{
  "description": "Harness defines a reusable agent runtime and infrastructure policy.",
  "properties": {
    "apiVersion": {
      "description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
      "type": [
        "string",
        "null"
      ]
    },
    "kind": {
      "description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
      "type": [
        "string",
        "null"
      ]
    },
    "metadata": {
      "type": [
        "object",
        "null"
      ]
    },
    "spec": {
      "additionalProperties": false,
      "description": "HarnessSpec defines a reusable runtime and its infrastructure policy.",
      "properties": {
        "allowedAgentTemplates": {
          "additionalProperties": false,
          "description": "AllowedAgentTemplates selects AgentTemplates this Harness admits.\nWhen omitted, the Harness admits none.",
          "properties": {
            "selector": {
              "additionalProperties": false,
              "description": "Selector selects admitted AgentTemplates in the Harness namespace.",
              "properties": {
                "matchExpressions": {
                  "description": "matchExpressions is a list of label selector requirements. The requirements are ANDed.",
                  "items": {
                    "additionalProperties": false,
                    "description": "A label selector requirement is a selector that contains values, a key, and an operator that\nrelates the key and values.",
                    "properties": {
                      "key": {
                        "description": "key is the label key that the selector applies to.",
                        "type": "string"
                      },
                      "operator": {
                        "description": "operator represents a key's relationship to a set of values.\nValid operators are In, NotIn, Exists and DoesNotExist.",
                        "type": "string"
                      },
                      "values": {
                        "description": "values is an array of string values. If the operator is In or NotIn,\nthe values array must be non-empty. If the operator is Exists or DoesNotExist,\nthe values array must be empty. This array is replaced during a strategic\nmerge patch.",
                        "items": {
                          "type": "string"
                        },
                        "type": [
                          "array",
                          "null"
                        ],
                        "x-kubernetes-list-type": "atomic"
                      }
                    },
                    "required": [
                      "key",
                      "operator"
                    ],
                    "type": "object"
                  },
                  "type": [
                    "array",
                    "null"
                  ],
                  "x-kubernetes-list-type": "atomic"
                },
                "matchLabels": {
                  "additionalProperties": {
                    "type": "string"
                  },
                  "description": "matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels\nmap is equivalent to an element of matchExpressions, whose key field is \"key\", the\noperator is \"In\", and the values array contains only \"value\". The requirements are ANDed.",
                  "type": [
                    "object",
                    "null"
                  ]
                }
              },
              "type": "object",
              "x-kubernetes-map-type": "atomic"
            }
          },
          "required": [
            "selector"
          ],
          "type": [
            "object",
            "null"
          ]
        },
        "byo": {
          "description": "BYOHarness selects an image that implements kagent's private A2A contract.",
          "type": [
            "object",
            "null"
          ]
        },
        "claude": {
          "description": "ClaudeHarness selects the Claude runtime adapter.",
          "type": [
            "object",
            "null"
          ]
        },
        "codex": {
          "description": "CodexHarness selects the Codex runtime adapter.",
          "type": [
            "object",
            "null"
          ]
        },
        "env": {
          "items": {
            "additionalProperties": false,
            "description": "HarnessEnvVar configures one runtime environment variable.",
            "properties": {
              "credentialRef": {
                "additionalProperties": false,
                "description": "CredentialRef references a key in a same-namespace Secret.",
                "properties": {
                  "key": {
                    "description": "The key of the secret to select from.  Must be a valid secret key.",
                    "type": "string"
                  },
                  "name": {
                    "default": "",
                    "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
                    "type": [
                      "string",
                      "null"
                    ]
                  },
                  "optional": {
                    "description": "Specify whether the Secret or its key must be defined",
                    "type": [
                      "boolean",
                      "null"
                    ]
                  }
                },
                "required": [
                  "key"
                ],
                "type": [
                  "object",
                  "null"
                ],
                "x-kubernetes-map-type": "atomic"
              },
              "name": {
                "minLength": 1,
