> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kubox.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# kubox cluster configuration reference

> The document a cluster is built from -- the -f file of kubox cluster create and the configYAML of a Cluster resource

The document a cluster is built from -- the `-f` file of `kubox cluster create` and the `configYAML` of a Cluster resource. Its shape is `internal/model.Config`, the type that parses it.

Every field, from `internal/model.Config`'s `yaml` tags and doc comments. A field this document does not list is ignored rather than reported, so check each name against this list -- a misspelled key is silently dropped, not applied.

## Config

<ResponseField name="apps" type="ConfigApps">
  <Expandable title="ConfigApps">
    <ResponseField name="containerRepository" type="string" default="ghcr.io/kubox-ai" />

    <ResponseField name="sourceDirectoryPath" type="string" />
  </Expandable>
</ResponseField>

<ResponseField name="aws" type="AwsConfig">
  <Expandable title="AwsConfig">
    <ResponseField name="ingress" type="IngressConfig">
      <Expandable title="IngressConfig">
        <ResponseField name="appAuth" type="AppAuthConfig">
          AppAuth puts the console's sign-in in front of every route this gateway serves.

          <Expandable title="AppAuthConfig">
            <ResponseField name="authoriseURL" type="string">
              AuthoriseURL is the console endpoint the gateway asks about each request, e.g. [https://app.kubox.cloud/api/gateway/authorize](https://app.kubox.cloud/api/gateway/authorize)
            </ResponseField>

            <ResponseField name="enabled" type="boolean" default="false" />
          </Expandable>
        </ResponseField>

        <ResponseField name="enabled" type="boolean" default="false" />

        <ResponseField name="host-subdomains" type="string[]">
          HostSubdomains are the names this gateway serves, each one label under the gateway hostname: \["app", "urban"] is served at app.\<gateway> and urban.\<gateway>. "@" is the gateway hostname itself, and needs a Routes entry because it has no name to default a backend from.
        </ResponseField>

        <ResponseField name="httpNodePort" type="integer" default="30080" />

        <ResponseField name="httpsNodePort" type="integer" default="30443" />

        <ResponseField name="letsEncryptEnv" type="string" default="staging">
          "staging" or "production"
        </ResponseField>

        <ResponseField name="routes" type="map of IngressRoute">
          Routes overrides the backend for a host-subdomain. By default a subdomain routes to Service \<subdomain>:80 in the gateway namespace ("kubox").

          <Expandable title="IngressRoute">
            <ResponseField name="modelGrant" type="boolean">
              ModelGrant passes the console's model grant to this route's backend. Turn it on only for an app that spends its own users' model access; any other app is safer never seeing one, since whoever holds a grant can open a model session as that user. Needs appAuth, which is what asks the console for the grant in the first place.
            </ResponseField>

            <ResponseField name="namespace" type="string">
              backend Service namespace; cross-namespace refs get a ReferenceGrant
            </ResponseField>

            <ResponseField name="port" type="integer">
              backend Service port
            </ResponseField>

            <ResponseField name="service" type="string">
              backend Service name
            </ResponseField>

            <ResponseField name="timeout" type="string">
              Gateway API duration, e.g. "300s"; applied to both request and backendRequest
            </ResponseField>
          </Expandable>
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="instanceMetadata" type="InstanceMetadataConfig">
      InstanceMetadata is how the nodes' IMDS answers pods. Unset leaves AWS's defaults, under which any pod can read the node's credentials.

      <Expandable title="InstanceMetadataConfig">
        <ResponseField name="podAccess" type="string">
          PodAccess is "blocked" or empty (AWS defaults).
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="nodeGroups" type="AwsNodeGroup[]">
      <Expandable title="AwsNodeGroup">
        <ResponseField name="awsAMI" type="string" />

        <ResponseField name="awsIAMInstanceProfile" type="string">
          AwsIAMInstanceProfile is the IAM instance profile this group's nodes launch with. Empty means the cloud connection's node profile on a cluster built through one, and no profile on a laptop build; "none" means no profile either way.
        </ResponseField>

