Skip to main content
Version: Next (Private Preview)

NexoConnectionPipeline

:::danger Ineffective contract

The Operator validates and records this Kind, but does not deliver its connection settings to the current runtime.

:::

This page documents the current development contract. Schema acceptance, Operator reconciliation, and runtime enforcement are separate claims; the status above is authoritative.

API identity

PropertyValue
KindNexoConnectionPipeline
API groupnexo.io
Versionv1alpha1
Resourcenexoconnectionpipelines
Short namencpl
ScopeNamespaced
Operator supportIneffective contract

Purpose and relationships

Records intended connection-layer TLS, handshake, identity, authentication, limits, and pooling policy as schema and graph metadata.

NexoProxy can reference it through spec.connectionPipelineRef, but the current Operator omits the unconsumed connection-pipeline configuration from runtime mounts.

Spec field reference

The table is derived from the installed Nexo Edge CRD OpenAPI schema. “Not declared” means the schema publishes no default. A missing schema description is reported explicitly rather than inferred from implementation.

FieldTypeRequiredDefaultSchema description
spec.tlsConfigobjectNoNot declaredNo description is declared in the CRD schema.
spec.tlsConfig.modestringNoNot declaredNo description is declared in the CRD schema. Allowed values: terminate, passthrough, mutual.
spec.tlsConfig.certificateRefobjectNoNot declaredNo description is declared in the CRD schema.
spec.tlsConfig.certificateRef.namestringYesNot declaredNo description is declared in the CRD schema.
spec.tlsConfig.minVersionstringNoNot declaredNo description is declared in the CRD schema. Allowed values: TLS1.2, TLS1.3.
spec.tlsConfig.cipherSuitesarray<string>NoNot declaredNo description is declared in the CRD schema.
spec.handshakeobjectNoNot declaredNo description is declared in the CRD schema.
spec.handshake.timeoutstringNoNot declaredNo description is declared in the CRD schema.
spec.handshake.maxPayloadSizeinteger (int64)NoNot declaredNo description is declared in the CRD schema. Minimum: 1.
spec.handshake.compressionarray<string>NoNot declaredNo description is declared in the CRD schema.
spec.tenantIdentificationobjectNoNot declaredNo description is declared in the CRD schema.
spec.tenantIdentification.strategystringNoNot declaredNo description is declared in the CRD schema. Allowed values: connectionString, certificate, header, static.
spec.tenantIdentification.fieldstringNoNot declaredNo description is declared in the CRD schema.
spec.tenantIdentification.fallbackstringNoNot declaredNo description is declared in the CRD schema.
spec.tenantIdentification.securityLevelstringNoNot declaredNo description is declared in the CRD schema. Allowed values: ``, strict, relaxed.
spec.connectionLimitsobjectNoNot declaredNo description is declared in the CRD schema.
spec.connectionLimits.maxConnectionsPerTenantinteger (int32)NoNot declaredNo description is declared in the CRD schema. Minimum: 0.
spec.connectionLimits.maxConnectionsGlobalinteger (int32)NoNot declaredNo description is declared in the CRD schema. Minimum: 0.
spec.connectionLimits.idleTimeoutstringNoNot declaredNo description is declared in the CRD schema.
spec.connectionLimits.maxLifetimestringNoNot declaredNo description is declared in the CRD schema.
spec.connectionLimits.maxTrackedTenantsinteger (int32)NoNot declaredNo description is declared in the CRD schema. Minimum: 0.
spec.authenticationobjectNoNot declaredNo description is declared in the CRD schema.
spec.authentication.strategystringNoNot declaredNo description is declared in the CRD schema. Allowed values: scram-sha-256, x509, ldap, passthrough.
spec.authentication.secretRefobjectNoNot declaredNo description is declared in the CRD schema.
spec.authentication.secretRef.namestringYesNot declaredNo description is declared in the CRD schema.
spec.authentication.cacheTTLstringNoNot declaredNo description is declared in the CRD schema.
spec.poolingobjectNoNot declaredNo description is declared in the CRD schema.
spec.pooling.modestringNo"none"No description is declared in the CRD schema. Allowed values: ``, none, session, transaction.
spec.pooling.maxServerConnectionsinteger (int32)NoNot declaredNo description is declared in the CRD schema. Minimum: 0.
spec.pooling.minIdleConnectionsinteger (int32)NoNot declaredNo description is declared in the CRD schema. Minimum: 0.
spec.pooling.maxConnectionAgestringNoNot declaredNo description is declared in the CRD schema.
spec.proxyRefobjectNoNot declaredNo description is declared in the CRD schema.
spec.proxyRef.namestringYesNot declaredNo description is declared in the CRD schema.

