--- apiVersion: apiextensions.k8s.io/v1 kind: CustomResourceDefinition metadata: annotations: controller-gen.kubebuilder.io/version: v0.20.1 kubectl.kubernetes.io/last-applied-configuration: | {"apiVersion":"apiextensions.k8s.io/v1","kind":"CustomResourceDefinition","metadata":{"annotations":{"controller-gen.kubebuilder.io/version":"v0.20.1"},"name":"externalproviders.inference.opendatahub.io"},"spec":{"group":"inference.opendatahub.io","names":{"kind":"ExternalProvider","listKind":"ExternalProviderList","plural":"externalproviders","singular":"externalprovider"},"scope":"Namespaced","versions":[{"additionalPrinterColumns":[{"jsonPath":".spec.provider","name":"Provider","type":"string"},{"jsonPath":".spec.endpoint","name":"Endpoint","type":"string"},{"jsonPath":".status.phase","name":"Phase","type":"string"},{"jsonPath":".metadata.creationTimestamp","name":"Age","type":"date"}],"name":"v1alpha1","schema":{"openAPIV3Schema":{"description":"ExternalProvider defines a connection to an external LLM provider (endpoint + credentials).\nMultiple ExternalModel resources can reference the same ExternalProvider.","properties":{"apiVersion":{"description":"APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources","type":"string"},"kind":{"description":"Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds","type":"string"},"metadata":{"type":"object"},"spec":{"description":"ExternalProviderSpec defines the desired state of ExternalProvider.","properties":{"auth":{"description":"Auth configures how to authenticate with the provider.","properties":{"secretRef":{"description":"SecretRef references a Kubernetes Secret containing the provider API key.\nThe Secret must be in the same namespace as the ExternalProvider\nand must contain a data key \"api-key\" with the credential value.","properties":{"name":{"maxLength":253,"minLength":1,"pattern":"^[a-z0-9]([a-z0-9\\-]*[a-z0-9])?$","type":"string"}},"required":["name"],"type":"object"},"type":{"description":"Type identifies the auth type for this provider.\ne.g. \"simple\" (header based), \"sigv4\", etc.","enum":["simple","sigv4","oauth2"],"type":"string"}},"required":["secretRef","type"],"type":"object"},"config":{"additionalProperties":{"type":"string"},"description":"Config holds provider-specific configuration as key-value pairs.\ne.g., Vertex AI: {\"project\": \"my-project\", \"location\": \"us-central1\"}.","type":"object"},"endpoint":{"description":"Endpoint is the FQDN of the external provider (no scheme or path).\ne.g. \"api.openai.com\", \"bedrock.amazonaws.com\".","maxLength":253,"minLength":1,"pattern":"^[a-zA-Z0-9]([a-zA-Z0-9\\-]*[a-zA-Z0-9])?(\\.[a-zA-Z0-9]([a-zA-Z0-9\\-]*[a-zA-Z0-9])?)+$","type":"string"},"provider":{"description":"Provider identifies the API type for this provider.\ne.g. \"openai\", \"anthropic\", \"azure\", \"aws-bedrock\", \"vertex\".","maxLength":63,"minLength":1,"type":"string"}},"required":["auth","endpoint","provider"],"type":"object"},"status":{"description":"ExternalProviderStatus defines the observed state of ExternalProvider.","properties":{"conditions":{"description":"Conditions represent the latest available observations of the provider's state.","items":{"description":"Condition contains details for one aspect of the current state of this API Resource.","properties":{"lastTransitionTime":{"description":"lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.","format":"date-time","type":"string"},"message":{"description":"message is a human readable message indicating details about the transition.\nThis may be an empty string.","maxLength":32768,"type":"string"},"observedGeneration":{"description":"observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.","format":"int64","minimum":0,"type":"integer"},"reason":{"description":"reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.","maxLength":1024,"minLength":1,"pattern":"^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$","type":"string"},"status":{"description":"status of the condition, one of True, False, Unknown.","enum":["True","False","Unknown"],"type":"string"},"type":{"description":"type of condition in CamelCase or in foo.example.com/CamelCase.","maxLength":316,"pattern":"^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$","type":"string"}},"required":["lastTransitionTime","message","reason","status","type"],"type":"object"},"type":"array"},"phase":{"description":"Phase represents the current reconciliation phase.\nReady: all networking resources created and Secret validated.\nFailed: reconciliation error (e.g., missing Secret, Istio resource creation failed).\nThis reflects controller reconciliation state, not runtime request health.","enum":["Pending","Ready","Failed"],"type":"string"}},"type":"object"}},"type":"object"}},"served":true,"storage":true,"subresources":{"status":{}}}]}} creationTimestamp: "2026-07-13T23:47:31Z" generation: 1 managedFields: - apiVersion: apiextensions.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:acceptedNames: f:kind: {} f:listKind: {} f:plural: {} f:singular: {} f:conditions: k:{"type":"Established"}: .: {} f:lastTransitionTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} k:{"type":"NamesAccepted"}: .: {} f:lastTransitionTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: kube-apiserver operation: Update subresource: status time: "2026-07-13T23:47:31Z" - apiVersion: apiextensions.