PostgresPolicy

On this page

CRD API reference · Served version v1alpha1.

Required fields apply when their containing object is present. Defaults shown are API-server defaults; null requires nullable. Standard metadata follows Kubernetes conventions. Status is controller-owned except documented decisions.

For workflows, see operator guidance, approval, candidates, and ephemeral access.

Spec

PathDefinition
specobject; required. Spec for a `PostgresPolicy` custom resource. Defines the desired state of PostgreSQL roles, grants, default privileges, and memberships for a single database connection. Constraints: {"required":["connection"]}.
spec.allow_schema_owner_transfersboolean; optional. Permit adopt mode to transfer schema ownership (`ALTER SCHEMA ... OWNER TO ...`) on schemas whose live owner differs. Without this, apply-mode adopt policies fail such plans with an `OwnerTransferBlocked` condition — the operator equivalent of the CLI's `--allow-schema-owner-transfers`. Default: false.
spec.approvalstring; optional. Approval mode for plans generated by this policy. Set this explicitly. When omitted it is currently inferred from `spec.mode` (`apply` implies `auto`, `observe` implies `manual`), which leaves a policy's execution gate invisible on the object. That inference is deprecated: a policy relying on it reports an `ApprovalUnset` status condition, and a future release will reject a policy that omits this field. Constraints: {"enum":["manual","auto"],"nullable":true}.
spec.connectionobject; required. Database connection configuration.
spec.connection.paramsobject; optional. Structured connection parameters. Each field is either a plain string or a reference to a Secret key. Mutually exclusive with `secretRef`. Constraints: {"nullable":true}.
spec.connection.params.authobject; optional. Provider-backed authentication for connections that use short-lived credentials instead of a static PostgreSQL password. Constraints: {"nullable":true}.
spec.connection.params.auth.impersonateServiceAccountstring; optional. Target Google service account to impersonate before requesting the Cloud SQL login token. Omit to use the pod's bound identity. Constraints: {"nullable":true}.
spec.connection.params.auth.scopestring; optional. OAuth scope requested for the access token. Constraints: {"nullable":true}.
spec.connection.params.auth.typestring; required. Provider authentication mechanism. Constraints: {"enum":["gcp_workload_identity"]}.
spec.connection.params.authoneOf branch 1 (conditional). Constraints and fields below apply within this branch.
spec.connection.params.authunion; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"required":["type"]}.
spec.connection.params.dbnamestring; optional. Database name as a literal value. Constraints: {"nullable":true}.
spec.connection.params.dbnameSecretobject; optional. Database name from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}.
spec.connection.params.dbnameSecret.keystring; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.dbnameSecret.namestring; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.hoststring; optional. PostgreSQL host as a literal value. Constraints: {"nullable":true}.
spec.connection.params.hostSecretobject; optional. PostgreSQL host from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}.
spec.connection.params.hostSecret.keystring; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.hostSecret.namestring; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.passwordstring; optional. Password as a literal value (not recommended for production). Constraints: {"nullable":true}.
spec.connection.params.passwordSecretobject; optional. Password from a Secret key (recommended). Constraints: {"nullable":true,"required":["key","name"]}.
spec.connection.params.passwordSecret.keystring; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.passwordSecret.namestring; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.portinteger; optional. Port as a literal value. Defaults to 5432 if neither port nor portSecret is set. Constraints: {"format":"uint16","maximum":65535.0,"minimum":0.0,"nullable":true}.
spec.connection.params.portSecretobject; optional. Port from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}.
spec.connection.params.portSecret.keystring; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.portSecret.namestring; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.setRolestring; optional. Run `SET ROLE "<value>"` once on every pooled connection. Useful when the operator authenticates as a low-privilege identity (e.g. a Cloud SQL IAM user) that has been granted membership in a privileged role like `cloudsqlsuperuser` — PostgreSQL does not inherit role *attributes* (`CREATEROLE`, `CREATEDB`, …) through `GRANT … TO …`, so `SET ROLE` is required for the connection to act with the parent role's attributes. Must be a simple PostgreSQL identifier matching `^[A-Za-z_][A-Za-z0-9_$-]*$`. The pattern intentionally excludes `@` and `.` — `setRole` is for switching to a privileged *group* role (e.g. `cloudsqlsuperuser`), not an IAM-style principal like `pgroles-operator@project.iam`, which has no extra attributes to inherit via `SET ROLE`. Constraints: {"nullable":true,"pattern":"^[A-Za-z_][A-Za-z0-9_$-]*$"}.
