GroupRoleManagementPolicyGroupRoleManagementPolicy is the Schema for the GroupRoleManagementPolicys API.
TypeMR
Providerprovider-azuread
Grouppolicies.azuread.m.upbound.io
Scopenamespaced
Versionv1beta1

1apiVersion: policies.azuread.m.upbound.io/v1beta1

2kind: GroupRoleManagementPolicy

kind
string
metadata
object
spec
object

GroupRoleManagementPolicySpec defines the desired state of GroupRoleManagementPolicy

forProvider
required
object

(No description available)

object

An activation_rules block as defined below. The activation rules of the policy

object

An approval_stage block as defined below. The approval stages for the activation

array

blocks as defined below. The IDs of the users or groups who can approve the activation

objectId
string
type
string
object

An active_assignment_rules block as defined below. The rules for active assignment of the policy

object

An eligible_assignment_rules block as defined below. The rules for eligible assignment of the policy

groupId
string
object

Reference to a Group in groups to populate groupId.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a Group in groups to populate groupId.

namespace
string
policy
object

Policies for selection.

resolve
string
object

A notification_rules block as defined below. The notification rules of the policy

object

A notification_target block as defined below to configure notfications on active role assignments. Notifications about active assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_target block as defined below for configuring notifications on activation of eligible role. Notifications about activations of eligible assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_target block as defined below to configure notification on eligible role assignments. Notifications about eligible assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

roleId
string
object

THIS IS A BETA FIELD. It will be honored unless the Management Policies feature flag is disabled. InitProvider holds the same fields as ForProvider, with the exception of Identifier and other resource reference fields. The fields that are in InitProvider are merged into ForProvider when the resource is created. The same fields are also added to the terraform ignore_changes hook, to avoid updating them after creation. This is useful for fields that are required on creation, but we do not desire to update them after creation, for example because of an external controller is managing them, like an autoscaler.

object

An activation_rules block as defined below. The activation rules of the policy

object

An approval_stage block as defined below. The approval stages for the activation

array

blocks as defined below. The IDs of the users or groups who can approve the activation

objectId
string
type
string
object

An active_assignment_rules block as defined below. The rules for active assignment of the policy

object

An eligible_assignment_rules block as defined below. The rules for eligible assignment of the policy

groupId
string
object

Reference to a Group in groups to populate groupId.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a Group in groups to populate groupId.

namespace
string
policy
object

Policies for selection.

resolve
string
object

A notification_rules block as defined below. The notification rules of the policy

object

A notification_target block as defined below to configure notfications on active role assignments. Notifications about active assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_target block as defined below for configuring notifications on activation of eligible role. Notifications about activations of eligible assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_target block as defined below to configure notification on eligible role assignments. Notifications about eligible assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

roleId
string
array

THIS IS A BETA FIELD. It is on by default but can be opted out through a Crossplane feature flag. ManagementPolicies specify the array of actions Crossplane is allowed to take on the managed and external resources. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223 and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md

object

ProviderConfigReference specifies how the provider that will be used to create, observe, update, and delete this managed resource should be configured.

kind
required
string
name
required
string
object

WriteConnectionSecretToReference specifies the namespace and name of a Secret to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource.

name
required
string
status
object

GroupRoleManagementPolicyStatus defines the observed state of GroupRoleManagementPolicy.

object

(No description available)

object

An activation_rules block as defined below. The activation rules of the policy

object

An approval_stage block as defined below. The approval stages for the activation

array

blocks as defined below. The IDs of the users or groups who can approve the activation

objectId
string
type
string
object

An active_assignment_rules block as defined below. The rules for active assignment of the policy

object

An eligible_assignment_rules block as defined below. The rules for eligible assignment of the policy

groupId
string
id
string
object

A notification_rules block as defined below. The notification rules of the policy

object

A notification_target block as defined below to configure notfications on active role assignments. Notifications about active assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_target block as defined below for configuring notifications on activation of eligible role. Notifications about activations of eligible assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_target block as defined below to configure notification on eligible role assignments. Notifications about eligible assignments

object

A notification_settings block as defined above. Admin notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Approver notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

object

A notification_settings block as defined above. Assignee notification settings

array

A list of additional email addresses that will receive these notifications. The additional recipients to notify

roleId
string
array

Conditions of the resource.

lastTransitionTime
required
string
message
string
reason
required
string
status
required
string
type
required
string