PostgresPolicy
On this page
CRD API reference · Served version v1alpha1.
Required fields apply when their containing object is present. Defaults shown are API-server defaults; null requires nullable. Standard metadata follows Kubernetes conventions. Status is controller-owned except documented decisions.
For workflows, see operator guidance, approval, candidates, and ephemeral access.
Spec
| Path | Definition |
|---|---|
spec | object; required. Spec for a `PostgresPolicy` custom resource. Defines the desired state of PostgreSQL roles, grants, default privileges, and memberships for a single database connection. Constraints: {"required":["connection"]}. |
spec.allow_schema_owner_transfers | boolean; optional. Permit adopt mode to transfer schema ownership (`ALTER SCHEMA ... OWNER TO ...`) on schemas whose live owner differs. Without this, apply-mode adopt policies fail such plans with an `OwnerTransferBlocked` condition — the operator equivalent of the CLI's `--allow-schema-owner-transfers`. Default: false. |
spec.approval | string; optional. Approval mode for plans generated by this policy. Set this explicitly. When omitted it is currently inferred from `spec.mode` (`apply` implies `auto`, `observe` implies `manual`), which leaves a policy's execution gate invisible on the object. That inference is deprecated: a policy relying on it reports an `ApprovalUnset` status condition, and a future release will reject a policy that omits this field. Constraints: {"enum":["manual","auto"],"nullable":true}. |
spec.connection | object; required. Database connection configuration. |
spec.connection.params | object; optional. Structured connection parameters. Each field is either a plain string or a reference to a Secret key. Mutually exclusive with `secretRef`. Constraints: {"nullable":true}. |
spec.connection.params.auth | object; optional. Provider-backed authentication for connections that use short-lived credentials instead of a static PostgreSQL password. Constraints: {"nullable":true}. |
spec.connection.params.auth.impersonateServiceAccount | string; optional. Target Google service account to impersonate before requesting the Cloud SQL login token. Omit to use the pod's bound identity. Constraints: {"nullable":true}. |
spec.connection.params.auth.scope | string; optional. OAuth scope requested for the access token. Constraints: {"nullable":true}. |
spec.connection.params.auth.type | string; required. Provider authentication mechanism. Constraints: {"enum":["gcp_workload_identity"]}. |
spec.connection.params.auth | oneOf branch 1 (conditional). Constraints and fields below apply within this branch. |
spec.connection.params.auth | union; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"required":["type"]}. |
spec.connection.params.dbname | string; optional. Database name as a literal value. Constraints: {"nullable":true}. |
spec.connection.params.dbnameSecret | object; optional. Database name from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}. |
spec.connection.params.dbnameSecret.key | string; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.dbnameSecret.name | string; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.host | string; optional. PostgreSQL host as a literal value. Constraints: {"nullable":true}. |
spec.connection.params.hostSecret | object; optional. PostgreSQL host from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}. |
spec.connection.params.hostSecret.key | string; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.hostSecret.name | string; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.password | string; optional. Password as a literal value (not recommended for production). Constraints: {"nullable":true}. |
spec.connection.params.passwordSecret | object; optional. Password from a Secret key (recommended). Constraints: {"nullable":true,"required":["key","name"]}. |
spec.connection.params.passwordSecret.key | string; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.passwordSecret.name | string; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.port | integer; optional. Port as a literal value. Defaults to 5432 if neither port nor portSecret is set. Constraints: {"format":"uint16","maximum":65535.0,"minimum":0.0,"nullable":true}. |
spec.connection.params.portSecret | object; optional. Port from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}. |
