes
- are forcibly halted with a kill signal. Set this
- value to longer than the expected cleanup time for
- your process. Value must be a non-negative integer.
- A zero value indicates delete immediately. You might
- need to increase the grace period for very large
- Kafka clusters, so that the Kafka brokers have
- enough time to transfer their work to another broker
- before they are terminated. Defaults to 30 seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler will
- be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an optional
- list of hosts and IPs that will be injected into the
- Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir volume
- (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services should
- be injected into Pod's environment variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for Kafka Connect `Pods`.
- apiService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the service.
- Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP family
- on single-stack clusters. `RequireDualStack` fails
- unless there are two IP families on dual-stack
- configured clusters. If unspecified, Kubernetes will
- choose the default value based on the service type.
- Available on Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for Kafka Connect API `Service`.
- headlessService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the service.
- Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP family
- on single-stack clusters. `RequireDualStack` fails
- unless there are two IP families on dual-stack
- configured clusters. If unspecified, Kubernetes will
- choose the default value based on the service type.
- Available on Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for Kafka Connect headless `Service`.
- connectContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka Connect container.
- initContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka init container.
- podDisruptionBudget:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- maxUnavailable:
- type: integer
- minimum: 0
- description: >-
- Maximum number of unavailable pods to allow
- automatic Pod eviction. A Pod eviction is allowed
- when the `maxUnavailable` number of pods or fewer
- are unavailable after the eviction. Setting this
- value to 0 prevents all voluntary evictions, so the
- pods must be evicted manually. Defaults to 1.
- description: Template for Kafka Connect `PodDisruptionBudget`.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Connect service account.
- clusterRoleBinding:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Connect ClusterRoleBinding.
- buildPod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same namespace
- to use for pulling any of the images used by this
- Pod. When the `STRIMZI_IMAGE_PULL_SECRETS`
- environment variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only the
- `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and common
- container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds after
- the processes running in the pod are sent a
- termination signal, and the time when the processes
- are forcibly halted with a kill signal. Set this
- value to longer than the expected cleanup time for
- your process. Value must be a non-negative integer.
- A zero value indicates delete immediately. You might
- need to increase the grace period for very large
- Kafka clusters, so that the Kafka brokers have
- enough time to transfer their work to another broker
- before they are terminated. Defaults to 30 seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler will
- be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an optional
- list of hosts and IPs that will be injected into the
- Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir volume
- (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services should
- be injected into Pod's environment variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: >-
- Template for Kafka Connect Build `Pods`. The build pod
- is used only on Kubernetes.
- buildContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: >-
- Template for the Kafka Connect Build container. The
- build container is used only on Kubernetes.
- buildConfig:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- pullSecret:
- type: string
- description: >-
- Container Registry Secret with the credentials for
- pulling the base image.
- description: >-
- Template for the Kafka Connect BuildConfig used to build
- new container images. The BuildConfig is used only on
- OpenShift.
- buildServiceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Connect Build service account.
- jmxSecret:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: >-
- Template for Secret of the Kafka Connect Cluster JMX
- authentication.
- description: >-
- Template for Kafka Connect and Kafka Mirror Maker 2
- resources. The template allows users to specify how the
- `Deployment`, `Pods` and `Service` are generated.
- externalConfiguration:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- Name of the environment variable which will be
- passed to the Kafka Connect pods. The name of the
- environment variable cannot start with `KAFKA_` or
- `STRIMZI_`.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: Reference to a key in a ConfigMap.
- secretKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: Reference to a key in a Secret.
- description: >-
- Value of the environment variable which will be
- passed to the Kafka Connect pods. It can be passed
- either as a reference to Secret or ConfigMap
- field. The field has to specify exactly one Secret
- or ConfigMap.
- required:
- - name
- - valueFrom
- description: >-
- Makes data from a Secret or ConfigMap available in the
- Kafka Connect pods as environment variables.
- volumes:
- type: array
- items:
- type: object
- properties:
- configMap:
- type: object
- properties:
- defaultMode:
- type: integer
- items:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- mode:
- type: integer
- path:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to a key in a ConfigMap. Exactly one
- Secret or ConfigMap has to be specified.
- name:
- type: string
- description: >-
- Name of the volume which will be added to the
- Kafka Connect pods.
- secret:
- type: object
- properties:
- defaultMode:
- type: integer
- items:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- mode:
- type: integer
- path:
- type: string
- optional:
- type: boolean
- secretName:
- type: string
- description: >-
- Reference to a key in a Secret. Exactly one Secret
- or ConfigMap has to be specified.
- required:
- - name
- description: >-
- Makes data from a Secret or ConfigMap available in the
- Kafka Connect pods as volumes.
- description: >-
- Pass data from Secrets or ConfigMaps to the Kafka Connect
- pods and use them to configure connectors.
- build:
- type: object
- properties:
- output:
- type: object
- properties:
- additionalKanikoOptions:
- type: array
- items:
- type: string
- description: >-
- Configures additional options which will be passed
- to the Kaniko executor when building the new Connect
- image. Allowed options are: --customPlatform,
- --insecure, --insecure-pull, --insecure-registry,
- --log-format, --log-timestamp, --registry-mirror,
- --reproducible, --single-snapshot,
- --skip-tls-verify, --skip-tls-verify-pull,
- --skip-tls-verify-registry, --verbosity,
- --snapshotMode, --use-new-run. These options will be
- used only on Kubernetes where the Kaniko executor is
- used. They will be ignored on OpenShift. The options
- are described in the
- link:https://github.com/GoogleContainerTools/kaniko[Kaniko
- GitHub repository^]. Changing this field does not
- trigger new build of the Kafka Connect image.
- image:
- type: string
- description: The name of the image which will be built. Required.
- pushSecret:
- type: string
- description: >-
- Container Registry Secret with the credentials for
- pushing the newly built image.
- type:
- type: string
- enum:
- - docker
- - imagestream
- description: >-
- Output type. Must be either `docker` for pushing the
- newly build image to Docker compatible registry or
- `imagestream` for pushing the image to OpenShift
- ImageStream. Required.
- required:
- - image
- - type
- description: >-
- Configures where should the newly built image be stored.
- Required.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve for the build.
- plugins:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- pattern: '^[a-z0-9][-_a-z0-9]*[a-z0-9]$'
- description: >-
- The unique name of the connector plugin. Will be
- used to generate the path where the connector
- artifacts will be stored. The name has to be
- unique within the KafkaConnect resource. The name
- has to follow the following pattern:
- `^[a-z][-_a-z0-9]*[a-z]$`. Required.
- artifacts:
- type: array
- items:
- type: object
- properties:
- artifact:
- type: string
- description: >-
- Maven artifact id. Applicable to the `maven`
- artifact type only.
- fileName:
- type: string
- description: >-
- Name under which the artifact will be
- stored.
- group:
- type: string
- description: >-
- Maven group id. Applicable to the `maven`
- artifact type only.
- insecure:
- type: boolean
- description: >-
- By default, connections using TLS are
- verified to check they are secure. The
- server certificate used must be valid,
- trusted, and contain the server name. By
- setting this option to `true`, all TLS
- verification is disabled and the artifact
- will be downloaded, even when the server is
- considered insecure.
- repository:
- type: string
- description: >-
- Maven repository to download the artifact
- from. Applicable to the `maven` artifact
- type only.
- sha512sum:
- type: string
- description: >-
- SHA512 checksum of the artifact. Optional.
- If specified, the checksum will be verified
- while building the new container. If not
- specified, the downloaded artifact will not
- be verified. Not applicable to the `maven`
- artifact type.
- type:
- type: string
- enum:
- - jar
- - tgz
- - zip
- - maven
- - other
- description: >-
- Artifact type. Currently, the supported
- artifact types are `tgz`, `jar`, `zip`,
- `other` and `maven`.
- url:
- type: string
- pattern: >-
- ^(https?|ftp)://[-a-zA-Z0-9+&@#/%?=~_|!:,.;]*[-a-zA-Z0-9+&@#/%=~_|]$
- description: >-
- URL of the artifact which will be
- downloaded. Strimzi does not do any security
- scanning of the downloaded artifacts. For
- security reasons, you should first verify
- the artifacts manually and configure the
- checksum verification to make sure the same
- artifact is used in the automated build.
- Required for `jar`, `zip`, `tgz` and `other`
- artifacts. Not applicable to the `maven`
- artifact type.
- version:
- type: string
- description: >-
- Maven version number. Applicable to the
- `maven` artifact type only.
- required:
- - type
- description: >-
- List of artifacts which belong to this connector
- plugin. Required.
- required:
- - name
- - artifacts
- description: >-
- List of connector plugins which should be added to the
- Kafka Connect. Required.
- required:
- - output
- - plugins
- description: >-
- Configures how the Connect container image should be built.
- Optional.
- metricsConfig:
- type: object
- properties:
- type:
- type: string
- enum:
- - jmxPrometheusExporter
- description: >-
- Metrics type. Only 'jmxPrometheusExporter' supported
- currently.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing the
- configuration.
- description: >-
- ConfigMap entry where the Prometheus JMX Exporter
- configuration is stored. For details of the structure of
- this configuration, see the {JMXExporter}.
- required:
- - type
- - valueFrom
- description: Metrics configuration.
- required:
- - bootstrapServers
- description: The specification of the Kafka Connect cluster.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- url:
- type: string
- description: >-
- The URL of the REST API endpoint for managing and monitoring
- Kafka Connect connectors.
- connectorPlugins:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The type of the connector plugin. The available types
- are `sink` and `source`.
