Skip to main content

FormalResource

Registers an in-cluster service as a Formal resource.

Spec

TLS Configuration

tls.mode is required whenever you set tls.

FormalListener

Creates a listener on an existing Formal connector with routing rules.

Spec

Rules

Each rule routes traffic to one or more resources: When using resource rules, the operator resolves the resourceRef to the Formal resource ID automatically.
The connector itself is not managed by the operator. Create the connector via Terraform or the Control Plane, then reference its ID in FormalListener resources.

FormalNativeUser

Creates a legacy Native User on a Formal Resource. Credentials come from a Kubernetes Secret.
This CRD supports only legacy Native Users. See Legacy Native Users for the selection and identity-link model used here.

Spec

The operator watches referenced Secrets. When a Secret is updated, the operator automatically propagates the new credentials to Formal.

Supported Types

basic

Username and password credentials, sourced from a Kubernetes Secret.

iam

Cloud IAM authentication.

kubernetes

Kubernetes authentication via kubeconfig.

ssh_key

SSH key authentication, with the private key sourced from a Kubernetes Secret.

snowflake_key

Snowflake key-pair authentication, with the private key sourced from a Kubernetes Secret.

http_basic

HTTP Basic authentication, with credentials sourced from a Kubernetes Secret.

http_bearer

HTTP Bearer token authentication, with the token sourced from a Kubernetes Secret.

http_api_key

HTTP API key authentication, with the value sourced from a Kubernetes Secret. identityLinks binds Formal identities to the native user. Each entry is resolved by name against the Formal control plane: Resolution rules per type:
  • group: matched against Group.name
  • user: matched against User.db_username
  • resource_hostname: matched against ResourceHostname.name within the parent resource
Links not present in identityLinks on reconcile are removed, so the spec is the source of truth.

FormalPolicy

Creates and manages a Formal policy from Rego code.

Spec

The operator uses metadata.name as the Formal policy name. It synchronizes spec changes and stores the Formal policy ID in status.policyId. If the policy is deleted in Formal, the operator recreates it during reconciliation. Deleting the custom resource also deletes the policy from Formal. Disable terminationProtection before deleting a protected policy. Verify: