Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

API Reference

CAPTF’s CRDs are one group/version, infrastructure.cluster.x-k8s.io/v1alpha1, with seven kinds:

  • TerraformCluster — the InfraCluster of Cluster API, provisioned by a Terraform/OpenTofu module.
  • TerraformClusterTemplate — a template for TerraformClusters, used by ClusterClass.
  • TerraformMachine — the InfraMachine of Cluster API, provisioned by a Terraform/OpenTofu module.
  • TerraformMachineTemplate — a template for TerraformMachines, used by MachineDeployments, MachineSets, KubeadmControlPlane and ClusterClass.
  • TerraformMachinePool — the InfraMachinePool of Cluster API, provisioned by a Terraform/OpenTofu module.
  • TerraformMachinePoolTemplate — a template for TerraformMachinePools, used by MachinePools.
  • TerraformClusterIdentity — cluster-scoped cloud credentials for TerraformClusters, TerraformMachines and TerraformMachinePools in allowed namespaces.

Every kind’s spec.variables and spec.variablesFrom, and the module contract they feed, are documented in Job Inputs.

infrastructure.cluster.x-k8s.io/v1alpha1

Package v1alpha1 contains the API Schema definitions for CAPTF (the cluster-api-provider-terraform), the infrastructure.cluster.x-k8s.io v1alpha1 group version. CAPTF turns a Cluster API cluster, machine or machine pool into one Terraform or OpenTofu module run: TerraformCluster, TerraformMachine and TerraformMachinePool carry the desired state that CAPI’s core controllers create and drive, TerraformClusterTemplate, TerraformMachineTemplate and TerraformMachinePoolTemplate each hold a template (their spec.template) from which a TerraformCluster, TerraformMachine or TerraformMachinePool is created — the first typically referenced by a ClusterClass, the second by a MachineDeployment, MachineSet or a control-plane provider, the third by a MachinePool — and TerraformClusterIdentity holds the cloud credentials a cluster’s module run is allowed to use, mirrored into the namespaces that reference it. Seven kinds in all, each registered, with its List type, in groupversion_info.go.

Every object’s spec.source names the one OCI image that bundles the module’s Terraform/OpenTofu code and the runtime binary that runs it (the image-contract types, Source and JobPolicy, live in common_types.go), and spec.identityRef, spec.variables and spec.variablesFrom feed that module’s inputs. The controllers in internal/controllers render those inputs, run the image as a Kubernetes Job and translate its outputs and health into the object’s status: status.conditions (see conditions_consts.go for every condition type and reason CAPTF sets, and their Ready-summarization rules) and the run-tracking status types common_types.go shares across the TerraformCluster, TerraformMachine and TerraformMachinePool kinds — ActiveJob, LastRun (with its RunStep and RunError), SourceStatus and StateBackup — alongside the drift and remediation policy types DriftPolicy (cluster), MachineDriftPolicy (also reused for a cluster’s per-machine and per-pool defaults), MachinePoolDriftPolicy (pool, never fully disabled) and MachineRemediation (machine).

zz_generated.deepcopy.go is controller-gen output; regenerate it with make generate, never hand-edit it. groupversion_info.go registers the group version and every kind with the runtime scheme.

Resource Types

ActiveJob

ActiveJob identifies the Job currently running for an object.

Appears in:

FieldDescriptionRequiredDefaultValidation
name stringname of the Job.YesMaxLength: 63
MinLength: 1
operation Operationoperation the Job runs.YesEnum: [apply destroy drift refresh restore plan]
attempt integerattempt is the operation’s Job sequence number, the a<N> in the Job
name, starting at 1. It counts every Job of the operation still
retained, not retries: the 40th refresh is attempt 40.
YesMinimum: 1
startTime TimestartTime of the Job.No

AllowedNamespaces

AllowedNamespaces selects namespaces allowed to use an identity. At least one of list and selector must be set.

Appears in:

FieldDescriptionRequiredDefaultValidation
list string arraylist of namespace names.NoMaxItems: 100
MinItems: 1
items:MaxLength: 63
items:MinLength: 1
items:Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
selector LabelSelectorselector matches namespace labels. An empty selector ({}) matches every
namespace.
No

ApplyPolicy

Underlying type: string

ApplyPolicy decides whether a TerraformCluster applies a change on its own or waits until its plan is approved.

Validation:

  • Enum: [Automatic Manual]

Appears in:

FieldDescription
AutomaticApplyPolicyAutomatic applies every change as soon as it is seen, only
guarded against destructive plans.
ManualApplyPolicyManual plans every change first (a plan Job), shows the
plan in status.plan and applies it only once ApprovePlanAnnotation
names its hash. The first apply of a new cluster is not gated.

Architecture

Underlying type: string

Architecture is a node CPU architecture, as reported for scale from zero.

Validation:

  • Enum: [amd64 arm64 s390x ppc64le]

Appears in:

FieldDescription
amd64ArchitectureAmd64 is amd64.
arm64ArchitectureArm64 is arm64.
s390xArchitectureS390x is s390x.
ppc64leArchitecturePpc64le is ppc64le.

CapacitySource

CapacitySource records which image the capacity was resolved from.

Appears in:

FieldDescriptionRequiredDefaultValidation
image stringimage is the spec image reference last resolved.YesMaxLength: 512
MinLength: 1

DriftAction

Underlying type: string

DriftAction is what the controller does when a drift check finds changes.

Validation:

  • Enum: [Report Remediate]

Appears in:

FieldDescription
ReportDriftActionReport records drift in the DriftDetected condition only.
RemediateDriftActionRemediate applies the current inputs to remove the drift.

DriftPolicy

DriftPolicy configures periodic drift detection of a TerraformCluster.

