Skip to main content

Platform Application Reference

Auto-generated derived type for PlatformApplicationSpec via CustomResource

NameTypeDescriptionRequired
apiVersionstringmeta.p6m.dev/v1alpha1true
kindstringPlatformApplicationtrue
metadataobjectRefer to the Kubernetes API documentation for the fields of the metadata field.true
specobject

Validations:

  • !(has(self.deployment) && (!has(self.deployment.kind) || self.deployment.kind == 'Deployment') && has(self.deployment.volumeMounts) && self.deployment.volumeMounts.exists(vm, has(vm.source) && (has(vm.source.size) || has(vm.source.claimName)) && (!has(vm.source.accessModes) || !vm.source.accessModes.exists(m, m == 'ReadWriteMany') || vm.source.accessModes.exists(m, m == 'ReadWriteOnce')) ) && has(self.autoscaling) && ((has(self.autoscaling.enabled) && self.autoscaling.enabled == true) || (has(self.autoscaling.minReplicas) && self.autoscaling.minReplicas > 1) || (has(self.autoscaling.maxReplicas) && self.autoscaling.maxReplicas > 1) || (has(self.autoscaling.triggers) && self.autoscaling.triggers.size() > 0))): Deployment with an RWO PersistentVolumeClaim must run as a singleton. Either disable autoscaling (remove triggers, enabled, minReplicas, maxReplicas), set accessModes: [ReadWriteMany] on the volume (requires RWX storage like EFS), or set kind: StatefulSet (each replica gets its own PVC).
  • !has(self.resourceRequirements) || self.resourceRequirements.all(r, self.resourceRequirements.exists_one(x, x.resourceName == r.resourceName)): spec.resourceRequirements entries must have unique resourceName values.

true
statusobject
false

spec​

NameTypeDescriptionRequired
autoscalingobject

Horizontal Pod Autoscaling (HPA) and KEDA trigger configuration. HPA uses a hardcoded CPU utilization threshold of 80%. Optional KEDA triggers can be used for alternative scaling metrics (e.g., cron-based scaling).

false
configmap[string]string

Environment variables to inject into the pod. Specified as key-value pairs (e.g., "KEY: value"). These are injected directly into the container environment.

false
deploymentobject

Kubernetes deployment configuration including container image, ports, readiness probes, and resource requests/limits.


Validations:

  • self.kind == oldSelf.kind: workload kind is immutable; delete and recreate the PlatformApplication to switch between Deployment and StatefulSet
  • self.kind == 'StatefulSet' || (!has(self.volumeClaimTemplates) || self.volumeClaimTemplates.size() == 0): volumeClaimTemplates is only valid when kind is StatefulSet
  • self.kind == 'StatefulSet' || !has(self.podManagementPolicy): podManagementPolicy is only valid when kind is StatefulSet
  • !has(self.podManagementPolicy) || self.podManagementPolicy == 'OrderedReady' || self.podManagementPolicy == 'Parallel': podManagementPolicy must be 'OrderedReady' or 'Parallel'

false
networkingobject

Networking configuration including ingress, inbound/outbound traffic policies, and CDN settings.

false
resourceRequirements[]object

Infrastructure dependencies this application needs (databases, caches, queues, buckets). Each entry is realized as a ResourceGrant (platform.p6m.dev/v1alpha1) in this namespace, owned by the application; the platform-resource-operator provisions the backing resource and surfaces a connection Secret, whose tokens are injected into the container as environment variables.

false
resourcesmap[string][]object

Cloud resources that the application will be granted access to via IAM policies. Any resources provisioned with Crossplane compositions can be referenced here. Note: this only grants access to existing resources and does not create them. Resource creation must be done via Crossplane compositions separately. Each composition has different accesses available—refer to the composition documentation. Special case: specify "crdb" as the key to request a CockroachDB database without needing to specify accesses.

false
rolloutsobject

ArgoCD Rollouts configuration for advanced deployment strategies. Not currently implemented.

false
secrets[]object

Secrets from the cloud secret store (e.g., AWS Secrets Manager, Azure Key Vault) that will be synced as Kubernetes secrets and mounted into the pod as environment variables. Each secret is stored in the cloud provider as key-value pairs and will be injected into the pod with the key as the environment variable name.

false
workloadSelectorsobject

Node selectors to restrict where the application can be deployed. Defaults to supporting both amd64 and arm64 architectures on any available instance type. If not specified, the application will be scheduled on any available compatible node. Use instanceTypes to further restrict scheduling to specific hardware SKUs (e.g. for performance-sensitive workloads that benefit from particular CPU features).


