diff --git a/pages/api-reference/kubernetes/agent-api-reference.md b/pages/api-reference/kubernetes/agent-api-reference.md
index a3dc9a30..c38721f9 100644
--- a/pages/api-reference/kubernetes/agent-api-reference.md
+++ b/pages/api-reference/kubernetes/agent-api-reference.md
@@ -14,6 +14,7 @@ Package v1alpha1 contains API Schema definitions for the deployments v1alpha1 AP
- [AgentRuntime](#agentruntime)
- [ClusterDrain](#clusterdrain)
- [CustomHealth](#customhealth)
+- [ImageWarmer](#imagewarmer)
- [IngressReplica](#ingressreplica)
- [KubecostExtractor](#kubecostextractor)
- [MetricsAggregate](#metricsaggregate)
@@ -170,8 +171,10 @@ _Appears in:_
| `prompt` _string_ | Prompt is the task/prompt given to the agent | | Required: \{\}
|
| `repository` _string_ | Repository is the git repository the agent will work with | | Required: \{\}
|
| `branch` _string_ | Branch is the repository branch the agent should operate on. If omitted, the repository default branch is used. | | Optional: \{\}
|
-| `mode` _[AgentRunMode](#agentrunmode)_ | Mode defines how the agent should run (ANALYZE, WRITE) | | Required: \{\}
|
+| `mode` _[AgentRunMode](#agentrunmode)_ | Mode defines how the agent should run (ANALYZE, WRITE, REVIEW) | | Required: \{\}
|
+| `reviewDepth` _[AgentReviewDepth](#agentreviewdepth)_ | ReviewDepth controls how far a review run explores code adjacent to the pull request changes. | | Optional: \{\}
|
| `flowId` _string_ | FlowID is the flow this agent run is associated with (optional) | | Optional: \{\}
|
+| `workbenchMcpUrl` _string_ | WorkbenchMCPURL is the Console MCP endpoint for the workbench that
originated this run. It is populated by the AgentRuntime controller. | | Optional: \{\}
|
| `language` _[AgentRunLanguage](#agentrunlanguage)_ | Language is the programming language used in the agent run.
Deprecated: No longer used for image selection. Enable dind on the AgentRuntime instead. | | Optional: \{\}
|
| `languageVersion` _string_ | LanguageVersion is the version of the language to use, if you wish to specify.
Deprecated: No longer used for image selection. Enable dind on the AgentRuntime instead. | | Optional: \{\}
|
@@ -274,15 +277,22 @@ _Appears in:_
| `streamingProxy` _boolean_ | StreamingProxy routes OpenAI-compatible LLM requests through the in-pod mcpserver
sse conversion proxy before they reach the Console AI proxy (/ext/ai). Only valid when aiProxy
is enabled. Applies to CODEX and OPENCODE runtimes. | | Optional: \{\}
|
| `dind` _boolean_ | Dind enables Docker-in-Docker for this agent runtime.
When true, the runtime will be configured to run with DinD support. | | Optional: \{\}
|
| `memory` _boolean_ | Memory enables team-shared codebase-memory persistence for this agent runtime.
When true, agents may create and commit .codebase-memory/ graph artifacts
by default so future runs can bootstrap from the persisted index. When false
or unset, codebase-memory indexes stay in the pod-local cache and generated
.codebase-memory/ artifacts are excluded from commits. | | Optional: \{\}
|
+| `repositoryImage` _string_ | RepositoryImage is an OCI image of precloned git repositories plus manifest.json.
When set, an init container copies it into /plural/shared/repos before bootstrap
so a matching repo can be copied locally instead of git clone. | | Optional: \{\}
|
+| `prewarm` _[RepositoryImagePrewarm](#repositoryimageprewarm)_ | Prewarm periodically pulls RepositoryImage onto selected nodes before
agent runs are scheduled. | | Optional: \{\}
|
| `allowedRepositories` _string array_ | AllowedRepositories the git repositories allowed to be used with this runtime. | | Optional: \{\}
|
| `browser` _[BrowserConfig](#browserconfig)_ | Browser configuration augments agent runtime with a headless browser.
When provided, the runtime will be configured to run with a headless browser available
for the agent to use. | | Optional: \{\}
|
| `bootstrapScript` _string_ | BootstrapScript is a bash script that will be executed inside the cloned repository
directory before the coding agent starts. It can be used to install dependencies,
configure tooling, or perform any other setup required by the agent. | | Optional: \{\}
|
+| `readOnlyRootFilesystem` _boolean_ | ReadOnlyRootFilesystem controls the default container securityContext.
When unset, the root filesystem stays writable (the current default).
Set true when extending a finished image that already contains compilers.
Set false (or leave unset) together with mise.config to run
`mise bootstrap --yes` at boot: https://mise.jdx.dev/bootstrap.html | | Optional: \{\}
|
+| `mise` _[MiseSpec](#misespec)_ | Mise supplies a mise.toml applied before the coding agent starts.
When the default container root is writable, the harness runs
`mise trust` and `mise bootstrap --yes`. When readOnlyRootFilesystem is true,
the config is still mounted so mise exec can use [tools] and [env],
but bootstrap is skipped. | | Optional: \{\}
|
| `git` _[GitSpec](#gitspec)_ | Git configure commit signing on agent run. When provided, the runtime will be configured to sign git commits using the provided key reference. | | |
| `babysitInterval` _[Duration](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#duration-v1-meta)_ | BabysitInterval configures the interval for the operator to check on the health of the agent runtime and perform necessary babysitting actions (e.g. restarting unhealthy runtimes). When not provided, a default interval of 1 minute will be used. | | |
| `agentTTL` _[Duration](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#duration-v1-meta)_ | AgentTTL configures the maximum lifetime for agent run pods on this runtime. When not provided, a default TTL of 12 hours will be used. | | Optional: \{\}
|
| `scmConnection` _string_ | ScmConnection is the name of an ScmConnection in Console to use for git operations on agent runs using this runtime.
This should match the name of an existing ScmConnection resource or connection created in the Plural UI. | | Optional: \{\}
|
| `exaConnection` _[ExaConnection](#exaconnection)_ | ExaConnection enables Exa web search and content retrieval tools on the Plural MCP server. | | |
| `mcpServers` _[MCPServer](#mcpserver) array_ | MCPServers are additional remote MCP servers made available to coding agents
on this runtime. Servers are expected to already be deployed and reachable
at the given URL. Built-in servers named "plural" and "codebase-memory-mcp"
are reserved and cannot be overridden. | | Optional: \{\}
|
+| `workbenchMcp` _[WorkbenchMCPConfig](#workbenchmcpconfig)_ | WorkbenchMCP exposes the originating workbench's read-only tools to coding
agents through the credential-isolating MCP sidecar. | | Optional: \{\}
|
+
+
#### Binding
@@ -776,6 +786,46 @@ _Appears in:_
| `vcluster` _[VClusterHelmConfiguration](#vclusterhelmconfiguration)_ | VCluster allows configuring vcluster specific helm chart options. | | Optional: \{\}
|
+#### ImageWarmer
+
+
+
+ImageWarmer is the Schema for the imagewarmers API.
+
+
+
+
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `apiVersion` _string_ | `deployments.plural.sh/v1alpha1` | | |
+| `kind` _string_ | `ImageWarmer` | | |
+| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | | |
+| `spec` _[ImageWarmerSpec](#imagewarmerspec)_ | | | |
+
+
+#### ImageWarmerSpec
+
+
+
+ImageWarmerSpec defines an image that should periodically be pulled onto
+every selected node.
+
+
+
+_Appears in:_
+- [ImageWarmer](#imagewarmer)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `cron` _string_ | Cron is a standard five-field cron expression controlling how often the
image is refreshed. | | MinLength: 1
Required: \{\}
|
+| `image` _string_ | Image is the OCI image to warm. | | MinLength: 1
Required: \{\}
|
+| `template` _[PodTemplateSpec](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#podtemplatespec-v1-core)_ | Template optionally overrides the secure default warmer pod template. | | Optional: \{\}
|
+| `selector` _[LabelSelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#labelselector-v1-meta)_ | Selector restricts warming to nodes matching this label selector. | | Optional: \{\}
|
+
+
+
+
#### IngressReplica
@@ -908,6 +958,23 @@ MetricsAggregate
+#### MiseSpec
+
+
+
+MiseSpec is an inline mise.toml used for unattended bootstrap.
+See https://mise.jdx.dev/bootstrap.html
+
+
+
+_Appears in:_
+- [AgentRuntimeSpec](#agentruntimespec)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `config` _string_ | Config is the contents of a mise.toml. | | Optional: \{\}
|
+
+
#### OpenCodeConfig
@@ -925,6 +992,7 @@ _Appears in:_
| `provider` _string_ | Provider is the OpenCode provider id from https://models.dev (for example openai, anthropic,
amazon-bedrock, google-vertex, google). Optional.
When the parent AgentRuntime has spec.aiProxy enabled, the harness ignores this field and
autowires provider "plural", routing requests through the Console AI proxy at /ext/ai/v1
using the deploy token. Set spec.config.opencode.model to a bare model id; the harness
prefixes it for proxy routing based on runtime type (for example gpt-5.4 -> openai/gpt-5.4).
When aiProxy is false, this selects the native OpenCode provider block; credentials come from
tokenSecretRef or the provider's usual environment variables. Defaults to plural when omitted.
Use exact models.dev slugs (for example amazon-bedrock, google-vertex, google). | | MaxLength: 128
Optional: \{\}
|
| `endpoint` _string_ | Endpoint optionally overrides the provider baseURL in opencode.json.
When omitted, the harness omits baseURL so OpenCode uses the models.dev default for the provider. | | Optional: \{\}
|
| `model` _string_ | Model is the LLM model to use. | | Optional: \{\}
|
+| `method` _[OpenAiMethod](#openaimethod)_ | Method configures which OpenAI API OpenCode should use.
CHAT selects @ai-sdk/openai-compatible and forces /chat/completions.
RESPONSES selects @ai-sdk/openai and forces /responses.
AUTO preserves the provider default. | | Enum: [CHAT RESPONSES AUTO]
Optional: \{\}
|
| `tokenSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | TokenSecretRef references a Secret containing the API token for OpenCode.
Optional when aiProxy is enabled; authentication uses the Console deploy token instead. | | Optional: \{\}
|
| `extraArgs` _string array_ | ExtraArgs args for advanced or experimental CLI flags.
Deprecated: It is being ignored by the agent harness. | | |
| `timeout` _[Duration](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#duration-v1-meta)_ | Timeout bounds a single opencode run invocation. | | Optional: \{\}
|
@@ -951,6 +1019,7 @@ _Appears in:_
| `provider` _string_ | Provider is the OpenCode provider id from https://models.dev. | | |
| `endpoint` _string_ | Endpoint API endpoint for the OpenCode service. | | |
| `model` _string_ | Model is the LLM model to use. | | |
+| `method` _[OpenAiMethod](#openaimethod)_ | Method configures which OpenAI API OpenCode should use. | | |
| `token` _string_ | Token is the raw API token for OpenCode. | | |
| `timeout` _[Duration](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#duration-v1-meta)_ | Timeout bounds a single opencode run invocation. | | Optional: \{\}
|
@@ -960,8 +1029,8 @@ _Appears in:_
OpenCodeOpenAICompatibleConfig configures a custom OpenAI-compatible API provider in opencode.json.
-The harness writes a provider block with npm @ai-sdk/openai-compatible. Use this for endpoints
-that are not listed on https://models.dev (for example LiteLLM, vLLM, or a private gateway).
+Use this for endpoints that are not listed on https://models.dev (for example LiteLLM, vLLM,
+or a private gateway).
When set and the parent AgentRuntime has spec.aiProxy false, spec.config.opencode.provider and
spec.config.opencode.endpoint are ignored in favor of this block.
@@ -994,6 +1063,7 @@ _Appears in:_
| `apiKeySecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | APIKeySecretRef references an API key. Optional with aiProxy enabled. | | Optional: \{\}
|
| `provider` _string_ | Provider is Pi's provider id. Defaults to openai. | | Optional: \{\}
|
| `model` _string_ | Model is the model id to use. | | Optional: \{\}
|
+| `method` _[OpenAiMethod](#openaimethod)_ | Method configures which OpenAI API Pi should use.
CHAT selects openai-completions and forces /chat/completions.
RESPONSES selects openai-responses and forces /responses.
AUTO preserves the current openai-responses default. | | Enum: [CHAT RESPONSES AUTO]
Optional: \{\}
|
| `endpoint` _string_ | Endpoint overrides the OpenAI-compatible provider base URL. | | Optional: \{\}
|
| `timeout` _[Duration](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#duration-v1-meta)_ | Timeout bounds a single Pi invocation. | | Optional: \{\}
|
@@ -1014,6 +1084,7 @@ _Appears in:_
| `apiKey` _string_ | | | |
| `provider` _string_ | | | |
| `model` _string_ | | | |
+| `method` _[OpenAiMethod](#openaimethod)_ | | | |
| `endpoint` _string_ | | | |
| `timeout` _[Duration](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#duration-v1-meta)_ | | | |
@@ -1130,6 +1201,24 @@ _Appears in:_
| `requireAnnotations` _object (keys:string, values:string)_ | | | |
+#### RepositoryImagePrewarm
+
+
+
+RepositoryImagePrewarm configures periodic repository image warming.
+
+
+
+_Appears in:_
+- [AgentRuntimeSpec](#agentruntimespec)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `cron` _string_ | Cron is a standard five-field cron expression controlling how often the
repository image is refreshed. | | MinLength: 1
Required: \{\}
|
+| `template` _[PodTemplateSpec](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#podtemplatespec-v1-core)_ | Template optionally overrides the secure default warmer pod template. | | Optional: \{\}
|
+| `selector` _[LabelSelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#labelselector-v1-meta)_ | Selector restricts warming to nodes matching this label selector. | | Optional: \{\}
|
+
+
#### SentinelRunJob
@@ -1212,6 +1301,7 @@ _Appears in:_
_Appears in:_
- [AgentRunStatus](#agentrunstatus)
+- [AgentRuntimeStatus](#agentruntimestatus)
- [SentinelRunJobStatus](#sentinelrunjobstatus)
- [StackRunJobStatus](#stackrunjobstatus)
- [VirtualClusterStatus](#virtualclusterstatus)
@@ -1322,3 +1412,50 @@ _Appears in:_
+#### WorkbenchMCPCategory
+
+_Underlying type:_ _string_
+
+WorkbenchMCPCategory is a workbench tool category accepted by the Console MCP endpoint.
