tatara-prometheus-operator 0.2.4

Tatara domain wrapping 1 CRD(s).
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
1001
1002
1003
1004
1005
1006
1007
1008
1009
1010
1011
1012
1013
1014
1015
1016
1017
1018
1019
1020
1021
1022
1023
1024
1025
1026
1027
1028
1029
1030
1031
1032
1033
1034
1035
1036
1037
1038
1039
1040
1041
1042
1043
1044
1045
1046
1047
1048
1049
1050
1051
1052
1053
1054
1055
1056
1057
1058
1059
1060
1061
1062
1063
1064
1065
1066
1067
1068
1069
1070
1071
1072
1073
1074
1075
1076
1077
1078
1079
1080
1081
1082
1083
1084
1085
1086
1087
1088
1089
1090
1091
1092
1093
1094
1095
1096
1097
1098
1099
1100
//! tatara-prometheus-operator — auto-generated tatara domain.
//!
//! Tatara domain wrapping 1 CRD(s).
//!
//! Generated by `tatara-domain-forge`. Do not hand-edit.
//! Re-run the generator to refresh.

#![allow(clippy::module_name_repetitions)]

use serde::{Deserialize, Serialize};
use tatara_lisp_derive::TataraDomain;

/// The `PodMonitor` custom resource definition (CRD) defines how `Prometheus` and `PrometheusAgent` can scrape metrics from a group of pods.
/// Among other things, it allows to specify:
/// * The pods to scrape via label selectors.
/// * The container ports to scrape.
/// * Authentication credentials to use.
/// * Target and metric relabeling.
/// 
/// `Prometheus` and `PrometheusAgent` objects select `PodMonitor` objects using label and namespace selectors.
#[derive(Debug, Clone, Serialize, Deserialize, TataraDomain)]
#[tatara(keyword = "defpodmonitor")]
pub struct PodMonitorSpec {
    /// `attachMetadata` defines additional metadata which is added to the
    /// discovered targets.
    /// 
    /// It requires Prometheus >= v2.35.0.
    #[serde(default)]
    pub attach_metadata: Option<PodMonitorAttachMetadata>,
    /// When defined, bodySizeLimit specifies a job level limit on the size
    /// of uncompressed response body that will be accepted by Prometheus.
    /// 
    /// It requires Prometheus >= v2.28.0.
    #[serde(default)]
    pub body_size_limit: Option<String>,
    /// The protocol to use if a scrape returns blank, unparseable, or otherwise invalid Content-Type.
    /// 
    /// It requires Prometheus >= v3.0.0.
    #[serde(default)]
    pub fallback_scrape_protocol: Option<PodMonitorFallbackScrapeProtocolKind>,
    /// The label to use to retrieve the job name from.
    /// `jobLabel` selects the label from the associated Kubernetes `Pod`
    /// object which will be used as the `job` label for all metrics.
    /// 
    /// For example if `jobLabel` is set to `foo` and the Kubernetes `Pod`
    /// object is labeled with `foo: bar`, then Prometheus adds the `job="bar"`
    /// label to all ingested metrics.
    /// 
    /// If the value of this field is empty, the `job` label of the metrics
    /// defaults to the namespace and name of the PodMonitor object (e.g. `<namespace>/<name>`).
    #[serde(default)]
    pub job_label: Option<String>,
    /// Per-scrape limit on the number of targets dropped by relabeling
    /// that will be kept in memory. 0 means no limit.
    /// 
    /// It requires Prometheus >= v2.47.0.
    #[serde(default)]
    pub keep_dropped_targets: Option<i64>,
    /// Per-scrape limit on number of labels that will be accepted for a sample.
    /// 
    /// It requires Prometheus >= v2.27.0.
    #[serde(default)]
    pub label_limit: Option<i64>,
    /// Per-scrape limit on length of labels name that will be accepted for a sample.
    /// 
    /// It requires Prometheus >= v2.27.0.
    #[serde(default)]
    pub label_name_length_limit: Option<i64>,
    /// Per-scrape limit on length of labels value that will be accepted for a sample.
    /// 
    /// It requires Prometheus >= v2.27.0.
    #[serde(default)]
    pub label_value_length_limit: Option<i64>,
    /// `namespaceSelector` defines in which namespace(s) Prometheus should discover the pods.
    /// By default, the pods are discovered in the same namespace as the `PodMonitor` object but it is possible to select pods across different/all namespaces.
    #[serde(default)]
    pub namespace_selector: Option<PodMonitorNamespaceSelector>,
    /// If there are more than this many buckets in a native histogram,
    /// buckets will be merged to stay within the limit.
    /// It requires Prometheus >= v2.45.0.
    #[serde(default)]
    pub native_histogram_bucket_limit: Option<i64>,
    /// If the growth factor of one bucket to the next is smaller than this,
    /// buckets will be merged to increase the factor sufficiently.
    /// It requires Prometheus >= v2.50.0.
    #[serde(default)]
    pub native_histogram_min_bucket_factor: Option<serde_json::Value>,
    /// Defines how to scrape metrics from the selected pods.
    #[serde(default)]
    pub pod_metrics_endpoints: Option<Vec<PodMonitorPodMetricsEndpointsItem>>,
    /// `podTargetLabels` defines the labels which are transferred from the
    /// associated Kubernetes `Pod` object onto the ingested metrics.
    #[serde(default)]
    pub pod_target_labels: Option<Vec<String>>,
    /// `sampleLimit` defines a per-scrape limit on the number of scraped samples
    /// that will be accepted.
    #[serde(default)]
    pub sample_limit: Option<i64>,
    /// The scrape class to apply.
    #[serde(default)]
    pub scrape_class: Option<String>,
    /// Whether to scrape a classic histogram that is also exposed as a native histogram.
    /// It requires Prometheus >= v2.45.0.
    #[serde(default)]
    pub scrape_classic_histograms: Option<bool>,
    /// `scrapeProtocols` defines the protocols to negotiate during a scrape. It tells clients the
    /// protocols supported by Prometheus in order of preference (from most to least preferred).
    /// 
    /// If unset, Prometheus uses its default value.
    /// 
    /// It requires Prometheus >= v2.49.0.
    #[serde(default)]
    pub scrape_protocols: Option<Vec<PodMonitorScrapeProtocolsItemKind>>,
    /// Label selector to select the Kubernetes `Pod` objects to scrape metrics from.
    pub selector: PodMonitorSelector,
    /// Mechanism used to select the endpoints to scrape.
    /// By default, the selection process relies on relabel configurations to filter the discovered targets.
    /// Alternatively, you can opt in for role selectors, which may offer better efficiency in large clusters.
    /// Which strategy is best for your use case needs to be carefully evaluated.
    /// 
    /// It requires Prometheus >= v2.17.0.
    #[serde(default)]
    pub selector_mechanism: Option<PodMonitorSelectorMechanismKind>,
    /// `targetLimit` defines a limit on the number of scraped targets that will
    /// be accepted.
    #[serde(default)]
    pub target_limit: Option<i64>,
}