Default: map[kubernetes.io/architectures:amd64,arm64]

false

spec.autoscaling​

↩ Parent

Horizontal Pod Autoscaling (HPA) and KEDA trigger configuration. HPA uses a hardcoded CPU utilization threshold of 80%. Optional KEDA triggers can be used for alternative scaling metrics (e.g., cron-based scaling).

NameTypeDescriptionRequired
cpuThresholdPercentageinteger

RESERVED: CPU utilization threshold percentage for scaling. Not currently implemented; HPA uses a hardcoded 80% CPU utilization threshold instead. Valid range: 1-100%.


Format: int32
Minimum: 1
Maximum: 100

false
enabledboolean

Enable Horizontal Pod Autoscaling (HPA) or KEDA-based scaling. Defaults to true — an application with a Deployment receives a CPU-based HPA (minReplicas 2 / maxReplicas 10 unless overridden, 80% CPU target) even when this field is unset; set false to opt out. Exception: a Deployment mounting a ReadWriteOnce PersistentVolumeClaim must run as a singleton, so no HPA is created regardless of this field. Explicitly requesting horizontal scaling (enabled: true, minReplicas/maxReplicas > 1, or triggers) together with an RWO PVC is rejected at admission rather than silently ignored.

false
maxReplicasinteger

Maximum number of pod replicas the autoscaler can create. Defaults to 10 if not specified. Must be >= 1.


Format: int32
Minimum: 1

false
memoryThresholdPercentageinteger

RESERVED: Memory utilization threshold percentage for scaling. Not currently implemented; use KEDA triggers for memory-based scaling instead. Valid range: 1-100%.


Format: int32
Minimum: 1
Maximum: 100

false
minReplicasinteger

Minimum number of pod replicas to maintain. Defaults to 2 if not specified. Must be >= 0.


Format: int32
Minimum: 0

false
triggers[]object

KEDA scaling triggers for custom metrics (e.g., cron-based scaling). See https://keda.sh/docs/2.13/scalers/cron/ for supported trigger types and configuration.

false

spec.autoscaling.triggers[index]​

↩ Parent
NameTypeDescriptionRequired
metadatamap[string]string
true
typestring
true

spec.deployment​

↩ Parent

Kubernetes deployment configuration including container image, ports, readiness probes, and resource requests/limits.

NameTypeDescriptionRequired
imagestring

Container image URI (including registry). Typically set to use a mutable tag like "latest" and CI/CD systems override this with specific version tags for deployments.

true
args[]string

Arguments to pass to the container entrypoint (maps to Kubernetes container args).

false
fsGroupinteger

Optional fsGroup for the pod's security context. If set, the pod's containers will run with a group ID that owns the mounted volumes. This is useful for shared storage scenarios where the application needs write access to the volume. If omitted, no fsGroup is set and Kubernetes default behavior applies.


Format: int64
Minimum: 0

false
kindenum

Workload kind: Deployment (default) or StatefulSet. Immutable after creation. Switching kinds requires deleting and recreating the PlatformApplication. Existing manifests without this field continue to be treated as Deployment.


Enum: Deployment, StatefulSet
Default: Deployment

false
podManagementPolicystring

Pod-management policy for the StatefulSet. Must be one of OrderedReady (default) or Parallel. StatefulSet-only — rejected when kind: Deployment. The string value is validated by a CEL rule on the CRD; typos are caught at admission.

false
ports[]object

List of ports exposed by the container. Each port requires a port number and protocol type (TCP, UDP, HTTP, or HTTPS).

false
readOnlyRootFilesystemboolean

Whether the container's root filesystem should be mounted as read-only. Improves security by preventing filesystem modifications. Temporary storage (/tmp, /var/tmp) will still be writable.

false
readinessProbeobject

Optional HTTP endpoint for Kubernetes readiness probes. When set, the container must return HTTP 200 on the specified path for the pod to be considered ready. When omitted, no readiness probe is injected and pods are considered ready immediately. Required when ingress is enabled (used for ALB health checks).

false
livenessProbeobject

Optional HTTP endpoint for Kubernetes liveness probes. When set, the container is restarted if it fails to return HTTP 200 on the specified path — independent of readiness, which only gates traffic. When omitted, no liveness probe is injected (no regression for existing manifests). Unlike readinessProbe, all probe timing fields (initialDelaySeconds, periodSeconds, timeoutSeconds) must be set explicitly — there is no default.

