EphemeralAccessRequest

On this page

CRD API reference · Served version v1alpha1.

Required fields apply when their containing object is present. Defaults shown are API-server defaults; null requires nullable. Standard metadata follows Kubernetes conventions. Status is controller-owned except documented decisions.

For workflows, see operator guidance, approval, candidates, and ephemeral access.

Spec

PathDefinition
specobject; required. One immutable runtime request for a bounded access bundle. Constraints: {"required":["accessPolicyRef","requestedBy","subject"]}.
specCEL: {"message":"request spec is immutable","rule":"self == oldSelf"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
spec.accessPolicyRefobject; required. EphemeralAccessPolicy in this namespace that defines the requested bundle. Constraints: {"required":["name"]}.
spec.accessPolicyRef.namestring; required. Name of the referenced resource in the same namespace. Constraints: {"maxLength":253,"minLength":1}.
spec.justificationstring; optional. Reason for requesting access; required when the policy demands it. Constraints: {"maxLength":2048,"nullable":true}.
spec.requestedByobject; required. Kubernetes identity which created the request. The supplied Kyverno reference policy overwrites this from authenticated admission `userInfo`. Constraints: {"required":["username"]}.
spec.requestedBy.groupsarray; optional. Kubernetes groups recorded for this actor. Default: []. Constraints: {"maxItems":64}.
spec.requestedBy.groups[]string; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"maxLength":256,"minLength":1}.
spec.requestedBy.uidstring; optional. Optional Kubernetes user UID recorded by admission. Constraints: {"maxLength":128,"nullable":true}.
spec.requestedBy.usernamestring; required. Kubernetes username asserted for this actor; authenticated only when enforced by admission. Constraints: {"maxLength":512,"minLength":1}.
spec.requestedDurationstring; optional. Requested access duration; omission uses the access policy default. Constraints: {"maxLength":64,"nullable":true,"pattern":"^([0-9]+[smh])+$"}.
spec.subjectobject; required. PostgreSQL role receiving the temporary memberships. Constraints: {"required":["role"]}.
spec.subject.rolestring; required. Existing PostgreSQL role receiving temporary access. Constraints: {"maxLength":63,"minLength":1}.

Status (read-only except decisions)