- version:
- type: string
- description: The version of the connector plugin.
- class:
- type: string
- description: The class of the connector plugin.
- description: >-
- The list of connector plugins available in this Kafka
- Connect deployment.
- labelSelector:
- type: string
- description: Label selector for pods providing this resource.
- replicas:
- type: integer
- description: >-
- The current number of pods being used to provide this
- resource.
- description: The status of the Kafka Connect cluster.
- ---
- apiVersion: apps/v1
- kind: Deployment
- metadata:
- name: strimzi-cluster-operator
- labels:
- app: strimzi
- namespace: kafka
- spec:
- replicas: 1
- selector:
- matchLabels:
- name: strimzi-cluster-operator
- strimzi.io/kind: cluster-operator
- template:
- metadata:
- labels:
- name: strimzi-cluster-operator
- strimzi.io/kind: cluster-operator
- spec:
- serviceAccountName: strimzi-cluster-operator
- volumes:
- - name: strimzi-tmp
- emptyDir:
- medium: Memory
- sizeLimit: 1Mi
- - name: co-config-volume
- configMap:
- name: strimzi-cluster-operator
- containers:
- - name: strimzi-cluster-operator
- image: 'quay.io/strimzi/operator:0.35.1'
- ports:
- - containerPort: 8080
- name: http
- args:
- - /opt/strimzi/bin/cluster_operator_run.sh
- volumeMounts:
- - name: strimzi-tmp
- mountPath: /tmp
- - name: co-config-volume
- mountPath: /opt/strimzi/custom-config/
- env:
- - name: STRIMZI_NAMESPACE
- valueFrom:
- fieldRef:
- fieldPath: metadata.namespace
- - name: STRIMZI_FULL_RECONCILIATION_INTERVAL_MS
- value: '120000'
- - name: STRIMZI_OPERATION_TIMEOUT_MS
- value: '300000'
- - name: STRIMZI_DEFAULT_TLS_SIDECAR_ENTITY_OPERATOR_IMAGE
- value: 'quay.io/strimzi/kafka:0.35.1-kafka-3.4.0'
- - name: STRIMZI_DEFAULT_KAFKA_EXPORTER_IMAGE
- value: 'quay.io/strimzi/kafka:0.35.1-kafka-3.4.0'
- - name: STRIMZI_DEFAULT_CRUISE_CONTROL_IMAGE
- value: 'quay.io/strimzi/kafka:0.35.1-kafka-3.4.0'
- - name: STRIMZI_KAFKA_IMAGES
- value: |
- 3.3.1=quay.io/strimzi/kafka:0.35.1-kafka-3.3.1
- 3.3.2=quay.io/strimzi/kafka:0.35.1-kafka-3.3.2
- 3.4.0=quay.io/strimzi/kafka:0.35.1-kafka-3.4.0
- - name: STRIMZI_KAFKA_CONNECT_IMAGES
- value: |
- 3.3.1=quay.io/strimzi/kafka:0.35.1-kafka-3.3.1
- 3.3.2=quay.io/strimzi/kafka:0.35.1-kafka-3.3.2
- 3.4.0=quay.io/strimzi/kafka:0.35.1-kafka-3.4.0
- - name: STRIMZI_KAFKA_MIRROR_MAKER_IMAGES
- value: |
- 3.3.1=quay.io/strimzi/kafka:0.35.1-kafka-3.3.1
- 3.3.2=quay.io/strimzi/kafka:0.35.1-kafka-3.3.2
- 3.4.0=quay.io/strimzi/kafka:0.35.1-kafka-3.4.0
- - name: STRIMZI_KAFKA_MIRROR_MAKER_2_IMAGES
- value: |
- 3.3.1=quay.io/strimzi/kafka:0.35.1-kafka-3.3.1
- 3.3.2=quay.io/strimzi/kafka:0.35.1-kafka-3.3.2
- 3.4.0=quay.io/strimzi/kafka:0.35.1-kafka-3.4.0
- - name: STRIMZI_DEFAULT_TOPIC_OPERATOR_IMAGE
- value: 'quay.io/strimzi/operator:0.35.1'
- - name: STRIMZI_DEFAULT_USER_OPERATOR_IMAGE
- value: 'quay.io/strimzi/operator:0.35.1'
- - name: STRIMZI_DEFAULT_KAFKA_INIT_IMAGE
- value: 'quay.io/strimzi/operator:0.35.1'
- - name: STRIMZI_DEFAULT_KAFKA_BRIDGE_IMAGE
- value: 'quay.io/strimzi/kafka-bridge:0.25.0'
- - name: STRIMZI_DEFAULT_KANIKO_EXECUTOR_IMAGE
- value: 'quay.io/strimzi/kaniko-executor:0.35.1'
- - name: STRIMZI_DEFAULT_MAVEN_BUILDER
- value: 'quay.io/strimzi/maven-builder:0.35.1'
- - name: STRIMZI_OPERATOR_NAMESPACE
- valueFrom:
- fieldRef:
- fieldPath: metadata.namespace
- - name: STRIMZI_FEATURE_GATES
- value: ''
- - name: STRIMZI_LEADER_ELECTION_ENABLED
- value: 'true'
- - name: STRIMZI_LEADER_ELECTION_LEASE_NAME
- value: strimzi-cluster-operator
- - name: STRIMZI_LEADER_ELECTION_LEASE_NAMESPACE
- valueFrom:
- fieldRef:
- fieldPath: metadata.namespace
- - name: STRIMZI_LEADER_ELECTION_IDENTITY
- valueFrom:
- fieldRef:
- fieldPath: metadata.name
- livenessProbe:
- httpGet:
- path: /healthy
- port: http
- initialDelaySeconds: 10
- periodSeconds: 30
- readinessProbe:
- httpGet:
- path: /ready
- port: http
- initialDelaySeconds: 10
- periodSeconds: 30
- resources:
- limits:
- cpu: 1000m
- memory: 384Mi
- requests:
- cpu: 200m
- memory: 384Mi
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkatopics.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: KafkaTopic
- listKind: KafkaTopicList
- singular: kafkatopic
- plural: kafkatopics
- shortNames:
- - kt
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Cluster
- description: The name of the Kafka cluster this topic belongs to
- jsonPath: .metadata.labels.strimzi\.io/cluster
- type: string
- - name: Partitions
- description: The desired number of partitions in the topic
- jsonPath: .spec.partitions
- type: integer
- - name: Replication factor
- description: The desired number of replicas of each partition
- jsonPath: .spec.replicas
- type: integer
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- partitions:
- type: integer
- minimum: 1
- description: >-
- The number of partitions the topic should have. This cannot
- be decreased after topic creation. It can be increased after
- topic creation, but it is important to understand the
- consequences that has, especially for topics with semantic
- partitioning. When absent this will default to the broker
- configuration for `num.partitions`.
- replicas:
- type: integer
- minimum: 1
- maximum: 32767
- description: >-
- The number of replicas the topic should have. When absent
- this will default to the broker configuration for
- `default.replication.factor`.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: The topic configuration.
- topicName:
- type: string
- description: >-
- The name of the topic. When absent this will default to the
- metadata.name of the topic. It is recommended to not set
- this unless the topic name is not a valid Kubernetes
- resource name.
- description: The specification of the topic.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- topicName:
- type: string
- description: Topic name.
- description: The status of the topic.
- - name: v1beta1
- served: true
- storage: false
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Cluster
- description: The name of the Kafka cluster this topic belongs to
- jsonPath: .metadata.labels.strimzi\.io/cluster
- type: string
- - name: Partitions
- description: The desired number of partitions in the topic
- jsonPath: .spec.partitions
- type: integer
- - name: Replication factor
- description: The desired number of replicas of each partition
- jsonPath: .spec.replicas
- type: integer
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- partitions:
- type: integer
- minimum: 1
- description: >-
- The number of partitions the topic should have. This cannot
- be decreased after topic creation. It can be increased after
- topic creation, but it is important to understand the
- consequences that has, especially for topics with semantic
- partitioning. When absent this will default to the broker
- configuration for `num.partitions`.
- replicas:
- type: integer
- minimum: 1
- maximum: 32767
- description: >-
- The number of replicas the topic should have. When absent
- this will default to the broker configuration for
- `default.replication.factor`.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: The topic configuration.
- topicName:
- type: string
- description: >-
- The name of the topic. When absent this will default to the
- metadata.name of the topic. It is recommended to not set
- this unless the topic name is not a valid Kubernetes
- resource name.
- description: The specification of the topic.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- topicName:
- type: string
- description: Topic name.
- description: The status of the topic.
- - name: v1alpha1
- served: true
- storage: false
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Cluster
- description: The name of the Kafka cluster this topic belongs to
- jsonPath: .metadata.labels.strimzi\.io/cluster
- type: string
- - name: Partitions
- description: The desired number of partitions in the topic
- jsonPath: .spec.partitions
- type: integer
- - name: Replication factor
- description: The desired number of replicas of each partition
- jsonPath: .spec.replicas
- type: integer
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- partitions:
- type: integer
- minimum: 1
- description: >-
- The number of partitions the topic should have. This cannot
- be decreased after topic creation. It can be increased after
- topic creation, but it is important to understand the
- consequences that has, especially for topics with semantic
- partitioning. When absent this will default to the broker
- configuration for `num.partitions`.
- replicas:
- type: integer
- minimum: 1
- maximum: 32767
- description: >-
- The number of replicas the topic should have. When absent
- this will default to the broker configuration for
- `default.replication.factor`.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: The topic configuration.