        <ResponseField name="count" type="integer" default="1" />

        <ResponseField name="labels" type="map of string" />

        <ResponseField name="maxSpotPrice" type="number" default="0.0" />

        <ResponseField name="osDiskSizeGB" type="integer" default="30" />

        <ResponseField name="pool" type="string">
          Pool names this group of workers as a pool that grows and shrinks with demand. Count is how many workers it starts with. Set its smallest and largest size on the cluster's node pools; changing those takes effect without a rebuild. Adding, removing or renaming a pool here rebuilds the cluster.
        </ResponseField>

        <ResponseField name="publicIp" type="string" default="true" />

        <ResponseField name="role" type="string" default="worker" />

        <ResponseField name="spotInstance" type="string" default="true">
          SpotInstance defaults to true, so a node group is spot unless it opts out with spotInstance: "false".
        </ResponseField>

        <ResponseField name="systemExtensions" type="string[]">
          SystemExtensions are Talos system extensions baked into this group's boot image, e.g. "siderolabs/gvisor".
        </ResponseField>

        <ResponseField name="taints" type="Taint[]">
          <Expandable title="Taint">
            <ResponseField name="effect" type="string" />

            <ResponseField name="key" type="string" />

            <ResponseField name="value" type="string" />
          </Expandable>
        </ResponseField>

        <ResponseField name="vmType" type="string" />
      </Expandable>
    </ResponseField>

    <ResponseField name="region" type="string" default="us-east-1" />

    <ResponseField name="route53" type="Route53Config">
      <Expandable title="Route53Config">
        <ResponseField name="create-subdomain" type="boolean" default="false">
          Whether to create a subdomain record
        </ResponseField>

        <ResponseField name="subdomain" type="string">
          Optional, defaults to cluster short name
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="secrets" type="AwsSecret[]">
      <Expandable title="AwsSecret">
        <ResponseField name="data" type="map of string">
          Maps each key in the created Secret to a key inside the AWS JSON secret. Empty copies the whole value.
        </ResponseField>

        <ResponseField name="key" type="string">
          Name of the secret in AWS Secrets Manager.
        </ResponseField>

        <ResponseField name="name" type="string">
          Name of the Kubernetes Secret. Defaults to the AWS key.
        </ResponseField>

        <ResponseField name="namespace" type="string">
          Namespace the Kubernetes Secret is created in. Defaults to "default".
        </ResponseField>

        <ResponseField name="type" type="string">
          Kind of Kubernetes Secret to create: generic, docker-registry, or tls.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="azure" type="AzureConfig">
  <Expandable title="AzureConfig">
    <ResponseField name="nodeGroups" type="AzureNodeGroup[]">
      <Expandable title="AzureNodeGroup">
        <ResponseField name="count" type="integer" default="1" />

        <ResponseField name="labels" type="map of string" />

        <ResponseField name="osDiskSizeGB" type="integer" default="30" />

        <ResponseField name="pool" type="string">
          Pool names this group of workers as a pool that grows and shrinks with demand. Count is how many workers it starts with. Set its smallest and largest size on the cluster's node pools; changing those takes effect without a rebuild. Adding, removing or renaming a pool here rebuilds the cluster.
        </ResponseField>

        <ResponseField name="publicIp" type="string" default="true" />

        <ResponseField name="role" type="string" default="worker" />

        <ResponseField name="systemExtensions" type="string[]">
          SystemExtensions are Talos system extensions baked into this group's boot image, e.g. "siderolabs/gvisor".
        </ResponseField>

        <ResponseField name="taints" type="Taint[]">
          <Expandable title="Taint">
            <ResponseField name="effect" type="string" />

            <ResponseField name="key" type="string" />

            <ResponseField name="value" type="string" />
          </Expandable>
        </ResponseField>

        <ResponseField name="vmType" type="string" />
      </Expandable>
    </ResponseField>

    <ResponseField name="region" type="string" />
  </Expandable>
</ResponseField>

<ResponseField name="components" type="string[]" />

<ResponseField name="controllers" type="ControllerConfig[]">
  <Expandable title="ControllerConfig">
    <ResponseField name="config" type="map of any">
      Config holds controller-specific configuration options.
    </ResponseField>

    <ResponseField name="enabled" type="boolean">
      Enabled determines whether this controller should be installed. Defaults to true.
    </ResponseField>

    <ResponseField name="name" type="string">
      Name identifies this entry. It is also the controller to install unless Type says otherwise, so an entry naming a controller directly keeps working.
    </ResponseField>

    <ResponseField name="roleBinding" type="RoleBinding[]">
      RoleBindings declare ClusterRoleBindings to apply alongside this controller. The subject is a Kubernetes Group (e.g., a Teleport team group).

