All pages
Powered by GitBook
1 of 1

Loading...

API Reference

Technical documentation of the Custom Resource Definitions (CRDs) and API fields used to configure the MariaDB Enterprise Kubernetes Operator.

Packages

  • enterprise.mariadb.com/v1alpha1

enterprise.mariadb.com/v1alpha1

Package v1alpha1 contains API Schema definitions for the v1alpha1 API group

Resource Types

  • Backup

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#affinity-v1-core.

Appears in:

Field
Description
Default
Validation

AffinityConfig defines policies to schedule Pods in Nodes.

Appears in:

Field
Description
Default
Validation

Agent is a sidecar agent that co-operates with mariadb-enterprise-operator.

Appears in:

Field
Description
Default
Validation

Appears in:

Field
Description
Default
Validation

Backup is the Schema for the backups API. It is used to define backup jobs and its storage.

Field
Description
Default
Validation

Underlying type: string

BackupContentType defines the backup content type.

Appears in:

Field
Description

BackupSpec defines the desired state of Backup

Appears in:

Field
Description
Default
Validation

BackupStorage defines the final storage for backups.

Appears in:

Field
Description
Default
Validation

BasicAuth refers to the basic authentication mechanism utilized for establishing a connection from the operator to the agent.

Appears in:

Field
Description
Default
Validation

BootstrapFrom defines a source to bootstrap MariaDB from.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#csivolumesource-v1-core.

Appears in:

Field
Description
Default
Validation

CertConfig defines parameters to configure a certificate.

Appears in:

Field
Description
Default
Validation

Underlying type: string

CleanupPolicy defines the behavior for cleaning up a resource.

Appears in:

Field
Description

Underlying type: string

CompressAlgorithm defines the compression algorithm for a Backup resource.

Appears in:

Field
Description

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#configmapkeyselector-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#configmapvolumesource-v1-core.

Appears in:

Field
Description
Default
Validation

Connection is the Schema for the connections API. It is used to configure connection strings for the applications connecting to MariaDB.

Field
Description
Default
Validation

ConnectionSpec defines the desired state of Connection

Appears in:

Field
Description
Default
Validation

ConnectionTemplate defines a template to customize Connection objects.

Appears in:

Field
Description
Default
Validation

Container object definition.

Appears in:

Field
Description
Default
Validation

ContainerTemplate defines a template to configure Container objects.

Appears in:

Field
Description
Default
Validation

Underlying type: string

CooperativeMonitoring enables coordination between multiple MaxScale instances running monitors. See: https://mariadb.com/docs/server/architecture/components/maxscale/monitors/mariadbmon/use-cooperative-locking-ha-maxscale-mariadb-monitor/

Appears in:

Field
Description

Cordoning defines the parameters for cordoning a resource, resulting in the connections being blocked.

Appears in:

Field
Description
Default
Validation

CronJobTemplate defines parameters for configuring CronJob objects.

Appears in:

Field
Description
Default
Validation

Database is the Schema for the databases API. It is used to define a logical database as if you were running a 'CREATE DATABASE' statement.

Field
Description
Default
Validation

DatabaseSpec defines the desired state of Database

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#emptydirvolumesource-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#envfromsource-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#envvarsource-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#envvarsource-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#ephemeralvolumesource-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#execaction-v1-core.

Appears in:

Field
Description
Default
Validation

Exporter defines a metrics exporter container.

Appears in:

Field
Description
Default
Validation

ExternalMariaDB is the Schema for the external MariaDBs API. It is used to define external MariaDB server.

Field
Description
Default
Validation

ExternalMariaDBSpec defines the desired state of an External MariaDB

Appears in:

Field
Description
Default
Validation

ExternalTLS defines the TLS configuration for external MariaDB instances.

Appears in:

Field
Description
Default
Validation

Galera allows you to enable multi-master HA via Galera in your MariaDB cluster.

Appears in:

Field
Description
Default
Validation

GaleraConfig defines storage options for the Galera configuration files.

Appears in:

Field
Description
Default
Validation

GaleraInitJob defines a Job used to be used to initialize the Galera cluster.

Appears in:

Field
Description
Default
Validation

GaleraRecovery is the recovery process performed by the operator whenever the Galera cluster is not healthy. More info: https://galeracluster.com/library/documentation/crash-recovery.html.

Appears in:

Field
Description
Default
Validation

GaleraRecoveryJob defines a Job used to be used to recover the Galera cluster.

Appears in:

Field
Description
Default
Validation

GaleraSpec is the Galera desired state specification.

Appears in:

Field
Description
Default
Validation

GeneratedSecretKeyRef defines a reference to a Secret that can be automatically generated by mariadb-enterprise-operator if needed.

Appears in:

Field
Description
Default
Validation

Grant is the Schema for the grants API. It is used to define grants as if you were running a 'GRANT' statement.

Field
Description
Default
Validation

GrantSpec defines the desired state of Grant

Appears in:

Field
Description
Default
Validation

Underlying type: string

Gtid indicates which Global Transaction ID (GTID) position mode should be used when connecting a replica to the master. See: https://mariadb.com/kb/en/gtid/#using-current_pos-vs-slave_pos.

Appears in:

Field
Description

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#httpgetaction-v1-core.

Appears in:

Field
Description
Default
Validation

HealthCheck defines intervals for performing health checks.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#hostpathvolumesource-v1-core

Appears in:

Field
Description
Default
Validation

InitContainer is an init container that runs in the MariaDB Pod and co-operates with mariadb-enterprise-operator.

Appears in:

Field
Description
Default
Validation

Job defines a Job used to be used with MariaDB.

Appears in:

Field
Description
Default
Validation

JobContainerTemplate defines a template to configure Container objects that run in a Job.

Appears in:

Field
Description
Default
Validation

JobPodTemplate defines a template to configure Container objects that run in a Job.

Appears in:

Field
Description
Default
Validation

KubernetesAuth refers to the Kubernetes authentication mechanism utilized for establishing a connection from the operator to the agent. The agent validates the legitimacy of the service account token provided as an Authorization header by creating a TokenReview resource.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#labelselector-v1-meta

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#labelselectorrequirement-v1-meta

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#lifecycle-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#lifecyclehandler-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#localobjectreference-v1-core.

Appears in:

Field
Description
Default
Validation

MariaDB is the Schema for the mariadbs API. It is used to define MariaDB clusters.

Field
Description
Default
Validation

MariaDBMaintenance defines different capabilities of the operator to allow for maintenance to be performed on MariaDB.

Appears in:

Field
Description
Default
Validation

MariaDBPodTemplate defines a template for MariaDB Pods. Refer to the Kubernetes dos: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#pod-v1-core.

Appears in:

Field
Description
Default
Validation

MariaDBRef is a reference to a MariaDB object.

Appears in:

Field
Description
Default
Validation

MariaDBSpec defines the desired state of MariaDB

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#volume-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#volume-v1-core.

Appears in:

Field
Description
Default
Validation

MariadbMetrics defines the metrics for a MariaDB.

Appears in:

Field
Description
Default
Validation

MaxScale is the Schema for the maxscales API. It is used to define MaxScale clusters.

Field
Description
Default
Validation

MaxScaleAdmin configures the admin REST API and GUI.

Appears in:

Field
Description
Default
Validation

MaxScaleAuth defines the credentials required for MaxScale to connect to MariaDB.

Appears in:

Field
Description
Default
Validation

MaxScaleConfig defines the MaxScale configuration.

Appears in:

Field
Description
Default
Validation

MaxScaleConfigSync defines how the config changes are replicated across replicas.

Appears in:

Field
Description
Default
Validation

MaxScaleListener defines how the MaxScale server will listen for connections.

Appears in:

Field
Description
Default
Validation

MaxScaleMaintenance defines different capabilities of the operator to allow for maintenance to be performed on MaxScale.

Appears in:

Field
Description
Default
Validation

MaxScaleMetrics defines the metrics for a Maxscale.

Appears in:

Field
Description
Default
Validation

MaxScaleMonitor monitors MariaDB server instances

Appears in:

Field
Description
Default
Validation

MaxScalePodTemplate defines a template for MaxScale Pods.

Appears in:

Field
Description
Default
Validation

MaxScaleServer defines a MariaDB server to forward traffic to.

Appears in:

Field
Description
Default
Validation

Services define how the traffic is forwarded to the MariaDB servers.

Appears in:

Field
Description
Default
Validation

MaxScaleSpec defines the desired state of MaxScale.

Appears in:

Field
Description
Default
Validation

TLS defines the PKI to be used with MaxScale.

Appears in:

Field
Description
Default
Validation

Metadata defines the metadata to added to resources.

Appears in:

Field
Description
Default
Validation

Underlying type: string

MonitorModule defines the type of monitor module

Appears in:

Field
Description

MultiCluster is the multi-cluster topology configuration.

Appears in:

Field
Description
Default
Validation

MultiClusterMember defines the configuration for a multi-cluster topology member.

Appears in:

Field
Description
Default
Validation

MultiClusterSpec is the specification for the multi-cluster topology.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#nfsvolumesource-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#nodeaffinity-v1-core

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#nodeselector-v1-core

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#nodeselectorrequirement-v1-core

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#nodeselectorterm-v1-core

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#objectfieldselector-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#objectreference-v1-core.

Appears in:

Field
Description
Default
Validation

PasswordPlugin defines the password plugin and its arguments.

Appears in:

Field
Description
Default
Validation

Underlying type: string

PersistentVolumeClaimRetentionPolicyType describes the lifecycle of persistent volume claims. Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#statefulsetpersistentvolumeclaimretentionpolicy-v1-apps.

Appears in:

Field
Description

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#persistentvolumeclaimspec-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#persistentvolumeclaimvolumesource-v1-core.

Appears in:

Field
Description
Default
Validation

PhysicalBackup is the Schema for the physicalbackups API. It is used to define physical backup jobs and its storage.

Field
Description
Default
Validation

PhysicalBackupPodTemplate defines a template to configure Container objects that run in a PhysicalBackup.

Appears in:

Field
Description
Default
Validation

PhysicalBackupSchedule defines when the PhysicalBackup will be taken.

Appears in:

Field
Description
Default
Validation

PhysicalBackupSpec defines the desired state of PhysicalBackup.

Appears in:

Field
Description
Default
Validation

PhysicalBackupStorage defines the storage for physical backups.

Appears in:

Field
Description
Default
Validation

Underlying type: string

PhysicalBackupTarget defines in which Pod the physical backups will be taken.

Appears in:

Field
Description

PhysicalBackupVolumeSnapshot defines parameters for the VolumeSnapshots used as physical backups.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#podaffinityterm-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#podantiaffinity-v1-core.

Appears in:

Field
Description
Default
Validation

PodDisruptionBudget is the Pod availability bundget for a MariaDB

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#podsecuritycontext-v1-core

Appears in:

Field
Description
Default
Validation

PointInTimeRecovery is the Schema for the pointintimerecoveries API. It contains binlog archival and point-in-time restoration settings.

Field
Description
Default
Validation

PointInTimeRecoverySpec defines the desired state of PointInTimeRecovery. It contains binlog archive and point-in-time restoration settings.

Appears in:

Field
Description
Default
Validation

PointInTimeRecoveryStorage stores the different storage options for PITR

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#preferredschedulingterm-v1-core

Appears in:

Field
Description
Default
Validation

PrimaryGalera is the Galera configuration for the primary node.

Appears in:

Field
Description
Default
Validation

PrimaryReplication is the replication configuration and operation parameters for the primary.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#probe-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#probe-v1-core.

Appears in:

Field
Description
Default
Validation

ReplicaBootstrapFrom defines the sources for bootstrapping new relicas.

Appears in:

Field
Description
Default
Validation

ReplicaRecovery defines how the replicas should be recovered after they enter an error state.

Appears in:

Field
Description
Default
Validation

ReplicaReplication is the replication configuration and operation parameters for the replicas.

Appears in:

Field
Description
Default
Validation

Replication defines replication configuration for a MariaDB cluster.

Appears in:

Field
Description
Default
Validation

ReplicationSpec is the replication desired state.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#resourcerequirements-v1-core.

Appears in:

Restore is the Schema for the restores API. It is used to define restore jobs and its restoration source.

Field
Description
Default
Validation

RestoreSource defines a source for restoring a logical backup.

Appears in:

Field
Description
Default
Validation

RestoreSpec defines the desired state of restore

Appears in:

Field
Description
Default
Validation

Appears in:

Field
Description
Default
Validation

SQLTemplate defines a template to customize SQL objects.

Appears in:

Field
Description
Default
Validation

SSECConfig defines the configuration for SSE-C (Server-Side Encryption with Customer-Provided Keys).

Appears in:

Field
Description
Default
Validation

Underlying type: string

SST is the Snapshot State Transfer used when new Pods join the cluster. More info: https://galeracluster.com/library/documentation/sst.html.

Appears in:

Field
Description

Schedule contains parameters to define a schedule

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#secretkeyselector-v1-core.

Appears in:

Field
Description
Default
Validation

SecretTemplate defines a template to customize Secret objects.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#secretvolumesource-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#securitycontext-v1-core.

Appears in:

Field
Description
Default
Validation

ServiceMonitor defines a prometheus ServiceMonitor object.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#serviceport-v1-core

Appears in:

Field
Description
Default
Validation

Underlying type: string

ServiceRouter defines the type of service router.

Appears in:

Field
Description

ServiceTemplate defines a template to customize Service objects.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#sleepaction-v1-core

Appears in:

Field
Description
Default
Validation

SqlJob is the Schema for the sqljobs API. It is used to run sql scripts as jobs.

Field
Description
Default
Validation

SqlJobSpec defines the desired state of SqlJob

Appears in:

Field
Description
Default
Validation

StagingStorage defines the temporary storage used to keep external backups (i.e. S3) while they are being processed.

Appears in:

Field
Description
Default
Validation

StatefulSetPersistentVolumeClaimRetentionPolicy describes the lifecycle of PVCs created from volumeClaimTemplates. Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#statefulsetpersistentvolumeclaimretentionpolicy-v1-apps.

Appears in:

Field
Description
Default
Validation

Storage defines the storage options to be used for provisioning the PVCs mounted by MariaDB.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#volume-v1-core.

Appears in:

Field
Description
Default
Validation

SuspendTemplate indicates whether the current resource should be suspended or not.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#tcpsocketaction-v1-core.

Appears in:

Field
Description
Default
Validation

TLS defines the PKI to be used with MariaDB.

Appears in:

Field
Description
Default
Validation

Appears in:

Field
Description
Default
Validation

TLSRequirements specifies TLS requirements for the user to connect. See: https://mariadb.com/kb/en/securing-connections-for-client-and-server/#requiring-tls.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#topologyspreadconstraint-v1-core.

Appears in:

Field
Description
Default
Validation

TypedLocalObjectReference is a reference to a specific object type.

Appears in:

Field
Description
Default
Validation

UpdateStrategy defines how a MariaDB resource is updated.

Appears in:

Field
Description
Default
Validation

Underlying type: string

UpdateType defines the type of update for a MariaDB resource.

Appears in:

Field
Description

User is the Schema for the users API. It is used to define grants as if you were running a 'CREATE USER' statement.

Field
Description
Default
Validation

UserSpec defines the desired state of User

Appears in:

Field
Description
Default
Validation

VolumeClaimTemplate defines a template to customize PVC objects.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#volumemount-v1-core.

Appears in:

Field
Description
Default
Validation

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#volume-v1-core.

Appears in:

Field
Description
Default
Validation

Underlying type: string

WaitPoint defines whether the transaction should wait for ACK before committing to the storage engine. More info: https://mariadb.com/kb/en/semisynchronous-replication/#rpl_semi_sync_master_wait_point.

Appears in:

Field
Description

Refer to the Kubernetes docs: https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.36/#weightedpodaffinityterm-v1-core.

Appears in:

Field
Description
Default
Validation

This page is: Copyright © 2026 MariaDB. All rights reserved.

