Kafka

API group/version: crabka.io/v1alpha1

Spec

FieldTypeRequiredDefaultDescription
authorizationobjectnoCluster-level authorizer selection. When None, the broker uses the default AllowAll authorizer and makes no ACL checks. When Some, the operator renders the [authorization] TOML section, so the broker builds the matching Arc<dyn Authorizer>. That is SimpleAclAuthorizer for type: simple, and OpaAuthorizer for type: opa. With simple or opa selected, the operator's inter-broker principal MUST appear in super_users. There is no implicit ANONYMOUS allow, and operators must opt in explicitly.
authorization.allowOnErrorbooleanno
authorization.expireAfterMsintegerno
authorization.initialCacheCapacityintegerno
authorization.maximumCacheSizeintegerno
authorization.superUsersarrayno
authorization.typestringyes
authorization.urlstringno
brokerTuningobjectnoValidated broker operational policy rendered into [runtime].
brokerTuning.aclMaxPrincipalstringno
brokerTuning.aclMaxResourceNamestringno
brokerTuning.auditEventQueueCapacityintegerno
brokerTuning.auditPartitionWaitTimeoutstringno
brokerTuning.auditSpoolReplayIntervalstringno
brokerTuning.auditStatsPollIntervalstringno
brokerTuning.auditTailReadMaxstringno
brokerTuning.auditTailWindowOffsetsintegerno
brokerTuning.autoJoinRetryBackoffstringno
brokerTuning.autoJoinVoterRequestTimeoutstringno
brokerTuning.classicGroupInitialRebalanceDelaystringno
brokerTuning.cleanerIntervalstringno
brokerTuning.clientMetricsDefaultIntervalstringno
brokerTuning.clientMetricsEvictionTickstringno
brokerTuning.clientMetricsOtlpQueueCapacityintegerno
brokerTuning.clientMetricsPromSnapshotTtlstringno
brokerTuning.clientMetricsStaleFloorstringno
brokerTuning.clientMetricsStalePushIntervalsintegerno
brokerTuning.clientMetricsTelemetryMaxstringno
brokerTuning.connectionCreationThrottleMaxstringno
brokerTuning.consumerGroupHeartbeatIntervalstringno
brokerTuning.consumerGroupMaxHeartbeatIntervalstringno
brokerTuning.consumerGroupMaxSessionTimeoutstringno
brokerTuning.consumerGroupMaxSizeintegerno
brokerTuning.consumerGroupMinHeartbeatIntervalstringno
brokerTuning.consumerGroupMinSessionTimeoutstringno
brokerTuning.consumerGroupSessionTimeoutstringno
brokerTuning.controlledShutdownDrainTimeoutstringno
brokerTuning.controllerElectionTimeoutstringno
brokerTuning.controllerFetchMissLimitintegerno
brokerTuning.controllerHeartbeatIntervalstringno
brokerTuning.coordinatorActorMailboxCapacityintegerno
brokerTuning.coordinatorSessionExpiryTickstringno
brokerTuning.coordinatorShutdownAckTimeoutstringno
brokerTuning.defaultMinInsyncReplicasintegerno
brokerTuning.delegationTokenDefaultRenewPeriodstringno
brokerTuning.delegationTokenExpiryCheckIntervalstringno
brokerTuning.delegationTokenMaxLifetimestringno
brokerTuning.disklessWalLocalReplicaCountintegerno
brokerTuning.futureLogMoveReadChunkstringno
brokerTuning.futureLogMoveRetryBackoffstringno
brokerTuning.gaugePollIntervalstringno
brokerTuning.heartbeatIntervalstringno
brokerTuning.heartbeatTimeoutstringno
brokerTuning.interBrokerServerNamestringno
brokerTuning.isrScanIntervalstringno
brokerTuning.leaderImbalanceCheckIntervalstringno
brokerTuning.leaderImbalancePerBrokerstringno
brokerTuning.livenessTickIntervalstringno
brokerTuning.logReadBufferCapstringno
brokerTuning.logTimestampScanWindowstringno
brokerTuning.maxConnectionsintegerno
brokerTuning.maxConnectionsPerIpintegerno
brokerTuning.maxIncrementalFetchSessionCacheSlotsintegerno
brokerTuning.maxProduceGroupintegerno
brokerTuning.metadataMaxBetweenSnapshotsstringno
brokerTuning.metadataMaxSnapshotIntervalstringno
brokerTuning.metadataRaftCommandQueueCapacityintegerno