// ── Nested types ──────────────────────────────────────
#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorAttachMetadata {
    /// When set to true, Prometheus attaches node metadata to the discovered
    /// targets.
    /// 
    /// The Prometheus service account must have the `list` and `watch`
    /// permissions on the `Nodes` objects.
    #[serde(default)]
    pub node: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorFallbackScrapeProtocolKind {
    #[serde(rename = "PrometheusProto")]
    PrometheusProto,
    #[serde(rename = "OpenMetricsText0.0.1")]
    OpenMetricsText001,
    #[serde(rename = "OpenMetricsText1.0.0")]
    OpenMetricsText100,
    #[serde(rename = "PrometheusText0.0.4")]
    PrometheusText004,
    #[serde(rename = "PrometheusText1.0.0")]
    PrometheusText100,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorNamespaceSelector {
    /// Boolean describing whether all namespaces are selected in contrast to a
    /// list restricting them.
    #[serde(default)]
    pub any: Option<bool>,
    /// List of namespace names to select from.
    #[serde(default)]
    pub match_names: Option<Vec<String>>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemAuthorizationCredentials {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemAuthorization {
    /// Selects a key of a Secret in the namespace that contains the credentials for authentication.
    #[serde(default)]
    pub credentials: Option<PodMonitorPodMetricsEndpointsItemAuthorizationCredentials>,
    /// Defines the authentication type. The value is case-insensitive.
    /// 
    /// "Basic" is not a supported value.
    /// 
    /// Default: "Bearer"
    #[serde(default)]
    pub r#type: Option<String>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemBasicAuthPassword {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemBasicAuthUsername {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemBasicAuth {
    /// `password` specifies a key of a Secret containing the password for
    /// authentication.
    #[serde(default)]
    pub password: Option<PodMonitorPodMetricsEndpointsItemBasicAuthPassword>,
    /// `username` specifies a key of a Secret containing the username for
    /// authentication.
    #[serde(default)]
    pub username: Option<PodMonitorPodMetricsEndpointsItemBasicAuthUsername>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemBearerTokenSecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorPodMetricsEndpointsItemMetricRelabelingsItemActionKind {
    #[serde(rename = "replace")]
    Replace,
    #[serde(rename = "Replace")]
    ReplaceV1,
    #[serde(rename = "keep")]
    Keep,
    #[serde(rename = "Keep")]
    KeepV1,
    #[serde(rename = "drop")]
    Drop,
    #[serde(rename = "Drop")]
    DropV1,
    #[serde(rename = "hashmod")]
    Hashmod,
    #[serde(rename = "HashMod")]
    HashMod,
    #[serde(rename = "labelmap")]
    Labelmap,
    #[serde(rename = "LabelMap")]
    LabelMap,
    #[serde(rename = "labeldrop")]
    Labeldrop,
    #[serde(rename = "LabelDrop")]
    LabelDrop,
    #[serde(rename = "labelkeep")]
    Labelkeep,
    #[serde(rename = "LabelKeep")]
    LabelKeep,
    #[serde(rename = "lowercase")]
    Lowercase,
    #[serde(rename = "Lowercase")]
    LowercaseV1,
    #[serde(rename = "uppercase")]
    Uppercase,
    #[serde(rename = "Uppercase")]
    UppercaseV1,
    #[serde(rename = "keepequal")]
    Keepequal,
    #[serde(rename = "KeepEqual")]
    KeepEqual,
    #[serde(rename = "dropequal")]
    Dropequal,
    #[serde(rename = "DropEqual")]
    DropEqual,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemMetricRelabelingsItem {
    /// Action to perform based on the regex matching.
    /// 
    /// `Uppercase` and `Lowercase` actions require Prometheus >= v2.36.0.
    /// `DropEqual` and `KeepEqual` actions require Prometheus >= v2.41.0.
    /// 
    /// Default: "Replace"
    #[serde(default)]
    pub action: Option<PodMonitorPodMetricsEndpointsItemMetricRelabelingsItemActionKind>,
    /// Modulus to take of the hash of the source label values.
    /// 
    /// Only applicable when the action is `HashMod`.
    #[serde(default)]
    pub modulus: Option<i64>,
    /// Regular expression against which the extracted value is matched.
    #[serde(default)]
    pub regex: Option<String>,
    /// Replacement value against which a Replace action is performed if the
    /// regular expression matches.
    /// 
    /// Regex capture groups are available.
    #[serde(default)]
    pub replacement: Option<String>,
    /// Separator is the string between concatenated SourceLabels.
    #[serde(default)]
    pub separator: Option<String>,
    /// The source labels select values from existing labels. Their content is
    /// concatenated using the configured Separator and matched against the
    /// configured regular expression.
    #[serde(default)]
    pub source_labels: Option<Vec<String>>,
    /// Label to which the resulting string is written in a replacement.
    /// 
    /// It is mandatory for `Replace`, `HashMod`, `Lowercase`, `Uppercase`,
    /// `KeepEqual` and `DropEqual` actions.
    /// 
    /// Regex capture groups are available.
    #[serde(default)]
    pub target_label: Option<String>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2ClientIdConfigMap {
    /// The key to select.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the ConfigMap or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2ClientIdSecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2ClientId {
    /// ConfigMap containing data to use for the targets.
    #[serde(default)]
    pub config_map: Option<PodMonitorPodMetricsEndpointsItemOauth2ClientIdConfigMap>,
    /// Secret containing data to use for the targets.
    #[serde(default)]
    pub secret: Option<PodMonitorPodMetricsEndpointsItemOauth2ClientIdSecret>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2ClientSecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2ProxyConnectHeaderValueItem {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCaConfigMap {
    /// The key to select.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the ConfigMap or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCaSecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCa {
    /// ConfigMap containing data to use for the targets.
    #[serde(default)]
    pub config_map: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCaConfigMap>,
    /// Secret containing data to use for the targets.
    #[serde(default)]
    pub secret: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCaSecret>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCertConfigMap {
    /// The key to select.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the ConfigMap or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCertSecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCert {
    /// ConfigMap containing data to use for the targets.
    #[serde(default)]
    pub config_map: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCertConfigMap>,
    /// Secret containing data to use for the targets.
    #[serde(default)]
    pub secret: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCertSecret>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2TlsConfigKeySecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorPodMetricsEndpointsItemOauth2TlsConfigMaxVersionKind {
    #[serde(rename = "TLS10")]
    TLS10,
    #[serde(rename = "TLS11")]
    TLS11,
    #[serde(rename = "TLS12")]
    TLS12,
    #[serde(rename = "TLS13")]
    TLS13,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorPodMetricsEndpointsItemOauth2TlsConfigMinVersionKind {
    #[serde(rename = "TLS10")]
    TLS10,
    #[serde(rename = "TLS11")]
    TLS11,
    #[serde(rename = "TLS12")]
    TLS12,
    #[serde(rename = "TLS13")]
    TLS13,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2TlsConfig {
    /// Certificate authority used when verifying server certificates.
    #[serde(default)]
    pub ca: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCa>,
    /// Client certificate to present when doing client-authentication.
    #[serde(default)]
    pub cert: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigCert>,
    /// Disable target certificate validation.
    #[serde(default)]
