Skip to content

MachineConfiguration [operator.openshift.io/v1]

Description

MachineConfiguration provides information to configure an operator to manage Machine Configuration.

Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer).

Type
`object`
Required
  • spec

Specification

Property Type Description
apiVersion string APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind string Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata ObjectMeta Standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata
spec object spec is the specification of the desired behavior of the Machine Config Operator
status object status is the most recently observed status of the Machine Config Operator

.spec

Description
spec is the specification of the desired behavior of the Machine Config Operator
Type
`object`
Property Type Description
bootImageSkewEnforcement object bootImageSkewEnforcement allows an admin to configure how boot image version skew is enforced on the cluster. When omitted, this will default to Automatic for clusters that support automatic boot image updates. For clusters that do not support automatic boot image updates, cluster upgrades will be disabled until a skew enforcement mode has been specified. When version skew is being enforced, cluster upgrades will be disabled until the version skew is deemed acceptable for the current release payload.
failedRevisionLimit integer failedRevisionLimit is the number of failed static pod installer revisions to keep on disk and in the api -1 = unlimited, 0 or unset = 5 (default)
forceRedeploymentReason string forceRedeploymentReason can be used to force the redeployment of the operand by providing a unique string. This provides a mechanism to kick a previously failed deployment and provide a reason why you think it will work this time instead of failing again on the same config.
logLevel string logLevel is an intent based logging for an overall component. It does not give fine grained control, but it is a simple way to manage coarse grained logging choices that operators have to interpret for their operands.
Valid values are: "Normal", "Debug", "Trace", "TraceAll". Defaults to "Normal".
managedBootImages object managedBootImages allows configuration for the management of boot images for machine resources within the cluster. This configuration allows users to select resources that should be updated to the latest boot images during cluster upgrades, ensuring that new machines always boot with the current cluster version’s boot image. When omitted, this means no opinion and the platform is left to choose a reasonable default, which is subject to change over time. The default for each machine manager mode is All for GCP and AWS platforms, and None for all other platforms.
managementState string managementState indicates whether and how the operator should manage the component
nodeDisruptionPolicy object nodeDisruptionPolicy allows an admin to set granular node disruption actions for MachineConfig-based updates, such as drains, service reloads, etc. Specifying this will allow for less downtime when doing small configuration updates to the cluster. This configuration has no effect on cluster upgrades which will still incur node disruption where required.
observedConfig `` observedConfig holds a sparse config that controller has observed from the cluster state. It exists in spec because it is an input to the level for the operator
operatorLogLevel string operatorLogLevel is an intent based logging for the operator itself. It does not give fine grained control, but it is a simple way to manage coarse grained logging choices that operators have to interpret for themselves.
Valid values are: "Normal", "Debug", "Trace", "TraceAll". Defaults to "Normal".
succeededRevisionLimit integer succeededRevisionLimit is the number of successful static pod installer revisions to keep on disk and in the api -1 = unlimited, 0 or unset = 5 (default)
unsupportedConfigOverrides `` unsupportedConfigOverrides overrides the final configuration that was computed by the operator. Red Hat does not support the use of this field. Misuse of this field could lead to unexpected behavior or conflict with other configuration options. Seek guidance from the Red Hat support before using this field. Use of this property blocks cluster upgrades, it must be removed before upgrading your cluster.

.spec.bootImageSkewEnforcement

Description
bootImageSkewEnforcement allows an admin to configure how boot image version skew is enforced on the cluster. When omitted, this will default to Automatic for clusters that support automatic boot image updates. For clusters that do not support automatic boot image updates, cluster upgrades will be disabled until a skew enforcement mode has been specified. When version skew is being enforced, cluster upgrades will be disabled until the version skew is deemed acceptable for the current release payload.
Type
`object`
Required
  • mode
Property Type Description
manual object manual describes the current boot image of the cluster. This should be set to the oldest boot image used amongst all machine resources in the cluster. This must include either the RHCOS version of the boot image or the OCP release version which shipped with that RHCOS boot image. Required when mode is set to "Manual" and forbidden otherwise.
mode string mode determines the underlying behavior of skew enforcement mechanism. Valid values are Manual and None. Manual means that the cluster admin is expected to perform manual boot image updates and store the OCP & RHCOS version associated with the last boot image update in the manual field. In Manual mode, the MCO will prevent upgrades when the boot image skew exceeds the skew limit described by the release image. None means that the MCO will no longer monitor the boot image skew. This may affect the cluster’s ability to scale. This field is required.