brokerTuning.metadataRaftFetchMaxstringno
brokerTuning.metadataSnapshotFetchMaxstringno
brokerTuning.metadataSnapshotIntervalRecordsintegerno
brokerTuning.oauthJwksHttpTimeoutstringno
brokerTuning.observerFetchMaxstringno
brokerTuning.observerLagBoundintegerno
brokerTuning.observerPollIntervalstringno
brokerTuning.offsetsTopicMetadataWaitTimeoutstringno
brokerTuning.opaHttpTimeoutstringno
brokerTuning.operatorRecoveryDeadlinestringno
brokerTuning.partitionDiskScanIntervalstringno
brokerTuning.partitionWriterQueueDepthintegerno
brokerTuning.producerIdExpirationstringno
brokerTuning.producerIdExpirationScanIntervalstringno
brokerTuning.quotaThrottleMaxstringno
brokerTuning.recordDecompressionMaxRatiostringno
brokerTuning.recordDecompressionOutputCeilingstringno
brokerTuning.recordDecompressionOutputFloorstringno
brokerTuning.remoteLogManagerIntervalstringno
brokerTuning.replicaLagTimeMaxstringno
brokerTuning.replicationEpochFenceBackoffstringno
brokerTuning.replicationFetchMaxstringno
brokerTuning.replicationFetchMaxWaitstringno
brokerTuning.replicationFetchMinstringno
brokerTuning.replicationReconnectDelayCapstringno
brokerTuning.replicationReconnectInitialDelaystringno
brokerTuning.replicationSendErrorBackoffstringno
brokerTuning.replicationThrottleExhaustedBackoffstringno
brokerTuning.replicationUnexpectedErrorBackoffstringno
brokerTuning.replicationUnknownTopicRetryDelaystringno
brokerTuning.rlmmBootstrapBackoffInitialstringno
brokerTuning.rlmmBootstrapBackoffMaxstringno
brokerTuning.rlmmReconcileTickstringno
brokerTuning.selfRegistrationBackoffMaxstringno
brokerTuning.selfRegistrationBackoffMinstringno
brokerTuning.selfRegistrationMaxAttemptsintegerno
brokerTuning.sendfileMinstringno
brokerTuning.shareGroupEnablebooleanno
brokerTuning.shareGroupHeartbeatIntervalstringno
brokerTuning.shareGroupIsolationLevelstringno
brokerTuning.shareGroupMaxDeliveryAttemptsintegerno
brokerTuning.shareGroupMaxInflightRecordsintegerno
brokerTuning.shareGroupRecordLockDurationstringno
brokerTuning.shareGroupSessionTimeoutstringno
brokerTuning.shareRecoveryReadMaxstringno
brokerTuning.shareSessionCacheMaxWhenUnlimitedintegerno
brokerTuning.shareStateNumPartitionsintegerno
brokerTuning.shareStateReplicationFactorintegerno
brokerTuning.socketReceiveBufferstringno
brokerTuning.socketRequestMaxstringno
brokerTuning.socketSendBufferstringno
brokerTuning.startupLeaderWaitTimeoutstringno
brokerTuning.streamsGroupAcceptableRecoveryLagintegerno
brokerTuning.streamsGroupAssignorstringno
brokerTuning.streamsGroupHeartbeatIntervalstringno
brokerTuning.streamsGroupNumStandbyReplicasintegerno
brokerTuning.streamsGroupNumWarmupReplicasintegerno
brokerTuning.streamsGroupSessionTimeoutstringno
brokerTuning.streamsGroupTaskOffsetIntervalstringno
brokerTuning.streamsInternalTopicReplicationFactorintegerno
brokerTuning.syncGroupFollowerWaitstringno
brokerTuning.telemetryDecompressedOutputCeilingstringno
brokerTuning.telemetryDecompressedOutputFloorstringno
brokerTuning.telemetryMaxDecompressionRatiostringno
brokerTuning.tlsReloadIntervalstringno
brokerTuning.transactionMaxTimeoutstringno
brokerTuning.transactionMinTimeoutstringno
brokerTuning.transactionRecoveryReadMaxstringno
brokerTuning.transactionStateNumPartitionsintegerno
brokerTuning.transactionStateReplicationFactorintegerno
brokerTuning.txnAbortCleanupIntervalstringno
brokerTuning.uncleanRecoveryAggressiveDeadlinestringno
brokerTuning.uncleanRecoveryBalancedDeadlinestringno
brokerTuning.uncleanRecoveryQueueCapacityintegerno
clientsCaobjectnoPer-cluster CA that signs KafkaUser TLS certs. When absent, the operator uses a fully-defaulted CertificateAuthority.
