{
  "description": "GarageReferenceGrant grants permission for resources in other namespaces to\nreference GarageCluster, GarageBucket, or GarageKey resources in this namespace.\nGarageAdminToken remains a listed source kind for schema/status compatibility,\nbut its static credential path is namespace-local and does not accept a grant.\n\nThis resource must be created in the destination namespace (where the\nreferenced GarageCluster, GarageBucket, or GarageKey lives). Only admins of that namespace can\ncreate it, so tenants cannot self-grant cross-namespace access.\n\nExample: allow GarageKey objects in namespace \"team-b\" to reference\nGarageCluster \"my-cluster\" in namespace \"storage-admin\":\n\n\tapiVersion: garage.rajsingh.info/v1beta1\n\tkind: GarageReferenceGrant\n\tmetadata:\n\t  namespace: storage-admin\n\tspec:\n\t  from:\n\t    - kind: GarageKey\n\t      namespace: team-b\n\t  to:\n\t    - kind: GarageCluster\n\t      name: my-cluster\n\nNamespace selectors provide the same authorization using labels. Namespace\nlabels are part of this authorization decision: namespaces that gain a\nmatching label gain access, and namespaces that lose it no longer match.",
  "properties": {
    "apiVersion": {
      "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
      "type": [
        "string",
        "null"
      ]
    },
    "kind": {
      "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
      "type": [
        "string",
        "null"
      ]
    },
    "metadata": {
      "type": [
        "object",
        "null"
      ]
    },
    "spec": {
      "additionalProperties": false,
      "description": "GarageReferenceGrantSpec defines which namespaces and resource kinds are\npermitted to make cross-namespace references to resources in this namespace.",
      "properties": {
        "from": {
          "description": "From lists the permitted sources of cross-namespace references.",
          "items": {
            "additionalProperties": false,
            "description": "ReferenceGrantFrom specifies a permitted source namespace (by exact name or\nlabels) and resource kind.",
            "properties": {
              "kind": {
                "description": "Kind is the resource kind allowed to make cross-namespace references.\nGarageAdminToken remains in the schema for compatibility, but the static\ncredential path is namespace-local and does not accept cross-namespace grants.",
                "enum": [
                  "GarageKey",
                  "GarageBucket",
                  "GarageAdminToken"
                ],
                "type": "string"
              },
              "namespace": {
                "description": "Namespace is the exact namespace from which cross-namespace references are\nallowed. Exactly one of Namespace or NamespaceSelector must be set.",
                "minLength": 1,
                "type": [
                  "string",
                  "null"
                ]
              },
              "namespaceSelector": {
                "additionalProperties": false,
                "description": "NamespaceSelector selects source namespaces by their Kubernetes labels.\nExactly one of Namespace or NamespaceSelector must be set. An empty\nselector matches every namespace.",
                "properties": {
                  "matchExpressions": {
                    "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
                    "items": {
                      "additionalProperties": false,
                      "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
                      "properties": {
                        "key": {
                          "description": "key is the label key that the selector applies to.",
                          "type": "string"
                        },
                        "operator": {
                          "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
                          "type": "string"
                        },
                        "values": {
                          "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
                          "items": {
                            "type": "string"
                          },
                          "type": [
                            "array",
                            "null"
                          ],
                          "x-kubernetes-list-type": "atomic"
                        }
                      },
                      "required": [
                        "key",
                        "operator"
                      ],
                      "type": "object"
                    },
                    "type": [
                      "array",
                      "null"
                    ],
                    "x-kubernetes-list-type": "atomic"
                  },
                  "matchLabels": {
                    "additionalProperties": {
                      "type": "string"
                    },
                    "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
                    "type": [
                      "object",
                      "null"
                    ]
                  }
                },
                "type": [
                  "object",
                  "null"
                ],
                "x-kubernetes-map-type": "atomic"
              }
            },
            "required": [
              "kind"
            ],
            "type": "object",
            "x-kubernetes-validations": [
              {
                "message": "exactly one of namespace or namespaceSelector must be set",
                "rule": "has(self.__namespace__) != has(self.namespaceSelector)"
              }
            ]
          },
          "minItems": 1,
          "type": "array"
        },
        "to": {
          "description": "To lists the target resource kinds (and optionally specific names) that\nmay be referenced. If omitted, all GarageCluster and GarageBucket resources\nin this namespace are accessible. This preserves the original grant\nbehavior; newer target kinds such as GarageKey require an explicit entry.",
          "items": {
            "additionalProperties": false,
            "description": "ReferenceGrantTo specifies a target resource kind and optionally a specific name.",
            "properties": {
              "kind": {
                "description": "Kind is the target resource kind.",
                "enum": [
                  "GarageCluster",
                  "GarageBucket",
                  "GarageKey"
                ],
                "type": "string"
              },
              "name": {
                "description": "Name restricts access to a specific resource. If omitted, all resources of\nthe given kind in this namespace are accessible.",
                "minLength": 1,
                "type": [
                  "string",
                  "null"
                ]
              }
            },
            "required": [
              "kind"
            ],
            "type": "object"
          },
          "type": [
            "array",
            "null"
          ]
        }
      },
      "required": [
        "from"
      ],
      "type": "object"
    },
    "status": {
      "additionalProperties": false,
      "description": "GarageReferenceGrantStatus reflects which resources are currently using this grant.",
      "properties": {
        "conditions": {
          "description": "Conditions represent the current state.",
          "items": {
            "additionalProperties": false,
            "description": "Condition contains details for one aspect of the current state of this API Resource.",
            "properties": {
              "lastTransitionTime": {
                "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed.  If that is not known, then using the time when the API field changed is acceptable.",
                "format": "date-time",
                "type": "string"
              },
              "message": {
                "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
                "maxLength": 32768,
                "type": "string"
              },
              "observedGeneration": {
                "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
                "format": "int64",
                "minimum": 0,
                "type": [
                  "integer",
                  "null"
                ]
              },
              "reason": {
                "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
                "maxLength": 1024,
                "minLength": 1,
                "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
                "type": "string"
              },
              "status": {
                "description": "status of the condition, one of True, False, Unknown.",
                "enum": [
                  "True",
                  "False",
                  "Unknown"
                ],
                "type": "string"
              },
              "type": {
                "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
                "maxLength": 316,
                "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
                "type": "string"
              }
            },
            "required": [
              "lastTransitionTime",
              "message",
              "reason",
              "status",
              "type"
            ],
            "type": "object"
          },
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "type"
          ],
          "x-kubernetes-list-type": "map"
        },
        "inUseBy": {
          "description": "InUseBy lists resources currently referencing through this grant.\nRebuilt on every reconcile — safe to delete when this is empty.",
          "items": {
            "additionalProperties": false,
            "description": "ReferenceGrantUser identifies a resource using this grant.",
            "properties": {
              "kind": {
                "description": "Kind of the referencing resource.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "name": {
                "description": "Name of the referencing resource.",
                "type": [
                  "string",
                  "null"
                ]
              },
              "namespace": {
                "description": "Namespace of the referencing resource.",
                "type": [
                  "string",
                  "null"
                ]
              }
            },
            "type": "object"
          },
          "type": [
            "array",
            "null"
          ]
        }
      },
      "type": [
        "object",
        "null"
      ]
    }
  },
  "required": [
    "spec"
  ],
  "type": "object"
}