spec.connection.params.sslModestring; optional. SSL mode as a literal value. Constraints: {"nullable":true}.
spec.connection.params.sslModeSecretobject; optional. SSL mode from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}.
spec.connection.params.sslModeSecret.keystring; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.sslModeSecret.namestring; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.usernamestring; optional. Username as a literal value. Constraints: {"nullable":true}.
spec.connection.params.usernameSecretobject; optional. Username from a Secret key. Constraints: {"nullable":true,"required":["key","name"]}.
spec.connection.params.usernameSecret.keystring; required. Key within the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.params.usernameSecret.namestring; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.connection.requirePhysicalIdentityboolean; optional. Refuse to plan or execute unless the target's *physical* identity — `pg_control_system().system_identifier` — can be read. Off by default: every mainstream managed PostgreSQL exposes the identifier, but PostgreSQL-protocol engines that are not PostgreSQL (CockroachDB, Spanner's PostgreSQL interface, Redshift, Aurora DSQL) do not implement it, and those targets run on the logical identity alone. Set it where a real PostgreSQL is expected and losing the strongest half of the target binding should stop reconciliation rather than silently weaken it. Constraints: {"nullable":true}.
spec.connection.secretKeystring; optional. Key within the Secret to read. Defaults to `DATABASE_URL`. Only used with `secretRef`. Constraints: {"nullable":true}.
spec.connection.secretRefobject; optional. Reference to a Kubernetes Secret containing a connection URL. Mutually exclusive with `params`. Constraints: {"nullable":true,"required":["name"]}.
spec.connection.secretRef.namestring; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.default_ownerstring; optional. Default owner for ALTER DEFAULT PRIVILEGES (e.g. "app_owner"). Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.default_privilegesarray; optional. One-off default privileges. Default: []. Constraints: {"maxItems":512}.
spec.default_privileges[]object; item or branch. Default privilege configuration. The scope rules are also expressed as CEL so the API server rejects a bad entry at apply time. `resolved_scope` enforces the same rules for the CLI, which has no admission step. Constraints: {"required":["grant"]}.
spec.default_privileges[]CEL: {"message":"exactly one of `schema` and `scope` must be set","rule":"has(self.schema) != has(self.scope)"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
spec.default_privileges[].grantarray; required. Grantee, privileges, and future object kind to reconcile. Constraints: {"maxItems":64}.
spec.default_privileges[].grant[]object; item or branch. A single default privilege grant entry. Constraints: {"required":["on_type","privileges"]}.
spec.default_privileges[].grant[].ensurestring; optional. Desired privilege state: present grants it; absent explicitly revokes it. Constraints: {"enum":["present","absent"]}.
spec.default_privileges[].grant[].on_typestring; required. Kind of future object affected by the default privilege. Constraints: {"enum":["table","view","materialized_view","sequence","function","schema","database","type"]}.
spec.default_privileges[].grant[].privilegesarray; required. PostgreSQL privileges to reconcile on the selected objects. Constraints: {"maxItems":16,"minItems":1}.
spec.default_privileges[].grant[].privileges[]string; item or branch. PostgreSQL privilege types. Constraints: {"enum":["SELECT","INSERT","UPDATE","DELETE","TRUNCATE","REFERENCES","TRIGGER","EXECUTE","USAGE","CREATE","CONNECT","TEMPORARY"]}.
spec.default_privileges[].grant[].rolestring; optional. The role receiving the default privilege. Only used in top-level default_privileges (in profiles, the role is determined by expansion). The exact-uppercase value `PUBLIC` means the PostgreSQL PUBLIC pseudo-role. Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.default_privileges[].ownerstring; optional. The role that owns newly created objects. If omitted, uses manifest's default_owner. Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.default_privileges[].schemastring; optional. Schema shorthand, equivalent to `scope: {type: schema, schema: ...}`. Exactly one of `schema` and `scope` must be set. Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.default_privileges[].scopeobject; optional. Where the defaults apply: one schema, or owner-wide (global). Global scope renders `ALTER DEFAULT PRIVILEGES` without an `IN SCHEMA` clause. Constraints: {"nullable":true,"required":["type"]}.