clientsCa.generateCertificateAuthoritybooleannotrueWhen true, which is the default, the operator generates and renews this CA. When false, the cluster admin must create the CA Secret pair first, and the operator refuses to overwrite them. The admin renews a BYO CA. The CronJob skips a BYO CA and emits an Event when the CA comes near its expiry.
clientsCa.renewalDaysintegerno30Window in days before notAfter in which the renewal CronJob reissues the leaf certs. Default 30.
clientsCa.validityDaysintegerno365Cert validity in days. Default 365.
clusterCaobjectnoPer-cluster CA for inter-broker mTLS and broker certs. When absent, the operator uses a fully-defaulted CertificateAuthority, which it generates itself with 365/30 days.
clusterCa.generateCertificateAuthoritybooleannotrueWhen true, which is the default, the operator generates and renews this CA. When false, the cluster admin must create the CA Secret pair first, and the operator refuses to overwrite them. The admin renews a BYO CA. The CronJob skips a BYO CA and emits an Event when the CA comes near its expiry.
clusterCa.renewalDaysintegerno30Window in days before notAfter in which the renewal CronJob reissues the leaf certs. Default 30.
clusterCa.validityDaysintegerno365Cert validity in days. Default 365.
configobjectnoOpaque broker properties, in server.properties-style key and value pairs. The operator passes them through to the broker's [server_properties] TOML table, and the broker treats them as inert today. Changes propagate through the config hash.
delegationTokenobjectnoDelegation-token master HMAC key source. When None, the broker rejects all KIP-48 delegation-token RPCs with err 61 DELEGATION_TOKEN_AUTH_DISABLED. When Some, the operator injects CRABKA_DELEGATION_TOKEN_SECRET_KEY into each broker pod through a valueFrom.secretKeyRef. The key is then part of the rendered StatefulSet, so the SSA reconcile does not race with out-of-band kubectl set env patches.
delegationToken.secretKeyRefobjectyesReference to a Kubernetes Secret in the same namespace as the Kafka CR. Its data.<key> value is the broker's master HMAC key for KIP-48 delegation tokens.
delegationToken.secretKeyRef.keystringnoKey within the Secret's data. Defaults to secret-key.
delegationToken.secretKeyRef.namestringyesSecret name in the same namespace as the Kafka CR.
gresRegistryobjectnoShared creation and reader policy for the Gres tenant registry topic.
gresRegistry.fetchMaxWaitstringnoMaximum time a registry fetch waits for data.
gresRegistry.fetchPartitionMaxstringnoMaximum bytes fetched from the registry partition.
gresRegistry.producerDnsTimeoutstringnoDNS lookup deadline for the registry producer.
gresRegistry.readerAdminDnsTimeoutstringnoDNS lookup deadline for registry reader and admin paths.
gresRegistry.readerFetchMinstringnoMinimum response size for registry reader fetches.
gresRegistry.readerRetryBackoffstringnoRegistry reader retry delay.
gresRegistry.replicationFactorintegernoRegistry topic replication factor.