  • MariaDBPodTemplate

  • MariaDBSpec

  • MaxScalePodTemplate

  • MaxScaleSpec

  • RestoreSpec

  • SqlJobSpec

  • antiAffinityEnabled boolean

    AntiAffinityEnabled configures PodAntiAffinity so each Pod is scheduled in a different Node, enabling HA. Make sure you have at least as many Nodes available as the replicas to not end up with unscheduled Pods.

    env array

    Env represents the environment variables to be injected in a container.

    envFrom array

    EnvFrom represents the references (via ConfigMap and Secrets) to environment variables to be injected in the container.

    volumeMounts array

    VolumeMounts to be used in the Container.

    livenessProbe

    LivenessProbe to be used in the Container.

    readinessProbe

    ReadinessProbe to be used in the Container.

    startupProbe

    StartupProbe to be used in the Container.

    resources

    Resources describes the compute resource requirements.

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    lifecycle

    Lifecycle are actions that the management system should take in response to container lifecycle events.

    image string

    Image name to be used by the MariaDB instances. The supported format is <image>:<tag>.

    imagePullPolicy

    ImagePullPolicy is the image pull policy. One of Always, Never or IfNotPresent. If not defined, it defaults to IfNotPresent.

    Enum: [Always Never IfNotPresent]

    port integer

    Port where the agent will be listening for API connections.

    probePort integer

    Port where the agent will be listening for probe connections.

    kubernetesAuth

    KubernetesAuth to be used by the agent container

    basicAuth

    BasicAuth to be used by the agent container

    gracefulShutdownTimeout

    GracefulShutdownTimeout is the time we give to the agent container in order to gracefully terminate in-flight requests.

    Required: {}

    prefix string

    Prefix indicates a folder/subfolder in the container. For example: mariadb/ or mariadb/backups. A trailing slash '/' is added if not provided.

    storageAccountName string

    StorageAccountName is the name of the storage account. Pairs with StorageAccountKey for static credential authentication

    storageAccountKey

    StorageAccountKey is a reference to a Secret key containing the Azure Blob Storage Storage account Key. Pairs with StorageAccountKey for static credential authentication

    tls

    TLS provides the configuration required to establish TLS connections with Azure Blob Storage.

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    podMetadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets array

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    successfulJobsHistoryLimit integer

    SuccessfulJobsHistoryLimit defines the maximum number of successful Jobs to be displayed.

    Minimum: 0

    failedJobsHistoryLimit integer

    FailedJobsHistoryLimit defines the maximum number of failed Jobs to be displayed.

    Minimum: 0

    timeZone string

    TimeZone defines the timezone associated with the cron expression.

    mariaDbRef

    MariaDBRef is a reference to a MariaDB object.

    Required: {}

    compression

    Compression algorithm to be used in the Backup.

    Enum: [none bzip2 gzip]

    stagingStorage

    StagingStorage defines the temporary storage used to keep external backups (i.e. S3) while they are being processed. It defaults to an emptyDir volume, meaning that the backups will be temporarily stored in the node where the Backup Job is scheduled. The staging area gets cleaned up after each backup is completed, consider this for sizing it appropriately.

    storage

    Storage defines the final storage for backups.

    Required: {}

    schedule

    Schedule defines when the Backup will be taken.

    maxRetention

    MaxRetention defines the retention policy for backups. Old backups will be cleaned up by the Backup Job. It defaults to 30 days.

    databases string array

    Databases defines the logical databases to be backed up. If not provided, all databases are backed up.

    ignoreGlobalPriv boolean

    IgnoreGlobalPriv indicates to ignore the mysql.global_priv in backups. If not provided, it will default to true when the referred MariaDB instance has Galera enabled and otherwise to false.

    logLevel string

    LogLevel to be used in the Backup Job. It defaults to 'info'.

    info

    Enum: [debug info warn error dpanic panic fatal]

    backoffLimit integer

    BackoffLimit defines the maximum number of attempts to successfully take a Backup.

    restartPolicy

    RestartPolicy to be added to the Backup Pod.

    OnFailure

    Enum: [Always OnFailure Never]

    inheritMetadata

    InheritMetadata defines the metadata to be inherited by children resources.

    volume

    Volume is a Kubernetes volume specification.

    passwordSecretKeyRef

    PasswordSecretKeyRef to be used for basic authentication

    pointInTimeRecoveryRef

    PointInTimeRecoveryRef is a reference to a PointInTimeRecovery object. Providing this field implies restoring the PhysicalBackup referenced in the PointInTimeRecovery object and replaying the archived binary logs up to the point-in-time restoration target, defined by the targetRecoveryTime field.

    backupContentType

    BackupContentType is the backup content type available in the source to bootstrap from. It is inferred based on the BackupRef and VolumeSnapshotRef fields. If inference is not possible, it defaults to Logical. Set this field explicitly when using physical backups from S3 or Volume sources.

    Enum: [Logical Physical]

    s3

    S3 defines the configuration to restore backups from a S3 compatible storage. This field takes precedence over the Volume source.

    azureBlob

    AzureBlob defines the configuration to restore from Azure Blob compatible storage. This field takes precedence over the Volume source.

    volume

    Volume is a Kubernetes Volume object that contains a backup.

    targetRecoveryTime

    TargetRecoveryTime is a RFC3339 (1970-01-01T00:00:00Z) date and time that defines the point in time recovery objective. It is used to determine the closest restoration source in time.

    stagingStorage

    StagingStorage defines the temporary storage used to keep external backups and binary logs (i.e. S3) while they are being processed. It defaults to an emptyDir volume, meaning that the backups will be temporarily stored in the node where the Job is scheduled.

    restoreJob

    RestoreJob defines additional properties for the restoration Job.

    logLevel string

    LogLevel to be used in the mariadb-enterprise-operator container of the restoration Job. It defaults to 'info'.

    info

    Enum: [debug info warn error dpanic panic fatal]

  • VolumeSource

  • fsType string

    volumeAttributes object (keys:string, values:string)

    nodePublishSecretRef

    privateKeyAlgorithm string

    PrivateKeyAlgorithm is the algorithm to be used for the CA and leaf certificate private keys. One of: ECDSA or RSA

    Enum: [ECDSA RSA]

    privateKeySize integer

    PrivateKeyAlgorithm is the key size to be used for the CA and leaf certificate private keys. Supported values: ECDSA(256, 384, 521), RSA(2048, 3072, 4096)

  • UserSpec

  • metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    healthCheck

    HealthCheck to be used in the Connection.

    params object (keys:string, values:string)

    Params to be used in the Connection.

    serviceName string

    ServiceName to be used in the Connection.

    port integer

    Port to connect to. If not provided, it defaults to the MariaDB port or to the first MaxScale listener.

    mariaDbRef

    MariaDBRef is a reference to the MariaDB to connect to. Either MariaDBRef or MaxScaleRef must be provided.

    maxScaleRef

    MaxScaleRef is a reference to the MaxScale to connect to. Either MariaDBRef or MaxScaleRef must be provided.

    username string

    Username to use for configuring the Connection.

    Required: {}

    passwordSecretKeyRef

    PasswordSecretKeyRef is a reference to the password to use for configuring the Connection. Either passwordSecretKeyRef or tlsClientCertSecretRef must be provided as client credentials. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password.

    tlsClientCertSecretRef

    TLSClientCertSecretRef is a reference to a Kubernetes TLS Secret used as authentication when checking the connection health. Either passwordSecretKeyRef or tlsClientCertSecretRef must be provided as client credentials. If not provided, the client certificate provided by the referred MariaDB is used if TLS is enabled. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the client certificate.

    host string

    Host to connect to. If not provided, it defaults to the MariaDB host or to the MaxScale host.

    database string

    Database to use when configuring the Connection.

    healthCheck

    HealthCheck to be used in the Connection.

    params object (keys:string, values:string)

    Params to be used in the Connection.

    serviceName string

    ServiceName to be used in the Connection.

    port integer

    Port to connect to. If not provided, it defaults to the MariaDB port or to the first MaxScale listener.

    Required: {}

    imagePullPolicy

    ImagePullPolicy is the image pull policy. One of Always, Never or IfNotPresent. If not defined, it defaults to IfNotPresent.

    Enum: [Always Never IfNotPresent]

    command string array

    Command to be used in the Container.

    args string array

    Args to be used in the Container.

    env array

    Env represents the environment variables to be injected in a container.

    volumeMounts array

    VolumeMounts to be used in the Container.

    resources

    Resources describes the compute resource requirements.

    env array

    Env represents the environment variables to be injected in a container.

    envFrom array

    EnvFrom represents the references (via ConfigMap and Secrets) to environment variables to be injected in the container.

    volumeMounts array

    VolumeMounts to be used in the Container.

    livenessProbe

    LivenessProbe to be used in the Container.

    readinessProbe

    ReadinessProbe to be used in the Container.

    startupProbe

    StartupProbe to be used in the Container.

    resources

    Resources describes the compute resource requirements.

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    lifecycle

    Lifecycle are actions that the management system should take in response to container lifecycle events.

    Minimum: 0

    timeZone string

    TimeZone defines the timezone associated with the cron expression.

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    cleanupPolicy

    CleanupPolicy defines the behavior for cleaning up a SQL resource.

    Enum: [Skip Delete]

    mariaDbRef

    MariaDBRef is a reference to a MariaDB object.

    Required: {}

    characterSet string

    CharacterSet to use in the Database.

    utf8

    collate string

    Collate to use in the Database.

    utf8_general_ci

    name string

    Name overrides the default Database name provided by metadata.name.

    MaxLength: 80

  • VolumeSource

  • MaxScaleSpec

  • secretRef

  • MariaDBSpec

  • MaxScaleSpec

  • valueFrom

    secretKeyRef

    Enum: [Always Never IfNotPresent]

    imagePullSecrets array

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    args string array

    Args to be used in the Container.

    port integer

    Port where the exporter will be listening for connections.

    resources

    Resources describes the compute resource requirements.

    podMetadata

    PodMetadata defines extra metadata for the Pod.

    securityContext

    SecurityContext holds container-level security attributes.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    Enum: [Always Never IfNotPresent]

    imagePullSecrets array

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    inheritMetadata

    InheritMetadata defines the metadata to be inherited by children resources.

    host string

    Hostname of the external MariaDB.

    Required: {}

    port integer

    Port of the external MariaDB.

    3306

    username string

    Username is the username to connect to the external MariaDB.

    Required: {}

    passwordSecretKeyRef

    PasswordSecretKeyRef is a reference to the password to connect to the external MariaDB.

    tls

    TLS defines the PKI to be used with the external MariaDB.

    connection

    Connection defines a template to configure a Connection for the external MariaDB.

    versions string array

    Versions specifies the supported TLS versions for this MariaDB instance. By default, the MariaDB's default supported versions are used. See: https://mariadb.com/kb/en/ssltls-system-variables/#tls_version.

    items:Enum: [TLSv1.0 TLSv1.1 TLSv1.2 TLSv1.3]

    serverCASecretRef

    ServerCASecretRef is a reference to a Secret containing the server certificate authority keypair. It is used to establish trust and issue server certificates. One of: - Secret containing both the 'ca.crt' and 'ca.key' keys. This allows you to bring your own CA to Kubernetes to issue certificates. - Secret containing only the 'ca.crt' in order to establish trust. In this case, either serverCertSecretRef or serverCertIssuerRef must be provided. If not provided, a self-signed CA will be provisioned to issue the server certificate.

    serverCertSecretRef

    ServerCertSecretRef is a reference to a TLS Secret containing the server certificate. It is mutually exclusive with serverCertIssuerRef.

    serverCertIssuerRef

    ServerCertIssuerRef is a reference to a cert-manager issuer object used to issue the server certificate. cert-manager must be installed previously in the cluster. It is mutually exclusive with serverCertSecretRef. By default, the Secret field 'ca.crt' provisioned by cert-manager will be added to the trust chain. A custom trust bundle may be specified via serverCASecretRef.

    serverCertConfig

    ServerCertConfig allows configuring the server certificates, either issued by the operator or cert-manager. If not set, the default settings will be used.

    clientCASecretRef

    ClientCASecretRef is a reference to a Secret containing the client certificate authority keypair. It is used to establish trust and issue client certificates. One of: - Secret containing both the 'ca.crt' and 'ca.key' keys. This allows you to bring your own CA to Kubernetes to issue certificates. - Secret containing only the 'ca.crt' in order to establish trust. In this case, either clientCertSecretRef or clientCertIssuerRef fields must be provided. If not provided, a self-signed CA will be provisioned to issue the client certificate.

    clientCertSecretRef

    ClientCertSecretRef is a reference to a TLS Secret containing the client certificate. It is mutually exclusive with clientCertIssuerRef.

    clientCertIssuerRef

    ClientCertIssuerRef is a reference to a cert-manager issuer object used to issue the client certificate. cert-manager must be installed previously in the cluster. It is mutually exclusive with clientCertSecretRef. By default, the Secret field 'ca.crt' provisioned by cert-manager will be added to the trust chain. A custom trust bundle may be specified via clientCASecretRef.

    clientCertConfig

    ClientCertConfig allows configuring the client certificates, either issued by the operator or cert-manager. If not set, the default settings will be used.

    galeraSSTEnabled boolean

    GaleraSSTEnabled determines whether Galera SST connections should use TLS. It disabled by default.

    galeraServerSSLMode string

    GaleraServerSSLMode defines the server SSL mode for a Galera Enterprise cluster. This field is only supported and applicable for Galera Enterprise >= 10.6 instances. Refer to the MariaDB Enterprise docs for more detail: https://mariadb.com/docs/galera-cluster/galera-security/mariadb-enterprise-cluster-security#wsrep-tls-modes

    Enum: [PROVIDER SERVER SERVER_X509]

    galeraClientSSLMode string

    GaleraClientSSLMode defines the client SSL mode for a Galera Enterprise cluster. This field is only supported and applicable for Galera Enterprise >= 10.6 instances. Refer to the MariaDB Enterprise docs for more detail: https://mariadb.com/docs/galera-cluster/galera-security/mariadb-enterprise-cluster-security#sst-tls-modes

    Enum: [DISABLED REQUIRED VERIFY_CA VERIFY_IDENTITY]

    serverCertAdditionalNames string array

    ServerCertAdditionalNames is a list of additional certificate common names

    mutual boolean

    Mutual specifies whether TLS must be mutual between server and client for external connections. When set to false, the client certificate will not be sent during the TLS handshake. It is enabled by default.

    Enum: [rsync mariabackup mysqldump]

    availableWhenDonor boolean

    AvailableWhenDonor indicates whether a donor node should be responding to queries. It defaults to false.

    galeraLibPath string

    GaleraLibPath is a path inside the MariaDB image to the wsrep provider plugin. It is defaulted if not provided. More info: https://galeracluster.com/library/documentation/mysql-wsrep-options.html#wsrep-provider.

    replicaThreads integer

    ReplicaThreads is the number of replica threads used to apply Galera write sets in parallel. More info: https://mariadb.com/kb/en/galera-cluster-system-variables/#wsrep_slave_threads.

    providerOptions object (keys:string, values:string)

    ProviderOptions is map of Galera configuration parameters. More info: https://mariadb.com/kb/en/galera-cluster-system-variables/#wsrep_provider_options.

    agent

    Agent is a sidecar agent that co-operates with mariadb-enterprise-operator.

    recovery

    GaleraRecovery is the recovery process performed by the operator whenever the Galera cluster is not healthy. More info: https://galeracluster.com/library/documentation/crash-recovery.html.

    initContainer

    InitContainer is an init container that runs in the MariaDB Pod and co-operates with mariadb-enterprise-operator.

    initJob

    InitJob defines a Job that co-operates with mariadb-enterprise-operator by performing initialization tasks.

    config

    GaleraConfig defines storage options for the Galera configuration files.

    clusterName string

    ClusterName is the name of the cluster to be used in the Galera config file.

    gtidDomainId integer

    GtidDomainID is the domain ID to be used in GTID mode, enabled when the multi-cluster topology is used. For example: if you set this to 0, the 'wsrep_gtid_domain_id' will be 0, while the replicas (if 3) will have 'gtid_domain_id' 1,2,3. Make sure it has a different value on each the member of a multi-cluster topology. See: https://mariadb.com/docs/galera-cluster/high-availability/using-mariadb-replication-with-mariadb-galera-cluster/configuring-mariadb-replication-between-two-mariadb-galera-clusters

    serverId integer

    ServerID is the server ID to be used in GTID mode, enabled when the multi-cluster topology is used. Make sure it has a different value on each the member of a multi-cluster topology. See: https://mariadb.com/docs/galera-cluster/high-availability/using-mariadb-replication-with-mariadb-galera-cluster/configuring-mariadb-replication-between-two-mariadb-galera-clusters

    replPasswordSecretKeyRef

    ReplPasswordSecretKeyRef provides a reference to the Secret to use as password for the replication user. This will be utilized as password of the replication user, when the multi-cluster topology is enabled. By default, a random password will be generated.

    enabled boolean

    Enabled is a flag to enable Galera.

    clusterMonitorInterval

    ClusterMonitorInterval represents the interval used to monitor the Galera cluster health.

    clusterHealthyTimeout

    ClusterHealthyTimeout represents the duration at which a Galera cluster, that consistently failed health checks, is considered unhealthy, and consequently the Galera recovery process will be initiated by the operator.

    clusterBootstrapTimeout

    ClusterBootstrapTimeout is the time limit for bootstrapping a cluster. Once this timeout is reached, the Galera recovery state is reset and a new cluster bootstrap will be attempted.

    clusterUpscaleTimeout

    ClusterUpscaleTimeout represents the maximum duration for upscaling the cluster's StatefulSet during the recovery process.

    clusterDownscaleTimeout

    ClusterDownscaleTimeout represents the maximum duration for downscaling the cluster's StatefulSet during the recovery process.

    podRecoveryTimeout

    PodRecoveryTimeout is the time limit for recevorying the sequence of a Pod during the cluster recovery.

    podSyncTimeout

    PodSyncTimeout is the time limit for a Pod to join the cluster after having performed a cluster bootstrap during the cluster recovery.

    forceClusterBootstrapInPod string

    ForceClusterBootstrapInPod allows you to manually initiate the bootstrap process in a specific Pod. IMPORTANT: Use this option only in exceptional circumstances. Not selecting the Pod with the highest sequence number may result in data loss. IMPORTANT: Ensure you unset this field after completing the bootstrap to allow the operator to choose the appropriate Pod to bootstrap from in an event of cluster recovery.

    job

    Job defines a Job that co-operates with mariadb-enterprise-operator by performing the Galera cluster recovery .

    podAffinity boolean

    PodAffinity indicates whether the recovery Jobs should run in the same Node as the MariaDB Pods. It defaults to true.

