{
  "description": "PocketIDAPI is the Schema for the pocketidapis API",
  "properties": {
    "apiVersion": {
      "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
      "type": [
        "string",
        "null"
      ]
    },
    "kind": {
      "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
      "type": [
        "string",
        "null"
      ]
    },
    "metadata": {
      "type": [
        "object",
        "null"
      ]
    },
    "spec": {
      "additionalProperties": false,
      "description": "spec defines the desired state of PocketIDAPI",
      "properties": {
        "instanceSelector": {
          "additionalProperties": false,
          "description": "InstanceSelector selects the PocketIDInstance to reconcile against.\nIf omitted, the controller expects exactly one instance in the cluster.",
          "properties": {
            "matchExpressions": {
              "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
              "items": {
                "additionalProperties": false,
                "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
                "properties": {
                  "key": {
                    "description": "key is the label key that the selector applies to.",
                    "type": "string"
                  },
                  "operator": {
                    "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
                    "type": "string"
                  },
                  "values": {
                    "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
                    "items": {
                      "type": "string"
                    },
                    "type": [
                      "array",
                      "null"
                    ],
                    "x-kubernetes-list-type": "atomic"
                  }
                },
                "required": [
                  "key",
                  "operator"
                ],
                "type": "object"
              },
              "type": [
                "array",
                "null"
              ],
              "x-kubernetes-list-type": "atomic"
            },
            "matchLabels": {
              "additionalProperties": {
                "type": "string"
              },
              "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
              "type": [
                "object",
                "null"
              ]
            }
          },
          "type": [
            "object",
            "null"
          ],
          "x-kubernetes-map-type": "atomic"
        },
        "name": {
          "description": "Name of the API to create in Pocket ID.\nIf omitted, defaults to metadata.name of the API resource.",
          "maxLength": 255,
          "minLength": 2,
          "type": [
            "string",
            "null"
          ]
        },
        "permissions": {
          "description": "Permissions are the scoped permissions offered by this API. The operator is\nthe sole owner of the API: the permission set in Pocket-ID is reconciled to\nexactly this list, so permissions added out-of-band are removed.",
          "items": {
            "additionalProperties": false,
            "description": "APIPermission defines a single scoped permission offered by an API.",
            "properties": {
              "description": {
                "description": "Description optionally explains what the permission grants.",
                "maxLength": 500,
                "type": [
                  "string",
                  "null"
                ]
              },
              "key": {
                "description": "Key is the permission identifier requested as a token scope, e.g. \"read:orders\".\nIt must be a valid RFC 6749 scope token: printable ASCII with no space, double\nquote, or backslash. Reserved OIDC scope/claim names are rejected at the spec level.",
                "maxLength": 255,
                "minLength": 1,
                "pattern": "^[\\x21\\x23-\\x5B\\x5D-\\x7E]+$",
                "type": "string"
              },
              "name": {
                "description": "Name is a human-friendly label for the permission.",
                "maxLength": 255,
                "minLength": 1,
                "type": "string"
              }
            },
            "required": [
              "key",
              "name"
            ],
            "type": "object"
          },
          "maxItems": 100,
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "key"
          ],
          "x-kubernetes-list-type": "map"
        },
        "resource": {
          "description": "Resource is the audience identifier for tokens issued against this API\n(typically a URI). It is the permanent identifier used to adopt an existing\nAPI and is immutable once set.",
          "maxLength": 255,
          "minLength": 1,
          "type": "string"
        }
      },
      "required": [
        "resource"
      ],
      "type": [
        "object",
        "null"
      ],
      "x-kubernetes-validations": [
        {
          "message": "resource is immutable",
          "rule": "self.resource == oldSelf.resource"
        },
        {
          "message": "permission key is reserved by Pocket ID",
          "rule": "!has(self.permissions) || self.permissions.all(p, !(p.key.lowerAscii() in ['openid','profile','email','email_verified','groups','offline_access']))"
        }
      ]
    },
    "status": {
      "additionalProperties": false,
      "description": "status defines the observed state of PocketIDAPI",
      "properties": {
        "apiID": {
          "description": "APIID is the ID assigned by Pocket-ID.",
          "type": [
            "string",
            "null"
          ]
        },
        "conditions": {
          "description": "Conditions represent the current state of the PocketIDAPI resource.",
          "items": {
            "additionalProperties": false,
            "description": "Condition contains details for one aspect of the current state of this API Resource.",
            "properties": {
              "lastTransitionTime": {
                "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed.  If that is not known, then using the time when the API field changed is acceptable.",
                "format": "date-time",
                "type": "string"
              },
              "message": {
                "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
                "maxLength": 32768,
                "type": "string"
              },
              "observedGeneration": {
                "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
                "format": "int64",
                "minimum": 0,
                "type": [
                  "integer",
                  "null"
                ]
              },
              "reason": {
                "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
                "maxLength": 1024,
                "minLength": 1,
                "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
                "type": "string"
              },
              "status": {
                "description": "status of the condition, one of True, False, Unknown.",
                "enum": [
                  "True",
                  "False",
                  "Unknown"
                ],
                "type": "string"
              },
              "type": {
                "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
                "maxLength": 316,
                "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
                "type": "string"
              }
            },
            "required": [
              "lastTransitionTime",
              "message",
              "reason",
              "status",
              "type"
            ],
            "type": "object"
          },
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "type"
          ],
          "x-kubernetes-list-type": "map"
        },
        "createdAt": {
          "description": "CreatedAt is the creation timestamp from Pocket-ID.",
          "type": [
            "string",
            "null"
          ]
        },
        "name": {
          "description": "Name is the resolved name from Pocket-ID.",
          "type": [
            "string",
            "null"
          ]
        },
        "permissions": {
          "description": "Permissions are the permissions resolved from Pocket-ID, including their IDs.\nThis is the lookup table PocketIDOIDCClients use to resolve permission keys.",
          "items": {
            "additionalProperties": false,
            "description": "ObservedAPIPermission is a permission resolved from Pocket-ID, including its ID.",
            "properties": {
              "id": {
                "description": "ID is the Pocket-ID identifier for the permission.",
                "type": "string"
              },
              "key": {
                "description": "Key is the permission identifier requested as a token scope.",
                "type": "string"
              },
              "name": {
                "description": "Name is the human-friendly label from Pocket-ID.",
                "type": [
                  "string",
                  "null"
                ]
              }
            },
            "required": [
              "id",
              "key"
            ],
            "type": "object"
          },
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "key"
          ],
          "x-kubernetes-list-type": "map"
        },
        "resource": {
          "description": "Resource is the resolved audience identifier from Pocket-ID.",
          "type": [
            "string",
            "null"
          ]
        }
      },
      "type": [
        "object",
        "null"
      ]
    }
  },
  "type": "object"
}