false
resourcesobject

Kubernetes resource requests and limits (CPU, memory, and GPUs). Requests are guaranteed resources; limits prevent the container from exceeding those amounts.

false
volumeClaimTemplates[]object

Per-pod PersistentVolumeClaim templates. StatefulSet-only — rejected by the API server when kind: Deployment. Each template provisions a PVC per pod, mounted at the given path. Backed by the cluster's default StorageClass unless storageClassName is set. Pod-N gets <template-name>-<app>-N and keeps it across rescheduling.

false
volumeMounts[]object

the volume source and the mount point inside the container. Capped at 32 entries — the cap exists so the spec-level CEL rule on autoscaling-vs-RWO-PVC fits within Kubernetes' static cost budget for x-kubernetes-validations.

false

spec.deployment.ports[index]​

↩ Parent
NameTypeDescriptionRequired
portinteger

Port number on the container (1-65535)


Format: int32
Minimum: 1
Maximum: 65535

true
protocolstring

Protocol for the port, examples: TCP, UDP, HTTP, HTTPS

true
namestring

Optional name for this port (e.g. "http", "grpc", "metrics"). Must conform to Kubernetes IANA_SVC_NAME: lowercase alphanumeric and hyphens, starting with a letter, max 15 characters.

false

spec.deployment.readinessProbe​

↩ Parent

Optional HTTP endpoint for Kubernetes readiness probes. When set, the container must return HTTP 200 on the specified path for the pod to be considered ready. When omitted, no readiness probe is injected and pods are considered ready immediately. Required when ingress is enabled (used for ALB health checks).

NameTypeDescriptionRequired
pathstring

HTTP path for the readiness check (e.g., "/health" or "/status"). The call must respond with HTTP 200 to be considered ready.

true
portinteger

Port number on the container to check for readiness (1-65535; must match one of the declared ports)


Format: int32
Minimum: 1
Maximum: 65535

true

spec.deployment.livenessProbe​

↩ Parent

Optional HTTP endpoint for Kubernetes liveness probes. When set, the container is restarted if it fails to return HTTP 200 on the specified path — independent of readiness, which only gates traffic. When omitted, no liveness probe is injected (no regression for existing manifests). Unlike readinessProbe, all probe timing fields (initialDelaySeconds, periodSeconds, timeoutSeconds) must be set explicitly — there is no default.

NameTypeDescriptionRequired
initialDelaySecondsinteger

Seconds after container start before the first liveness check runs. Must be set explicitly — there is no default.


Format: int32
Minimum: 1

true
pathstring

HTTP path for the liveness check (e.g., "/health" or "/status"). The call must respond with HTTP 200 to be considered alive.

true
periodSecondsinteger

Seconds between liveness checks. Must be set explicitly — there is no default.


Format: int32
Minimum: 1

true
portinteger

Port number on the container to check for liveness (1-65535; must match one of the declared ports)


Format: int32
Minimum: 1
Maximum: 65535

true
timeoutSecondsinteger

Seconds before a liveness check is considered failed. Must be set explicitly — there is no default.


Format: int32
Minimum: 1

true

spec.deployment.resources​

↩ Parent

Kubernetes resource requests and limits (CPU, memory, and GPUs). Requests are guaranteed resources; limits prevent the container from exceeding those amounts.

NameTypeDescriptionRequired
limitsobject

Maximum resource allocation for the container. Kubernetes will kill the container if it exceeds these limits. Requires requests to be set. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/

false
requestsobject

Guaranteed resource allocation reserved for the container on the node. The scheduler uses this to determine pod placement. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/

false

spec.deployment.resources.limits​

↩ Parent

Maximum resource allocation for the container. Kubernetes will kill the container if it exceeds these limits. Requires requests to be set. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/

NameTypeDescriptionRequired
cpustring

CPU resources in Kubernetes format (e.g., "500m" for 500 millicores, "1" for 1 core). See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu

false
gpustring

GPU resources (e.g., "1" for 1 GPU). GPU node availability depends on your cluster configuration.

false
memorystring

Memory resources in Kubernetes format (e.g., "128Mi" for 128 mebibytes, "1Gi" for 1 gibibyte). See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory

false

spec.deployment.resources.requests​

↩ Parent

Guaranteed resource allocation reserved for the container on the node. The scheduler uses this to determine pod placement. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/