    Enum: [rsync mariabackup mysqldump]

    availableWhenDonor boolean

    AvailableWhenDonor indicates whether a donor node should be responding to queries. It defaults to false.

    galeraLibPath string

    GaleraLibPath is a path inside the MariaDB image to the wsrep provider plugin. It is defaulted if not provided. More info: https://galeracluster.com/library/documentation/mysql-wsrep-options.html#wsrep-provider.

    replicaThreads integer

    ReplicaThreads is the number of replica threads used to apply Galera write sets in parallel. More info: https://mariadb.com/kb/en/galera-cluster-system-variables/#wsrep_slave_threads.

    providerOptions object (keys:string, values:string)

    ProviderOptions is map of Galera configuration parameters. More info: https://mariadb.com/kb/en/galera-cluster-system-variables/#wsrep_provider_options.

    agent

    Agent is a sidecar agent that co-operates with mariadb-enterprise-operator.

    recovery

    GaleraRecovery is the recovery process performed by the operator whenever the Galera cluster is not healthy. More info: https://galeracluster.com/library/documentation/crash-recovery.html.

    initContainer

    InitContainer is an init container that runs in the MariaDB Pod and co-operates with mariadb-enterprise-operator.

    initJob

    InitJob defines a Job that co-operates with mariadb-enterprise-operator by performing initialization tasks.

    config

    GaleraConfig defines storage options for the Galera configuration files.

    clusterName string

    ClusterName is the name of the cluster to be used in the Galera config file.

    gtidDomainId integer

    GtidDomainID is the domain ID to be used in GTID mode, enabled when the multi-cluster topology is used. For example: if you set this to 0, the 'wsrep_gtid_domain_id' will be 0, while the replicas (if 3) will have 'gtid_domain_id' 1,2,3. Make sure it has a different value on each the member of a multi-cluster topology. See: https://mariadb.com/docs/galera-cluster/high-availability/using-mariadb-replication-with-mariadb-galera-cluster/configuring-mariadb-replication-between-two-mariadb-galera-clusters

    serverId integer

    ServerID is the server ID to be used in GTID mode, enabled when the multi-cluster topology is used. Make sure it has a different value on each the member of a multi-cluster topology. See: https://mariadb.com/docs/galera-cluster/high-availability/using-mariadb-replication-with-mariadb-galera-cluster/configuring-mariadb-replication-between-two-mariadb-galera-clusters

    replPasswordSecretKeyRef

    ReplPasswordSecretKeyRef provides a reference to the Secret to use as password for the replication user. This will be utilized as password of the replication user, when the multi-cluster topology is enabled. By default, a random password will be generated.

  • MariadbMetrics

  • MaxScaleAuth

  • ReplicaReplication

  • generate boolean

    Generate indicates whether the Secret should be generated if the Secret referenced is not present.

    false

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    cleanupPolicy

    CleanupPolicy defines the behavior for cleaning up a SQL resource.

    Enum: [Skip Delete]

    mariaDbRef

    MariaDBRef is a reference to a MariaDB object.

    Required: {}

    privileges string array

    Privileges to use in the Grant.

    MinItems: 1 Required: {}

    database string

    Database to use in the Grant.

    *

    table string

    Table to use in the Grant.

    *

    username string

    Username to use in the Grant.

    Required: {}

    host string

    Host to use in the Grant. It can be localhost, an IP or '%'.

    grantOption boolean

    GrantOption to use in the Grant.

    false

    host string

    scheme

  • VolumeSource

  • env array

    Env represents the environment variables to be injected in a container.

    envFrom array

    EnvFrom represents the references (via ConfigMap and Secrets) to environment variables to be injected in the container.

    volumeMounts array

    VolumeMounts to be used in the Container.

    livenessProbe

    LivenessProbe to be used in the Container.

    readinessProbe

    ReadinessProbe to be used in the Container.

    startupProbe

    StartupProbe to be used in the Container.

    resources

    Resources describes the compute resource requirements.

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    lifecycle

    Lifecycle are actions that the management system should take in response to container lifecycle events.

    image string

    Image name to be used by the MariaDB instances. The supported format is <image>:<tag>.

    Required: {}

    imagePullPolicy

    ImagePullPolicy is the image pull policy. One of Always, Never or IfNotPresent. If not defined, it defaults to IfNotPresent.

    Enum: [Always Never IfNotPresent]

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    resources

    Resources describes the compute resource requirements.

    args string array

    Args to be used in the Container.

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    values string array

  • MaxScaleSpec

  • sleep

  • ConfigMapVolumeSource

  • ConnectionSpec

  • EnvFromSource

  • Exporter

  • ExternalMariaDBSpec

  • ExternalTLS

  • GeneratedSecretKeyRef

  • JobPodTemplate

  • MariaDBPodTemplate

  • MariaDBSpec

  • MaxScalePodTemplate

  • MaxScaleSpec

  • MaxScaleTLS

  • PhysicalBackupPodTemplate

  • PhysicalBackupSpec

  • PointInTimeRecoverySpec

  • ReplicaBootstrapFrom

  • RestoreSource

  • RestoreSpec

  • SecretKeySelector

  • SqlJobSpec

  • TLS

  • metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    drainConnections boolean

    DrainConnections determines whether all connections in MariaDB should be drained after drainGracePeriodSeconds.

    drainGracePeriodSeconds integer

    DrainGracePeriodSeconds defines the grace period in seconds before a connection in MariaDB is drained.

    30

    readOnly boolean

    ReadOnly will allow only read statements to be performed on the resource.

    initContainers array

    InitContainers to be used in the Pod.

    sidecarContainers array

    SidecarContainers to be used in the Pod.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    volumes array

    Volumes to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    topologySpreadConstraints array

    TopologySpreadConstraints to be used in the Pod.

    enableServiceLinks boolean

    EnableServiceLinks to be used in the Pod.

    terminationGracePeriodSeconds integer

    TerminationGracePeriodSeconds to be used in the Pod.

  • MaxScaleSpec

  • PhysicalBackupSpec

  • RestoreSpec

  • SqlJobSpec

  • UserSpec

  • kind string

    Kind of the referent.

    waitForIt boolean

    WaitForIt indicates whether the controller using this reference should wait for MariaDB to be ready.

    true

    env array

    Env represents the environment variables to be injected in a container.

    envFrom array

    EnvFrom represents the references (via ConfigMap and Secrets) to environment variables to be injected in the container.

    volumeMounts array

    VolumeMounts to be used in the Container.

    livenessProbe

    LivenessProbe to be used in the Container.

    readinessProbe

    ReadinessProbe to be used in the Container.

    startupProbe

    StartupProbe to be used in the Container.

    resources

    Resources describes the compute resource requirements.

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    lifecycle

    Lifecycle are actions that the management system should take in response to container lifecycle events.

    podMetadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets array

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    initContainers array

    InitContainers to be used in the Pod.

    sidecarContainers array

    SidecarContainers to be used in the Pod.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    volumes array

    Volumes to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    topologySpreadConstraints array

    TopologySpreadConstraints to be used in the Pod.

    enableServiceLinks boolean

    EnableServiceLinks to be used in the Pod.

    terminationGracePeriodSeconds integer

    TerminationGracePeriodSeconds to be used in the Pod.

    suspend boolean

    Suspend indicates whether the current resource should be suspended or not. This can be useful for maintenance, as disabling the reconciliation prevents the operator from interfering with user operations during maintenance activities.

    false

    image string

    Image name to be used by the MariaDB instances. The supported format is <image>:<tag>. Only MariaDB official images are supported.

    imagePullPolicy

    ImagePullPolicy is the image pull policy. One of Always, Never or IfNotPresent. If not defined, it defaults to IfNotPresent.

    Enum: [Always Never IfNotPresent]

    inheritMetadata

    InheritMetadata defines the metadata to be inherited by children resources.

    rootPasswordSecretKeyRef

    RootPasswordSecretKeyRef is a reference to a Secret key containing the root password.

    rootEmptyPassword boolean

    RootEmptyPassword indicates if the root password should be empty. Don't use this feature in production, it is only intended for development and test environments.

    database string

    Database is the name of the initial Database.

    username string

    Username is the initial username to be created by the operator once MariaDB is ready. The initial User will have ALL PRIVILEGES in the initial Database.

    passwordSecretKeyRef

    PasswordSecretKeyRef is a reference to a Secret that contains the password to be used by the initial User. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password.

    passwordHashSecretKeyRef

    PasswordHashSecretKeyRef is a reference to the password hash to be used by the initial User. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password hash. It requires the 'strict-password-validation=false' option to be set. See: https://mariadb.com/docs/server/server-management/variables-and-modes/server-system-variables#strict_password_validation.

    passwordPlugin

    PasswordPlugin is a reference to the password plugin and arguments to be used by the initial User. It requires the 'strict-password-validation=false' option to be set. See: https://mariadb.com/docs/server/server-management/variables-and-modes/server-system-variables#strict_password_validation.

    cleanupPolicy

    CleanupPolicy defines the behavior for cleaning up the initial User, Database, and Grant created by the operator.

    Enum: [Skip Delete]

    myCnf string

    MyCnf allows to specify the my.cnf file mounted by Mariadb. Updating this field will trigger an update to the Mariadb resource.

    myCnfConfigMapKeyRef

    MyCnfConfigMapKeyRef is a reference to the my.cnf config file provided via a ConfigMap. If not provided, it will be defaulted with a reference to a ConfigMap containing the MyCnf field. If the referred ConfigMap is labeled with "enterprise.mariadb.com/watch", an update to the Mariadb resource will be triggered when the ConfigMap is updated.

    timeZone string

    TimeZone sets the default timezone. If not provided, it defaults to SYSTEM and the timezone data is not loaded.

    bootstrapFrom

    BootstrapFrom defines a source to bootstrap from.

    storage

    Storage defines the storage options to be used for provisioning the PVCs mounted by MariaDB.

    metrics

    Metrics configures metrics and how to scrape them.

    tls

    TLS defines the PKI to be used with MariaDB.

    replication

    Replication configures high availability via replication. This feature is still in alpha, use Galera if you are looking for a more production-ready HA.

    galera

    Galera configures high availability via Galera.

    multiCluster

    MultiCluster configures the multi-cluster topology.

    maxScaleRef

    MaxScaleRef is a reference to a MaxScale resource to be used with the current MariaDB. Providing this reference implies delegating high availability tasks such as primary failover to MaxScale.

    pointInTimeRecoveryRef

    PointInTimeRecoveryRef is a reference to a PointInTimeRecovery resource to be used with the current MariaDB. Providing this reference implies configuring binary logs in the MariaDB instance and binary log archival in the sidecar agent.

    replicas integer

    Replicas indicates the number of desired instances.

    1

    replicasAllowEvenNumber boolean

    disables the validation check for an odd number of replicas.

    false

    port integer

    Port where the instances will be listening for connections.

    3306

    servicePorts array

    ServicePorts is the list of additional named ports to be added to the Services created by the operator.

    podDisruptionBudget

    PodDisruptionBudget defines the budget for replica availability.

    updateStrategy

    UpdateStrategy defines how a MariaDB resource is updated.

    service

    Service defines a template to configure the general Service object. The network traffic of this Service will be routed to all Pods.

    connection

    Connection defines a template to configure the general Connection object. This Connection provides the initial User access to the initial Database. It will make use of the Service to route network traffic to all Pods.

    primaryService

    PrimaryService defines a template to configure the primary Service object. The network traffic of this Service will be routed to the primary Pod.

    primaryConnection

    PrimaryConnection defines a template to configure the primary Connection object. This Connection provides the initial User access to the initial Database. It will make use of the PrimaryService to route network traffic to the primary Pod.

    secondaryService

    SecondaryService defines a template to configure the secondary Service object. The network traffic of this Service will be routed to the secondary Pods.

    secondaryConnection

    SecondaryConnection defines a template to configure the secondary Connection object. This Connection provides the initial User access to the initial Database. It will make use of the SecondaryService to route network traffic to the secondary Pods.

    maintenance

    Maintenance defines different capabilities of the operator to allow for maintenance to be performed on the DB. Not to be confused with suspend, maintenance does not interfere with the normal reconciliation of the operator.

    csi

    hostPath

    persistentVolumeClaim

    secret

    configMap

    ephemeral

    name string

    csi

    hostPath

    persistentVolumeClaim

    secret

    configMap

    ephemeral

    serviceMonitor

    ServiceMonitor defines the ServiceMonior object.

    username string

    Username is the username of the monitoring user used by the exporter.

    passwordSecretKeyRef

    PasswordSecretKeyRef is a reference to the password of the monitoring user used by the exporter. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password.

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    adminPasswordSecretKeyRef

    AdminPasswordSecretKeyRef is Secret key reference to the admin password to call the admin REST API. It is defaulted if not provided.

    deleteDefaultAdmin boolean

    DeleteDefaultAdmin determines whether the default admin user should be deleted after the initial configuration. If not provided, it defaults to true.

    metricsUsername string

    MetricsUsername is an metrics username to call the REST API. It is defaulted if metrics are enabled.

    metricsPasswordSecretKeyRef

    MetricsPasswordSecretKeyRef is Secret key reference to the metrics password to call the admib REST API. It is defaulted if metrics are enabled.

    clientUsername string

    ClientUsername is the user to connect to MaxScale. It is defaulted if not provided.

    clientPasswordSecretKeyRef

    ClientPasswordSecretKeyRef is Secret key reference to the password to connect to MaxScale. It is defaulted if not provided. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password.

    clientMaxConnections integer

    ClientMaxConnections defines the maximum number of connections that the client can establish. If HA is enabled, make sure to increase this value, as more MaxScale replicas implies more connections. It defaults to 30 times the number of MaxScale replicas.

    serverUsername string

    ServerUsername is the user used by MaxScale to connect to MariaDB server. It is defaulted if not provided.

    serverPasswordSecretKeyRef

    ServerPasswordSecretKeyRef is Secret key reference to the password used by MaxScale to connect to MariaDB server. It is defaulted if not provided. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password.

    serverMaxConnections integer

    ServerMaxConnections defines the maximum number of connections that the server can establish. If HA is enabled, make sure to increase this value, as more MaxScale replicas implies more connections. It defaults to 30 times the number of MaxScale replicas.

    monitorUsername string

    MonitorUsername is the user used by MaxScale monitor to connect to MariaDB server. It is defaulted if not provided.

    monitorPasswordSecretKeyRef

    MonitorPasswordSecretKeyRef is Secret key reference to the password used by MaxScale monitor to connect to MariaDB server. It is defaulted if not provided. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password.

    monitorMaxConnections integer

    MonitorMaxConnections defines the maximum number of connections that the monitor can establish. If HA is enabled, make sure to increase this value, as more MaxScale replicas implies more connections. It defaults to 30 times the number of MaxScale replicas.

    syncUsername string

    MonitoSyncUsernamerUsername is the user used by MaxScale config sync to connect to MariaDB server. It is defaulted when HA is enabled.

    syncPasswordSecretKeyRef

    SyncPasswordSecretKeyRef is Secret key reference to the password used by MaxScale config to connect to MariaDB server. It is defaulted when HA is enabled. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password.

    syncMaxConnections integer

    SyncMaxConnections defines the maximum number of connections that the sync can establish. If HA is enabled, make sure to increase this value, as more MaxScale replicas implies more connections. It defaults to 30 times the number of MaxScale replicas.

    sync

    Sync defines how to replicate configuration across MaxScale replicas. It is defaulted when HA is enabled.

    timeout

    Interval defines the config synchronization timeout. It is defaulted if not provided.

    port integer

    Port is the network port where the MaxScale server will listen.