spec.default_privileges[].scopeCEL: {"message":"`schema` is required when type is `schema` and forbidden when type is `global`","rule":"has(self.schema) == (self.type == 'schema')"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
spec.default_privileges[].scope.schemastring; optional. Schema name. Required for `type: schema`, forbidden for `type: global`. Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.default_privileges[].scope.typestring; required. Global or per-schema scope of the default privilege. Constraints: {"enum":["global","schema"]}.
spec.grantsarray; optional. One-off grants. Default: []. Constraints: {"maxItems":4096}.
spec.grants[]object; item or branch. A concrete grant on a specific object or wildcard. Constraints: {"required":["object","privileges","role"]}.
spec.grants[].ensurestring; optional. Desired object privilege state: present grants it; absent explicitly revokes it. Constraints: {"enum":["present","absent"]}.
spec.grants[].objectobject; required. Object kind and target to which the privileges apply. Constraints: {"required":["type"]}.
spec.grants[].objectCEL: {"message":"database grant targets must set `name`","rule":"self.type != 'database' || has(self.name)"}. Evaluated with self at this path; oldSelf refers to the previous value on update.
spec.grants[].object.namestring; optional. Object name, or "*" for all objects. Omit for schema-level grants; required for database grants, where it names the connected database. Constraints: {"maxLength":256,"minLength":1,"nullable":true}.
spec.grants[].object.schemastring; optional. Schema name. Required for most object types except database. Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.grants[].object.typestring; required. PostgreSQL object kind. Constraints: {"enum":["table","view","materialized_view","sequence","function","schema","database","type"]}.
spec.grants[].privilegesarray; required. PostgreSQL privileges to reconcile on the selected objects. Constraints: {"maxItems":16,"minItems":1}.
spec.grants[].privileges[]string; item or branch. PostgreSQL privilege types. Constraints: {"enum":["SELECT","INSERT","UPDATE","DELETE","TRUNCATE","REFERENCES","TRIGGER","EXECUTE","USAGE","CREATE","CONNECT","TEMPORARY"]}.
spec.grants[].rolestring; required. The grantee. The exact-uppercase value `PUBLIC` means the PostgreSQL PUBLIC pseudo-role; any other value is an ordinary role name. Constraints: {"maxLength":63,"minLength":1}.
spec.intervalstring; optional. Reconciliation interval (e.g. "5m", "1h"). Defaults to "5m". Default: "5m".
spec.membershipsarray; optional. Membership edges. Default: []. Constraints: {"maxItems":2048}.
spec.memberships[]object; item or branch. A membership declaration — which members belong to a role. Constraints: {"required":["members","role"]}.
spec.memberships[].exclusiveboolean; optional. Assert that `members` is the complete membership of `role`: plan a REVOKE for any live member not listed here. Only meaningful for predefined (`pg_*`) and `external: true` roles, whose undeclared members are otherwise left untouched — memberships of ordinary managed roles are already reconciled exhaustively. Defaults to `false` so that adopting pgroles never strips provider-granted memberships (for example `pg_monitor` grants made by a cloud platform) without an explicit assertion.
spec.memberships[].membersarray; required. Roles that should receive this membership. Constraints: {"maxItems":512}.
spec.memberships[].members[]object; item or branch. A single member of a role. Both `inherit` and `admin` are optional. When omitted, they default to `inherit: true` and `admin: false` at resolution time (in `RoleGraph` construction). Keeping them optional in the CRD avoids Kubernetes injecting default values into the stored resource, which causes perpetual diffs in GitOps tools like ArgoCD. Constraints: {"required":["name"]}.
spec.memberships[].members[].adminboolean; optional. Whether the member can administer the role. Defaults to `false`. Constraints: {"nullable":true}.
spec.memberships[].members[].inheritboolean; optional. Whether the member inherits the role's privileges. Defaults to `true`. Constraints: {"nullable":true}.
spec.memberships[].members[].namestring; required. PostgreSQL role receiving the membership. Constraints: {"maxLength":63,"minLength":1}.
