Find out more about the Event Manager custom resource properties.
Note: This reference page includes only the Event Manager CR properties that you might want to view or update. Do not edit any CR properties that are not listed on this page.
spec
| Field |
Type |
Description |
| deployNetworkPolicies |
boolean |
Control deployment of NetworkPolicies used by the instance. (default: true) |
| license |
license |
Object containing product licensing details. |
| manager |
manager |
Object containing Event Manager configuration. |
spec.license
For more information about licensing, see the licensing reference.
| Field |
Type |
Description |
| accept |
boolean |
Setting to true declares that you accept the license terms and conditions. (default: false) |
| license |
string |
The license string. |
| metric |
string |
The license metric used for your product license. |
| use |
string |
The license usage. |
spec.manager
| Field |
Type |
Description |
| apic |
apic |
Object containing API Connect connection configuration. |
| authConfig |
authConfig |
Object containing authentication configuration. |
| endpoints |
[]endpoint |
List of endpoint configuration. |
| extensionServices |
object |
Configure extension service endpoints. |
| storage |
storage |
Object containing persistence configuration. |
| template |
template |
Object containing Kubernetes resource overrides. |
| tls |
tls |
Object containing TLS configuration. |
| fips |
fips |
Object containing Federal Information Processing Standard (FIPS) configuration. |
| openTelemetry |
openTelemetry |
Object containing OpenTelemetry configuration. |
| traceSpec |
string |
Dynamically configurable trace specification. |
spec.manager.apic
For integration with IBM API Connect v12.1.1.2 and later releases:
| Field |
Type |
Description |
| developerPortal |
arraydeveloperPortal |
Array of objects that contain API Connect configuration. |
For integration with IBM API Connect v10.0.6 and later 10.x.x releases:
| Field |
Type |
Description |
| clientSubjectDN |
string |
Common name used for mTLS with IBM API Connect. |
| jwks |
jwks |
Object containing jwks configuration. |
| tls |
boolean |
Enable or disable mTLS with API Connect. |
spec.manager.apic.developer-portal
| Field |
Type |
Description |
| organization |
string |
The organization name. Must use "eem". |
| endpoint |
string |
The IBM API Connect v12.1.1.2 or later URL. Must use https protocol. |
| authentication |
authentication |
Authentication configuration. |
spec.manager.apic.developerPortal
| Field |
Type |
Description |
| key |
string |
The key in the secret that holds the value of the basic authentication credentials in the format <username>:<password>. |
| secretName |
string |
The name of the secret that holds the credentials. |
spec.manager.apic.jwks
| Field |
Type |
Description |
| endpoint |
string |
Service endpoint to provide JWKS URL. |
spec.manager.authConfig
| Field |
Type |
Description |
| authType |
string |
The authentication method to use. One of LOCAL, OIDC, or INTEGRATION_KEYCLOAK. |
| oidcConfig |
oidcConfig |
Object containing OIDC configuration. |
spec.manager.authConfig.oidcConfig
| Field |
Type |
Description |
| additionalScopes |
array[string] |
Additional scopes over openid, profile, and email that are required. Useful with authorizationClaimPointer. |
| authorizationClaimPointer |
string |
A JSON pointer to a claim in the ID token from the provider, which is used for mapping authorization roles (for example, "/resource_access/client_id/roles"). |
| authorizationPath |
string |
The path to the authorization endpoint of this provider. |
| clientIDKey |
string |
The key in the secret that contains the OIDC Client ID. |
| clientSecretKey |
string |
The key in the secret that contains the OIDC Secret Key. |
| discovery |
boolean |
Whether to use OIDC discovery to retrieve the configuration for this provider. |
| endSessionPath |
string |
The path to the end session endpoint of this provider. |
| secretName |
string |
Secret containing OIDC credentials. |
| site |
string |
The site of the OIDC provider. |
| tokenPath |
string |
The path to the token endpoint of this provider. |
| userGroupClaimPointer |
string |
A JSON pointer to a claim in the ID token from the provider, which is used for adding user groups, for example \"/resource_access/client_id/groups\". |
| userInfoPath |
string |
The path to the user info endpoint of this provider |
Important: Removing groups from the userGroupClaimPointer field can have unintended consequences. Before you change the value for this field, review the information in disabling user groups.
