{
  "description": "AgentTemplate defines portable agent behavior.",
  "properties": {
    "apiVersion": {
      "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
      "type": [
        "string",
        "null"
      ]
    },
    "kind": {
      "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
      "type": [
        "string",
        "null"
      ]
    },
    "metadata": {
      "type": [
        "object",
        "null"
      ]
    },
    "spec": {
      "additionalProperties": false,
      "description": "AgentTemplateSpec defines portable agent behavior.",
      "properties": {
        "description": {
          "type": [
            "string",
            "null"
          ]
        },
        "modelConfig": {
          "additionalProperties": false,
          "description": "ModelConfig is required by managed harnesses and optional for BYO harnesses.",
          "properties": {
            "name": {
              "default": "",
              "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
              "type": [
                "string",
                "null"
              ]
            }
          },
          "type": [
            "object",
            "null"
          ],
          "x-kubernetes-map-type": "atomic",
          "x-kubernetes-validations": [
            {
              "message": "name must not be empty",
              "rule": "has(self.name) \u0026\u0026 self.name != ''"
            }
          ]
        },
        "plugins": {
          "items": {
            "additionalProperties": false,
            "description": "PluginBundle selects Agent Skills from one immutable Agent Plugins package.",
            "properties": {
              "skills": {
                "description": "An empty selection enables nothing.",
                "items": {
                  "minLength": 1,
                  "type": "string"
                },
                "maxItems": 50,
                "type": [
                  "array",
                  "null"
                ],
                "x-kubernetes-list-type": "set"
              },
              "source": {
                "additionalProperties": false,
                "description": "ArtifactSource selects exactly one immutable artifact.",
                "properties": {
                  "bucket": {
                    "additionalProperties": false,
                    "description": "BucketArtifact selects the supported object-store provider.",
                    "properties": {
                      "s3": {
                        "additionalProperties": false,
                        "description": "S3Object identifies one immutable S3 object version.",
                        "properties": {
                          "bucket": {
                            "minLength": 1,
                            "type": "string"
                          },
                          "endpoint": {
                            "description": "Endpoint is the HTTP(S) endpoint of an AWS or S3-compatible service.",
                            "pattern": "^https?://[^[:space:]]+$",
                            "type": "string"
                          },
                          "key": {
                            "minLength": 1,
                            "type": "string"
                          },
                          "region": {
                            "description": "Region is used for request signing when required by the service.",
                            "type": [
                              "string",
                              "null"
                            ]
                          },
                          "versionId": {
                            "minLength": 1,
                            "type": "string"
                          }
                        },
                        "required": [
                          "bucket",
                          "endpoint",
                          "key",
                          "versionId"
                        ],
                        "type": "object"
                      }
                    },
                    "required": [
                      "s3"
                    ],
                    "type": [
                      "object",
                      "null"
                    ]
                  },
                  "git": {
                    "additionalProperties": false,
                    "description": "GitArtifact identifies immutable content at a full Git commit ID.",
                    "properties": {
                      "commit": {
                        "pattern": "^([0-9a-fA-F]{40}|[0-9a-fA-F]{64})$",
                        "type": "string"
                      },
                      "url": {
                        "minLength": 1,
                        "pattern": "^https?://[^[:space:]]+$",
                        "type": "string"
                      }
                    },
                    "required": [
                      "commit",
                      "url"
                    ],
                    "type": [
                      "object",
                      "null"
                    ]
                  },
                  "oci": {
                    "description": "OCI is a digest-pinned image reference.",
                    "pattern": "^[^[:space:]@]+@sha256:[0-9a-f]{64}$",
                    "type": [
                      "string",
                      "null"
                    ]
                  },
                  "path": {
                    "description": "Path selects a directory within the immutable artifact.",
                    "maxLength": 1024,
                    "type": [
                      "string",
                      "null"
                    ]
                  }
                },
                "type": "object",
                "x-kubernetes-validations": [
                  {
                    "message": "exactly one of oci, git or bucket must be specified",
                    "rule": "(has(self.oci) ? 1 : 0) + (has(self.git) ? 1 : 0) + (has(self.bucket) ? 1 : 0) == 1"
                  },
                  {
                    "message": "path must be relative and must not contain '..' segments",
                    "rule": "!has(self.path) || (!self.path.startsWith('/') \u0026\u0026 !self.path.split('/').exists(p, p == '..'))"