spec.memberships[].rolestring; required. PostgreSQL role granted to the listed members. Constraints: {"maxLength":63,"minLength":1}.
spec.modestring; optional. Reconciliation mode: `apply` executes SQL, `observe` computes drift only. Default: "apply". Constraints: {"enum":["apply","observe","plan"]}.
spec.profilesobject; optional. Reusable privilege profiles. Default: {}. Constraints: {"maxProperties":128}.
spec.profiles.<name>object; item or branch. A reusable privilege profile.
spec.profiles.<name>.configobject; optional. Role-level configuration parameter defaults for generated roles, applied via `ALTER ROLE ... SET parameter = value`. Values support the `{schema}` and `{profile}` placeholders, substituted per `schema x profile` expansion (e.g. `search_path: "{schema}"`). Constraints: {"maxProperties":32}.
spec.profiles.<name>.config.<name>string; item or branch. A role configuration parameter value. Values are always strings — quote numbers and booleans (e.g. `statement_timeout: "30000"`, `jit: "off"`). The Kubernetes CRD schema types config values as strings, and the CLI enforces the same rule so a manifest means the same thing whether it is applied with `pgroles` or `kubectl`. PostgreSQL coerces the string to the parameter's type. Constraints: {"maxLength":256}.
spec.profiles.<name>.default_privilegesarray; optional. Privileges to grant on future objects created by the configured owner. Default: []. Constraints: {"maxItems":32}.
spec.profiles.<name>.default_privileges[]object; item or branch. Default privilege grant within a profile. Constraints: {"required":["on_type","privileges"]}.
spec.profiles.<name>.default_privileges[].ensurestring; optional. Whether the privilege must be present or absent. Matches the top-level `default_privileges` entries, which carry the same field. Constraints: {"enum":["present","absent"]}.
spec.profiles.<name>.default_privileges[].on_typestring; required. Kind of future object affected by the default privilege. Constraints: {"enum":["table","view","materialized_view","sequence","function","schema","database","type"]}.
spec.profiles.<name>.default_privileges[].privilegesarray; required. PostgreSQL privileges to reconcile on the selected objects. Constraints: {"maxItems":16,"minItems":1}.
spec.profiles.<name>.default_privileges[].privileges[]string; item or branch. PostgreSQL privilege types. Constraints: {"enum":["SELECT","INSERT","UPDATE","DELETE","TRUNCATE","REFERENCES","TRIGGER","EXECUTE","USAGE","CREATE","CONNECT","TEMPORARY"]}.
spec.profiles.<name>.default_privileges[].rolestring; optional. Grantee role; omitted values use the generated profile role. Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.profiles.<name>.grantsarray; optional. Object privilege templates expanded for each bound schema. Default: []. Constraints: {"maxItems":64}.
spec.profiles.<name>.grants[]object; item or branch. Grant template within a profile. Constraints: {"required":["object","privileges"]}.
spec.profiles.<name>.grants[].ensurestring; optional. Whether the privilege must be present or absent. Matches the top-level `grants` entries, which carry the same field. Profiles are additive templates, so validation rejects `absent`; the schema accepts it so the API server does not prune the value before that check can name it. Constraints: {"enum":["present","absent"]}.
spec.profiles.<name>.grants[].objectobject; required. Object kind and target to which the privileges apply. Constraints: {"required":["type"]}.
spec.profiles.<name>.grants[].object.namestring; optional. Object name; omission selects the object-kind scope supported by the profile. Constraints: {"maxLength":256,"minLength":1,"nullable":true}.
spec.profiles.<name>.grants[].object.typestring; required. PostgreSQL object kind. Constraints: {"enum":["table","view","materialized_view","sequence","function","schema","database","type"]}.
spec.profiles.<name>.grants[].privilegesarray; required. PostgreSQL privileges to reconcile on the selected objects. Constraints: {"maxItems":16,"minItems":1}.
spec.profiles.<name>.grants[].privileges[]string; item or branch. PostgreSQL privilege types. Constraints: {"enum":["SELECT","INSERT","UPDATE","DELETE","TRUNCATE","REFERENCES","TRIGGER","EXECUTE","USAGE","CREATE","CONNECT","TEMPORARY"]}.
