{
  "description": "GarageAdminToken is the Schema for the garageadmintokens API\nIt manages static Admin API bootstrap material for Garage clusters.",
  "properties": {
    "apiVersion": {
      "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
      "type": [
        "string",
        "null"
      ]
    },
    "kind": {
      "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
      "type": [
        "string",
        "null"
      ]
    },
    "metadata": {
      "type": [
        "object",
        "null"
      ]
    },
    "spec": {
      "additionalProperties": false,
      "description": "GarageAdminTokenSpec defines the desired state of GarageAdminToken.\n\nGarageAdminToken provisions a static bootstrap Secret for the Garage Admin\nHTTP API. The referenced GarageCluster must explicitly select this Secret in\nspec.admin.adminTokenSecretRef. This resource does not create a row in\nGarage's dynamic Admin-token table, and deletion does not revoke bytes that a\nrunning Garage process already loaded at startup.\nAdmin tokens authenticate differently from S3 keys (GarageKey) — they use\nBearer token auth against the admin port (default 3903) instead of HMAC-SHA256.\n\nStatic configured tokens always have full admin access and no server-side\nname, scope, or expiry metadata. Use Garage's Admin API directly for a\nuser-managed scoped/dynamic token.",
      "properties": {
        "clusterRef": {
          "additionalProperties": false,
          "description": "ClusterRef references the GarageCluster this token belongs to",
          "properties": {
            "kubeConfigSecretRef": {
              "additionalProperties": false,
              "description": "KubeConfigSecretRef is reserved for a future remote Kubernetes client integration.\nIt is currently rejected by admission because the operator does not use it.",
              "properties": {
                "key": {
                  "description": "The key of the secret to select from.  Must be a valid secret key.",
                  "type": "string"
                },
                "name": {
                  "default": "",
                  "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
                  "type": [
                    "string",
                    "null"
                  ]
                },
                "optional": {
                  "description": "Specify whether the Secret or its key must be defined",
                  "type": [
                    "boolean",
                    "null"
                  ]
                }
              },
              "required": [
                "key"
              ],
              "type": [
                "object",
                "null"
              ],
              "x-kubernetes-map-type": "atomic"
            },
            "name": {
              "description": "Name of the GarageCluster resource.",
              "type": "string"
            },
            "namespace": {
              "description": "Namespace of the GarageCluster. Defaults to the referencing resource's namespace.\nCross-namespace references require a GarageReferenceGrant where supported by\nthe owning resource. GarageNode and GarageAdminToken reject them.",
              "type": [
                "string",
                "null"
              ]
            }
          },
          "required": [
            "name"
          ],
          "type": "object"
        },
        "expiresAt": {
          "description": "ExpiresAt is retained for compatibility but rejected because static\nconfigured tokens have no Garage-side expiry or revocation record.",
          "format": "date-time",
          "type": [
            "string",
            "null"
          ]
        },
        "name": {
          "description": "Name is retained for compatibility but rejected because static bootstrap\nmaterial has no Garage-side friendly name.",
          "type": [
            "string",
            "null"
          ]
        },
        "neverExpires": {
          "description": "NeverExpires is retained for compatibility. Static configured tokens are\nalways non-expiring, so this field is deprecated and has no effect.",
          "type": [
            "boolean",
            "null"
          ]
        },
        "secretTemplate": {
          "additionalProperties": false,
          "description": "SecretTemplate configures how the secret containing the token is generated",
          "properties": {
            "annotations": {
              "additionalProperties": {
                "type": "string"
              },
              "description": "Annotations to add to the secret",
              "type": [
                "object",
                "null"
              ]
            },
            "endpointKey": {
              "default": "admin-endpoint",
              "description": "EndpointKey is the key name for the admin endpoint",
              "type": [
                "string",
                "null"
              ]
            },
            "includeEndpoint": {
              "description": "IncludeEndpoint includes the admin API endpoint in the secret\nDefaults to true if not specified",
              "type": [
                "boolean",
                "null"
              ]
            },
            "labels": {
              "additionalProperties": {
                "type": "string"
              },
              "description": "Labels to add to the secret",
              "type": [