                  }
                ]
              }
            },
            "required": [
              "source"
            ],
            "type": "object"
          },
          "maxItems": 20,
          "type": [
            "array",
            "null"
          ]
        },
        "promptTemplate": {
          "additionalProperties": false,
          "description": "AgentTemplatePromptTemplateSpec enables Go template rendering and ConfigMap includes.",
          "properties": {
            "dataSources": {
              "description": "DataSources are same-namespace ConfigMaps available to include(\"source/key\").",
              "items": {
                "additionalProperties": false,
                "description": "AgentTemplatePromptSource makes a same-namespace ConfigMap available to a prompt template.",
                "properties": {
                  "alias": {
                    "description": "Alias is the name used by include. The ConfigMap name is used when omitted.",
                    "minLength": 1,
                    "type": [
                      "string",
                      "null"
                    ]
                  },
                  "name": {
                    "minLength": 1,
                    "type": "string"
                  }
                },
                "required": [
                  "name"
                ],
                "type": "object"
              },
              "maxItems": 20,
              "type": [
                "array",
                "null"
              ],
              "x-kubernetes-list-map-keys": [
                "name"
              ],
              "x-kubernetes-list-type": "map"
            }
          },
          "type": [
            "object",
            "null"
          ]
        },
        "skills": {
          "items": {
            "additionalProperties": false,
            "description": "AgentTemplateSkill identifies one standalone skill and its immutable source.",
            "properties": {
              "name": {
                "minLength": 1,
                "type": "string"
              },
              "source": {
                "additionalProperties": false,
                "description": "ArtifactSource selects exactly one immutable artifact.",
                "properties": {
                  "bucket": {
                    "additionalProperties": false,
                    "description": "BucketArtifact selects the supported object-store provider.",
                    "properties": {
                      "s3": {
                        "additionalProperties": false,
                        "description": "S3Object identifies one immutable S3 object version.",
                        "properties": {
                          "bucket": {
                            "minLength": 1,
                            "type": "string"
                          },
                          "endpoint": {
                            "description": "Endpoint is the HTTP(S) endpoint of an AWS or S3-compatible service.",
                            "pattern": "^https?://[^[:space:]]+$",
                            "type": "string"
                          },
                          "key": {
                            "minLength": 1,
                            "type": "string"
                          },
                          "region": {
                            "description": "Region is used for request signing when required by the service.",
                            "type": [
                              "string",
                              "null"
                            ]
                          },
                          "versionId": {
                            "minLength": 1,
                            "type": "string"
                          }
                        },
                        "required": [
                          "bucket",
                          "endpoint",
                          "key",
                          "versionId"
                        ],
                        "type": "object"
                      }
                    },
                    "required": [
                      "s3"
                    ],
                    "type": [
                      "object",
                      "null"
                    ]
                  },
                  "git": {
                    "additionalProperties": false,
                    "description": "GitArtifact identifies immutable content at a full Git commit ID.",
                    "properties": {
                      "commit": {
                        "pattern": "^([0-9a-fA-F]{40}|[0-9a-fA-F]{64})$",
                        "type": "string"
                      },
                      "url": {
                        "minLength": 1,
                        "pattern": "^https?://[^[:space:]]+$",
                        "type": "string"
                      }
                    },
                    "required": [
                      "commit",
                      "url"
                    ],
                    "type": [
                      "object",
                      "null"
                    ]
                  },
                  "oci": {
                    "description": "OCI is a digest-pinned image reference.",
                    "pattern": "^[^[:space:]@]+@sha256:[0-9a-f]{64}$",
                    "type": [
                      "string",
                      "null"
                    ]
                  },
                  "path": {
                    "description": "Path selects a directory within the immutable artifact.",
                    "maxLength": 1024,
                    "type": [
                      "string",
                      "null"
                    ]
                  }
                },
                "type": "object",
                "x-kubernetes-validations": [
                  {
                    "message": "exactly one of oci, git or bucket must be specified",
                    "rule": "(has(self.oci) ? 1 : 0) + (has(self.git) ? 1 : 0) + (has(self.bucket) ? 1 : 0) == 1"
                  },
                  {
                    "message": "path must be relative and must not contain '..' segments",
                    "rule": "!has(self.path) || (!self.path.startsWith('/') \u0026\u0026 !self.path.split('/').exists(p, p == '..'))"
                  }
                ]
              }
            },
            "required": [
              "name",
              "source"
            ],
            "type": "object"
          },
          "maxItems": 50,
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "name"
          ],
          "x-kubernetes-list-type": "map"
        },
        "systemPrompt": {
          "type": [
            "string",
            "null"
          ]
        },
        "systemPromptFrom": {
          "additionalProperties": false,
          "description": "SystemPromptFrom references prompt text in a same-namespace ConfigMap.",
          "properties": {
            "key": {
              "minLength": 1,
              "type": "string"
            },
            "name": {
              "minLength": 1,
              "type": "string"
            }
          },
          "required": [
            "key",
            "name"
          ],
          "type": [
            "object",
            "null"
          ]
        },
        "tools": {
          "items": {
            "additionalProperties": false,
            "description": "ToolBinding selects exactly one MCP or AgentTemplate-backed tool source.",
            "properties": {
              "agent": {
                "additionalProperties": false,
                "description": "AgentToolBinding exposes another same-namespace AgentTemplate as a logical tool.",
                "properties": {
                  "description": {
                    "description": "Description tells the parent when to route work to this binding.",
                    "minLength": 1,
                    "type": "string"
                  },
                  "isolation": {
                    "default": "Shared",
                    "description": "AgentToolIsolation controls whether a referenced template shares its parent's runtime boundary.",
                    "enum": [
                      "Shared",
                      "Dedicated"
                    ],
                    "type": [
                      "string",
                      "null"
                    ]
                  },
                  "name": {
                    "minLength": 1,
                    "type": "string"
                  },
                  "templateRef": {
                    "additionalProperties": false,
                    "description": "LocalObjectReference contains enough information to let you locate the\nreferenced object inside the same namespace.",
                    "properties": {
                      "name": {
                        "default": "",
                        "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
                        "type": [
                          "string",
                          "null"
                        ]
                      }
                    },
                    "type": "object",
                    "x-kubernetes-map-type": "atomic",
                    "x-kubernetes-validations": [
                      {
                        "message": "name must not be empty",
                        "rule": "has(self.name) \u0026\u0026 self.name != ''"
                      }
                    ]
                  }
                },
                "required": [
                  "description",
                  "name",
                  "templateRef"
                ],
                "type": [
                  "object",
                  "null"
                ]
              },
              "mcp": {
                "additionalProperties": false,
                "description": "MCPToolBinding binds tools from a same-namespace MCP server.",
                "properties": {
                  "requireApproval": {
                    "description": "RequireApproval pauses before each invocation of a tool exposed by this\nbinding. It applies to the selected tools, or to every server tool when\nTools is omitted or empty.",
                    "type": [
                      "boolean",
                      "null"
                    ]
                  },
                  "server": {
                    "additionalProperties": false,
                    "description": "TypedLocalObjectReference contains enough information to let you locate the\ntyped referenced object inside the same namespace.",
                    "properties": {
                      "apiGroup": {
                        "description": "APIGroup is the group for the resource being referenced.\nIf APIGroup is not specified, the specified Kind must be in the core API group.\nFor any other third-party types, APIGroup is required.",
                        "type": [
                          "string",
                          "null"
                        ]
                      },
                      "kind": {
                        "description": "Kind is the type of resource being referenced",
                        "type": "string"
                      },
                      "name": {
                        "description": "Name is the name of resource being referenced",
                        "type": "string"
                      }
                    },
                    "required": [
                      "kind",
                      "name"
                    ],
                    "type": "object",
                    "x-kubernetes-map-type": "atomic",
                    "x-kubernetes-validations": [
                      {
                        "message": "kind must be RemoteMCPServer",
                        "rule": "self.kind == 'RemoteMCPServer'"
                      },
                      {
                        "message": "apiGroup must be omitted",
                        "rule": "!has(self.apiGroup)"
                      }
                    ]
                  },
                  "tools": {
                    "description": "Tools optionally limits which server tools are exposed. An omitted or empty\nlist exposes every tool. Harnesses that cannot enforce a partial selection\nmay expose the whole server and report a warning.",
                    "items": {
                      "minLength": 1,
                      "type": "string"
                    },
                    "maxItems": 50,
                    "type": [
                      "array",
                      "null"
                    ],
                    "x-kubernetes-list-type": "set"
                  }
                },
                "required": [
                  "server"
                ],
                "type": [
                  "object",
                  "null"
                ]
              }
            },
            "type": "object",
            "x-kubernetes-validations": [
              {
                "message": "exactly one of mcp or agent must be specified",
                "rule": "has(self.mcp) != has(self.agent)"
              }
            ]
          },
          "maxItems": 50,
          "type": [
            "array",
            "null"
          ]
        }
      },
      "type": "object",
      "x-kubernetes-validations": [
        {
          "message": "systemPrompt and systemPromptFrom are mutually exclusive",
          "rule": "!(has(self.systemPrompt) \u0026\u0026 has(self.systemPromptFrom))"
        }
      ]
    },
    "status": {
      "additionalProperties": false,
      "description": "AgentTemplateStatus is the controller-observed state for each admitting Harness.",
      "properties": {
        "harnesses": {
          "description": "Harnesses has at most one entry for each admitting Harness.",
          "items": {
            "additionalProperties": false,
            "description": "AgentTemplateHarnessStatus reports runtime revision state for one admitting Harness.",
            "properties": {
              "conditions": {
                "items": {
                  "additionalProperties": false,
                  "description": "Condition contains details for one aspect of the current state of this API Resource.",
                  "properties": {
                    "lastTransitionTime": {
                      "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed.  If that is not known, then using the time when the API field changed is acceptable.",
                      "format": "date-time",
                      "type": "string"
                    },
                    "message": {
                      "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
                      "maxLength": 32768,
                      "type": "string"
                    },
                    "observedGeneration": {
                      "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
                      "format": "int64",
                      "minimum": 0,
                      "type": [
                        "integer",
                        "null"
                      ]
                    },
                    "reason": {
                      "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
                      "maxLength": 1024,
                      "minLength": 1,
                      "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
                      "type": "string"
                    },
                    "status": {
                      "description": "status of the condition, one of True, False, Unknown.",
                      "enum": [
                        "True",
                        "False",
                        "Unknown"
                      ],
                      "type": "string"
                    },
                    "type": {
                      "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
                      "maxLength": 316,
                      "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
                      "type": "string"
                    }
                  },
                  "required": [
                    "lastTransitionTime",
                    "message",
                    "reason",
                    "status",
                    "type"
                  ],
                  "type": "object"
                },
                "maxItems": 4,
                "type": [
                  "array",
                  "null"
                ],
                "x-kubernetes-list-map-keys": [
                  "type"
                ],
                "x-kubernetes-list-type": "map"
              },
              "desiredRevision": {
                "minLength": 1,
                "type": "string"
              },
              "harness": {
                "description": "Harness names a same-namespace Harness whose admission selector matches\nthis AgentTemplate.",
                "minLength": 1,
                "type": "string"
              },
              "latestSuccessfulRevision": {
                "minLength": 1,
                "type": [
                  "string",
                  "null"
                ]
              },
              "warnings": {
                "description": "Warnings reports non-blocking compatibility decisions made while compiling\nthis AgentTemplate for the Harness.",
                "items": {
                  "type": "string"
                },
                "maxItems": 100,
                "type": [
                  "array",
                  "null"
                ],
                "x-kubernetes-list-type": "set"
              }
            },
            "required": [
              "desiredRevision",
              "harness"
            ],
            "type": "object"
          },
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "harness"
          ],
          "x-kubernetes-list-type": "map"
        },
        "observedGeneration": {
          "format": "int64",
          "type": [
            "integer",
            "null"
          ]
        }
      },
      "type": [
        "object",
        "null"
      ]
    }
  },
  "required": [
    "spec"
  ],
  "type": "object"
}