                "type": "string"
              },
              "value": {
                "description": "Value is a literal value, including an empty string.",
                "type": [
                  "string",
                  "null"
                ]
              }
            },
            "required": [
              "name"
            ],
            "type": "object",
            "x-kubernetes-validations": [
              {
                "message": "exactly one of value or credentialRef must be specified",
                "rule": "has(self.value) != has(self.credentialRef)"
              },
              {
                "message": "credentialRef name must not be empty",
                "rule": "!has(self.credentialRef) || self.credentialRef.name.size() \u003e 0"
              }
            ]
          },
          "maxItems": 100,
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "name"
          ],
          "x-kubernetes-list-type": "map"
        },
        "kagent": {
          "additionalProperties": false,
          "description": "KagentHarness configures the kagent runtime adapter.",
          "properties": {
            "memory": {
              "additionalProperties": false,
              "description": "Memory enables long-term memory for agents using this Harness.",
              "properties": {
                "modelConfigRef": {
                  "additionalProperties": false,
                  "description": "ModelConfigRef references the embedding ModelConfig in the Harness namespace.",
                  "properties": {
                    "name": {
                      "default": "",
                      "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
                      "type": [
                        "string",
                        "null"
                      ]
                    }
                  },
                  "type": "object",
                  "x-kubernetes-map-type": "atomic"
                },
                "ttlDays": {
                  "description": "TTLDays controls how many days a stored memory entry remains valid.",
                  "minimum": 1,
                  "type": [
                    "integer",
                    "null"
                  ]
                }
              },
              "required": [
                "modelConfigRef"
              ],
              "type": [
                "object",
                "null"
              ],
              "x-kubernetes-validations": [
                {
                  "message": "modelConfigRef name must not be empty",
                  "rule": "self.modelConfigRef.name.size() \u003e 0"
                }
              ]
            }
          },
          "type": [
            "object",
            "null"
          ]
        },
        "substrate": {
          "additionalProperties": false,
          "description": "HarnessSubstratePolicy contains the Substrate policy shared by all runtime variants.",
          "properties": {
            "snapshotPolicy": {
              "additionalProperties": false,
              "description": "SnapshotPolicy configures runtime snapshot storage.",
              "properties": {
                "location": {
                  "description": "Location is the snapshot storage location used by Substrate.",
                  "pattern": "^[^[:space:]]+$",
                  "type": "string"
                }
              },
              "required": [
                "location"
              ],
              "type": "object"
            },
            "workerPoolRef": {
              "additionalProperties": false,
              "description": "WorkerPoolRef references a WorkerPool in the Harness namespace.",
              "properties": {
                "name": {
                  "default": "",
                  "description": "Name of the referent.\nThis field is effectively required, but due to backwards compatibility is\nallowed to be empty. Instances of this type with an empty value here are\nalmost certainly wrong.\nMore info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names",
                  "type": [
                    "string",
                    "null"
                  ]
                }
              },
              "type": "object",
              "x-kubernetes-map-type": "atomic"
            }
          },
          "required": [
            "snapshotPolicy",
            "workerPoolRef"
          ],
          "type": "object",
          "x-kubernetes-validations": [
            {
              "message": "workerPoolRef name must not be empty",
              "rule": "self.workerPoolRef.name.size() \u003e 0"
            }
          ]
        },
        "workload": {
          "additionalProperties": false,
          "description": "HarnessWorkload identifies the immutable runtime image used by a Harness.",
          "properties": {
            "args": {
              "description": "Args overrides the image command arguments when set.",
              "items": {
                "type": "string"
              },
              "maxItems": 64,
              "type": [
                "array",
                "null"
              ]
            },
            "command": {
              "description": "Command overrides the image entrypoint when set.",
              "items": {
                "type": "string"
              },
              "maxItems": 32,
              "type": [
                "array",
                "null"
              ]
            },
            "image": {
              "description": "Image is an OCI image reference pinned by sha256 digest.",
              "pattern": "^[^[:space:]@]+@sha256:[a-f0-9]{64}$",
              "type": "string"
            }
          },
          "required": [
            "image"