      <Expandable title="RoleBinding">
        <ResponseField name="name" type="string">
          Name is the ClusterRoleBinding name.
        </ResponseField>

        <ResponseField name="role" type="string">
          Role is the ClusterRole name referenced by the binding.
        </ResponseField>

        <ResponseField name="teleportGroup" type="string">
          TeleportGroup is the Kubernetes Group subject that receives the role.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="type" type="string">
      Type is the controller implementation to install. It defaults to Name, and lets a cluster run two instances of one controller under different names -- an nvidia and a gVisor RuntimeClass, say.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="dns" type="DNSConfig">
  <Expandable title="DNSConfig">
    <ResponseField name="rootDomain" type="string">
      e.g., "kubox.cloud"
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="gitOps" type="ConfigGitOps">
  <Expandable title="ConfigGitOps">
    <ResponseField name="directoryName" type="string" default="./cluster" />

    <ResponseField name="waitForCRD" type="WaitForCRD">
      <Expandable title="WaitForCRD">
        <ResponseField name="retries" type="integer" default="10" />

        <ResponseField name="sleep" type="string" default="30s" />
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="identity" type="IdentityConfig">
  Identity makes this cluster trust a console, so kubectl works with the same sign-in as everything else. Absent means it trusts nobody and the sealed admin kubeconfig remains the only way in.

  <Expandable title="IdentityConfig">
    <ResponseField name="audience" type="string">
      Audience the token must name. Defaults to kubox-cluster:\<cluster name>.
    </ResponseField>

    <ResponseField name="caBundle" type="string">
      CABundle validates the discovery fetch, when the serving certificate is not one the node already trusts. Empty means the in-cluster mirror is served by a certificate from the cluster's own CA.
    </ResponseField>

    <ResponseField name="discoveryURL" type="string">
      DiscoveryURL is where THIS cluster fetches the issuer's keys. Defaults to the in-cluster mirror, which is what almost every deployment should use.
    </ResponseField>

    <ResponseField name="groupBindings" type="GroupBinding[]">
      GroupBindings grants a ClusterRole to everyone in a group, so access belongs to an organisation rather than a person and removing someone there removes it here.

      <Expandable title="GroupBinding">
        <ResponseField name="clusterRole" type="string">
          ClusterRole is an existing role: view, edit, cluster-admin, or your own.
        </ResponseField>

        <ResponseField name="group" type="string">
          Group is the claim value, normally `<organisation>:<role>`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="groupsClaim" type="string">
      GroupsClaim carries organisation membership. Defaults to groups.
    </ResponseField>

    <ResponseField name="issuerURL" type="string">
      IssuerURL is what the `iss` claim in a token says, and must match it exactly.
    </ResponseField>

    <ResponseField name="usernameClaim" type="string">
      UsernameClaim identifies the person. Defaults to email.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="metadata" type="Metadata">
  <Expandable title="Metadata">
    <ResponseField name="clusterConfigDir" type="string" default="./cluster/config" />

    <ResponseField name="clusterName" type="string" />

    <ResponseField name="pulumi" type="MetadataPulumi">
      Pulumi identifies where the cluster's infrastructure state is stored: which organisation and project it is kept under, and its location.

      <Expandable title="MetadataPulumi">
        <ResponseField name="backendURL" type="string" />

        <ResponseField name="localStateDir" type="string" />

        <ResponseField name="orgName" type="string" />

        <ResponseField name="projectName" type="string" />
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="rbac" type="RbacRole[]">
  <Expandable title="RbacRole">
    <ResponseField name="name" type="string" />

    <ResponseField name="rules" type="RbacPolicyRule[]">
      <Expandable title="RbacPolicyRule">
        <ResponseField name="apiGroups" type="string[]" />

        <ResponseField name="resourceNames" type="string[]" />

        <ResponseField name="resources" type="string[]" />

        <ResponseField name="verbs" type="string[]" />
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="secrets" type="SecretsConfig">
  <Expandable title="SecretsConfig">
    <ResponseField name="generated" type="GeneratedSecret[]">
      <Expandable title="GeneratedSecret">
        <ResponseField name="copies" type="SecretCopy[]">
          <Expandable title="SecretCopy">
            <ResponseField name="keys" type="map of string">
              destination key -> source key; empty copies every key as-is
            </ResponseField>