gresRegistry.topicCreateTimeoutstringnoKafka topic creation timeout.
interBrokerKerberosobjectnoInter-broker Kerberos initiate config. It is required when interBrokerListenerName resolves to a type: gssapi listener. It supplies the shared client principal and the KDC. The keytab comes from that listener's keytabSecretRef.
interBrokerKerberos.clientPrincipalstringyesPrincipal that every broker authenticates as when it dials peers, for example kafka@EXAMPLE.COM. It must exist in the shared keytab.
interBrokerKerberos.kdcUrlstringyesKDC endpoint, for example tcp://kdc:88.
interBrokerKerberos.serviceNamestringnoTarget SPN primary. Defaults to kafka.
interBrokerListenerNamestringnoName of the listener for inter-broker traffic. When None, the operator picks the first internal listener. When listeners is empty, the operator picks the synthesized default "PLAIN".
kafkaVersionstringyesCrabka version label. The operator propagates it to all pool pods through the app.kubernetes.io/version label.
krb5ConfSecretRefobjectnoOptional process-wide krb5.conf. The operator mounts it into the broker pods and points KRB5_CONFIG at it. It serves both the accept path and the initiate path.
krb5ConfSecretRef.keystringyesKey within the Secret whose value is the krb5.conf contents.
krb5ConfSecretRef.secretNamestringyesName of the Secret holding the krb5.conf.
listenersarraynoNamed listeners. An empty or absent list synthesizes one internal PLAIN listener on port 9092.
loggingobjectnoBroker log configuration. When None, the brokers use their built-in default RUST_LOG filter. When Some, the operator composes an inline tracing env-filter string, or reads an external one. The operator then renders it into the broker ConfigMap under the rust.log key, wires it into the RUST_LOG env of each broker pod, and rolls the cluster on a change through the config hash.
logging.loggersobjectnoInline loggers, from tracing target to level. The key root is case-insensitive and sets the global default level as a bare env-filter directive. Any other key is a tracing target, that is, a Rust module path such as crabka_broker. The levels are trace|debug|info|warn|error|off, and they are case-insensitive. fatal is accepted as an alias for error.
logging.typestringnoinline
logging.valueFromobjectnoExternal logging source. This field is required when type: external. The operator uses the value of the referenced ConfigMap key verbatim as the broker's RUST_LOG filter.
logging.valueFrom.configMapKeyRefobjectyes
logging.valueFrom.configMapKeyRef.keystringyes
logging.valueFrom.configMapKeyRef.namestringyes
metadataVersionstringnoKRaft metadata version, the runtime analog of inter.broker.protocol.version. When unset, it tracks the major.minor of kafkaVersion. When set, it pins the metadata version for the safe two-step upgrade. The operator validates it against kafkaVersion and the finalized status.metadataVersion. An invalid value surfaces KafkaVersionValid=False and blocks the roll.
metricsConfigobjectnoPrometheus scrape configuration. When None, the brokers do not bind /metrics, and the operator renders no PodMonitor and no ServiceMonitor. When Some, the broker StatefulSet gains a metrics container port on TCP 9404, and the operator SSA-applies the resources that pod_monitor and service_monitor request.
metricsConfig.podMonitorobjectno
metricsConfig.podMonitor.intervalstringno
metricsConfig.podMonitor.labelsobjectno
metricsConfig.podMonitor.scrapeTimeoutstringno
metricsConfig.serviceMonitorobjectno
metricsConfig.serviceMonitor.intervalstringno
metricsConfig.serviceMonitor.labelsobjectno
metricsConfig.serviceMonitor.scrapeTimeoutstringno
metricsConfig.typestringnoprometheus
networkPolicyobjectnoOpt-in NetworkPolicy generation. When None, the operator generates no NetworkPolicy. When Some, even {}, the operator renders a cluster-level NetworkPolicy that gates ingress to the broker and controller pods.