    Required: {}

    protocol string

    Protocol is the MaxScale protocol to use when communicating with the client. If not provided, it defaults to MariaDBProtocol.

    params object (keys:string, values:string)

    Params defines extra parameters to pass to the listener. Any parameter supported by MaxScale may be specified here. See reference: https://mariadb.com/kb/en/mariadb-maxscale-2308-mariadb-maxscale-configuration-guide/#listener_1.

    serviceMonitor

    ServiceMonitor defines the ServiceMonior object.

    module

    Module is the module to use to monitor MariaDB servers. It is mandatory when no MariaDB reference is provided.

    interval

    Interval used to monitor MariaDB servers. It is defaulted if not provided.

    cooperativeMonitoring

    CooperativeMonitoring enables coordination between multiple MaxScale instances running monitors. It is defaulted when HA is enabled.

    Enum: [majority_of_all majority_of_running]

    params object (keys:string, values:string)

    Params defines extra parameters to pass to the monitor. Any parameter supported by MaxScale may be specified here. See reference: https://mariadb.com/kb/en/mariadb-maxscale-2308-common-monitor-parameters/. Monitor specific parameter are also supported: https://mariadb.com/kb/en/mariadb-maxscale-2308-galera-monitor/#galera-monitor-optional-parameters. https://mariadb.com/kb/en/mariadb-maxscale-2308-mariadb-monitor/#configuration.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    topologySpreadConstraints array

    TopologySpreadConstraints to be used in the Pod.

    enableServiceLinks boolean

    EnableServiceLinks indicates whether information about services should be injected into pod's environment variables, matching the syntax of Docker links. Defaults to true if not specified. Set to false to disable injection of service link environment variables.

    Required: {}

    port integer

    Port is the network port of the MariaDB server. If not provided, it defaults to 3306.

    protocol string

    Protocol is the MaxScale protocol to use when communicating with this MariaDB server. If not provided, it defaults to MariaDBBackend.

    maintenance boolean

    Maintenance indicates whether the server is in maintenance mode.

    params object (keys:string, values:string)

    Params defines extra parameters to pass to the server. Any parameter supported by MaxScale may be specified here. See reference: https://mariadb.com/kb/en/mariadb-maxscale-2308-mariadb-maxscale-configuration-guide/#server_1.

    Required: {}

    router

    Router is the type of router to use.

    Enum: [readwritesplit readconnroute] Required: {}

    listener

    MaxScaleListener defines how the MaxScale server will listen for connections.

    Required: {}

    params object (keys:string, values:string)

    Params defines extra parameters to pass to the service. Any parameter supported by MaxScale may be specified here. See reference: https://mariadb.com/kb/en/mariadb-maxscale-2308-mariadb-maxscale-configuration-guide/#service_1. Router specific parameter are also supported: https://mariadb.com/kb/en/mariadb-maxscale-2308-readwritesplit/#configuration. https://mariadb.com/kb/en/mariadb-maxscale-2308-readconnroute/#configuration.

    env array

    Env represents the environment variables to be injected in a container.

    envFrom array

    EnvFrom represents the references (via ConfigMap and Secrets) to environment variables to be injected in the container.

    volumeMounts array

    VolumeMounts to be used in the Container.

    livenessProbe

    LivenessProbe to be used in the Container.

    readinessProbe

    ReadinessProbe to be used in the Container.

    startupProbe

    StartupProbe to be used in the Container.

    resources

    Resources describes the compute resource requirements.

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    lifecycle

    Lifecycle are actions that the management system should take in response to container lifecycle events.

    podMetadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets array

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    topologySpreadConstraints array

    TopologySpreadConstraints to be used in the Pod.

    enableServiceLinks boolean

    EnableServiceLinks indicates whether information about services should be injected into pod's environment variables, matching the syntax of Docker links. Defaults to true if not specified. Set to false to disable injection of service link environment variables.

    suspend boolean

    Suspend indicates whether the current resource should be suspended or not. This can be useful for maintenance, as disabling the reconciliation prevents the operator from interfering with user operations during maintenance activities.

    false

    mariaDbRef

    MariaDBRef is a reference to the MariaDB that MaxScale points to. It is used to initialize the servers field.

    primaryServer string

    PrimaryServer specifies the desired primary server. Setting this field triggers a switchover operation in MaxScale to the desired server. This option is only valid when using monitors that support switchover, currently limited to the MariaDB monitor.

    servers array

    Servers are the MariaDB servers to forward traffic to. It is required if 'spec.mariaDbRef' is not provided.

    image string

    Image name to be used by the MaxScale instances. The supported format is <image>:<tag>. Only MaxScale official images are supported.

    imagePullPolicy

    ImagePullPolicy is the image pull policy. One of Always, Never or IfNotPresent. If not defined, it defaults to IfNotPresent.

    Enum: [Always Never IfNotPresent]

    inheritMetadata

    InheritMetadata defines the metadata to be inherited by children resources.

    services array

    Services define how the traffic is forwarded to the MariaDB servers. It is defaulted if not provided.

    monitor

    Monitor monitors MariaDB server instances. It is required if 'spec.mariaDbRef' is not provided.

    admin

    Admin configures the admin REST API and GUI.

    config

    Config defines the MaxScale configuration.

    auth

    Auth defines the credentials required for MaxScale to connect to MariaDB.

    metrics

    Metrics configures metrics and how to scrape them.

    tls

    TLS defines the PKI to be used with MaxScale.

    connection

    Connection provides a template to define the Connection for MaxScale.

    replicas integer

    Replicas indicates the number of desired instances.

    1

    podDisruptionBudget

    PodDisruptionBudget defines the budget for replica availability.

    updateStrategy

    UpdateStrategy defines the update strategy for the StatefulSet object.

    kubernetesService

    KubernetesService defines a template for a Kubernetes Service object to connect to MaxScale.

    guiKubernetesService

    GuiKubernetesService defines a template for a Kubernetes Service object to connect to MaxScale's GUI.

    requeueInterval

    RequeueInterval is used to perform requeue reconciliations. If not defined, it defaults to 10s.

    maintenance

    Maintenance defines different capabilities of the operator to allow for maintenance to be performed on the DB. Not to be confused with suspend, maintenance does not interfere with the normal reconciliation of the operator.

    items:Enum: [TLSv10 TLSv11 TLSv12 TLSv13 MAX]

    serverVersions string array

    ServerVersions specifies the supported TLS versions in both the servers and listeners managed by this MaxScale instance. By default, the MaxScale's default supported versions are used. See: https://mariadb.com/kb/en/mariadb-maxscale-25-mariadb-maxscale-configuration-guide/#ssl_version.

    items:Enum: [TLSv10 TLSv11 TLSv12 TLSv13 MAX]

    adminCASecretRef

    AdminCASecretRef is a reference to a Secret containing the admin certificate authority keypair. It is used to establish trust and issue certificates for the MaxScale's administrative REST API and GUI. One of: - Secret containing both the 'ca.crt' and 'ca.key' keys. This allows you to bring your own CA to Kubernetes to issue certificates. - Secret containing only the 'ca.crt' in order to establish trust. In this case, either adminCertSecretRef or adminCertIssuerRef fields must be provided. If not provided, a self-signed CA will be provisioned to issue the server certificate.

    adminCertSecretRef

    AdminCertSecretRef is a reference to a TLS Secret used by the MaxScale's administrative REST API and GUI.

    adminCertIssuerRef

    AdminCertIssuerRef is a reference to a cert-manager issuer object used to issue the MaxScale's administrative REST API and GUI certificate. cert-manager must be installed previously in the cluster. It is mutually exclusive with adminCertSecretRef. By default, the Secret field 'ca.crt' provisioned by cert-manager will be added to the trust chain. A custom trust bundle may be specified via adminCASecretRef.

    adminCertConfig

    AdminCertConfig allows configuring the admin certificates, either issued by the operator or cert-manager. If not set, the default settings will be used.

    listenerCASecretRef

    ListenerCASecretRef is a reference to a Secret containing the listener certificate authority keypair. It is used to establish trust and issue certificates for the MaxScale's listeners. One of: - Secret containing both the 'ca.crt' and 'ca.key' keys. This allows you to bring your own CA to Kubernetes to issue certificates. - Secret containing only the 'ca.crt' in order to establish trust. In this case, either listenerCertSecretRef or listenerCertIssuerRef fields must be provided. If not provided, a self-signed CA will be provisioned to issue the listener certificate.

    listenerCertSecretRef

    ListenerCertSecretRef is a reference to a TLS Secret used by the MaxScale's listeners.

    listenerCertIssuerRef

    ListenerCertIssuerRef is a reference to a cert-manager issuer object used to issue the MaxScale's listeners certificate. cert-manager must be installed previously in the cluster. It is mutually exclusive with listenerCertSecretRef. By default, the Secret field 'ca.crt' provisioned by cert-manager will be added to the trust chain. A custom trust bundle may be specified via listenerCASecretRef.

    listenerCertConfig

    ListenerCertConfig allows configuring the listener certificates, either issued by the operator or cert-manager. If not set, the default settings will be used.

    serverCASecretRef

    ServerCASecretRef is a reference to a Secret containing the MariaDB server CA certificates. It is used to establish trust with MariaDB servers. The Secret should contain a 'ca.crt' key in order to establish trust. If not provided, and the reference to a MariaDB resource is set (mariaDbRef), it will be defaulted to the referred MariaDB CA bundle.

    serverCertSecretRef

    ServerCertSecretRef is a reference to a TLS Secret used by MaxScale to connect to the MariaDB servers. If not provided, and the reference to a MariaDB resource is set (mariaDbRef), it will be defaulted to the referred MariaDB client certificate (clientCertSecretRef).

    verifyPeerCertificate boolean

    VerifyPeerCertificate specifies whether the peer certificate's signature should be validated against the CA. It is disabled by default.

    verifyPeerHost boolean

    VerifyPeerHost specifies whether the peer certificate's SANs should match the peer host. It is disabled by default.

    replicationSSLEnabled boolean

    ReplicationSSLEnabled specifies whether the replication SSL is enabled. If enabled, the SSL options will be added to the server configuration. It is enabled by default when the referred MariaDB instance (via mariaDbRef) has replication enabled. If the MariaDB servers are manually provided by the user via the 'servers' field, this must be set by the user as well.

  • GaleraRecoveryJob

  • Job

  • JobPodTemplate

  • MariaDBPodTemplate

  • MariaDBSpec

  • MaxScalePodTemplate

  • MaxScaleSpec

  • PhysicalBackupPodTemplate

  • PhysicalBackupSpec

  • PhysicalBackupVolumeSnapshot

  • RestoreSpec

  • SecretTemplate

  • ServiceTemplate

  • SqlJobSpec

  • VolumeClaimTemplate

  • enabled boolean

    Enabled is a flag to enable the multi-cluster topology.

  • VolumeSource

  • readOnly boolean

    values string array

    pluginPasswordSecretKeyRef

    PluginPasswordSecretKeyRef is a reference to a PASSWORD('%s') argument to be provided to the authentication plugin for the User. This is mutually exclusive with pluginArgSecretKeyRef.

    resources

    storageClassName string

  • VolumeSource

  • metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    false

    immediate boolean

    Immediate indicates whether the first backup should be taken immediately after creating the PhysicalBackup.

    onDemand string

    OnDemand is an identifier used to trigger an on-demand backup. If the identifier is different than the one tracked under status.lastScheduleOnDemand, a new physical backup will be triggered.

    onPrimaryChange boolean

    OnPrimaryChange indicates whether a PhysicalBackup should be scheduled when the referred MariaDB has changed primary Pod.

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    podMetadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets array

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    mariaDbRef

    MariaDBRef is a reference to a MariaDB object.

    Required: {}

    target

    Target defines in which Pod the physical backups will be taken. It defaults to "Replica", meaning that the physical backups will only be taken in ready replicas.

    Enum: [Replica PreferReplica]

    compression

    Compression algorithm to be used in the Backup.

    Enum: [none bzip2 gzip]

    stagingStorage

    StagingStorage defines the temporary storage used to keep external backups (i.e. S3) while they are being processed. It defaults to an emptyDir volume, meaning that the backups will be temporarily stored in the node where the PhysicalBackup Job is scheduled. The staging area gets cleaned up after each backup is completed, consider this for sizing it appropriately.

    storage

    Storage defines the final storage for backups.

    Required: {}

    schedule

    Schedule defines when the PhysicalBackup will be taken.

    maxRetention

    MaxRetention defines the retention policy for backups. Old backups will be cleaned up by the Backup Job. It defaults to 30 days.

    timeout

    Timeout defines the maximum duration of a PhysicalBackup job or snapshot. If this duration is exceeded, the job or snapshot is considered expired and is deleted by the operator. A new job or snapshot will then be created according to the schedule. It defaults to 1 hour.

    podAffinity boolean

    PodAffinity indicates whether the Jobs should run in the same Node as the MariaDB Pods to be able to attach the PVC. It defaults to true.

    backoffLimit integer

    BackoffLimit defines the maximum number of attempts to successfully take a PhysicalBackup.

    restartPolicy

    RestartPolicy to be added to the PhysicalBackup Pod.

    OnFailure

    Enum: [Always OnFailure Never]

    inheritMetadata

    InheritMetadata defines the metadata to be inherited by children resources.

    successfulJobsHistoryLimit integer

    SuccessfulJobsHistoryLimit defines the maximum number of successful Jobs to be displayed. It defaults to 5.

    Minimum: 0

    failedJobsHistoryLimit integer

    FailedJobsHistoryLimit defines the maximum number of failed Jobs to be displayed. It defaults to 5.

    Minimum: 0

    logLevel string

    LogLevel to be used in the PhysicalBackup Job. It defaults to 'info'.

    info

    Enum: [debug info warn error dpanic panic fatal]

    persistentVolumeClaim

    PersistentVolumeClaim is a Kubernetes PVC specification.

    volume

    Volume is a Kubernetes volume specification.

    volumeSnapshot

    VolumeSnapshot is a Kubernetes VolumeSnapshot specification.

    Required: {}

  • MariaDBSpec

  • MaxScalePodTemplate

  • MaxScaleSpec

  • PhysicalBackupPodTemplate

  • PhysicalBackupSpec

  • RestoreSpec

  • SqlJobSpec

  • runAsGroup integer

    runAsNonRoot boolean

    supplementalGroups integer array

    fsGroup integer

    fsGroupChangePolicy

    seccompProfile

    appArmorProfile

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    Required: {}

    compression

    Compression algorithm to be used for compressing the binary logs. This field is immutable, it cannot be updated after creation.

    Enum: [none bzip2 gzip]

    archiveTimeout

    ArchiveTimeout defines the maximum duration for the binary log archival. If this duration is exceeded, the sidecar agent will log an error and it will be retried in the next archive cycle. It defaults to 1 hour.

