Ingress
This declares one Ingress to be managed by Orkestra.
Example:
onReconcile:
ingresses:
- name: "{{ .metadata.name }}-ingress"
host: "{{ .spec.hostname }}"
serviceName: "{{ .metadata.name }}-svc"
servicePort: "{{ .spec.port }}"
path: /
pathType: Prefix
className: nginx
tls:
create: true
secretName: "{{ .metadata.name }}-tls"
hosts:
- "{{ .spec.hostname }}"
Lifecycle
Declare this resource under onCreate for an idempotent, one-time create: Orkestra creates it on the first reconcile and leaves it untouched afterward. Set reconcile: true on the same entry to also apply it as drift correction on every subsequent reconcile. This is a shorthand for declaring the identical entry under onReconcile as well — there’s no need to do both.
Declare a resource under onDelete to run explicit cleanup before the CR’s finalizer is removed. Most resources need no onDelete entry — they are garbage-collected automatically through owner references when the CR itself is deleted.
Fields
name
Type: string
Name — Ingress resource name. Default: “{{ .metadata.name }}-ingress”
namespace
Type: string
Namespace — target namespace. Default: CR namespace.
host
Type: string
Host — virtual host name for the Ingress rule.
serviceName
Type: string
ServiceName — backend Service name this Ingress routes to.
servicePort
Type: string
ServicePort — backend Service port as a string. Supports template expressions.
path
Type: string
Path — HTTP path prefix. Default: “/”
pathType
Type: string
PathType — Kubernetes IngressPathType: Prefix, Exact, ImplementationSpecific. Default: Prefix.
className
Type: string
IngressClass — Ingress class name (nginx, traefik, etc.). Optional.
labels
Type: map
Labels applied to Ingress metadata. Values support template expressions.
annotations
Type: map
Annotations applied to Ingress metadata. Values support template expressions.
tls
Type: object
TLS — optional TLS configuration. When tls.create is true, Orkestra generates a self-signed TLS Secret before creating the Ingress.
tls:
create: true
secretName: "{{ .metadata.name }}-tls"
hosts:
- "{{ .spec.hostname }}"
reconcile
Type: boolean
Reconcile: true — also apply this declaration as drift correction on every reconcile. Equivalent to declaring the same entry under both onCreate and onReconcile. When false (default), only runs on onCreate (idempotent create).
when
Type: list
Conditions declares the set of runtime predicates that must all evaluate to true for this resource template to be applied during reconciliation.
Each condition inspects a field on the live Custom Resource using dot-notation (e.g. “spec.enabled”, “metadata.labels.tier”) and compares it against a value using the chosen operator. All conditions in the list are AND‑ed together.
If any condition fails, the resource is skipped for that reconcile cycle. This is not an error — it simply means “do not create/update this resource right now”. This enables expressive, data‑driven orchestration such as:
when:
- field: spec.exposePublicly
equals: "true"
- field: spec.environment
prefix: "prod"
Conditions allow templates to be selectively activated based on the CR’s state, enabling dynamic topologies, feature flags, environment‑specific behavior, and conditional provisioning without writing Go code.
anyOf
Type: list
AnyOf holds OR conditions — at least one must pass for this resource to be created. Works alongside the existing Conditions (when:) field which uses AND semantics.
anyOf:
- field: spec.tier
equals: pro
- field: spec.tier
equals: enterprise
forEach
Type: object
ForEach declares dynamic expansion over a list field. When set, one source declaration becomes N declarations — one per list element. .item and .<as> are available in template expressions within this declaration.
forEach:
field: spec.regions
as: region
sleep
Type: string
Sleep injects an artificial delay into the reconcile of this resource. Useful for autoscale testing, latency simulation, and chaos engineering. Accepts extended duration units (s, m, h, d, w, mo, y).
Quick reference
| YAML key | Type |
|---|---|
name | string |
namespace | string |
host | string |
serviceName | string |
servicePort | string |
path | string |
pathType | string |
className | string |
labels | map |
annotations | map |
tls | object |
reconcile | boolean |
when | list |
anyOf | list |
forEach | object |
sleep | string |