.spec.bootImageSkewEnforcement.manual

Description
manual describes the current boot image of the cluster. This should be set to the oldest boot image used amongst all machine resources in the cluster. This must include either the RHCOS version of the boot image or the OCP release version which shipped with that RHCOS boot image. Required when mode is set to "Manual" and forbidden otherwise.
Type
`object`
Required
  • mode
Property Type Description
mode string mode is used to configure which boot image field is defined in Manual mode. Valid values are OCPVersion and RHCOSVersion. OCPVersion means that the cluster admin is expected to set the OCP version associated with the last boot image update in the OCPVersion field. RHCOSVersion means that the cluster admin is expected to set the RHCOS version associated with the last boot image update in the RHCOSVersion field. This field is required.
ocpVersion string ocpVersion provides a string which represents the OCP version of the boot image. This field must match the OCP semver compatible format of x.y.z. This field must be between 5 and 10 characters long. Required when mode is set to "OCPVersion" and forbidden otherwise.
rhcosVersion string rhcosVersion provides a string which represents the RHCOS version of the boot image This field must match rhcosVersion formatting of [major].[minor].[datestamp(YYYYMMDD)]-[buildnumber] or the legacy format of [major].[minor].[timestamp(YYYYMMDDHHmm)]-[buildnumber]. This field must be between 14 and 21 characters long. Required when mode is set to "RHCOSVersion" and forbidden otherwise.

.spec.managedBootImages

Description
managedBootImages allows configuration for the management of boot images for machine resources within the cluster. This configuration allows users to select resources that should be updated to the latest boot images during cluster upgrades, ensuring that new machines always boot with the current cluster version’s boot image. When omitted, this means no opinion and the platform is left to choose a reasonable default, which is subject to change over time. The default for each machine manager mode is All for GCP and AWS platforms, and None for all other platforms.
Type
`object`
Property Type Description
machineManagers array machineManagers can be used to register machine management resources for boot image updates. The Machine Config Operator will watch for changes to this list. Only one entry is permitted per type of machine management resource.
machineManagers[] object MachineManager describes a target machine resource that is registered for boot image updates. It stores identifying information such as the resource type and the API Group of the resource. It also provides granular control via the selection field.

.spec.managedBootImages.machineManagers

Description
machineManagers can be used to register machine management resources for boot image updates. The Machine Config Operator will watch for changes to this list. Only one entry is permitted per type of machine management resource.
Type
`array`

.spec.managedBootImages.machineManagers[]

Description
MachineManager describes a target machine resource that is registered for boot image updates. It stores identifying information such as the resource type and the API Group of the resource. It also provides granular control via the selection field.
Type
`object`
Required
  • apiGroup
  • resource
  • selection
Property Type Description
apiGroup string apiGroup is name of the APIGroup that the machine management resource belongs to. The only current valid value is machine.openshift.io. machine.openshift.io means that the machine manager will only register resources that belong to OpenShift machine API group.
resource string resource is the machine management resource’s type. Valid values are machinesets and controlplanemachinesets. machinesets means that the machine manager will only register resources of the kind MachineSet. controlplanemachinesets means that the machine manager will only register resources of the kind ControlPlaneMachineSet.
selection object selection allows granular control of the machine management resources that will be registered for boot image updates.

.spec.managedBootImages.machineManagers[].selection

Description
selection allows granular control of the machine management resources that will be registered for boot image updates.
Type
`object`
Required
  • mode
Property Type Description
mode string mode determines how machine managers will be selected for updates. Valid values are All, Partial and None. All means that every resource matched by the machine manager will be updated. Partial requires specified selector(s) and allows customisation of which resources matched by the machine manager will be updated. Partial is not permitted for the controlplanemachinesets resource type as they are a singleton within the cluster. None means that every resource matched by the machine manager will not be updated.
partial object partial provides label selector(s) that can be used to match machine management resources. Only permitted when mode is set to "Partial".

.spec.managedBootImages.machineManagers[].selection.partial

Description
partial provides label selector(s) that can be used to match machine management resources. Only permitted when mode is set to "Partial".
Type
`object`
Required
  • machineResourceSelector
Property Type Description
machineResourceSelector object machineResourceSelector is a label selector that can be used to select machine resources like MachineSets.

.spec.managedBootImages.machineManagers[].selection.partial.machineResourceSelector

Description
machineResourceSelector is a label selector that can be used to select machine resources like MachineSets.
Type
`object`
Property Type Description
matchExpressions array matchExpressions is a list of label selector requirements. The requirements are ANDed.
matchExpressions[] object A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values.
matchLabels object (string) matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

.spec.managedBootImages.machineManagers[].selection.partial.machineResourceSelector.matchExpressions

Description
matchExpressions is a list of label selector requirements. The requirements are ANDed.
Type
`array`

.spec.managedBootImages.machineManagers[].selection.partial.machineResourceSelector.matchExpressions[]

Description
A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values.
Type
`object`
Required
  • key
  • operator
Property Type Description
key string key is the label key that the selector applies to.
operator string operator represents a key’s relationship to a set of values. Valid operators are In, NotIn, Exists and DoesNotExist.
values array (string) values is an array of string values. If the operator is In or NotIn, the values array must be non-empty. If the operator is Exists or DoesNotExist, the values array must be empty. This array is replaced during a strategic merge patch.

.spec.nodeDisruptionPolicy

Description
nodeDisruptionPolicy allows an admin to set granular node disruption actions for MachineConfig-based updates, such as drains, service reloads, etc. Specifying this will allow for less downtime when doing small configuration updates to the cluster. This configuration has no effect on cluster upgrades which will still incur node disruption where required.
Type
`object`
Property Type Description
files array files is a list of MachineConfig file definitions and actions to take to changes on those paths This list supports a maximum of 50 entries.
files[] object NodeDisruptionPolicySpecFile is a file entry and corresponding actions to take and is used in the NodeDisruptionPolicyConfig object
sshkey object sshkey maps to the ignition.sshkeys field in the MachineConfig object, definition an action for this will apply to all sshkey changes in the cluster
units array units is a list MachineConfig unit definitions and actions to take on changes to those services This list supports a maximum of 50 entries.
units[] object NodeDisruptionPolicySpecUnit is a systemd unit name and corresponding actions to take and is used in the NodeDisruptionPolicyConfig object

.spec.nodeDisruptionPolicy.files

Description
files is a list of MachineConfig file definitions and actions to take to changes on those paths This list supports a maximum of 50 entries.
Type
`array`

.spec.nodeDisruptionPolicy.files[]

Description
NodeDisruptionPolicySpecFile is a file entry and corresponding actions to take and is used in the NodeDisruptionPolicyConfig object
Type
`object`
Required
  • actions
  • path
Property Type Description
actions array actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
actions[] object
path string path is the location of a file being managed through a MachineConfig. The Actions in the policy will apply to changes to the file at this path.

.spec.nodeDisruptionPolicy.files[].actions

Description
actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
Type
`array`

.spec.nodeDisruptionPolicy.files[].actions[]

Description

Type
`object`
Required
  • type
Property Type Description
reload object reload specifies the service to reload, only valid if type is reload
restart object restart specifies the service to restart, only valid if type is restart
type string type represents the commands that will be carried out if this NodeDisruptionPolicySpecActionType is executed Valid values are Reboot, Drain, Reload, Restart, DaemonReload and None. reload/restart requires a corresponding service target specified in the reload/restart field. Other values require no further configuration

.spec.nodeDisruptionPolicy.files[].actions[].reload

Description
reload specifies the service to reload, only valid if type is reload
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be reloaded Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.spec.nodeDisruptionPolicy.files[].actions[].restart

Description
restart specifies the service to restart, only valid if type is restart
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be restarted Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.spec.nodeDisruptionPolicy.sshkey

Description
sshkey maps to the ignition.sshkeys field in the MachineConfig object, definition an action for this will apply to all sshkey changes in the cluster
Type
`object`
Required
  • actions
Property Type Description
actions array actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
actions[] object

.spec.nodeDisruptionPolicy.sshkey.actions

Description
actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
Type
`array`

.spec.nodeDisruptionPolicy.sshkey.actions[]