spec.connection.params.portSecret.key | string; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.portSecret.name | string; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.setRole | string; optional. Run `SET ROLE "<value>"` once on every pooled connection. Useful when the operator authenticates as a low-privilege identity (e.g. a Cloud SQL IAM user) that has been granted membership in a privileged role like `cloudsqlsuperuser` — PostgreSQL does not inherit role *attributes* (`CREATEROLE`, `CREATEDB`, …) through `GRANT … TO …`, so `SET ROLE` is required for the connection to act with the parent role's attributes. Must be a simple PostgreSQL identifier matching `^[A-Za-z_][A-Za-z0-9_$-]*$`. The pattern intentionally excludes `@` and `.` — `setRole` is for switching to a privileged *group* role (e.g. `cloudsqlsuperuser`), not an IAM-style principal like `pgroles-operator@project.iam`, which has no extra attributes to inherit via `SET ROLE`. Constraints: {"nullable":true,"pattern":"^[A-Za-z_][A-Za-z0-9_$-]*$"}. |
spec.connection.params.sslMode | string; optional. SSL mode as a literal value. Constraints: {"nullable":true}. |
spec.connection.params.sslModeSecret | object; optional. SSL mode from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}. |
spec.connection.params.sslModeSecret.key | string; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.sslModeSecret.name | string; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.username | string; optional. Username as a literal value. Constraints: {"nullable":true}. |
spec.connection.params.usernameSecret | object; optional. Username from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}. |
spec.connection.params.usernameSecret.key | string; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.params.usernameSecret.name | string; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.connection.requirePhysicalIdentity | boolean; optional. Refuse to plan or execute unless the target's *physical* identity — `pg_control_system().system_identifier` — can be read. Off by default: every mainstream managed PostgreSQL exposes the identifier, but PostgreSQL-protocol engines that are not PostgreSQL (CockroachDB, Spanner's PostgreSQL interface, Redshift, Aurora DSQL) do not implement it, and those targets run on the logical identity alone. Set it where a real PostgreSQL is expected and losing the strongest half of the target binding should stop reconciliation rather than silently weaken it. Constraints: {"nullable":true}. |
spec.connection.secretKey | string; optional. Key within the Secret to read. Defaults to `DATABASE_URL`. Only used with `secretRef`. Constraints: {"nullable":true}. |
spec.connection.secretRef | object; optional. Reference to a Kubernetes Secret containing a connection URL. Mutually exclusive with `params`. Constraints: {"nullable":true,"required":["name"]}. |
spec.connection.secretRef.name | string; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.default_owner | string; optional. Default owner for ALTER DEFAULT PRIVILEGES (e.g. "app_owner"). Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.default_privileges | array; optional. One-off default privileges. Default: []. Constraints: {"maxItems":512}. |
spec.default_privileges[] | object; item or branch. Default privilege configuration. The scope rules are also expressed as CEL so the API server rejects a bad entry at apply time. `resolved_scope` enforces the same rules for the CLI, which has no admission step. Constraints: {"required":["grant"]}. |
spec.default_privileges[] | CEL: {"message":"exactly one of `schema` and `scope` must be set","rule":"has(self.schema) != has(self.scope)"}. Evaluated with self at this path; oldSelf refers to the previous value on update. |
spec.default_privileges[].grant | array; required. Grantee, privileges, and future object kind to reconcile. Constraints: {"maxItems":64}. |
spec.default_privileges[].grant[] | object; item or branch. A single default privilege grant entry. Constraints: {"required":["on_type","privileges"]}. |
spec.default_privileges[].grant[].ensure | string; optional. Desired privilege state: present grants it; absent explicitly revokes it. Constraints: {"enum":["present","absent"]}. |
spec.default_privileges[].grant[].on_type | string; required. Kind of future object affected by the default privilege. Constraints: {"enum":["table","view","materialized_view","sequence","function","schema","database","type"]}. |
spec.default_privileges[].grant[].privileges | array; required. PostgreSQL privileges to reconcile on the selected objects. Constraints: {"maxItems":16,"minItems":1}. |
spec.default_privileges[].grant[].privileges[] | string; item or branch. PostgreSQL privilege types. Constraints: {"enum":["SELECT","INSERT","UPDATE","DELETE","TRUNCATE","REFERENCES","TRIGGER","EXECUTE","USAGE","CREATE","CONNECT","TEMPORARY"]}. |