NameTypeDescriptionRequired
cpustring

CPU resources in Kubernetes format (e.g., "500m" for 500 millicores, "1" for 1 core). See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu

false
gpustring

GPU resources (e.g., "1" for 1 GPU). GPU node availability depends on your cluster configuration.

false
memorystring

Memory resources in Kubernetes format (e.g., "128Mi" for 128 mebibytes, "1Gi" for 1 gibibyte). See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory

false

spec.deployment.volumeClaimTemplates[index]​

↩ Parent
NameTypeDescriptionRequired
mountPathstring

Path inside the container where the volume will be mounted.

true
namestring

Template name. Becomes the PVC name prefix (<name>-<app>-<ordinal>) and the volume name mounted into the container.

true
sizestring

Requested storage size (e.g., "10Gi"). Required.

true
accessModes[]string

Access modes for each PVC. Defaults to ["ReadWriteOnce"]. Per-pod PVCs are almost always RWO; if you need shared storage across pods, use a single shared PVC via volumeMounts[*].source.size with accessModes: [ReadWriteMany] instead.

false
storageClassNamestring

StorageClass to provision each PVC from. Defaults to the cluster's default StorageClass when omitted (e.g., gp3 on AWS).

false

spec.deployment.volumeMounts[index]​

↩ Parent
NameTypeDescriptionRequired
mountPathstring

Path inside the container where the volume will be mounted.

true
namestring

Name used to correlate the volume with the mount point.

true
readOnlyboolean

Whether to mount the volume as read-only. Defaults to true for ConfigMap/Secret sources and to false for PVC / emptyDir sources.

false
sourceobject

Optional volume source. When omitted, the volume is an ephemeral emptyDir (scratch space that lives as long as the pod). Otherwise at most one of the source fields (size, claimName, configMap, secret) must be set — see [PlatformApplicationVolumeSource].


Validations:

  • (has(self.size) ? 1 : 0) + (has(self.claimName) ? 1 : 0) + (has(self.configMap) ? 1 : 0) + (has(self.secret) ? 1 : 0) <= 1: at most one of size, claimName, configMap, secret may be set on a volume source; omit all for an emptyDir

false

spec.deployment.volumeMounts[index].source​

↩ Parent

Optional volume source. When omitted, the volume is an ephemeral emptyDir (scratch space that lives as long as the pod). Otherwise at most one of the source fields (size, claimName, configMap, secret) must be set — see [PlatformApplicationVolumeSource].

NameTypeDescriptionRequired
accessModes[]string

Provision mode: access modes for the PVC. Defaults to ["ReadWriteOnce"]. Note: ReadWriteOnce + a Deployment with replicas > 1 will deadlock.

Spec vs. bound-PVC discrepancy: the operator's singleton-mode override and the admission-time CEL rule both read accessModes from this spec field, not from the actual bound PVC. PVC accessModes is immutable after binding, so changing the value here on an existing app will lift the singleton override at the operator level — but the underlying volume is still RWO and a second pod will still deadlock on attach. To genuinely change accessModes, delete the PVC and recreate the app.

Ignored when size is not set.

Capped at 4 entries — Kubernetes only defines 4 access modes (RWO, ROX, RWX, RWOP) and the cap is required to keep the spec-level CEL rule within Kubernetes' static cost budget for x-kubernetes-validations.

false
claimNamestring

Reference mode: name of a pre-existing PersistentVolumeClaim in the same namespace. Mutually exclusive with size / configMap / secret.

false
configMapobject

Mount a ConfigMap as files. Mutually exclusive with the other source fields.

false
secretobject

Mount a Secret as files. Mutually exclusive with the other source fields.

false
sizestring

Provision mode: operator creates a PersistentVolumeClaim named <app>-<volumeName> of this size (e.g., "10Gi"). Mutually exclusive with claimName / configMap / secret.

false
storageClassNamestring

Provision mode: StorageClass to provision the PVC from. Defaults to the cluster's default StorageClass. Ignored when size is not set.

false

spec.deployment.volumeMounts[index].source.configMap​

↩ Parent

Mount a ConfigMap as files. Mutually exclusive with the other source fields.