Appears in:

FieldDescriptionRequiredDefaultValidation
intervalSeconds integerintervalSeconds between drift checks, in seconds. Defaults to the
manager’s –drift-default-interval (30m), applied at reconcile. 0
disables drift checks, and with them every health sample after
provisioning: health is re-read only by a refresh or drift run.
NoMinimum: 0
action DriftActionaction taken when drift is found: Report or Remediate. Defaults to
Report, applied at reconcile. Remediate applies the current inputs
automatically, reverting every out-of-band change.
NoEnum: [Report Remediate]

DriftSummary

DriftSummary summarizes the plan of a drift run that found changes.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
add integeradd is the number of resources the plan would create.NoMinimum: 0
change integerchange is the number of resources the plan would update in place.NoMinimum: 0
destroy integerdestroy is the number of resources the plan would destroy, counting
replacements.
NoMinimum: 0
resources string arrayresources are the addresses of the drifted resources, at most 20.NoMaxItems: 20
MinItems: 1
items:MaxLength: 512
items:MinLength: 1

HealthState

Underlying type: string

HealthState mirrors the health.state enum of the module contract (internal/contract.HealthState, https://captf.io/docs/module-author/contract/v1alpha1/common.html), for MachinePoolInstance.State.

Validation:

  • Enum: [pending running degraded stopped terminated unknown]

Appears in:

FieldDescription
pendingHealthStatePending is the contract’s “pending” health state.
runningHealthStateRunning is the contract’s “running” health state.
degradedHealthStateDegraded is the contract’s “degraded” health state.
stoppedHealthStateStopped is the contract’s “stopped” health state.
terminatedHealthStateTerminated is the contract’s “terminated” health state.
unknownHealthStateUnknown is the contract’s “unknown” health state.

IdentityReference

IdentityReference names a cluster-scoped TerraformClusterIdentity.

Appears in:

FieldDescriptionRequiredDefaultValidation
name stringname of the TerraformClusterIdentity.YesMaxLength: 253
MinLength: 1

Initialization

Initialization holds the v1beta2 contract’s initialization status.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
provisioned booleanprovisioned is true once the infrastructure is provisioned: derived from
state until it first holds, then latched for the object’s life.
No

JobPolicy

JobPolicy tunes the Kubernetes Jobs that run the module. Every field is optional. On a TerraformMachine or TerraformMachinePool the policy is merged field by field with TerraformCluster.spec.defaults.jobs: a field the machine or pool sets wins, an unset one comes from the defaults, and a field neither sets gets the controller’s built-in default. env is merged by name (the machine’s or pool’s wins on the same name) and imagePullSecrets is the union (the machine’s or pool’s first); resources, securityContext and podSecurityContext are replaced as a whole. Defaults are resolved at reconcile time and never persisted, so a provider upgrade reaches existing objects. Jobs never retry pods (backoffLimit 0) and never get a TTL: the controller owns retries and prunes finished Jobs itself.

Appears in:

FieldDescriptionRequiredDefaultValidation
successfulJobsHistoryLimit integersuccessfulJobsHistoryLimit is how many succeeded Jobs to keep per object
and operation. The newest succeeded Job of each operation is kept even
at 0. Defaults to 3, applied at reconcile.
NoMaximum: 100
Minimum: 0
failedJobsHistoryLimit integerfailedJobsHistoryLimit is how many failed Jobs to keep per object and
operation. The newest failed Job of an operation is kept even at 0
while no newer Job of that operation succeeded: retry backoff counts
it. Defaults to 3, applied at reconcile.
NoMaximum: 100
Minimum: 0
activeDeadlineSeconds integeractiveDeadlineSeconds bounds a Job’s run time, in seconds, at most one
day. Defaults to 3600, applied at reconcile when unset (0). When a
policy sets both, lockTimeoutSeconds must be less than
activeDeadlineSeconds.
NoMaximum: 86400
Minimum: 1
serviceAccountName stringserviceAccountName overrides the runner ServiceAccount. When unset the
controller creates captf-runner, bound to the static captf-runner
ClusterRole. An override ServiceAccount must exist and carry the label
captf.io/runner=true, or no Job is created.
NoMaxLength: 253
MinLength: 1
lockTimeoutSeconds integerlockTimeoutSeconds is passed to the runtime as -lock-timeout, in seconds.
Defaults to 300, applied at reconcile.
NoMaximum: 3600
Minimum: 0
imagePullSecrets LocalObjectReference arrayimagePullSecrets for the Job pod: they cover the source image and the
runner init image.
NoMaxItems: 10
MinItems: 1
resources ResourceRequirementsresources of the main container.No
env EnvVar arrayenv adds environment variables to the main container. It cannot override
the TF_* and KUBE_* variables the runner sets.
NoMaxItems: 64
MinItems: 1
securityContext SecurityContextsecurityContext of the main container. Defaults, applied when the Job is
built: seccompProfile RuntimeDefault, capabilities drop ALL,
allowPrivilegeEscalation false, readOnlyRootFilesystem true. runAsNonRoot
is not defaulted. The webhook rejects privileged: true,
allowPrivilegeEscalation: true and any capabilities.add: the container
holds cloud credentials.
No
podSecurityContext PodSecurityContextpodSecurityContext of the Job pod. Defaults, applied when the Job is
built: seccompProfile RuntimeDefault.
No

LastRun

LastRun is the result of the most recent completed Job, copied from the runner’s termination message.

Appears in:

FieldDescriptionRequiredDefaultValidation
job stringjob is the name of the Job.YesMaxLength: 63
MinLength: 1
operation Operationoperation the Job ran.YesEnum: [apply destroy drift refresh restore plan]
steps RunStep arraysteps the runner executed, in order.NoMaxItems: 16
MinItems: 1
error RunErrorerror is set when the run failed.No
drift DriftSummarydrift is set when a drift run found changes.NoMinProperties: 1

MachineDriftPolicy

MachineDriftPolicy configures periodic drift detection of a TerraformMachine. Drift on a machine is always reported, never remediated: the machine is immutable infrastructure, replaced by a rollout.

Appears in:

FieldDescriptionRequiredDefaultValidation
intervalSeconds integerintervalSeconds between drift checks, in seconds. Defaults to the
manager’s –drift-default-interval (30m), applied at reconcile. 0
disables drift checks. Unless remediation.annotateMachine is true
(which refreshes at remediation.healthCheckIntervalSeconds), that also
stops every health sample after provisioning.
NoMinimum: 0

MachinePoolDriftPolicy

MachinePoolDriftPolicy configures periodic drift detection of a TerraformMachinePool. Unlike MachineDriftPolicy, 0 is rejected by the CRD schema: for a pool it is membership refresh (TerraformMachinePoolSpec.MembershipRefreshIntervalSeconds), not drift, that keeps status fresh (https://captf.io/docs/module-author/contract/v1alpha1/machinepool.html “Membership refresh”), and the drift Job itself feeds the refreshed replicas into its plan (machinepool.md “Drift order”), so disabling drift would also stop that refresh from ever reaching a plan.

