Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions api/v1alpha1/dataprotectionapplication_types.go
Original file line number Diff line number Diff line change
Expand Up @@ -755,8 +755,19 @@ type CloudStorageLocation struct {
Prefix string `json:"prefix,omitempty"`

// CACert defines a CA bundle to use when verifying TLS connections to the provider.
// Deprecated: use CACertRef instead, matching Velero's own deprecation of inline CACert.
// Inline CACert requires updating this BSL to rotate the certificate; CACertRef lets
// Velero resolve the CA fresh from the Secret on each use, so rotation is just a Secret
// update.
// +optional
CACert []byte `json:"caCert,omitempty"`

// CACertRef is a reference to a Secret containing the CA certificate bundle to use
// when verifying TLS connections to the provider. The Secret must be in the same
// namespace as the DataProtectionApplication. Prefer this over CACert for CA
// certificate rotation support.
// +optional
CACertRef *corev1.SecretKeySelector `json:"caCertRef,omitempty"`
}

// BackupLocation defines the configuration for the DPA backup storage
Expand Down Expand Up @@ -794,8 +805,19 @@ type ObjectStorageLocation struct {
Prefix string `json:"prefix,omitempty"`

// CACert defines a CA bundle to use when verifying TLS connections to the provider.
// Deprecated: use CACertRef instead, matching Velero's own deprecation of inline CACert.
// Inline CACert requires updating this BSL to rotate the certificate; CACertRef lets
// Velero resolve the CA fresh from the Secret on each use, so rotation is just a Secret
// update.
// +optional
CACert []byte `json:"caCert,omitempty"`

// CACertRef is a reference to a Secret containing the CA certificate bundle to use
// when verifying TLS connections to the provider. The Secret must be in the same
// namespace as the DataProtectionApplication. Prefer this over CACert for CA
// certificate rotation support.
// +optional
CACertRef *corev1.SecretKeySelector `json:"caCertRef,omitempty"`
}

// StorageType defines the enforced values for the Velero StorageType
Expand Down
10 changes: 10 additions & 0 deletions api/v1alpha1/zz_generated.deepcopy.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

66 changes: 64 additions & 2 deletions bundle/manifests/oadp.openshift.io_dataprotectionapplications.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -69,9 +69,40 @@ spec:
nullable: true
type: string
caCert:
description: CACert defines a CA bundle to use when verifying TLS connections to the provider.
description: |-
CACert defines a CA bundle to use when verifying TLS connections to the provider.
Deprecated: use CACertRef instead, matching Velero's own deprecation of inline CACert.
Inline CACert requires updating this BSL to rotate the certificate; CACertRef lets
Velero resolve the CA fresh from the Secret on each use, so rotation is just a Secret
update.
format: byte
type: string
caCertRef:
description: |-
CACertRef is a reference to a Secret containing the CA certificate bundle to use
when verifying TLS connections to the provider. The Secret must be in the same
namespace as the DataProtectionApplication. Prefer this over CACert for CA
certificate rotation support.
properties:
key:
description: The key of the secret to select from. Must be a valid secret key.
type: string
name:
default: ""
description: |-
Name of the referent.
This field is effectively required, but due to backwards compatibility is
allowed to be empty. Instances of this type with an empty value here are
almost certainly wrong.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
optional:
description: Specify whether the Secret or its key must be defined
type: boolean
required:
- key
type: object
x-kubernetes-map-type: atomic
cloudStorageRef:
description: |-
LocalObjectReference contains enough information to let you locate the
Expand Down Expand Up @@ -1972,9 +2003,40 @@ spec:
description: Bucket is the bucket to use for object storage.
type: string
caCert:
description: CACert defines a CA bundle to use when verifying TLS connections to the provider.
description: |-
CACert defines a CA bundle to use when verifying TLS connections to the provider.
Deprecated: use CACertRef instead, matching Velero's own deprecation of inline CACert.
Inline CACert requires updating this BSL to rotate the certificate; CACertRef lets
Velero resolve the CA fresh from the Secret on each use, so rotation is just a Secret
update.
format: byte
type: string
caCertRef:
description: |-
CACertRef is a reference to a Secret containing the CA certificate bundle to use
when verifying TLS connections to the provider. The Secret must be in the same
namespace as the DataProtectionApplication. Prefer this over CACert for CA
certificate rotation support.
properties:
key:
description: The key of the secret to select from. Must be a valid secret key.
type: string
name:
default: ""
description: |-
Name of the referent.
This field is effectively required, but due to backwards compatibility is
allowed to be empty. Instances of this type with an empty value here are
almost certainly wrong.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
optional:
description: Specify whether the Secret or its key must be defined
type: boolean
required:
- key
type: object
x-kubernetes-map-type: atomic
prefix:
description: Prefix is the path inside a bucket to use for Velero storage. Optional.
type: string
Expand Down
66 changes: 64 additions & 2 deletions config/crd/bases/oadp.openshift.io_dataprotectionapplications.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -69,9 +69,40 @@ spec:
nullable: true
type: string
caCert:
description: CACert defines a CA bundle to use when verifying TLS connections to the provider.
description: |-
CACert defines a CA bundle to use when verifying TLS connections to the provider.
Deprecated: use CACertRef instead, matching Velero's own deprecation of inline CACert.
Inline CACert requires updating this BSL to rotate the certificate; CACertRef lets
Velero resolve the CA fresh from the Secret on each use, so rotation is just a Secret
update.
format: byte
type: string
caCertRef:
description: |-
CACertRef is a reference to a Secret containing the CA certificate bundle to use
when verifying TLS connections to the provider. The Secret must be in the same
namespace as the DataProtectionApplication. Prefer this over CACert for CA
certificate rotation support.
properties:
key:
description: The key of the secret to select from. Must be a valid secret key.
type: string
name:
default: ""
description: |-
Name of the referent.
This field is effectively required, but due to backwards compatibility is
allowed to be empty. Instances of this type with an empty value here are
almost certainly wrong.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
optional:
description: Specify whether the Secret or its key must be defined
type: boolean
required:
- key
type: object
x-kubernetes-map-type: atomic
cloudStorageRef:
description: |-
LocalObjectReference contains enough information to let you locate the
Expand Down Expand Up @@ -1972,9 +2003,40 @@ spec:
description: Bucket is the bucket to use for object storage.
type: string
caCert:
description: CACert defines a CA bundle to use when verifying TLS connections to the provider.
description: |-
CACert defines a CA bundle to use when verifying TLS connections to the provider.
Deprecated: use CACertRef instead, matching Velero's own deprecation of inline CACert.
Inline CACert requires updating this BSL to rotate the certificate; CACertRef lets
Velero resolve the CA fresh from the Secret on each use, so rotation is just a Secret
update.
format: byte
type: string
caCertRef:
description: |-
CACertRef is a reference to a Secret containing the CA certificate bundle to use
when verifying TLS connections to the provider. The Secret must be in the same
namespace as the DataProtectionApplication. Prefer this over CACert for CA
certificate rotation support.
properties:
key:
description: The key of the secret to select from. Must be a valid secret key.
type: string
name:
default: ""
description: |-
Name of the referent.
This field is effectively required, but due to backwards compatibility is
allowed to be empty. Instances of this type with an empty value here are
almost certainly wrong.
More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
type: string
optional:
description: Specify whether the Secret or its key must be defined
type: boolean
required:
- key
type: object
x-kubernetes-map-type: atomic
prefix:
description: Prefix is the path inside a bucket to use for Velero storage. Optional.
type: string
Expand Down
Loading