Status fields and conditions

FieldTypeRequiredDefaultSchema description
status.phasestringNoNot declaredNo description is declared in the CRD schema. Allowed values: Pending, Ready, Failed.
status.readybooleanNoNot declaredNo description is declared in the CRD schema.
status.observedGenerationinteger (int64)NoNot declaredNo description is declared in the CRD schema.
status.configHashstringNoNot declaredNo description is declared in the CRD schema.
status.conditionsarray<object>NoNot declaredNo description is declared in the CRD schema.
status.conditions[].typestringNoNot declaredNo description is declared in the CRD schema.
status.conditions[].statusstringNoNot declaredNo description is declared in the CRD schema.
status.conditions[].reasonstringNoNot declaredNo description is declared in the CRD schema.
status.conditions[].messagestringNoNot declaredNo description is declared in the CRD schema.
status.conditions[].lastTransitionTimestring (date-time)NoNot declaredNo description is declared in the CRD schema.
status.conditions[].observedGenerationinteger (int64)NoNot declaredNo description is declared in the CRD schema.

A Ready or configHash value proves that the Operator accepted/hashed the object; it does not by itself prove runtime execution or policy enforcement.

Reconciliation and watch behavior

The registered controller validates the resource and records status. Data-path changes are applied only when the relevant NexoProxy controller rebuilds or reloads the owning graph.

At startup, the current NexoProxy controller installs a typed watch when the CRD is discoverable. A CRD installed after Operator startup requires an Operator restart before that reference watch is added.

Runtime execution effect

None in the current runtime path. TLS, handshake, tenant identification, authentication, limits, and pooling values are validated and recorded as graph metadata but are not mounted into a runtime container. Configure supported listener and upstream TLS on NexoDeploymentProfile.

Example

Use placeholders and validate in a non-production namespace first. For schema-only or ineffective kinds, this example is for schema inspection only and must not be used as evidence of enforcement.

# Schema inspection only; this Kind has no current runtime enforcement.
apiVersion: nexo.io/v1alpha1
kind: NexoConnectionPipeline
metadata:
name: <connection-policy-name>
namespace: <namespace>
spec:
tlsConfig:
mode: passthrough

Update and reconciliation caveats

  • Apply component and pipeline changes before expecting the owning NexoProxy graph to change.
  • Check metadata.generation, status.observedGeneration when present, and the owning Proxy graphRevision/appliedRevision after every update.
  • A successful kubectl apply proves only schema admission; inspect Operator conditions, generated configuration, rollout state, and runtime behavior separately.

Release-specific limitations

  • The API is v1alpha1 and has no conversion webhook or second served version.
  • The CRD schema is retained by Helm and can outlive the Operator release that installed it.
  • Current documentation can describe unreleased development behavior; verify the exact deployed bundle and image digests.

Inspect with kubectl

kubectl get nexoconnectionpipelines --namespace <namespace>
kubectl describe nexoconnectionpipelines <name> --namespace <namespace>
kubectl get nexoconnectionpipelines <name> --namespace <namespace> -o yaml
kubectl get crd nexoconnectionpipelines.nexo.io -o yaml

For resources participating in a Proxy graph, also inspect:

kubectl get nexoproxy <proxy-name> --namespace <namespace> \
-o jsonpath='{.status.phase}{" graph="}{.status.graphRevision}{" applied="}{.status.appliedRevision}{"\n"}'
kubectl get nexopipeline <pipeline-name> --namespace <namespace> -o yaml

Search Nexo documentation

Type to search titles, headings, and page content.