    1h

    strictMode boolean

    StrictMode controls the behavior when a point-in-time restoration cannot reach the exact target time: When enabled: Returns an error and avoids replaying binary logs if target time is not reached. When disabled (default): Replays available binary logs until the last recoverable time. It logs logs an error if target time is not reached.

    archiveInterval

    ArchiveInterval defines the time interval at which the binary logs will be archived. It defaults to 10 minutes.

    10m

    maxParallel integer

    MaxParallel defines the maximum number of parallel workers, both for archiving and restoring the binary logs. It defaults to 1.

    1

    Minimum: 1

    maxRetention

    MaxRetention defines the retention policy for binary logs. Binary logs older than this duration will be cleaned up when the archival is completed. It is not set by default, meaning that old binary logs will not be cleaned up. This field is immutable, it cannot be updated after creation.

    autoFailoverDelay

    AutoFailoverDelay indicates the duration before performing an automatic primary failover. By default, no extra delay is added.

    autoSwitchoverOnGracefulShutdown boolean

    AutoSwitchoverOnGracefulShutdown indicates whether the operator should automatically trigger a switchover when the primary Pod is gracefully shutdown. This can include pod evictions, node draining, kubectl delete executions and other. It is enabled by default.

  • MaxScaleSpec

  • tcpSocket

    initialDelaySeconds integer

    timeoutSeconds integer

    periodSeconds integer

    successThreshold integer

    failureThreshold integer

    tcpSocket

    Enum: [CurrentPos SlavePos]

    connectionRetrySeconds integer

    ConnectionRetrySeconds is the number of seconds that the replica will wait between connection retries. See: https://mariadb.com/docs/server/reference/sql-statements/administrative-sql-statements/replication-statements/change-master-to#master_connect_retry.

    maxLagSeconds integer

    MaxLagSeconds is the maximum number of seconds that replicas are allowed to lag behind the primary. If a replica exceeds this threshold, it is marked as not ready and read queries will no longer be forwarded to it. If not provided, it defaults to 0, which means that replicas are not allowed to lag behind the primary (recommended). Lagged replicas will not be taken into account as candidates for the new primary during failover, and they will block other operations, such as switchover and upgrade. This field is not taken into account by MaxScale, you can define the maximum lag as router parameters. See: https://mariadb.com/docs/maxscale/reference/maxscale-routers/maxscale-readwritesplit#max_replication_lag.

    syncTimeout

    SyncTimeout defines the timeout for the synchronization phase during switchover and failover operations. During switchover, all replicas must be synced with the current primary before promoting the new primary. During failover, the new primary must be synced before being promoted as primary. This implies processing all the events in the relay log. When the timeout is reached, the operator restarts the operation from the beginning. It defaults to 10s. See: https://mariadb.com/docs/server/reference/sql-functions/secondary-functions/miscellaneous-functions/master_gtid_wait

    bootstrapFrom

    ReplicaBootstrapFrom defines the data sources used to bootstrap new replicas. This will be used as part of the scaling out and recovery operations, when new replicas are created. If not provided, scale out and recovery operations will return an error.

    recovery

    ReplicaRecovery defines how the replicas should be recovered after they enter an error state. This process deletes data from faulty replicas and recreates them using the source defined in the bootstrapFrom field. It is disabled by default, and it requires the bootstrapFrom field to be set.

    gtidStrictMode boolean

    GtidStrictMode determines whether the GTID strict mode is enabled. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/gtid#gtid_strict_mode. It is enabled by default.

    gtidDomainId integer

    GtidDomainID is gtid_domain_id for all of the MariaDB nodes. It is immutable. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/gtid#gtid_domain_id

    serverIdStartIndex integer

    ServerIDStartIndex sets the start index of the MariaDB nodes. Each subsequent replica will increment this by 1. It is immutable. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/replication-and-binary-log-system-variables#server_id

    semiSyncEnabled boolean

    SemiSyncEnabled determines whether semi-synchronous replication is enabled. Semi-synchronous replication requires that at least one replica should have sent an ACK to the primary node before committing the transaction back to the client. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/semisynchronous-replication It is enabled by default

    semiSyncAckTimeout

    SemiSyncAckTimeout for the replica to acknowledge transactions to the primary. It requires semi-synchronous replication to be enabled. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/semisynchronous-replication#rpl_semi_sync_master_timeout

    semiSyncWaitPoint

    SemiSyncWaitPoint determines whether the transaction should wait for an ACK after having synced the binlog (AfterSync) or after having committed to the storage engine (AfterCommit, the default). It requires semi-synchronous replication to be enabled. See: https://mariadb.com/kb/en/semisynchronous-replication/#rpl_semi_sync_master_wait_point.

    Enum: [AfterSync AfterCommit]

    syncBinlog integer

    SyncBinlog indicates after how many events the binary log is synchronized to the disk. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/replication-and-binary-log-system-variables#sync_binlog

    initContainer

    InitContainer is an init container that runs in the MariaDB Pod and co-operates with mariadb-enterprise-operator.

    agent

    Agent is a sidecar agent that runs in the MariaDB Pod and co-operates with mariadb-enterprise-operator.

    standaloneProbes boolean

    StandaloneProbes indicates whether to use the default non-HA startup and liveness probes. It is disabled by default

    enabled boolean

    Enabled is a flag to enable replication.

    gtidStrictMode boolean

    GtidStrictMode determines whether the GTID strict mode is enabled. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/gtid#gtid_strict_mode. It is enabled by default.

    gtidDomainId integer

    GtidDomainID is gtid_domain_id for all of the MariaDB nodes. It is immutable. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/gtid#gtid_domain_id

    serverIdStartIndex integer

    ServerIDStartIndex sets the start index of the MariaDB nodes. Each subsequent replica will increment this by 1. It is immutable. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/replication-and-binary-log-system-variables#server_id

    semiSyncEnabled boolean

    SemiSyncEnabled determines whether semi-synchronous replication is enabled. Semi-synchronous replication requires that at least one replica should have sent an ACK to the primary node before committing the transaction back to the client. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/semisynchronous-replication It is enabled by default

    semiSyncAckTimeout

    SemiSyncAckTimeout for the replica to acknowledge transactions to the primary. It requires semi-synchronous replication to be enabled. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/semisynchronous-replication#rpl_semi_sync_master_timeout

    semiSyncWaitPoint

    SemiSyncWaitPoint determines whether the transaction should wait for an ACK after having synced the binlog (AfterSync) or after having committed to the storage engine (AfterCommit, the default). It requires semi-synchronous replication to be enabled. See: https://mariadb.com/kb/en/semisynchronous-replication/#rpl_semi_sync_master_wait_point.

    Enum: [AfterSync AfterCommit]

    syncBinlog integer

    SyncBinlog indicates after how many events the binary log is synchronized to the disk. See: https://mariadb.com/docs/server/ha-and-performance/standard-replication/replication-and-binary-log-system-variables#sync_binlog

    initContainer

    InitContainer is an init container that runs in the MariaDB Pod and co-operates with mariadb-enterprise-operator.

    agent

    Agent is a sidecar agent that runs in the MariaDB Pod and co-operates with mariadb-enterprise-operator.

    standaloneProbes boolean

    StandaloneProbes indicates whether to use the default non-HA startup and liveness probes. It is disabled by default

  • Exporter

  • GaleraInitJob

  • GaleraRecoveryJob

  • InitContainer

  • Job

  • JobContainerTemplate

  • MariaDBSpec

  • MaxScaleSpec

  • PhysicalBackupSpec

  • RestoreSpec

  • SqlJobSpec

  • metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    volume

    Volume is a Kubernetes Volume object that contains a backup.

    targetRecoveryTime

    TargetRecoveryTime is a RFC3339 (1970-01-01T00:00:00Z) date and time that defines the point in time recovery objective. It is used to determine the closest restoration source in time.

    stagingStorage

    StagingStorage defines the temporary storage used to keep external backups (i.e. S3) while they are being processed. It defaults to an emptyDir volume, meaning that the backups will be temporarily stored in the node where the Restore Job is scheduled.

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    podMetadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets array

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    backupRef

    BackupRef is a reference to a Backup object. It has priority over S3 and Volume.

    s3

    S3 defines the configuration to restore backups from a S3 compatible storage. It has priority over Volume.

    volume

    Volume is a Kubernetes Volume object that contains a backup.

    targetRecoveryTime

    TargetRecoveryTime is a RFC3339 (1970-01-01T00:00:00Z) date and time that defines the point in time recovery objective. It is used to determine the closest restoration source in time.

    stagingStorage

    StagingStorage defines the temporary storage used to keep external backups (i.e. S3) while they are being processed. It defaults to an emptyDir volume, meaning that the backups will be temporarily stored in the node where the Restore Job is scheduled.

    mariaDbRef

    MariaDBRef is a reference to a MariaDB object.

    Required: {}

    database string

    Database defines the logical database to be restored. If not provided, all databases available in the backup are restored. IMPORTANT: The database must previously exist.

    logLevel string

    LogLevel to be used n the Backup Job. It defaults to 'info'.

    info

    Enum: [debug info warn error dpanic panic fatal]

    backoffLimit integer

    BackoffLimit defines the maximum number of attempts to successfully perform a Backup.

    5

    restartPolicy

    RestartPolicy to be added to the Backup Job.

    OnFailure

    Enum: [Always OnFailure Never]

    inheritMetadata

    InheritMetadata defines the metadata to be inherited by children resources.

  • RestoreSource

  • RestoreSpec

  • Required: {}

    region string

    Region is the S3 region name to use.

    prefix string

    Prefix indicates a folder/subfolder in the bucket. For example: mariadb/ or mariadb/backups. A trailing slash '/' is added if not provided.

    accessKeyIdSecretKeyRef

    AccessKeyIdSecretKeyRef is a reference to a Secret key containing the S3 access key id.

    secretAccessKeySecretKeyRef

    AccessKeyIdSecretKeyRef is a reference to a Secret key containing the S3 secret key.

    sessionTokenSecretKeyRef

    SessionTokenSecretKeyRef is a reference to a Secret key containing the S3 session token.

    tls

    TLS provides the configuration required to establish TLS connections with S3.

    ssec

    SSEC is a reference to a Secret containing the SSE-C (Server-Side Encryption with Customer-Provided Keys) key. The secret must contain a 32-byte key (256 bits) in the specified key. This enables server-side encryption where you provide and manage the encryption key.

    cleanupPolicy

    CleanupPolicy defines the behavior for cleaning up a SQL resource.

    Enum: [Skip Delete]

    false

  • GeneratedSecretKeyRef

  • MariaDBSpec

  • PasswordPlugin

  • S3

  • SSECConfig

  • SqlJobSpec

  • TLSConfig

  • UserSpec

  • format string

    Format to be used in the Secret.

    usernameKey string

    UsernameKey to be used in the Secret.

    passwordKey string

    PasswordKey to be used in the Secret.

    hostKey string

    HostKey to be used in the Secret.

    portKey string

    PortKey to be used in the Secret.

    databaseKey string

    DatabaseKey to be used in the Secret.

  • InitContainer

  • JobContainerTemplate

  • MariaDBSpec

  • MaxScaleSpec

  • PhysicalBackupSpec

  • RestoreSpec

  • SqlJobSpec

  • runAsUser integer

    runAsGroup integer

    runAsNonRoot boolean

    readOnlyRootFilesystem boolean

    allowPrivilegeEscalation boolean

    interval string

    Interval for scraping metrics.

    scrapeTimeout string

    ScrapeTimeout defines the timeout for scraping metrics.

    loadBalancerIP string

    LoadBalancerIP Service field.

    loadBalancerSourceRanges string array

    LoadBalancerSourceRanges Service field.

    externalTrafficPolicy

    ExternalTrafficPolicy Service field.

    sessionAffinity

    SessionAffinity Service field.

    allocateLoadBalancerNodePorts boolean

    AllocateLoadBalancerNodePorts Service field.

    loadBalancerClass string

    LoadBalancerClass Service field.

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    securityContext

    SecurityContext holds security configuration that will be applied to a container.

    podMetadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets array

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    podSecurityContext

    SecurityContext holds pod-level security attributes and common container settings.

    serviceAccountName string

    ServiceAccountName is the name of the ServiceAccount to be used by the Pods.

    affinity

    Affinity to be used in the Pod.

    nodeSelector object (keys:string, values:string)

    NodeSelector to be used in the Pod.

    tolerations array

    Tolerations to be used in the Pod.

    priorityClassName string

    PriorityClassName to be used in the Pod.

    successfulJobsHistoryLimit integer

    SuccessfulJobsHistoryLimit defines the maximum number of successful Jobs to be displayed.

    Minimum: 0

    failedJobsHistoryLimit integer

    FailedJobsHistoryLimit defines the maximum number of failed Jobs to be displayed.

    Minimum: 0

    timeZone string

    TimeZone defines the timezone associated with the cron expression.

    mariaDbRef

    MariaDBRef is a reference to a MariaDB object.

    Required: {}

    schedule

    Schedule defines when the SqlJob will be executed.

    username string

    Username to be impersonated when executing the SqlJob.

    Required: {}

    passwordSecretKeyRef

    UserPasswordSecretKeyRef is a reference to the impersonated user's password to be used when executing the SqlJob.

    Required: {}

    tlsCASecretRef

    TLSCACertSecretRef is a reference toa CA Secret used to establish trust when executing the SqlJob. If not provided, the CA bundle provided by the referred MariaDB is used.

    tlsClientCertSecretRef

    TLSClientCertSecretRef is a reference to a Kubernetes TLS Secret used as authentication when executing the SqlJob. If not provided, the client certificate provided by the referred MariaDB is used.

    database string

    Username to be used when executing the SqlJob.

    dependsOn array

    DependsOn defines dependencies with other SqlJob objectecs.

    sql string

    Sql is the script to be executed by the SqlJob.

    sqlConfigMapKeyRef

    SqlConfigMapKeyRef is a reference to a ConfigMap containing the Sql script. It is defaulted to a ConfigMap with the contents of the Sql field.

    backoffLimit integer

    BackoffLimit defines the maximum number of attempts to successfully execute a SqlJob.

    5

    restartPolicy

    RestartPolicy to be added to the SqlJob Pod.

    OnFailure

    Enum: [Always OnFailure Never]

    inheritMetadata

    InheritMetadata defines the metadata to be inherited by children resources.

  • RestoreSpec

  • storageClassName string

    StorageClassName to be used to provision the PVCS. It supersedes the 'StorageClassName' specified in 'VolumeClaimTemplate'. If not provided, the default 'StorageClass' configured in the cluster is used.

    resizeInUseVolumes boolean

    ResizeInUseVolumes indicates whether the PVCs can be resized. The 'StorageClassName' used should have 'allowVolumeExpansion' set to 'true' to allow resizing. It defaults to true.

    waitForVolumeResize boolean

    WaitForVolumeResize indicates whether to wait for the PVCs to be resized before marking the MariaDB object as ready. This will block other operations such as cluster recovery while the resize is in progress. It defaults to true.

    volumeClaimTemplate

    VolumeClaimTemplate provides a template to define the PVCs.

    pvcRetentionPolicy

    PersistentVolumeClaimRetentionPolicy describes the lifecycle of PVCs created from volumeClaimTemplates. By default, all persistent volume claims are created as needed and retained until manually deleted. This policy allows the lifecycle to be altered, for example by deleting PVCs when their statefulset is deleted, or when their pod is scaled down.

