CRD API reference
Use the operator quick start for a working deployment. These references describe the served schemas generated from the source revision used to build this documentation, including nested fields, defaults, requiredness, and CEL admission rules. The site can lead the latest release; compare against the CRDs installed in your cluster or the tagged source for your operator version.
| Resource | Purpose |
|---|---|
| PostgresPolicy | Desired database access and reconciliation settings. |
| PostgresPolicyPlan | Computed changes, approval decisions, and execution results. |
| PostgresPolicyCandidate | Immutable proposed policy content evaluated before promotion. |
| EphemeralAccessPolicy | Requestable membership bundles and approval rules. |
| EphemeralAccessRequest | Temporary access requests and their lifecycle. |
Schema validation is only the admission boundary. The controller also checks database state, executor authority, target identity, and lifecycle invariants. Follow plan approval, candidate promotion, and ephemeral access for those workflows.
For contributors: edit the Rust schema descriptions, regenerate CRDs and run cargo run --bin crdgen -- --docs-dir docs/src/pages/docs/reference --schemas-dir docs/public/crd-reference, then run scripts/check-crd-drift.sh and scripts/check-crd-docs.sh. The documentation generator rejects undocumented spec and status fields. CI checks every generated page, including missing or extra files.