tieredStorageobjectnoKIP-405: cluster-wide tiered storage. When Some, every broker pod boots with the local-tier RSM enabled, with an emptyDir mounted at /var/lib/crabka/remote, which is the broker's remote_log_storage_dir, and with [remote_storage] rendered in the broker TOML. The per-topic enablement does not change. It stays KafkaTopic.spec.config["remote.storage.enable"] = "true". With the emptyDir default and InmemoryRemoteLogMetadataManager as the only RLMM, tier data does not survive pod restarts. PVC support pairs with the production RLMM.
tieredStorage.gcsobjectnoGCS-backend tuning. It is required when kind == Gcs, and it must be absent in any other case. The struct has the same shape as crabka_remote_storage::GcsConfig. The operator renders the non-credential fields verbatim into the broker TOML's [remote_storage.gcs] block. S3 uses env-var credentials, but GCS does not. The operator mounts an explicit service-account JSON key as a FILE on the broker pod and gives it to the broker as service_account_path in the TOML. Unset credentials select keyless Workload Identity or ADC.
tieredStorage.gcs.allowHttpbooleannoAllow plaintext HTTP. It is off by default. Turn it on for GCS emulators that run without TLS. Real GCS never needs it.
tieredStorage.gcs.bucketstringyesGCS bucket name. Required.
tieredStorage.gcs.credentialsobjectnoOptional explicit service-account credentials. When None, the broker uses Workload Identity or ADC, which is the keyless GKE path.
tieredStorage.gcs.credentials.serviceAccountKeyobjectyesReference to the Secret holding the service-account JSON key.
tieredStorage.gcs.credentials.serviceAccountKey.keystringnoKey within the Secret's data. Defaults to secret-key.
tieredStorage.gcs.credentials.serviceAccountKey.namestringyesSecret name in the same namespace as the Kafka CR.
tieredStorage.gcs.endpointstringnoOptional custom GCS API base URL, for example for emulators and fakes. When None, the broker uses the standard Google Cloud Storage endpoint.
tieredStorage.gcs.multipartChunkSizeintegernoOverride the per-part size for multipart uploads in bytes. When unset, the broker uses crabka_remote_storage::DEFAULT_MULTIPART_CHUNK_SIZE, which is 16 MiB.
tieredStorage.gcs.multipartThresholdintegernoOverride the single-PUT and multipart cutoff in bytes. When unset, the broker uses crabka_remote_storage::DEFAULT_MULTIPART_THRESHOLD, which is 100 MiB. Lower it in tests to exercise the multipart path on small fixtures.
tieredStorage.gcs.prefixstringnoOptional key prefix inside the bucket. It lets more than one Crabka cluster share a bucket without a collision.
tieredStorage.metadataManagerobjectnoKIP-405: pick the RemoteLogMetadataManager that the broker pods run. When the field is absent, or when it is type: Topic, the broker activates the durable crabka_remote_storage_topic::TopicBasedRemoteLogMetadataManager against the internal __remote_log_metadata topic. Tier-segment metadata then survives pod restarts and is consistent across the brokers in the cluster. Only an explicit type: InMemory selects the in-memory fixture, which is for test and dev only.
tieredStorage.metadataManager.topicobjectnoTopic-backed tuning. It is optional when kind == Topic, and the broker fills the defaults for the bootstrap and topic parameters. It must be absent in any other case.
tieredStorage.metadataManager.topic.bootstrapstringyeshost:port that the broker pod dials to reach its own listener, so that it can publish and consume __remote_log_metadata. This is usually the pod's loopback inter-broker listener, for example 127.0.0.1:9094.
tieredStorage.metadataManager.topic.eventQueueCapacityintegernoCapacity of the shared metadata-event delivery queue.
tieredStorage.metadataManager.topic.fetchMaxBytesstringnoMaximum bytes returned by each per-partition metadata fetch.
tieredStorage.metadataManager.topic.fetchMaxWaitstringnoMaximum wait for each per-partition metadata fetch.
tieredStorage.metadataManager.topic.fetchRetryBackoffstringnoBackoff after a failed metadata fetch.
tieredStorage.metadataManager.topic.numPartitionsintegernoPartition count for __remote_log_metadata on the first creation. Defaults to 50, which is the Kafka remote.log.metadata.topic.num.partitions.