Description

Type
`object`
Required
  • type
Property Type Description
reload object reload specifies the service to reload, only valid if type is reload
restart object restart specifies the service to restart, only valid if type is restart
type string type represents the commands that will be carried out if this NodeDisruptionPolicySpecActionType is executed Valid values are Reboot, Drain, Reload, Restart, DaemonReload and None. reload/restart requires a corresponding service target specified in the reload/restart field. Other values require no further configuration

.spec.nodeDisruptionPolicy.sshkey.actions[].reload

Description
reload specifies the service to reload, only valid if type is reload
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be reloaded Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.spec.nodeDisruptionPolicy.sshkey.actions[].restart

Description
restart specifies the service to restart, only valid if type is restart
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be restarted Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.spec.nodeDisruptionPolicy.units

Description
units is a list MachineConfig unit definitions and actions to take on changes to those services This list supports a maximum of 50 entries.
Type
`array`

.spec.nodeDisruptionPolicy.units[]

Description
NodeDisruptionPolicySpecUnit is a systemd unit name and corresponding actions to take and is used in the NodeDisruptionPolicyConfig object
Type
`object`
Required
  • actions
  • name
Property Type Description
actions array actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
actions[] object
name string name represents the service name of a systemd service managed through a MachineConfig Actions specified will be applied for changes to the named service. Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.spec.nodeDisruptionPolicy.units[].actions

Description
actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
Type
`array`

.spec.nodeDisruptionPolicy.units[].actions[]

Description

Type
`object`
Required
  • type
Property Type Description
reload object reload specifies the service to reload, only valid if type is reload
restart object restart specifies the service to restart, only valid if type is restart
type string type represents the commands that will be carried out if this NodeDisruptionPolicySpecActionType is executed Valid values are Reboot, Drain, Reload, Restart, DaemonReload and None. reload/restart requires a corresponding service target specified in the reload/restart field. Other values require no further configuration

.spec.nodeDisruptionPolicy.units[].actions[].reload

Description
reload specifies the service to reload, only valid if type is reload
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be reloaded Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.spec.nodeDisruptionPolicy.units[].actions[].restart

Description
restart specifies the service to restart, only valid if type is restart
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be restarted Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.status

Description
status is the most recently observed status of the Machine Config Operator
Type
`object`
Property Type Description
bootImageSkewEnforcementStatus object bootImageSkewEnforcementStatus reflects what the latest cluster-validated boot image skew enforcement configuration is and will be used by Machine Config Controller while performing boot image skew enforcement. When omitted, the MCO has no knowledge of how to enforce boot image skew. When the MCO does not know how boot image skew should be enforced, cluster upgrades will be blocked until it can either automatically determine skew enforcement or there is an explicit skew enforcement configuration provided in the spec.bootImageSkewEnforcement field.
conditions array conditions is a list of conditions and their status
conditions[] object Condition contains details for one aspect of the current state of this API Resource.
managedBootImagesStatus object managedBootImagesStatus reflects what the latest cluster-validated boot image configuration is and will be used by Machine Config Controller while performing boot image updates.
nodeDisruptionPolicyStatus object nodeDisruptionPolicyStatus status reflects what the latest cluster-validated policies are, and will be used by the Machine Config Daemon during future node updates.
observedGeneration integer observedGeneration is the last generation change you’ve dealt with

.status.bootImageSkewEnforcementStatus

Description
bootImageSkewEnforcementStatus reflects what the latest cluster-validated boot image skew enforcement configuration is and will be used by Machine Config Controller while performing boot image skew enforcement. When omitted, the MCO has no knowledge of how to enforce boot image skew. When the MCO does not know how boot image skew should be enforced, cluster upgrades will be blocked until it can either automatically determine skew enforcement or there is an explicit skew enforcement configuration provided in the spec.bootImageSkewEnforcement field.
Type
`object`
Required
  • mode
Property Type Description
automatic object automatic describes the current boot image of the cluster. This will be populated by the MCO when performing boot image updates. This value will be compared against the cluster’s skew limit to determine skew compliance. Required when mode is set to "Automatic" and forbidden otherwise.
manual object manual describes the current boot image of the cluster. This will be populated by the MCO using the values provided in the spec.bootImageSkewEnforcement.manual field. This value will be compared against the cluster’s skew limit to determine skew compliance. Required when mode is set to "Manual" and forbidden otherwise.
mode string mode determines the underlying behavior of skew enforcement mechanism. Valid values are Automatic, Manual and None. Automatic means that the MCO will perform boot image updates and store the OCP & RHCOS version associated with the last boot image update in the automatic field. Manual means that the cluster admin is expected to perform manual boot image updates and store the OCP & RHCOS version associated with the last boot image update in the manual field. In Automatic and Manual mode, the MCO will prevent upgrades when the boot image skew exceeds the skew limit described by the release image. None means that the MCO will no longer monitor the boot image skew. This may affect the cluster’s ability to scale. This field is required.