- topicName:
- type: string
- description: >-
- The name of the topic. When absent this will default to the
- metadata.name of the topic. It is recommended to not set
- this unless the topic name is not a valid Kubernetes
- resource name.
- description: The specification of the topic.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- topicName:
- type: string
- description: Topic name.
- description: The status of the topic.
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: strimzi-kafka-client
- labels:
- app: strimzi
- rules:
- - apiGroups:
- - ''
- resources:
- - nodes
- verbs:
- - get
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkaconnectors.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: KafkaConnector
- listKind: KafkaConnectorList
- singular: kafkaconnector
- plural: kafkaconnectors
- shortNames:
- - kctr
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- scale:
- specReplicasPath: .spec.tasksMax
- statusReplicasPath: .status.tasksMax
- additionalPrinterColumns:
- - name: Cluster
- description: The name of the Kafka Connect cluster this connector belongs to
- jsonPath: .metadata.labels.strimzi\.io/cluster
- type: string
- - name: Connector class
- description: The class used by this connector
- jsonPath: .spec.class
- type: string
- - name: Max Tasks
- description: Maximum number of tasks
- jsonPath: .spec.tasksMax
- type: integer
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- class:
- type: string
- description: The Class for the Kafka Connector.
- tasksMax:
- type: integer
- minimum: 1
- description: The maximum number of tasks for the Kafka Connector.
- autoRestart:
- type: object
- properties:
- enabled:
- type: boolean
- description: >-
- Whether automatic restart for failed connectors and
- tasks should be enabled or disabled.
- description: Automatic restart of connector and tasks configuration.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Kafka Connector configuration. The following properties
- cannot be set: connector.class, tasks.max.
- pause:
- type: boolean
- description: Whether the connector should be paused. Defaults to false.
- description: The specification of the Kafka Connector.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- autoRestart:
- type: object
- properties:
- count:
- type: integer
- description: The number of times the connector or task is restarted.
- connectorName:
- type: string
- description: The name of the connector being restarted.
- lastRestartTimestamp:
- type: string
- description: >-
- The last time the automatic restart was attempted. The
- required format is 'yyyy-MM-ddTHH:mm:ssZ' in the UTC
- time zone.
- description: The auto restart status.
- connectorStatus:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The connector status, as reported by the Kafka Connect REST
- API.
- tasksMax:
- type: integer
- description: The maximum number of tasks for the Kafka Connector.
- topics:
- type: array
- items:
- type: string
- description: The list of topics used by the Kafka Connector.
- description: The status of the Kafka Connector.
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkamirrormakers.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: KafkaMirrorMaker
- listKind: KafkaMirrorMakerList
- singular: kafkamirrormaker
- plural: kafkamirrormakers
- shortNames:
- - kmm
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- scale:
- specReplicasPath: .spec.replicas
- statusReplicasPath: .status.replicas
- labelSelectorPath: .status.labelSelector
- additionalPrinterColumns:
- - name: Desired replicas
- description: The desired number of Kafka MirrorMaker replicas
- jsonPath: .spec.replicas
- type: integer
- - name: Consumer Bootstrap Servers
- description: The boostrap servers for the consumer
- jsonPath: .spec.consumer.bootstrapServers
- type: string
- priority: 1
- - name: Producer Bootstrap Servers
- description: The boostrap servers for the producer
- jsonPath: .spec.producer.bootstrapServers
- type: string
- priority: 1
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- version:
- type: string
- description: >-
- The Kafka MirrorMaker version. Defaults to
- {DefaultKafkaVersion}. Consult the documentation to
- understand the process required to upgrade or downgrade the
- version.
- replicas:
- type: integer
- minimum: 0
- description: The number of pods in the `Deployment`.
- image:
- type: string
- description: The docker image for the pods.
- consumer:
- type: object
- properties:
- numStreams:
- type: integer
- minimum: 1
- description: >-
- Specifies the number of consumer stream threads to
- create.
- offsetCommitInterval:
- type: integer
- description: >-
- Specifies the offset auto-commit interval in ms. Default
- value is 60000.
- bootstrapServers:
- type: string
- description: >-
- A list of host:port pairs for establishing the initial
- connection to the Kafka cluster.
- groupId:
- type: string
- description: >-
- A unique string that identifies the consumer group this
- consumer belongs to.
- authentication:
- type: object
- properties:
- accessToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the access
- token which was obtained from the authorization
- server.
- accessTokenIsJwt:
- type: boolean
- description: >-
- Configure whether access token should be treated as
- JWT. This should be set to `false` if the
- authorization server returns opaque tokens. Defaults
- to `true`.
- audience:
- type: string
- description: >-
- OAuth audience to use when authenticating against
- the authorization server. Some authorization servers
- require the audience to be explicitly set. The
- possible values depend on how the authorization
- server is configured. By default, `audience` is not
- specified when performing the token endpoint
- request.
- certificateAndKey:
- type: object
- properties:
- certificate:
- type: string
- description: The name of the file certificate in the Secret.
- key:
- type: string
- description: The name of the private key in the Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - key
- - secretName
- description: >-
- Reference to the `Secret` which holds the
- certificate and private key pair.
- clientId:
- type: string
- description: >-
- OAuth Client ID which the Kafka client can use to
- authenticate against the OAuth server and use the
- token endpoint URI.
- clientSecret:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the OAuth
- client secret which the Kafka client can use to
- authenticate against the OAuth server and use the
- token endpoint URI.
- connectTimeoutSeconds:
- type: integer
- description: >-
- The connect timeout in seconds when connecting to
- authorization server. If not set, the effective
- connect timeout is 60 seconds.
- disableTlsHostnameVerification:
- type: boolean
- description: >-
- Enable or disable TLS hostname verification. Default
- value is `false`.
- enableMetrics:
- type: boolean
- description: >-
- Enable or disable OAuth metrics. Default value is
- `false`.
- httpRetries:
- type: integer
- description: >-
- The maximum number of retries to attempt if an
- initial HTTP request fails. If not set, the default
- is to not attempt any retries.
- httpRetryPauseMs:
- type: integer
- description: >-
- The pause to take before retrying a failed HTTP
- request. If not set, the default is to not pause at
- all but to immediately repeat a request.
- maxTokenExpirySeconds:
- type: integer
- description: >-
- Set or limit time-to-live of the access tokens to
- the specified number of seconds. This should be set
- if the authorization server returns opaque tokens.
- passwordSecret:
- type: object
- properties:
- password:
- type: string
- description: >-
- The name of the key in the Secret under which
- the password is stored.
- secretName:
- type: string
- description: The name of the Secret containing the password.
- required:
- - password
- - secretName
- description: Reference to the `Secret` which holds the password.
- readTimeoutSeconds:
- type: integer
- description: >-
- The read timeout in seconds when connecting to
- authorization server. If not set, the effective read
- timeout is 60 seconds.
- refreshToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the refresh
- token which can be used to obtain access token from
- the authorization server.
- scope:
- type: string
- description: >-
- OAuth scope to use when authenticating against the
- authorization server. Some authorization servers
- require this to be set. The possible values depend
- on how authorization server is configured. By
- default `scope` is not specified when doing the
- token endpoint request.
- tlsTrustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - secretName
- description: >-
- Trusted certificates for TLS connection to the OAuth
- server.
- tokenEndpointUri:
- type: string
- description: Authorization server token endpoint URI.
- type:
- type: string
- enum:
- - tls
- - scram-sha-256
- - scram-sha-512
- - plain
- - oauth
- description: >-
- Authentication type. Currently the supported types
- are `tls`, `scram-sha-256`, `scram-sha-512`,
- `plain`, and 'oauth'. `scram-sha-256` and
- `scram-sha-512` types use SASL SCRAM-SHA-256 and
- SASL SCRAM-SHA-512 Authentication, respectively.
- `plain` type uses SASL PLAIN Authentication. `oauth`
- type uses SASL OAUTHBEARER Authentication. The `tls`
- type uses TLS Client Authentication. The `tls` type
- is supported only over TLS connections.
- username:
- type: string
- description: Username used for the authentication.
- required:
- - type
- description: >-
- Authentication configuration for connecting to the
- cluster.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The MirrorMaker consumer config. Properties with the
- following prefixes cannot be set: ssl.,
- bootstrap.servers, group.id, sasl., security.,
- interceptor.classes (with the exception of:
- ssl.endpoint.identification.algorithm,
- ssl.cipher.suites, ssl.protocol, ssl.enabled.protocols).
- tls:
- type: object
- properties:
- trustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - secretName
- description: Trusted certificates for TLS connection.
- description: >-
- TLS configuration for connecting MirrorMaker to the
- cluster.
- required:
- - bootstrapServers
- - groupId
- description: Configuration of source cluster.
- producer:
- type: object
- properties:
- bootstrapServers:
- type: string
- description: >-
- A list of host:port pairs for establishing the initial
- connection to the Kafka cluster.
- abortOnSendFailure:
- type: boolean
- description: >-
- Flag to set the MirrorMaker to exit on a failed send.
- Default value is `true`.
- authentication:
- type: object
- properties:
- accessToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the access
- token which was obtained from the authorization
- server.
- accessTokenIsJwt:
- type: boolean
- description: >-
- Configure whether access token should be treated as
- JWT. This should be set to `false` if the
- authorization server returns opaque tokens. Defaults
- to `true`.
- audience:
- type: string
- description: >-
- OAuth audience to use when authenticating against
- the authorization server. Some authorization servers
- require the audience to be explicitly set. The
- possible values depend on how the authorization
- server is configured. By default, `audience` is not
- specified when performing the token endpoint
- request.
- certificateAndKey:
- type: object
- properties:
- certificate:
- type: string
- description: The name of the file certificate in the Secret.
