FormalResource
Registers an in-cluster service as a Formal resource.Spec
TLS Configuration
tls.mode is required whenever you set tls.
FormalListener
Creates a listener on an existing Formal connector with routing rules.Spec
Rules
Each rule routes traffic to one or more resources:
When using
resource rules, the operator resolves the resourceRef to the Formal resource ID automatically.
The connector itself is not managed by the operator. Create the connector via
Terraform or the Control Plane, then reference its ID in
FormalListener resources.
FormalNativeUser
Creates a legacy Native User on a Formal Resource. Credentials come from a Kubernetes Secret.This CRD supports only legacy Native Users. See
Legacy Native Users
for the selection and identity-link model used here.
Spec
The operator watches referenced Secrets. When a Secret is updated, the
operator automatically propagates the new credentials to Formal.
Supported Types
basic
Username and password credentials, sourced from a Kubernetes Secret.
iam
Cloud IAM authentication.
kubernetes
Kubernetes authentication via kubeconfig.
ssh_key
SSH key authentication, with the private key sourced from a Kubernetes Secret.
snowflake_key
Snowflake key-pair authentication, with the private key sourced from a Kubernetes Secret.
http_basic
HTTP Basic authentication, with credentials sourced from a Kubernetes Secret.
http_bearer
HTTP Bearer token authentication, with the token sourced from a Kubernetes Secret.
http_api_key
HTTP API key authentication, with the value sourced from a Kubernetes Secret.
Identity Links
identityLinks binds Formal identities to the native user. Each entry is resolved by name against the Formal control plane:
Resolution rules per
type:
group: matched againstGroup.nameuser: matched againstUser.db_usernameresource_hostname: matched againstResourceHostname.namewithin the parent resource
identityLinks on reconcile are removed, so the spec is the source of truth.
FormalPolicy
Creates and manages a Formal policy from Rego code.Spec
The operator uses
metadata.name as the Formal policy name.
It synchronizes spec changes and stores the Formal policy ID in status.policyId.
If the policy is deleted in Formal, the operator recreates it during reconciliation.
Deleting the custom resource also deletes the policy from Formal.
Disable terminationProtection before deleting a protected policy.
Verify: