GroupIdentityProviderMapper
identityprovider.keycloak.crossplane.io / v1alpha1
apiVersion: identityprovider.keycloak.crossplane.io/v1alpha1
kind: GroupIdentityProviderMapper
metadata:
name: example
apiVersion
string
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind
string
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata
object
spec object required
GroupIdentityProviderMapperSpec defines the desired state of GroupIdentityProviderMapper
deletionPolicy
string
DeletionPolicy specifies what will happen to the underlying external
when this managed resource is deleted - either "Delete" or "Orphan" the
external resource.
This field is planned to be deprecated in favor of the ManagementPolicies
field in a future release. Currently, both could be set independently and
non-default values would be honored if the feature flag is enabled.
See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223
enum:
Orphan, DeleteforProvider object required
extraConfig
object
A map of key/value pairs to add extra configuration attributes to this mapper. Use this attribute at your own risk, as it may conflict with top-level configuration attributes in future provider updates.
facebookIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
facebookIdentityProviderAliasRef object
Reference to a FacebookIdentityProvider in oidc to populate facebookIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentfacebookIdentityProviderAliasSelector object
Selector for a FacebookIdentityProvider in oidc to populate facebookIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
githubIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
githubIdentityProviderAliasRef object
Reference to a GithubIdentityProvider in oidc to populate githubIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentgithubIdentityProviderAliasSelector object
Selector for a GithubIdentityProvider in oidc to populate githubIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
googleIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
googleIdentityProviderAliasRef object
Reference to a GoogleIdentityProvider in oidc to populate googleIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentgoogleIdentityProviderAliasSelector object
Selector for a GoogleIdentityProvider in oidc to populate googleIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
group
string
The name of the group which should be assigned to the users.
Group Name
identityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
identityProviderAliasRef object
Reference to a IdentityProvider in oidc to populate identityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentidentityProviderAliasSelector object
Selector for a IdentityProvider in oidc to populate identityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
kubernetesIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
kubernetesIdentityProviderAliasRef object
Reference to a KubernetesIdentityProvider in identityprovider to populate kubernetesIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentkubernetesIdentityProviderAliasSelector object
Selector for a KubernetesIdentityProvider in identityprovider to populate kubernetesIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
microsoftIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
microsoftIdentityProviderAliasRef object
Reference to a MicrosoftIdentityProvider in oidc to populate microsoftIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentmicrosoftIdentityProviderAliasSelector object
Selector for a MicrosoftIdentityProvider in oidc to populate microsoftIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
name
string
Display name of this mapper when displayed in the console.
IDP Mapper Name
openshiftV4IdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
openshiftV4IdentityProviderAliasRef object
Reference to a OidcOpenShiftV4IdentityProvider in identityprovider to populate openshiftV4IdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentopenshiftV4IdentityProviderAliasSelector object
Selector for a OidcOpenShiftV4IdentityProvider in identityprovider to populate openshiftV4IdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
realm
string
The realm ID that this mapper will exist in.
Realm Name
realmRef object
Reference to a Realm in realm to populate realm.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentrealmSelector object
Selector for a Realm in realm to populate realm.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
samlIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
samlIdentityProviderAliasRef object
Reference to a IdentityProvider in saml to populate samlIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentsamlIdentityProviderAliasSelector object
Selector for a IdentityProvider in saml to populate samlIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
spiffeIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
spiffeIdentityProviderAliasRef object
Reference to a SpiffeIdentityProvider in identityprovider to populate spiffeIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentspiffeIdentityProviderAliasSelector object
Selector for a SpiffeIdentityProvider in identityprovider to populate spiffeIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentinitProvider object
THIS IS A BETA FIELD. It will be honored
unless the Management Policies feature flag is disabled.
InitProvider holds the same fields as ForProvider, with the exception
of Identifier and other resource reference fields. The fields that are
in InitProvider are merged into ForProvider when the resource is created.
The same fields are also added to the terraform ignore_changes hook, to
avoid updating them after creation. This is useful for fields that are
required on creation, but we do not desire to update them after creation,
for example because of an external controller is managing them, like an
autoscaler.
extraConfig
object
A map of key/value pairs to add extra configuration attributes to this mapper. Use this attribute at your own risk, as it may conflict with top-level configuration attributes in future provider updates.
facebookIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
facebookIdentityProviderAliasRef object
Reference to a FacebookIdentityProvider in oidc to populate facebookIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentfacebookIdentityProviderAliasSelector object
Selector for a FacebookIdentityProvider in oidc to populate facebookIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
githubIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
githubIdentityProviderAliasRef object
Reference to a GithubIdentityProvider in oidc to populate githubIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentgithubIdentityProviderAliasSelector object
Selector for a GithubIdentityProvider in oidc to populate githubIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
googleIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
googleIdentityProviderAliasRef object
Reference to a GoogleIdentityProvider in oidc to populate googleIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentgoogleIdentityProviderAliasSelector object
Selector for a GoogleIdentityProvider in oidc to populate googleIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
group
string
The name of the group which should be assigned to the users.