- key:
- type: string
- description: The name of the private key in the Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - key
- - secretName
- description: >-
- Reference to the `Secret` which holds the
- certificate and private key pair.
- clientId:
- type: string
- description: >-
- OAuth Client ID which the Kafka client can use to
- authenticate against the OAuth server and use the
- token endpoint URI.
- clientSecret:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the OAuth
- client secret which the Kafka client can use to
- authenticate against the OAuth server and use the
- token endpoint URI.
- connectTimeoutSeconds:
- type: integer
- description: >-
- The connect timeout in seconds when connecting to
- authorization server. If not set, the effective
- connect timeout is 60 seconds.
- disableTlsHostnameVerification:
- type: boolean
- description: >-
- Enable or disable TLS hostname verification. Default
- value is `false`.
- enableMetrics:
- type: boolean
- description: >-
- Enable or disable OAuth metrics. Default value is
- `false`.
- httpRetries:
- type: integer
- description: >-
- The maximum number of retries to attempt if an
- initial HTTP request fails. If not set, the default
- is to not attempt any retries.
- httpRetryPauseMs:
- type: integer
- description: >-
- The pause to take before retrying a failed HTTP
- request. If not set, the default is to not pause at
- all but to immediately repeat a request.
- maxTokenExpirySeconds:
- type: integer
- description: >-
- Set or limit time-to-live of the access tokens to
- the specified number of seconds. This should be set
- if the authorization server returns opaque tokens.
- passwordSecret:
- type: object
- properties:
- password:
- type: string
- description: >-
- The name of the key in the Secret under which
- the password is stored.
- secretName:
- type: string
- description: The name of the Secret containing the password.
- required:
- - password
- - secretName
- description: Reference to the `Secret` which holds the password.
- readTimeoutSeconds:
- type: integer
- description: >-
- The read timeout in seconds when connecting to
- authorization server. If not set, the effective read
- timeout is 60 seconds.
- refreshToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored
- in the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the refresh
- token which can be used to obtain access token from
- the authorization server.
- scope:
- type: string
- description: >-
- OAuth scope to use when authenticating against the
- authorization server. Some authorization servers
- require this to be set. The possible values depend
- on how authorization server is configured. By
- default `scope` is not specified when doing the
- token endpoint request.
- tlsTrustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - secretName
- description: >-
- Trusted certificates for TLS connection to the OAuth
- server.
- tokenEndpointUri:
- type: string
- description: Authorization server token endpoint URI.
- type:
- type: string
- enum:
- - tls
- - scram-sha-256
- - scram-sha-512
- - plain
- - oauth
- description: >-
- Authentication type. Currently the supported types
- are `tls`, `scram-sha-256`, `scram-sha-512`,
- `plain`, and 'oauth'. `scram-sha-256` and
- `scram-sha-512` types use SASL SCRAM-SHA-256 and
- SASL SCRAM-SHA-512 Authentication, respectively.
- `plain` type uses SASL PLAIN Authentication. `oauth`
- type uses SASL OAUTHBEARER Authentication. The `tls`
- type uses TLS Client Authentication. The `tls` type
- is supported only over TLS connections.
- username:
- type: string
- description: Username used for the authentication.
- required:
- - type
- description: >-
- Authentication configuration for connecting to the
- cluster.
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The MirrorMaker producer config. Properties with the
- following prefixes cannot be set: ssl.,
- bootstrap.servers, sasl., security., interceptor.classes
- (with the exception of:
- ssl.endpoint.identification.algorithm,
- ssl.cipher.suites, ssl.protocol, ssl.enabled.protocols).
- tls:
- type: object
- properties:
- trustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: >-
- The name of the file certificate in the
- Secret.
- secretName:
- type: string
- description: >-
- The name of the Secret containing the
- certificate.
- required:
- - certificate
- - secretName
- description: Trusted certificates for TLS connection.
- description: >-
- TLS configuration for connecting MirrorMaker to the
- cluster.
- required:
- - bootstrapServers
- description: Configuration of target cluster.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- whitelist:
- type: string
- description: >-
- List of topics which are included for mirroring. This option
- allows any regular expression using Java-style regular
- expressions. Mirroring two topics named A and B is achieved
- by using the expression `A\|B`. Or, as a special case, you
- can mirror all topics using the regular expression `*`. You
- can also specify multiple regular expressions separated by
- commas.
- include:
- type: string
- description: >-
- List of topics which are included for mirroring. This option
- allows any regular expression using Java-style regular
- expressions. Mirroring two topics named A and B is achieved
- by using the expression `A\|B`. Or, as a special case, you
- can mirror all topics using the regular expression `*`. You
- can also specify multiple regular expressions separated by
- commas.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging is
- enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will be
- passed using the `-D` option to the JVM.
- description: JVM Options for pods.
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: 'Logging type, must be either ''inline'' or ''external''.'
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing the
- configuration.
- description: >-
- `ConfigMap` entry where the logging configuration is
- stored.
- required:
- - type
- description: Logging configuration for MirrorMaker.
- metricsConfig:
- type: object
- properties:
- type:
- type: string
- enum:
- - jmxPrometheusExporter
- description: >-
- Metrics type. Only 'jmxPrometheusExporter' supported
- currently.
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing the
- configuration.
- description: >-
- ConfigMap entry where the Prometheus JMX Exporter
- configuration is stored. For details of the structure of
- this configuration, see the {JMXExporter}.
- required:
- - type
- - valueFrom
- description: Metrics configuration.
- tracing:
- type: object
- properties:
- type:
- type: string
- enum:
- - jaeger
- - opentelemetry
- description: >-
- Type of the tracing used. Currently the only supported
- types are `jaeger` for OpenTracing (Jaeger) tracing and
- `opentelemetry` for OpenTelemetry tracing. The
- OpenTracing (Jaeger) tracing is deprecated.
- required:
- - type
- description: The configuration of tracing in Kafka MirrorMaker.
- template:
- type: object
- properties:
- deployment:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- deploymentStrategy:
- type: string
- enum:
- - RollingUpdate
- - Recreate
- description: >-
- Pod replacement strategy for deployment
- configuration changes. Valid values are
- `RollingUpdate` and `Recreate`. Defaults to
- `RollingUpdate`.
- description: Template for Kafka MirrorMaker `Deployment`.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same namespace
- to use for pulling any of the images used by this
- Pod. When the `STRIMZI_IMAGE_PULL_SECRETS`
- environment variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only the
- `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and common
- container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds after
- the processes running in the pod are sent a
- termination signal, and the time when the processes
- are forcibly halted with a kill signal. Set this
- value to longer than the expected cleanup time for
- your process. Value must be a non-negative integer.
- A zero value indicates delete immediately. You might
- need to increase the grace period for very large
- Kafka clusters, so that the Kafka brokers have
- enough time to transfer their work to another broker
- before they are terminated. Defaults to 30 seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler will
- be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an optional
- list of hosts and IPs that will be injected into the
- Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir volume
- (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services should
- be injected into Pod's environment variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for Kafka MirrorMaker `Pods`.
- podDisruptionBudget:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- maxUnavailable:
- type: integer
- minimum: 0
- description: >-
- Maximum number of unavailable pods to allow
- automatic Pod eviction. A Pod eviction is allowed
- when the `maxUnavailable` number of pods or fewer
- are unavailable after the eviction. Setting this
- value to 0 prevents all voluntary evictions, so the
- pods must be evicted manually. Defaults to 1.
- description: Template for Kafka MirrorMaker `PodDisruptionBudget`.
- mirrorMakerContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for Kafka MirrorMaker container.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka MirrorMaker service account.
- description: >-
- Template to specify how Kafka MirrorMaker resources,
- `Deployments` and `Pods`, are generated.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults to 3.
- Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default to
- 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults to
- 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default to
- 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults to 3.
- Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default to
- 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults to
- 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default to
- 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- oneOf:
- - properties:
- include: {}
- required:
- - include
- - properties:
- whitelist: {}
- required:
- - whitelist
- required:
- - replicas
- - consumer
- - producer
- description: The specification of Kafka MirrorMaker.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- labelSelector:
- type: string
- description: Label selector for pods providing this resource.
- replicas:
- type: integer
- description: >-
- The current number of pods being used to provide this
- resource.
- description: The status of Kafka MirrorMaker.
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
- name: strimzi-cluster-operator-watched
- labels:
- app: strimzi
- namespace: kafka
- subjects:
- - kind: ServiceAccount
- name: strimzi-cluster-operator
- namespace: kafka
- roleRef:
- kind: ClusterRole
- name: strimzi-cluster-operator-watched
- apiGroup: rbac.authorization.k8s.io
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkausers.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: KafkaUser
- listKind: KafkaUserList
- singular: kafkauser
- plural: kafkausers
- shortNames:
- - ku
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Cluster
- description: The name of the Kafka cluster this user belongs to
- jsonPath: .metadata.labels.strimzi\.io/cluster
- type: string
- - name: Authentication
- description: How the user is authenticated
- jsonPath: .spec.authentication.type
- type: string
- - name: Authorization
- description: How the user is authorised
- jsonPath: .spec.authorization.type
- type: string
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- authentication:
- type: object
- properties:
- password:
- type: object
- properties:
- valueFrom:
- type: object
- properties:
- secretKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Selects a key of a Secret in the resource's
- namespace.
- description: Secret from which the password should be read.
- required:
- - valueFrom
- description: >-
- Specify the password for the user. If not set, a new
- password is generated by the User Operator.