+
+_Validation:_
+- Enum: [metrics logs integration ticketing traces error_tracking infrastructure search scm chat function coding verification observability]
+
+_Appears in:_
+- [WorkbenchMCPConfig](#workbenchmcpconfig)
+
+| Field | Description |
+| --- | --- |
+| `metrics` | |
+| `logs` | |
+| `integration` | |
+| `ticketing` | |
+| `traces` | |
+| `error_tracking` | |
+| `infrastructure` | |
+| `search` | |
+| `scm` | |
+| `chat` | |
+| `function` | |
+| `coding` | |
+| `verification` | |
+| `observability` | |
+
+
+#### WorkbenchMCPConfig
+
+
+
+
+
+
+
+_Appears in:_
+- [AgentRuntimeSpec](#agentruntimespec)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `enabled` _boolean_ | Enabled controls whether workbench tools are available to coding agents. | false | |
+| `categories` _[WorkbenchMCPCategory](#workbenchmcpcategory) array_ | Categories limits the exposed workbench tools. When omitted, the default
set is metrics, logs, traces, ticketing, search, scm, and infrastructure. | | Enum: [metrics logs integration ticketing traces error_tracking infrastructure search scm chat function coding verification observability]
Optional: \{\}
|
+
+
diff --git a/pages/api-reference/kubernetes/management-api-reference.md b/pages/api-reference/kubernetes/management-api-reference.md
index b2b9f18f..3bf1d644 100644
--- a/pages/api-reference/kubernetes/management-api-reference.md
+++ b/pages/api-reference/kubernetes/management-api-reference.md
@@ -21,6 +21,7 @@ Package v1alpha1 contains API Schema definitions for the deployments v1alpha1 AP
- [ComplianceReportGenerator](#compliancereportgenerator)
- [CustomCompatibilityMatrix](#customcompatibilitymatrix)
- [CustomStackRun](#customstackrun)
+- [Dashboard](#dashboard)
- [DeploymentSettings](#deploymentsettings)
- [FederatedCredential](#federatedcredential)
- [Flow](#flow)
@@ -32,6 +33,7 @@ Package v1alpha1 contains API Schema definitions for the deployments v1alpha1 AP
- [InfrastructureStack](#infrastructurestack)
- [MCPServer](#mcpserver)
- [ManagedNamespace](#managednamespace)
+- [Monitor](#monitor)
- [NamespaceCredentials](#namespacecredentials)
- [NotificationRouter](#notificationrouter)
- [NotificationSink](#notificationsink)
@@ -372,6 +374,23 @@ _Appears in:_
| `tokenSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | TokenSecretRef is a reference to the local secret holding the token to access
the configured AI provider. | | Required: \{\}
|
+#### BedrockModelSettings
+
+
+
+
+
+
+
+_Appears in:_
+- [BedrockSettings](#bedrocksettings)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `modelId` _string_ | ModelID is the foundation model served by the application inference profile. | | Required: \{\}
|
+| `inferenceProfileArn` _string_ | InferenceProfileARN is the full ARN of the Bedrock application inference profile. | | Required: \{\}
|
+
+
#### BedrockSettings
@@ -388,12 +407,14 @@ _Appears in:_
| `modelId` _string_ | ModelID is the primary AWS Bedrock model or inference profile identifier.
Use a egional inference profile ID with three dot-separated segments (e.g. us.anthropic.claude-3-5-sonnet-20241022-v2:0,
global.anthropic.claude-haiku-4-5-20251001-v1:0). | | Optional: \{\}
|
| `toolModelId` _string_ | ToolModelId is the Bedrock model or inference profile for tool calling. Same ID formats as modelId. | | Optional: \{\}
|
| `embeddingModel` _string_ | EmbeddingModel is the Bedrock model or inference profile for embeddings. Same ID formats as modelId. | | Optional: \{\}
|
+| `endpoint` _[BedrockEndpoint](#bedrockendpoint)_ | Endpoint selects the AWS Bedrock API surface. RUNTIME (the default) uses InvokeModel or
Converse on bedrock-runtime; MANTLE uses the Bedrock Mantle Anthropic/OpenAI-compatible APIs. | RUNTIME | Enum: [RUNTIME MANTLE]
Optional: \{\}
|
| `proxyModels` _string array_ | ProxyModels lists additional Bedrock model or inference profile IDs exposed through the Nexus
OpenAI-compatible proxy beyond modelId, toolModelId, and embeddingModel. Same ID formats as modelId. | | Optional: \{\}
|
| `region` _string_ | Region is the AWS region the model is hosted in | | Required: \{\}
|
| `tokenSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | TokenSecretRef is a reference to the local secret holding the token to access
the configured AI provider. | | Optional: \{\}
|
| `awsAccessKeyId` _string_ | AWS Access Key ID to use for authentication | | Optional: \{\}
|
| `awsSecretAccessKeyRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | AWS Secret Access Key to use for authentication | | Optional: \{\}
|
| `deployments` _object (keys:string, values:string)_ | Deployments is deprecated for most configurations: prefer regional-prefixed inference profile IDs in
modelId, toolModelId, embeddingModel, or proxyModels (Nexus infers Bifrost aliases automatically).
Still needed when clients use a logical model name that must resolve to a different Bedrock identifier,
for application inference profile resource IDs (use the profile resource suffix, not the full ARN),
or other explicit alias overrides. Maps client-facing model ID to inference profile ID. Example:
\{"anthropic.claude-3-5-sonnet-20241022-v2:0": "us.anthropic.claude-3-5-sonnet-20241022-v2:0"\} | | Optional: \{\}
|
+| `modelSettings` _[BedrockModelSettings](#bedrockmodelsettings) array_ | ModelSettings configures per-model Bedrock options, including application inference profiles. | | Optional: \{\}
|
#### Binding
@@ -1436,6 +1457,131 @@ _Appears in:_
| `reconciliation` _[Reconciliation](#reconciliation)_ | Reconciliation settings for this resource.
Controls drift detection and reconciliation intervals. | | Optional: \{\}
|
+#### Dashboard
+
+
+
+Dashboard represents an observability dashboard owned by a Workbench. It consists of graphs
+arranged on a grid, each backed by an observability tool datasource, and optional user-configurable inputs.
+
+
+
+
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `apiVersion` _string_ | `deployments.plural.sh/v1alpha1` | | |
+| `kind` _string_ | `Dashboard` | | |
+| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | | |
+| `spec` _[DashboardSpec](#dashboardspec)_ | Spec defines the desired state of the Dashboard. | | Required: \{\}
|
+
+
+#### DashboardDatasource
+
+
+
+DashboardDatasource defines an observability tool call used to fetch dashboard data.
+
+
+
+_Appears in:_
+- [DashboardGraph](#dashboardgraph)
+- [DashboardInput](#dashboardinput)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `type` _[DashboardDatasourceType](#dashboarddatasourcetype)_ | Type is the kind of data returned by the datasource. | | Enum: [LOGS METRICS TRACES LABELS]
Required: \{\}
|
+| `tool` _string_ | Tool is the name of the observability tool used to fetch the data. | | MinLength: 1
Required: \{\}
Type: string
|
+| `input` _[RawExtension](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#rawextension-runtime-pkg)_ | Input is passed to the observability tool. | | Required: \{\}
|
+
+
+#### DashboardGraph
+
+
+
+DashboardGraph is a single graph placed on the dashboard grid.
+
+
+
+_Appears in:_
+- [DashboardSpec](#dashboardspec)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `identifier` _string_ | Identifier is a stable identifier unique within the dashboard. | | MaxLength: 128
MinLength: 1
Required: \{\}
Type: string
|
+| `title` _string_ | Title is the graph title. | | Optional: \{\}
Type: string
|
+| `description` _string_ | Description is an optional graph description. | | Optional: \{\}
Type: string
|
+| `type` _[DashboardGraphType](#dashboardgraphtype)_ | Type is the graph visualization type. | | Enum: [TIMESERIES GAUGE LOGS MARKDOWN TABLE STAT BAR PIE HEATMAP TRACES SECTION]
MaxLength: 16
Required: \{\}
Type: string
|
+| `sectionId` _string_ | SectionID is the identifier of the SECTION graph containing this graph. Sections cannot be nested. | | MaxLength: 128
Optional: \{\}
Type: string
|
+| `markdown` _string_ | Markdown is the content for MARKDOWN graphs. | | Optional: \{\}
Type: string
|
+| `options` _[RawExtension](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#rawextension-runtime-pkg)_ | Options are visualization-specific display options. Sections may set collapsed. | | Optional: \{\}
|
+| `layout` _[DashboardGraphLayout](#dashboardgraphlayout)_ | Layout is the grid position and size of the graph. | | Required: \{\}
|
+| `datasource` _[DashboardDatasource](#dashboarddatasource)_ | Datasource is the tool call used to fetch external data. | | Optional: \{\}
|
+
+
+#### DashboardGraphLayout
+
+
+
+DashboardGraphLayout defines the grid position and size of a graph.
+
+
+
+_Appears in:_
+- [DashboardGraph](#dashboardgraph)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `x` _integer_ | X is the zero-based horizontal grid coordinate. | | Minimum: 0
Required: \{\}
|
+| `y` _integer_ | Y is the zero-based vertical grid coordinate. | | Minimum: 0
Required: \{\}
|
+| `w` _integer_ | W is the width in grid columns. | | Minimum: 1
Required: \{\}
|
+| `h` _integer_ | H is the height in grid rows. | | Minimum: 1
Required: \{\}
|
+
+
+#### DashboardInput
+
+
+
+DashboardInput is a user-configurable dashboard variable.
+
+
+
+_Appears in:_
+- [DashboardSpec](#dashboardspec)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `name` _string_ | Name is the variable name referenced by graph datasource inputs. | | MinLength: 1
Required: \{\}
Type: string
|
+| `label` _string_ | Label is a human-readable input label. | | Optional: \{\}
Type: string
|
+| `description` _string_ | Description is an optional input description. | | Optional: \{\}
Type: string
|
+| `type` _[DashboardInputType](#dashboardinputtype)_ | Type is the input control type. | | Enum: [TEXT NUMBER BOOLEAN SELECT TIME_RANGE]
Required: \{\}
|
+| `default` _string_ | Default is the default input value. | | Optional: \{\}
Type: string
|
+| `options` _string array_ | Options are the allowed values for select inputs. | | Optional: \{\}
|
+| `required` _boolean_ | Required defines whether a value is required when rendering. | | Optional: \{\}
|
+| `datasource` _[DashboardDatasource](#dashboarddatasource)_ | Datasource is the tool query used to populate input options, such as metric label search. | | Optional: \{\}
|
+
+
+#### DashboardSpec
+
+
+
+DashboardSpec defines the desired state of a Dashboard.
+
+
+
+_Appears in:_
+- [Dashboard](#dashboard)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `workbenchRef` _[LocalObjectReference](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#localobjectreference-v1-core)_ | WorkbenchRef references the Workbench that owns this dashboard.
The Workbench must be in the same namespace as the dashboard.
It is immutable, a dashboard cannot be moved to a different workbench. | | Required: \{\}
|
+| `name` _string_ | Name is the dashboard name, unique within its workbench.
If not set, metadata.name is used. | | Optional: \{\}
Type: string
|
+| `description` _string_ | Description is an optional dashboard description. | | Optional: \{\}
Type: string
|
+| `graphs` _[DashboardGraph](#dashboardgraph) array_ | Graphs arranged on the dashboard grid. Graph identifiers must be unique within the dashboard.
Graphs can be grouped by setting sectionId to the identifier of a SECTION graph.
Note that overlapping graph layouts are only validated by the Console API. | | MaxItems: 200
Optional: \{\}
|
+| `inputs` _[DashboardInput](#dashboardinput) array_ | Inputs are user-configurable dashboard variables. | | Optional: \{\}
|
+| `reconciliation` _[Reconciliation](#reconciliation)_ | Reconciliation settings for this resource. | | Optional: \{\}
|
+
+
#### DeploymentSettings
@@ -2417,6 +2563,7 @@ _Appears in:_
| Field | Description | Default | Validation |
| --- | --- | --- | --- |
| `plural` _boolean_ | Plural enables built-in Plural JWT authentication for this MCP server.
When true, the server will receive a valid Plural JWT token in requests,
allowing it to authenticate and authorize operations within the Plural ecosystem. | | Optional: \{\}
|
+| `oauth` _[OAuth2TokenExchange](#oauth2tokenexchange)_ | OAuth configures client credentials token exchange for requests to this server. | | Optional: \{\}
|
| `headers` _object (keys:string, values:string)_ | Headers specify custom HTTP headers required for authentication with this MCP server.
This allows integration with servers that use API keys, bearer tokens, or other
header-based authentication schemes. Common examples include "Authorization",
"X-API-Key", or custom authentication headers. | | Optional: \{\}
|
@@ -2525,6 +2672,219 @@ _Appears in:_
| `crontab` _string_ | Crontab is the cron expression for how often to export metrics.
Example: "*/5 * * * *" for every 5 minutes. | | Optional: \{\}
|
+#### Monitor
+
+
+
+Monitor represents an observability monitor attached to a service deployment. It periodically
+evaluates a log or metrics query against a threshold and fires alerts when it is crossed.
+Optionally, it can be attached to a workbench to start an investigation when it fires.
+
+
+
+
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `apiVersion` _string_ | `deployments.plural.sh/v1alpha1` | | |
+| `kind` _string_ | `Monitor` | | |
+| `metadata` _[ObjectMeta](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectmeta-v1-meta)_ | Refer to Kubernetes API documentation for fields of `metadata`. | | |
+| `spec` _[MonitorSpec](#monitorspec)_ | Spec defines the desired state of the Monitor. | | Required: \{\}
|
+
+
+#### MonitorFacet
+
+
+
+MonitorFacet is a key/value facet used to further filter log queries.
+
+
+
+_Appears in:_
+- [MonitorLogQuery](#monitorlogquery)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `key` _string_ | Key is the facet key (e.g. kubernetes namespace or pod label name). | | Required: \{\}
Type: string
|
+| `value` _string_ | Value is the facet value to match for the given key. | | Required: \{\}
Type: string
|
+
+
+#### MonitorLogAzureOptions
+
+
+
+MonitorLogAzureOptions are Azure-specific log query options.
+
+
+
+_Appears in:_
+- [MonitorLogOptions](#monitorlogoptions)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `resourceId` _string_ | ResourceID is the Azure resource ID to query logs for. | | Optional: \{\}
Type: string
|
+
+
+#### MonitorLogOptions
+
+
+
+MonitorLogOptions are provider-specific log query options.
+
+
+
+_Appears in:_
+- [MonitorLogQuery](#monitorlogquery)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `azure` _[MonitorLogAzureOptions](#monitorlogazureoptions)_ | Azure log query options. | | Optional: \{\}
|
+
+
+#### MonitorLogQuery
+
+
+
+MonitorLogQuery is the log query configuration for a monitor.