    pub insecure_skip_verify: Option<bool>,
    /// Secret containing the client key file for the targets.
    #[serde(default)]
    pub key_secret: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigKeySecret>,
    /// Maximum acceptable TLS version.
    /// 
    /// It requires Prometheus >= v2.41.0.
    #[serde(default)]
    pub max_version: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigMaxVersionKind>,
    /// Minimum acceptable TLS version.
    /// 
    /// It requires Prometheus >= v2.35.0.
    #[serde(default)]
    pub min_version: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfigMinVersionKind>,
    /// Used to verify the hostname for the targets.
    #[serde(default)]
    pub server_name: Option<String>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemOauth2 {
    /// `clientId` specifies a key of a Secret or ConfigMap containing the
    /// OAuth2 client's ID.
    pub client_id: PodMonitorPodMetricsEndpointsItemOauth2ClientId,
    /// `clientSecret` specifies a key of a Secret containing the OAuth2
    /// client's secret.
    pub client_secret: PodMonitorPodMetricsEndpointsItemOauth2ClientSecret,
    /// `endpointParams` configures the HTTP parameters to append to the token
    /// URL.
    #[serde(default)]
    pub endpoint_params: Option<std::collections::HashMap<String, String>>,
    /// `noProxy` is a comma-separated string that can contain IPs, CIDR notation, domain names
    /// that should be excluded from proxying. IP and domain names can
    /// contain port numbers.
    /// 
    /// It requires Prometheus >= v2.43.0 or Alertmanager >= 0.25.0.
    #[serde(default)]
    pub no_proxy: Option<String>,
    /// ProxyConnectHeader optionally specifies headers to send to
    /// proxies during CONNECT requests.
    /// 
    /// It requires Prometheus >= v2.43.0 or Alertmanager >= 0.25.0.
    #[serde(default)]
    pub proxy_connect_header: Option<std::collections::HashMap<String, Vec<PodMonitorPodMetricsEndpointsItemOauth2ProxyConnectHeaderValueItem>>>,
    /// Whether to use the proxy configuration defined by environment variables (HTTP_PROXY, HTTPS_PROXY, and NO_PROXY).
    /// 
    /// It requires Prometheus >= v2.43.0 or Alertmanager >= 0.25.0.
    #[serde(default)]
    pub proxy_from_environment: Option<bool>,
    /// `proxyURL` defines the HTTP proxy server to use.
    #[serde(default)]
    pub proxy_url: Option<String>,
    /// `scopes` defines the OAuth2 scopes used for the token request.
    #[serde(default)]
    pub scopes: Option<Vec<String>>,
    /// TLS configuration to use when connecting to the OAuth2 server.
    /// It requires Prometheus >= v2.43.0.
    #[serde(default)]
    pub tls_config: Option<PodMonitorPodMetricsEndpointsItemOauth2TlsConfig>,
    /// `tokenURL` configures the URL to fetch the token from.
    pub token_url: String,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorPodMetricsEndpointsItemRelabelingsItemActionKind {
    #[serde(rename = "replace")]
    Replace,
    #[serde(rename = "Replace")]
    ReplaceV1,
    #[serde(rename = "keep")]
    Keep,
    #[serde(rename = "Keep")]
    KeepV1,
    #[serde(rename = "drop")]
    Drop,
    #[serde(rename = "Drop")]
    DropV1,
    #[serde(rename = "hashmod")]
    Hashmod,
    #[serde(rename = "HashMod")]
    HashMod,
    #[serde(rename = "labelmap")]
    Labelmap,
    #[serde(rename = "LabelMap")]
    LabelMap,
    #[serde(rename = "labeldrop")]
    Labeldrop,
    #[serde(rename = "LabelDrop")]
    LabelDrop,
    #[serde(rename = "labelkeep")]
    Labelkeep,
    #[serde(rename = "LabelKeep")]
    LabelKeep,
    #[serde(rename = "lowercase")]
    Lowercase,
    #[serde(rename = "Lowercase")]
    LowercaseV1,
    #[serde(rename = "uppercase")]
    Uppercase,
    #[serde(rename = "Uppercase")]
    UppercaseV1,
    #[serde(rename = "keepequal")]
    Keepequal,
    #[serde(rename = "KeepEqual")]
    KeepEqual,
    #[serde(rename = "dropequal")]
    Dropequal,
    #[serde(rename = "DropEqual")]
    DropEqual,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemRelabelingsItem {
    /// Action to perform based on the regex matching.
    /// 
    /// `Uppercase` and `Lowercase` actions require Prometheus >= v2.36.0.
    /// `DropEqual` and `KeepEqual` actions require Prometheus >= v2.41.0.
    /// 
    /// Default: "Replace"
    #[serde(default)]
    pub action: Option<PodMonitorPodMetricsEndpointsItemRelabelingsItemActionKind>,
    /// Modulus to take of the hash of the source label values.
    /// 
    /// Only applicable when the action is `HashMod`.
    #[serde(default)]
    pub modulus: Option<i64>,
    /// Regular expression against which the extracted value is matched.
    #[serde(default)]
    pub regex: Option<String>,
    /// Replacement value against which a Replace action is performed if the
    /// regular expression matches.
    /// 
    /// Regex capture groups are available.
    #[serde(default)]
    pub replacement: Option<String>,
    /// Separator is the string between concatenated SourceLabels.
    #[serde(default)]
    pub separator: Option<String>,
    /// The source labels select values from existing labels. Their content is
    /// concatenated using the configured Separator and matched against the
    /// configured regular expression.
    #[serde(default)]
    pub source_labels: Option<Vec<String>>,
    /// Label to which the resulting string is written in a replacement.
    /// 
    /// It is mandatory for `Replace`, `HashMod`, `Lowercase`, `Uppercase`,
    /// `KeepEqual` and `DropEqual` actions.
    /// 
    /// Regex capture groups are available.
    #[serde(default)]
    pub target_label: Option<String>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorPodMetricsEndpointsItemSchemeKind {
    #[serde(rename = "http")]
    Http,
    #[serde(rename = "https")]
    Https,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemTlsConfigCaConfigMap {
    /// The key to select.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the ConfigMap or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemTlsConfigCaSecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemTlsConfigCa {
    /// ConfigMap containing data to use for the targets.
    #[serde(default)]
    pub config_map: Option<PodMonitorPodMetricsEndpointsItemTlsConfigCaConfigMap>,
    /// Secret containing data to use for the targets.
    #[serde(default)]
    pub secret: Option<PodMonitorPodMetricsEndpointsItemTlsConfigCaSecret>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemTlsConfigCertConfigMap {
    /// The key to select.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the ConfigMap or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemTlsConfigCertSecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemTlsConfigCert {
    /// ConfigMap containing data to use for the targets.
    #[serde(default)]
    pub config_map: Option<PodMonitorPodMetricsEndpointsItemTlsConfigCertConfigMap>,
    /// Secret containing data to use for the targets.
    #[serde(default)]
    pub secret: Option<PodMonitorPodMetricsEndpointsItemTlsConfigCertSecret>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemTlsConfigKeySecret {
    /// The key of the secret to select from.  Must be a valid secret key.
    pub key: String,
    /// Name of the referent.
    /// This field is effectively required, but due to backwards compatibility is
    /// allowed to be empty. Instances of this type with an empty value here are
    /// almost certainly wrong.
    /// More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
    #[serde(default)]
    pub name: Option<String>,
    /// Specify whether the Secret or its key must be defined
    #[serde(default)]
    pub optional: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorPodMetricsEndpointsItemTlsConfigMaxVersionKind {
    #[serde(rename = "TLS10")]
    TLS10,
    #[serde(rename = "TLS11")]
    TLS11,
    #[serde(rename = "TLS12")]
    TLS12,
    #[serde(rename = "TLS13")]
    TLS13,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorPodMetricsEndpointsItemTlsConfigMinVersionKind {
    #[serde(rename = "TLS10")]
    TLS10,
    #[serde(rename = "TLS11")]
    TLS11,
    #[serde(rename = "TLS12")]
    TLS12,
    #[serde(rename = "TLS13")]
    TLS13,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItemTlsConfig {
    /// Certificate authority used when verifying server certificates.
    #[serde(default)]
    pub ca: Option<PodMonitorPodMetricsEndpointsItemTlsConfigCa>,
    /// Client certificate to present when doing client-authentication.
    #[serde(default)]
    pub cert: Option<PodMonitorPodMetricsEndpointsItemTlsConfigCert>,
    /// Disable target certificate validation.
    #[serde(default)]
    pub insecure_skip_verify: Option<bool>,
    /// Secret containing the client key file for the targets.
    #[serde(default)]
    pub key_secret: Option<PodMonitorPodMetricsEndpointsItemTlsConfigKeySecret>,
    /// Maximum acceptable TLS version.
    /// 
    /// It requires Prometheus >= v2.41.0.
    #[serde(default)]
    pub max_version: Option<PodMonitorPodMetricsEndpointsItemTlsConfigMaxVersionKind>,
    /// Minimum acceptable TLS version.
    /// 
    /// It requires Prometheus >= v2.35.0.
    #[serde(default)]
    pub min_version: Option<PodMonitorPodMetricsEndpointsItemTlsConfigMinVersionKind>,
    /// Used to verify the hostname for the targets.
    #[serde(default)]
    pub server_name: Option<String>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorPodMetricsEndpointsItem {
    /// `authorization` configures the Authorization header credentials to use when
    /// scraping the target.
    /// 
    /// Cannot be set at the same time as `basicAuth`, or `oauth2`.
    #[serde(default)]
    pub authorization: Option<PodMonitorPodMetricsEndpointsItemAuthorization>,
    /// `basicAuth` configures the Basic Authentication credentials to use when
    /// scraping the target.
    /// 
    /// Cannot be set at the same time as `authorization`, or `oauth2`.
    #[serde(default)]
    pub basic_auth: Option<PodMonitorPodMetricsEndpointsItemBasicAuth>,
    /// `bearerTokenSecret` specifies a key of a Secret containing the bearer
    /// token for scraping targets. The secret needs to be in the same namespace
    /// as the PodMonitor object and readable by the Prometheus Operator.
    /// 
    /// Deprecated: use `authorization` instead.
    #[serde(default)]
    pub bearer_token_secret: Option<PodMonitorPodMetricsEndpointsItemBearerTokenSecret>,
    /// `enableHttp2` can be used to disable HTTP2 when scraping the target.
    #[serde(default)]
    pub enable_http2: Option<bool>,
    /// When true, the pods which are not running (e.g. either in Failed or
    /// Succeeded state) are dropped during the target discovery.
    /// 
    /// If unset, the filtering is enabled.
    /// 
    /// More info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase
    #[serde(default)]
    pub filter_running: Option<bool>,
    /// `followRedirects` defines whether the scrape requests should follow HTTP
    /// 3xx redirects.
    #[serde(default)]
    pub follow_redirects: Option<bool>,
    /// When true, `honorLabels` preserves the metric's labels when they collide
    /// with the target's labels.
    #[serde(default)]
    pub honor_labels: Option<bool>,
    /// `honorTimestamps` controls whether Prometheus preserves the timestamps
    /// when exposed by the target.
    #[serde(default)]
    pub honor_timestamps: Option<bool>,
    /// Interval at which Prometheus scrapes the metrics from the target.
    /// 
    /// If empty, Prometheus uses the global scrape interval.
    #[serde(default)]
    pub interval: Option<String>,
    /// `metricRelabelings` configures the relabeling rules to apply to the
    /// samples before ingestion.
    #[serde(default)]
    pub metric_relabelings: Option<Vec<PodMonitorPodMetricsEndpointsItemMetricRelabelingsItem>>,
    /// `oauth2` configures the OAuth2 settings to use when scraping the target.
    /// 
    /// It requires Prometheus >= 2.27.0.
    /// 
    /// Cannot be set at the same time as `authorization`, or `basicAuth`.
    #[serde(default)]
    pub oauth2: Option<PodMonitorPodMetricsEndpointsItemOauth2>,
    /// `params` define optional HTTP URL parameters.
    #[serde(default)]
    pub params: Option<std::collections::HashMap<String, Vec<String>>>,
    /// HTTP path from which to scrape for metrics.
    /// 
    /// If empty, Prometheus uses the default value (e.g. `/metrics`).
    #[serde(default)]
    pub path: Option<String>,
    /// The `Pod` port name which exposes the endpoint.
    /// 
    /// It takes precedence over the `portNumber` and `targetPort` fields.
    #[serde(default)]
    pub port: Option<String>,
    /// The `Pod` port number which exposes the endpoint.
    #[serde(default)]
    pub port_number: Option<i64>,
    /// `proxyURL` configures the HTTP Proxy URL (e.g.
    /// "http://proxyserver:2195") to go through when scraping the target.
    #[serde(default)]
    pub proxy_url: Option<String>,
    /// `relabelings` configures the relabeling rules to apply the target's
    /// metadata labels.
    /// 
    /// The Operator automatically adds relabelings for a few standard Kubernetes fields.
    /// 
    /// The original scrape job's name is available via the `__tmp_prometheus_job_name` label.
    /// 
    /// More info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config
    #[serde(default)]
    pub relabelings: Option<Vec<PodMonitorPodMetricsEndpointsItemRelabelingsItem>>,
    /// HTTP scheme to use for scraping.
    /// 
    /// `http` and `https` are the expected values unless you rewrite the
    /// `__scheme__` label via relabeling.
    /// 
    /// If empty, Prometheus uses the default value `http`.
    #[serde(default)]
    pub scheme: Option<PodMonitorPodMetricsEndpointsItemSchemeKind>,
    /// Timeout after which Prometheus considers the scrape to be failed.
    /// 
    /// If empty, Prometheus uses the global scrape timeout unless it is less
    /// than the target's scrape interval value in which the latter is used.
    #[serde(default)]
    pub scrape_timeout: Option<String>,
    /// Name or number of the target port of the `Pod` object behind the Service, the
    /// port must be specified with container port property.
    /// 
    /// Deprecated: use 'port' or 'portNumber' instead.
    #[serde(default)]
    pub target_port: Option<serde_json::Value>,
    /// TLS configuration to use when scraping the target.
    #[serde(default)]
    pub tls_config: Option<PodMonitorPodMetricsEndpointsItemTlsConfig>,
    /// `trackTimestampsStaleness` defines whether Prometheus tracks staleness of
    /// the metrics that have an explicit timestamp present in scraped data.
    /// Has no effect if `honorTimestamps` is false.
    /// 
    /// It requires Prometheus >= v2.48.0.
    #[serde(default)]
    pub track_timestamps_staleness: Option<bool>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorScrapeProtocolsItemKind {
    #[serde(rename = "PrometheusProto")]
    PrometheusProto,
    #[serde(rename = "OpenMetricsText0.0.1")]
    OpenMetricsText001,
    #[serde(rename = "OpenMetricsText1.0.0")]
    OpenMetricsText100,
    #[serde(rename = "PrometheusText0.0.4")]
    PrometheusText004,
    #[serde(rename = "PrometheusText1.0.0")]
    PrometheusText100,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorSelectorMatchExpressionsItem {
    /// key is the label key that the selector applies to.
    pub key: String,
    /// operator represents a key's relationship to a set of values.
    /// Valid operators are In, NotIn, Exists and DoesNotExist.
    pub operator: String,
    /// values is an array of string values. If the operator is In or NotIn,
    /// the values array must be non-empty. If the operator is Exists or DoesNotExist,
    /// the values array must be empty. This array is replaced during a strategic
    /// merge patch.
    #[serde(default)]
    pub values: Option<Vec<String>>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct PodMonitorSelector {
    /// matchExpressions is a list of label selector requirements. The requirements are ANDed.
    #[serde(default)]
    pub match_expressions: Option<Vec<PodMonitorSelectorMatchExpressionsItem>>,
    /// matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
    /// map is equivalent to an element of matchExpressions, whose key field is "key", the
    /// operator is "In", and the values array contains only "value". The requirements are ANDed.
    #[serde(default)]
    pub match_labels: Option<std::collections::HashMap<String, String>>,
}