spec.manager.authentication
| Field |
Type |
Description |
| maxRetries |
integer |
The maximum number of failed authentication attempts after which further attempts are blocked. Default is -1 (no limit). |
| retryBackoffMs |
integer |
The backoff time in milliseconds between consecutive failed authentication attempts. Default is 0. |
| lockoutPeriod |
integer |
The duration in seconds while the account is locked after an unsuccessful authentication attempt. Default is 0. |
spec.manager.endpoints
| Field |
Type |
Description |
| annotations |
map[string] |
The annotations to apply to the ingress resource. When class is nginx (the default), this overrides the default nginx annotations. When class is set to any other value, no annotations are injected automatically and this field is the only way to set annotations on the ingress resource. |
| class |
string |
The ingress class name to use on the ingress resource, defaults to nginx. When set to a value other than nginx, you must also set annotations with the SSL passthrough annotation keys for your ingress controller. For an example, see using a non-nginx ingress controller. |
| host |
string |
The DNS resolvable hostname to set on the ingress endpoint. |
| name |
string |
The name of the endpoint. For valid values, see the following important notes. |
Important:
- On the OpenShift Container Platform,
annotations and class are not valid configuration options because OpenShift routes are created.
- On other Kubernetes platforms, you must specify host values for exposed endpoints.
- Valid values for
name are: ui, gateway, admin, server, and apic.
spec.manager.fips
| Field |
Type |
Description |
| mode |
string |
The value for Federal Information Processing Standard (FIPS) mode. Valid value is ‘wall’. |
spec.manager.template
| Field |
Type |
Description |
| annotations |
object |
Annotations that are added to all Kubernetes resources used by the instance. Any annotations that are added to the template object and later deleted are not automatically removed from resources that are already instantiated. These annotations need to be manually removed from the existing resources. |
| labels |
object |
Labels that are added to all Kubernetes resources used by the instance. |
| pod |
pod |
Object containing pod override configuration. |
spec.manager.template.pod
| Field |
Type |
Description |
| spec |
podSpec |
Kubernetes pod spec overrides. |
spec.manager.storage
| Field |
Type |
Description |
| deleteClaim |
boolean |
Specifies whether the persistent volume claim must be deleted when the instance is deleted. |
| existingClaimName |
string |
The name of a pre-created Persistence Volume Claim (PVC). |
| root |
string |
The root storage path where data is stored. |
| rotationSecretName |
string |
The Kubernetes secret that is used for supplying a new encryption key. This field should only be set temporarily during the process of rotating the encryption key. |
| selectors |
object |
Labels to be used during PVC bind. |
| size |
string |
The storage size limit for the volume. Default is 500Mi. |
| storageClassName |
string |
The storage class name to use on created Persistent Volume Claims (PVCs). |
| type |
string |
Type of persistence to use. One of ephemeral or persistent-claim. |
spec.manager.tls
| Field |
Type |
Description |
| caCertificate |
string |
The key in the secret that holds the value of the CA certificate. |
| caSecretName |
string |
The name of a secret that contains a root CA certificate that the product uses when it creates additional certificates. |
| key |
string |
The key in the secret that holds the value of the private key. |
| secretName |
string |
The name of a secret that contains certificates for securing component communications. |
| serverCertificate |
string |
The key in the secret that holds the value of the server certificate. |
| trustedCertificates |
array[trustedCertificate] |
A set of secrets that contain certificates that the Event Manager must trust to communicate with other services, such as gateways or OIDC providers. |
| ui |
ui |
Object containing TLS configuration explicitly for the UI. (Not present in eventgateway.events.ibm.com/v1beta1) |
spec.manager.tls.trustedCertificates