+
+
+
+_Appears in:_
+- [MonitorQuery](#monitorquery)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `tool` _string_ | Tool is the named workbench logs tool. When omitted, the native Plural logs provider is used. | | Optional: \{\}
Type: string
|
+| `query` _string_ | Query is the log query string passed through to the underlying log provider. | | MinLength: 1
Required: \{\}
Type: string
|
+| `bucketSize` _string_ | BucketSize is the time bucket size (e.g. 5m) used when aggregating log results. | | Pattern: `^[0-9]+[dmhs]$`
Required: \{\}
Type: string
|
+| `duration` _string_ | Duration is the lookback duration for the log query (e.g. 1h, 10m, 30s). | | Optional: \{\}
Pattern: `^[0-9]+[dmhs]$`
Type: string
|
+| `operator` _[MonitorOperator](#monitoroperator)_ | Operator to use when combining multiple log queries.
Defaults to OR, which is also the Console API default. | OR | Enum: [OR AND]
Optional: \{\}
|
+| `facets` _[MonitorFacet](#monitorfacet) array_ | Facets are optional key/value facets applied as additional filters on the log query. | | Optional: \{\}
|
+| `options` _[MonitorLogOptions](#monitorlogoptions)_ | Options are provider-specific log query options. | | Optional: \{\}
|
+
+
+#### MonitorMetricsAzureOptions
+
+
+
+MonitorMetricsAzureOptions are Azure-specific metrics query options.
+
+
+
+_Appears in:_
+- [MonitorMetricsOptions](#monitormetricsoptions)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `resourceId` _string_ | ResourceID is the Azure resource ID to query metrics for. | | Optional: \{\}
Type: string
|
+| `metricsNamespace` _string_ | MetricsNamespace is the Azure metrics namespace. | | Optional: \{\}
Type: string
|
+| `aggregation` _string_ | Aggregation is the Azure metrics aggregation type. | | Optional: \{\}
Type: string
|
+| `filter` _string_ | Filter is the Azure metrics filter expression. | | Optional: \{\}
Type: string
|
+| `orderBy` _string_ | OrderBy is the Azure metrics ordering expression. | | Optional: \{\}
Type: string
|
+| `rollUpBy` _string_ | RollUpBy is the Azure metrics dimension to roll up by. | | Optional: \{\}
Type: string
|
+| `metricsEndpoint` _string_ | MetricsEndpoint is the Azure metrics endpoint override. | | Optional: \{\}
Type: string
|
+
+
+#### MonitorMetricsOptions
+
+
+
+MonitorMetricsOptions are provider-specific metrics query options.
+
+
+
+_Appears in:_
+- [MonitorMetricsQuery](#monitormetricsquery)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `azure` _[MonitorMetricsAzureOptions](#monitormetricsazureoptions)_ | Azure metrics query options. | | Optional: \{\}
|
+
+
+#### MonitorMetricsQuery
+
+
+
+MonitorMetricsQuery is the metrics query configuration for a monitor.
+
+
+
+_Appears in:_
+- [MonitorQuery](#monitorquery)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `tool` _string_ | Tool is the named workbench metrics tool. When omitted, the native Plural metrics provider is used. | | Optional: \{\}
Type: string
|
+| `query` _string_ | Query is the metrics query string passed through to the underlying metrics provider. | | MinLength: 1
Required: \{\}
Type: string
|
+| `step` _string_ | Step is the metrics query step (e.g. 5m). | | Optional: \{\}
Pattern: `^[0-9]+[dmhs]$`
Type: string
|
+| `duration` _string_ | Duration is the lookback duration for the metrics query (e.g. 1h). | | Optional: \{\}
Pattern: `^[0-9]+[dmhs]$`
Type: string
|
+| `options` _[MonitorMetricsOptions](#monitormetricsoptions)_ | Options are provider-specific metrics query options. | | Optional: \{\}
|
+
+
+#### MonitorQuery
+
+
+
+MonitorQuery is a wrapper for the underlying query definition for a monitor.
+Exactly one of log or metrics should be set, matching the monitor type.
+
+
+
+_Appears in:_
+- [MonitorSpec](#monitorspec)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `log` _[MonitorLogQuery](#monitorlogquery)_ | Log query used when the monitor type is LOG. | | Optional: \{\}
|
+| `metrics` _[MonitorMetricsQuery](#monitormetricsquery)_ | Metrics query used when the monitor type is METRICS. | | Optional: \{\}
|
+
+
+#### MonitorSpec
+
+
+
+MonitorSpec defines the desired state of a Monitor.
+
+
+
+_Appears in:_
+- [Monitor](#monitor)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `name` _string_ | Name is the short name used to identify this monitor in the Console API.
If not set, metadata.name is used. | | Optional: \{\}
Type: string
|
+| `serviceRef` _[LocalObjectReference](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#localobjectreference-v1-core)_ | ServiceRef references the ServiceDeployment resource this monitor is attached to.
The ServiceDeployment must be in the same namespace as the monitor.
Either ServiceRef or Service must be set. | | Optional: \{\}
|
+| `service` _string_ | Service references an existing service in the Console API this monitor is attached to,
in the format "cluster-handle/service-name" (e.g. mgmt/console). Use it to attach
a monitor to a service that is not managed by a ServiceDeployment resource.
Either ServiceRef or Service must be set. | | Optional: \{\}
Pattern: `^[^/]+/[^/]+$`
Type: string
|
+| `workbenchRef` _[LocalObjectReference](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#localobjectreference-v1-core)_ | WorkbenchRef references the Workbench this monitor is attached to.
When set, the monitor can start a workbench investigation when it fires.
It is required if the query uses a named workbench tool.
The Workbench must be in the same namespace as the monitor. | | Optional: \{\}
|
+| `prompt` _string_ | Prompt is used when the monitor starts a workbench investigation. | | MaxLength: 2048
Optional: \{\}
Type: string
|
+| `modes` _[WorkbenchJobModes](#workbenchjobmodes)_ | Modes defines mode-specific options for monitor-triggered workbench jobs. | | Optional: \{\}
|
+| `description` _string_ | Description is an optional free-form description of what this monitor is checking. | | Optional: \{\}
Type: string
|
+| `alertTemplate` _string_ | AlertTemplate is an optional template used when rendering alert messages for this monitor. | | Optional: \{\}
Type: string
|
+| `severity` _[AlertSeverity](#alertseverity)_ | Severity is the severity level applied to alerts generated by this monitor. | | Enum: [LOW MEDIUM HIGH CRITICAL UNDEFINED]
Required: \{\}
|
+| `type` _[MonitorType](#monitortype)_ | Type is the monitor data type. | | Enum: [LOG METRICS]
Required: \{\}
|
+| `evaluationCron` _string_ | EvaluationCron is the cron schedule defining when the monitor is evaluated (e.g. */5 * * * *).
It must be a cron expression with 5 fields (or 6 with an optional year), separated by single spaces,
or one of the @yearly, @annually, @monthly, @weekly, @daily, @midnight, @hourly, @minutely,
@secondly or @reboot shortcuts. Field values are validated by the Console API. | | MinLength: 1
Pattern: `^(@(?i:yearly\|annually\|monthly\|weekly\|daily\|midnight\|hourly\|minutely\|secondly\|reboot)\|[^ ]+( [^ ]+)\{4,5\})$`
Required: \{\}
Type: string
|
+| `query` _[MonitorQuery](#monitorquery)_ | Query is the underlying query configuration used to fetch data for this monitor. | | Required: \{\}
|
+| `threshold` _[MonitorThreshold](#monitorthreshold)_ | Threshold is the configuration that determines when the monitor should fire. | | Required: \{\}
|
+| `reconciliation` _[Reconciliation](#reconciliation)_ | Reconciliation settings for this resource. | | Optional: \{\}
|
+
+
+#### MonitorThreshold
+
+
+
+MonitorThreshold is the threshold configuration used to decide when a monitor should fire.