Appears in:

FieldDescriptionRequiredDefaultValidation
intervalSeconds integerintervalSeconds between drift checks, in seconds. Defaults to the
manager’s –drift-default-interval (30m), applied at reconcile when
unset (0). Unlike a machine’s or the cluster’s, a pool’s drift cannot
be disabled, so 0 always means “use the default”, never “disabled”.
NoMinimum: 1
action DriftActionaction taken when drift is found: Report or Remediate. Defaults to
Report, applied at reconcile. Unlike a machine’s, a pool’s drift may
be remediated: the group’s instances are not immutable infrastructure.
NoEnum: [Report Remediate]

MachinePoolInstance

MachinePoolInstance is one entry of a TerraformMachinePool’s status.instances, mapped from the module’s instances output (https://captf.io/docs/module-author/contract/v1alpha1/machinepool.html “instances”).

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
providerID stringproviderID of the instance.YesMaxLength: 512
MinLength: 1
instanceID stringinstanceID is a provider-defined identifier, distinct from providerID
when the module has one to give.
NoMaxLength: 256
MinLength: 1
addresses MachineAddress arrayaddresses of the instance.NoMaxItems: 256
MinItems: 1
failureDomain stringfailureDomain the instance actually runs in.NoMaxLength: 256
MinLength: 1
state HealthStatestate of the instance, the health.state enum.NoEnum: [pending running degraded stopped terminated unknown]

MachineRemediation

MachineRemediation configures how a TerraformMachine signals an unhealthy instance to Cluster API beyond its Ready condition.

Appears in:

FieldDescriptionRequiredDefaultValidation
annotateMachine booleanannotateMachine sets cluster.x-k8s.io/remediate-machine on the owner
Machine once the instance has been unhealthy for unhealthyThreshold
consecutive samples, or at once when it is terminated. CAPTF removes
the annotation it set once the instance reads Healthy again and the
Machine is not being deleted; an annotation set by anyone else is left
alone. It has an effect only when a MachineHealthCheck selects the
Machine; a single-replica control plane refuses the remediation.
Defaults to false.
No
unhealthyThreshold integerunhealthyThreshold is the number of consecutive unhealthy health samples
before the Machine is annotated. A sample is one completed refresh or
drift Job. Defaults to 3, applied at reconcile when unset (0). A
terminated instance counts on the first sample.
NoMaximum: 100
Minimum: 1
healthCheckIntervalSeconds integerhealthCheckIntervalSeconds is how often a provisioned machine is
refreshed to sample its health while annotateMachine is true,
independent of drift.intervalSeconds. Defaults to 300, applied at
reconcile when unset (0). With annotateMachine false it is ignored and
health is re-read only at the drift (or refresh) cadence, so
drift.intervalSeconds 0 then stops health sampling after provisioning.
NoMaximum: 86400
Minimum: 60

NodeInfo

NodeInfo describes the nodes the template creates, for Cluster Autoscaler scale from zero. It comes from the image label io.captf.node-info.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
architecture Architecturearchitecture of the node’s CPU.NoEnum: [amd64 arm64 s390x ppc64le]
operatingSystem stringoperatingSystem of the node, e.g. linux.NoMaxLength: 64
MinLength: 1

Operation

Underlying type: string

Operation is one of the operations a Job runs.

Validation:

  • Enum: [apply destroy drift refresh restore plan]

Appears in:

FieldDescription
applyOperationApply creates or updates the infrastructure.
destroyOperationDestroy destroys the infrastructure.
driftOperationDrift refreshes state and plans to detect drift.
refreshOperationRefresh refreshes state and outputs only.
restoreOperationRestore pushes a state backup back into the backend
(RestoreStateAnnotation).
planOperationPlan plans a TerraformCluster’s change for review and
applies nothing (applyPolicy Manual).

PlanPreview

PlanPreview summarizes a plan for review: counts and the address and action of each changed resource, never a value.

Appears in:

FieldDescriptionRequiredDefaultValidation
inputsHash stringinputsHash is the hash of the inputs the plan was made for.YesMaxLength: 128
MinLength: 1
job stringjob is the Job that made the plan: a plan Job, or an approved apply
that found the plan changed.
YesMaxLength: 63
MinLength: 1
planHash stringplanHash fingerprints the plan’s changes: the value of the
captf.io/approve-plan annotation that approves it.
YesMaxLength: 128
MinLength: 1
add integeradd is the number of resources the plan creates.NoMinimum: 0
change integerchange is the number of resources the plan updates in place.NoMinimum: 0
destroy integerdestroy is the number of resources the plan destroys, counting
replacements.
NoMinimum: 0
resources string arrayresources are “<address> (<action>)” of the changed resources, sorted
by address, at most 50; action is create, update, delete, replace,
read or forget.
NoMaxItems: 50
MinItems: 1
items:MaxLength: 600
items:MinLength: 1
truncated booleantruncated is true when resources lists fewer resources than the plan
changes.
No
createdAt TimecreatedAt is when the plan was made.No

RunError

RunError describes why a run failed.

Appears in:

FieldDescriptionRequiredDefaultValidation
kind RunErrorKindkind of failure.YesEnum: [image-layout step interrupted blocked plan-changed]
step stringstep that failed, for kind step.NoMaxLength: 64
MinLength: 1
summary stringsummary is the runner’s short description of the failure, at most 512
bytes. It is not raw stderr: status is readable by everyone who can get
the object, so the full output stays in the Job’s logs.
NoMaxLength: 512
MinLength: 1

RunErrorKind

Underlying type: string

RunErrorKind classifies a failed run.

Validation:

  • Enum: [image-layout step interrupted blocked plan-changed]

Appears in:

FieldDescription
image-layoutRunErrorKindImageLayout means the image does not follow the image contract.
stepRunErrorKindStep means a runtime step failed.
interruptedRunErrorKindInterrupted means the step was stopped from outside (the
pod got SIGTERM: a drain, an eviction, a Job deletion or its deadline),
not that the module failed.
blockedRunErrorKindBlocked means a TerraformCluster apply stopped before a
plan that deletes or replaces resources, because the
captf.io/approve-destructive-plan annotation does not name the
inputs hash it renders. Nothing was changed.
plan-changedRunErrorKindPlanChanged means a TerraformCluster apply approved for
one plan (applyPolicy Manual, captf.io/approve-plan) planned other
changes and stopped before applying them. Nothing was changed; the
new plan waits for its own approval in status.plan.

