AgentSessionGrants
Group agentprimitives.authzed.com · Scope Namespaced · Short names agrants
AgentSessionGrants is the per-AgentClass declaration of the (resourceType, permission) pairs that must exist as grant_<perm>_<resType> relations on the SpiceDB "agentsession" definition.
Namespaced. Reconciled by pkg/controllers/guardian, which watches every AgentSessionGrants cluster-wide and composes their union -- together with the schema fragments contributed by MCPServer and SpiceDBBootstrap -- into a single agentsession schema block. No individual CR owns that block; the composition of all of them does, so a lone CR read in isolation does not tell you what SpiceDB actually enforces.
Spec
| Field | Type | Description |
|---|---|---|
spec.pairs | []object | Pairs is the unique set of (resourceType, permission) tuples this class needs as grant relations. Order is normalized at write time. |
spec.pairs[].permission * | string | Permission is the SpiceDB permission name on ResourceType (e.g., "read", "admin"). |
spec.pairs[].resourceType * | string | ResourceType is the SpiceDB definition name (e.g., "github_repo"). |
spec.slots | []object | Slots is the set of (resourceType, permission) tuples this class declares through authz.slots — the INSTANCE axis. Shape-identical to Pairs and semantically its mirror image, which is why it is a separate field rather than more entries in the same list. A Pair makes the composer put a grant relation on the SESSION pointing at the resource; a Slot makes it put one on the RESOURCE pointing at the session. Collapsing them would lose exactly the distinction that decides whether the resulting check is per-requester. |
spec.slots[].permission * | string | Permission is the SpiceDB permission name on ResourceType (e.g., "read", "admin"). |
spec.slots[].resourceType * | string | ResourceType is the SpiceDB definition name (e.g., "github_repo"). |
Status
Status is controller-owned (observed state).
| Field | Type | Description |
|---|---|---|
status.conditions | []object | Conditions carries SchemaIncluded. |
status.conditions[].lastTransitionTime * | string (date-time) | lastTransitionTime is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. |
status.conditions[].message * | string | message is a human readable message indicating details about the transition. This may be an empty string. |
status.conditions[].observedGeneration | integer (int64) | observedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance. (min 0) |
status.conditions[].reason * | string | reason contains a programmatic identifier indicating the reason for the condition's last transition. Producers of specific condition types may define expected values and meanings for this field, and whether the values are considered a guaranteed API. The value should be a CamelCase string. This field may not be empty. |
status.conditions[].status * | string | status of the condition, one of True, False, Unknown. (enum: True | False | Unknown) |
status.conditions[].type * | string | type of condition in CamelCase or in foo.example.com/CamelCase. |
status.observedPairCount | integer (int32) | ObservedPairCount echoes len(spec.pairs) at the last observation. |
status.observedSchemaWrittenAt | string (date-time) | ObservedSchemaWrittenAt records when the guardian controller last confirmed (or wrote) a SpiceDB schema that includes these pairs. |