PathDefinition
statusobject; optional. Controller lifecycle state and approval decisions for an access request. Constraints: {"nullable":true}.
statusCEL: {"message":"resolvedAccess is write-once","rule":"!has(oldSelf.resolvedAccess) || (has(self.resolvedAccess) && self.resolvedAccess == oldSelf.resolvedAccess)"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
statusCEL: {"message":"Approved=True and Denied=True are mutually exclusive","rule":"!(self.conditions.exists(c, c.type == 'Approved' && c.status == 'True') && self.conditions.exists(c, c.type == 'Denied' && c.status == 'True'))"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
statusCEL: {"message":"approval decisions are terminal","rule":"oldSelf.conditions.filter(c, (c.type == 'Approved' || c.type == 'Denied') && c.status == 'True').size() == 0 || self.conditions.filter(c, (c.type == 'Approved' || c.type == 'Denied') && c.status == 'True') == oldSelf.conditions.filter(c, (c.type == 'Approved' || c.type == 'Denied') && c.status == 'True')"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
statusCEL: {"message":"decision identity is write-once","rule":"!has(oldSelf.decidedBy) || (has(self.decidedBy) && self.decidedBy == oldSelf.decidedBy)"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
statusCEL: {"message":"a terminal approval decision and decidedBy identity must be recorded together","rule":"self.conditions.exists(c, (c.type == 'Approved' || c.type == 'Denied') && c.status == 'True') == has(self.decidedBy)"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
statusCEL: {"message":"request conditions must use a declared lifecycle or decision type","rule":"self.conditions.all(c, c.type in ['Approved', 'Denied', 'Resolved', 'Ready', 'Applied'])"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
status.activatedAtstring; optional. Timestamp at which the requested access became active. Constraints: {"maxLength":64,"nullable":true}.
status.approvalExpiresAtstring; optional. Timestamp after which a pending approval is no longer actionable. Constraints: {"maxLength":64,"nullable":true}.
status.conditionsarray; optional. Lifecycle observations and terminal Approved or Denied decisions. Default: []. Constraints: {"maxItems":8}.
status.conditions[]object; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"required":["status","type"]}.
status.conditions[].bundleHashstring; optional. Digest of the membership bundle to which this decision applies. Constraints: {"maxLength":71,"nullable":true}.
status.conditions[].grantedDurationstring; optional. Access duration to which this decision applies. Constraints: {"maxLength":64,"nullable":true}.
status.conditions[].lastTransitionTimestring; optional. Timestamp of the last condition-state transition. Constraints: {"maxLength":64,"nullable":true}.
status.conditions[].messagestring; optional. Human-readable explanation of the condition. Constraints: {"maxLength":2048,"nullable":true}.
status.conditions[].reasonstring; optional. Machine-readable reason for the condition. Constraints: {"maxLength":128,"nullable":true}.
status.conditions[].statusstring; required. Condition state, conventionally True, False, or Unknown. Constraints: {"maxLength":16,"minLength":1}.
status.conditions[].typestring; required. Lifecycle or decision condition name. Constraints: {"maxLength":32,"minLength":1}.
status.decidedByobject; optional. Kubernetes identity which approved or denied the request. The supplied Kyverno reference policy overwrites this from authenticated admission `userInfo` in the same status update as the terminal decision. Constraints: {"nullable":true,"required":["username"]}.
status.decidedBy.groupsarray; optional. Kubernetes groups recorded for this actor. Default: []. Constraints: {"maxItems":64}.
status.decidedBy.groups[]string; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"maxLength":256,"minLength":1}.
status.decidedBy.uidstring; optional. Optional Kubernetes user UID recorded by admission. Constraints: {"maxLength":128,"nullable":true}.
status.decidedBy.usernamestring; required. Kubernetes username asserted for this actor; authenticated only when enforced by admission. Constraints: {"maxLength":512,"minLength":1}.
status.endedAtstring; optional. Timestamp at which the request reached its terminal state. Constraints: {"maxLength":64,"nullable":true}.
status.expiresAtstring; optional. Timestamp at which active access must be revoked. Constraints: {"maxLength":64,"nullable":true}.
status.lastErrorstring; optional. Most recent controller error for this request. Constraints: {"maxLength":4096,"nullable":true}.
status.phasestring; optional. Current request lifecycle phase. Default: "Pending". Constraints: {"enum":["Pending","PendingApproval","Applying","Active","Revoking","Ended","Revoked","Cancelled","Denied","ApprovalExpired","Failed"]}.
status.resolvedAccessobject; optional. Write-once snapshot of the resolved target, duration, and exact memberships, recorded before approval so the decision binds to this access bundle. Constraints: {"nullable":true,"required":["accessPolicyGeneration","accessPolicyUid","bundleEncoding","bundleHash","grantedDuration","memberships","targetDatabaseFingerprint","targetPolicyGeneration","targetPolicyUid"]}.
status.resolvedAccess.accessPolicyGenerationinteger; required. Generation of the access policy resolved for this request. Constraints: {"format":"int64"}.
status.resolvedAccess.accessPolicyUidstring; required. UID of the access policy resolved for this request. Constraints: {"maxLength":128}.
status.resolvedAccess.bundleEncodingstring; required. Versioned encoding used to compute the canonical bundle digest. Constraints: {"maxLength":128}.
status.resolvedAccess.bundleHashstring; required. SHA-256 digest of the canonical target and membership bundle. Constraints: {"maxLength":71}.
status.resolvedAccess.grantedDurationstring; required. Resolved duration for which access is granted. Constraints: {"maxLength":64}.
status.resolvedAccess.membershipsarray; required. Exact membership edges frozen for activation and revocation. Constraints: {"maxItems":32}.
status.resolvedAccess.memberships[]object; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"required":["inherit","member","role"]}.
status.resolvedAccess.memberships[].inheritboolean; required. Whether privileges from role memberships are inherited automatically.
status.resolvedAccess.memberships[].memberstring; required. PostgreSQL role receiving the membership. Constraints: {"maxLength":63,"minLength":1}.
status.resolvedAccess.memberships[].rolestring; required. Granted PostgreSQL role. Constraints: {"maxLength":63,"minLength":1}.
status.resolvedAccess.targetDatabaseFingerprintstring; required. SHA-256 fingerprint of resolved host, port, and database name. It binds activation and revocation to one database without persisting secrets. Constraints: {"maxLength":71}.
status.resolvedAccess.targetPolicyGenerationinteger; required. Generation of the target PostgresPolicy at resolution. Constraints: {"format":"int64"}.
status.resolvedAccess.targetPolicyUidstring; required. UID of the PostgresPolicy managing the resolved database. Constraints: {"maxLength":128}.
status.retainedMembershipsarray; optional. Memberships retained because another active request or the base policy still requires them. Default: []. Constraints: {"maxItems":32}.
status.retainedMemberships[]object; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"required":["inherit","member","role"]}.
status.retainedMemberships[].inheritboolean; required. Whether privileges from role memberships are inherited automatically.
status.retainedMemberships[].memberstring; required. PostgreSQL role receiving the membership. Constraints: {"maxLength":63,"minLength":1}.
status.retainedMemberships[].rolestring; required. Granted PostgreSQL role. Constraints: {"maxLength":63,"minLength":1}.

Download the complete served OpenAPI schema for structural composition and all Kubernetes extensions.

Generated with crdgen --docs-dir; edit the Rust schema descriptions to change this reference.