RunStep

RunStep is one runtime command the runner executed.

Appears in:

FieldDescriptionRequiredDefaultValidation
name stringname of the step, e.g. init, validate, plan, apply, apply-refresh-only.YesMaxLength: 64
MinLength: 1
exitCode integerexitCode of the step.Yes
durationMilliseconds integerdurationMilliseconds is the step’s wall time, in milliseconds.NoMinimum: 0

SecretReference

SecretReference names a Secret in a given namespace.

Appears in:

FieldDescriptionRequiredDefaultValidation
name stringname of the Secret.YesMaxLength: 253
MinLength: 1
Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
namespace stringnamespace of the Secret.YesMaxLength: 63
MinLength: 1
Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$

Source

Source is the deliverable: one OCI image that bundles the role module’s Terraform/OpenTofu code and the runtime binary. There is no separate module source and no separate runtime image. The image layout is a fixed-path contract: /captf/module, /captf/runtime and an optional /captf/providers mirror. The runner always execs /captf/runtime; pull secrets for the image are jobs.imagePullSecrets.

Appears in:

FieldDescriptionRequiredDefaultValidation
image stringimage is the OCI image reference, registry/repo:tag or
registry/repo@sha256:digest. The tag or digest is the module version.
Referencing an image grants its publisher Secret-read and cloud-credential
access in this namespace.
YesMaxLength: 512
MinLength: 1
imagePullPolicy PullPolicyimagePullPolicy for the image. Defaults to IfNotPresent, applied when the
Job is built; Always is recommended for mutable tags.
NoEnum: [IfNotPresent Always Never]

SourceStatus

SourceStatus records what the last Job actually ran.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
image stringimage is the reference that was run last, as given in the spec.NoMaxLength: 512
MinLength: 1
imageDigest stringimageDigest is the digest the container runtime resolved the image to
(pod status imageID). Informational: the pinned copy lives on the durable
inputs Secret as captf.io/image-digest.
NoMaxLength: 512
MinLength: 1
runtimeVersion stringruntimeVersion reported by &lt;command&gt; version -json.NoMaxLength: 64
MinLength: 1

StateBackup

StateBackup is one versioned copy of the object’s Terraform state that the controller keeps in a captf-state-backup-* Secret.

Appears in:

FieldDescriptionRequiredDefaultValidation
serial integerserial is the state serial the backup holds; set it as the
captf.io/restore-state annotation to restore it.
YesMinimum: 1
takenAt TimetakenAt is when the controller copied the state.Yes
bytes integerbytes is the compressed size of the backup summed over its Secrets.YesMinimum: 1

TemplateMeta

TemplateMeta holds the metadata field every *TemplateResource copies onto the object it creates. TerraformClusterTemplateResource and TerraformMachineTemplateResource embed it.

Appears in:

FieldDescriptionRequiredDefaultValidation
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No

TerraformCluster

TerraformCluster is the Schema for the terraformclusters API: the InfraCluster of Cluster API, provisioned by a Terraform/OpenTofu module.

FieldDescriptionRequiredDefaultValidation
apiVersion stringinfrastructure.cluster.x-k8s.io/v1alpha1Yes
kind stringTerraformClusterYes
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
No
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
No
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformClusterSpecspec is the desired state of the TerraformCluster.YesMinProperties: 1
status TerraformClusterStatusstatus is the observed state of the TerraformCluster.NoMinProperties: 1

TerraformClusterDefaults

TerraformClusterDefaults are values the TerraformMachines and TerraformMachinePools of a cluster inherit when they do not set them. There is no source: every role names its own image.

Appears in:

FieldDescriptionRequiredDefaultValidation
identityRef IdentityReferenceidentityRef is used by machines and pools without their own
identityRef. When unset, such machines and pools use
spec.identityRef.
No
jobs JobPolicyjobs is merged field by field under each machine’s or pool’s jobs
policy (see JobPolicy).
No
drift MachineDriftPolicydrift is merged field by field under each machine’s or pool’s drift
policy. A pool’s drift is never fully disabled: an inherited
intervalSeconds of 0 disables a machine’s drift checks but not a
pool’s, which then uses the controller’s default interval.
No

TerraformClusterIdentity

TerraformClusterIdentity is the Schema for the terraformclusteridentities API: cluster-scoped cloud credentials for TerraformClusters, TerraformMachines and TerraformMachinePools in allowed namespaces.

FieldDescriptionRequiredDefaultValidation
apiVersion stringinfrastructure.cluster.x-k8s.io/v1alpha1Yes
kind stringTerraformClusterIdentityYes
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
No
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
No
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformClusterIdentitySpecspec is the desired state of the TerraformClusterIdentity.YesMinProperties: 1
status TerraformClusterIdentityStatusstatus is the observed state of the TerraformClusterIdentity.NoMinProperties: 1

TerraformClusterIdentitySpec

TerraformClusterIdentitySpec is the desired state of a TerraformClusterIdentity: cloud credentials and who may use them.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
secretRef SecretReferencesecretRef names the Secret holding the credentials. It is mirrored into
each allowed namespace that uses this identity and delivered to Jobs as
environment variables and files.
Yes
allowedNamespaces AllowedNamespacesallowedNamespaces restricts which namespaces may reference this
identity. Unset allows no namespace; selector: \{\} allows every
namespace; list and selector are ORed. An empty object is rejected.
No

TerraformClusterIdentityStatus

TerraformClusterIdentityStatus is the observed state of a TerraformClusterIdentity. The manager fills it: whether the credentials Secret exists, and where it is mirrored.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
conditions Condition arrayconditions of the TerraformClusterIdentity. Ready is True when the
credentials Secret exists (SecretFound), False when it does not
(SecretNotFound).
NoMaxItems: 32
namespaces string arraynamespaces where a mirror of the credentials Secret currently exists.NoMaxItems: 1000
items:MaxLength: 63
items:MinLength: 1

