plane.yaml document a management plane is built from — the -f file of kubox plane create. Its shape is internal/application/plane.Deployment.
Every field, from internal/application/plane.Deployment’s yaml tags and doc comments. A field this document does not list is refused, so a misspelled name is caught rather than ignored.
Deployment
Deployment is one management plane, as an operator describes it.string
string
Metadata
Spec
All types
Every type in the document, in the order the root reaches them. Each is also linked from the field that uses it above.Metadata
Metadata names the deployment.string
Name is what this plane is called. It becomes the cluster’s name and the name its state is stored under, so it must not collide with another deployment that shares a state backend.
Spec
Spec is what an operator decides.string
Environment is what this deployment’s resources are TAGGED as, which is what cost reports group by. Empty takes metadata.name.
Capacity
Capacity is how big the plane is.integer
MaxConcurrentBuilds is how many builds run at once.
string
Profile names a shape: small, medium or large.
Database
Database is the record store.string
Mode is “external” today and only external: the plane stores no data itself, so a managed database would have nowhere to live.
string
Secret names the Kubernetes Secret holding the DSN.
Domain
Domain is what the plane is reachable at.string
Certificates is production or staging. Empty is production, because a plane that nobody chose an answer for is one in service.
string
Root is the zone that must already be delegated, e.g. kubox.cloud.
string
Subdomain is the label under it that this deployment owns.
Identity
Identity is who this plane trusts, and who vouches for it.string
WorkloadIdentity
Workload names the identity plane the plane’s own workloads federate through. Required: without it the plane’s pods have no identity of their own. The identity plane is created out of band, before any plane exists.
See WorkloadIdentity.
Provider
Provider is where the plane runs.AWSProvider
See AWSProvider.
Release
Release is what version to run, and where it comes from.string
AppRepository is where a built cluster’s apps come from. Empty takes the public one, which is right outside an air-gapped install.
string
PublicRegistry is where the two PUBLIC images come from: kubox, which a build Job runs, and kubox-agent, which every built cluster runs. Anyone can pull them, so a customer’s nodes need no credential and no registry extension to run the agent. Only kubox-plane, the licensed image, comes from Registry. Empty takes the default public registry; set it to mirror them somewhere else.
string
Registry is where the OPERATOR image is pulled from — an ECR host in production, because the plane’s nodes authenticate to it with their instance role. Empty takes the public one.
string
Version is the image tag, e.g. v0.4.2. Required: a plane built from whatever
latest meant that afternoon is a plane nobody can reproduce.State
State is where the plane’s infrastructure state is stored.string
Backend is the s3:// URL, required when Mode is external.
string
Mode is “managed” — kubox admin creates and owns the bucket — or “external”, where Backend names one that already exists.
string
Project is the name the plane’s state is stored under, and it is also the path the state lives at within the backend. Empty derives it from metadata.name.
WorkloadIdentity
WorkloadIdentity is the identity plane this deployment’s pods attest to.string
Issuer is the public OIDC issuer AWS validates the tokens against.
string
SpireServer is what the agent on each node dials, as host:port.
string
TrustBundleURL is where an agent bootstraps the server’s bundle from.
string
TrustDomain is the SPIFFE trust domain. Empty takes spec.domain.root, which is what it has always been for kubox.cloud.
AWSProvider
AWSProvider is the AWS half.string