NameTypeDescriptionRequired
namestring

Name of the ConfigMap to mount.

true
items[]object

Optional list of specific keys to mount as specific file paths. If omitted, all keys are mounted.

false

spec.deployment.volumeMounts[index].source.configMap.items[index]​

↩ Parent
NameTypeDescriptionRequired
keystring

The key in the ConfigMap or Secret.

true
pathstring

The relative file path to mount the key as.

true

spec.deployment.volumeMounts[index].source.secret​

↩ Parent

Mount a Secret as files. Mutually exclusive with the other source fields.

NameTypeDescriptionRequired
namestring

Name of the Secret to mount.

true
items[]object

Optional list of specific keys to mount as specific file paths. If omitted, all keys are mounted.

false

spec.deployment.volumeMounts[index].source.secret.items[index]​

↩ Parent
NameTypeDescriptionRequired
keystring

The key in the ConfigMap or Secret.

true
pathstring

The relative file path to mount the key as.

true

spec.networking​

↩ Parent

Networking configuration including ingress, inbound/outbound traffic policies, and CDN settings.

NameTypeDescriptionRequired
inboundobject

Inbound access policy: list of services allowed to access this application. Used to generate Istio/network policies. If not specified, all traffic is allowed.

false
ingressobject

Ingress configuration for exposing the application to external traffic (internet or internal networks)

false
outboundobject

Outbound access policy: list of services and external hosts this application is allowed to access. Used to generate Istio/network policies. If not specified, all traffic is allowed.

false

spec.networking.inbound​

↩ Parent

Inbound access policy: list of services allowed to access this application. Used to generate Istio/network policies. If not specified, all traffic is allowed.

NameTypeDescriptionRequired
services[]object

List of services allowed to access this application. Generates Istio/network policies to enforce access. If not specified, all inbound traffic to the service is allowed.

false

spec.networking.inbound.services[index]​

↩ Parent
NameTypeDescriptionRequired
namestring

Kubernetes service name allowed to access this application

true
namespacestring

Kubernetes namespace of the source service. Should be explicitly specified; if omitted, will use the service name as namespace as well.

false
portinteger

Port on this application to allow the service to access (1-65535). If not specified, all ports are allowed.


Format: int32
Minimum: 1
Maximum: 65535

false

spec.networking.ingress​

↩ Parent

Ingress configuration for exposing the application to external traffic (internet or internal networks)

NameTypeDescriptionRequired
annotationsmap[string]string

Additional AWS ALB (Application Load Balancer) annotations for the Kubernetes Ingress resource. Only applied when using AWS cloud provider with Kubernetes ingress type (not Istio/Gateway API). See: https://kubernetes-sigs.github.io/aws-load-balancer-controller/v2.2/guide/ingress/annotations/

false
authenticationenum

RESERVED: Authentication requirement for standard methods (Required or Anonymous). Not currently implemented. Use jwt_authentication: true for JWT-based authentication. When neither field is specified, the ingress allows anonymous access.


Enum: Required, Anonymous

false
cdnobject

DEPRECATED and IGNORED: the operator-managed CDN feature has been removed. This field is still accepted so existing manifests continue to apply, but it has no effect and no CDN is provisioned. Any hostname previously served through the CDN must be declared in networking.ingress.hostnames instead, or it will stop being served. The operator sets a CdnIgnored status condition while this block is present.

false
certificateobject

Certificate configuration for custom gateway (TLS/SSL). Required when using a custom domain or custom gateway.

false
enabledboolean

Whether to expose the application externally via an ingress/load balancer. When disabled, the application is only accessible within the cluster.

false
gatewaystring

Specific Istio gateway to use for this ingress, or omit to use the cluster default gateway. Used to route through custom gateways.

false
hostnamePrefixstring

Prefix to prepend to the auto-generated default hostname (e.g., "staging" + "myapp" = "staging-myapp.platform.domain"). Ignored if custom hostnames are specified.

false
hostnames[]string

List of fully qualified domain names (FQDNs) to register for this application (e.g., ["app.example.com", "app-alt.example.com"]). Requires DNS records to be created externally.

false
internalboolean

Whether the application should only be internally accessible via the ingress (only applies with custom gateway). When true, no external IP is assigned.

false
jwtAuthenticationboolean

Enable JWT token authentication. Requests must include valid JWT tokens in the Authorization header.

false
oidcboolean

Enable OpenID Connect (OIDC) authentication. Requests must provide valid OIDC credentials to access the application.