spec.default_privileges[].grant[].role | string; optional. The role receiving the default privilege. Only used in top-level default_privileges (in profiles, the role is determined by expansion). The exact-uppercase value `PUBLIC` means the PostgreSQL PUBLIC pseudo-role. Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.default_privileges[].owner | string; optional. The role that owns newly created objects. If omitted, uses manifest's default_owner. Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.default_privileges[].schema | string; optional. Schema shorthand, equivalent to `scope: {type: schema, schema: ...}`. Exactly one of `schema` and `scope` must be set. Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.default_privileges[].scope | object; optional. Where the defaults apply: one schema, or owner-wide (global). Global scope renders `ALTER DEFAULT PRIVILEGES` without an `IN SCHEMA` clause. Constraints: {"nullable":true,"required":["type"]}. |
spec.default_privileges[].scope | CEL: {"message":"`schema` is required when type is `schema` and forbidden when type is `global`","rule":"has(self.schema) == (self.type == 'schema')"}. Evaluated with self at this path; oldSelf refers to the previous value on update. |
spec.default_privileges[].scope.schema | string; optional. Schema name. Required for `type: schema`, forbidden for `type: global`. Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.default_privileges[].scope.type | string; required. Global or per-schema scope of the default privilege. Constraints: {"enum":["global","schema"]}. |
spec.grants | array; optional. One-off grants. Default: []. Constraints: {"maxItems":4096}. |
spec.grants[] | object; item or branch. A concrete grant on a specific object or wildcard. Constraints: {"required":["object","privileges","role"]}. |
spec.grants[].ensure | string; optional. Desired object privilege state: present grants it; absent explicitly revokes it. Constraints: {"enum":["present","absent"]}. |
spec.grants[].object | object; required. Object kind and target to which the privileges apply. Constraints: {"required":["type"]}. |
spec.grants[].object | CEL: {"message":"database grant targets must set `name`","rule":"self.type != 'database' || has(self.name)"}. Evaluated with self at this path; oldSelf refers to the previous value on update. |
spec.grants[].object.name | string; optional. Object name, or "*" for all objects. Omit for schema-level grants; required for database grants, where it names the connected database. Constraints: {"maxLength":256,"minLength":1,"nullable":true}. |
spec.grants[].object.schema | string; optional. Schema name. Required for most object types except database. Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.grants[].object.type | string; required. PostgreSQL object kind. Constraints: {"enum":["table","view","materialized_view","sequence","function","schema","database","type"]}. |
spec.grants[].privileges | array; required. PostgreSQL privileges to reconcile on the selected objects. Constraints: {"maxItems":16,"minItems":1}. |
spec.grants[].privileges[] | string; item or branch. PostgreSQL privilege types. Constraints: {"enum":["SELECT","INSERT","UPDATE","DELETE","TRUNCATE","REFERENCES","TRIGGER","EXECUTE","USAGE","CREATE","CONNECT","TEMPORARY"]}. |
spec.grants[].role | string; required. The grantee. The exact-uppercase value `PUBLIC` means the PostgreSQL PUBLIC pseudo-role; any other value is an ordinary role name. Constraints: {"maxLength":63,"minLength":1}. |
spec.interval | string; optional. Reconciliation interval (e.g. "5m", "1h"). Defaults to "5m". Default: "5m". |
spec.memberships | array; optional. Membership edges. Default: []. Constraints: {"maxItems":2048}. |
spec.memberships[] | object; item or branch. A membership declaration — which members belong to a role. Constraints: {"required":["members","role"]}. |
spec.memberships[].exclusive | boolean; optional. Assert that `members` is the complete membership of `role`: plan a REVOKE for any live member not listed here. Only meaningful for predefined (`pg_*`) and `external: true` roles, whose undeclared members are otherwise left untouched — memberships of ordinary managed roles are already reconciled exhaustively. Defaults to `false` so that adopting pgroles never strips provider-granted memberships (for example `pg_monitor` grants made by a cloud platform) without an explicit assertion. |
spec.memberships[].members | array; required. Roles that should receive this membership. Constraints: {"maxItems":512}. |
spec.memberships[].members[] | object; item or branch. A single member of a role. Both `inherit` and `admin` are optional. When omitted, they default to `inherit: true` and `admin: false` at resolution time (in `RoleGraph` construction). Keeping them optional in the CRD avoids Kubernetes injecting default values into the stored resource, which causes perpetual diffs in GitOps tools like ArgoCD. Constraints: {"required":["name"]}. |
spec.memberships[].members[].admin | boolean; optional. Whether the member can administer the role. Defaults to `false`. Constraints: {"nullable":true}. |