          ],
          "type": "object"
        }
      },
      "required": [
        "substrate",
        "workload"
      ],
      "type": "object",
      "x-kubernetes-validations": [
        {
          "message": "exactly one of kagent, codex, claude, or byo must be specified",
          "rule": "(has(self.kagent) ? 1 : 0) + (has(self.codex) ? 1 : 0) + (has(self.claude) ? 1 : 0) + (has(self.byo) ? 1 : 0) == 1"
        },
        {
          "message": "BYO harnesses must specify workload.command",
          "rule": "!has(self.byo) || size(self.workload.command) \u003e 0"
        }
      ]
    },
    "status": {
      "additionalProperties": false,
      "description": "HarnessStatus reports controller-derived capabilities and current health.",
      "properties": {
        "capabilities": {
          "additionalProperties": false,
          "description": "Capabilities is the single capability record for the selected runtime.",
          "properties": {
            "approvals": {
              "type": "boolean"
            },
            "checkpoint": {
              "type": "boolean"
            },
            "dedicatedAgentTools": {
              "type": "boolean"
            },
            "inputModalities": {
              "items": {
                "type": "string"
              },
              "maxItems": 16,
              "type": [
                "array",
                "null"
              ],
              "x-kubernetes-list-type": "set"
            },
            "inputRequired": {
              "type": "boolean"
            },
            "interruption": {
              "type": "boolean"
            },
            "maxNativeAgentDepth": {
              "format": "int32",
              "minimum": 0,
              "type": "integer"
            },
            "mcpInjection": {
              "type": "boolean"
            },
            "nativeAgentTools": {
              "type": "boolean"
            },
            "outputModalities": {
              "items": {
                "type": "string"
              },
              "maxItems": 16,
              "type": [
                "array",
                "null"
              ],
              "x-kubernetes-list-type": "set"
            },
            "resume": {
              "type": "boolean"
            },
            "streaming": {
              "type": "boolean"
            },
            "version": {
              "description": "Version identifies the controller capability catalog entry.",
              "minLength": 1,
              "type": "string"
            }
          },
          "required": [
            "approvals",
            "checkpoint",
            "dedicatedAgentTools",
            "inputRequired",
            "interruption",
            "maxNativeAgentDepth",
            "mcpInjection",
            "nativeAgentTools",
            "resume",
            "streaming",
            "version"
          ],
          "type": [
            "object",
            "null"
          ]
        },
        "conditions": {
          "description": "Conditions report adapter and dependency health.",
          "items": {
            "additionalProperties": false,
            "description": "Condition contains details for one aspect of the current state of this API Resource.",
            "properties": {
              "lastTransitionTime": {
                "description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed.  If that is not known, then using the time when the API field changed is acceptable.",
                "format": "date-time",
                "type": "string"
              },
              "message": {
                "description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
                "maxLength": 32768,
                "type": "string"
              },
              "observedGeneration": {
                "description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
                "format": "int64",
                "minimum": 0,
                "type": [
                  "integer",
                  "null"
                ]
              },
              "reason": {
                "description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
                "maxLength": 1024,
                "minLength": 1,
                "pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
                "type": "string"
              },
              "status": {
                "description": "status of the condition, one of True, False, Unknown.",
                "enum": [
                  "True",
                  "False",
                  "Unknown"
                ],
                "type": "string"
              },
              "type": {
                "description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
                "maxLength": 316,
                "pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
                "type": "string"
              }
            },
            "required": [
              "lastTransitionTime",
              "message",
              "reason",
              "status",
              "type"
            ],
            "type": "object"
          },
          "maxItems": 8,
          "type": [
            "array",
            "null"
          ],
          "x-kubernetes-list-map-keys": [
            "type"
          ],
          "x-kubernetes-list-type": "map"
        },
        "observedGeneration": {
          "description": "ObservedGeneration is the latest Harness generation observed by the controller.",
          "format": "int64",
          "type": [
            "integer",
            "null"
          ]
        }
      },
      "type": [
        "object",
        "null"
      ]
    }
  },
  "required": [
    "spec"
  ],
  "type": "object"
}