false
originRequestRestrictionobject

Restrictions on origin requests. HTTP requests to the origin will return a 404 unless they match the specified headers. Used to prevent direct backend access.

false
pathstring

Path prefix to forward to the backend (e.g., "/api" will route "/api/*" to the application). Used for routing to specific endpoints.

false
pathRewritestring

Path to rewrite requests to before sending to the backend (e.g., "/api" -> "/" will strip the prefix). Used for path manipulation.

false
tldstring

Custom top-level domain (TLD) for this application instead of the cluster default (e.g., "mycompany.com"). Only applies when using custom gateway.

false
typeenum

Ingress implementation type: "istio" (Istio VirtualService/Gateway) or "kubernetes" (standard Kubernetes Ingress). Defaults based on cluster configuration.


Enum: istio, kubernetes

false
visibilityenum

Load balancer visibility: PublicIP (internet-routable) or PrivateIP (internal only). Defaults based on cluster configuration.


Enum: PublicIP, PrivateIP

false

spec.networking.ingress.cdn​

↩ Parent

DEPRECATED and IGNORED: the operator-managed CDN feature has been removed. This field is still accepted so existing manifests continue to apply, but it has no effect and no CDN is provisioned. Any hostname previously served through the CDN must be declared in networking.ingress.hostnames instead, or it will stop being served. The operator sets a CdnIgnored status condition while this block is present.

NameTypeDescriptionRequired
domains[]string

DEPRECATED and IGNORED: the CDN feature was removed and this field has no effect.

false
enabledboolean

DEPRECATED and IGNORED: had no effect once set; the CDN feature was removed.

false
requiredboolean

DEPRECATED and IGNORED: had no effect once set; the CDN feature was removed.

false
wafIdstring

DEPRECATED and IGNORED: the CDN feature was removed and this field has no effect.

false
zoneIdstring

DEPRECATED and IGNORED: the CDN feature was removed and this field has no effect.

false

spec.networking.ingress.certificate​

↩ Parent

Certificate configuration for custom gateway (TLS/SSL). Required when using a custom domain or custom gateway.

NameTypeDescriptionRequired
externalSecretobject

Fetch certificate from cloud provider secret store (AWS Secrets Manager, Azure Key Vault) via ExternalSecrets operator

false
secretRefobject

Reference to an existing Kubernetes secret containing the TLS certificate and private key

false

spec.networking.ingress.certificate.externalSecret​

↩ Parent

Fetch certificate from cloud provider secret store (AWS Secrets Manager, Azure Key Vault) via ExternalSecrets operator

NameTypeDescriptionRequired
formatenum

Format of the certificate: 'pkcs12' (binary format) or 'pem' (text format). Determines how the certificate is extracted and converted.


Enum: pkcs12, pem

true
secretNamestring

Name of the secret in the cloud provider (AWS Secrets Manager, Azure Key Vault, etc.)

true
secretStorestring

Name of an existing ExternalSecrets SecretStore resource in the cluster that knows how to authenticate with your cloud provider

true

spec.networking.ingress.certificate.secretRef​

↩ Parent

Reference to an existing Kubernetes secret containing the TLS certificate and private key

NameTypeDescriptionRequired
namestring

Name of the Kubernetes secret containing the TLS certificate and key (usually in tls.crt and tls.key keys)

true
namespacestring

Namespace where the secret is located. Defaults to the application's namespace if not specified.

false

spec.networking.ingress.originRequestRestriction​

↩ Parent

Restrictions on origin requests. HTTP requests to the origin will return a 404 unless they match the specified headers. Used to prevent direct backend access.

NameTypeDescriptionRequired
headers[]object

HTTP headers that must be present and match for the request to reach the origin. Requests without matching headers receive HTTP 404. Useful for protecting the origin from direct access.

false

spec.networking.ingress.originRequestRestriction.headers[index]​

↩ Parent
NameTypeDescriptionRequired
namestring

HTTP header name to match (e.g., "Authorization", "X-Custom-Header")

true
valuestring

Expected header value (exact string or regex pattern depending on type)

true
typeenum

Match type: "Exact" for exact string match or "Regex" for regular expression pattern matching. Default: Exact


Enum: Exact, Regex
Default: Exact

false

spec.networking.outbound​

↩ Parent

Outbound access policy: list of services and external hosts this application is allowed to access. Used to generate Istio/network policies. If not specified, all traffic is allowed.