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:annotations: .: {} f:controller-gen.kubebuilder.io/version: {} f:kubectl.kubernetes.io/last-applied-configuration: {} f:spec: f:conversion: .: {} f:strategy: {} f:group: {} f:names: f:kind: {} f:listKind: {} f:plural: {} f:singular: {} f:scope: {} f:versions: {} manager: kubectl-client-side-apply operation: Update time: "2026-07-13T23:47:31Z" name: externalproviders.inference.opendatahub.io resourceVersion: "21148" uid: ee44f776-bff4-4824-8418-62e628ba096d spec: conversion: strategy: None group: inference.opendatahub.io names: kind: ExternalProvider listKind: ExternalProviderList plural: externalproviders singular: externalprovider scope: Namespaced versions: - additionalPrinterColumns: - jsonPath: .spec.provider name: Provider type: string - jsonPath: .spec.endpoint name: Endpoint type: string - jsonPath: .status.phase name: Phase type: string - jsonPath: .metadata.creationTimestamp name: Age type: date name: v1alpha1 schema: openAPIV3Schema: description: |- ExternalProvider defines a connection to an external LLM provider (endpoint + credentials). Multiple ExternalModel resources can reference the same ExternalProvider. properties: apiVersion: description: |- APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources type: string kind: description: |- Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds type: string metadata: type: object spec: description: ExternalProviderSpec defines the desired state of ExternalProvider. properties: auth: description: Auth configures how to authenticate with the provider. properties: secretRef: description: |- SecretRef references a Kubernetes Secret containing the provider API key. The Secret must be in the same namespace as the ExternalProvider and must contain a data key "api-key" with the credential value. properties: name: maxLength: 253 minLength: 1 pattern: ^[a-z0-9]([a-z0-9\-]*[a-z0-9])?$ type: string required: - name type: object type: description: |- Type identifies the auth type for this provider. e.g. "simple" (header based), "sigv4", etc. enum: - simple - sigv4 - oauth2 type: string required: - secretRef - type type: object config: additionalProperties: type: string description: |- Config holds provider-specific configuration as key-value pairs. e.g., Vertex AI: {"project": "my-project", "location": "us-central1"}. type: object endpoint: description: |- Endpoint is the FQDN of the external provider (no scheme or path). e.g. "api.openai.com", "bedrock.amazonaws.com". maxLength: 253 minLength: 1 pattern: ^[a-zA-Z0-9]([a-zA-Z0-9\-]*[a-zA-Z0-9])?(\.[a-zA-Z0-9]([a-zA-Z0-9\-]*[a-zA-Z0-9])?)+$ type: string provider: description: |- Provider identifies the API type for this provider. e.g. "openai", "anthropic", "azure", "aws-bedrock", "vertex". maxLength: 63 minLength: 1 type: string required: - auth - endpoint - provider type: object status: description: ExternalProviderStatus defines the observed state of ExternalProvider. properties: conditions: description: Conditions represent the latest available observations of the provider's state. items: description: Condition contains details for one aspect of the current state of this API Resource. properties: lastTransitionTime: description: |- lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. format: date-time type: string message: description: |- message is a human readable message indicating details about the transition. This may be an empty string. maxLength: 32768 type: string observedGeneration: description: |- observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. format: int64 minimum: 0 type: integer reason: description: |- reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. maxLength: 1024 minLength: 1 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ type: string status: description: status of the condition, one of True, False, Unknown. enum: - "True" - "False" - Unknown type: string type: description: type of condition in CamelCase or in foo.example.com/CamelCase. maxLength: 316 pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$ type: string required: - lastTransitionTime - message - reason - status - type type: object type: array phase: description: |- Phase represents the current reconciliation phase. Ready: all networking resources created and Secret validated. Failed: reconciliation error (e.g., missing Secret, Istio resource creation failed). This reflects controller reconciliation state, not runtime request health. enum: - Pending - Ready - Failed type: string type: object type: object served: true storage: true subresources: status: {} status: acceptedNames: kind: ExternalProvider listKind: ExternalProviderList plural: externalproviders singular: externalprovider conditions: - lastTransitionTime: "2026-07-13T23:47:31Z" message: no conflicts found reason: NoConflicts status: "True" type: NamesAccepted - lastTransitionTime: "2026-07-13T23:47:31Z" message: the initial names have been accepted reason: InitialNamesAccepted status: "True" type: Established storedVersions: - v1alpha1