.status.bootImageSkewEnforcementStatus.automatic

Description
automatic describes the current boot image of the cluster. This will be populated by the MCO when performing boot image updates. This value will be compared against the cluster’s skew limit to determine skew compliance. Required when mode is set to "Automatic" and forbidden otherwise.
Type
`object`
Property Type Description
ocpVersion string ocpVersion provides a string which represents the OCP version of the boot image. This field must match the OCP semver compatible format of x.y.z. This field must be between 5 and 10 characters long.
rhcosVersion string rhcosVersion provides a string which represents the RHCOS version of the boot image This field must match rhcosVersion formatting of [major].[minor].[datestamp(YYYYMMDD)]-[buildnumber] or the legacy format of [major].[minor].[timestamp(YYYYMMDDHHmm)]-[buildnumber]. This field must be between 14 and 21 characters long.

.status.bootImageSkewEnforcementStatus.manual

Description
manual describes the current boot image of the cluster. This will be populated by the MCO using the values provided in the spec.bootImageSkewEnforcement.manual field. This value will be compared against the cluster’s skew limit to determine skew compliance. Required when mode is set to "Manual" and forbidden otherwise.
Type
`object`
Required
  • mode
Property Type Description
mode string mode is used to configure which boot image field is defined in Manual mode. Valid values are OCPVersion and RHCOSVersion. OCPVersion means that the cluster admin is expected to set the OCP version associated with the last boot image update in the OCPVersion field. RHCOSVersion means that the cluster admin is expected to set the RHCOS version associated with the last boot image update in the RHCOSVersion field. This field is required.
ocpVersion string ocpVersion provides a string which represents the OCP version of the boot image. This field must match the OCP semver compatible format of x.y.z. This field must be between 5 and 10 characters long. Required when mode is set to "OCPVersion" and forbidden otherwise.
rhcosVersion string rhcosVersion provides a string which represents the RHCOS version of the boot image This field must match rhcosVersion formatting of [major].[minor].[datestamp(YYYYMMDD)]-[buildnumber] or the legacy format of [major].[minor].[timestamp(YYYYMMDDHHmm)]-[buildnumber]. This field must be between 14 and 21 characters long. Required when mode is set to "RHCOSVersion" and forbidden otherwise.

.status.conditions

Description
conditions is a list of conditions and their status
Type
`array`

.status.conditions[]

Description
Condition contains details for one aspect of the current state of this API Resource.
Type
`object`
Required
  • lastTransitionTime
  • message
  • reason
  • status
  • type
Property Type Description
lastTransitionTime string lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
message string message is a human readable message indicating details about the transition. This may be an empty string.
observedGeneration integer observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
reason string reason contains a programmatic identifier indicating the reason for the condition’s last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty.
status string status of the condition, one of True, False, Unknown.
type string type of condition in CamelCase or in foo.example.com/CamelCase.

.status.managedBootImagesStatus

Description
managedBootImagesStatus reflects what the latest cluster-validated boot image configuration is and will be used by Machine Config Controller while performing boot image updates.
Type
`object`
Property Type Description
machineManagers array machineManagers can be used to register machine management resources for boot image updates. The Machine Config Operator will watch for changes to this list. Only one entry is permitted per type of machine management resource.
machineManagers[] object MachineManager describes a target machine resource that is registered for boot image updates. It stores identifying information such as the resource type and the API Group of the resource. It also provides granular control via the selection field.

