codekingpro/portable-devtools
114k
1# coding: utf-82 3"""4 Kubernetes5 6 No description provided (generated by Openapi Generator https://github.com/openapitools/openapi-generator) # noqa: E5017 8 The version of the OpenAPI document: release-1.359 Generated by: https://openapi-generator.tech10"""11 12 13import pprint14import re # noqa: F40115 16import six17 18from kubernetes.client.configuration import Configuration19 20 21class V1PodSecurityContext(object):22 """NOTE: This class is auto generated by OpenAPI Generator.23 Ref: https://openapi-generator.tech24 25 Do not edit the class manually.26 """27 28 """29 Attributes:30 openapi_types (dict): The key is attribute name31 and the value is attribute type.32 attribute_map (dict): The key is attribute name33 and the value is json key in definition.34 """35 openapi_types = {36 'app_armor_profile': 'V1AppArmorProfile',37 'fs_group': 'int',38 'fs_group_change_policy': 'str',39 'run_as_group': 'int',40 'run_as_non_root': 'bool',41 'run_as_user': 'int',42 'se_linux_change_policy': 'str',43 'se_linux_options': 'V1SELinuxOptions',44 'seccomp_profile': 'V1SeccompProfile',45 'supplemental_groups': 'list[int]',46 'supplemental_groups_policy': 'str',47 'sysctls': 'list[V1Sysctl]',48 'windows_options': 'V1WindowsSecurityContextOptions'49 }50 51 attribute_map = {52 'app_armor_profile': 'appArmorProfile',53 'fs_group': 'fsGroup',54 'fs_group_change_policy': 'fsGroupChangePolicy',55 'run_as_group': 'runAsGroup',56 'run_as_non_root': 'runAsNonRoot',57 'run_as_user': 'runAsUser',58 'se_linux_change_policy': 'seLinuxChangePolicy',59 'se_linux_options': 'seLinuxOptions',60 'seccomp_profile': 'seccompProfile',61 'supplemental_groups': 'supplementalGroups',62 'supplemental_groups_policy': 'supplementalGroupsPolicy',63 'sysctls': 'sysctls',64 'windows_options': 'windowsOptions'65 }66 67 def __init__(self, app_armor_profile=None, fs_group=None, fs_group_change_policy=None, run_as_group=None, run_as_non_root=None, run_as_user=None, se_linux_change_policy=None, se_linux_options=None, seccomp_profile=None, supplemental_groups=None, supplemental_groups_policy=None, sysctls=None, windows_options=None, local_vars_configuration=None): # noqa: E50168 """V1PodSecurityContext - a model defined in OpenAPI""" # noqa: E50169 if local_vars_configuration is None:70 local_vars_configuration = Configuration()71 self.local_vars_configuration = local_vars_configuration72 73 self._app_armor_profile = None74 self._fs_group = None75 self._fs_group_change_policy = None76 self._run_as_group = None77 self._run_as_non_root = None78 self._run_as_user = None79 self._se_linux_change_policy = None80 self._se_linux_options = None81 self._seccomp_profile = None82 self._supplemental_groups = None83 self._supplemental_groups_policy = None84 self._sysctls = None85 self._windows_options = None86 self.discriminator = None87 88 if app_armor_profile is not None:89 self.app_armor_profile = app_armor_profile90 if fs_group is not None:91 self.fs_group = fs_group92 if fs_group_change_policy is not None:93 self.fs_group_change_policy = fs_group_change_policy94 if run_as_group is not None:95 self.run_as_group = run_as_group96 if run_as_non_root is not None:97 self.run_as_non_root = run_as_non_root98 if run_as_user is not None:99 self.run_as_user = run_as_user100 if se_linux_change_policy is not None:101 self.se_linux_change_policy = se_linux_change_policy102 if se_linux_options is not None:103 self.se_linux_options = se_linux_options104 if seccomp_profile is not None:105 self.seccomp_profile = seccomp_profile106 if supplemental_groups is not None:107 self.supplemental_groups = supplemental_groups108 if supplemental_groups_policy is not None:109 self.supplemental_groups_policy = supplemental_groups_policy110 if sysctls is not None:111 self.sysctls = sysctls112 if windows_options is not None:113 self.windows_options = windows_options114 115 @property116 def app_armor_profile(self):117 """Gets the app_armor_profile of this V1PodSecurityContext. # noqa: E501118 119 120 :return: The app_armor_profile of this V1PodSecurityContext. # noqa: E501121 :rtype: V1AppArmorProfile122 """123 return self._app_armor_profile124 125 @app_armor_profile.setter126 def app_armor_profile(self, app_armor_profile):127 """Sets the app_armor_profile of this V1PodSecurityContext.128 129 130 :param app_armor_profile: The app_armor_profile of this V1PodSecurityContext. # noqa: E501131 :type: V1AppArmorProfile132 """133 134 self._app_armor_profile = app_armor_profile135 136 @property137 def fs_group(self):138 """Gets the fs_group of this V1PodSecurityContext. # noqa: E501139 140 A special supplemental group that applies to all containers in a pod. Some volume types allow the Kubelet to change the ownership of that volume to be owned by the pod: 1. The owning GID will be the FSGroup 2. The setgid bit is set (new files created in the volume will be owned by FSGroup) 3. The permission bits are OR'd with rw-rw---- If unset, the Kubelet will not modify the ownership and permissions of any volume. Note that this field cannot be set when spec.os.name is windows. # noqa: E501141 142 :return: The fs_group of this V1PodSecurityContext. # noqa: E501143 :rtype: int144 """145 return self._fs_group146 147 @fs_group.setter148 def fs_group(self, fs_group):149 """Sets the fs_group of this V1PodSecurityContext.150 151 A special supplemental group that applies to all containers in a pod. Some volume types allow the Kubelet to change the ownership of that volume to be owned by the pod: 1. The owning GID will be the FSGroup 2. The setgid bit is set (new files created in the volume will be owned by FSGroup) 3. The permission bits are OR'd with rw-rw---- If unset, the Kubelet will not modify the ownership and permissions of any volume. Note that this field cannot be set when spec.os.name is windows. # noqa: E501152 153 :param fs_group: The fs_group of this V1PodSecurityContext. # noqa: E501154 :type: int155 """156 157 self._fs_group = fs_group158 159 @property160 def fs_group_change_policy(self):161 """Gets the fs_group_change_policy of this V1PodSecurityContext. # noqa: E501162 163 fsGroupChangePolicy defines behavior of changing ownership and permission of the volume before being exposed inside Pod. This field will only apply to volume types which support fsGroup based ownership(and permissions). It will have no effect on ephemeral volume types such as: secret, configmaps and emptydir. Valid values are \"OnRootMismatch\" and \"Always\". If not specified, \"Always\" is used. Note that this field cannot be set when spec.os.name is windows. # noqa: E501164 165 :return: The fs_group_change_policy of this V1PodSecurityContext. # noqa: E501166 :rtype: str167 """168 return self._fs_group_change_policy169 170 @fs_group_change_policy.setter171 def fs_group_change_policy(self, fs_group_change_policy):172 """Sets the fs_group_change_policy of this V1PodSecurityContext.173 174 fsGroupChangePolicy defines behavior of changing ownership and permission of the volume before being exposed inside Pod. This field will only apply to volume types which support fsGroup based ownership(and permissions). It will have no effect on ephemeral volume types such as: secret, configmaps and emptydir. Valid values are \"OnRootMismatch\" and \"Always\". If not specified, \"Always\" is used. Note that this field cannot be set when spec.os.name is windows. # noqa: E501175 176 :param fs_group_change_policy: The fs_group_change_policy of this V1PodSecurityContext. # noqa: E501177 :type: str178 """179 180 self._fs_group_change_policy = fs_group_change_policy181 182 @property183 def run_as_group(self):184 """Gets the run_as_group of this V1PodSecurityContext. # noqa: E501185 186 The GID to run the entrypoint of the container process. Uses runtime default if unset. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence for that container. Note that this field cannot be set when spec.os.name is windows. # noqa: E501187 188 :return: The run_as_group of this V1PodSecurityContext. # noqa: E501189 :rtype: int190 """191 return self._run_as_group192 193 @run_as_group.setter194 def run_as_group(self, run_as_group):195 """Sets the run_as_group of this V1PodSecurityContext.196 197 The GID to run the entrypoint of the container process. Uses runtime default if unset. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence for that container. Note that this field cannot be set when spec.os.name is windows. # noqa: E501198 199 :param run_as_group: The run_as_group of this V1PodSecurityContext. # noqa: E501200 :type: int201 """202 203 self._run_as_group = run_as_group204 205 @property206 def run_as_non_root(self):207 """Gets the run_as_non_root of this V1PodSecurityContext. # noqa: E501208 209 Indicates that the container must run as a non-root user. If true, the Kubelet will validate the image at runtime to ensure that it does not run as UID 0 (root) and fail to start the container if it does. If unset or false, no such validation will be performed. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. # noqa: E501210 211 :return: The run_as_non_root of this V1PodSecurityContext. # noqa: E501212 :rtype: bool213 """214 return self._run_as_non_root215 216 @run_as_non_root.setter217 def run_as_non_root(self, run_as_non_root):218 """Sets the run_as_non_root of this V1PodSecurityContext.219 220 Indicates that the container must run as a non-root user. If true, the Kubelet will validate the image at runtime to ensure that it does not run as UID 0 (root) and fail to start the container if it does. If unset or false, no such validation will be performed. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. # noqa: E501221 222 :param run_as_non_root: The run_as_non_root of this V1PodSecurityContext. # noqa: E501223 :type: bool224 """225 226 self._run_as_non_root = run_as_non_root227 228 @property229 def run_as_user(self):230 """Gets the run_as_user of this V1PodSecurityContext. # noqa: E501231 232 The UID to run the entrypoint of the container process. Defaults to user specified in image metadata if unspecified. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence for that container. Note that this field cannot be set when spec.os.name is windows. # noqa: E501233 234 :return: The run_as_user of this V1PodSecurityContext. # noqa: E501235 :rtype: int236 """237 return self._run_as_user238 239 @run_as_user.setter240 def run_as_user(self, run_as_user):241 """Sets the run_as_user of this V1PodSecurityContext.242 243 The UID to run the entrypoint of the container process. Defaults to user specified in image metadata if unspecified. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence for that container. Note that this field cannot be set when spec.os.name is windows. # noqa: E501244 245 :param run_as_user: The run_as_user of this V1PodSecurityContext. # noqa: E501246 :type: int247 """248 249 self._run_as_user = run_as_user250 251 @property252 def se_linux_change_policy(self):253 """Gets the se_linux_change_policy of this V1PodSecurityContext. # noqa: E501254 255 seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod. It has no effect on nodes that do not support SELinux or to volumes does not support SELinux. Valid values are \"MountOption\" and \"Recursive\". \"Recursive\" means relabeling of all files on all Pod volumes by the container runtime. This may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node. \"MountOption\" mounts all eligible Pod volumes with `-o context` mount option. This requires all Pods that share the same volume to use the same SELinux label. It is not possible to share the same volume among privileged and unprivileged Pods. Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. \"MountOption\" value is allowed only when SELinuxMount feature gate is enabled. If not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used. If not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes and \"Recursive\" for all other volumes. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. All Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state. Note that this field cannot be set when spec.os.name is windows. # noqa: E501256 257 :return: The se_linux_change_policy of this V1PodSecurityContext. # noqa: E501258 :rtype: str259 """260 return self._se_linux_change_policy261 262 @se_linux_change_policy.setter263 def se_linux_change_policy(self, se_linux_change_policy):264 """Sets the se_linux_change_policy of this V1PodSecurityContext.265 266 seLinuxChangePolicy defines how the container's SELinux label is applied to all volumes used by the Pod. It has no effect on nodes that do not support SELinux or to volumes does not support SELinux. Valid values are \"MountOption\" and \"Recursive\". \"Recursive\" means relabeling of all files on all Pod volumes by the container runtime. This may be slow for large volumes, but allows mixing privileged and