                "object",
                "null"
              ]
            },
            "name": {
              "description": "Name is the name of the secret to create\nDefaults to the GarageAdminToken name",
              "type": [
                "string",
                "null"
              ]
            },
            "tokenKey": {
              "default": "admin-token",
              "description": "TokenKey is the key name for the admin token in the secret",
              "type": [
                "string",
                "null"
              ]
            }
          },
          "type": [
            "object",
            "null"
          ]
        }
      },
      "required": [
        "clusterRef"
      ],
      "type": "object"
    },
    "status": {
      "additionalProperties": false,
      "description": "GarageAdminTokenStatus defines the observed state of GarageAdminToken",
      "properties": {
        "conditions": {
          "description": "Conditions represent the current state",
          "items": {
            "additionalProperties": false,
            "description": "Condition contains details for one aspect of the current state of this API Resource.",
            "properties": {
              "lastTransitionTime": {
                "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed.  If that is not known, then using the time when the API field changed is acceptable.",
                "format": "date-time",
                "type": "string"
              },
              "message": {
                "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
                "maxLength": 32768,
                "type": "string"
              },
              "observedGeneration": {
                "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
                "format": "int64",
                "minimum": 0,
                "type": [
                  "integer",
                  "null"
                ]
              },
              "reason": {
                "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
                "maxLength": 1024,
                "minLength": 1,
                "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
                "type": "string"
              },
              "status": {
                "description": "status of the condition, one of True, False, Unknown.",
                "enum": [
                  "True",
                  "False",
                  "Unknown"
                ],
                "type": "string"
              },
              "type": {
                "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
                "maxLength": 316,
                "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
                "type": "string"
              }
            },
            "required": [
              "lastTransitionTime",
              "message",
              "reason",
              "status",
              "type"
            ],
            "type": "object"
          },
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "type"
          ],
          "x-kubernetes-list-type": "map"
        },
        "expiresAt": {
          "description": "ExpiresAt is deprecated and always cleared because static configured\ntokens have no Garage-side expiry record.",
          "format": "date-time",
          "type": [
            "string",
            "null"
          ]
        },
        "observedGeneration": {
          "description": "ObservedGeneration is the last observed generation",
          "format": "int64",
          "type": [
            "integer",
            "null"
          ]
        },
        "phase": {
          "description": "Phase represents the current phase",
          "enum": [
            "Pending",
            "Creating",
            "Ready",
            "Deleting",
            "Failed",
            "Expired",
            "Unknown"
          ],
          "type": [
            "string",
            "null"
          ]
        },
        "secretRef": {
          "additionalProperties": false,
          "description": "SecretRef references the created secret",
          "properties": {
            "name": {
              "description": "name is unique within a namespace to reference a secret resource.",
              "type": [
                "string",
                "null"
              ]
            },
            "namespace": {
              "description": "namespace defines the space within which the secret name must be unique.",
              "type": [
                "string",
                "null"
              ]
            }
          },
          "type": [
            "object",
            "null"
          ],
          "x-kubernetes-map-type": "atomic"
        },
        "tokenDigest": {
          "description": "TokenDigest is the full SHA-256 digest of the static bearer. The controller\nuses it to detect mutation of an existing generated Secret without exposing\nany bearer bytes.",
          "type": [
            "string",
            "null"
          ]
        },
        "tokenId": {
          "description": "TokenID is a short display fingerprint of the generated static token. It is\nnot a Garage-assigned dynamic token ID.",
          "type": [
            "string",
            "null"
          ]
        }
      },
      "type": [
        "object",
        "null"
      ]
    }
  },
  "required": [
    "spec"
  ],
  "type": "object"
}