spec.memberships[].members[].inherit | boolean; optional. Whether the member inherits the role's privileges. Defaults to `true`. Constraints: {"nullable":true}. |
spec.memberships[].members[].name | string; required. PostgreSQL role receiving the membership. Constraints: {"maxLength":63,"minLength":1}. |
spec.memberships[].role | string; required. PostgreSQL role granted to the listed members. Constraints: {"maxLength":63,"minLength":1}. |
spec.mode | string; optional. Reconciliation mode: `apply` executes SQL, `observe` computes drift only. Default: "apply". Constraints: {"enum":["apply","observe","plan"]}. |
spec.profiles | object; optional. Reusable privilege profiles. Default: {}. Constraints: {"maxProperties":128}. |
spec.profiles.<name> | object; item or branch. A reusable privilege profile. |
spec.profiles.<name>.config | object; optional. Role-level configuration parameter defaults for generated roles, applied via `ALTER ROLE ... SET parameter = value`. Values support the `{schema}` and `{profile}` placeholders, substituted per `schema x profile` expansion (e.g. `search_path: "{schema}"`). Constraints: {"maxProperties":32}. |
spec.profiles.<name>.config.<name> | string; item or branch. A role configuration parameter value. Values are always strings — quote numbers and booleans (e.g. `statement_timeout: "30000"`, `jit: "off"`). The Kubernetes CRD schema types config values as strings, and the CLI enforces the same rule so a manifest means the same thing whether it is applied with `pgroles` or `kubectl`. PostgreSQL coerces the string to the parameter's type. Constraints: {"maxLength":256}. |
spec.profiles.<name>.default_privileges | array; optional. Privileges to grant on future objects created by the configured owner. Default: []. Constraints: {"maxItems":32}. |
spec.profiles.<name>.default_privileges[] | object; item or branch. Default privilege grant within a profile. Constraints: {"required":["on_type","privileges"]}. |
spec.profiles.<name>.default_privileges[].ensure | string; optional. Whether the privilege must be present or absent. Matches the top-level `default_privileges` entries, which carry the same field. Constraints: {"enum":["present","absent"]}. |
spec.profiles.<name>.default_privileges[].on_type | string; required. Kind of future object affected by the default privilege. Constraints: {"enum":["table","view","materialized_view","sequence","function","schema","database","type"]}. |
spec.profiles.<name>.default_privileges[].privileges | array; required. PostgreSQL privileges to reconcile on the selected objects. Constraints: {"maxItems":16,"minItems":1}. |
spec.profiles.<name>.default_privileges[].privileges[] | string; item or branch. PostgreSQL privilege types. Constraints: {"enum":["SELECT","INSERT","UPDATE","DELETE","TRUNCATE","REFERENCES","TRIGGER","EXECUTE","USAGE","CREATE","CONNECT","TEMPORARY"]}. |
spec.profiles.<name>.default_privileges[].role | string; optional. Grantee role; omitted values use the generated profile role. Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.profiles.<name>.grants | array; optional. Object privilege templates expanded for each bound schema. Default: []. Constraints: {"maxItems":64}. |
spec.profiles.<name>.grants[] | object; item or branch. Grant template within a profile. Constraints: {"required":["object","privileges"]}. |
spec.profiles.<name>.grants[].ensure | string; optional. Whether the privilege must be present or absent. Matches the top-level `grants` entries, which carry the same field. Profiles are additive templates, so validation rejects `absent`; the schema accepts it so the API server does not prune the value before that check can name it. Constraints: {"enum":["present","absent"]}. |
spec.profiles.<name>.grants[].object | object; required. Object kind and target to which the privileges apply. Constraints: {"required":["type"]}. |
spec.profiles.<name>.grants[].object.name | string; optional. Object name; omission selects the object-kind scope supported by the profile. Constraints: {"maxLength":256,"minLength":1,"nullable":true}. |
spec.profiles.<name>.grants[].object.type | string; required. PostgreSQL object kind. Constraints: {"enum":["table","view","materialized_view","sequence","function","schema","database","type"]}. |
spec.profiles.<name>.grants[].privileges | array; required. PostgreSQL privileges to reconcile on the selected objects. Constraints: {"maxItems":16,"minItems":1}. |
spec.profiles.<name>.grants[].privileges[] | string; item or branch. PostgreSQL privilege types. Constraints: {"enum":["SELECT","INSERT","UPDATE","DELETE","TRUNCATE","REFERENCES","TRIGGER","EXECUTE","USAGE","CREATE","CONNECT","TEMPORARY"]}. |
spec.profiles.<name>.inherit | boolean; optional. Whether privileges from role memberships are inherited automatically. Constraints: {"nullable":true}. |