- type:
- type: string
- enum:
- - tls
- - tls-external
- - scram-sha-512
- description: Authentication type.
- required:
- - type
- description: >-
- Authentication mechanism enabled for this Kafka user. The
- supported authentication mechanisms are `scram-sha-512`,
- `tls`, and `tls-external`.
- * `scram-sha-512` generates a secret with SASL SCRAM-SHA-512
- credentials.
- * `tls` generates a secret with user certificate for mutual
- TLS authentication.
- * `tls-external` does not generate a user certificate. But
- prepares the user for using mutual TLS authentication using
- a user certificate generated outside the User Operator.
- ACLs and quotas set for this user are configured in the `CN=<username>` format.
- Authentication is optional. If authentication is not
- configured, no credentials are generated. ACLs and quotas
- set for the user are configured in the `<username>` format
- suitable for SASL authentication.
- authorization:
- type: object
- properties:
- acls:
- type: array
- items:
- type: object
- properties:
- host:
- type: string
- description: >-
- The host from which the action described in the
- ACL rule is allowed or denied.
- operation:
- type: string
- enum:
- - Read
- - Write
- - Create
- - Delete
- - Alter
- - Describe
- - ClusterAction
- - AlterConfigs
- - DescribeConfigs
- - IdempotentWrite
- - All
- description: >-
- Operation which will be allowed or denied.
- Supported operations are: Read, Write, Create,
- Delete, Alter, Describe, ClusterAction,
- AlterConfigs, DescribeConfigs, IdempotentWrite and
- All.
- operations:
- type: array
- items:
- type: string
- enum:
- - Read
- - Write
- - Create
- - Delete
- - Alter
- - Describe
- - ClusterAction
- - AlterConfigs
- - DescribeConfigs
- - IdempotentWrite
- - All
- description: >-
- List of operations which will be allowed or
- denied. Supported operations are: Read, Write,
- Create, Delete, Alter, Describe, ClusterAction,
- AlterConfigs, DescribeConfigs, IdempotentWrite and
- All.
- resource:
- type: object
- properties:
- name:
- type: string
- description: >-
- Name of resource for which given ACL rule
- applies. Can be combined with `patternType`
- field to use prefix pattern.
- patternType:
- type: string
- enum:
- - literal
- - prefix
- description: >-
- Describes the pattern used in the resource
- field. The supported types are `literal` and
- `prefix`. With `literal` pattern type, the
- resource field will be used as a definition of
- a full name. With `prefix` pattern type, the
- resource name will be used only as a prefix.
- Default value is `literal`.
- type:
- type: string
- enum:
- - topic
- - group
- - cluster
- - transactionalId
- description: >-
- Resource type. The available resource types
- are `topic`, `group`, `cluster`, and
- `transactionalId`.
- required:
- - type
- description: >-
- Indicates the resource for which given ACL rule
- applies.
- type:
- type: string
- enum:
- - allow
- - deny
- description: >-
- The type of the rule. Currently the only supported
- type is `allow`. ACL rules with type `allow` are
- used to allow user to execute the specified
- operations. Default value is `allow`.
- required:
- - resource
- description: List of ACL rules which should be applied to this user.
- type:
- type: string
- enum:
- - simple
- description: >-
- Authorization type. Currently the only supported type is
- `simple`. `simple` authorization type uses Kafka's
- `kafka.security.authorizer.AclAuthorizer` class for
- authorization.
- required:
- - acls
- - type
- description: Authorization rules for this Kafka user.
- quotas:
- type: object
- properties:
- consumerByteRate:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum bytes per-second that each client
- group can fetch from a broker before the clients in the
- group are throttled. Defined on a per-broker basis.
- controllerMutationRate:
- type: number
- minimum: 0
- description: >-
- A quota on the rate at which mutations are accepted for
- the create topics request, the create partitions request
- and the delete topics request. The rate is accumulated
- by the number of partitions created or deleted.
- producerByteRate:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum bytes per-second that each client
- group can publish to a broker before the clients in the
- group are throttled. Defined on a per-broker basis.
- requestPercentage:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum CPU utilization of each client
- group as a percentage of network and I/O threads.
- description: >-
- Quotas on requests to control the broker resources used by
- clients. Network bandwidth and request rate quotas can be
- enforced.Kafka documentation for Kafka User quotas can be
- found at
- http://kafka.apache.org/documentation/#design_quotas.
- template:
- type: object
- properties:
- secret:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: >-
- Template for KafkaUser resources. The template allows
- users to specify how the `Secret` with password or TLS
- certificates is generated.
- description: Template to specify how Kafka User `Secrets` are generated.
- description: The specification of the user.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- username:
- type: string
- description: Username.
- secret:
- type: string
- description: The name of `Secret` where the credentials are stored.
- description: The status of the Kafka User.
- - name: v1beta1
- served: true
- storage: false
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Cluster
- description: The name of the Kafka cluster this user belongs to
- jsonPath: .metadata.labels.strimzi\.io/cluster
- type: string
- - name: Authentication
- description: How the user is authenticated
- jsonPath: .spec.authentication.type
- type: string
- - name: Authorization
- description: How the user is authorised
- jsonPath: .spec.authorization.type
- type: string
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- authentication:
- type: object
- properties:
- password:
- type: object
- properties:
- valueFrom:
- type: object
- properties:
- secretKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Selects a key of a Secret in the resource's
- namespace.
- description: Secret from which the password should be read.
- required:
- - valueFrom
- description: >-
- Specify the password for the user. If not set, a new
- password is generated by the User Operator.
- type:
- type: string
- enum:
- - tls
- - tls-external
- - scram-sha-512
- description: Authentication type.
- required:
- - type
- description: >-
- Authentication mechanism enabled for this Kafka user. The
- supported authentication mechanisms are `scram-sha-512`,
- `tls`, and `tls-external`.
- * `scram-sha-512` generates a secret with SASL SCRAM-SHA-512
- credentials.
- * `tls` generates a secret with user certificate for mutual
- TLS authentication.
- * `tls-external` does not generate a user certificate. But
- prepares the user for using mutual TLS authentication using
- a user certificate generated outside the User Operator.
- ACLs and quotas set for this user are configured in the `CN=<username>` format.
- Authentication is optional. If authentication is not
- configured, no credentials are generated. ACLs and quotas
- set for the user are configured in the `<username>` format
- suitable for SASL authentication.
- authorization:
- type: object
- properties:
- acls:
- type: array
- items:
- type: object
- properties:
- host:
- type: string
- description: >-
- The host from which the action described in the
- ACL rule is allowed or denied.
- operation:
- type: string
- enum:
- - Read
- - Write
- - Create
- - Delete
- - Alter
- - Describe
- - ClusterAction
- - AlterConfigs
- - DescribeConfigs
- - IdempotentWrite
- - All
- description: >-
- Operation which will be allowed or denied.
- Supported operations are: Read, Write, Create,
- Delete, Alter, Describe, ClusterAction,
- AlterConfigs, DescribeConfigs, IdempotentWrite and
- All.
- operations:
- type: array
- items:
- type: string
- enum:
- - Read
- - Write
- - Create
- - Delete
- - Alter
- - Describe
- - ClusterAction
- - AlterConfigs
- - DescribeConfigs
- - IdempotentWrite
- - All
- description: >-
- List of operations which will be allowed or
- denied. Supported operations are: Read, Write,
- Create, Delete, Alter, Describe, ClusterAction,
- AlterConfigs, DescribeConfigs, IdempotentWrite and
- All.
- resource:
- type: object
- properties:
- name:
- type: string
- description: >-
- Name of resource for which given ACL rule
- applies. Can be combined with `patternType`
- field to use prefix pattern.
- patternType:
- type: string
- enum:
- - literal
- - prefix
- description: >-
- Describes the pattern used in the resource
- field. The supported types are `literal` and
- `prefix`. With `literal` pattern type, the
- resource field will be used as a definition of
- a full name. With `prefix` pattern type, the
- resource name will be used only as a prefix.
- Default value is `literal`.
- type:
- type: string
- enum:
- - topic
- - group
- - cluster
- - transactionalId
- description: >-
- Resource type. The available resource types
- are `topic`, `group`, `cluster`, and
- `transactionalId`.
- required:
- - type
- description: >-
- Indicates the resource for which given ACL rule
- applies.
- type:
- type: string
- enum:
- - allow
- - deny
- description: >-
- The type of the rule. Currently the only supported
- type is `allow`. ACL rules with type `allow` are
- used to allow user to execute the specified
- operations. Default value is `allow`.
- required:
- - resource
- description: List of ACL rules which should be applied to this user.
- type:
- type: string
- enum:
- - simple
- description: >-
- Authorization type. Currently the only supported type is
- `simple`. `simple` authorization type uses Kafka's
- `kafka.security.authorizer.AclAuthorizer` class for
- authorization.
- required:
- - acls
- - type
- description: Authorization rules for this Kafka user.
- quotas:
- type: object
- properties:
- consumerByteRate:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum bytes per-second that each client
- group can fetch from a broker before the clients in the
- group are throttled. Defined on a per-broker basis.
- controllerMutationRate:
- type: number
- minimum: 0
- description: >-
- A quota on the rate at which mutations are accepted for
- the create topics request, the create partitions request
- and the delete topics request. The rate is accumulated
- by the number of partitions created or deleted.
- producerByteRate:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum bytes per-second that each client
- group can publish to a broker before the clients in the
- group are throttled. Defined on a per-broker basis.
- requestPercentage:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum CPU utilization of each client
- group as a percentage of network and I/O threads.