+
+
+
+_Appears in:_
+- [MonitorSpec](#monitorspec)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `aggregate` _[MonitorAggregate](#monitoraggregate)_ | Aggregate is the aggregation function applied over the result set. | | Enum: [MAX MIN AVG]
Required: \{\}
|
+| `value` _string_ | Value is the numeric value the aggregated metric must cross to trigger the alert.
It is a string to allow decimal values (e.g. "0.95"). | | Pattern: `^-?[0-9]+(\.[0-9]+)?$`
Required: \{\}
Type: string
|
+
+
#### NamespaceCredentials
@@ -2699,19 +3059,27 @@ _Appears in:_
-OAuth2TokenExchange configures OAuth2 client credentials token endpoint exchange for OpenAI-compatible APIs.
+OAuth2TokenExchange configures OAuth2 client credentials token endpoint exchange.
_Appears in:_
+- [MCPServerAuthentication](#mcpserverauthentication)
- [OpenAISettings](#openaisettings)
+- [WorkbenchToolSpec](#workbenchtoolspec)
| Field | Description | Default | Validation |
| --- | --- | --- | --- |
| `enabled` _boolean_ | Enabled turns token exchange on for obtaining access tokens via the configured token endpoint. | | Optional: \{\}
|
+| `type` _[OauthTokenExchangeType](#oauthtokenexchangetype)_ | Type selects client secret or signed JWT client assertion authentication. | CLIENT_SECRET | Enum: [CLIENT_SECRET CLIENT_ASSERTION]
Optional: \{\}
|
| `tokenUrl` _string_ | TokenURL is the OAuth2 token endpoint URL. | | Optional: \{\}
|
| `clientId` _string_ | ClientID is the OAuth2 client identifier. | | Optional: \{\}
|
| `clientSecretSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | ClientSecretSecretRef is a reference to a Kubernetes secret key holding the OAuth2 client secret. | | Optional: \{\}
|
+| `privateKeySecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | PrivateKeySecretRef references a PEM-encoded RSA private key used to sign client assertions. | | Optional: \{\}
|
+| `keyId` _string_ | KeyID is added to the signed JWT header as kid when configured. | | Optional: \{\}
|
+| `audience` _string_ | Audience overrides the JWT aud claim. It defaults to tokenUrl. | | Optional: \{\}
|
+| `resource` _string_ | Resource is the OAuth resource parameter requested from the token endpoint. | | Optional: \{\}
|
+| `scopes` _string array_ | Scopes are sent as a space-separated OAuth scope parameter. | | Optional: \{\}
|
#### OIDCProvider
@@ -3324,6 +3692,7 @@ _Appears in:_
| `flows` _[PersonaFlows](#personaflows)_ | Flows controls access to flow-related features and sections.
This includes workbenches, pipelines, and preview environments grouped under flows. | | Optional: \{\}
|
| `sidebar` _[PersonaSidebar](#personasidebar)_ | Sidebar configures which navigation items and sections are visible in the main sidebar.
This allows personas to have streamlined navigation focused on their primary workflows
while hiding irrelevant or restricted functionality. | | Optional: \{\}
|
| `services` _[PersonaServices](#personaservices)_ | Services controls access to service-specific features and configuration options.
This includes service configuration, secrets management, and other service-level operations. | | Optional: \{\}
|
+| `settings` _[PersonaSettings](#personasettings)_ | Settings controls which tabs are visible within the Console settings page.
Tabs are visible by default and can be hidden by explicitly setting them to false. | | Optional: \{\}
|
| `ai` _[PersonaAI](#personaai)_ | AI configures access to AI-powered features and capabilities within the Console.
This includes AI-assisted operations, automated suggestions, and other intelligent features. | | Optional: \{\}
|
@@ -3411,6 +3780,31 @@ _Appears in:_
| `configuration` _boolean_ | Configuration enables access to service configuration management when set to true.
This includes modifying service deployment settings, environment variables,
and other configuration parameters that affect service behavior. | | Optional: \{\}
|
+#### PersonaSettings
+
+
+
+PersonaSettings defines the visibility of tabs on the Console settings page.
+
+
+
+_Appears in:_
+- [PersonaConfiguration](#personaconfiguration)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `userManagement` _boolean_ | | | Optional: \{\}
|
+| `global` _boolean_ | | | Optional: \{\}
|
+| `ai` _boolean_ | | | Optional: \{\}
|
+| `webhooks` _boolean_ | | | Optional: \{\}
|
+| `chatbots` _boolean_ | | | Optional: \{\}
|
+| `cloudConnections` _boolean_ | | | Optional: \{\}
|
+| `projects` _boolean_ | | | Optional: \{\}
|
+| `notifications` _boolean_ | | | Optional: \{\}
|
+| `audits` _boolean_ | | | Optional: \{\}
|
+| `accessTokens` _boolean_ | | | Optional: \{\}
|
+
+
#### PersonaSidebar
@@ -4367,6 +4761,7 @@ _Appears in:_
- [ComplianceReportGeneratorSpec](#compliancereportgeneratorspec)
- [CustomCompatibilityMatrixSpec](#customcompatibilitymatrixspec)
- [CustomStackRunSpec](#customstackrunspec)
+- [DashboardSpec](#dashboardspec)
- [DeploymentSettingsSpec](#deploymentsettingsspec)
- [FederatedCredentialSpec](#federatedcredentialspec)
- [FlowSpec](#flowspec)
@@ -4378,6 +4773,7 @@ _Appears in:_
- [InfrastructureStackSpec](#infrastructurestackspec)
- [MCPServerSpec](#mcpserverspec)
- [ManagedNamespaceSpec](#managednamespacespec)
+- [MonitorSpec](#monitorspec)
- [NamespaceCredentialsSpec](#namespacecredentialsspec)
- [NotificationRouterSpec](#notificationrouterspec)
- [NotificationSinkSpec](#notificationsinkspec)
@@ -4900,6 +5296,7 @@ _Appears in:_
| Field | Description | Default | Validation |
| --- | --- | --- | --- |
| `email` _string_ | Email address that will be bound to this service account for identification
and authentication purposes. This email serves as the unique identifier
for the service account within the Console API. | | Required: \{\}
Type: string
|
+| `allowedScopes` _string array_ | AllowedScopes define the Console API endpoints that can be granted to access
tokens created for this service account. An empty list imposes no restriction. | | Optional: \{\}
|
| `scopes` _[ServiceAccountScope](#serviceaccountscope) array_ | Scopes define the access boundaries for this service account, controlling
which Console APIs and resources it can interact with. Each scope can restrict
access to specific API endpoints and resource identifiers, enabling fine-grained
permission control for automated processes. | | Optional: \{\}
|
| `tokenExpiry` _string_ | TokenExpiry is the TTL of the access token, e.g. 1h, 1d, 1w | | Optional: \{\}
|
| `tokenSecretRef` _[SecretReference](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretreference-v1-core)_ | TokenSecretRef references a Kubernetes secret that should contain the
authentication token for this service account. This enables secure storage
and management of credentials within the cluster. | | Optional: \{\}
|
@@ -5053,11 +5450,11 @@ _Appears in:_
| `git` _[GitRef](#gitref)_ | Git contains a reference to a Git folder and ref where the Helm chart is located. | | Optional: \{\}
|
| `ignoreHooks` _boolean_ | IgnoreHooks indicates whether to completely ignore Helm hooks when actualizing this service. | | Optional: \{\}
|
| `ignoreCrds` _boolean_ | IgnoreCrds indicates whether to not include the CRDs in the /crds folder of the chart.