#[derive(Debug, Clone, Serialize, Deserialize)]
pub enum PodMonitorSelectorMechanismKind {
    #[serde(rename = "RelabelConfig")]
    RelabelConfig,
    #[serde(rename = "RoleSelector")]
    RoleSelector,
}


// ── Render metadata (consumed by tatara-render) ──────────

impl tatara_lisp::RenderableDomain for PodMonitorSpec {
    const API_VERSION: &'static str = "monitoring.coreos.com/v1";
    const KIND: &'static str = "PodMonitor";
    const NAME_FIELD: &'static str = "name";
}

// ── Documentation metadata (consumed by tatara-doc / IDE) ──

impl tatara_lisp::DocumentedDomain for PodMonitorSpec {
    const DOCSTRING: &'static str = "The `PodMonitor` custom resource definition (CRD) defines how `Prometheus` and `PrometheusAgent` can scrape metrics from a group of pods. Among other things, it allows to specify: * The pods to scrape via label selectors. * The container ports to scrape. * Authentication credentials to use. * Target and metric relabeling. `Prometheus` and `PrometheusAgent` objects select `PodMonitor` objects using label and namespace selectors.";
    const FIELD_DOCS: &'static [(&'static str, &'static str)] = &[
        ("attach_metadata", "`attachMetadata` defines additional metadata which is added to the discovered targets. It requires Prometheus >= v2.35.0."),
        ("body_size_limit", "When defined, bodySizeLimit specifies a job level limit on the size of uncompressed response body that will be accepted by Prometheus. It requires Prometheus >= v2.28.0."),
        ("fallback_scrape_protocol", "The protocol to use if a scrape returns blank, unparseable, or otherwise invalid Content-Type. It requires Prometheus >= v3.0.0."),
        ("job_label", "The label to use to retrieve the job name from. `jobLabel` selects the label from the associated Kubernetes `Pod` object which will be used as the `job` label for all metrics. For example if `jobLabel` is set to `foo` and the Kubernetes `Pod` object is labeled with `foo: bar`, then Prometheus adds the `job=\"bar\"` label to all ingested metrics. If the value of this field is empty, the `job` label of the metrics defaults to the namespace and name of the PodMonitor object (e.g. `<namespace>/<name>`)."),
        ("keep_dropped_targets", "Per-scrape limit on the number of targets dropped by relabeling that will be kept in memory. 0 means no limit. It requires Prometheus >= v2.47.0."),
        ("label_limit", "Per-scrape limit on number of labels that will be accepted for a sample. It requires Prometheus >= v2.27.0."),
        ("label_name_length_limit", "Per-scrape limit on length of labels name that will be accepted for a sample. It requires Prometheus >= v2.27.0."),
        ("label_value_length_limit", "Per-scrape limit on length of labels value that will be accepted for a sample. It requires Prometheus >= v2.27.0."),
        ("namespace_selector", "`namespaceSelector` defines in which namespace(s) Prometheus should discover the pods. By default, the pods are discovered in the same namespace as the `PodMonitor` object but it is possible to select pods across different/all namespaces."),
        ("native_histogram_bucket_limit", "If there are more than this many buckets in a native histogram, buckets will be merged to stay within the limit. It requires Prometheus >= v2.45.0."),
        ("native_histogram_min_bucket_factor", "If the growth factor of one bucket to the next is smaller than this, buckets will be merged to increase the factor sufficiently. It requires Prometheus >= v2.50.0."),
        ("pod_metrics_endpoints", "Defines how to scrape metrics from the selected pods."),
        ("pod_target_labels", "`podTargetLabels` defines the labels which are transferred from the associated Kubernetes `Pod` object onto the ingested metrics."),
        ("sample_limit", "`sampleLimit` defines a per-scrape limit on the number of scraped samples that will be accepted."),
        ("scrape_class", "The scrape class to apply."),
        ("scrape_classic_histograms", "Whether to scrape a classic histogram that is also exposed as a native histogram. It requires Prometheus >= v2.45.0."),
        ("scrape_protocols", "`scrapeProtocols` defines the protocols to negotiate during a scrape. It tells clients the protocols supported by Prometheus in order of preference (from most to least preferred). If unset, Prometheus uses its default value. It requires Prometheus >= v2.49.0."),
        ("selector", "Label selector to select the Kubernetes `Pod` objects to scrape metrics from."),
        ("selector_mechanism", "Mechanism used to select the endpoints to scrape. By default, the selection process relies on relabel configurations to filter the discovered targets. Alternatively, you can opt in for role selectors, which may offer better efficiency in large clusters. Which strategy is best for your use case needs to be carefully evaluated. It requires Prometheus >= v2.17.0."),
        ("target_limit", "`targetLimit` defines a limit on the number of scraped targets that will be accepted."),
    ];
}

// ── Default capabilities (Layers 3/4/7/8/9/10/11/12) ──

tatara_lisp::impl_default_capabilities!(PodMonitorSpec);

// ── Attestation metadata (consumed by tameshi BLAKE3 chain) ──

impl tatara_lisp::AttestableDomain for PodMonitorSpec {
    const ATTESTATION_NAMESPACE: &'static str = "monitoring.coreos.com";
}

