# schema source: Flux v2.9.5 https://github.com/fluxcd/flux2
apiVersion <string> enum=notification.toolkit.fluxcd.io/v1beta3
kind <string> enum=Provider
metadata.name <string> (required)
metadata.namespace <string> (required)
spec <object>	# ProviderSpec defines the desired state of the Provider.
spec.address <string> max=2048	# Address specifies the endpoint, in a generic sense, to where alerts are sent. What kind of endpoint depends on the specific Provider type being used. For the generic Provider, for example, this is an HTTP/S address. For other Provider types this could be a project ID or a namespace.
spec.certSecretRef <object>	# CertSecretRef specifies the Secret containing TLS certificates for secure communication. Supported configurations: - CA-only: Server authentication (provide ca.crt only) - mTLS: Mutual authentication (provide ca.crt + tls.crt + tls.key) - Client-only: Client authentication with system CA (provide tls.crt + tls.key only) Legacy keys "caFile", "certFile", "keyFile" are supported but deprecated. Use "ca.crt", "tls.crt", "tls.key" instead.
spec.certSecretRef.name <string> (required)	# Name of the referent.
spec.channel <string> max=2048	# Channel specifies the destination channel where events should be posted.
spec.commitStatusExpr <string>	# CommitStatusExpr is a CEL expression that evaluates to a string value that can be used to generate a custom commit status message for use with eligible Provider types (github, gitlab, gitea, bitbucketserver, bitbucket, azuredevops). Supported variables are: event, provider, and alert.
spec.interval <string> pattern="^([0-9]+(\\.[0-9]+)?(ms|s|m|h))+$"	# Interval at which to reconcile the Provider with its Secret references. Deprecated and not used in v1beta3.
spec.proxy <string> pattern="^(http|https)://.*$" max=2048	# Proxy the HTTP/S address of the proxy server. Deprecated: Use ProxySecretRef instead. Will be removed in v1.
spec.proxySecretRef <object>	# ProxySecretRef specifies the Secret containing the proxy configuration for this Provider. The Secret should contain an 'address' key with the HTTP/S address of the proxy server. Optional 'username' and 'password' keys can be provided for proxy authentication.
spec.proxySecretRef.name <string> (required)	# Name of the referent.
spec.secretRef <object>	# SecretRef specifies the Secret containing the authentication credentials for this Provider.
spec.secretRef.name <string> (required)	# Name of the referent.
spec.serviceAccountName <string>	# ServiceAccountName is the name of the Kubernetes ServiceAccount used to authenticate with cloud provider services through workload identity. This enables multi-tenant authentication without storing static credentials. Supported provider types: azureeventhub, azuredevops, googlepubsub When specified, the controller will: 1. Create an OIDC token for the specified ServiceAccount 2. Exchange it for cloud provider credentials via STS 3. Use the obtained credentials for API authentication When unspecified, controller-level authentication is used (single-tenant). An error is thrown if static credentials are also defined in SecretRef. This field requires the ObjectLevelWorkloadIdentity feature gate to be enabled.
spec.suspend <boolean>	# Suspend tells the controller to suspend subsequent events handling for this Provider.
spec.timeout <string> pattern="^([0-9]+(\\.[0-9]+)?(ms|s|m))+$"	# Timeout for sending alerts to the Provider.
spec.type <string> (required) enum=slack|discord|msteams|rocket|generic|generic-hmac|github|gitlab|gitea|giteapullrequestcomment|bitbucketserver|bitbucket|azuredevops|googlechat|googlepubsub|webex|sentry|azureeventhub|telegram|lark|matrix|opsgenie|alertmanager|grafana|githubdispatch|githubpullrequestcomment|gitlabmergerequestcomment|pagerduty|datadog|nats|zulip|otel	# Type specifies which Provider implementation to use.
spec.username <string> max=2048	# Username specifies the name under which events are posted.