.status.managedBootImagesStatus.machineManagers

Description
machineManagers can be used to register machine management resources for boot image updates. The Machine Config Operator will watch for changes to this list. Only one entry is permitted per type of machine management resource.
Type
`array`

.status.managedBootImagesStatus.machineManagers[]

Description
MachineManager describes a target machine resource that is registered for boot image updates. It stores identifying information such as the resource type and the API Group of the resource. It also provides granular control via the selection field.
Type
`object`
Required
  • apiGroup
  • resource
  • selection
Property Type Description
apiGroup string apiGroup is name of the APIGroup that the machine management resource belongs to. The only current valid value is machine.openshift.io. machine.openshift.io means that the machine manager will only register resources that belong to OpenShift machine API group.
resource string resource is the machine management resource’s type. Valid values are machinesets and controlplanemachinesets. machinesets means that the machine manager will only register resources of the kind MachineSet. controlplanemachinesets means that the machine manager will only register resources of the kind ControlPlaneMachineSet.
selection object selection allows granular control of the machine management resources that will be registered for boot image updates.

.status.managedBootImagesStatus.machineManagers[].selection

Description
selection allows granular control of the machine management resources that will be registered for boot image updates.
Type
`object`
Required
  • mode
Property Type Description
mode string mode determines how machine managers will be selected for updates. Valid values are All, Partial and None. All means that every resource matched by the machine manager will be updated. Partial requires specified selector(s) and allows customisation of which resources matched by the machine manager will be updated. Partial is not permitted for the controlplanemachinesets resource type as they are a singleton within the cluster. None means that every resource matched by the machine manager will not be updated.
partial object partial provides label selector(s) that can be used to match machine management resources. Only permitted when mode is set to "Partial".

.status.managedBootImagesStatus.machineManagers[].selection.partial

Description
partial provides label selector(s) that can be used to match machine management resources. Only permitted when mode is set to "Partial".
Type
`object`
Required
  • machineResourceSelector
Property Type Description
machineResourceSelector object machineResourceSelector is a label selector that can be used to select machine resources like MachineSets.

.status.managedBootImagesStatus.machineManagers[].selection.partial.machineResourceSelector

Description
machineResourceSelector is a label selector that can be used to select machine resources like MachineSets.
Type
`object`
Property Type Description
matchExpressions array matchExpressions is a list of label selector requirements. The requirements are ANDed.
matchExpressions[] object A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values.
matchLabels object (string) matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels map is equivalent to an element of matchExpressions, whose key field is "key", the operator is "In", and the values array contains only "value". The requirements are ANDed.

.status.managedBootImagesStatus.machineManagers[].selection.partial.machineResourceSelector.matchExpressions

Description
matchExpressions is a list of label selector requirements. The requirements are ANDed.
Type
`array`

.status.managedBootImagesStatus.machineManagers[].selection.partial.machineResourceSelector.matchExpressions[]

Description
A label selector requirement is a selector that contains values, a key, and an operator that relates the key and values.
Type
`object`
Required
  • key
  • operator
Property Type Description
key string key is the label key that the selector applies to.
operator string operator represents a key’s relationship to a set of values. Valid operators are In, NotIn, Exists and DoesNotExist.
values array (string) values is an array of string values. If the operator is In or NotIn, the values array must be non-empty. If the operator is Exists or DoesNotExist, the values array must be empty. This array is replaced during a strategic merge patch.

.status.nodeDisruptionPolicyStatus

Description
nodeDisruptionPolicyStatus status reflects what the latest cluster-validated policies are, and will be used by the Machine Config Daemon during future node updates.
Type
`object`
Property Type Description
clusterPolicies object clusterPolicies is a merge of cluster default and user provided node disruption policies.

.status.nodeDisruptionPolicyStatus.clusterPolicies

Description
clusterPolicies is a merge of cluster default and user provided node disruption policies.
Type
`object`
Property Type Description
files array files is a list of MachineConfig file definitions and actions to take to changes on those paths
files[] object NodeDisruptionPolicyStatusFile is a file entry and corresponding actions to take and is used in the NodeDisruptionPolicyClusterStatus object
sshkey object sshkey is the overall sshkey MachineConfig definition
units array units is a list MachineConfig unit definitions and actions to take on changes to those services
units[] object NodeDisruptionPolicyStatusUnit is a systemd unit name and corresponding actions to take and is used in the NodeDisruptionPolicyClusterStatus object

.status.nodeDisruptionPolicyStatus.clusterPolicies.files

Description
files is a list of MachineConfig file definitions and actions to take to changes on those paths
Type
`array`

.status.nodeDisruptionPolicyStatus.clusterPolicies.files[]

Description
NodeDisruptionPolicyStatusFile is a file entry and corresponding actions to take and is used in the NodeDisruptionPolicyClusterStatus object
Type
`object`
Required
  • actions
  • path
Property Type Description
actions array actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
actions[] object
path string path is the location of a file being managed through a MachineConfig. The Actions in the policy will apply to changes to the file at this path.