// ── Schema metadata (consumed by IDEs / openapi exporters) ──

impl tatara_lisp::SchematicDomain for PodMonitorSpec {
    const SCHEMA_JSON: &'static str = "{\"description\":\"The `PodMonitor` custom resource definition (CRD) defines how `Prometheus` and `PrometheusAgent` can scrape metrics from a group of pods.\\nAmong other things, it allows to specify:\\n* The pods to scrape via label selectors.\\n* The container ports to scrape.\\n* Authentication credentials to use.\\n* Target and metric relabeling.\\n\\n`Prometheus` and `PrometheusAgent` objects select `PodMonitor` objects using label and namespace selectors.\",\"properties\":{\"apiVersion\":{\"description\":\"APIVersion defines the versioned schema of this representation of an object.\\nServers should convert recognized schemas to the latest internal value, and\\nmay reject unrecognized values.\\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources\",\"type\":\"string\"},\"kind\":{\"description\":\"Kind is a string value representing the REST resource this object represents.\\nServers may infer this from the endpoint the client submits requests to.\\nCannot be updated.\\nIn CamelCase.\\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds\",\"type\":\"string\"},\"metadata\":{\"type\":\"object\"},\"spec\":{\"description\":\"Specification of desired Pod selection for target discovery by Prometheus.\",\"properties\":{\"attachMetadata\":{\"description\":\"`attachMetadata` defines additional metadata which is added to the\\ndiscovered targets.\\n\\nIt requires Prometheus >= v2.35.0.\",\"properties\":{\"node\":{\"description\":\"When set to true, Prometheus attaches node metadata to the discovered\\ntargets.\\n\\nThe Prometheus service account must have the `list` and `watch`\\npermissions on the `Nodes` objects.\",\"type\":\"boolean\"}},\"type\":\"object\"},\"bodySizeLimit\":{\"description\":\"When defined, bodySizeLimit specifies a job level limit on the size\\nof uncompressed response body that will be accepted by Prometheus.\\n\\nIt requires Prometheus >= v2.28.0.\",\"pattern\":\"(^0|([0-9]*[.])?[0-9]+((K|M|G|T|E|P)i?)?B)$\",\"type\":\"string\"},\"fallbackScrapeProtocol\":{\"description\":\"The protocol to use if a scrape returns blank, unparseable, or otherwise invalid Content-Type.\\n\\nIt requires Prometheus >= v3.0.0.\",\"enum\":[\"PrometheusProto\",\"OpenMetricsText0.0.1\",\"OpenMetricsText1.0.0\",\"PrometheusText0.0.4\",\"PrometheusText1.0.0\"],\"type\":\"string\"},\"jobLabel\":{\"description\":\"The label to use to retrieve the job name from.\\n`jobLabel` selects the label from the associated Kubernetes `Pod`\\nobject which will be used as the `job` label for all metrics.\\n\\nFor example if `jobLabel` is set to `foo` and the Kubernetes `Pod`\\nobject is labeled with `foo: bar`, then Prometheus adds the `job=\\\"bar\\\"`\\nlabel to all ingested metrics.\\n\\nIf the value of this field is empty, the `job` label of the metrics\\ndefaults to the namespace and name of the PodMonitor object (e.g. `<namespace>/<name>`).\",\"type\":\"string\"},\"keepDroppedTargets\":{\"description\":\"Per-scrape limit on the number of targets dropped by relabeling\\nthat will be kept in memory. 0 means no limit.\\n\\nIt requires Prometheus >= v2.47.0.\",\"format\":\"int64\",\"type\":\"integer\"},\"labelLimit\":{\"description\":\"Per-scrape limit on number of labels that will be accepted for a sample.\\n\\nIt requires Prometheus >= v2.27.0.\",\"format\":\"int64\",\"type\":\"integer\"},\"labelNameLengthLimit\":{\"description\":\"Per-scrape limit on length of labels name that will be accepted for a sample.\\n\\nIt requires Prometheus >= v2.27.0.\",\"format\":\"int64\",\"type\":\"integer\"},\"labelValueLengthLimit\":{\"description\":\"Per-scrape limit on length of labels value that will be accepted for a sample.\\n\\nIt requires Prometheus >= v2.27.0.\",\"format\":\"int64\",\"type\":\"integer\"},\"namespaceSelector\":{\"description\":\"`namespaceSelector` defines in which namespace(s) Prometheus should discover the pods.\\nBy default, the pods are discovered in the same namespace as the `PodMonitor` object but it is possible to select pods across different/all namespaces.\",\"properties\":{\"any\":{\"description\":\"Boolean describing whether all namespaces are selected in contrast to a\\nlist restricting them.\",\"type\":\"boolean\"},\"matchNames\":{\"description\":\"List of namespace names to select from.\",\"items\":{\"type\":\"string\"},\"type\":\"array\"}},\"type\":\"object\"},\"nativeHistogramBucketLimit\":{\"description\":\"If there are more than this many buckets in a native histogram,\\nbuckets will be merged to stay within the limit.\\nIt requires Prometheus >= v2.45.0.\",\"format\":\"int64\",\"type\":\"integer\"},\"nativeHistogramMinBucketFactor\":{\"anyOf\":[{\"type\":\"integer\"},{\"type\":\"string\"}],\"description\":\"If the growth factor of one bucket to the next is smaller than this,\\nbuckets will be merged to increase the factor sufficiently.\\nIt requires Prometheus >= v2.50.0.\",\"pattern\":\"^(\\\\+|-)?(([0-9]+(\\\\.[0-9]*)?)|(\\\\.[0-9]+))(([KMGTPE]i)|[numkMGTPE]|([eE](\\\\+|-)?(([0-9]+(\\\\.[0-9]*)?)|(\\\\.[0-9]+))))?$\",\"x-kubernetes-int-or-string\":true},\"podMetricsEndpoints\":{\"description\":\"Defines how to scrape metrics from the selected pods.\",\"items\":{\"description\":\"PodMetricsEndpoint defines an endpoint serving Prometheus metrics to be scraped by\\nPrometheus.\",\"properties\":{\"authorization\":{\"description\":\"`authorization` configures the Authorization header credentials to use when\\nscraping the target.\\n\\nCannot be set at the same time as `basicAuth`, or `oauth2`.\",\"properties\":{\"credentials\":{\"description\":\"Selects a key of a Secret in the namespace that contains the credentials for authentication.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"type\":{\"description\":\"Defines the authentication type. The value is case-insensitive.\\n\\n\\\"Basic\\\" is not a supported value.\\n\\nDefault: \\\"Bearer\\\"\",\"type\":\"string\"}},\"type\":\"object\"},\"basicAuth\":{\"description\":\"`basicAuth` configures the Basic Authentication credentials to use when\\nscraping the target.\\n\\nCannot be set at the same time as `authorization`, or `oauth2`.\",\"properties\":{\"password\":{\"description\":\"`password` specifies a key of a Secret containing the password for\\nauthentication.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"username\":{\"description\":\"`username` specifies a key of a Secret containing the username for\\nauthentication.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"}},\"type\":\"object\"},\"bearerTokenSecret\":{\"description\":\"`bearerTokenSecret` specifies a key of a Secret containing the bearer\\ntoken for scraping targets. The secret needs to be in the same namespace\\nas the PodMonitor object and readable by the Prometheus Operator.\\n\\nDeprecated: use `authorization` instead.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"enableHttp2\":{\"description\":\"`enableHttp2` can be used to disable HTTP2 when scraping the target.\",\"type\":\"boolean\"},\"filterRunning\":{\"description\":\"When true, the pods which are not running (e.g. either in Failed or\\nSucceeded state) are dropped during the target discovery.\\n\\nIf unset, the filtering is enabled.\\n\\nMore info: https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-phase\",\"type\":\"boolean\"},\"followRedirects\":{\"description\":\"`followRedirects` defines whether the scrape requests should follow HTTP\\n3xx redirects.\",\"type\":\"boolean\"},\"honorLabels\":{\"description\":\"When true, `honorLabels` preserves the metric's labels when they collide\\nwith the target's labels.\",\"type\":\"boolean\"},\"honorTimestamps\":{\"description\":\"`honorTimestamps` controls whether Prometheus preserves the timestamps\\nwhen exposed by the target.\",\"type\":\"boolean\"},\"interval\":{\"description\":\"Interval at which Prometheus scrapes the metrics from the target.\\n\\nIf empty, Prometheus uses the global scrape interval.\",\"pattern\":\"^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$\",\"type\":\"string\"},\"metricRelabelings\":{\"description\":\"`metricRelabelings` configures the relabeling rules to apply to the\\nsamples before ingestion.\",\"items\":{\"description\":\"RelabelConfig allows dynamic rewriting of the label set for targets, alerts,\\nscraped samples and remote write samples.\\n\\nMore info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config\",\"properties\":{\"action\":{\"default\":\"replace\",\"description\":\"Action to perform based on the regex matching.\\n\\n`Uppercase` and `Lowercase` actions require Prometheus >= v2.36.0.