- description: >-
- Quotas on requests to control the broker resources used by
- clients. Network bandwidth and request rate quotas can be
- enforced.Kafka documentation for Kafka User quotas can be
- found at
- http://kafka.apache.org/documentation/#design_quotas.
- template:
- type: object
- properties:
- secret:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: >-
- Template for KafkaUser resources. The template allows
- users to specify how the `Secret` with password or TLS
- certificates is generated.
- description: Template to specify how Kafka User `Secrets` are generated.
- description: The specification of the user.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- username:
- type: string
- description: Username.
- secret:
- type: string
- description: The name of `Secret` where the credentials are stored.
- description: The status of the Kafka User.
- - name: v1alpha1
- served: true
- storage: false
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Cluster
- description: The name of the Kafka cluster this user belongs to
- jsonPath: .metadata.labels.strimzi\.io/cluster
- type: string
- - name: Authentication
- description: How the user is authenticated
- jsonPath: .spec.authentication.type
- type: string
- - name: Authorization
- description: How the user is authorised
- jsonPath: .spec.authorization.type
- type: string
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- authentication:
- type: object
- properties:
- password:
- type: object
- properties:
- valueFrom:
- type: object
- properties:
- secretKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Selects a key of a Secret in the resource's
- namespace.
- description: Secret from which the password should be read.
- required:
- - valueFrom
- description: >-
- Specify the password for the user. If not set, a new
- password is generated by the User Operator.
- type:
- type: string
- enum:
- - tls
- - tls-external
- - scram-sha-512
- description: Authentication type.
- required:
- - type
- description: >-
- Authentication mechanism enabled for this Kafka user. The
- supported authentication mechanisms are `scram-sha-512`,
- `tls`, and `tls-external`.
- * `scram-sha-512` generates a secret with SASL SCRAM-SHA-512
- credentials.
- * `tls` generates a secret with user certificate for mutual
- TLS authentication.
- * `tls-external` does not generate a user certificate. But
- prepares the user for using mutual TLS authentication using
- a user certificate generated outside the User Operator.
- ACLs and quotas set for this user are configured in the `CN=<username>` format.
- Authentication is optional. If authentication is not
- configured, no credentials are generated. ACLs and quotas
- set for the user are configured in the `<username>` format
- suitable for SASL authentication.
- authorization:
- type: object
- properties:
- acls:
- type: array
- items:
- type: object
- properties:
- host:
- type: string
- description: >-
- The host from which the action described in the
- ACL rule is allowed or denied.
- operation:
- type: string
- enum:
- - Read
- - Write
- - Create
- - Delete
- - Alter
- - Describe
- - ClusterAction
- - AlterConfigs
- - DescribeConfigs
- - IdempotentWrite
- - All
- description: >-
- Operation which will be allowed or denied.
- Supported operations are: Read, Write, Create,
- Delete, Alter, Describe, ClusterAction,
- AlterConfigs, DescribeConfigs, IdempotentWrite and
- All.
- operations:
- type: array
- items:
- type: string
- enum:
- - Read
- - Write
- - Create
- - Delete
- - Alter
- - Describe
- - ClusterAction
- - AlterConfigs
- - DescribeConfigs
- - IdempotentWrite
- - All
- description: >-
- List of operations which will be allowed or
- denied. Supported operations are: Read, Write,
- Create, Delete, Alter, Describe, ClusterAction,
- AlterConfigs, DescribeConfigs, IdempotentWrite and
- All.
- resource:
- type: object
- properties:
- name:
- type: string
- description: >-
- Name of resource for which given ACL rule
- applies. Can be combined with `patternType`
- field to use prefix pattern.
- patternType:
- type: string
- enum:
- - literal
- - prefix
- description: >-
- Describes the pattern used in the resource
- field. The supported types are `literal` and
- `prefix`. With `literal` pattern type, the
- resource field will be used as a definition of
- a full name. With `prefix` pattern type, the
- resource name will be used only as a prefix.
- Default value is `literal`.
- type:
- type: string
- enum:
- - topic
- - group
- - cluster
- - transactionalId
- description: >-
- Resource type. The available resource types
- are `topic`, `group`, `cluster`, and
- `transactionalId`.
- required:
- - type
- description: >-
- Indicates the resource for which given ACL rule
- applies.
- type:
- type: string
- enum:
- - allow
- - deny
- description: >-
- The type of the rule. Currently the only supported
- type is `allow`. ACL rules with type `allow` are
- used to allow user to execute the specified
- operations. Default value is `allow`.
- required:
- - resource
- description: List of ACL rules which should be applied to this user.
- type:
- type: string
- enum:
- - simple
- description: >-
- Authorization type. Currently the only supported type is
- `simple`. `simple` authorization type uses Kafka's
- `kafka.security.authorizer.AclAuthorizer` class for
- authorization.
- required:
- - acls
- - type
- description: Authorization rules for this Kafka user.
- quotas:
- type: object
- properties:
- consumerByteRate:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum bytes per-second that each client
- group can fetch from a broker before the clients in the
- group are throttled. Defined on a per-broker basis.
- controllerMutationRate:
- type: number
- minimum: 0
- description: >-
- A quota on the rate at which mutations are accepted for
- the create topics request, the create partitions request
- and the delete topics request. The rate is accumulated
- by the number of partitions created or deleted.
- producerByteRate:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum bytes per-second that each client
- group can publish to a broker before the clients in the
- group are throttled. Defined on a per-broker basis.
- requestPercentage:
- type: integer
- minimum: 0
- description: >-
- A quota on the maximum CPU utilization of each client
- group as a percentage of network and I/O threads.
- description: >-
- Quotas on requests to control the broker resources used by
- clients. Network bandwidth and request rate quotas can be
- enforced.Kafka documentation for Kafka User quotas can be
- found at
- http://kafka.apache.org/documentation/#design_quotas.
- template:
- type: object
- properties:
- secret:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: >-
- Template for KafkaUser resources. The template allows
- users to specify how the `Secret` with password or TLS
- certificates is generated.
- description: Template to specify how Kafka User `Secrets` are generated.
- description: The specification of the user.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- username:
- type: string
- description: Username.
- secret:
- type: string
- description: The name of `Secret` where the credentials are stored.
- description: The status of the Kafka User.
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRoleBinding
- metadata:
- name: strimzi-cluster-operator-kafka-broker-delegation
- labels:
- app: strimzi
- subjects:
- - kind: ServiceAccount
- name: strimzi-cluster-operator
- namespace: kafka
- roleRef:
- kind: ClusterRole
- name: strimzi-kafka-broker
- apiGroup: rbac.authorization.k8s.io
- ---
- apiVersion: rbac.authorization.k8s.io/v1
- kind: RoleBinding
- metadata:
- name: strimzi-cluster-operator
- labels:
- app: strimzi
- namespace: kafka
- subjects:
- - kind: ServiceAccount
- name: strimzi-cluster-operator
- namespace: kafka
- roleRef:
- kind: ClusterRole
- name: strimzi-cluster-operator-namespaced
- apiGroup: rbac.authorization.k8s.io
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: kafkabridges.kafka.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: kafka.strimzi.io
- names:
- kind: KafkaBridge
- listKind: KafkaBridgeList
- singular: kafkabridge
- plural: kafkabridges
- shortNames:
- - kb
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- scale:
- specReplicasPath: .spec.replicas
- statusReplicasPath: .status.replicas
- labelSelectorPath: .status.labelSelector
- additionalPrinterColumns:
- - name: Desired replicas
- description: The desired number of Kafka Bridge replicas
- jsonPath: .spec.replicas
- type: integer
- - name: Bootstrap Servers
- description: The boostrap servers
- jsonPath: .spec.bootstrapServers
- type: string
- priority: 1
- - name: Ready
- description: The state of the custom resource
- jsonPath: '.status.conditions[?(@.type=="Ready")].status'
- type: string
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- replicas:
- type: integer
- minimum: 0
- description: The number of pods in the `Deployment`. Defaults to `1`.
- image:
- type: string
- description: The docker image for the pods.
- bootstrapServers:
- type: string
- description: >-
- A list of host:port pairs for establishing the initial
- connection to the Kafka cluster.
- tls:
- type: object
- properties:
- trustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: The name of the file certificate in the Secret.
- secretName:
- type: string
- description: The name of the Secret containing the certificate.
- required:
- - certificate
- - secretName
- description: Trusted certificates for TLS connection.
- description: >-
- TLS configuration for connecting Kafka Bridge to the
- cluster.
- authentication:
- type: object
- properties:
- accessToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored in
- the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the access token
- which was obtained from the authorization server.
- accessTokenIsJwt:
- type: boolean
- description: >-
- Configure whether access token should be treated as JWT.
- This should be set to `false` if the authorization
- server returns opaque tokens. Defaults to `true`.
- audience:
- type: string
- description: >-
- OAuth audience to use when authenticating against the
- authorization server. Some authorization servers require
- the audience to be explicitly set. The possible values
- depend on how the authorization server is configured. By
- default, `audience` is not specified when performing the
- token endpoint request.
- certificateAndKey:
- type: object
- properties:
- certificate:
- type: string
- description: The name of the file certificate in the Secret.
- key:
- type: string
- description: The name of the private key in the Secret.
- secretName:
- type: string
- description: The name of the Secret containing the certificate.
- required:
- - certificate
- - key
- - secretName
- description: >-
- Reference to the `Secret` which holds the certificate
- and private key pair.
- clientId:
- type: string
- description: >-
- OAuth Client ID which the Kafka client can use to
- authenticate against the OAuth server and use the token
- endpoint URI.