spec.profiles.<name>.login | boolean; optional. Whether the role may initiate database sessions. Constraints: {"nullable":true}. |
spec.reconciliation_mode | string; optional. Convergence strategy: how aggressively to converge the database. - `authoritative` (default): revoke undeclared managed privileges and drop undeclared roles within the configured inspection scope. External roles are not altered or dropped; PUBLIC targets require explicit rules. - `additive`: only grant, never revoke — safe for incremental adoption; `ensure: absent` assertions are ignored with a warning condition. - `adopt`: manage declared roles fully, but never drop undeclared roles. Default: "authoritative". Constraints: {"enum":["authoritative","additive","adopt"]}. |
spec.retirements | array; optional. Explicit role-retirement workflows for roles that should be removed. Keyed by `role`, which is this list's unique identifier rather than `name`. Retiring one role twice was never meaningful, so the key is unambiguous. Default: []. Constraints: {"maxItems":512,"x-kubernetes-list-map-keys":["role"],"x-kubernetes-list-type":"map"}. |
spec.retirements[] | object; item or branch. Declarative workflow for retiring an existing role. Constraints: {"required":["role"]}. |
spec.retirements[].drop_owned | boolean; optional. Whether to run `DROP OWNED BY` before dropping the role. Default: false. |
spec.retirements[].reassign_owned_to | string; optional. Optional successor role for `REASSIGN OWNED BY ... TO ...`. Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.retirements[].role | string; required. The role to retire and ultimately drop. Constraints: {"maxLength":63,"minLength":1}. |
spec.retirements[].terminate_sessions | boolean; optional. Whether to terminate other active sessions for the role before drop. Default: false. |
spec.role_pattern | string; optional. Default role naming pattern. Schema bindings can override it. Supports `{schema}` and requires `{profile}`; falls back to `{schema}-{profile}`. Constraints: {"maxLength":128,"minLength":1,"nullable":true}. |
spec.roles | array; optional. One-off role definitions. Keyed by `name`; see `schemas`. Default: []. Constraints: {"maxItems":1024,"x-kubernetes-list-map-keys":["name"],"x-kubernetes-list-type":"map"}. |
spec.roles[] | object; item or branch. A concrete PostgreSQL role definition. Constraints: {"required":["name"]}. |
spec.roles[].bypassrls | boolean; optional. Whether the role bypasses row-level security. Constraints: {"nullable":true}. |
spec.roles[].comment | string; optional. Descriptive PostgreSQL role comment. Constraints: {"maxLength":256,"nullable":true}. |
spec.roles[].config | object; optional. Role-level configuration parameter defaults, applied via `ALTER ROLE ... SET parameter = value` (e.g. `role: combined`, `search_path: app`). Settings present on the role in the database but absent here are RESET in authoritative mode. Constraints: {"maxProperties":32}. |
spec.roles[].config.<name> | string; item or branch. A role configuration parameter value. Values are always strings — quote numbers and booleans (e.g. `statement_timeout: "30000"`, `jit: "off"`). The Kubernetes CRD schema types config values as strings, and the CLI enforces the same rule so a manifest means the same thing whether it is applied with `pgroles` or `kubectl`. PostgreSQL coerces the string to the parameter's type. Constraints: {"maxLength":256}. |
spec.roles[].connection_limit | integer; optional. Maximum concurrent connections for the role; -1 means unlimited. Constraints: {"format":"int32","nullable":true}. |
spec.roles[].createdb | boolean; optional. Whether the role may create databases. Constraints: {"nullable":true}. |
spec.roles[].createrole | boolean; optional. Whether the role may create and administer roles, subject to server-version rules. Constraints: {"nullable":true}. |
spec.roles[].external | boolean; optional. Treat this role as externally managed. The operator may reference it in grants, ownership, and memberships, but will not create, alter, drop, or password-manage it. Declared membership edges remain managed. Default: false. |
spec.roles[].inherit | boolean; optional. Whether privileges from role memberships are inherited automatically. Constraints: {"nullable":true}. |
spec.roles[].login | boolean; optional. Whether the role may initiate database sessions. Constraints: {"nullable":true}. |
spec.roles[].name | string; required. PostgreSQL role name. Constraints: {"maxLength":63,"minLength":1}. |
spec.roles[].password | object; optional. Password source for this role. Either a reference to an existing Secret or a request for the operator to generate one. Constraints: {"nullable":true}. |
spec.roles[].password.generate | object; optional. Generate a random password and store it in a new Kubernetes Secret. Mutually exclusive with `secretRef`. Constraints: {"nullable":true}. |