TerraformClusterSpec

TerraformClusterSpec is the desired state of a TerraformCluster: the cluster-role module image and how to run it.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
controlPlaneEndpoint APIEndpointcontrolPlaneEndpoint is the endpoint of the cluster’s API server. A value
set by the user is passed to the module as its control_plane_endpoint
input; otherwise the controller writes the module’s output here once.
Once it has a host it is immutable (the webhook enforces this).
No
source Sourcesource is the role image: module code and runtime.Yes
identityRef IdentityReferenceidentityRef names the TerraformClusterIdentity whose credentials this
object’s Jobs use. Whether it is required, and where it falls back to
when unset, depends on the kind.
No
jobs JobPolicyjobs tunes the Jobs that run this object’s module. On a kind that
inherits defaults it is merged field by field over them (see
JobPolicy).
No
variables RawExtensionvariables are module variables, a JSON object: each key becomes a
named argument of the role module, converted by the module’s declared
type. Keys are Terraform identifiers; captf_ names and the role’s
contract inputs are reserved. Inline variables win over variablesFrom.
Whether a change re-applies or is rejected as immutable depends on the
kind. A key the module does not declare fails the apply (“Unsupported
argument”).
NoMaxProperties: 256
MinProperties: 1
Type: object
variablesFrom VariablesSource arrayvariablesFrom reads module variables from ConfigMaps and Secrets in
this namespace labeled captf.io/variables=true, in list order: a later
source wins on the same key, and inline variables win over all of
them. Whether and when a change to a referenced source takes effect
depends on the kind.
NoExactlyOneOf: [configMapRef secretRef]
MaxItems: 16
MinItems: 1
drift DriftPolicydrift configures drift detection for this cluster.No
applyPolicy ApplyPolicyapplyPolicy decides when a change is applied. Automatic (the default,
applied at reconcile) applies every change of the inputs, and a drift
remediation, as soon as it is seen; only a plan that deletes or
replaces resources waits for captf.io/approve-destructive-plan.
Manual runs a plan Job first, reports the plan in status.plan and
waits until the captf.io/approve-plan annotation names its hash; the
apply then runs only if it plans the same changes again. The first
apply of a new cluster (no state yet) is never gated. Mutable.
NoEnum: [Automatic Manual]
defaults TerraformClusterDefaultsdefaults are inherited by the TerraformMachines and TerraformMachinePools
of this cluster, field by field: a field a machine or pool sets wins,
an unset one comes from here. They do not apply to the
TerraformCluster itself.
No

TerraformClusterStatus

TerraformClusterStatus is the observed state of a TerraformCluster. Nothing here is load-bearing: every value is rebuilt from spec, the state Secret, the durable inputs Secret or the Job list, because clusterctl move does not restore status.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
conditions Condition arrayconditions of the TerraformCluster. Ready is mirrored by Cluster API into
the Cluster’s InfrastructureReady condition.
NoMaxItems: 32
initialization Initializationinitialization is the v1beta2 contract’s initialization status.NoMinProperties: 1
observedGeneration integerobservedGeneration is the generation this status was computed for.NoMinimum: 1
activeJob ActiveJobactiveJob is the Job currently running for this object, if any.No
lastRun LastRunlastRun is the result of the most recent completed Job.No
lastDriftCheck TimelastDriftCheck is when the last drift check completed.No
lastRefresh TimelastRefresh is when the last refresh or drift check completed, or,
for a kind whose apply itself can give a definite health reading,
when that apply finished instead (that reading stands in for the
refresh after the apply).
No
pendingRefreshes integerpendingRefreshes counts the consecutive health samples (completed
refresh or drift Jobs) that read pending since the last other reading
or the last apply; unset otherwise. It spaces the refreshes while
health is pending: 30s, then 1m, 2m, 4m and at most 5m. It lives in
status only, so it restarts at 0 (30s) after clusterctl move.
NoMinimum: 1
observedStateSerial integerobservedStateSerial is the Terraform state serial the outputs were read
from.
NoMinimum: 1
stateSecretSuffix stringstateSecretSuffix is the kubernetes backend secret_suffix of this
object’s state. Informational: the controller derives it
deterministically.
NoMaxLength: 63
MinLength: 1
source SourceStatussource records what the last Job actually ran.NoMinProperties: 1
stateBackups StateBackup arraystateBackups are the state backups the controller keeps (newest
first), as of the last backup, prune or restore request.
NoMaxItems: 16
MinItems: 1
failureDomains FailureDomain arrayfailureDomains reported by the module’s failure_domains output.NoMaxItems: 100
MinItems: 1
plan PlanPreviewplan is the plan of the change waiting for approval under
applyPolicy Manual; empty when none waits. Approve it by setting the
captf.io/approve-plan annotation to plan.planHash.
No

TerraformClusterTemplate

TerraformClusterTemplate is the Schema for the terraformclustertemplates API: a template for TerraformClusters, used by ClusterClass.

FieldDescriptionRequiredDefaultValidation
apiVersion stringinfrastructure.cluster.x-k8s.io/v1alpha1Yes
kind stringTerraformClusterTemplateYes
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
No
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
No
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformClusterTemplateSpecspec is the desired state of the TerraformClusterTemplate.Yes

TerraformClusterTemplateResource

TerraformClusterTemplateResource describes the TerraformCluster created from a template.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformClusterSpecspec of the TerraformCluster created from this template.YesMinProperties: 1

TerraformClusterTemplateSpec

TerraformClusterTemplateSpec is the desired state of a TerraformClusterTemplate.

Appears in:

FieldDescriptionRequiredDefaultValidation
template TerraformClusterTemplateResourcetemplate is the TerraformCluster created from this template.YesMinProperties: 1

TerraformMachine

TerraformMachine is the Schema for the terraformmachines API: the InfraMachine of Cluster API, provisioned by a Terraform/OpenTofu module.

FieldDescriptionRequiredDefaultValidation
apiVersion stringinfrastructure.cluster.x-k8s.io/v1alpha1Yes
kind stringTerraformMachineYes
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
No
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
No
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformMachineSpecspec is the desired state of the TerraformMachine.YesMinProperties: 1
status TerraformMachineStatusstatus is the observed state of the TerraformMachine.NoMinProperties: 1

TerraformMachinePool

TerraformMachinePool is the Schema for the terraformmachinepools API: the InfraMachinePool of Cluster API, provisioned by a Terraform/OpenTofu module.