tieredStorage.metadataManager.topic.replicationintegernoReplication factor for __remote_log_metadata on the first creation. Defaults to 3, which is the Kafka remote.log.metadata.topic.replication.factor.
tieredStorage.metadataManager.topic.snapshotIntervalstringnoRLMM cache snapshot cadence.
tieredStorage.metadataManager.topic.topicCreateTimeoutstringnoTimeout for provisioning each internal metadata topic.
tieredStorage.metadataManager.typestringyesImplementation selector.
tieredStorage.persistenceobjectnoKIP-405: durable storage for the local-tier directory. It is valid only with type=Local. When it is absent, which is the default, the operator renders an emptyDir for tier-storage. When Some, the operator renders a volumeClaimTemplate of the configured size and class, so tier data survives pod restarts. Together with the topic-backed RLMM, this closes the "tier data is lost on pod restart" caveat.
tieredStorage.persistence.classstringnoStorage class name. None means the cluster default.
tieredStorage.persistence.deleteClaimbooleannofalsetrue gives persistentVolumeClaimRetentionPolicy.whenDeleted: Delete. It must match the parent KafkaNodePool.spec.storage.deleteClaim when both PVCs are present, because K8s StatefulSets have one set-wide retention policy and no per-template override. The operator validates this at reconcile time, and a mismatch surfaces as TieredStorageInvalid.
tieredStorage.persistence.sizestringyesK8s Quantity, for example "50Gi" or "500Mi". It must be non-empty. The Kubernetes API server validates the resource-quantity form at SSA time.
tieredStorage.s3objectnoS3-backend tuning. It is required when kind == S3, and it must be absent in any other case. The struct has the same shape as crabka_remote_storage::S3Config. The operator renders the non-credential fields verbatim into the broker TOML's [remote_storage.s3] block. The credentials come from Kubernetes Secrets, and the operator injects them as the broker-pod env vars AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY.
tieredStorage.s3.allowHttpbooleannoAllow plaintext HTTP. It is off by default. Turn it on for a MinIO that runs without TLS. AWS S3 never needs it.
tieredStorage.s3.bucketstringyesS3 bucket name. Required.
tieredStorage.s3.credentialsobjectnoOptional explicit credentials. When None, the broker falls back to the AWS credential chain, such as IRSA on EKS or an instance profile on EC2.
tieredStorage.s3.credentials.accessKeyIdobjectyesReference to the Secret holding the AWS_ACCESS_KEY_ID value.
tieredStorage.s3.credentials.accessKeyId.keystringnoKey within the Secret's data. Defaults to secret-key.
tieredStorage.s3.credentials.accessKeyId.namestringyesSecret name in the same namespace as the Kafka CR.
tieredStorage.s3.credentials.secretAccessKeyobjectyesReference to the Secret holding the AWS_SECRET_ACCESS_KEY value.
tieredStorage.s3.credentials.secretAccessKey.keystringnoKey within the Secret's data. Defaults to secret-key.
tieredStorage.s3.credentials.secretAccessKey.namestringyesSecret name in the same namespace as the Kafka CR.
tieredStorage.s3.endpointstringnoOptional custom endpoint URL, for example http://minio:9000 for MinIO, or https://<account>.r2.cloudflarestorage.com for Cloudflare R2. When None, the broker uses the AWS S3 endpoint for the configured region.
tieredStorage.s3.multipartChunkSizeintegernoOverride the per-part size for multipart uploads in bytes. When unset, the broker uses crabka_remote_storage::DEFAULT_MULTIPART_CHUNK_SIZE, which is 16 MiB.
tieredStorage.s3.multipartThresholdintegernoOverride the single-PUT and multipart cutoff in bytes. When unset, the broker uses crabka_remote_storage::DEFAULT_MULTIPART_THRESHOLD, which is 100 MiB. Lower it in tests to exercise the multipart path on small fixtures.
tieredStorage.s3.prefixstringnoOptional key prefix inside the bucket. It lets more than one Crabka cluster share a bucket without a collision.