\\n`DropEqual` and `KeepEqual` actions require Prometheus >= v2.41.0.\\n\\nDefault: \\\"Replace\\\"\",\"enum\":[\"replace\",\"Replace\",\"keep\",\"Keep\",\"drop\",\"Drop\",\"hashmod\",\"HashMod\",\"labelmap\",\"LabelMap\",\"labeldrop\",\"LabelDrop\",\"labelkeep\",\"LabelKeep\",\"lowercase\",\"Lowercase\",\"uppercase\",\"Uppercase\",\"keepequal\",\"KeepEqual\",\"dropequal\",\"DropEqual\"],\"type\":\"string\"},\"modulus\":{\"description\":\"Modulus to take of the hash of the source label values.\\n\\nOnly applicable when the action is `HashMod`.\",\"format\":\"int64\",\"type\":\"integer\"},\"regex\":{\"description\":\"Regular expression against which the extracted value is matched.\",\"type\":\"string\"},\"replacement\":{\"description\":\"Replacement value against which a Replace action is performed if the\\nregular expression matches.\\n\\nRegex capture groups are available.\",\"type\":\"string\"},\"separator\":{\"description\":\"Separator is the string between concatenated SourceLabels.\",\"type\":\"string\"},\"sourceLabels\":{\"description\":\"The source labels select values from existing labels. Their content is\\nconcatenated using the configured Separator and matched against the\\nconfigured regular expression.\",\"items\":{\"description\":\"LabelName is a valid Prometheus label name which may only contain ASCII\\nletters, numbers, as well as underscores.\",\"pattern\":\"^[a-zA-Z_][a-zA-Z0-9_]*$\",\"type\":\"string\"},\"type\":\"array\"},\"targetLabel\":{\"description\":\"Label to which the resulting string is written in a replacement.\\n\\nIt is mandatory for `Replace`, `HashMod`, `Lowercase`, `Uppercase`,\\n`KeepEqual` and `DropEqual` actions.\\n\\nRegex capture groups are available.\",\"type\":\"string\"}},\"type\":\"object\"},\"type\":\"array\"},\"oauth2\":{\"description\":\"`oauth2` configures the OAuth2 settings to use when scraping the target.\\n\\nIt requires Prometheus >= 2.27.0.\\n\\nCannot be set at the same time as `authorization`, or `basicAuth`.\",\"properties\":{\"clientId\":{\"description\":\"`clientId` specifies a key of a Secret or ConfigMap containing the\\nOAuth2 client's ID.\",\"properties\":{\"configMap\":{\"description\":\"ConfigMap containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key to select.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the ConfigMap or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"secret\":{\"description\":\"Secret containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"}},\"type\":\"object\"},\"clientSecret\":{\"description\":\"`clientSecret` specifies a key of a Secret containing the OAuth2\\nclient's secret.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"endpointParams\":{\"additionalProperties\":{\"type\":\"string\"},\"description\":\"`endpointParams` configures the HTTP parameters to append to the token\\nURL.\",\"type\":\"object\"},\"noProxy\":{\"description\":\"`noProxy` is a comma-separated string that can contain IPs, CIDR notation, domain names\\nthat should be excluded from proxying. IP and domain names can\\ncontain port numbers.\\n\\nIt requires Prometheus >= v2.43.0 or Alertmanager >= 0.25.0.\",\"type\":\"string\"},\"proxyConnectHeader\":{\"additionalProperties\":{\"items\":{\"description\":\"SecretKeySelector selects a key of a Secret.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"type\":\"array\"},\"description\":\"ProxyConnectHeader optionally specifies headers to send to\\nproxies during CONNECT requests.\\n\\nIt requires Prometheus >= v2.43.0 or Alertmanager >= 0.25.0.\",\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"proxyFromEnvironment\":{\"description\":\"Whether to use the proxy configuration defined by environment variables (HTTP_PROXY, HTTPS_PROXY, and NO_PROXY).\\n\\nIt requires Prometheus >= v2.43.0 or Alertmanager >= 0.25.0.\",\"type\":\"boolean\"},\"proxyUrl\":{\"description\":\"`proxyURL` defines the HTTP proxy server to use.\",\"pattern\":\"^http(s)?://.+$\",\"type\":\"string\"},\"scopes\":{\"description\":\"`scopes` defines the OAuth2 scopes used for the token request.\",\"items\":{\"type\":\"string\"},\"type\":\"array\"},\"tlsConfig\":{\"description\":\"TLS configuration to use when connecting to the OAuth2 server.\\nIt requires Prometheus >= v2.43.0.\",\"properties\":{\"ca\":{\"description\":\"Certificate authority used when verifying server certificates.\",\"properties\":{\"configMap\":{\"description\":\"ConfigMap containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key to select.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the ConfigMap or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"secret\":{\"description\":\"Secret containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"}},\"type\":\"object\"},\"cert\":{\"description\":\"Client certificate to present when doing client-authentication.\",\"properties\":{\"configMap\":{\"description\":\"ConfigMap containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key to select.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the ConfigMap or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"secret\":{\"description\":\"Secret containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"}},\"type\":\"object\"},\"insecureSkipVerify\":{\"description\":\"Disable target certificate validation.\",\"type\":\"boolean\"},\"keySecret\":{\"description\":\"Secret containing the client key file for the targets.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"maxVersion\":{\"description\":\"Maximum acceptable TLS version.\\n\\nIt requires Prometheus >= v2.41.0.\",\"enum\":[\"TLS10\",\"TLS11\",\"TLS12\",\"TLS13\"],\"type\":\"string\"},\"minVersion\":{\"description\":\"Minimum acceptable TLS version.\\n\\nIt requires Prometheus >= v2.35.0.\",\"enum\":[\"TLS10\",\"TLS11\",\"TLS12\",\"TLS13\"],\"type\":\"string\"},\"serverName\":{\"description\":\"Used to verify the hostname for the targets.\",\"type\":\"string\"}},\"type\":\"object\"},\"tokenUrl\":{\"description\":\"`tokenURL` configures the URL to fetch the token from.\",\"minLength\":1,\"type\":\"string\"}},\"required\":[\"clientId\",\"clientSecret\",\"tokenUrl\"],\"type\":\"object\"},\"params\":{\"additionalProperties\":{\"items\":{\"type\":\"string\"},\"type\":\"array\"},\"description\":\"`params` define optional HTTP URL parameters.\",\"type\":\"object\"},\"path\":{\"description\":\"HTTP path from which to scrape for metrics.\\n\\nIf empty, Prometheus uses the default value (e.g. `/metrics`).\",\"type\":\"string\"},\"port\":{\"description\":\"The `Pod` port name which exposes the endpoint.\\n\\nIt takes precedence over the `portNumber` and `targetPort` fields.\",\"type\":\"string\"},\"portNumber\":{\"description\":\"The `Pod` port number which exposes the endpoint.\",\"format\":\"int32\",\"maximum\":65535,\"minimum\":1,\"type\":\"integer\"},\"proxyUrl\":{\"description\":\"`proxyURL` configures the HTTP Proxy URL (e.g.\\n\\\"http://proxyserver:2195\\\") to go through when scraping the target.\",\"type\":\"string\"},\"relabelings\":{\"description\":\"`relabelings` configures the relabeling rules to apply the target's\\nmetadata labels.\\n\\nThe Operator automatically adds relabelings for a few standard Kubernetes fields.\\n\\nThe original scrape job's name is available via the `__tmp_prometheus_job_name` label.\\n\\nMore info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config\",\"items\":{\"description\":\"RelabelConfig allows dynamic rewriting of the label set for targets, alerts,\\nscraped samples and remote write samples.\\n\\nMore info: https://prometheus.io/docs/prometheus/latest/configuration/configuration/#relabel_config\",\"properties\":{\"action\":{\"default\":\"replace\",\"description\":\"Action to perform based on the regex matching.\\n\\n`Uppercase` and `Lowercase` actions require Prometheus >= v2.36.0.\\n`DropEqual` and `KeepEqual` actions require Prometheus >= v2.41.0.\\n\\nDefault: \\\"Replace\\\"\",\"enum\":[\"replace\",\"Replace\",\"keep\",\"Keep\",\"drop\",\"Drop\",\"hashmod\",\"HashMod\",\"labelmap\",\"LabelMap\",\"labeldrop\",\"LabelDrop\",\"labelkeep\",\"LabelKeep\",\"lowercase\",\"Lowercase\",\"uppercase\",\"Uppercase\",\"keepequal\",\"KeepEqual\",\"dropequal\",\"DropEqual\"],\"type\":\"string\"},\"modulus\":{\"description\":\"Modulus to take of the hash of the source label values.\\n\\nOnly applicable when the action is `HashMod`.\",\"format\":\"int64\",\"type\":\"integer\"},\"regex\":{\"description\":\"Regular expression against which the extracted value is matched.\",\"type\":\"string\"},\"replacement\":{\"description\":\"Replacement value against which a Replace action is performed if the\\nregular expression matches.\\n\\nRegex capture groups are available.\",\"type\":\"string\"},\"separator\":{\"description\":\"Separator is the string between concatenated SourceLabels.