spec.roles[].password.generate.length | integer; optional. Password length. Defaults to 32. Minimum 16, maximum 128. Constraints: {"format":"uint32","minimum":0.0,"nullable":true}. |
spec.roles[].password.generate.secretKey | string; optional. Key within the generated Secret. Defaults to `password`. Constraints: {"maxLength":253,"minLength":1,"nullable":true}. |
spec.roles[].password.generate.secretName | string; optional. Override the generated Secret name. Defaults to `{policy}-pgr-{role}`. Constraints: {"maxLength":253,"minLength":1,"nullable":true}. |
spec.roles[].password.secretKey | string; optional. Key within the referenced Secret. Defaults to the role name. Only used with `secretRef`. Constraints: {"maxLength":253,"minLength":1,"nullable":true}. |
spec.roles[].password.secretRef | object; optional. Reference to an existing Kubernetes Secret containing the password. Mutually exclusive with `generate`. Constraints: {"nullable":true,"required":["name"]}. |
spec.roles[].password.secretRef.name | string; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}. |
spec.roles[].password_valid_until | string; optional. Password expiration timestamp (ISO 8601, e.g. "2025-12-31T00:00:00Z"). Constraints: {"maxLength":64,"nullable":true}. |
spec.roles[].preserve_undeclared_grants | boolean; optional. Preserve this role's undeclared in-scope object grants during convergence. Revokes against the role are skipped unless the revoked privileges are explicitly asserted absent (`ensure: absent`). Default: false. |
spec.roles[].replication | boolean; optional. Whether the role may initiate replication connections. Constraints: {"nullable":true}. |
spec.roles[].superuser | boolean; optional. Whether the role bypasses PostgreSQL permission checks as a superuser. Constraints: {"nullable":true}. |
spec.schemas | array; optional. Schema bindings that expand profiles into concrete roles/grants. Keyed by `name` so server-side apply merges entries per schema instead of replacing the whole list. The API server also rejects duplicate keys. Default: []. Constraints: {"maxItems":1024,"x-kubernetes-list-map-keys":["name"],"x-kubernetes-list-type":"map"}. |
spec.schemas[] | object; item or branch. Associates a PostgreSQL schema with one or more reusable privilege profiles. Constraints: {"required":["name"]}. |
spec.schemas[].name | string; required. PostgreSQL schema name. Constraints: {"maxLength":63,"minLength":1}. |
spec.schemas[].owner | string; optional. Override default_owner for this schema's default privileges. Constraints: {"maxLength":63,"minLength":1,"nullable":true}. |
spec.schemas[].profiles | array; optional. Profile names to expand for this schema. Default: []. Constraints: {"maxItems":64}. |
spec.schemas[].profiles[] | string; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"maxLength":63,"minLength":1}. |
spec.schemas[].role_pattern | string; optional. Role naming pattern. Supports `{schema}` and `{profile}` placeholders. Overrides the policy pattern; otherwise inherits it, falling back to `"{schema}-{profile}"`. Constraints: {"maxLength":128,"minLength":1,"nullable":true}. |
spec.suspend | boolean; optional. Suspend reconciliation when true. Defaults to false. Default: false. |
Status (read-only except decisions)
| Path | Definition |
|---|---|
status | object; optional. Status of a `PostgresPolicy` resource. Constraints: {"nullable":true}. |
status.applied_password_source_versions | object; optional. Last applied password source version for each password-managed role. Default: {}. |
status.applied_password_source_versions.<name> | string; item or branch. Constraints on this array item, map value, or conditional schema. |
status.change_summary | object; optional. Summary of changes applied in the last reconciliation. Constraints: {"nullable":true}. |
status.change_summary.default_privileges_revoked | integer; optional. Number of default privilege revoke steps. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.default_privileges_set | integer; optional. Number of default privilege grant steps. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.grants_added | integer; optional. Number of object privilege grant steps. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.grants_revoked | integer; optional. Number of object privilege revoke steps. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.members_added | integer; optional. Number of membership additions. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.members_removed | integer; optional. Number of membership removals. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.passwords_set | integer; optional. Number of password updates. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.roles_altered | integer; optional. Number of role attribute or configuration changes. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.roles_created | integer; optional. Number of role creations. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.roles_dropped | integer; optional. Number of role drops. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.schema_owners_altered | integer; optional. Number of schema ownership changes. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.schemas_created | integer; optional. Number of schema creations. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.sessions_terminated | integer; optional. Number of session-termination steps. Default: 0. Constraints: {"format":"int32"}. |