tieredStorage.s3.regionstringyesAWS region. It is required even for the non-AWS endpoints MinIO and R2, because the AmazonS3Builder of object_store rejects an empty region.
tieredStorage.typestringyesBackend kind selector.
tracingobjectnoDistributed-tracing wiring for the broker pods. When Some, the operator renders the matching CRABKA_OTLP_* env vars onto every broker pod. The broker's telemetry pipeline reads them with TelemetryConfig::from_env and installs the OTLP tracer at startup. When None, the operator emits no OTLP env vars, and the broker leaves tracing off. That is the default.
tracing.otlpobjectnoOTLP-backend tuning. Required when kind == Otlp.
tracing.otlp.endpointstringyesRequired. OTLP collector endpoint in the form scheme://host:port. The operator renders it as CRABKA_OTLP_ENDPOINT. A set field also sets CRABKA_OTLP_ENABLED=true.
tracing.otlp.protocolstringnoOTLP wire protocol selector. It has the same shape as the broker's internal OtlpProtocol enum and the OTEL_EXPORTER_OTLP_PROTOCOL spec values.
tracing.otlp.sampleRationumbernoOptional sampling ratio in [0.0, 1.0]. The operator renders it as CRABKA_OTLP_SAMPLE_RATIO. An unset field leaves the binary's own default of 1.0, which samples every trace.
tracing.otlp.serviceNamestringnoOptional service.name resource attribute. The operator renders it as OTEL_SERVICE_NAME. An unset field leaves the binary's own name, which is "crabka-broker" for Kafka and "crabka-gres" for Gres.
tracing.otlp.timeoutstringnoOptional export timeout. The operator renders it as CRABKA_OTLP_TIMEOUT. An unset field leaves the binary's own default of 10s.
tracing.typestringyesTracing backend selector.

Status

FieldTypeRequiredDefaultDescription
clientsCaobjectnoStatus surface for one CA. The reconciler fills it in from the parsed CA cert and the CRD spec.
clientsCa.certGenerationintegerno0Monotonic generation of the active signing cert. It increments on a same-key renewal and on a key promotion.
clientsCa.generatedbooleanyestrue when the operator generated this CA, that is, when generateCertificateAuthority == true. false for a BYO CA.
clientsCa.keyGenerationintegerno0Monotonic generation of the active signing key. It increments only on a key replacement.
clientsCa.notAfterstringyesRFC3339 notAfter of the current CA cert, which is the signing cert.
clientsCa.rotationPhasestringnoStaged key-replacement phase. One of idle, key-replace-trust, and key-replace-promote.
clientsCa.trustAnchorsintegernoNumber of CA certs in the trust bundle now.
clusterCaobjectnoStatus surface for one CA. The reconciler fills it in from the parsed CA cert and the CRD spec.
clusterCa.certGenerationintegerno0Monotonic generation of the active signing cert. It increments on a same-key renewal and on a key promotion.
clusterCa.generatedbooleanyestrue when the operator generated this CA, that is, when generateCertificateAuthority == true. false for a BYO CA.
clusterCa.keyGenerationintegerno0Monotonic generation of the active signing key. It increments only on a key replacement.
clusterCa.notAfterstringyesRFC3339 notAfter of the current CA cert, which is the signing cert.
clusterCa.rotationPhasestringnoStaged key-replacement phase. One of idle, key-replace-trust, and key-replace-promote.
clusterCa.trustAnchorsintegernoNumber of CA certs in the trust bundle now.
conditionsarrayno[]Standard Kubernetes-style condition list. It shows Ready, ListenersValid, and ListenersReady.
kafkaVersionstringnoEcho of spec.kafkaVersion, for observability.
listenersarraynoPer-listener resolved addresses. The operator fills them in once ListenersReady=True.
metadataVersionstringnoThe operator-finalized metadata version. It advances only when the version validation passes. It drives the downgrade-window check on the next reconcile.
readyReplicasintegernoThe same value as StatefulSet.status.readyReplicas.
replicasintegernoThe same value as StatefulSet.status.replicas.