Shared types
All Palena CRDs reuse a handful of cross-cutting types. This page documents them once to avoid repetition in the per-CRD reference pages.
SecretKeyRef
Reference a single key inside a Secret.
yaml
name: my-secret # Secret name (same namespace)
key: apiKey # Key name inside the Secret's data| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Secret name (same namespace as the referencing CR). |
key | string | Yes | Key inside the Secret's data map. |
SecretKeysRef
Reference multiple keys inside a Secret. Map values are the actual keys in the Secret; map keys are the logical names the consuming operator expects.
yaml
name: my-s3-secret
keys:
accessKeyId: AWS_ACCESS_KEY_ID
secretAccessKey: AWS_SECRET_ACCESS_KEY| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Secret name (same namespace). |
keys | map[string]string | Yes | Logical → actual key mapping. |
LocalObjectReference
Reference another Kubernetes object by name in the same namespace.
yaml
name: production| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | Target object name. |
ImageSpec
yaml
repository: ghcr.io/palenaai/palena-websearch-mcp
tag: v0.1.0
pullPolicy: IfNotPresent| Field | Type | Default | Description |
|---|---|---|---|
repository | string | — | Container image repository. |
tag | string | component default | Image tag. |
pullPolicy | string | IfNotPresent | Always, IfNotPresent, Never. |
pullSecrets | []LocalObjectReference | — | Image pull secrets. |
IngressSpec
yaml
enabled: true
className: nginx
host: gateway.example.com
annotations:
nginx.ingress.kubernetes.io/proxy-body-size: "10m"
tls:
enabled: true
secretName: gateway-tls
# or:
certManager:
issuerRef:
name: letsencrypt-prod
kind: ClusterIssuer| Field | Type | Required | Description |
|---|---|---|---|
enabled | bool | Yes | Create an Ingress. |
className | string | No | ingressClassName passthrough. |
host | string | Yes (when enabled) | Hostname. |
annotations | map[string]string | No | Ingress annotations. |
tls.enabled | bool | No | Enable TLS. |
tls.secretName | string | No | Pre-existing TLS Secret. |
tls.certManager.issuerRef.name | string | No | cert-manager Issuer name. |
tls.certManager.issuerRef.kind | string | No | Issuer or ClusterIssuer. |
RouteSpec
OpenShift Route variant. Mutually exclusive with IngressSpec on platforms that support both.
yaml
enabled: true
host: gateway.apps.example.com
tls:
termination: edge
insecureEdgeTerminationPolicy: Redirect| Field | Type | Description |
|---|---|---|
enabled | bool | Create a Route. |
host | string | Hostname. |
tls.termination | string | edge, passthrough, reencrypt. |
tls.insecureEdgeTerminationPolicy | string | None, Allow, Redirect. |
AutoscalingSpec
yaml
enabled: true
minReplicas: 2
maxReplicas: 10
targetCPUUtilization: 70
targetMemoryUtilization: 80| Field | Type | Default | Description |
|---|---|---|---|
enabled | bool | false | Create an HPA. |
minReplicas | int32 | 1 | HPA min. |
maxReplicas | int32 | — | HPA max. |
targetCPUUtilization | int32 | — | Target CPU % across pods. |
targetMemoryUtilization | int32 | — | Target memory % across pods. |
OIDCSpec
yaml
enabled: true
issuer: https://auth.example.com/realms/palena
clientCredentials:
name: palena-oidc
key: clientSecret
scopes:
- openid
- profile
- email| Field | Type | Required | Description |
|---|---|---|---|
enabled | bool | Yes | Enable OIDC integration. |
issuer | string | Yes | OIDC issuer URL. |
clientId | string | No | OAuth client ID (plaintext). |
clientIdSecretRef | SecretKeyRef | No | OAuth client ID from Secret. |
clientCredentials | SecretKeyRef | Yes | OAuth client secret. |
scopes | []string | No | Requested scopes (default: openid profile email). |