spec.profiles.<name>.inheritboolean; optional. Whether privileges from role memberships are inherited automatically. Constraints: {"nullable":true}.
spec.profiles.<name>.loginboolean; optional. Whether the role may initiate database sessions. Constraints: {"nullable":true}.
spec.reconciliation_modestring; optional. Convergence strategy: how aggressively to converge the database. - `authoritative` (default): revoke undeclared managed privileges and drop undeclared roles within the configured inspection scope. External roles are not altered or dropped; PUBLIC targets require explicit rules. - `additive`: only grant, never revoke — safe for incremental adoption; `ensure: absent` assertions are ignored with a warning condition. - `adopt`: manage declared roles fully, but never drop undeclared roles. Default: "authoritative". Constraints: {"enum":["authoritative","additive","adopt"]}.
spec.retirementsarray; optional. Explicit role-retirement workflows for roles that should be removed. Keyed by `role`, which is this list's unique identifier rather than `name`. Retiring one role twice was never meaningful, so the key is unambiguous. Default: []. Constraints: {"maxItems":512,"x-kubernetes-list-map-keys":["role"],"x-kubernetes-list-type":"map"}.
spec.retirements[]object; item or branch. Declarative workflow for retiring an existing role. Constraints: {"required":["role"]}.
spec.retirements[].drop_ownedboolean; optional. Whether to run `DROP OWNED BY` before dropping the role. Default: false.
spec.retirements[].reassign_owned_tostring; optional. Optional successor role for `REASSIGN OWNED BY ... TO ...`. Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.retirements[].rolestring; required. The role to retire and ultimately drop. Constraints: {"maxLength":63,"minLength":1}.
spec.retirements[].terminate_sessionsboolean; optional. Whether to terminate other active sessions for the role before drop. Default: false.
spec.role_patternstring; optional. Default role naming pattern. Schema bindings can override it. Supports `{schema}` and requires `{profile}`; falls back to `{schema}-{profile}`. Constraints: {"maxLength":128,"minLength":1,"nullable":true}.
spec.rolesarray; optional. One-off role definitions. Keyed by `name`; see `schemas`. Default: []. Constraints: {"maxItems":1024,"x-kubernetes-list-map-keys":["name"],"x-kubernetes-list-type":"map"}.
spec.roles[]object; item or branch. A concrete PostgreSQL role definition. Constraints: {"required":["name"]}.
spec.roles[].bypassrlsboolean; optional. Whether the role bypasses row-level security. Constraints: {"nullable":true}.
spec.roles[].commentstring; optional. Descriptive PostgreSQL role comment. Constraints: {"maxLength":256,"nullable":true}.
spec.roles[].configobject; optional. Role-level configuration parameter defaults, applied via `ALTER ROLE ... SET parameter = value` (e.g. `role: combined`, `search_path: app`). Settings present on the role in the database but absent here are RESET in authoritative mode. Constraints: {"maxProperties":32}.
spec.roles[].config.<name>string; item or branch. A role configuration parameter value. Values are always strings — quote numbers and booleans (e.g. `statement_timeout: "30000"`, `jit: "off"`). The Kubernetes CRD schema types config values as strings, and the CLI enforces the same rule so a manifest means the same thing whether it is applied with `pgroles` or `kubectl`. PostgreSQL coerces the string to the parameter's type. Constraints: {"maxLength":256}.
spec.roles[].connection_limitinteger; optional. Maximum concurrent connections for the role; -1 means unlimited. Constraints: {"format":"int32","nullable":true}.
spec.roles[].createdbboolean; optional. Whether the role may create databases. Constraints: {"nullable":true}.
spec.roles[].createroleboolean; optional. Whether the role may create and administer roles, subject to server-version rules. Constraints: {"nullable":true}.
spec.roles[].externalboolean; optional. Treat this role as externally managed. The operator may reference it in grants, ownership, and memberships, but will not create, alter, drop, or password-manage it. Declared membership edges remain managed. Default: false.
spec.roles[].inheritboolean; optional. Whether privileges from role memberships are inherited automatically. Constraints: {"nullable":true}.
spec.roles[].loginboolean; optional. Whether the role may initiate database sessions. Constraints: {"nullable":true}.
spec.roles[].namestring; required. PostgreSQL role name. Constraints: {"maxLength":63,"minLength":1}.