  • PhysicalBackupStorage

  • RestoreSource

  • RestoreSpec

  • StagingStorage

  • Volume

  • VolumeSource

  • csi

    hostPath

    persistentVolumeClaim

  • MaxScaleSpec

  • versions string array

    Versions specifies the supported TLS versions for this MariaDB instance. By default, the MariaDB's default supported versions are used. See: https://mariadb.com/kb/en/ssltls-system-variables/#tls_version.

    items:Enum: [TLSv1.0 TLSv1.1 TLSv1.2 TLSv1.3]

    serverCASecretRef

    ServerCASecretRef is a reference to a Secret containing the server certificate authority keypair. It is used to establish trust and issue server certificates. One of: - Secret containing both the 'ca.crt' and 'ca.key' keys. This allows you to bring your own CA to Kubernetes to issue certificates. - Secret containing only the 'ca.crt' in order to establish trust. In this case, either serverCertSecretRef or serverCertIssuerRef must be provided. If not provided, a self-signed CA will be provisioned to issue the server certificate.

    serverCertSecretRef

    ServerCertSecretRef is a reference to a TLS Secret containing the server certificate. It is mutually exclusive with serverCertIssuerRef.

    serverCertIssuerRef

    ServerCertIssuerRef is a reference to a cert-manager issuer object used to issue the server certificate. cert-manager must be installed previously in the cluster. It is mutually exclusive with serverCertSecretRef. By default, the Secret field 'ca.crt' provisioned by cert-manager will be added to the trust chain. A custom trust bundle may be specified via serverCASecretRef.

    serverCertConfig

    ServerCertConfig allows configuring the server certificates, either issued by the operator or cert-manager. If not set, the default settings will be used.

    clientCASecretRef

    ClientCASecretRef is a reference to a Secret containing the client certificate authority keypair. It is used to establish trust and issue client certificates. One of: - Secret containing both the 'ca.crt' and 'ca.key' keys. This allows you to bring your own CA to Kubernetes to issue certificates. - Secret containing only the 'ca.crt' in order to establish trust. In this case, either clientCertSecretRef or clientCertIssuerRef fields must be provided. If not provided, a self-signed CA will be provisioned to issue the client certificate.

    clientCertSecretRef

    ClientCertSecretRef is a reference to a TLS Secret containing the client certificate. It is mutually exclusive with clientCertIssuerRef.

    clientCertIssuerRef

    ClientCertIssuerRef is a reference to a cert-manager issuer object used to issue the client certificate. cert-manager must be installed previously in the cluster. It is mutually exclusive with clientCertSecretRef. By default, the Secret field 'ca.crt' provisioned by cert-manager will be added to the trust chain. A custom trust bundle may be specified via clientCASecretRef.

    clientCertConfig

    ClientCertConfig allows configuring the client certificates, either issued by the operator or cert-manager. If not set, the default settings will be used.

    galeraSSTEnabled boolean

    GaleraSSTEnabled determines whether Galera SST connections should use TLS. It disabled by default.

    galeraServerSSLMode string

    GaleraServerSSLMode defines the server SSL mode for a Galera Enterprise cluster. This field is only supported and applicable for Galera Enterprise >= 10.6 instances. Refer to the MariaDB Enterprise docs for more detail: https://mariadb.com/docs/galera-cluster/galera-security/mariadb-enterprise-cluster-security#wsrep-tls-modes

    Enum: [PROVIDER SERVER SERVER_X509]

    galeraClientSSLMode string

    GaleraClientSSLMode defines the client SSL mode for a Galera Enterprise cluster. This field is only supported and applicable for Galera Enterprise >= 10.6 instances. Refer to the MariaDB Enterprise docs for more detail: https://mariadb.com/docs/galera-cluster/galera-security/mariadb-enterprise-cluster-security#sst-tls-modes

    Enum: [DISABLED REQUIRED VERIFY_CA VERIFY_IDENTITY]

    serverCertAdditionalNames string array

    ServerCertAdditionalNames is a list of additional certificate common names

    issuer string

    Issuer indicates that the TLS certificate provided by the user must be issued by a specific issuer.

    subject string

    Subject indicates that the TLS certificate provided by the user must have a specific subject.

    whenUnsatisfiable

    labelSelector

    minDomains integer

    nodeAffinityPolicy

    nodeTaintsPolicy

    matchLabelKeys string array

    autoUpdateDataPlane boolean

    AutoUpdateDataPlane indicates whether the Galera data-plane version (agent and init containers) should be automatically updated based on the operator version. It defaults to false. Updating the operator will trigger updates on all the MariaDB instances that have this flag set to true. Thus, it is recommended to progressively set this flag after having updated the operator.

    Never

    NeverUpdateType indicates that the StatefulSet will never be updated. This can be used to roll out updates progressively to a fleet of instances.

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

    spec

    cleanupPolicy

    CleanupPolicy defines the behavior for cleaning up a SQL resource.

    Enum: [Skip Delete]

    mariaDbRef

    MariaDBRef is a reference to a MariaDB object.

    Required: {}

    passwordSecretKeyRef

    PasswordSecretKeyRef is a reference to the password to be used by the User. If not provided, the account will be locked and the password will expire. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password.

    passwordHashSecretKeyRef

    PasswordHashSecretKeyRef is a reference to the password hash to be used by the User. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the password hash. It requires the 'strict-password-validation=false' option to be set. See: https://mariadb.com/docs/server/server-management/variables-and-modes/server-system-variables#strict_password_validation.

    passwordPlugin

    PasswordPlugin is a reference to the password plugin and arguments to be used by the User. It requires the 'strict-password-validation=false' option to be set. See: https://mariadb.com/docs/server/server-management/variables-and-modes/server-system-variables#strict_password_validation.

    require

    Require specifies TLS requirements for the user to connect. See: https://mariadb.com/kb/en/securing-connections-for-client-and-server/#requiring-tls.

    maxUserConnections integer

    MaxUserConnections defines the maximum number of simultaneous connections that the User can establish.

    10

    name string

    Name overrides the default name provided by metadata.name.

    MaxLength: 80

    host string

    Host related to the User.

    MaxLength: 255

    resources

    storageClassName string

    metadata

    Refer to Kubernetes API documentation for fields of metadata.

  • MariaDBSpec

  • MaxScaleSpec

  • mountPath string

    subPath string

    csi

    hostPath

    persistentVolumeClaim

    secret

    configMap

    podAntiAffinity PodAntiAffinity

    nodeAffinity NodeAffinity

    podAntiAffinity PodAntiAffinity

    nodeAffinity NodeAffinity

    command string array

    Command to be used in the Container.

    args string array

    containerName string

    ContainerName is the name of the storage container.

    Required: {}

    serviceURL string

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    Logical

    BackupContentTypeLogical represents a logical backup created using mariadb-dump.

    Physical

    BackupContentTypePhysical represents a physical backup created using mariadb-backup or a VolumeSnapshot.

    args string array

    Args to be used in the Container.

    resources ResourceRequirements

    s3 S3

    S3 defines the configuration to store backups in a S3 compatible storage.

    persistentVolumeClaim PersistentVolumeClaimSpec

    enabled boolean

    Enabled is a flag to enable BasicAuth

    username string

    backupRef TypedLocalObjectReference

    BackupRef is reference to a backup object. If the Kind is not specified, a logical Backup is assumed. This field takes precedence over S3 and Volume sources.

    volumeSnapshotRef LocalObjectReference

    driver string

    readOnly boolean

    caLifetime Duration

    CALifetime defines the CA certificate validity.

    certLifetime Duration

    Skip

    CleanupPolicySkip indicates that the resource will NOT be deleted from the database after the CR is deleted.

    Delete

    CleanupPolicyDelete indicates that the resource will be deleted from the database after the CR is deleted.

    none

    No compression

    bzip2

    Bzip2 compression. Good compression ratio, but slower compression/decompression speed compared to gzip.

    gzip

    Gzip compression. Good compression/decompression speed, but worse compression ratio compared to bzip2.

    name string

    key string

    name string

    defaultMode integer

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    secretName string

    SecretName to be used in the Connection.

    secretTemplate SecretTemplate

    secretName string

    SecretName to be used in the Connection.

    secretTemplate SecretTemplate

    name string

    Name to be given to the container.

    image string

    command string array

    Command to be used in the Container.

    args string array

    majority_of_all

    CooperativeMonitoringMajorityOfAll requires a lock from the majority of the MariaDB servers, even the ones that are down.

    majority_of_running

    CooperativeMonitoringMajorityOfRunning requires a lock from the majority of the MariaDB servers.

    cordon boolean

    Cordon blocks connections to the resource.

    successfulJobsHistoryLimit integer

    SuccessfulJobsHistoryLimit defines the maximum number of successful Jobs to be displayed.

    Minimum: 0

    failedJobsHistoryLimit integer

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    requeueInterval Duration

    RequeueInterval is used to perform requeue reconciliations.

    retryInterval Duration

    medium StorageMedium

    sizeLimit Quantity

    prefix string

    configMapRef LocalObjectReference

    name string

    Name of the environment variable. Must be a C_IDENTIFIER.

    value string

    fieldRef ObjectFieldSelector

    configMapKeyRef ConfigMapKeySelector

    volumeClaimTemplate VolumeClaimTemplate

    command string array

    image string

    Image name to be used as metrics exporter. The supported format is <image>:<tag>.

    imagePullPolicy PullPolicy

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    image string

    Image name to be used to perform operations on the external MariaDB, for example, for taking backups. The supported format is <image>:<tag>. Only MariaDB official images are supported. If not provided, the MariaDB image version be inferred by the operator in runtime. The default MariaDB image will be used in this case,

    imagePullPolicy PullPolicy

    enabled boolean

    Enabled indicates whether TLS is enabled, determining if certificates should be issued and mounted to the MariaDB instance. It is enabled by default.

    required boolean

    primary PrimaryGalera

    Primary is the Galera configuration for the primary node.

    sst SST

    reuseStorageVolume boolean

    ReuseStorageVolume indicates that storage volume used by MariaDB should be reused to store the Galera configuration files. It defaults to false, which implies that a dedicated volume for the Galera configuration files is provisioned.

    volumeClaimTemplate VolumeClaimTemplate

    metadata Metadata

    Refer to Kubernetes API documentation for fields of metadata.

    resources ResourceRequirements

    enabled boolean

    Enabled is a flag to enable GaleraRecovery.

    minClusterSize IntOrString

    metadata Metadata

    Refer to Kubernetes API documentation for fields of metadata.

    resources ResourceRequirements

    primary PrimaryGalera

    Primary is the Galera configuration for the primary node.

    sst SST

    name string

    key string

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    requeueInterval Duration

    RequeueInterval is used to perform requeue reconciliations.

    retryInterval Duration

    CurrentPos

    GtidCurrentPos indicates the union of gtid_binlog_pos and gtid_slave_pos will be used when replicating from master.

    SlavePos

    GtidSlavePos indicates that gtid_slave_pos will be used when replicating from master.

    path string

    port IntOrString

    interval Duration

    Interval used to perform health checks.

    retryInterval Duration

    path string

    type string

    command string array

    Command to be used in the Container.

    args string array

    metadata Metadata

    Refer to Kubernetes API documentation for fields of metadata.

    affinity AffinityConfig

    args string array

    Args to be used in the Container.

    resources ResourceRequirements

    podMetadata Metadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets LocalObjectReference array

    enabled boolean

    Enabled is a flag to enable KubernetesAuth

    authDelegatorRoleName string

    matchLabels object (keys:string, values:string)

    matchExpressions LabelSelectorRequirement array

    key string

    operator LabelSelectorOperator

    postStart LifecycleHandler

    preStop LifecycleHandler

    exec ExecAction

    httpGet HTTPGetAction

    name string

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    cordon boolean

    Cordon blocks connections to the resource.

    enabled boolean

    podMetadata Metadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets LocalObjectReference array

    name string

    namespace string

    command string array

    Command to be used in the Container.

    args string array

    emptyDir EmptyDirVolumeSource

    nfs NFSVolumeSource

    emptyDir EmptyDirVolumeSource

    nfs NFSVolumeSource

    enabled boolean

    Enabled is a flag to enable Metrics

    exporter Exporter

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    port integer

    Port where the admin REST API and GUI will be exposed.

    guiEnabled boolean

    generate boolean

    Generate defies whether the operator should generate users and grants for MaxScale to work. It only supports MariaDBs specified via spec.mariaDbRef.

    adminUsername string

    params object (keys:string, values:string)

    Params is a key value pair of parameters to be used in the MaxScale static configuration file. Any parameter supported by MaxScale may be specified here. See reference: https://mariadb.com/kb/en/mariadb-maxscale-2308-mariadb-maxscale-configuration-guide/#global-settings.

    volumeClaimTemplate VolumeClaimTemplate

    database string

    Database is the MariaDB logical database where the 'maxscale_config' table will be created in order to persist and synchronize config changes. If not provided, it defaults to 'mysql'.

    interval Duration

    suspend boolean

    Suspend indicates whether the current resource should be suspended or not. This can be useful for maintenance, as disabling the reconciliation prevents the operator from interfering with user operations during maintenance activities.

    false

    name string

    cordon boolean

    Cordon blocks connections to the resource.

    enabled boolean

    enabled boolean

    Enabled is a flag to enable Metrics

    exporter Exporter

    suspend boolean

    Suspend indicates whether the current resource should be suspended or not. This can be useful for maintenance, as disabling the reconciliation prevents the operator from interfering with user operations during maintenance activities.

    false

    name string

    podMetadata Metadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets LocalObjectReference array

    name string

    Name is the identifier of the MariaDB server.

    Required: {}

    address string

    suspend boolean

    Suspend indicates whether the current resource should be suspended or not. This can be useful for maintenance, as disabling the reconciliation prevents the operator from interfering with user operations during maintenance activities.

    false

    name string

    command string array

    Command to be used in the Container.

    args string array

    enabled boolean

    Enabled indicates whether TLS is enabled, determining if certificates should be issued and mounted to the MaxScale instance. It is enabled by default when the referred MariaDB instance (via mariaDbRef) has TLS enabled and enforced.

    adminVersions string array

    labels object (keys:string, values:string)

    Labels to be added to children resources.

    annotations object (keys:string, values:string)

    mariadbmon

    MonitorModuleMariadb is a monitor to be used with MariaDB servers.

    galeramon

    MonitorModuleGalera is a monitor to be used with Galera servers.

    primary string

    Primary is the name of the primary cluster. It refers to a member in the 'members' field, containing its full specification.

    members MultiClusterMember array

    name string

    Name is the identifier of the member.

    externalMariaDbRef ObjectReference

    primary string

    Primary is the name of the primary cluster. It refers to a member in the 'members' field, containing its full specification.

    members MultiClusterMember array

    server string

    path string

    requiredDuringSchedulingIgnoredDuringExecution NodeSelector

    preferredDuringSchedulingIgnoredDuringExecution PreferredSchedulingTerm array

    nodeSelectorTerms NodeSelectorTerm array

    key string

    operator NodeSelectorOperator

    matchExpressions NodeSelectorRequirement array

    matchFields NodeSelectorRequirement array

    apiVersion string

    fieldPath string

    name string

    namespace string

    pluginNameSecretKeyRef SecretKeySelector

    PluginNameSecretKeyRef is a reference to the authentication plugin to be used by the User. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the authentication plugin.

    pluginArgSecretKeyRef SecretKeySelector

    Delete

    PersistentVolumeClaimRetentionPolicyDelete deletes PVCs when their owning pods or StatefulSet are deleted.

    Retain

    PersistentVolumeClaimRetentionPolicyRetain retains PVCs when their owning pods or StatefulSet are deleted.

    accessModes PersistentVolumeAccessMode array

    selector LabelSelector

    claimName string

    readOnly boolean

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    podMetadata Metadata

    PodMetadata defines extra metadata for the Pod.

    imagePullSecrets LocalObjectReference array

    cron string

    Cron is a cron expression that defines the schedule.

    suspend boolean

    args string array

    Args to be used in the Container.

    resources ResourceRequirements

    s3 S3

    S3 defines the configuration to store backups in a S3 compatible storage.

    azureBlob AzureBlob

    Replica

    PhysicalBackupTargetReplica indicates that the physical backup will be taken in a ready replica.

    PreferReplica

    PhysicalBackupTargetReplica indicates that the physical backup will preferably be taken in a ready replica. If no ready replicas are available, physical backups will be taken in the primary.

    metadata Metadata

    Refer to Kubernetes API documentation for fields of metadata.

    volumeSnapshotClassName string

    labelSelector LabelSelector

    topologyKey string

    requiredDuringSchedulingIgnoredDuringExecution PodAffinityTerm array

    preferredDuringSchedulingIgnoredDuringExecution WeightedPodAffinityTerm array

    minAvailable IntOrString

    MinAvailable defines the number of minimum available Pods.

    maxUnavailable IntOrString

    seLinuxOptions SELinuxOptions

    runAsUser integer

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    physicalBackupRef LocalObjectReference

    PhysicalBackupRef is a reference to a PhysicalBackup object that will be used as base backup.