FieldDescriptionRequiredDefaultValidation
apiVersion stringinfrastructure.cluster.x-k8s.io/v1alpha1Yes
kind stringTerraformMachinePoolYes
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
No
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
No
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformMachinePoolSpecspec is the desired state of the TerraformMachinePool.YesMinProperties: 1
status TerraformMachinePoolStatusstatus is the observed state of the TerraformMachinePool.NoMinProperties: 1

TerraformMachinePoolSpec

TerraformMachinePoolSpec is the desired state of a TerraformMachinePool: the machinepool-role module image and how to run it. Unlike a TerraformMachine, every field here is mutable: the pool is re-applied on a spec change, a replica change or the bootstrap Secret’s rotation (https://captf.io/docs/module-author/contract/v1alpha1/machinepool.html “Lifecycle”).

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
providerID stringproviderID is the scaling group’s provider ID, set by the controller
from the module’s provider_id output. Optional in the InfraMachinePool
contract; may stay unset for group-less implementations.
NoMaxLength: 512
MinLength: 1
providerIDList string arrayproviderIDList are the provider IDs of every non-terminated member of
the group, set by the controller from the module’s provider_id_list
output. Each entry must equal the corresponding Node’s spec.providerID.
NoMaxItems: 10000
items:MaxLength: 512
items:MinLength: 1
source Sourcesource is the role image: module code and runtime.Yes
identityRef IdentityReferenceidentityRef names the TerraformClusterIdentity whose credentials this
object’s Jobs use. Whether it is required, and where it falls back to
when unset, depends on the kind.
No
jobs JobPolicyjobs tunes the Jobs that run this object’s module. On a kind that
inherits defaults it is merged field by field over them (see
JobPolicy).
No
variables RawExtensionvariables are module variables, a JSON object: each key becomes a
named argument of the role module, converted by the module’s declared
type. Keys are Terraform identifiers; captf_ names and the role’s
contract inputs are reserved. Inline variables win over variablesFrom.
Whether a change re-applies or is rejected as immutable depends on the
kind. A key the module does not declare fails the apply (“Unsupported
argument”).
NoMaxProperties: 256
MinProperties: 1
Type: object
variablesFrom VariablesSource arrayvariablesFrom reads module variables from ConfigMaps and Secrets in
this namespace labeled captf.io/variables=true, in list order: a later
source wins on the same key, and inline variables win over all of
them. Whether and when a change to a referenced source takes effect
depends on the kind.
NoExactlyOneOf: [configMapRef secretRef]
MaxItems: 16
MinItems: 1
drift MachinePoolDriftPolicydrift is merged field by field over the cluster’s defaults.drift.
Unlike a machine’s, a pool’s drift may be remediated.
No
membershipRefreshIntervalSeconds integermembershipRefreshIntervalSeconds is how often the controller runs
apply -refresh-only to pick up group membership changes (new or
departed instances) between applies, in seconds
(https://captf.io/docs/module-author/contract/v1alpha1/machinepool.html “Membership refresh”). 0 (unset)
means 60, applied at reconcile; the CRD schema’s minimum of 15 makes 0
itself an invalid setting, so it unambiguously means unset, the same
convention as activeDeadlineSeconds and unhealthyThreshold
(kube-api-linter optionalfields: WhenRequired).
NoMaximum: 86400
Minimum: 15

TerraformMachinePoolStatus

TerraformMachinePoolStatus is the observed state of a TerraformMachinePool. Nothing here is load-bearing: every value is rebuilt after clusterctl move.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
conditions Condition arrayconditions of the TerraformMachinePool. Ready is mirrored by Cluster
API into the MachinePool’s InfrastructureReady condition.
NoMaxItems: 32
initialization Initializationinitialization is the v1beta2 contract’s initialization status.NoMinProperties: 1
observedGeneration integerobservedGeneration is the generation this status was computed for.NoMinimum: 1
activeJob ActiveJobactiveJob is the Job currently running for this object, if any.No
lastRun LastRunlastRun is the result of the most recent completed Job.No
lastDriftCheck TimelastDriftCheck is when the last drift check completed.No
lastRefresh TimelastRefresh is when the last refresh or drift check completed, or,
for a kind whose apply itself can give a definite health reading,
when that apply finished instead (that reading stands in for the
refresh after the apply).
No
pendingRefreshes integerpendingRefreshes counts the consecutive health samples (completed
refresh or drift Jobs) that read pending since the last other reading
or the last apply; unset otherwise. It spaces the refreshes while
health is pending: 30s, then 1m, 2m, 4m and at most 5m. It lives in
status only, so it restarts at 0 (30s) after clusterctl move.
NoMinimum: 1
observedStateSerial integerobservedStateSerial is the Terraform state serial the outputs were read
from.
NoMinimum: 1
stateSecretSuffix stringstateSecretSuffix is the kubernetes backend secret_suffix of this
object’s state. Informational: the controller derives it
deterministically.
NoMaxLength: 63
MinLength: 1
source SourceStatussource records what the last Job actually ran.NoMinProperties: 1
stateBackups StateBackup arraystateBackups are the state backups the controller keeps (newest
first), as of the last backup, prune or restore request.
NoMaxItems: 16
MinItems: 1
ready booleanready is the v1beta1 compatibility field Cluster API v1.14 still reads
to decide the pool is provisioned (external.IsReady,
capi/core/reconcilers/machinepool/machinepool_controller_phases.go).
It is latched together with initialization.provisioned: once true, it
stays true for the object’s life.
No
replicas integerreplicas is the group’s desired capacity as observed at the last
refresh, from the module’s replicas output. Outside a scaling
transition it equals len(providerIDList).
NoMinimum: 0
instances MachinePoolInstance arrayinstances are the group’s members, from the module’s instances
output. Provider-defined shape; not used by core Cluster API.
NoMaxItems: 1000
MinItems: 1
MinProperties: 1

TerraformMachinePoolTemplate

TerraformMachinePoolTemplate is the Schema for the terraformmachinepooltemplates API: a template for TerraformMachinePools, used by MachinePools. Unlike TerraformMachineTemplate it has no status: pools have no scale-from-zero, so there is no capacity or nodeInfo to resolve.