            <ResponseField name="name" type="string" />

            <ResponseField name="namespace" type="string" />
          </Expandable>
        </ResponseField>

        <ResponseField name="env" type="map of string">
          data key -> environment variable that seeds it
        </ResponseField>

        <ResponseField name="keys" type="map of string">
          data key -> generator (hex16, hex32, alnum16, alnum32, uuid)
        </ResponseField>

        <ResponseField name="name" type="string" />

        <ResponseField name="namespace" type="string">
          defaults to "default"; created if missing
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="tags" type="ConfigTags[]">
  <Expandable title="ConfigTags">
    <ResponseField name="key" type="string" />

    <ResponseField name="value" type="string" />
  </Expandable>
</ResponseField>

<ResponseField name="talos" type="ConfigTalos">
  <Expandable title="ConfigTalos">
    <ResponseField name="architecture" type="string" default="amd64" />

    <ResponseField name="imageStorageAccount" type="string" />

    <ResponseField name="machine" type="Machine">
      <Expandable title="Machine">
        <ResponseField name="kubelet" type="KubeletConfig">
          <Expandable title="KubeletConfig">
            <ResponseField name="credentialProviderConfig" type="map of any" />

            <ResponseField name="defaultRuntimeSeccompProfileEnabled" type="boolean" />

            <ResponseField name="disableManifestsDirectory" type="boolean" />

            <ResponseField name="extraArgs" type="map of string" />
          </Expandable>
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="url" type="string" />

    <ResponseField name="version" type="string" default="v1.13.10" />
  </Expandable>
</ResponseField>

## All types

Every type in the document, in the order the root reaches them. Each is also linked from the field that uses it above.

### ConfigApps

<ResponseField name="containerRepository" type="string" default="ghcr.io/kubox-ai" />

<ResponseField name="sourceDirectoryPath" type="string" />

### AwsConfig

<ResponseField name="ingress" type="IngressConfig">
  See [IngressConfig](#ingressconfig).
</ResponseField>

<ResponseField name="instanceMetadata" type="InstanceMetadataConfig">
  InstanceMetadata is how the nodes' IMDS answers pods. Unset leaves AWS's defaults, under which any pod can read the node's credentials.
  See [InstanceMetadataConfig](#instancemetadataconfig).
</ResponseField>

<ResponseField name="nodeGroups" type="AwsNodeGroup[]">
  See [AwsNodeGroup](#awsnodegroup).
</ResponseField>

<ResponseField name="region" type="string" default="us-east-1" />

<ResponseField name="route53" type="Route53Config">
  See [Route53Config](#route53config).
</ResponseField>

<ResponseField name="secrets" type="AwsSecret[]">
  See [AwsSecret](#awssecret).
</ResponseField>

### AzureConfig

<ResponseField name="nodeGroups" type="AzureNodeGroup[]">
  See [AzureNodeGroup](#azurenodegroup).
</ResponseField>

<ResponseField name="region" type="string" />

### ControllerConfig

ControllerConfig holds the configuration for a system controller.

<ResponseField name="config" type="map of any">
  Config holds controller-specific configuration options.
</ResponseField>

<ResponseField name="enabled" type="boolean">
  Enabled determines whether this controller should be installed. Defaults to true.
</ResponseField>

<ResponseField name="name" type="string">
  Name identifies this entry. It is also the controller to install unless Type says otherwise, so an entry naming a controller directly keeps working.
</ResponseField>

<ResponseField name="roleBinding" type="RoleBinding[]">
  RoleBindings declare ClusterRoleBindings to apply alongside this controller. The subject is a Kubernetes Group (e.g., a Teleport team group).
  See [RoleBinding](#rolebinding).
</ResponseField>

<ResponseField name="type" type="string">
  Type is the controller implementation to install. It defaults to Name, and lets a cluster run two instances of one controller under different names -- an nvidia and a gVisor RuntimeClass, say.
</ResponseField>

### DNSConfig

DNSConfig configures global DNS settings.