    Required: {}

    storage PointInTimeRecoveryStorage

    s3 S3

    S3 is the S3-compatible storage where the binary logs will be kept.

    azureBlob AzureBlob

    weight integer

    preference NodeSelectorTerm

    podIndex integer

    PodIndex is the StatefulSet index of the primary node. The user may change this field to perform a manual switchover.

    autoFailover boolean

    podIndex integer

    PodIndex is the StatefulSet index of the primary node. The user may change this field to perform a manual switchover.

    autoFailover boolean

    exec ExecAction

    httpGet HTTPGetAction

    exec ExecAction

    httpGet HTTPGetAction

    physicalBackupTemplateRef LocalObjectReference

    PhysicalBackupTemplateRef is a reference to a PhysicalBackup object that will be used as template to create a new PhysicalBackup object used synchronize the data from an up to date replica to the new replica to be bootstrapped.

    Required: {}

    restoreJob Job

    enabled boolean

    Enabled is a flag to enable replica recovery.

    Required: {}

    errorDurationThreshold Duration

    replPasswordSecretKeyRef GeneratedSecretKeyRef

    ReplPasswordSecretKeyRef provides a reference to the Secret to use as password for the replication user. By default, a random password will be generated.

    gtid Gtid

    primary PrimaryReplication

    Primary is the replication configuration for the primary node.

    replica ReplicaReplication

    primary PrimaryReplication

    Primary is the replication configuration for the primary node.

    replica ReplicaReplication

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    backupRef LocalObjectReference

    BackupRef is a reference to a Backup object. It has priority over S3 and Volume.

    s3 S3

    args string array

    Args to be used in the Container.

    resources ResourceRequirements

    bucket string

    Bucket is the name Name of the bucket to store backups.

    Required: {}

    endpoint string

    requeueInterval Duration

    RequeueInterval is used to perform requeue reconciliations.

    retryInterval Duration

    customerKeySecretKeyRef SecretKeySelector

    CustomerKeySecretKeyRef is a reference to a Secret key containing the SSE-C customer-provided encryption key. The key must be a 32-byte (256-bit) key encoded in base64.

    Required: {}

    rsync

    SSTRsync is an SST based on rsync.

    mariabackup

    SSTMariaBackup is an SST based on mariabackup. It is the recommended SST.

    mysqldump

    SSTMysqldump is an SST based on mysqldump.

    cron string

    Cron is a cron expression that defines the schedule.

    Required: {}

    suspend boolean

    name string

    key string

    metadata Metadata

    Refer to Kubernetes API documentation for fields of metadata.

    key string

    secretName string

    defaultMode integer

    capabilities Capabilities

    privileged boolean

    prometheusRelease string

    PrometheusRelease is the release label to add to the ServiceMonitor object.

    jobLabel string

    name string

    port integer

    readwritesplit

    ServiceRouterReadWriteSplit splits the load based on the queries. Write queries are performed on master and read queries on the replicas.

    readconnroute

    ServiceRouterReadConnRoute splits the load based on the connections. Each connection is assigned to a server.

    type ServiceType

    Type is the Service type. One of ClusterIP, NodePort or LoadBalancer. If not defined, it defaults to ClusterIP.

    ClusterIP

    Enum: [ClusterIP NodePort LoadBalancer]

    metadata Metadata

    seconds integer

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    args string array

    Args to be used in the Container.

    resources ResourceRequirements

    persistentVolumeClaim PersistentVolumeClaimSpec

    PersistentVolumeClaim is a Kubernetes PVC specification.

    volume StorageVolumeSource

    whenDeleted PersistentVolumeClaimRetentionPolicyType

    whenScaled PersistentVolumeClaimRetentionPolicyType

    ephemeral boolean

    Ephemeral indicates whether to use ephemeral storage in the PVCs. It is only compatible with non HA MariaDBs.

    size Quantity

    emptyDir EmptyDirVolumeSource

    nfs NFSVolumeSource

    suspend boolean

    Suspend indicates whether the current resource should be suspended or not. This can be useful for maintenance, as disabling the reconciliation prevents the operator from interfering with user operations during maintenance activities.

    false

    port IntOrString

    host string

    enabled boolean

    Enabled indicates whether TLS is enabled, determining if certificates should be issued and mounted to the MariaDB instance. It is enabled by default.

    required boolean

    enabled boolean

    Enabled is a flag to enable TLS.

    caSecretKeyRef SecretKeySelector

    ssl boolean

    SSL indicates that the user must connect via TLS.

    x509 boolean

    maxSkew integer

    topologyKey string

    name string

    Name of the referent.

    kind string

    type UpdateType

    Type defines the type of updates. One of ReplicasFirstPrimaryLast, RollingUpdate or OnDelete. If not defined, it defaults to ReplicasFirstPrimaryLast.

    ReplicasFirstPrimaryLast

    Enum: [ReplicasFirstPrimaryLast RollingUpdate OnDelete Never]

    rollingUpdate RollingUpdateStatefulSetStrategy

    ReplicasFirstPrimaryLast

    ReplicasFirstPrimaryLastUpdateType indicates that the update will be applied to all replica Pods first and later on to the primary Pod. The updates are applied one by one waiting until each Pod passes the readiness probe i.e. the Pod gets synced and it is ready to receive traffic.

    RollingUpdate

    RollingUpdateUpdateType indicates that the update will be applied by the StatefulSet controller using the RollingUpdate strategy. This strategy is unaware of the roles that the Pod have (primary or replica) and it will perform the update following the StatefulSet ordinal, from higher to lower.

    OnDelete

    OnDeleteUpdateType indicates that the update will be applied by the StatefulSet controller using the OnDelete strategy. The update will be done when the Pods get manually deleted by the user.

    apiVersion string

    enterprise.mariadb.com/v1alpha1

    kind string

    requeueInterval Duration

    RequeueInterval is used to perform requeue reconciliations.

    retryInterval Duration

    accessModes PersistentVolumeAccessMode array

    selector LabelSelector

    name string

    This must match the Name of a Volume.

    readOnly boolean

    emptyDir EmptyDirVolumeSource

    nfs NFSVolumeSource

    AfterSync

    WaitPointAfterSync indicates that the primary waits for the replica ACK before committing the transaction to the storage engine. It trades off performance for consistency.

    AfterCommit

    WaitPointAfterCommit indicates that the primary commits the transaction to the storage engine and waits for the replica ACK afterwards. It trades off consistency for performance.

    weight integer

    podAffinityTerm PodAffinityTerm

    Affinity

    AffinityConfig

    Agent

    AzureBlob

    Backup

    BackupContentType

    BackupSpec

    BackupStorage

    BasicAuth

    BootstrapFrom

    CSIVolumeSource

    CertConfig

    CleanupPolicy

    CompressAlgorithm

    ConfigMapKeySelector

    ConfigMapVolumeSource

    Connection

    ConnectionSpec

    ConnectionTemplate

    Container

    ContainerTemplate

    CooperativeMonitoring

    Cordoning

    CronJobTemplate

    Database

    DatabaseSpec

    EmptyDirVolumeSource

    EnvFromSource

    EnvVar

    EnvVarSource

    EphemeralVolumeSource

    ExecAction

    Exporter

    ExternalMariaDB

    ExternalMariaDBSpec

    ExternalTLS

    Galera

    GaleraConfig

    GaleraInitJob

    GaleraRecovery

    GaleraRecoveryJob

    GaleraSpec

    GeneratedSecretKeyRef

    Grant

    GrantSpec

    Gtid

    HTTPGetAction

    HealthCheck

    HostPathVolumeSource

    InitContainer

    Job

    JobContainerTemplate

    JobPodTemplate

    KubernetesAuth

    LabelSelector

    LabelSelectorRequirement

    Lifecycle

    LifecycleHandler

    LocalObjectReference

    MariaDB

    MariaDBMaintenance

    MariaDBPodTemplate

    MariaDBRef

    MariaDBSpec

    MariaDBVolume

    MariaDBVolumeSource

    MariadbMetrics

    MaxScale

    MaxScaleAdmin

    MaxScaleAuth

    MaxScaleConfig

    MaxScaleConfigSync

    MaxScaleListener

    MaxScaleMaintenance

    MaxScaleMetrics

    MaxScaleMonitor

    MaxScalePodTemplate

    MaxScaleServer

    MaxScaleService

    MaxScaleSpec

    MaxScaleTLS

    Metadata

    MonitorModule

    MultiCluster

    MultiClusterMember

    MultiClusterSpec

    NFSVolumeSource

    NodeAffinity

    NodeSelector

    NodeSelectorRequirement

    NodeSelectorTerm

    ObjectFieldSelector

    ObjectReference

    PasswordPlugin

    PersistentVolumeClaimRetentionPolicyType

    PersistentVolumeClaimSpec

    PersistentVolumeClaimVolumeSource

    PhysicalBackup

    PhysicalBackupPodTemplate

    PhysicalBackupSchedule

    PhysicalBackupSpec

    PhysicalBackupStorage

    PhysicalBackupTarget

    PhysicalBackupVolumeSnapshot

    PodAffinityTerm

    PodAntiAffinity

    PodDisruptionBudget

    PodSecurityContext

    PointInTimeRecovery

    PointInTimeRecoverySpec

    PointInTimeRecoveryStorage

    PreferredSchedulingTerm

    PrimaryGalera

    PrimaryReplication

    Probe

    ProbeHandler

    ReplicaBootstrapFrom

    ReplicaRecovery

    ReplicaReplication

    Replication

    ReplicationSpec

    ResourceRequirements

    Restore

    RestoreSource

    RestoreSpec

    S3

    SQLTemplate

    SSECConfig

    SST

    Schedule

    SecretKeySelector

    SecretTemplate

    SecretVolumeSource

    SecurityContext

    ServiceMonitor

    ServicePort

    ServiceRouter

    ServiceTemplate

    SleepAction

    SqlJob

    SqlJobSpec

    StagingStorage

    StatefulSetPersistentVolumeClaimRetentionPolicy

    Storage

    StorageVolumeSource

    SuspendTemplate

    TCPSocketAction

    TLS

    TLSConfig

    TLSRequirements

    TopologySpreadConstraint

    TypedLocalObjectReference

    UpdateStrategy

    UpdateType

    User

    UserSpec

    VolumeClaimTemplate

    VolumeMount

    VolumeSource

    WaitPoint

    WeightedPodAffinityTerm

    Connection
    Database
    ExternalMariaDB
    Grant
    MariaDB
    MaxScale
    PhysicalBackup
    PointInTimeRecovery
    Restore
    SqlJob
    User
    AffinityConfig
    BackupSpec
    Exporter
    Job
    Galera
    GaleraSpec
    Replication
    BootstrapFrom
    PhysicalBackupStorage
    PointInTimeRecoveryStorage
    BootstrapFrom
    Backup
    BackupSpec
    Agent
    MariaDBSpec
    MariaDBVolume
    MariaDBVolumeSource
    StorageVolumeSource
    ExternalTLS
    MaxScaleTLS
    TLS
    DatabaseSpec
    GrantSpec
    MariaDBSpec
    BackupSpec
    PhysicalBackupSpec
    PointInTimeRecoverySpec
    EnvVarSource
    MariaDBSpec
    SqlJobSpec
    MariaDBVolume
    MariaDBVolumeSource
    Volume
    Connection
    ConnectionSpec
    ExternalMariaDBSpec
    MariaDBSpec
    MariaDBPodTemplate
    MariaDBSpec
    Agent
    InitContainer
    MariaDBSpec
    MaxScaleMonitor
    MariaDBMaintenance
    MaxScaleMaintenance
    BackupSpec
    SqlJobSpec
    Database
    MariaDBVolume
    MariaDBVolumeSource
    StorageVolumeSource
    Agent
    ContainerTemplate
    InitContainer
    Agent
    Container
    ContainerTemplate
    EnvVar
    MariaDBVolume
    MariaDBVolumeSource
    LifecycleHandler
    Probe
    ProbeHandler
    MariadbMetrics
    MaxScaleMetrics
    ExternalMariaDB
    ExternalMariaDBSpec
    MariaDBSpec
    Galera
    GaleraSpec
    Galera
    GaleraSpec
    Galera
    GaleraSpec
    GaleraRecovery
    Galera
    BasicAuth
    Galera
    GaleraSpec
    Grant
    ReplicaReplication
    LifecycleHandler
    Probe
    ProbeHandler
    ConnectionSpec
    ConnectionTemplate
    MariaDBVolume
    MariaDBVolumeSource
    StorageVolumeSource
    Galera
    GaleraSpec
    Replication
    BootstrapFrom
    ReplicaBootstrapFrom
    BackupSpec
    PhysicalBackupSpec
    RestoreSpec
    BackupSpec
    RestoreSpec
    SqlJobSpec
    Agent
    PodAffinityTerm
    LabelSelector
    Agent
    ContainerTemplate
    InitContainer
    Lifecycle
    BackupSpec
    BootstrapFrom
    CSIVolumeSource
    MariaDBSpec
    MariaDBSpec
    BackupSpec
    ConnectionSpec
    DatabaseSpec
    MariaDB
    MariaDBPodTemplate
    MariaDBSpec
    MariaDBVolume
    MariaDBSpec
    MaxScaleSpec
    MaxScaleSpec
    MaxScaleSpec
    MaxScaleConfig
    MaxScaleService
    MaxScaleSpec
    MaxScaleSpec
    MaxScaleSpec
    MaxScaleSpec
    MaxScaleSpec
    MaxScaleSpec
    MaxScale
    MaxScaleSpec
    BackupSpec
    Exporter
    ExternalMariaDBSpec
    MaxScaleMonitor
    MariaDBSpec
    MultiCluster
    MultiClusterSpec
    MultiCluster
    MariaDBVolume
    MariaDBVolumeSource
    StorageVolumeSource
    Affinity
    AffinityConfig
    NodeAffinity
    NodeSelectorTerm
    NodeSelector
    PreferredSchedulingTerm
    EnvVarSource
    ConnectionSpec
    MariaDBRef
    MariaDBSpec
    MariaDBSpec
    UserSpec
    StatefulSetPersistentVolumeClaimRetentionPolicy
    BackupStorage
    PhysicalBackupStorage
    StagingStorage
    MariaDBVolume
    MariaDBVolumeSource
    StorageVolumeSource
    PhysicalBackupSpec
    PhysicalBackupSpec
    PhysicalBackup
    PhysicalBackupSpec
    PhysicalBackupSpec
    PhysicalBackupStorage
    PodAntiAffinity
    WeightedPodAffinityTerm
    Affinity
    AffinityConfig
    MariaDBSpec
    MaxScaleSpec
    BackupSpec
    Exporter
    JobPodTemplate
    PointInTimeRecovery
    PointInTimeRecoverySpec
    NodeAffinity
    Galera
    GaleraSpec
    Replication
    ReplicationSpec
    Agent
    ContainerTemplate
    InitContainer
    Probe
    ReplicaReplication
    ReplicaReplication
    Replication
    ReplicationSpec
    MariaDBSpec
    Replication
    Agent
    BackupSpec
    Container
    RestoreSpec
    Restore
    BackupStorage
    BootstrapFrom
    PhysicalBackupStorage
    DatabaseSpec
    GrantSpec
    UserSpec
    S3
    Galera
    GaleraSpec
    BackupSpec
    SqlJobSpec
    AzureBlob
    ConnectionSpec
    EnvVarSource
    ConnectionSpec
    ConnectionTemplate
    MariaDBVolume
    MariaDBVolumeSource
    Volume
    Agent
    BackupSpec
    ContainerTemplate
    MariadbMetrics
    MaxScaleMetrics
    MariaDBSpec
    MaxScaleService
    MariaDBSpec
    MaxScaleSpec
    LifecycleHandler
    SqlJob
    BackupSpec
    BootstrapFrom
    PhysicalBackupSpec
    Storage
    MariaDBSpec
    BackupStorage
    BootstrapFrom
    MariaDBVolume
    MariaDBSpec
    MaxScaleListener
    MaxScaleMonitor
    Probe
    ProbeHandler
    ExternalTLS
    MariaDBSpec
    AzureBlob
    S3
    UserSpec
    MariaDBPodTemplate
    MariaDBSpec
    MaxScalePodTemplate
    BootstrapFrom
    MariaDBSpec
    UpdateStrategy
    User
    EphemeralVolumeSource
    GaleraConfig
    MaxScaleConfig
    Agent
    Container
    ContainerTemplate
    MariaDBVolume
    MariaDBVolumeSource
    Volume
    Replication
    ReplicationSpec
    PodAntiAffinity

    Args to be used in the Container.