FieldDescriptionRequiredDefaultValidation
apiVersion stringinfrastructure.cluster.x-k8s.io/v1alpha1Yes
kind stringTerraformMachinePoolTemplateYes
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
No
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
No
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformMachinePoolTemplateSpecspec is the desired state of the TerraformMachinePoolTemplate.Yes

TerraformMachinePoolTemplateResource

TerraformMachinePoolTemplateResource describes the TerraformMachinePool created from a template.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformMachinePoolSpecspec of the TerraformMachinePool created from this template.YesMinProperties: 1

TerraformMachinePoolTemplateSpec

TerraformMachinePoolTemplateSpec is the desired state of a TerraformMachinePoolTemplate.

Appears in:

FieldDescriptionRequiredDefaultValidation
template TerraformMachinePoolTemplateResourcetemplate is the TerraformMachinePool created from this template.YesMinProperties: 1

TerraformMachineSpec

TerraformMachineSpec is the desired state of a TerraformMachine: the machine-role module image and how to run it. source, identityRef, variables and variablesFrom define the machine and are immutable after creation, and providerID can only be set once, by the controller; the admission webhook enforces this. jobs, drift and remediation are operational policy and may change at any time.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
providerID stringproviderID is the instance’s provider ID, set by the controller from the
module’s provider_id output. It must equal the Node’s spec.providerID.
NoMaxLength: 512
MinLength: 1
source Sourcesource is the role image: module code and runtime.Yes
identityRef IdentityReferenceidentityRef names the TerraformClusterIdentity whose credentials this
object’s Jobs use. Whether it is required, and where it falls back to
when unset, depends on the kind.
No
jobs JobPolicyjobs tunes the Jobs that run this object’s module. On a kind that
inherits defaults it is merged field by field over them (see
JobPolicy).
No
variables RawExtensionvariables are module variables, a JSON object: each key becomes a
named argument of the role module, converted by the module’s declared
type. Keys are Terraform identifiers; captf_ names and the role’s
contract inputs are reserved. Inline variables win over variablesFrom.
Whether a change re-applies or is rejected as immutable depends on the
kind. A key the module does not declare fails the apply (“Unsupported
argument”).
NoMaxProperties: 256
MinProperties: 1
Type: object
variablesFrom VariablesSource arrayvariablesFrom reads module variables from ConfigMaps and Secrets in
this namespace labeled captf.io/variables=true, in list order: a later
source wins on the same key, and inline variables win over all of
them. Whether and when a change to a referenced source takes effect
depends on the kind.
NoExactlyOneOf: [configMapRef secretRef]
MaxItems: 16
MinItems: 1
drift MachineDriftPolicydrift is merged field by field over the cluster’s defaults.drift. Drift
on a machine is always reported, never remediated.
No
remediation MachineRemediationremediation configures how an unhealthy instance is signalled to
Cluster API beyond the Ready condition.
No

TerraformMachineStatus

TerraformMachineStatus is the observed state of a TerraformMachine. Nothing here is load-bearing: every value is rebuilt after clusterctl move.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
conditions Condition arrayconditions of the TerraformMachine. Ready is mirrored by Cluster API into
the Machine’s InfrastructureReady condition.
NoMaxItems: 32
initialization Initializationinitialization is the v1beta2 contract’s initialization status.NoMinProperties: 1
observedGeneration integerobservedGeneration is the generation this status was computed for.NoMinimum: 1
activeJob ActiveJobactiveJob is the Job currently running for this object, if any.No
lastRun LastRunlastRun is the result of the most recent completed Job.No
lastDriftCheck TimelastDriftCheck is when the last drift check completed.No
lastRefresh TimelastRefresh is when the last refresh or drift check completed, or,
for a kind whose apply itself can give a definite health reading,
when that apply finished instead (that reading stands in for the
refresh after the apply).
No
pendingRefreshes integerpendingRefreshes counts the consecutive health samples (completed
refresh or drift Jobs) that read pending since the last other reading
or the last apply; unset otherwise. It spaces the refreshes while
health is pending: 30s, then 1m, 2m, 4m and at most 5m. It lives in
status only, so it restarts at 0 (30s) after clusterctl move.
NoMinimum: 1
observedStateSerial integerobservedStateSerial is the Terraform state serial the outputs were read
from.
NoMinimum: 1
stateSecretSuffix stringstateSecretSuffix is the kubernetes backend secret_suffix of this
object’s state. Informational: the controller derives it
deterministically.
NoMaxLength: 63
MinLength: 1
source SourceStatussource records what the last Job actually ran.NoMinProperties: 1
stateBackups StateBackup arraystateBackups are the state backups the controller keeps (newest
first), as of the last backup, prune or restore request.
NoMaxItems: 16
MinItems: 1
addresses MachineAddress arrayaddresses of the instance, from the module’s addresses output, in the
controller’s canonical order.
NoMaxItems: 256
MinItems: 1
failureDomain stringfailureDomain the instance actually runs in.NoMaxLength: 256
MinLength: 1
interruptible booleaninterruptible is true for spot/preemptible instances. Cluster API then
labels the Node cluster.x-k8s.io/interruptible.
No
unhealthySamples integerunhealthySamples counts consecutive unhealthy health samples (one per
completed refresh or drift Job after provisioning, or per apply whose
own outputs stood in for the post-apply refresh); unset when the
instance is healthy. It lives in status only, so it restarts at 0
after clusterctl move.
NoMinimum: 1

TerraformMachineTemplate

TerraformMachineTemplate is the Schema for the terraformmachinetemplates API: a template for TerraformMachines, used by MachineDeployments, MachineSets, KubeadmControlPlane and ClusterClass.

FieldDescriptionRequiredDefaultValidation
apiVersion stringinfrastructure.cluster.x-k8s.io/v1alpha1Yes
kind stringTerraformMachineTemplateYes
kind stringKind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
No
apiVersion stringAPIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
No
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformMachineTemplateSpecspec is the desired state of the TerraformMachineTemplate.Yes
status TerraformMachineTemplateStatusstatus is the observed state of the TerraformMachineTemplate.NoMinProperties: 1

TerraformMachineTemplateResource

TerraformMachineTemplateResource describes the TerraformMachine created from a template.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.No
spec TerraformMachineSpecspec of the TerraformMachine created from this template.YesMinProperties: 1

TerraformMachineTemplateSpec

TerraformMachineTemplateSpec is the desired state of a TerraformMachineTemplate.