.status.nodeDisruptionPolicyStatus.clusterPolicies.files[].actions

Description
actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
Type
`array`

.status.nodeDisruptionPolicyStatus.clusterPolicies.files[].actions[]

Description

Type
`object`
Required
  • type
Property Type Description
reload object reload specifies the service to reload, only valid if type is reload
restart object restart specifies the service to restart, only valid if type is restart
type string type represents the commands that will be carried out if this NodeDisruptionPolicyStatusActionType is executed Valid values are Reboot, Drain, Reload, Restart, DaemonReload, None and Special. reload/restart requires a corresponding service target specified in the reload/restart field. Other values require no further configuration

.status.nodeDisruptionPolicyStatus.clusterPolicies.files[].actions[].reload

Description
reload specifies the service to reload, only valid if type is reload
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be reloaded Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.status.nodeDisruptionPolicyStatus.clusterPolicies.files[].actions[].restart

Description
restart specifies the service to restart, only valid if type is restart
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be restarted Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.status.nodeDisruptionPolicyStatus.clusterPolicies.sshkey

Description
sshkey is the overall sshkey MachineConfig definition
Type
`object`
Required
  • actions
Property Type Description
actions array actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
actions[] object

.status.nodeDisruptionPolicyStatus.clusterPolicies.sshkey.actions

Description
actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
Type
`array`

.status.nodeDisruptionPolicyStatus.clusterPolicies.sshkey.actions[]

Description

Type
`object`
Required
  • type
Property Type Description
reload object reload specifies the service to reload, only valid if type is reload
restart object restart specifies the service to restart, only valid if type is restart
type string type represents the commands that will be carried out if this NodeDisruptionPolicyStatusActionType is executed Valid values are Reboot, Drain, Reload, Restart, DaemonReload, None and Special. reload/restart requires a corresponding service target specified in the reload/restart field. Other values require no further configuration

.status.nodeDisruptionPolicyStatus.clusterPolicies.sshkey.actions[].reload

Description
reload specifies the service to reload, only valid if type is reload
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be reloaded Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.status.nodeDisruptionPolicyStatus.clusterPolicies.sshkey.actions[].restart

Description
restart specifies the service to restart, only valid if type is restart
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be restarted Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.status.nodeDisruptionPolicyStatus.clusterPolicies.units

Description
units is a list MachineConfig unit definitions and actions to take on changes to those services
Type
`array`

.status.nodeDisruptionPolicyStatus.clusterPolicies.units[]

Description
NodeDisruptionPolicyStatusUnit is a systemd unit name and corresponding actions to take and is used in the NodeDisruptionPolicyClusterStatus object
Type
`object`
Required
  • actions
  • name
Property Type Description
actions array actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
actions[] object
name string name represents the service name of a systemd service managed through a MachineConfig Actions specified will be applied for changes to the named service. Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.status.nodeDisruptionPolicyStatus.clusterPolicies.units[].actions

Description
actions represents the series of commands to be executed on changes to the file at the corresponding file path. Actions will be applied in the order that they are set in this list. If there are other incoming changes to other MachineConfig entries in the same update that require a reboot, the reboot will supercede these actions. Valid actions are Reboot, Drain, Reload, DaemonReload and None. The Reboot action and the None action cannot be used in conjunction with any of the other actions. This list supports a maximum of 10 entries.
Type
`array`

.status.nodeDisruptionPolicyStatus.clusterPolicies.units[].actions[]

Description

Type
`object`
Required
  • type
Property Type Description
reload object reload specifies the service to reload, only valid if type is reload
restart object restart specifies the service to restart, only valid if type is restart
type string type represents the commands that will be carried out if this NodeDisruptionPolicyStatusActionType is executed Valid values are Reboot, Drain, Reload, Restart, DaemonReload, None and Special. reload/restart requires a corresponding service target specified in the reload/restart field. Other values require no further configuration