    ServiceURL is the full URL for connecting to Azure, usually in the form: http(s)://.blob.core.windows.net/.

    Backup

    Resources describes the compute resource requirements.

    PersistentVolumeClaim is a Kubernetes PVC specification.

    Username to be used for basic authentication

    VolumeSnapshotRef is a reference to a VolumeSnapshot object. This field takes precedence over S3 and Volume sources.

    CertLifetime defines the certificate validity.

    Connection

    SecretTemplate to be used in the Connection.

    SecretTemplate to be used in the Connection.

    Image name to be used by the container. The supported format is <image>:<tag>.

    Args to be used in the Container.

    FailedJobsHistoryLimit defines the maximum number of failed Jobs to be displayed.

    Database

    RetryInterval is the interval used to perform retries.

    ImagePullPolicy is the image pull policy. One of Always, Never or IfNotPresent. If not defined, it defaults to IfNotPresent.

    ExternalMariaDB

    ImagePullPolicy is the image pull policy. One of Always, Never or IfNotPresent. If not defined, it defaults to IfNotPresent.

    Required specifies whether TLS must be enforced for all connections. User TLS requirements take precedence over this. It disabled by default.

    SST is the Snapshot State Transfer used when new Pods join the cluster. More info: https://galeracluster.com/library/documentation/sst.html.

    VolumeClaimTemplate is a template for the PVC that will contain the Galera configuration files shared between the InitContainer, Agent and MariaDB.

    Resources describes the compute resource requirements.

    MinClusterSize is the minimum number of replicas to consider the cluster healthy. It can be either a number of replicas (1) or a percentage (50%). If Galera consistently reports less replicas than this value for the given 'ClusterHealthyTimeout' interval, a cluster recovery is initiated. It defaults to '1' replica, and it is highly recommended to keep this value at '1' in most cases. If set to more than one replica, the cluster recovery process may restart the healthy replicas as well.

    Resources describes the compute resource requirements.

    SST is the Snapshot State Transfer used when new Pods join the cluster. More info: https://galeracluster.com/library/documentation/sst.html.

    Grant

    RetryInterval is the interval used to perform retries.

    RetryInterval is the interval used to perform health check retries.

    Args to be used in the Container.

    Affinity to be used in the Pod.

    Resources describes the compute resource requirements.

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    AuthDelegatorRoleName is the name of the ClusterRoleBinding that is associated with the "system:auth-delegator" ClusterRole. It is necessary for creating TokenReview objects in order for the agent to validate the service account token.

    MariaDB

    Enabled turns on maintenance mode

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    Args to be used in the Container.

    Exporter defines the metrics exporter container.

    MaxScale

    GuiEnabled indicates whether the admin GUI should be enabled.

    AdminUsername is an admin username to call the admin REST API. It is defaulted if not provided.

    VolumeClaimTemplate provides a template to define the PVCs for storing MaxScale runtime configuration files. It is defaulted if not provided.

    Interval defines the config synchronization interval. It is defaulted if not provided.

    Name is the identifier of the listener. It is defaulted if not provided

    Enabled turns on maintenance mode

    Exporter defines the metrics exporter container.

    Name is the identifier of the monitor. It is defaulted if not provided.

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    Address is the network address of the MariaDB server.

    Name is the identifier of the MaxScale service.

    Args to be used in the Container.

    Versions specifies the supported TLS versions in the MaxScale REST API. By default, the MaxScale's default supported versions are used. See: https://mariadb.com/kb/en/mariadb-maxscale-25-mariadb-maxscale-configuration-guide/#admin_ssl_version

    Annotations to be added to children resources.

    Members is the specification of each member of the multi-cluster topology.

    ExternalMariaDBRef holds a reference to an ExternalMariaDB with connection details to form the multi-cluster topology. These connection details are utilized to setup remote replicas.

    Members is the specification of each member of the multi-cluster topology.

    PluginArgSecretKeyRef is a reference to the arguments to be provided to the authentication plugin for the User. If the referred Secret is labeled with "enterprise.mariadb.com/watch", updates may be performed to the Secret in order to update the authentication plugin arguments.

    PhysicalBackup

    ImagePullSecrets is the list of pull Secrets to be used to pull the image.

    Suspend defines whether the schedule is active or not.

    Resources describes the compute resource requirements.

    AzureBlob defines the configuration to store backups in a AzureBlob compatible storage.

    VolumeSnapshotClassName is the VolumeSnapshot class to be used to take snapshots.

    MaxUnavailable defines the number of maximum unavailable Pods.

    PointInTimeRecovery

    PointInTimeRecoveryStorage is the storage where the point in time recovery data will be stored

    AzureBlob is the Azure Blob Storage where the binary logs will be kept.

    AutoFailover indicates whether the operator should automatically update PodIndex to perform an automatic primary failover.

    AutoFailover indicates whether the operator should automatically update PodIndex to perform an automatic primary failover. It is enabled by default.

    RestoreJob defines additional properties for the Job used to perform the restoration.

    ErrorDurationThreshold defines the time duration after which, if a replica continues to report errors, the operator will initiate the recovery process for that replica. This threshold applies only to error codes not identified as recoverable by the operator. Errors identified as recoverable will trigger the recovery process immediately. It defaults to 5 minutes.

    Gtid indicates which Global Transaction ID (GTID) position mode should be used when connecting a replica to the master. By default, CurrentPos is used. See: https://mariadb.com/docs/server/reference/sql-statements/administrative-sql-statements/replication-statements/change-master-to#master_use_gtid.

    ReplicaReplication is the replication configuration for the replica nodes.

    ReplicaReplication is the replication configuration for the replica nodes.

    Restore

    S3 defines the configuration to restore backups from a S3 compatible storage. It has priority over Volume.

    Resources describes the compute resource requirements.

    Endpoint is the S3 API endpoint without scheme.

    RetryInterval is the interval used to perform retries.

    Suspend defines whether the schedule is active or not.

    Key to be used in the Secret.

    JobLabel to add to the ServiceMonitor object.

    Refer to Kubernetes API documentation for fields of metadata.

    SqlJob

    Resources describes the compute resource requirements.

    Volume is a Kubernetes volume specification.

    Size of the PVCs to be mounted by MariaDB. Required if not provided in 'VolumeClaimTemplate'. It supersedes the storage size specified in 'VolumeClaimTemplate'.

    Required specifies whether TLS must be enforced for all connections. User TLS requirements take precedence over this. It disabled by default.

    CASecretKeyRef is a reference to a Secret key containing a CA bundle in PEM format used to establish TLS connections with S3. By default, the system trust chain will be used, but you can use this field to add more CAs to the bundle.

    X509 indicates that the user must provide a valid x509 certificate to connect.

    Kind of the referent.

    RollingUpdate defines parameters for the RollingUpdate type.

    User

    RetryInterval is the interval used to perform retries.

    JobPodTemplate
    ReplicationSpec
    Volume
    SQLTemplate
    VolumeSource
    MaxScaleSpec
    MaxScaleSpec
    Volume
    MariaDBSpec
    InitContainer
    MariaDBSpec
    Volume
    ReplicationSpec
    SqlJobSpec
    MariaDBSpec
    ConfigMapKeySelector
    GrantSpec
    GaleraInitJob
    Volume
    MultiClusterMember
    VolumeClaimTemplate
    Volume
    MariaDBPodTemplate
    MariaDBSpec
    ContainerTemplate
    PointInTimeRecoveryStorage
    ExternalMariaDBSpec
    VolumeSource
    Exporter
    RestoreSource
    MariaDBVolumeSource
    MaxScaleService
    MaxScaleSpec
    Storage
    InitContainer
    EnvVar
    EnvFromSource
    VolumeMount
    Probe
    Probe
    Probe
    ResourceRequirements
    SecurityContext
    Lifecycle
    PullPolicy
    KubernetesAuth
    BasicAuth
    Duration
    SecretKeySelector
    TLSConfig
    ObjectMeta
    BackupSpec
    SecurityContext
    Metadata
    LocalObjectReference
    PodSecurityContext
    AffinityConfig
    Toleration
    MariaDBRef
    CompressAlgorithm
    StagingStorage
    BackupStorage
    Schedule
    Duration
    RestartPolicy
    Metadata
    StorageVolumeSource
    GeneratedSecretKeyRef
    LocalObjectReference
    BackupContentType
    S3
    AzureBlob
    StorageVolumeSource
    Time
    StagingStorage
    Job
    LocalObjectReference
    ObjectMeta
    ConnectionSpec
    HealthCheck
    MariaDBRef
    ObjectReference
    SecretKeySelector
    LocalObjectReference
    HealthCheck
    PullPolicy
    EnvVar
    VolumeMount
    ResourceRequirements
    EnvVar
    EnvFromSource
    VolumeMount
    Probe
    Probe
    Probe
    ResourceRequirements
    SecurityContext
    Lifecycle
    ObjectMeta
    DatabaseSpec
    CleanupPolicy
    MariaDBRef
    LocalObjectReference
    EnvVarSource
    SecretKeySelector
    LocalObjectReference
    ResourceRequirements
    Metadata
    SecurityContext
    PodSecurityContext
    AffinityConfig
    Toleration
    ObjectMeta
    ExternalMariaDBSpec
    LocalObjectReference
    Metadata
    SecretKeySelector
    ExternalTLS
    ConnectionTemplate
    LocalObjectReference
    LocalObjectReference
    IssuerReference
    CertConfig
    LocalObjectReference
    LocalObjectReference
    IssuerReference
    CertConfig
    Agent
    GaleraRecovery
    InitContainer
    GaleraInitJob
    GaleraConfig
    GeneratedSecretKeyRef
    Duration
    Duration
    Duration
    Duration
    Duration
    Duration
    Duration
    GaleraRecoveryJob
    Agent
    GaleraRecovery
    InitContainer
    GaleraInitJob
    GaleraConfig
    GeneratedSecretKeyRef
    ObjectMeta
    GrantSpec
    CleanupPolicy
    MariaDBRef
    URIScheme
    EnvVar
    EnvFromSource
    VolumeMount
    Probe
    Probe
    Probe
    ResourceRequirements
    SecurityContext
    Lifecycle
    PullPolicy
    Toleration
    ResourceRequirements
    SecurityContext
    PodSecurityContext
    AffinityConfig
    Toleration
    SleepAction
    ObjectMeta
    MariaDBSpec
    Container
    Container
    PodSecurityContext
    AffinityConfig
    Toleration
    MariaDBVolume
    TopologySpreadConstraint
    EnvVar
    EnvFromSource
    VolumeMount
    Probe
    Probe
    Probe
    ResourceRequirements
    SecurityContext
    Lifecycle
    Metadata
    LocalObjectReference
    Container
    Container
    PodSecurityContext
    AffinityConfig
    Toleration
    MariaDBVolume
    TopologySpreadConstraint
    PullPolicy
    Metadata
    GeneratedSecretKeyRef
    GeneratedSecretKeyRef
    SecretKeySelector
    PasswordPlugin
    CleanupPolicy
    ConfigMapKeySelector
    BootstrapFrom
    Storage
    MariadbMetrics
    TLS
    Replication
    Galera
    MultiCluster
    ObjectReference
    LocalObjectReference
    ServicePort
    PodDisruptionBudget
    UpdateStrategy
    ServiceTemplate
    ConnectionTemplate
    ServiceTemplate
    ConnectionTemplate
    ServiceTemplate
    ConnectionTemplate
    MariaDBMaintenance
    CSIVolumeSource
    HostPathVolumeSource
    PersistentVolumeClaimVolumeSource
    SecretVolumeSource
    ConfigMapVolumeSource
    EphemeralVolumeSource
    CSIVolumeSource
    HostPathVolumeSource
    PersistentVolumeClaimVolumeSource
    SecretVolumeSource
    ConfigMapVolumeSource
    EphemeralVolumeSource
    ServiceMonitor
    GeneratedSecretKeyRef
    ObjectMeta
    MaxScaleSpec
    GeneratedSecretKeyRef
    GeneratedSecretKeyRef
    GeneratedSecretKeyRef
    GeneratedSecretKeyRef
    GeneratedSecretKeyRef
    GeneratedSecretKeyRef
    MaxScaleConfigSync
    Duration
    ServiceMonitor
    MonitorModule
    Duration
    CooperativeMonitoring
    PodSecurityContext
    AffinityConfig
    Toleration
    TopologySpreadConstraint
    ServiceRouter
    MaxScaleListener
    EnvVar
    EnvFromSource
    VolumeMount
    Probe
    Probe
    Probe
    ResourceRequirements
    SecurityContext
    Lifecycle
    Metadata
    LocalObjectReference
    PodSecurityContext
    AffinityConfig
    Toleration
    TopologySpreadConstraint
    MariaDBRef
    MaxScaleServer
    PullPolicy
    Metadata
    MaxScaleService
    MaxScaleMonitor
    MaxScaleAdmin
    MaxScaleConfig
    MaxScaleAuth
    MaxScaleMetrics
    MaxScaleTLS
    ConnectionTemplate
    PodDisruptionBudget
    StatefulSetUpdateStrategy
    ServiceTemplate
    ServiceTemplate
    Duration
    MaxScaleMaintenance
    LocalObjectReference
    LocalObjectReference
    IssuerReference
    CertConfig
    LocalObjectReference
    LocalObjectReference
    IssuerReference
    CertConfig
    LocalObjectReference
    LocalObjectReference
    SecretKeySelector
    VolumeResourceRequirements
    ObjectMeta
    PhysicalBackupSpec
    PodSecurityContext
    Toleration
    SecurityContext
    Metadata
    LocalObjectReference
    PodSecurityContext
    Toleration
    MariaDBRef
    PhysicalBackupTarget
    CompressAlgorithm
    StagingStorage
    PhysicalBackupStorage
    PhysicalBackupSchedule
    Duration
    Duration
    RestartPolicy
    Metadata
    PersistentVolumeClaimSpec
    StorageVolumeSource
    PhysicalBackupVolumeSnapshot
    PodFSGroupChangePolicy
    SeccompProfile
    AppArmorProfile
    ObjectMeta
    PointInTimeRecoverySpec
    CompressAlgorithm
    Duration
    Duration
    Duration
    Duration
    TCPSocketAction
    TCPSocketAction
    Duration
    ReplicaBootstrapFrom
    ReplicaRecovery
    Duration
    WaitPoint
    InitContainer
    Agent
    Duration
    WaitPoint
    InitContainer
    Agent
    ObjectMeta
    RestoreSpec
    StorageVolumeSource
    Time
    StagingStorage
    SecurityContext
    Metadata
    LocalObjectReference
    PodSecurityContext
    AffinityConfig
    Toleration
    LocalObjectReference
    S3
    StorageVolumeSource
    Time
    StagingStorage
    MariaDBRef
    RestartPolicy
    Metadata
    SecretKeySelector
    SecretKeySelector
    SecretKeySelector
    TLSConfig
    SSECConfig
    CleanupPolicy
    ServiceExternalTrafficPolicy
    ServiceAffinity
    ObjectMeta
    SqlJobSpec
    SecurityContext
    Metadata
    LocalObjectReference
    PodSecurityContext
    AffinityConfig
    Toleration
    MariaDBRef
    Schedule
    SecretKeySelector
    LocalObjectReference
    LocalObjectReference
    LocalObjectReference
    ConfigMapKeySelector
    RestartPolicy
    Metadata
    VolumeClaimTemplate
    StatefulSetPersistentVolumeClaimRetentionPolicy
    CSIVolumeSource
    HostPathVolumeSource
    PersistentVolumeClaimVolumeSource
    LocalObjectReference
    LocalObjectReference
    IssuerReference
    CertConfig
    LocalObjectReference
    LocalObjectReference
    IssuerReference
    CertConfig
    UnsatisfiableConstraintAction
    LabelSelector
    NodeInclusionPolicy
    NodeInclusionPolicy
    ObjectMeta
    UserSpec
    CleanupPolicy
    MariaDBRef
    SecretKeySelector
    SecretKeySelector
    PasswordPlugin
    TLSRequirements
    VolumeResourceRequirements
    Metadata
    CSIVolumeSource
    HostPathVolumeSource
    PersistentVolumeClaimVolumeSource
    SecretVolumeSource
    ConfigMapVolumeSource