status.change_summary.total | integer; optional. Number of all planned change steps. Default: 0. Constraints: {"format":"int32"}. |
status.conditions | array; optional. Standard Kubernetes conditions. Default: []. |
status.conditions[] | object; item or branch. A condition on the `PostgresPolicy` resource. Constraints: {"required":["status","type"]}. |
status.conditions[].last_transition_time | string; optional. Last time the condition transitioned. Constraints: {"nullable":true}. |
status.conditions[].message | string; optional. Human-readable message. Constraints: {"nullable":true}. |
status.conditions[].reason | string; optional. Human-readable reason for the condition. Constraints: {"nullable":true}. |
status.conditions[].status | string; required. Status: "True", "False", or "Unknown". |
status.conditions[].type | string; required. Controller-defined condition type, such as Ready, Reconciling, or Degraded. This is an open vocabulary; consult status guidance for operational meanings. |
status.content_digest | string; optional. Canonical digest of this policy's own content, computed by exactly the same function as a candidate's `status.contentDigest` (note the wire names differ: this status object serialises snake_case, so the field is `status.content_digest` here). Promotion is recognised by comparing the two. The value is also the operator's memory of what the content was on the previous reconcile, which is how an edited-after-approval promotion is distinguished from a policy that simply has not changed while a candidate is under review. Constraints: {"nullable":true}. |
status.current_plan_ref | object; optional. Reference to the current/latest plan for this policy. Constraints: {"nullable":true,"required":["name"]}. |
status.current_plan_ref.name | string; required. Name of the PostgresPolicyPlan in the same namespace. |
status.lastHandledReconcileAt | string; optional. Last force-reconcile annotation value handled by the operator. Constraints: {"nullable":true}. |
status.last_attempted_generation | integer; optional. The `.metadata.generation` that was last attempted. Constraints: {"format":"int64","nullable":true}. |
status.last_error | string; optional. Last reconcile error message, if any. Constraints: {"nullable":true}. |
status.last_reconcile_mode | string; optional. Controls whether the operator executes changes or only computes plans. Constraints: {"enum":["apply","observe","plan"],"nullable":true}. |
status.last_successful_reconcile_time | string; optional. ISO 8601 timestamp of the last successful reconciliation. Constraints: {"nullable":true}. |
status.managed_database_identity | string; optional. Canonical identity of the managed database target. Constraints: {"nullable":true}. |
status.observed_generation | integer; optional. The `.metadata.generation` that was last successfully reconciled. Constraints: {"format":"int64","nullable":true}. |
status.owned_roles | array; optional. Roles claimed by this policy's declared ownership scope. Default: []. |
status.owned_roles[] | string; item or branch. Constraints on this array item, map value, or conditional schema. |
status.owned_schemas | array; optional. Schemas claimed by this policy's declared ownership scope. Default: []. |
status.owned_schemas[] | string; item or branch. Constraints on this array item, map value, or conditional schema. |
status.plan_warnings | array; optional. Advisory warnings from the last reconciliation's computed plan — for example adopt-mode schema ownership transfers or an undeclared `default_owner`. Populated even when the plan applied cleanly. Default: []. |
status.plan_warnings[] | string; item or branch. Constraints on this array item, map value, or conditional schema. |
status.transient_failure_count | integer; optional. Consecutive transient operational failures used for exponential backoff. Default: 0. Constraints: {"format":"int32"}. |
Download the complete served OpenAPI schema for structural composition and all Kubernetes extensions.
Generated with crdgen --docs-dir; edit the Rust schema descriptions to change this reference.