Skip to content

Shared types ​

All Palena CRDs reuse a handful of cross-cutting types. This page documents them once to avoid repetition in the per-CRD reference pages.

SecretKeyRef ​

Reference a single key inside a Secret.

yaml
name: my-secret   # Secret name (same namespace)
key: apiKey       # Key name inside the Secret's data
FieldTypeRequiredDescription
namestringYesSecret name (same namespace as the referencing CR).
keystringYesKey inside the Secret's data map.

SecretKeysRef ​

Reference multiple keys inside a Secret. Map values are the actual keys in the Secret; map keys are the logical names the consuming operator expects.

yaml
name: my-s3-secret
keys:
  accessKeyId: AWS_ACCESS_KEY_ID
  secretAccessKey: AWS_SECRET_ACCESS_KEY
FieldTypeRequiredDescription
namestringYesSecret name (same namespace).
keysmap[string]stringYesLogical → actual key mapping.

LocalObjectReference ​

Reference another Kubernetes object by name in the same namespace.

yaml
name: production
FieldTypeRequiredDescription
namestringYesTarget object name.

ImageSpec ​

yaml
repository: ghcr.io/palenaai/palena-websearch-mcp
tag: v0.1.0
pullPolicy: IfNotPresent
FieldTypeDefaultDescription
repositorystring—Container image repository.
tagstringcomponent defaultImage tag.
pullPolicystringIfNotPresentAlways, IfNotPresent, Never.
pullSecrets[]LocalObjectReference—Image pull secrets.

IngressSpec ​

yaml
enabled: true
className: nginx
host: gateway.example.com
annotations:
  nginx.ingress.kubernetes.io/proxy-body-size: "10m"
tls:
  enabled: true
  secretName: gateway-tls
  # or:
  certManager:
    issuerRef:
      name: letsencrypt-prod
      kind: ClusterIssuer
FieldTypeRequiredDescription
enabledboolYesCreate an Ingress.
classNamestringNoingressClassName passthrough.
hoststringYes (when enabled)Hostname.
annotationsmap[string]stringNoIngress annotations.
tls.enabledboolNoEnable TLS.
tls.secretNamestringNoPre-existing TLS Secret.
tls.certManager.issuerRef.namestringNocert-manager Issuer name.
tls.certManager.issuerRef.kindstringNoIssuer or ClusterIssuer.

RouteSpec ​

OpenShift Route variant. Mutually exclusive with IngressSpec on platforms that support both.

yaml
enabled: true
host: gateway.apps.example.com
tls:
  termination: edge
  insecureEdgeTerminationPolicy: Redirect
FieldTypeDescription
enabledboolCreate a Route.
hoststringHostname.
tls.terminationstringedge, passthrough, reencrypt.
tls.insecureEdgeTerminationPolicystringNone, Allow, Redirect.

AutoscalingSpec ​

yaml
enabled: true
minReplicas: 2
maxReplicas: 10
targetCPUUtilization: 70
targetMemoryUtilization: 80
FieldTypeDefaultDescription
enabledboolfalseCreate an HPA.
minReplicasint321HPA min.
maxReplicasint32—HPA max.
targetCPUUtilizationint32—Target CPU % across pods.
targetMemoryUtilizationint32—Target memory % across pods.

OIDCSpec ​

yaml
enabled: true
issuer: https://auth.example.com/realms/palena
clientCredentials:
  name: palena-oidc
  key: clientSecret
scopes:
  - openid
  - profile
  - email
FieldTypeRequiredDescription
enabledboolYesEnable OIDC integration.
issuerstringYesOIDC issuer URL.
clientIdstringNoOAuth client ID (plaintext).
clientIdSecretRefSecretKeyRefNoOAuth client ID from Secret.
clientCredentialsSecretKeyRefYesOAuth client secret.
scopes[]stringNoRequested scopes (default: openid profile email).

Released under the Apache 2.0 License. "Palena" is a trademark of bitkaio LLC.