<ResponseField name="rootDomain" type="string">
  e.g., "kubox.cloud"
</ResponseField>

### ConfigGitOps

<ResponseField name="directoryName" type="string" default="./cluster" />

<ResponseField name="waitForCRD" type="WaitForCRD">
  See [WaitForCRD](#waitforcrd).
</ResponseField>

### IdentityConfig

IdentityConfig makes a cluster trust a console, so a person can use kubectl with the same sign-in they use everywhere else.

<ResponseField name="audience" type="string">
  Audience the token must name. Defaults to kubox-cluster:\<cluster name>.
</ResponseField>

<ResponseField name="caBundle" type="string">
  CABundle validates the discovery fetch, when the serving certificate is not one the node already trusts. Empty means the in-cluster mirror is served by a certificate from the cluster's own CA.
</ResponseField>

<ResponseField name="discoveryURL" type="string">
  DiscoveryURL is where THIS cluster fetches the issuer's keys. Defaults to the in-cluster mirror, which is what almost every deployment should use.
</ResponseField>

<ResponseField name="groupBindings" type="GroupBinding[]">
  GroupBindings grants a ClusterRole to everyone in a group, so access belongs to an organisation rather than a person and removing someone there removes it here.
  See [GroupBinding](#groupbinding).
</ResponseField>

<ResponseField name="groupsClaim" type="string">
  GroupsClaim carries organisation membership. Defaults to groups.
</ResponseField>

<ResponseField name="issuerURL" type="string">
  IssuerURL is what the `iss` claim in a token says, and must match it exactly.
</ResponseField>

<ResponseField name="usernameClaim" type="string">
  UsernameClaim identifies the person. Defaults to email.
</ResponseField>

### Metadata

<ResponseField name="clusterConfigDir" type="string" default="./cluster/config" />

<ResponseField name="clusterName" type="string" />

<ResponseField name="pulumi" type="MetadataPulumi">
  Pulumi identifies where the cluster's infrastructure state is stored: which organisation and project it is kept under, and its location.
  See [MetadataPulumi](#metadatapulumi).
</ResponseField>

### RbacRole

RbacRole is a declarative ClusterRole definition loaded from the cluster config.

<ResponseField name="name" type="string" />

<ResponseField name="rules" type="RbacPolicyRule[]">
  See [RbacPolicyRule](#rbacpolicyrule).
</ResponseField>

### SecretsConfig

SecretsConfig declares secrets kubox itself materialises at create time, as opposed to aws.secrets which are fetched from AWS Secrets Manager.

<ResponseField name="generated" type="GeneratedSecret[]">
  See [GeneratedSecret](#generatedsecret).
</ResponseField>

### ConfigTags

<ResponseField name="key" type="string" />

<ResponseField name="value" type="string" />

### ConfigTalos

<ResponseField name="architecture" type="string" default="amd64" />

<ResponseField name="imageStorageAccount" type="string" />

<ResponseField name="machine" type="Machine">
  See [Machine](#machine).
</ResponseField>

<ResponseField name="url" type="string" />

<ResponseField name="version" type="string" default="v1.13.10" />

### IngressConfig

IngressConfig configures internet ingress through the load balancer.

<ResponseField name="appAuth" type="AppAuthConfig">
  AppAuth puts the console's sign-in in front of every route this gateway serves.
  See [AppAuthConfig](#appauthconfig).
</ResponseField>

<ResponseField name="enabled" type="boolean" default="false" />

<ResponseField name="host-subdomains" type="string[]">
  HostSubdomains are the names this gateway serves, each one label under the gateway hostname: \["app", "urban"] is served at app.\<gateway> and urban.\<gateway>. "@" is the gateway hostname itself, and needs a Routes entry because it has no name to default a backend from.
</ResponseField>

<ResponseField name="httpNodePort" type="integer" default="30080" />

<ResponseField name="httpsNodePort" type="integer" default="30443" />

<ResponseField name="letsEncryptEnv" type="string" default="staging">
  "staging" or "production"
</ResponseField>

<ResponseField name="routes" type="map of IngressRoute">
  Routes overrides the backend for a host-subdomain. By default a subdomain routes to Service \<subdomain>:80 in the gateway namespace ("kubox").
  See [IngressRoute](#ingressroute).
</ResponseField>

### InstanceMetadataConfig

InstanceMetadataConfig is the IMDS boundary on a node.