It is useful if you want to avoid installing CRDs that are already present in the cluster. | | Optional: \{\}
|
-| `luaScript` _string_ | LuaScript to use to generate Helm configuration.
This can ultimately return a lua table with keys "values" and "valuesFiles"
to supply overlays for either dynamically based on git state or other metadata. | | Optional: \{\}
|
-| `luaFile` _string_ | LuaFile to use to generate Helm configuration.
This can ultimately return a Lua table with keys "values" and "valuesFiles"
to supply overlays for either dynamically based on Git state or other metadata. | | Optional: \{\}
|
+| `luaScript` _string_ | LuaScript to use to generate Helm configuration.
This can ultimately return a lua table with keys "values" and "valuesFiles"
to supply overlays for either dynamically based on git state or other metadata.
The script can call warn(message) to report non-fatal service warnings, which mark the service as stale. | | Optional: \{\}
|
+| `luaFile` _string_ | LuaFile to use to generate Helm configuration.
This can ultimately return a Lua table with keys "values" and "valuesFiles"
to supply overlays for either dynamically based on Git state or other metadata.
The script can call warn(message) to report non-fatal service warnings, which mark the service as stale. | | Optional: \{\}
|
| `luaFolder` _string_ | a folder of lua files to include in the final script used | | Optional: \{\}
|
-| `pythonScript` _string_ | PythonScript to use to generate Helm configuration.
This can ultimately return a dict with keys "values" and "valuesFiles"
to supply overlays for either dynamically based on git state or other metadata. | | Optional: \{\}
|
-| `pythonFile` _string_ | PythonFile to use to generate Helm configuration.
This can ultimately return a dict with keys "values" and "valuesFiles"
to supply overlays for either dynamically based on Git state or other metadata. | | Optional: \{\}
|
+| `pythonScript` _string_ | PythonScript to use to generate Helm configuration.
This can ultimately return a dict with keys "values" and "valuesFiles"
to supply overlays for either dynamically based on git state or other metadata.
The script can call warn(message) to report non-fatal service warnings, which mark the service as stale. | | Optional: \{\}
|
+| `pythonFile` _string_ | PythonFile to use to generate Helm configuration.
This can ultimately return a dict with keys "values" and "valuesFiles"
to supply overlays for either dynamically based on Git state or other metadata.
The script can call warn(message) to report non-fatal service warnings, which mark the service as stale. | | Optional: \{\}
|
| `pythonFolder` _string_ | a folder of python files to include in the final script used | | Optional: \{\}
|
| `kustomizePostrender` _string_ | KustomizePostrender is a folder containing a kustomization to apply to the result of rendering this service's manifests. | | Optional: \{\}
|
@@ -5804,6 +6201,100 @@ _Appears in:_
| `kubernetes` _boolean_ | Kubernetes enables the Kubernetes capability. | | Optional: \{\}
|
+#### WorkbenchJobBudget
+
+
+
+WorkbenchJobBudget defines budget limits for a workbench job.
+
+
+
+_Appears in:_
+- [WorkbenchJobModes](#workbenchjobmodes)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `cost` _string_ | Cost is the maximum cost budget for the job.
It is a string to allow decimal values (e.g. "12.5"). | | Optional: \{\}
Pattern: `^[0-9]+(\.[0-9]+)?$`
Type: string
|
+| `tokens` _integer_ | Tokens is the maximum token budget for the job. | | Minimum: 0
Optional: \{\}
|
+
+
+#### WorkbenchJobCodingModes
+
+
+
+WorkbenchJobCodingModes defines coding mode options for a workbench job.
+
+
+
+_Appears in:_
+- [WorkbenchJobModes](#workbenchjobmodes)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `babysit` _boolean_ | Babysit enables babysit mode for coding agent runs. | | Optional: \{\}
|
+| `approval` _boolean_ | Approval requires approval before coding agent runs continue. | | Optional: \{\}
|
+| `review` _boolean_ | Review enables pull request review mode for coding agent runs. | | Optional: \{\}
|
+
+
+#### WorkbenchJobKubernetesModes
+
+
+
+WorkbenchJobKubernetesModes defines kubernetes action options for a workbench job.
+
+
+
+_Appears in:_
+- [WorkbenchJobModes](#workbenchjobmodes)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `update` _boolean_ | Update enables kubernetes update actions. | | Optional: \{\}
|
+| `delete` _boolean_ | Delete enables kubernetes delete actions. | | Optional: \{\}
|
+| `exec` _boolean_ | Exec enables kubernetes exec actions. | | Optional: \{\}
|
+| `drain` _boolean_ | Drain enables kubernetes node drain actions. | | Optional: \{\}
|
+| `excludeNamespaces` _string array_ | ExcludeNamespaces are namespaces the agent can never act in. | | Optional: \{\}
|
+| `requireNamespaces` _string array_ | RequireNamespaces, if set, are the only namespaces the agent is allowed to act in. | | Optional: \{\}
|
+
+
+#### WorkbenchJobModel
+
+
+
+WorkbenchJobModel defines the AI model override for a workbench job.
+
+
+
+_Appears in:_
+- [WorkbenchJobModes](#workbenchjobmodes)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `provider` _[AiProvider](#aiprovider)_ | Provider is the AI provider for the job. | | Enum: [OPENAI ANTHROPIC OLLAMA AZURE BEDROCK VERTEX OPENAI_COMPATIBLE XAI]
Required: \{\}
|
+| `model` _string_ | Model is the model name for the job. | | MinLength: 1
Required: \{\}
Type: string
|
+
+
+#### WorkbenchJobModes
+
+
+
+WorkbenchJobModes defines mode-specific options for workbench jobs.