| Field |
Type |
Description |
| certificate |
string |
The key within the specified secret that holds the value of the CA certificate. |
| secretName |
string |
The name of a Kubernetes secret that contains a CA certificate to add to the truststore. |
spec.manager.tls.ui
| Field |
Type |
Description |
| caCertificate |
string |
The key in the secret that holds the value of the CA certificate. |
| key |
string |
The key in the secret that holds the value of the private key. |
| secretName |
string |
The name of a secret containing certificates for securing component communications. |
| serverCertificate |
string |
The key in the secret that holds the value of the server certificate. |
spec.manager.openTelemetry
| Field |
Type |
Description |
| endpoint |
string |
The endpoint to send the OpenTelemetry metrics. Must include http:// or https:// |
| protocol |
string |
The transport protocol to use, grpc (default) or http/protobuf. |
| interval |
integer |
The interval between reporting of metrics in milliseconds. Default is 30000. |
| tls |
otelTLS |
The configuration of SSL Certificates for mTLS and a trusted certificate for endpoint server validation. |
| instrumentations |
[]instrumentation |
A list of instrumentations to enable in addition to the instrumentations for the Event Manager and Event Gateway. |
spec.manager.openTelemetry.tls
| Field |
Type |
Description |
| clientCertificate |
string |
The key in the secret that holds the value of the PKCS8 encoded client certificate to use for mutualTLS (mTLS). |
| clientKey |
string |
The key in the secret that holds the value of the PKCS8 encoded private key certificate to use for mutualTLS (mTLS). |
| secretName |
string |
The name of a secret containing certificates for securing component communications for mutualTLS (mTLS). |
| trustedCertificate |
[] |
Configuration of a secret that contains a TLS certificate to trust to validate the endpoint servers identity. |
spec.manager.openTelemetry.instrumentation
| Field |
Type |
Description |
| name |
string |
The instrumentation name. |
| enabled |
boolean |
Whether to enable or disabled the specified instrumentation. |
Important:
- The instrumentation name must be the instrumentation shortname. The supplied shortname is then configured as an env var against the relevant pod as
OTEL_INSTRUMENTATION_<name>_ENABLED=<enabled> automatically.
status
| Field |
Type |
Description |
| conditions |
array[condition] |
A list of conditions that represent the state of the custom resource. |
| versions |
versions |
Object containing versioning information. |
| endpoints |
array[endpoint] |
A list of endpoints exposed by the instance. |
| phase |
string |
Represents the phase in which the instance is operating. One of Running, Failed, or Pending. |
status.versions
| Field |
Type |
Description |
| reconciled |
string |
The reconciled version of the instance |
| available |
available |
Object containing available versions. |
status.versions.available
| Field |
Type |
Description |
| versions |
array[version] |
A list of the available versions. |
| channels |
array[channel] |
A list of the available channels. |
status.versions.available.versions
| Field |
Type |
Description |
| name |
string |
The semantic version number. |
| licenses |
array[] |
A list of available licenses. |
status.versions.available.channels
| Field |
Type |
Description |
| name |
string |
The semantic version number. |
| licenses |
array[] |
A list of available licenses. |
status.conditions
| Field |
Type |
Description |
| lastTransitionTime |
string |
The time at which the condition was applied. |
| message |
string |
Human-readable message that contains details about the condition. |
| reason |
string |
Machine-readable, UpperCamelCase text that indicates the reason for the condition. |
| status |
string |
Indicates whether that condition is applicable. One of True, False, or Unknown. |
status.endpoints
| Field |
Type |
Description |
| name |
string |
Unique name for the endpoint. |
| type |
string |
Type of service the endpoint exposes. For example, UI or API. |
| scope |
string |
The scope of the endpoint. For example, External, Internal. |
| uri |
string |
The URI of the endpoint. |