<ResponseField name="podAccess" type="string">
  PodAccess is "blocked" or empty (AWS defaults).
</ResponseField>

### AwsNodeGroup

AwsNodeGroup extends NodeGroup with AWS-specific configuration.

<ResponseField name="awsAMI" type="string" />

<ResponseField name="awsIAMInstanceProfile" type="string">
  AwsIAMInstanceProfile is the IAM instance profile this group's nodes launch with. Empty means the cloud connection's node profile on a cluster built through one, and no profile on a laptop build; "none" means no profile either way.
</ResponseField>

<ResponseField name="count" type="integer" default="1" />

<ResponseField name="labels" type="map of string" />

<ResponseField name="maxSpotPrice" type="number" default="0.0" />

<ResponseField name="osDiskSizeGB" type="integer" default="30" />

<ResponseField name="pool" type="string">
  Pool names this group of workers as a pool that grows and shrinks with demand. Count is how many workers it starts with. Set its smallest and largest size on the cluster's node pools; changing those takes effect without a rebuild. Adding, removing or renaming a pool here rebuilds the cluster.
</ResponseField>

<ResponseField name="publicIp" type="string" default="true" />

<ResponseField name="role" type="string" default="worker" />

<ResponseField name="spotInstance" type="string" default="true">
  SpotInstance defaults to true, so a node group is spot unless it opts out with spotInstance: "false".
</ResponseField>

<ResponseField name="systemExtensions" type="string[]">
  SystemExtensions are Talos system extensions baked into this group's boot image, e.g. "siderolabs/gvisor".
</ResponseField>

<ResponseField name="taints" type="Taint[]">
  See [Taint](#taint).
</ResponseField>

<ResponseField name="vmType" type="string" />

### Route53Config

Route53Config configures AWS Route53 DNS record creation.

<ResponseField name="create-subdomain" type="boolean" default="false">
  Whether to create a subdomain record
</ResponseField>

<ResponseField name="subdomain" type="string">
  Optional, defaults to cluster short name
</ResponseField>

### AwsSecret

AwsSecret pulls a secret from AWS Secrets Manager into the cluster.

<ResponseField name="data" type="map of string">
  Maps each key in the created Secret to a key inside the AWS JSON secret. Empty copies the whole value.
</ResponseField>

<ResponseField name="key" type="string">
  Name of the secret in AWS Secrets Manager.
</ResponseField>

<ResponseField name="name" type="string">
  Name of the Kubernetes Secret. Defaults to the AWS key.
</ResponseField>

<ResponseField name="namespace" type="string">
  Namespace the Kubernetes Secret is created in. Defaults to "default".
</ResponseField>

<ResponseField name="type" type="string">
  Kind of Kubernetes Secret to create: generic, docker-registry, or tls.
</ResponseField>

### AzureNodeGroup

AzureNodeGroup extends NodeGroup with Azure-specific configuration.

<ResponseField name="count" type="integer" default="1" />

<ResponseField name="labels" type="map of string" />

<ResponseField name="osDiskSizeGB" type="integer" default="30" />

<ResponseField name="pool" type="string">
  Pool names this group of workers as a pool that grows and shrinks with demand. Count is how many workers it starts with. Set its smallest and largest size on the cluster's node pools; changing those takes effect without a rebuild. Adding, removing or renaming a pool here rebuilds the cluster.
</ResponseField>

<ResponseField name="publicIp" type="string" default="true" />

<ResponseField name="role" type="string" default="worker" />

<ResponseField name="systemExtensions" type="string[]">
  SystemExtensions are Talos system extensions baked into this group's boot image, e.g. "siderolabs/gvisor".
</ResponseField>

<ResponseField name="taints" type="Taint[]">
  See [Taint](#taint).
</ResponseField>

<ResponseField name="vmType" type="string" />

### RoleBinding

RoleBinding is a declarative ClusterRoleBinding that grants a role to a group.

<ResponseField name="name" type="string">
  Name is the ClusterRoleBinding name.
</ResponseField>

<ResponseField name="role" type="string">
  Role is the ClusterRole name referenced by the binding.
</ResponseField>

<ResponseField name="teleportGroup" type="string">
  TeleportGroup is the Kubernetes Group subject that receives the role.
</ResponseField>

### WaitForCRD

<ResponseField name="retries" type="integer" default="10" />

<ResponseField name="sleep" type="string" default="30s" />

### GroupBinding

GroupBinding grants a ClusterRole to everyone in a group.