- clientSecret:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored in
- the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the OAuth client
- secret which the Kafka client can use to authenticate
- against the OAuth server and use the token endpoint URI.
- connectTimeoutSeconds:
- type: integer
- description: >-
- The connect timeout in seconds when connecting to
- authorization server. If not set, the effective connect
- timeout is 60 seconds.
- disableTlsHostnameVerification:
- type: boolean
- description: >-
- Enable or disable TLS hostname verification. Default
- value is `false`.
- enableMetrics:
- type: boolean
- description: >-
- Enable or disable OAuth metrics. Default value is
- `false`.
- httpRetries:
- type: integer
- description: >-
- The maximum number of retries to attempt if an initial
- HTTP request fails. If not set, the default is to not
- attempt any retries.
- httpRetryPauseMs:
- type: integer
- description: >-
- The pause to take before retrying a failed HTTP request.
- If not set, the default is to not pause at all but to
- immediately repeat a request.
- maxTokenExpirySeconds:
- type: integer
- description: >-
- Set or limit time-to-live of the access tokens to the
- specified number of seconds. This should be set if the
- authorization server returns opaque tokens.
- passwordSecret:
- type: object
- properties:
- password:
- type: string
- description: >-
- The name of the key in the Secret under which the
- password is stored.
- secretName:
- type: string
- description: The name of the Secret containing the password.
- required:
- - password
- - secretName
- description: Reference to the `Secret` which holds the password.
- readTimeoutSeconds:
- type: integer
- description: >-
- The read timeout in seconds when connecting to
- authorization server. If not set, the effective read
- timeout is 60 seconds.
- refreshToken:
- type: object
- properties:
- key:
- type: string
- description: >-
- The key under which the secret value is stored in
- the Kubernetes Secret.
- secretName:
- type: string
- description: >-
- The name of the Kubernetes Secret containing the
- secret value.
- required:
- - key
- - secretName
- description: >-
- Link to Kubernetes Secret containing the refresh token
- which can be used to obtain access token from the
- authorization server.
- scope:
- type: string
- description: >-
- OAuth scope to use when authenticating against the
- authorization server. Some authorization servers require
- this to be set. The possible values depend on how
- authorization server is configured. By default `scope`
- is not specified when doing the token endpoint request.
- tlsTrustedCertificates:
- type: array
- items:
- type: object
- properties:
- certificate:
- type: string
- description: The name of the file certificate in the Secret.
- secretName:
- type: string
- description: The name of the Secret containing the certificate.
- required:
- - certificate
- - secretName
- description: >-
- Trusted certificates for TLS connection to the OAuth
- server.
- tokenEndpointUri:
- type: string
- description: Authorization server token endpoint URI.
- type:
- type: string
- enum:
- - tls
- - scram-sha-256
- - scram-sha-512
- - plain
- - oauth
- description: >-
- Authentication type. Currently the supported types are
- `tls`, `scram-sha-256`, `scram-sha-512`, `plain`, and
- 'oauth'. `scram-sha-256` and `scram-sha-512` types use
- SASL SCRAM-SHA-256 and SASL SCRAM-SHA-512
- Authentication, respectively. `plain` type uses SASL
- PLAIN Authentication. `oauth` type uses SASL OAUTHBEARER
- Authentication. The `tls` type uses TLS Client
- Authentication. The `tls` type is supported only over
- TLS connections.
- username:
- type: string
- description: Username used for the authentication.
- required:
- - type
- description: Authentication configuration for connecting to the cluster.
- http:
- type: object
- properties:
- port:
- type: integer
- minimum: 1023
- description: The port which is the server listening on.
- cors:
- type: object
- properties:
- allowedOrigins:
- type: array
- items:
- type: string
- description: >-
- List of allowed origins. Java regular expressions
- can be used.
- allowedMethods:
- type: array
- items:
- type: string
- description: List of allowed HTTP methods.
- required:
- - allowedOrigins
- - allowedMethods
- description: CORS configuration for the HTTP Bridge.
- description: The HTTP related configuration.
- adminClient:
- type: object
- properties:
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Kafka AdminClient configuration used for AdminClient
- instances created by the bridge.
- description: Kafka AdminClient related configuration.
- consumer:
- type: object
- properties:
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Kafka consumer configuration used for consumer
- instances created by the bridge. Properties with the
- following prefixes cannot be set: ssl.,
- bootstrap.servers, group.id, sasl., security. (with the
- exception of: ssl.endpoint.identification.algorithm,
- ssl.cipher.suites, ssl.protocol, ssl.enabled.protocols).
- description: Kafka consumer related configuration.
- producer:
- type: object
- properties:
- config:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- The Kafka producer configuration used for producer
- instances created by the bridge. Properties with the
- following prefixes cannot be set: ssl.,
- bootstrap.servers, sasl., security. (with the exception
- of: ssl.endpoint.identification.algorithm,
- ssl.cipher.suites, ssl.protocol, ssl.enabled.protocols).
- description: Kafka producer related configuration.
- resources:
- type: object
- properties:
- claims:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- limits:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- requests:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: CPU and memory resources to reserve.
- jvmOptions:
- type: object
- properties:
- '-XX':
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A map of -XX options to the JVM.
- '-Xms':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xms option to to the JVM.'
- '-Xmx':
- type: string
- pattern: '^[0-9]+[mMgG]?$'
- description: '-Xmx option to to the JVM.'
- gcLoggingEnabled:
- type: boolean
- description: >-
- Specifies whether the Garbage Collection logging is
- enabled. The default is false.
- javaSystemProperties:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The system property name.
- value:
- type: string
- description: The system property value.
- description: >-
- A map of additional system properties which will be
- passed using the `-D` option to the JVM.
- description: '**Currently not supported** JVM Options for pods.'
- logging:
- type: object
- properties:
- loggers:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: A Map from logger name to logger level.
- type:
- type: string
- enum:
- - inline
- - external
- description: 'Logging type, must be either ''inline'' or ''external''.'
- valueFrom:
- type: object
- properties:
- configMapKeyRef:
- type: object
- properties:
- key:
- type: string
- name:
- type: string
- optional:
- type: boolean
- description: >-
- Reference to the key in the ConfigMap containing the
- configuration.
- description: >-
- `ConfigMap` entry where the logging configuration is
- stored.
- required:
- - type
- description: Logging configuration for Kafka Bridge.
- clientRackInitImage:
- type: string
- description: >-
- The image of the init container used for initializing the
- `client.rack`.
- rack:
- type: object
- properties:
- topologyKey:
- type: string
- example: topology.kubernetes.io/zone
- description: >-
- A key that matches labels assigned to the Kubernetes
- cluster nodes. The value of the label is used to set a
- broker's `broker.rack` config, and the `client.rack`
- config for Kafka Connect or MirrorMaker 2.
- required:
- - topologyKey
- description: >-
- Configuration of the node label which will be used as the
- client.rack consumer configuration.
- enableMetrics:
- type: boolean
- description: Enable the metrics for the Kafka Bridge. Default is false.
- livenessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults to 3.
- Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default to
- 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults to
- 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default to
- 5 seconds. Minimum value is 1.
- description: Pod liveness checking.
- readinessProbe:
- type: object
- properties:
- failureThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive failures for the probe to be
- considered failed after having succeeded. Defaults to 3.
- Minimum value is 1.
- initialDelaySeconds:
- type: integer
- minimum: 0
- description: >-
- The initial delay before first the health is first
- checked. Default to 15 seconds. Minimum value is 0.
- periodSeconds:
- type: integer
- minimum: 1
- description: >-
- How often (in seconds) to perform the probe. Default to
- 10 seconds. Minimum value is 1.
- successThreshold:
- type: integer
- minimum: 1
- description: >-
- Minimum consecutive successes for the probe to be
- considered successful after having failed. Defaults to
- 1. Must be 1 for liveness. Minimum value is 1.
- timeoutSeconds:
- type: integer
- minimum: 1
- description: >-
- The timeout for each attempted health check. Default to
- 5 seconds. Minimum value is 1.
- description: Pod readiness checking.
- template:
- type: object
- properties:
- deployment:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- deploymentStrategy:
- type: string
- enum:
- - RollingUpdate
- - Recreate
- description: >-
- Pod replacement strategy for deployment
- configuration changes. Valid values are
- `RollingUpdate` and `Recreate`. Defaults to
- `RollingUpdate`.
- description: Template for Kafka Bridge `Deployment`.
- pod:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- imagePullSecrets:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: >-
- List of references to secrets in the same namespace
- to use for pulling any of the images used by this
- Pod. When the `STRIMZI_IMAGE_PULL_SECRETS`
- environment variable in Cluster Operator and the
- `imagePullSecrets` option are specified, only the
- `imagePullSecrets` variable is used and the
- `STRIMZI_IMAGE_PULL_SECRETS` variable is ignored.
- securityContext:
- type: object
- properties:
- fsGroup:
- type: integer
- fsGroupChangePolicy:
- type: string
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- supplementalGroups:
- type: array
- items:
- type: integer
- sysctls:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- value:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: >-
- Configures pod-level security attributes and common
- container settings.
- terminationGracePeriodSeconds:
- type: integer
- minimum: 0
- description: >-
- The grace period is the duration in seconds after
- the processes running in the pod are sent a
- termination signal, and the time when the processes
- are forcibly halted with a kill signal. Set this
- value to longer than the expected cleanup time for
- your process. Value must be a non-negative integer.
- A zero value indicates delete immediately. You might
- need to increase the grace period for very large
- Kafka clusters, so that the Kafka brokers have
- enough time to transfer their work to another broker
- before they are terminated. Defaults to 30 seconds.