.status.nodeDisruptionPolicyStatus.clusterPolicies.units[].actions[].reload

Description
reload specifies the service to reload, only valid if type is reload
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be reloaded Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

.status.nodeDisruptionPolicyStatus.clusterPolicies.units[].actions[].restart

Description
restart specifies the service to restart, only valid if type is restart
Type
`object`
Required
  • serviceName
Property Type Description
serviceName string serviceName is the full name (e.g. crio.service) of the service to be restarted Service names should be of the format \({NAME}\) must be one of ".service", ".socket", ".device", ".mount", ".automount", ".swap", ".target", ".path", ".timer", ".snapshot", ".slice" or ".scope".} and can up to 255 characters long. ${NAME} must be atleast 1 character long and can only consist of alphabets, digits, ":", "-", "_", ".", and "". ${SERVICETYPE

API endpoints

The following API endpoints are available:

  • /apis/operator.openshift.io/v1/machineconfigurations

    • DELETE: delete collection of MachineConfiguration
    • GET: list objects of kind MachineConfiguration
    • POST: create a MachineConfiguration
  • /apis/operator.openshift.io/v1/machineconfigurations/{name}

    • DELETE: delete a MachineConfiguration
    • GET: read the specified MachineConfiguration
    • PATCH: partially update the specified MachineConfiguration
    • PUT: replace the specified MachineConfiguration
  • /apis/operator.openshift.io/v1/machineconfigurations/{name}/status

    • GET: read status of the specified MachineConfiguration
    • PATCH: partially update status of the specified MachineConfiguration
    • PUT: replace status of the specified MachineConfiguration

/apis/operator.openshift.io/v1/machineconfigurations

HTTP method
`DELETE`
Description
delete collection of MachineConfiguration

HTTP responses

HTTP code Reponse body
200 - OK Status schema
401 - Unauthorized Empty
HTTP method
`GET`
Description
list objects of kind MachineConfiguration

HTTP responses

HTTP code Reponse body
200 - OK MachineConfigurationList schema
401 - Unauthorized Empty
HTTP method
`POST`
Description
create a MachineConfiguration

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

Body parameters

Parameter Type Description
body MachineConfiguration schema

HTTP responses

HTTP code Reponse body
200 - OK MachineConfiguration schema
201 - Created MachineConfiguration schema
202 - Accepted MachineConfiguration schema
401 - Unauthorized Empty

/apis/operator.openshift.io/v1/machineconfigurations/{name}

Global path parameters

Parameter Type Description
name string name of the MachineConfiguration
HTTP method
`DELETE`
Description
delete a MachineConfiguration

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed

HTTP responses

HTTP code Reponse body
200 - OK Status schema
202 - Accepted Status schema
401 - Unauthorized Empty
HTTP method
`GET`
Description
read the specified MachineConfiguration

HTTP responses

HTTP code Reponse body
200 - OK MachineConfiguration schema
401 - Unauthorized Empty
HTTP method
`PATCH`
Description
partially update the specified MachineConfiguration

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

HTTP responses

HTTP code Reponse body
200 - OK MachineConfiguration schema
401 - Unauthorized Empty
HTTP method
`PUT`
Description
replace the specified MachineConfiguration

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

Body parameters

Parameter Type Description
body MachineConfiguration schema

HTTP responses

HTTP code Reponse body
200 - OK MachineConfiguration schema
201 - Created MachineConfiguration schema
401 - Unauthorized Empty

/apis/operator.openshift.io/v1/machineconfigurations/{name}/status

Global path parameters

Parameter Type Description
name string name of the MachineConfiguration
HTTP method
`GET`
Description
read status of the specified MachineConfiguration

HTTP responses

HTTP code Reponse body
200 - OK MachineConfiguration schema
401 - Unauthorized Empty
HTTP method
`PATCH`
Description
partially update status of the specified MachineConfiguration

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

HTTP responses

HTTP code Reponse body
200 - OK MachineConfiguration schema
401 - Unauthorized Empty
HTTP method
`PUT`
Description
replace status of the specified MachineConfiguration

Query parameters

Parameter Type Description
dryRun string When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed
fieldValidation string fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered.

Body parameters

Parameter Type Description
body MachineConfiguration schema

HTTP responses

HTTP code Reponse body
200 - OK MachineConfiguration schema
201 - Created MachineConfiguration schema
401 - Unauthorized Empty