NameTypeDescriptionRequired
external[]object

List of external services (outside the cluster) this application is allowed to access by hostname and port. Generates ServiceEntry and network policies.

false
services[]object

List of in-cluster services this application is allowed to access. Generates Istio/network policies to enforce access. If not specified, all outbound traffic is allowed.

false

spec.networking.outbound.external[index]​

↩ Parent
NameTypeDescriptionRequired
hoststring

Hostname or FQDN of the external service this application can access (e.g., "api.example.com", "database.provider.com")

true
portinteger

Port number on the external service to allow access to (1-65535)


Format: int32
Minimum: 1
Maximum: 65535

true
protocolenum

Protocol of the external service connection (HTTP, HTTPS, gRPC, TCP, TLS, etc.). Affects how the connection is handled by the service mesh.


Enum: HTTP, HTTPS, GRPC, HTTP2, MONGO, TCP, TLS

false

spec.networking.outbound.services[index]​

↩ Parent
NameTypeDescriptionRequired
namestring

Kubernetes service name this application is allowed to access

true
namespacestring

Kubernetes namespace of the destination service. If not specified, assumes the same namespace as this application.

false
portinteger

Port on the destination service to allow access to (1-65535). If not specified, all ports are allowed.


Format: int32
Minimum: 1
Maximum: 65535

false

spec.resourceRequirements[index]​

↩ Parent

An infrastructure dependency declared inline on a PlatformApplication's spec.resourceRequirements. Each entry is realized by the operator as a [ResourceGrant] (platform.p6m.dev/v1alpha1) in the application namespace, owned by the application. (PlatformTask support is planned but not yet wired.)

The platform-resource-operator (PRO) matches the Grant to a ResourceCapability, provisions the backing ResourceRequirement, and surfaces a connection Secret in this namespace. The operator then injects the connection tokens into the container as environment variables (default convention: {RESOURCE_NAME}_{TOKEN}).

NameTypeDescriptionRequired
resourceNamestring

The application's logical handle for this resource. Drives the connection secret name on the resource side and, by default, the environment-variable prefix ({RESOURCE_NAME}_{TOKEN}) injected into the container.

true
resourceTypestring

Technology-specific resource type the application is written against (e.g. "postgresql", "redis", "kafka-topic"). Must match the resourceType of a ResourceCapability installed in the cluster.

true
accessstring

Per-grant access mode for shared resources (e.g. "produce", "consume", "admin" for topic types). Composition-specific; treated as opaque by the framework.

false
envPrefixstring

Override the environment-variable name prefix for this resource's connection tokens. Defaults to the upper-snake-cased resourceName. Tokens inject as {prefix}_{TOKEN} via secretKeyRef.

false
parametersmap[string]string

Per-grant parameters forwarded onto the ResourceGrant. Keys must be in the matched capability's grantParameters list.

false
providerstring

Target a specific provider (ResourceCapability) by name. If omitted, PRO selects the capability marked isDefault: true for this resourceType.

false
scopeenum

Whether the application wants a private resource or to participate in a shared one. If omitted, PRO uses the matched capability's sharingPolicy.default. Must be permitted by that capability's sharingPolicy.allowed.


Enum: Private, Shared

false

spec.resources[key][index]​

↩ Parent
NameTypeDescriptionRequired
namestring

Name of the cloud resource to grant access to. Must match an existing resource provisioned in your cloud environment.

true
accesses[]string

List of access permissions to grant on this resource. Available access types depend on the specific Crossplane composition. Common examples include "read", "write", "admin". Leave empty for default access level defined by the composition.

false

spec.rollouts​

↩ Parent

ArgoCD Rollouts configuration for advanced deployment strategies. Not currently implemented.

NameTypeDescriptionRequired
enabledboolean

Enable ArgoCD Rollouts for advanced deployment strategies (canary, blue-green). Not currently implemented.

false
strategyenum

Rollout strategy: Canary or BlueGreen. Not currently implemented.


Enum: canary, blueGreen

false

spec.secrets[index]​

↩ Parent
NameTypeDescriptionRequired
namestring

Name of the secret in the cloud secret store (e.g., AWS Secrets Manager, Azure Key Vault). The secret must be stored as key-value pairs and will be injected into the pod as environment variables (keys become variable names).

true
admins[]string

Optional list of user identifiers (e.g., email addresses) who can administer/rotate this secret in the cloud secret store.

false

spec.workloadSelectors​

↩ Parent

Node selectors to restrict where the application can be deployed. Defaults to supporting both amd64 and arm64 architectures on any available instance type. If not specified, the application will be scheduled on any available compatible node. Use instanceTypes to further restrict scheduling to specific hardware SKUs (e.g. for performance-sensitive workloads that benefit from particular CPU features).