<ResponseField name="clusterRole" type="string">
  ClusterRole is an existing role: view, edit, cluster-admin, or your own.
</ResponseField>

<ResponseField name="group" type="string">
  Group is the claim value, normally `<organisation>:<role>`.
</ResponseField>

### MetadataPulumi

<ResponseField name="backendURL" type="string" />

<ResponseField name="localStateDir" type="string" />

<ResponseField name="orgName" type="string" />

<ResponseField name="projectName" type="string" />

### RbacPolicyRule

RbacPolicyRule mirrors the fields of a Kubernetes rbacv1.PolicyRule.

<ResponseField name="apiGroups" type="string[]" />

<ResponseField name="resourceNames" type="string[]" />

<ResponseField name="resources" type="string[]" />

<ResponseField name="verbs" type="string[]" />

### GeneratedSecret

GeneratedSecret is a Secret whose values are created once, on first `kubox admin create`, and then left alone: a value that already exists in the cluster is never regenerated, so re-running create (or rotating by hand) does not break anything that holds the old value. Copies are always re-synced from the primary so they cannot drift.

<ResponseField name="copies" type="SecretCopy[]">
  See [SecretCopy](#secretcopy).
</ResponseField>

<ResponseField name="env" type="map of string">
  data key -> environment variable that seeds it
</ResponseField>

<ResponseField name="keys" type="map of string">
  data key -> generator (hex16, hex32, alnum16, alnum32, uuid)
</ResponseField>

<ResponseField name="name" type="string" />

<ResponseField name="namespace" type="string">
  defaults to "default"; created if missing
</ResponseField>

### Machine

<ResponseField name="kubelet" type="KubeletConfig">
  See [KubeletConfig](#kubeletconfig).
</ResponseField>

### AppAuthConfig

AppAuthConfig makes the gateway ask the console who somebody is before an app behind it sees the request.

<ResponseField name="authoriseURL" type="string">
  AuthoriseURL is the console endpoint the gateway asks about each request, e.g. [https://app.kubox.cloud/api/gateway/authorize](https://app.kubox.cloud/api/gateway/authorize)
</ResponseField>

<ResponseField name="enabled" type="boolean" default="false" />

### IngressRoute

IngressRoute overrides where a host-subdomain's HTTPRoute sends traffic. Every field is optional; an unset field keeps the default (Service named after the subdomain, gateway namespace, port 80, gateway default timeout).

<ResponseField name="modelGrant" type="boolean">
  ModelGrant passes the console's model grant to this route's backend. Turn it on only for an app that spends its own users' model access; any other app is safer never seeing one, since whoever holds a grant can open a model session as that user. Needs appAuth, which is what asks the console for the grant in the first place.
</ResponseField>

<ResponseField name="namespace" type="string">
  backend Service namespace; cross-namespace refs get a ReferenceGrant
</ResponseField>

<ResponseField name="port" type="integer">
  backend Service port
</ResponseField>

<ResponseField name="service" type="string">
  backend Service name
</ResponseField>

<ResponseField name="timeout" type="string">
  Gateway API duration, e.g. "300s"; applied to both request and backendRequest
</ResponseField>

### Taint

<ResponseField name="effect" type="string" />

<ResponseField name="key" type="string" />

<ResponseField name="value" type="string" />

### SecretCopy

SecretCopy mirrors keys of a GeneratedSecret into another Secret, typically in another namespace, because Kubernetes Secrets are namespaced.

<ResponseField name="keys" type="map of string">
  destination key -> source key; empty copies every key as-is
</ResponseField>

<ResponseField name="name" type="string" />

<ResponseField name="namespace" type="string" />

### KubeletConfig

KubeletConfig represents the kubelet configuration.

<ResponseField name="credentialProviderConfig" type="map of any" />

<ResponseField name="defaultRuntimeSeccompProfileEnabled" type="boolean" />

<ResponseField name="disableManifestsDirectory" type="boolean" />

<ResponseField name="extraArgs" type="map of string" />


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.