\",\"type\":\"string\"},\"sourceLabels\":{\"description\":\"The source labels select values from existing labels. Their content is\\nconcatenated using the configured Separator and matched against the\\nconfigured regular expression.\",\"items\":{\"description\":\"LabelName is a valid Prometheus label name which may only contain ASCII\\nletters, numbers, as well as underscores.\",\"pattern\":\"^[a-zA-Z_][a-zA-Z0-9_]*$\",\"type\":\"string\"},\"type\":\"array\"},\"targetLabel\":{\"description\":\"Label to which the resulting string is written in a replacement.\\n\\nIt is mandatory for `Replace`, `HashMod`, `Lowercase`, `Uppercase`,\\n`KeepEqual` and `DropEqual` actions.\\n\\nRegex capture groups are available.\",\"type\":\"string\"}},\"type\":\"object\"},\"type\":\"array\"},\"scheme\":{\"description\":\"HTTP scheme to use for scraping.\\n\\n`http` and `https` are the expected values unless you rewrite the\\n`__scheme__` label via relabeling.\\n\\nIf empty, Prometheus uses the default value `http`.\",\"enum\":[\"http\",\"https\"],\"type\":\"string\"},\"scrapeTimeout\":{\"description\":\"Timeout after which Prometheus considers the scrape to be failed.\\n\\nIf empty, Prometheus uses the global scrape timeout unless it is less\\nthan the target's scrape interval value in which the latter is used.\",\"pattern\":\"^(0|(([0-9]+)y)?(([0-9]+)w)?(([0-9]+)d)?(([0-9]+)h)?(([0-9]+)m)?(([0-9]+)s)?(([0-9]+)ms)?)$\",\"type\":\"string\"},\"targetPort\":{\"anyOf\":[{\"type\":\"integer\"},{\"type\":\"string\"}],\"description\":\"Name or number of the target port of the `Pod` object behind the Service, the\\nport must be specified with container port property.\\n\\nDeprecated: use 'port' or 'portNumber' instead.\",\"x-kubernetes-int-or-string\":true},\"tlsConfig\":{\"description\":\"TLS configuration to use when scraping the target.\",\"properties\":{\"ca\":{\"description\":\"Certificate authority used when verifying server certificates.\",\"properties\":{\"configMap\":{\"description\":\"ConfigMap containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key to select.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the ConfigMap or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"secret\":{\"description\":\"Secret containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"}},\"type\":\"object\"},\"cert\":{\"description\":\"Client certificate to present when doing client-authentication.\",\"properties\":{\"configMap\":{\"description\":\"ConfigMap containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key to select.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the ConfigMap or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"secret\":{\"description\":\"Secret containing data to use for the targets.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"}},\"type\":\"object\"},\"insecureSkipVerify\":{\"description\":\"Disable target certificate validation.\",\"type\":\"boolean\"},\"keySecret\":{\"description\":\"Secret containing the client key file for the targets.\",\"properties\":{\"key\":{\"description\":\"The key of the secret to select from.  Must be a valid secret key.\",\"type\":\"string\"},\"name\":{\"default\":\"\",\"description\":\"Name of the referent.\\nThis field is effectively required, but due to backwards compatibility is\\nallowed to be empty. Instances of this type with an empty value here are\\nalmost certainly wrong.\\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names\",\"type\":\"string\"},\"optional\":{\"description\":\"Specify whether the Secret or its key must be defined\",\"type\":\"boolean\"}},\"required\":[\"key\"],\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"maxVersion\":{\"description\":\"Maximum acceptable TLS version.\\n\\nIt requires Prometheus >= v2.41.0.\",\"enum\":[\"TLS10\",\"TLS11\",\"TLS12\",\"TLS13\"],\"type\":\"string\"},\"minVersion\":{\"description\":\"Minimum acceptable TLS version.\\n\\nIt requires Prometheus >= v2.35.0.\",\"enum\":[\"TLS10\",\"TLS11\",\"TLS12\",\"TLS13\"],\"type\":\"string\"},\"serverName\":{\"description\":\"Used to verify the hostname for the targets.\",\"type\":\"string\"}},\"type\":\"object\"},\"trackTimestampsStaleness\":{\"description\":\"`trackTimestampsStaleness` defines whether Prometheus tracks staleness of\\nthe metrics that have an explicit timestamp present in scraped data.\\nHas no effect if `honorTimestamps` is false.\\n\\nIt requires Prometheus >= v2.48.0.\",\"type\":\"boolean\"}},\"type\":\"object\"},\"type\":\"array\"},\"podTargetLabels\":{\"description\":\"`podTargetLabels` defines the labels which are transferred from the\\nassociated Kubernetes `Pod` object onto the ingested metrics.\",\"items\":{\"type\":\"string\"},\"type\":\"array\"},\"sampleLimit\":{\"description\":\"`sampleLimit` defines a per-scrape limit on the number of scraped samples\\nthat will be accepted.\",\"format\":\"int64\",\"type\":\"integer\"},\"scrapeClass\":{\"description\":\"The scrape class to apply.\",\"minLength\":1,\"type\":\"string\"},\"scrapeClassicHistograms\":{\"description\":\"Whether to scrape a classic histogram that is also exposed as a native histogram.\\nIt requires Prometheus >= v2.45.0.\",\"type\":\"boolean\"},\"scrapeProtocols\":{\"description\":\"`scrapeProtocols` defines the protocols to negotiate during a scrape. It tells clients the\\nprotocols supported by Prometheus in order of preference (from most to least preferred).\\n\\nIf unset, Prometheus uses its default value.\\n\\nIt requires Prometheus >= v2.49.0.\",\"items\":{\"description\":\"ScrapeProtocol represents a protocol used by Prometheus for scraping metrics.\\nSupported values are:\\n* `OpenMetricsText0.0.1`\\n* `OpenMetricsText1.0.0`\\n* `PrometheusProto`\\n* `PrometheusText0.0.4`\\n* `PrometheusText1.0.0`\",\"enum\":[\"PrometheusProto\",\"OpenMetricsText0.0.1\",\"OpenMetricsText1.0.0\",\"PrometheusText0.0.4\",\"PrometheusText1.0.0\"],\"type\":\"string\"},\"type\":\"array\",\"x-kubernetes-list-type\":\"set\"},\"selector\":{\"description\":\"Label selector to select the Kubernetes `Pod` objects to scrape metrics from.\",\"properties\":{\"matchExpressions\":{\"description\":\"matchExpressions is a list of label selector requirements. The requirements are ANDed.\",\"items\":{\"description\":\"A label selector requirement is a selector that contains values, a key, and an operator that\\nrelates the key and values.\",\"properties\":{\"key\":{\"description\":\"key is the label key that the selector applies to.\",\"type\":\"string\"},\"operator\":{\"description\":\"operator represents a key's relationship to a set of values.\\nValid operators are In, NotIn, Exists and DoesNotExist.\",\"type\":\"string\"},\"values\":{\"description\":\"values is an array of string values. If the operator is In or NotIn,\\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\\nthe values array must be empty. This array is replaced during a strategic\\nmerge patch.\",\"items\":{\"type\":\"string\"},\"type\":\"array\",\"x-kubernetes-list-type\":\"atomic\"}},\"required\":[\"key\",\"operator\"],\"type\":\"object\"},\"type\":\"array\",\"x-kubernetes-list-type\":\"atomic\"},\"matchLabels\":{\"additionalProperties\":{\"type\":\"string\"},\"description\":\"matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\\nmap is equivalent to an element of matchExpressions, whose key field is \\\"key\\\", the\\noperator is \\\"In\\\", and the values array contains only \\\"value\\\". The requirements are ANDed.\",\"type\":\"object\"}},\"type\":\"object\",\"x-kubernetes-map-type\":\"atomic\"},\"selectorMechanism\":{\"description\":\"Mechanism used to select the endpoints to scrape.\\nBy default, the selection process relies on relabel configurations to filter the discovered targets.\\nAlternatively, you can opt in for role selectors, which may offer better efficiency in large clusters.\\nWhich strategy is best for your use case needs to be carefully evaluated.\\n\\nIt requires Prometheus >= v2.17.0.\",\"enum\":[\"RelabelConfig\",\"RoleSelector\"],\"type\":\"string\"},\"targetLimit\":{\"description\":\"`targetLimit` defines a limit on the number of scraped targets that will\\nbe accepted.\",\"format\":\"int64\",\"type\":\"integer\"}},\"required\":[\"selector\"],\"type\":\"object\"}},\"required\":[\"spec\"],\"type\":\"object\"}";
}

/// Register every keyword form this domain exposes onto the host
/// interpreter. Embedders call this once during boot.
pub fn register() {
    tatara_lisp::register_all_capabilities!(PodMonitorSpec);
    tatara_lisp::domain::register_render::<PodMonitorSpec>();
    tatara_lisp::domain::register_schema::<PodMonitorSpec>();
    tatara_lisp::domain::register_attest::<PodMonitorSpec>();
}