CRD reference
OAP's resources are Kubernetes CRDs. Each page below is generated from the CRD schema — so field names, types, and descriptions match what the cluster enforces. Pick a kind for its full spec.
| Kind | Scope | Summary |
|---|---|---|
| AgentClass | Namespaced | AgentClass is the reviewable template an agent is defined by: model, system |
| AgentIdentity | Namespaced | AgentIdentity is the named credential set an agent acts as: reusable static |
| AgentSession | Namespaced | AgentSession is one running instance of an AgentClass: a conversation with |
| AgentSessionGrants | Namespaced | AgentSessionGrants is the per-AgentClass declaration of the (resourceType, |
| AgentSettings | Namespaced | AgentSettings is the namespace tier of agent governance settings: limits |
| AgentUI | Namespaced | AgentUI is a bundle-authored DECLARATION of an agent-defined view: a page |
| ArtifactRender | Namespaced | ArtifactRender is one request to turn agent-supplied bytes into a |
| Channel | Namespaced | Channel binds one transport conversation -- a Slack channel, a scheduled |
| ClusterAgentSettings | Cluster | ClusterAgentSettings is the cluster-wide top tier of agent governance |
| ClusterIdentityProvider | Cluster | ClusterIdentityProvider configures cluster-wide human login: which |
| ClusterSkill | Cluster | ClusterSkill is a cluster-scoped Skill, visible to every namespace. A |
| ClusterSkillSource | Cluster | ClusterSkillSource is a git repo that materializes cluster-scoped |
| CredentialUpdateRequest | Namespaced | CredentialUpdateRequest is an agent's REQUEST that a human replace a |
| MCPServer | Namespaced | MCPServer declares one MCP endpoint an agent may call: where it lives |
| PublicEndpoint | Cluster | PublicEndpoint is how this cluster is reached from the public Internet. |
| RelationshipSource | Namespaced | RelationshipSource declares one upstream directory (Slack first) to poll |
| SessionHold | Namespaced | SessionHold parks an AgentSession for forensic review and gates its return to |
| SessionUserIdentity | Namespaced | SessionUserIdentity is one session's narrowing of a user's UserIdentity |
| SidecarToolbox | Namespaced | SidecarToolbox declares a user-supplied MCP server that runs as a sidecar |
| Skill | Namespaced | Skill is one agentskills.io skill: a SKILL.md (frontmatter + body) plus |
| SkillSource | Namespaced | SkillSource is a git repo that yields one or more Skills. |
| SpiceDBBootstrap | Namespaced | SpiceDBBootstrap declaratively seeds SpiceDB state: an optional schema |
| SpiceboxClass | Cluster | SpiceboxClass is the template a tool sandbox is cut from: image, resources, |
| SpiceboxSession | Namespaced | SpiceboxSession is one live sandbox instantiated from a SpiceboxClass: the |
| SpiceboxToolchain | Cluster | SpiceboxToolchain is a language or tooling overlay a sandbox can mount -- a |
| SpiceboxToolkit | Cluster | SpiceboxToolkit is the machine-readable description of one CLI a sandbox |
| SpiceboxToolspec | Cluster | SpiceboxToolspec is one sandbox tool as the agent sees it: a SpiceboxToolkit |
| SubagentRequest | Namespaced | SubagentRequest is a runner's request to delegate a task to a child session. |
| ToolCall | Namespaced | ToolCall is one execution of one sandbox tool inside a SpiceboxSession: the |
| UserIdentity | Cluster | UserIdentity is a human's credential catalog: the credentials one person has |
| Workshop | Namespaced | Workshop is one builder session's isolated build space: the durable record |
| WorkshopProbe | Namespaced | WorkshopProbe is the tool-discovery probe object for an agent-builder |
| WorkspaceSource | Namespaced | WorkspaceSource declares a named, pluggable origin that per-session |