+
+
+
+_Appears in:_
+- [MonitorSpec](#monitorspec)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `plan` _boolean_ | Plan enables planning mode for the job. | | Optional: \{\}
|
+| `verification` _boolean_ | Verification enables verification mode for the job. | | Optional: \{\}
|
+| `model` _[WorkbenchJobModel](#workbenchjobmodel)_ | Model overrides the AI model used for the job. | | Optional: \{\}
|
+| `coding` _[WorkbenchJobCodingModes](#workbenchjobcodingmodes)_ | Coding defines coding mode options for the job. | | Optional: \{\}
|
+| `budget` _[WorkbenchJobBudget](#workbenchjobbudget)_ | Budget defines budget limits for the job. | | Optional: \{\}
|
+| `kubernetes` _[WorkbenchJobKubernetesModes](#workbenchjobkubernetesmodes)_ | Kubernetes defines kubernetes action options for the job. | | Optional: \{\}
|
+
+
#### WorkbenchObservabilityConfig
@@ -6103,6 +6594,7 @@ _Appears in:_
| `opensearch` _[WorkbenchToolOpensearchConfig](#workbenchtoolopensearchconfig)_ | AWS OpenSearch connection (logs). | | Optional: \{\}
|
| `prometheus` _[WorkbenchToolPrometheusConfig](#workbenchtoolprometheusconfig)_ | Prometheus connection (metrics). | | Optional: \{\}
|
| `loki` _[WorkbenchToolLokiConfig](#workbenchtoollokiconfig)_ | Loki connection (logs). | | Optional: \{\}
|
+| `victoriaLogs` _[WorkbenchToolVictoriaLogsConfig](#workbenchtoolvictorialogsconfig)_ | VictoriaLogs connection (logs). | | Optional: \{\}
|
| `tempo` _[WorkbenchToolTempoConfig](#workbenchtooltempoconfig)_ | Tempo connection (traces). | | Optional: \{\}
|
| `jaeger` _[WorkbenchToolJaegerConfig](#workbenchtooljaegerconfig)_ | Jaeger connection (traces). | | Optional: \{\}
|
| `splunk` _[WorkbenchToolSplunkConfig](#workbenchtoolsplunkconfig)_ | Splunk connection (logs). | | Optional: \{\}
|
@@ -6116,6 +6608,7 @@ _Appears in:_
| `pagerduty` _[WorkbenchToolPagerdutyConfig](#workbenchtoolpagerdutyconfig)_ | PagerDuty connection (integration). | | Optional: \{\}
|
| `teams` _[WorkbenchToolTeamsConfig](#workbenchtoolteamsconfig)_ | Microsoft Teams / Graph connection (integration). | | Optional: \{\}
|
| `atlassian` _[WorkbenchToolAtlassianConfig](#workbenchtoolatlassianconfig)_ | Atlassian/jira connection (ticketing). | | Optional: \{\}
|
+| `jiraDatacenter` _[WorkbenchToolJiraDatacenterConfig](#workbenchtooljiradatacenterconfig)_ | Jira Data Center connection (ticketing). | | Optional: \{\}
|
| `exa` _[WorkbenchToolExaConfig](#workbenchtoolexaconfig)_ | Exa connection (search). | | Optional: \{\}
|
| `github` _[WorkbenchToolGithubConfig](#workbenchtoolgithubconfig)_ | GitHub connection (integration). | | Optional: \{\}
|
| `gitlab` _[WorkbenchToolGitlabConfig](#workbenchtoolgitlabconfig)_ | GitLab connection (scm). | | Optional: \{\}
|
@@ -6312,6 +6805,23 @@ _Appears in:_
| `passwordSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | Reference to a secret key containing the basic auth password. | | Optional: \{\}
|
+#### WorkbenchToolJiraDatacenterConfig
+
+
+
+WorkbenchToolJiraDatacenterConfig defines a Jira Data Center connection.
+
+
+
+_Appears in:_
+- [WorkbenchToolConfiguration](#workbenchtoolconfiguration)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `url` _string_ | Jira Data Center base URL. | | Required: \{\}
|
+| `apiTokenSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | APITokenSecretRef references a personal access token when OAuth is not used. | | Optional: \{\}
|
+
+
#### WorkbenchToolLambdaConfig
@@ -6475,7 +6985,7 @@ _Appears in:_
| Field | Description | Default | Validation |
| --- | --- | --- | --- |
| `name` _string_ | The name of the tool (a-z, 0-9, underscores). If not set, metadata.name is used. | | Optional: \{\}
Pattern: `^[a-z0-9_]+$`
Type: string
|
-| `tool` _[WorkbenchToolType](#workbenchtooltype)_ | The type of tool. | | Enum: [HTTP ELASTIC DATADOG PROMETHEUS LOKI TEMPO SENTRY MCP LINEAR ATLASSIAN SPLUNK DYNATRACE CLOUDWATCH AZURE CLOUD JAEGER EXA GITHUB SLACK TEAMS GITLAB BITBUCKET BITBUCKET_DATACENTER AZURE_DEVOPS PAGERDUTY OPENSEARCH LAMBDA CLOUD_RUN AZURE_FUNCTION DOCKER]
Required: \{\}
|
+| `tool` _[WorkbenchToolType](#workbenchtooltype)_ | The type of tool. | | Enum: [HTTP ELASTIC DATADOG PROMETHEUS LOKI TEMPO SENTRY MCP LINEAR ATLASSIAN SPLUNK DYNATRACE CLOUDWATCH AZURE CLOUD JAEGER EXA GITHUB SLACK TEAMS GITLAB BITBUCKET BITBUCKET_DATACENTER AZURE_DEVOPS PAGERDUTY OPENSEARCH LAMBDA CLOUD_RUN AZURE_FUNCTION DOCKER VICTORIA_LOGS JIRA JIRA_DATACENTER]
Required: \{\}
|
| `categories` _WorkbenchToolCategory array_ | Categories for the tool. | | Optional: \{\}
|
| `approval` _boolean_ | Whether this tool requires approval before execution. | | Optional: \{\}
|
| `projectRef` _[ObjectReference](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectreference-v1-core)_ | The project for this tool. | | Optional: \{\}
|
@@ -6484,6 +6994,7 @@ _Appears in:_
| `scmConnectionRef` _[ObjectReference](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#objectreference-v1-core)_ | The SCM connection for this tool (e.g. shared Git provider credentials). | | Optional: \{\}
|
| `bindings` _[Bindings](#bindings)_ | Bindings define the read and write access policies for this tool. | | Optional: \{\}
|
| `configuration` _[WorkbenchToolConfiguration](#workbenchtoolconfiguration)_ | Tool configuration (e.g. HTTP). | | Optional: \{\}
|
+| `oauth` _[OAuth2TokenExchange](#oauth2tokenexchange)_ | OAuth configures client credentials token exchange for this tool. | | Optional: \{\}
|
| `reconciliation` _[Reconciliation](#reconciliation)_ | | | Optional: \{\}
|
@@ -6501,7 +7012,8 @@ _Appears in:_
| Field | Description | Default | Validation |
| --- | --- | --- | --- |
| `url` _string_ | Splunk base URL. | | Required: \{\}
|
-| `tokenSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | Reference to a secret key containing the bearer token. | | Optional: \{\}
|
+| `tokenSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | Reference to a secret key containing the authentication token. | | Optional: \{\}
|
+| `tokenType` _[SplunkTokenType](#splunktokentype)_ | Authorization realm used for token authentication. | BEARER | Enum: [BEARER SPLUNK]
Optional: \{\}
|
| `username` _string_ | Basic auth username. | | Optional: \{\}
|
| `passwordSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | Reference to a secret key containing the basic auth password. | | Optional: \{\}
|
@@ -6544,6 +7056,27 @@ _Appears in:_
| `tenantId` _string_ | Optional tenant id. | | Optional: \{\}
|
+#### WorkbenchToolVictoriaLogsConfig
+
+
+
+WorkbenchToolVictoriaLogsConfig defines a VictoriaLogs connection.
+
+
+
+_Appears in:_
+- [WorkbenchToolConfiguration](#workbenchtoolconfiguration)
+
+| Field | Description | Default | Validation |
+| --- | --- | --- | --- |
+| `url` _string_ | VictoriaLogs base URL. | | Required: \{\}
|
+| `tokenSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | Reference to a secret key containing the bearer token or api key. | | Optional: \{\}
|
+| `username` _string_ | Basic auth username. | | Optional: \{\}
|
+| `passwordSecretRef` _[SecretKeySelector](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.29/#secretkeyselector-v1-core)_ | Reference to a secret key containing the basic auth password. | | Optional: \{\}
|
+| `accountId` _string_ | Optional AccountID tenant header. | | Optional: \{\}
|
+| `projectId` _string_ | Optional ProjectID tenant header. | | Optional: \{\}
|
+
+
#### WorkbenchWebhook