NameTypeDescriptionRequired
instanceTypes[]string

Optional list of node instance types to restrict scheduling to. When set, the pod will only be scheduled on nodes whose node.kubernetes.io/instance-type label matches one of the listed values (ANDed with the architecture constraint). Useful for targeting specific hardware SKUs, e.g. ["Standard_D4ps_v6"] to pin to Azure Cobalt 100 nodes for maximum ARM64 performance.

false
kubernetes.io/architecturesstring

Comma-separated list of CPU architectures this application can run on. Defaults to "amd64,arm64" (both Intel/AMD and ARM64 architectures). This value is matched against the kubernetes.io/arch node label during pod scheduling.


Default: amd64,arm64

false

status​

NameTypeDescriptionRequired
cdnmap[string]object
false
cloudobject
false
conditions[]object
false
lastReconcileTimestring

RFC3339 timestamp of the last reconcile attempt.


Format: date-time

false
managedResources[]object
false
phaseenum

Enum: pending, progressing, ready, failed

false
runStudioCdnobject
false

status.cdn[key]​

↩ Parent
NameTypeDescriptionRequired
distributionIdstring
false
dnsConfigurationobject
false

status.cdn[key].dnsConfiguration​

↩ Parent
NameTypeDescriptionRequired
domains[]string
false

status.cloud​

↩ Parent
NameTypeDescriptionRequired
keyVaultNamestring

The name of the provisioned Azure Key Vault resource.

false
principalIdstring

The Azure Workload Identity object (principal) ID assigned to the application.

false
rolestring

The AWS IAM role ARN assigned to the application via IRSA (IAM Roles for Service Accounts).

false

status.conditions[index]​

↩ Parent
NameTypeDescriptionRequired
statusstring
true
typestring
true
lastTransitionTimestring
false
messagestring
false
reasonstring
false

status.managedResources[index]​

↩ Parent

ObjectReference contains enough information to let you inspect or modify the referred object.

NameTypeDescriptionRequired
apiVersionstring

API version of the referent.

false
fieldPathstring

If referring to a piece of an object instead of an entire object, this string should contain a valid JSON/Go field access statement, such as desiredState.manifest.containers[2]. For example, if the object reference is to a container within a pod, this would take on a value like: "spec.containers{name}" (where "name" refers to the name of the container that triggered the event) or if no container name is specified "spec.containers[2]" (container with index 2 in this pod). This syntax is chosen only to have some well-defined way of referencing a part of an object.

false
kindstring

Kind of the referent. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds

false
messagestring
false
namestring

Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names

false
namespacestring

Namespace of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/

false
phaseenum

Enum: pending, progressing, ready, failed

false
resourceVersionstring

Specific resourceVersion to which this reference is made, if any. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency

false
uidstring

UID of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#uids

false

status.runStudioCdn​

↩ Parent
NameTypeDescriptionRequired
configMapstring
false
invalidations[]object
false

status.runStudioCdn.invalidations[index]​

↩ Parent
NameTypeDescriptionRequired
observedGenerationinteger

Format: int64

false
timestampstring
false

Auto-injected environment variables​

Database URLs​

CRDB URL​

When you declare a CockroachDB resource under spec.resources.crdb, the operator automatically injects a PostgreSQL connection URL into your container as an additional environment variable. You do not need to construct it yourself in spec.config.

This variable is additive: it is provided alongside the existing CockroachDB environment variables for the same resource (for example, the individually injected endpoint, port, username, and password variables). It does not replace or deprecate those variables.

Env var name: CRDB_{NAME}_URL, where {NAME} is the resource's name converted to UPPER_SNAKE_CASE (e.g., organization-service becomes ORGANIZATION_SERVICE).

Value: postgresql://{username}:{password}@{endpoint}:{port}/{name_snake}_db?sslmode=require, derived from the same injected connection details.

Example​
spec:
resources:
crdb:
- name: organization-service

Your container will see:

CRDB_ORGANIZATION_SERVICE_URL=postgresql://<user>:<pass>@<host>:<port>/organization_service_db?sslmode=require

The database name is derived as {name_snake}_db and sslmode=require is always set.