spec.roles[].passwordobject; optional. Password source for this role. Either a reference to an existing Secret or a request for the operator to generate one. Constraints: {"nullable":true}.
spec.roles[].password.generateobject; optional. Generate a random password and store it in a new Kubernetes Secret. Mutually exclusive with `secretRef`. Constraints: {"nullable":true}.
spec.roles[].password.generate.lengthinteger; optional. Password length. Defaults to 32. Minimum 16, maximum 128. Constraints: {"format":"uint32","minimum":0.0,"nullable":true}.
spec.roles[].password.generate.secretKeystring; optional. Key within the generated Secret. Defaults to `password`. Constraints: {"maxLength":253,"minLength":1,"nullable":true}.
spec.roles[].password.generate.secretNamestring; optional. Override the generated Secret name. Defaults to `{policy}-pgr-{role}`. Constraints: {"maxLength":253,"minLength":1,"nullable":true}.
spec.roles[].password.secretKeystring; optional. Key within the referenced Secret. Defaults to the role name. Only used with `secretRef`. Constraints: {"maxLength":253,"minLength":1,"nullable":true}.
spec.roles[].password.secretRefobject; optional. Reference to an existing Kubernetes Secret containing the password. Mutually exclusive with `generate`. Constraints: {"nullable":true,"required":["name"]}.
spec.roles[].password.secretRef.namestring; required. Name of the Secret. Constraints: {"maxLength":253,"minLength":1}.
spec.roles[].password_valid_untilstring; optional. Password expiration timestamp (ISO 8601, e.g. "2025-12-31T00:00:00Z"). Constraints: {"maxLength":64,"nullable":true}.
spec.roles[].preserve_undeclared_grantsboolean; optional. Preserve this role's undeclared in-scope object grants during convergence. Revokes against the role are skipped unless the revoked privileges are explicitly asserted absent (`ensure: absent`). Default: false.
spec.roles[].replicationboolean; optional. Whether the role may initiate replication connections. Constraints: {"nullable":true}.
spec.roles[].superuserboolean; optional. Whether the role bypasses PostgreSQL permission checks as a superuser. Constraints: {"nullable":true}.
spec.schemasarray; optional. Schema bindings that expand profiles into concrete roles/grants. Keyed by `name` so server-side apply merges entries per schema instead of replacing the whole list. The API server also rejects duplicate keys. Default: []. Constraints: {"maxItems":1024,"x-kubernetes-list-map-keys":["name"],"x-kubernetes-list-type":"map"}.
spec.schemas[]object; item or branch. Associates a PostgreSQL schema with one or more reusable privilege profiles. Constraints: {"required":["name"]}.
spec.schemas[].namestring; required. PostgreSQL schema name. Constraints: {"maxLength":63,"minLength":1}.
spec.schemas[].ownerstring; optional. Override default_owner for this schema's default privileges. Constraints: {"maxLength":63,"minLength":1,"nullable":true}.
spec.schemas[].profilesarray; optional. Profile names to expand for this schema. Default: []. Constraints: {"maxItems":64}.
spec.schemas[].profiles[]string; item or branch. Constraints on this array item, map value, or conditional schema. Constraints: {"maxLength":63,"minLength":1}.
spec.schemas[].role_patternstring; optional. Role naming pattern. Supports `{schema}` and `{profile}` placeholders. Overrides the policy pattern; otherwise inherits it, falling back to `"{schema}-{profile}"`. Constraints: {"maxLength":128,"minLength":1,"nullable":true}.
spec.suspendboolean; optional. Suspend reconciliation when true. Defaults to false. Default: false.