unprivileged Pods sharing the same volume on the same node. \"MountOption\" mounts all eligible Pod volumes with `-o context` mount option. This requires all Pods that share the same volume to use the same SELinux label. It is not possible to share the same volume among privileged and unprivileged Pods. Eligible volumes are in-tree FibreChannel and iSCSI volumes, and all CSI volumes whose CSI driver announces SELinux support by setting spec.seLinuxMount: true in their CSIDriver instance. Other volumes are always re-labelled recursively. \"MountOption\" value is allowed only when SELinuxMount feature gate is enabled. If not specified and SELinuxMount feature gate is enabled, \"MountOption\" is used. If not specified and SELinuxMount feature gate is disabled, \"MountOption\" is used for ReadWriteOncePod volumes and \"Recursive\" for all other volumes. This field affects only Pods that have SELinux label set, either in PodSecurityContext or in SecurityContext of all containers. All Pods that use the same volume should use the same seLinuxChangePolicy, otherwise some pods can get stuck in ContainerCreating state. Note that this field cannot be set when spec.os.name is windows. # noqa: E501267 268 :param se_linux_change_policy: The se_linux_change_policy of this V1PodSecurityContext. # noqa: E501269 :type: str270 """271 272 self._se_linux_change_policy = se_linux_change_policy273 274 @property275 def se_linux_options(self):276 """Gets the se_linux_options of this V1PodSecurityContext. # noqa: E501277 278 279 :return: The se_linux_options of this V1PodSecurityContext. # noqa: E501280 :rtype: V1SELinuxOptions281 """282 return self._se_linux_options283 284 @se_linux_options.setter285 def se_linux_options(self, se_linux_options):286 """Sets the se_linux_options of this V1PodSecurityContext.287 288 289 :param se_linux_options: The se_linux_options of this V1PodSecurityContext. # noqa: E501290 :type: V1SELinuxOptions291 """292 293 self._se_linux_options = se_linux_options294 295 @property296 def seccomp_profile(self):297 """Gets the seccomp_profile of this V1PodSecurityContext. # noqa: E501298 299 300 :return: The seccomp_profile of this V1PodSecurityContext. # noqa: E501301 :rtype: V1SeccompProfile302 """303 return self._seccomp_profile304 305 @seccomp_profile.setter306 def seccomp_profile(self, seccomp_profile):307 """Sets the seccomp_profile of this V1PodSecurityContext.308 309 310 :param seccomp_profile: The seccomp_profile of this V1PodSecurityContext. # noqa: E501311 :type: V1SeccompProfile312 """313 314 self._seccomp_profile = seccomp_profile315 316 @property317 def supplemental_groups(self):318 """Gets the supplemental_groups of this V1PodSecurityContext. # noqa: E501319 320 A list of groups applied to the first process run in each container, in addition to the container's primary GID and fsGroup (if specified). If the SupplementalGroupsPolicy feature is enabled, the supplementalGroupsPolicy field determines whether these are in addition to or instead of any group memberships defined in the container image. If unspecified, no additional groups are added, though group memberships defined in the container image may still be used, depending on the supplementalGroupsPolicy field. Note that this field cannot be set when spec.os.name is windows. # noqa: E501321 322 :return: The supplemental_groups of this V1PodSecurityContext. # noqa: E501323 :rtype: list[int]324 """325 return self._supplemental_groups326 327 @supplemental_groups.setter328 def supplemental_groups(self, supplemental_groups):329 """Sets the supplemental_groups of this V1PodSecurityContext.330 331 A list of groups applied to the first process run in each container, in addition to the container's primary GID and fsGroup (if specified). If the SupplementalGroupsPolicy feature is enabled, the supplementalGroupsPolicy field determines whether these are in addition to or instead of any group memberships defined in the container image. If unspecified, no additional groups are added, though group memberships defined in the container image may still be used, depending on the supplementalGroupsPolicy field. Note that this field cannot be set when spec.os.name is windows. # noqa: E501332 333 :param supplemental_groups: The supplemental_groups of this V1PodSecurityContext. # noqa: E501334 :type: list[int]335 """336 337 self._supplemental_groups = supplemental_groups338 339 @property340 def supplemental_groups_policy(self):341 """Gets the supplemental_groups_policy of this V1PodSecurityContext. # noqa: E501342 343 Defines how supplemental groups of the first container processes are calculated. Valid values are \"Merge\" and \"Strict\". If not specified, \"Merge\" is used. (Alpha) Using the field requires the SupplementalGroupsPolicy feature gate to be enabled and the container runtime must implement support for this feature. Note that this field cannot be set when spec.os.name is windows. # noqa: E501344 345 :return: The supplemental_groups_policy of this V1PodSecurityContext. # noqa: E501346 :rtype: str347 """348 return self._supplemental_groups_policy349 350 @supplemental_groups_policy.setter351 def supplemental_groups_policy(self, supplemental_groups_policy):352 """Sets the supplemental_groups_policy of this V1PodSecurityContext.353 354 Defines how supplemental groups of the first container processes are calculated. Valid values are \"Merge\" and \"Strict\". If not specified, \"Merge\" is used. (Alpha) Using the field requires the SupplementalGroupsPolicy feature gate to be enabled and the container runtime must implement support for this feature. Note that this field cannot be set when spec.os.name is windows. # noqa: E501355 356 :param supplemental_groups_policy: The supplemental_groups_policy of this V1PodSecurityContext. # noqa: E501357 :type: str358 """359 360 self._supplemental_groups_policy = supplemental_groups_policy361 362 @property363 def sysctls(self):364 """Gets the sysctls of this V1PodSecurityContext. # noqa: E501365 366 Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported sysctls (by the container runtime) might fail to launch. Note that this field cannot be set when spec.os.name is windows. # noqa: E501367 368 :return: The sysctls of this V1PodSecurityContext. # noqa: E501369 :rtype: list[V1Sysctl]370 """371 return self._sysctls372 373 @sysctls.setter374 def sysctls(self, sysctls):375 """Sets the sysctls of this V1PodSecurityContext.376 377 Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported sysctls (by the container runtime) might fail to launch. Note that this field cannot be set when spec.os.name is windows. # noqa: E501378 379 :param sysctls: The sysctls of this V1PodSecurityContext. # noqa: E501380 :type: list[V1Sysctl]381 """382 383 self._sysctls = sysctls384 385 @property386 def windows_options(self):387 """Gets the windows_options of this V1PodSecurityContext. # noqa: E501388 389 390 :return: The windows_options of this V1PodSecurityContext. # noqa: E501391 :rtype: V1WindowsSecurityContextOptions392 """393 return self._windows_options394 395 @windows_options.setter396 def windows_options(self, windows_options):397 """Sets the windows_options of this V1PodSecurityContext.398 399 400 :param windows_options: The windows_options of this V1PodSecurityContext. # noqa: E501401 :type: V1WindowsSecurityContextOptions402 """403 404 self._windows_options = windows_options405 406 def to_dict(self):407 """Returns the model properties as a dict"""408 result = {}409 410 for attr, _ in six.iteritems(self.openapi_types):411 value = getattr(self, attr)412 if isinstance(value, list):413 result[attr] = list(map(414 lambda x: x.to_dict() if hasattr(x, "to_dict") else x,415 value416 ))417 elif hasattr(value, "to_dict"):418 result[attr] = value.to_dict()419 elif isinstance(value, dict):420 result[attr] = dict(map(421 lambda item: (item[0], item[1].to_dict())422 if hasattr(item[1], "to_dict") else item,423 value.items()424 ))425 else:426 result[attr] = value427 428 return result429 430 def to_str(self):431 """Returns the string representation of the model"""432 return pprint.pformat(self.to_dict())433 434 def __repr__(self):435 """For `print` and `pprint`"""436 return self.to_str()437 438 def __eq__(self, other):439 """Returns true if both objects are equal"""440 if not isinstance(other, V1PodSecurityContext):441 return False442 443 return self.to_dict() == other.to_dict()444 445 def __ne__(self, other):446 """Returns true if both objects are not equal"""447 if not isinstance(other, V1PodSecurityContext):448 return True449 450 return self.to_dict() != other.to_dict()451 