--- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.16.4 kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"apiextensions.k8s.io/v1","kind":"CustomResourceDefinition","metadata":{"annotations":{"controller-gen.kubebuilder.io/version":"v0.16.4"},"name":"configs.maas.opendatahub.io"},"spec":{"group":"maas.opendatahub.io","names":{"kind":"Config","listKind":"ConfigList","plural":"configs","shortNames":["maasconfig"],"singular":"config"},"scope":"Cluster","versions":[{"additionalPrinterColumns":[{"jsonPath":".metadata.creationTimestamp","name":"Age","type":"date"}],"name":"v1alpha1","schema":{"openAPIV3Schema":{"description":"Config is a cluster-scoped anchor for MaaS platform resources. Namespaced and\ncluster-scoped operands created by maas-controller reference this object as their controller\nowner so Kubernetes garbage collection can tear down the full graph when the Config\nis deleted (subject to finalizers on dependents).","properties":{"apiVersion":{"description":"APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources","type":"string"},"kind":{"description":"Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds","type":"string"},"metadata":{"type":"object"},"spec":{"description":"ConfigSpec defines the desired state of Config.","properties":{"limitadorScrapeInterval":{"default":"30s","description":"LimitadorScrapeInterval defines the scrape interval for Limitador metrics in the ServiceMonitor.\nDefaults to \"30s\" if not specified.","maxLength":16,"pattern":"^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$","type":"string"},"maxSubscriptionReconciles":{"description":"MaxSubscriptionReconciles sets the maximum number of MaaSSubscription\nreconciliations that run in parallel. Increasing this value improves\nthroughput when the cluster has many subscriptions, at the cost of\nhigher CPU and API-server request rate.\nWhen unset the controller-runtime default (1) is used.","format":"int32","maximum":50,"minimum":1,"type":"integer"},"usageLogging":{"default":false,"description":"UsageLogging enables cluster-wide per-request structured OTel access logging\nfor usage tracking (token counts, identity, model). When enabled, the\ncontroller deploys an EnvoyFilter on the shared gateway that emits\nstructured usage logs via OTel Access Log Service.\nEnabling this logs identity attributes (user_id, key_id, key_name,\norganization_id, groups, subscription) per request — ensure\nGDPR/privacy compliance before enabling.","type":"boolean"}},"type":"object"},"status":{"description":"ConfigStatus defines the observed state of Config.","type":"object"}},"type":"object","x-kubernetes-validations":[{"message":"Config name must be default","rule":"self.metadata.name == 'default'"}]}},"served":true,"storage":true,"subresources":{"status":{}}}]}} creationTimestamp: "2026-07-29T01:24:00Z" generation: 1 managedFields: - apiVersion: apiextensions.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:acceptedNames: f:kind: {} f:listKind: {} f:plural: {} f:shortNames: {} f:singular: {} f:conditions: k:{"type":"Established"}: .: {} f:lastTransitionTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} k:{"type":"NamesAccepted"}: .: {} f:lastTransitionTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: kube-apiserver operation: Update subresource: status time: "2026-07-29T01:24:00Z" - apiVersion: apiextensions.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:annotations: .: {} f:controller-gen.kubebuilder.io/version: {} f:kubectl.kubernetes.io/last-applied-configuration: {} f:spec: f:conversion: .: {} f:strategy: {} f:group: {} f:names: f:kind: {} f:listKind: {} f:plural: {} f:shortNames: {} f:singular: {} f:scope: {} f:versions: {} manager: kubectl-client-side-apply operation: Update time: "2026-07-29T01:24:00Z" name: configs.maas.opendatahub.io resourceVersion: "22751" uid: 6f4e3e9b-1663-4557-92ee-eeda67218d18 spec: conversion: strategy: None group: maas.opendatahub.io names: kind: Config listKind: ConfigList plural: configs shortNames: - maasconfig singular: config scope: Cluster versions: - additionalPrinterColumns: - jsonPath: .metadata.creationTimestamp name: Age type: date name: v1alpha1 schema: openAPIV3Schema: description: |- Config is a cluster-scoped anchor for MaaS platform resources. Namespaced and cluster-scoped operands created by maas-controller reference this object as their controller owner so Kubernetes garbage collection can tear down the full graph when the Config is deleted (subject to finalizers on dependents). properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: ConfigSpec defines the desired state of Config. properties: limitadorScrapeInterval: default: 30s description: |- LimitadorScrapeInterval defines the scrape interval for Limitador metrics in the ServiceMonitor. Defaults to "30s" if not specified. maxLength: 16 pattern: ^([0-9]+(\.[0-9]+)?(ms|s|m|h))+$ type: string maxSubscriptionReconciles: description: |- MaxSubscriptionReconciles sets the maximum number of MaaSSubscription reconciliations that run in parallel. Increasing this value improves throughput when the cluster has many subscriptions, at the cost of higher CPU and API-server request rate. When unset the controller-runtime default (1) is used. format: int32 maximum: 50 minimum: 1 type: integer usageLogging: default: false description: |- UsageLogging enables cluster-wide per-request structured OTel access logging for usage tracking (token counts, identity, model). When enabled, the controller deploys an EnvoyFilter on the shared gateway that emits structured usage logs via OTel Access Log Service. Enabling this logs identity attributes (user_id, key_id, key_name, organization_id, groups, subscription) per request — ensure GDPR/privacy compliance before enabling. type: boolean type: object status: description: ConfigStatus defines the observed state of Config. type: object type: object x-kubernetes-validations: - message: Config name must be default rule: self.metadata.name == 'default' served: true storage: true subresources: status: {} status: acceptedNames: kind: Config listKind: ConfigList plural: configs shortNames: - maasconfig singular: config conditions: - lastTransitionTime: "2026-07-29T01:24:00Z" message: no conflicts found reason: NoConflicts status: "True" type: NamesAccepted - lastTransitionTime: "2026-07-29T01:24:00Z" message: the initial names have been accepted reason: InitialNamesAccepted status: "True" type: Established storedVersions: - v1alpha1