Appears in:

FieldDescriptionRequiredDefaultValidation
template TerraformMachineTemplateResourcetemplate is the TerraformMachine created from this template.YesMinProperties: 1

TerraformMachineTemplateStatus

TerraformMachineTemplateStatus is the observed state of a TerraformMachineTemplate: the node size declared by its image, for Cluster Autoscaler scale from zero.

Validation:

  • MinProperties: 1

Appears in:

FieldDescriptionRequiredDefaultValidation
conditions Condition arrayconditions of the TerraformMachineTemplate (CapacityResolved).NoMaxItems: 32
nodeInfo NodeInfonodeInfo of the nodes the template creates, from the image label
io.captf.node-info.
NoMinProperties: 1
capacitySource CapacitySourcecapacitySource is the spec image reference capacity and nodeInfo were
resolved from; they are re-resolved when the spec image changes.
No

VariablesFormat

Underlying type: string

VariablesFormat is how the data values of a variablesFrom source are passed to the module.

Validation:

  • Enum: [String JSON]

Appears in:

FieldDescription
StringVariablesFormatString passes each data value as a string. The module’s
declared variable type converts it (“3” to a number, “true” to a bool).
JSONVariablesFormatJSON parses each data value as JSON, for lists, maps
and objects. A value that is not valid JSON is VariablesInvalid.

VariablesSource

VariablesSource reads module variables from the data of one ConfigMap or Secret in the object’s namespace: every data key becomes a variable of the same name. The source must carry the label captf.io/variables=true. Variables from a Secret are declared sensitive in the generated root, so Terraform redacts them in plan and apply output; they are still stored in the inputs Secrets and in state, like every input.

Validation:

  • ExactlyOneOf: [configMapRef secretRef]

Appears in:

FieldDescriptionRequiredDefaultValidation
configMapRef VariablesSourceReferenceconfigMapRef names a ConfigMap. Exactly one of configMapRef and
secretRef is set.
No
secretRef VariablesSourceReferencesecretRef names a Secret. Exactly one of configMapRef and secretRef is
set.
No
optional booleanoptional makes a missing or unlabeled source contribute nothing
instead of holding the object at DependenciesReady False
(VariablesSourceNotFound). Defaults to false.
No
format VariablesFormatformat of the data values: String passes each value as a string, JSON
parses each as JSON. Defaults to String, applied at reconcile.
NoEnum: [String JSON]

VariablesSourceReference

VariablesSourceReference names a ConfigMap or Secret in the object’s own namespace.

Appears in:

FieldDescriptionRequiredDefaultValidation
name stringname of the ConfigMap or Secret.YesMaxLength: 253
MinLength: 1
Pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$

WorkspaceSpec

WorkspaceSpec is the part of a Job-running kind’s spec every such kind shares: the role module image, its identity, Job policy and module variables. TerraformClusterSpec and TerraformMachineSpec embed it.

Appears in:

FieldDescriptionRequiredDefaultValidation
source Sourcesource is the role image: module code and runtime.Yes
identityRef IdentityReferenceidentityRef names the TerraformClusterIdentity whose credentials this
object’s Jobs use. Whether it is required, and where it falls back to
when unset, depends on the kind.
No
jobs JobPolicyjobs tunes the Jobs that run this object’s module. On a kind that
inherits defaults it is merged field by field over them (see
JobPolicy).
No
variables RawExtensionvariables are module variables, a JSON object: each key becomes a
named argument of the role module, converted by the module’s declared
type. Keys are Terraform identifiers; captf_ names and the role’s
contract inputs are reserved. Inline variables win over variablesFrom.
Whether a change re-applies or is rejected as immutable depends on the
kind. A key the module does not declare fails the apply (“Unsupported
argument”).
NoMaxProperties: 256
MinProperties: 1
Type: object
variablesFrom VariablesSource arrayvariablesFrom reads module variables from ConfigMaps and Secrets in
this namespace labeled captf.io/variables=true, in list order: a later
source wins on the same key, and inline variables win over all of
them. Whether and when a change to a referenced source takes effect
depends on the kind.
NoExactlyOneOf: [configMapRef secretRef]
MaxItems: 16
MinItems: 1

WorkspaceStatus

WorkspaceStatus is the part of a Job-running kind’s status every such kind shares. Nothing here is load-bearing: every value is rebuilt from spec, the state Secret, the durable inputs Secret or the Job list, because clusterctl move does not restore status. TerraformClusterStatus and TerraformMachineStatus embed it.

Appears in:

FieldDescriptionRequiredDefaultValidation
initialization Initializationinitialization is the v1beta2 contract’s initialization status.NoMinProperties: 1
observedGeneration integerobservedGeneration is the generation this status was computed for.NoMinimum: 1
activeJob ActiveJobactiveJob is the Job currently running for this object, if any.No
lastRun LastRunlastRun is the result of the most recent completed Job.No
lastDriftCheck TimelastDriftCheck is when the last drift check completed.No
lastRefresh TimelastRefresh is when the last refresh or drift check completed, or,
for a kind whose apply itself can give a definite health reading,
when that apply finished instead (that reading stands in for the
refresh after the apply).
No
pendingRefreshes integerpendingRefreshes counts the consecutive health samples (completed
refresh or drift Jobs) that read pending since the last other reading
or the last apply; unset otherwise. It spaces the refreshes while
health is pending: 30s, then 1m, 2m, 4m and at most 5m. It lives in
status only, so it restarts at 0 (30s) after clusterctl move.
NoMinimum: 1
observedStateSerial integerobservedStateSerial is the Terraform state serial the outputs were read
from.
NoMinimum: 1
stateSecretSuffix stringstateSecretSuffix is the kubernetes backend secret_suffix of this
object’s state. Informational: the controller derives it
deterministically.
NoMaxLength: 63
MinLength: 1
source SourceStatussource records what the last Job actually ran.NoMinProperties: 1
stateBackups StateBackup arraystateBackups are the state backups the controller keeps (newest
first), as of the last backup, prune or restore request.
NoMaxItems: 16
MinItems: 1