- affinity:
- type: object
- properties:
- nodeAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- preference:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: object
- properties:
- nodeSelectorTerms:
- type: array
- items:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchFields:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- podAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- podAntiAffinity:
- type: object
- properties:
- preferredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- podAffinityTerm:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- weight:
- type: integer
- requiredDuringSchedulingIgnoredDuringExecution:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaceSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- namespaces:
- type: array
- items:
- type: string
- topologyKey:
- type: string
- description: The pod's affinity rules.
- tolerations:
- type: array
- items:
- type: object
- properties:
- effect:
- type: string
- key:
- type: string
- operator:
- type: string
- tolerationSeconds:
- type: integer
- value:
- type: string
- description: The pod's tolerations.
- priorityClassName:
- type: string
- description: >-
- The name of the priority class used to assign
- priority to the pods. For more information about
- priority classes, see {K8sPriorityClass}.
- schedulerName:
- type: string
- description: >-
- The name of the scheduler used to dispatch this
- `Pod`. If not specified, the default scheduler will
- be used.
- hostAliases:
- type: array
- items:
- type: object
- properties:
- hostnames:
- type: array
- items:
- type: string
- ip:
- type: string
- description: >-
- The pod's HostAliases. HostAliases is an optional
- list of hosts and IPs that will be injected into the
- Pod's hosts file if specified.
- tmpDirSizeLimit:
- type: string
- pattern: '^([0-9.]+)([eEinumkKMGTP]*[-+]?[0-9]*)$'
- description: >-
- Defines the total amount (for example `1Gi`) of
- local storage required for temporary EmptyDir volume
- (`/tmp`). Default value is `5Mi`.
- enableServiceLinks:
- type: boolean
- description: >-
- Indicates whether information about services should
- be injected into Pod's environment variables.
- topologySpreadConstraints:
- type: array
- items:
- type: object
- properties:
- labelSelector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- matchLabelKeys:
- type: array
- items:
- type: string
- maxSkew:
- type: integer
- minDomains:
- type: integer
- nodeAffinityPolicy:
- type: string
- nodeTaintsPolicy:
- type: string
- topologyKey:
- type: string
- whenUnsatisfiable:
- type: string
- description: The pod's topology spread constraints.
- description: Template for Kafka Bridge `Pods`.
- apiService:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- ipFamilyPolicy:
- type: string
- enum:
- - SingleStack
- - PreferDualStack
- - RequireDualStack
- description: >-
- Specifies the IP Family Policy used by the service.
- Available options are `SingleStack`,
- `PreferDualStack` and `RequireDualStack`.
- `SingleStack` is for a single IP family.
- `PreferDualStack` is for two IP families on
- dual-stack configured clusters or a single IP family
- on single-stack clusters. `RequireDualStack` fails
- unless there are two IP families on dual-stack
- configured clusters. If unspecified, Kubernetes will
- choose the default value based on the service type.
- Available on Kubernetes 1.20 and newer.
- ipFamilies:
- type: array
- items:
- type: string
- enum:
- - IPv4
- - IPv6
- description: >-
- Specifies the IP Families used by the service.
- Available options are `IPv4` and `IPv6. If
- unspecified, Kubernetes will choose the default
- value based on the `ipFamilyPolicy` setting.
- Available on Kubernetes 1.20 and newer.
- description: Template for Kafka Bridge API `Service`.
- podDisruptionBudget:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: >-
- Metadata to apply to the
- `PodDisruptionBudgetTemplate` resource.
- maxUnavailable:
- type: integer
- minimum: 0
- description: >-
- Maximum number of unavailable pods to allow
- automatic Pod eviction. A Pod eviction is allowed
- when the `maxUnavailable` number of pods or fewer
- are unavailable after the eviction. Setting this
- value to 0 prevents all voluntary evictions, so the
- pods must be evicted manually. Defaults to 1.
- description: Template for Kafka Bridge `PodDisruptionBudget`.
- bridgeContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka Bridge container.
- clusterRoleBinding:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Bridge ClusterRoleBinding.
- serviceAccount:
- type: object
- properties:
- metadata:
- type: object
- properties:
- labels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Labels added to the Kubernetes resource.
- annotations:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: Annotations added to the Kubernetes resource.
- description: Metadata applied to the resource.
- description: Template for the Kafka Bridge service account.
- initContainer:
- type: object
- properties:
- env:
- type: array
- items:
- type: object
- properties:
- name:
- type: string
- description: The environment variable key.
- value:
- type: string
- description: The environment variable value.
- description: >-
- Environment variables which should be applied to the
- container.
- securityContext:
- type: object
- properties:
- allowPrivilegeEscalation:
- type: boolean
- capabilities:
- type: object
- properties:
- add:
- type: array
- items:
- type: string
- drop:
- type: array
- items:
- type: string
- privileged:
- type: boolean
- procMount:
- type: string
- readOnlyRootFilesystem:
- type: boolean
- runAsGroup:
- type: integer
- runAsNonRoot:
- type: boolean
- runAsUser:
- type: integer
- seLinuxOptions:
- type: object
- properties:
- level:
- type: string
- role:
- type: string
- type:
- type: string
- user:
- type: string
- seccompProfile:
- type: object
- properties:
- localhostProfile:
- type: string
- type:
- type: string
- windowsOptions:
- type: object
- properties:
- gmsaCredentialSpec:
- type: string
- gmsaCredentialSpecName:
- type: string
- hostProcess:
- type: boolean
- runAsUserName:
- type: string
- description: Security context for the container.
- description: Template for the Kafka Bridge init container.
- description: >-
- Template for Kafka Bridge resources. The template allows
- users to specify how a `Deployment` and `Pod` is generated.
- tracing:
- type: object
- properties:
- type:
- type: string
- enum:
- - jaeger
- - opentelemetry
- description: >-
- Type of the tracing used. Currently the only supported
- types are `jaeger` for OpenTracing (Jaeger) tracing and
- `opentelemetry` for OpenTelemetry tracing. The
- OpenTracing (Jaeger) tracing is deprecated.
- required:
- - type
- description: The configuration of tracing in Kafka Bridge.
- required:
- - bootstrapServers
- description: The specification of the Kafka Bridge.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- url:
- type: string
- description: >-
- The URL at which external client applications can access the
- Kafka Bridge.
- labelSelector:
- type: string
- description: Label selector for pods providing this resource.
- replicas:
- type: integer
- description: >-
- The current number of pods being used to provide this
- resource.
- description: The status of the Kafka Bridge.
- ---
- apiVersion: apiextensions.k8s.io/v1
- kind: CustomResourceDefinition
- metadata:
- name: strimzipodsets.core.strimzi.io
- labels:
- app: strimzi
- strimzi.io/crd-install: 'true'
- spec:
- group: core.strimzi.io
- names:
- kind: StrimziPodSet
- listKind: StrimziPodSetList
- singular: strimzipodset
- plural: strimzipodsets
- shortNames:
- - sps
- categories:
- - strimzi
- scope: Namespaced
- conversion:
- strategy: None
- versions:
- - name: v1beta2
- served: true
- storage: true
- subresources:
- status: {}
- additionalPrinterColumns:
- - name: Pods
- description: Number of pods managed by the StrimziPodSet
- jsonPath: .status.pods
- type: integer
- - name: Ready Pods
- description: Number of ready pods managed by the StrimziPodSet
- jsonPath: .status.readyPods
- type: integer
- - name: Current Pods
- description: Number of up-to-date pods managed by the StrimziPodSet
- jsonPath: .status.currentPods
- type: integer
- - name: Age
- description: Age of the StrimziPodSet
- jsonPath: .metadata.creationTimestamp
- type: date
- schema:
- openAPIV3Schema:
- type: object
- properties:
- spec:
- type: object
- properties:
- selector:
- type: object
- properties:
- matchExpressions:
- type: array
- items:
- type: object
- properties:
- key:
- type: string
- operator:
- type: string
- values:
- type: array
- items:
- type: string
- matchLabels:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: >-
- Selector is a label query which matches all the pods managed
- by this `StrimziPodSet`. Only `matchLabels` is supported. If
- `matchExpressions` is set, it will be ignored.
- pods:
- type: array
- items:
- x-kubernetes-preserve-unknown-fields: true
- type: object
- description: The Pods managed by this StrimziPodSet.
- required:
- - selector
- - pods
- description: The specification of the StrimziPodSet.
- status:
- type: object
- properties:
- conditions:
- type: array
- items:
- type: object
- properties:
- type:
- type: string
- description: >-
- The unique identifier of a condition, used to
- distinguish between other conditions in the resource.
- status:
- type: string
- description: >-
- The status of the condition, either True, False or
- Unknown.
- lastTransitionTime:
- type: string
- description: >-
- Last time the condition of a type changed from one
- status to another. The required format is
- 'yyyy-MM-ddTHH:mm:ssZ', in the UTC time zone.
- reason:
- type: string
- description: >-
- The reason for the condition's last transition (a
- single word in CamelCase).
- message:
- type: string
- description: >-
- Human-readable message indicating details about the
- condition's last transition.
- description: List of status conditions.
- observedGeneration:
- type: integer
- description: >-
- The generation of the CRD that was last reconciled by the
- operator.
- pods:
- type: integer
- description: Number of pods managed by the StrimziPodSet controller.
- readyPods:
- type: integer
- description: >-
- Number of pods managed by the StrimziPodSet controller that
- are ready.
- currentPods:
- type: integer
- description: >-
- Number of pods managed by the StrimziPodSet controller that
- have the current revision.
- description: The status of the StrimziPodSet.
|