CRD reference

OAP's resources are Kubernetes CRDs. Each page below is generated from the CRD schema — so field names, types, and descriptions match what the cluster enforces. Pick a kind for its full spec.

KindScopeSummary
AgentClassNamespacedAgentClass is the reviewable template an agent is defined by: model, system
AgentIdentityNamespacedAgentIdentity is the named credential set an agent acts as: reusable static
AgentSessionNamespacedAgentSession is one running instance of an AgentClass: a conversation with
AgentSessionGrantsNamespacedAgentSessionGrants is the per-AgentClass declaration of the (resourceType,
AgentSettingsNamespacedAgentSettings is the namespace tier of agent governance settings: limits
AgentUINamespacedAgentUI is a bundle-authored DECLARATION of an agent-defined view: a page
ArtifactRenderNamespacedArtifactRender is one request to turn agent-supplied bytes into a
ChannelNamespacedChannel binds one transport conversation -- a Slack channel, a scheduled
ClusterAgentSettingsClusterClusterAgentSettings is the cluster-wide top tier of agent governance
ClusterIdentityProviderClusterClusterIdentityProvider configures cluster-wide human login: which
ClusterSkillClusterClusterSkill is a cluster-scoped Skill, visible to every namespace. A
ClusterSkillSourceClusterClusterSkillSource is a git repo that materializes cluster-scoped
CredentialUpdateRequestNamespacedCredentialUpdateRequest is an agent's REQUEST that a human replace a
MCPServerNamespacedMCPServer declares one MCP endpoint an agent may call: where it lives
PublicEndpointClusterPublicEndpoint is how this cluster is reached from the public Internet.
RelationshipSourceNamespacedRelationshipSource declares one upstream directory (Slack first) to poll
SessionHoldNamespacedSessionHold parks an AgentSession for forensic review and gates its return to
SessionUserIdentityNamespacedSessionUserIdentity is one session's narrowing of a user's UserIdentity
SidecarToolboxNamespacedSidecarToolbox declares a user-supplied MCP server that runs as a sidecar
SkillNamespacedSkill is one agentskills.io skill: a SKILL.md (frontmatter + body) plus
SkillSourceNamespacedSkillSource is a git repo that yields one or more Skills.
SpiceDBBootstrapNamespacedSpiceDBBootstrap declaratively seeds SpiceDB state: an optional schema
SpiceboxClassClusterSpiceboxClass is the template a tool sandbox is cut from: image, resources,
SpiceboxSessionNamespacedSpiceboxSession is one live sandbox instantiated from a SpiceboxClass: the
SpiceboxToolchainClusterSpiceboxToolchain is a language or tooling overlay a sandbox can mount -- a
SpiceboxToolkitClusterSpiceboxToolkit is the machine-readable description of one CLI a sandbox
SpiceboxToolspecClusterSpiceboxToolspec is one sandbox tool as the agent sees it: a SpiceboxToolkit
SubagentRequestNamespacedSubagentRequest is a runner's request to delegate a task to a child session.
ToolCallNamespacedToolCall is one execution of one sandbox tool inside a SpiceboxSession: the
UserIdentityClusterUserIdentity is a human's credential catalog: the credentials one person has
WorkshopNamespacedWorkshop is one builder session's isolated build space: the durable record
WorkshopProbeNamespacedWorkshopProbe is the tool-discovery probe object for an agent-builder
WorkspaceSourceNamespacedWorkspaceSource declares a named, pluggable origin that per-session