Status (read-only except decisions)

PathDefinition
statusobject; optional. Status of a `PostgresPolicy` resource. Constraints: {"nullable":true}.
status.applied_password_source_versionsobject; optional. Last applied password source version for each password-managed role. Default: {}.
status.applied_password_source_versions.<name>string; item or branch. Constraints on this array item, map value, or conditional schema.
status.change_summaryobject; optional. Summary of changes applied in the last reconciliation. Constraints: {"nullable":true}.
status.change_summary.default_privileges_revokedinteger; optional. Number of default privilege revoke steps. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.default_privileges_setinteger; optional. Number of default privilege grant steps. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.grants_addedinteger; optional. Number of object privilege grant steps. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.grants_revokedinteger; optional. Number of object privilege revoke steps. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.members_addedinteger; optional. Number of membership additions. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.members_removedinteger; optional. Number of membership removals. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.passwords_setinteger; optional. Number of password updates. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.roles_alteredinteger; optional. Number of role attribute or configuration changes. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.roles_createdinteger; optional. Number of role creations. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.roles_droppedinteger; optional. Number of role drops. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.schema_owners_alteredinteger; optional. Number of schema ownership changes. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.schemas_createdinteger; optional. Number of schema creations. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.sessions_terminatedinteger; optional. Number of session-termination steps. Default: 0. Constraints: {"format":"int32"}.
status.change_summary.totalinteger; optional. Number of all planned change steps. Default: 0. Constraints: {"format":"int32"}.
status.conditionsarray; optional. Standard Kubernetes conditions. Default: [].
status.conditions[]object; item or branch. A condition on the `PostgresPolicy` resource. Constraints: {"required":["status","type"]}.
status.conditions[].last_transition_timestring; optional. Last time the condition transitioned. Constraints: {"nullable":true}.
status.conditions[].messagestring; optional. Human-readable message. Constraints: {"nullable":true}.
status.conditions[].reasonstring; optional. Human-readable reason for the condition. Constraints: {"nullable":true}.
status.conditions[].statusstring; required. Status: "True", "False", or "Unknown".
status.conditions[].typestring; required. Controller-defined condition type, such as Ready, Reconciling, or Degraded. This is an open vocabulary; consult status guidance for operational meanings.
status.content_digeststring; optional. Canonical digest of this policy's own content, computed by exactly the same function as a candidate's `status.contentDigest` (note the wire names differ: this status object serialises snake_case, so the field is `status.content_digest` here). Promotion is recognised by comparing the two. The value is also the operator's memory of what the content was on the previous reconcile, which is how an edited-after-approval promotion is distinguished from a policy that simply has not changed while a candidate is under review. Constraints: {"nullable":true}.
status.current_plan_refobject; optional. Reference to the current/latest plan for this policy. Constraints: {"nullable":true,"required":["name"]}.
status.current_plan_ref.namestring; required. Name of the PostgresPolicyPlan in the same namespace.
status.lastHandledReconcileAtstring; optional. Last force-reconcile annotation value handled by the operator. Constraints: {"nullable":true}.
status.last_attempted_generationinteger; optional. The `.metadata.generation` that was last attempted. Constraints: {"format":"int64","nullable":true}.
status.last_errorstring; optional. Last reconcile error message, if any. Constraints: {"nullable":true}.
status.last_reconcile_modestring; optional. Controls whether the operator executes changes or only computes plans. Constraints: {"enum":["apply","observe","plan"],"nullable":true}.
status.last_successful_reconcile_timestring; optional. ISO 8601 timestamp of the last successful reconciliation. Constraints: {"nullable":true}.
status.managed_database_identitystring; optional. Canonical identity of the managed database target. Constraints: {"nullable":true}.
status.observed_generationinteger; optional. The `.metadata.generation` that was last successfully reconciled. Constraints: {"format":"int64","nullable":true}.
status.owned_rolesarray; optional. Roles claimed by this policy's declared ownership scope. Default: [].
status.owned_roles[]string; item or branch. Constraints on this array item, map value, or conditional schema.
status.owned_schemasarray; optional. Schemas claimed by this policy's declared ownership scope. Default: [].
status.owned_schemas[]string; item or branch. Constraints on this array item, map value, or conditional schema.
status.plan_warningsarray; optional. Advisory warnings from the last reconciliation's computed plan — for example adopt-mode schema ownership transfers or an undeclared `default_owner`. Populated even when the plan applied cleanly. Default: [].
status.plan_warnings[]string; item or branch. Constraints on this array item, map value, or conditional schema.
status.transient_failure_countinteger; optional. Consecutive transient operational failures used for exponential backoff. Default: 0. Constraints: {"format":"int32"}.

Download the complete served OpenAPI schema for structural composition and all Kubernetes extensions.

Generated with crdgen --docs-dir; edit the Rust schema descriptions to change this reference.