Group Name
identityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
identityProviderAliasRef object
Reference to a IdentityProvider in oidc to populate identityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentidentityProviderAliasSelector object
Selector for a IdentityProvider in oidc to populate identityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
kubernetesIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
kubernetesIdentityProviderAliasRef object
Reference to a KubernetesIdentityProvider in identityprovider to populate kubernetesIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentkubernetesIdentityProviderAliasSelector object
Selector for a KubernetesIdentityProvider in identityprovider to populate kubernetesIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
microsoftIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
microsoftIdentityProviderAliasRef object
Reference to a MicrosoftIdentityProvider in oidc to populate microsoftIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentmicrosoftIdentityProviderAliasSelector object
Selector for a MicrosoftIdentityProvider in oidc to populate microsoftIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
name
string
Display name of this mapper when displayed in the console.
IDP Mapper Name
openshiftV4IdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
openshiftV4IdentityProviderAliasRef object
Reference to a OidcOpenShiftV4IdentityProvider in identityprovider to populate openshiftV4IdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentopenshiftV4IdentityProviderAliasSelector object
Selector for a OidcOpenShiftV4IdentityProvider in identityprovider to populate openshiftV4IdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
realm
string
The realm ID that this mapper will exist in.
Realm Name
realmRef object
Reference to a Realm in realm to populate realm.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentrealmSelector object
Selector for a Realm in realm to populate realm.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
samlIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
samlIdentityProviderAliasRef object
Reference to a IdentityProvider in saml to populate samlIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentsamlIdentityProviderAliasSelector object
Selector for a IdentityProvider in saml to populate samlIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
spiffeIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
spiffeIdentityProviderAliasRef object
Reference to a SpiffeIdentityProvider in identityprovider to populate spiffeIdentityProviderAlias.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentspiffeIdentityProviderAliasSelector object
Selector for a SpiffeIdentityProvider in identityprovider to populate spiffeIdentityProviderAlias.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
managementPolicies
[]string
THIS IS A BETA FIELD. It is on by default but can be opted out
through a Crossplane feature flag.
ManagementPolicies specify the array of actions Crossplane is allowed to
take on the managed and external resources.
This field is planned to replace the DeletionPolicy field in a future
release. Currently, both could be set independently and non-default
values would be honored if the feature flag is enabled. If both are
custom, the DeletionPolicy field will be ignored.
See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223
and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md
providerConfigRef object
ProviderConfigReference specifies how the provider that will be used to
create, observe, update, and delete this managed resource should be
configured.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentwriteConnectionSecretToRef object
WriteConnectionSecretToReference specifies the namespace and name of a
Secret to which any connection details for this managed resource should
be written. Connection details frequently include the endpoint, username,
and password required to connect to the managed resource.
name
string required
Name of the secret.
namespace
string required
Namespace of the secret.
status object
GroupIdentityProviderMapperStatus defines the observed state of GroupIdentityProviderMapper.
atProvider object
extraConfig
object
A map of key/value pairs to add extra configuration attributes to this mapper. Use this attribute at your own risk, as it may conflict with top-level configuration attributes in future provider updates.
facebookIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
githubIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
googleIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
group
string
The name of the group which should be assigned to the users.
Group Name
id
string
identityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
kubernetesIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
microsoftIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
name
string
Display name of this mapper when displayed in the console.
IDP Mapper Name
openshiftV4IdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
realm
string
The realm ID that this mapper will exist in.
Realm Name
samlIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
spiffeIdentityProviderAlias
string
The IDP alias of the attribute to set.
IDP Alias
conditions []object
Conditions of the resource.
lastTransitionTime
string required
LastTransitionTime is the last time this condition transitioned from one
status to another.
format:
date-time
message
string
A Message containing details about this condition's last transition from
one status to another, if any.
observedGeneration
integer
ObservedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format:
int64
reason
string required
A Reason for this condition's last transition from one status to another.
status
string required
Status of this condition; is it currently True, False, or Unknown?
type
string required
Type of this condition. At most one of each condition type may apply to
a resource at any point in time.
observedGeneration
integer
ObservedGeneration is the latest metadata.generation
which resulted in either a ready state, or stalled due to error
it can not recover from without human intervention.
format:
int64No matches. Try .spec.deletionPolicy for an exact path