specification: API Commons JSON Schema Index specificationVersion: '0.1' provider: Envoy Gateway providerId: envoy-gateway generated: '2026-09-07' method: searched source: >- https://github.com/envoyproxy/gateway/releases/download/v1.9.1/envoy-gateway-crds.yaml — the `envoy-gateway-crds.yaml` asset published on the Envoy Gateway v1.9.1 GitHub release (2026-08-28). Saved verbatim to json-schema/envoy-gateway-crds.yaml. description: >- Envoy Gateway does not expose a REST API of its own. Its user-facing API is a set of Kubernetes Custom Resource Definitions in the gateway.envoyproxy.io API group, each carrying a full structural `openAPIV3Schema` generated by controller-gen. That schema is the machine-readable contract: it is what the Kubernetes API server validates submitted manifests against, and what any client, GitOps tool or agent reads to know the shape of an Envoy Gateway resource. This index catalogues the eight CRDs shipped in the v1.9.1 release bundle. x-evidence: fetched: '2026-09-07' url: https://github.com/envoyproxy/gateway/releases/download/v1.9.1/envoy-gateway-crds.yaml http_status: 200 bytes: 2553413 release: v1.9.1 released: '2026-08-28' generator: controller-gen.kubebuilder.io v0.20.1 schemaDialect: >- Kubernetes structural schema (a constrained profile of OpenAPI 3.0 Schema Object, itself an extended subset of JSON Schema draft-04) apiGroup: gateway.envoyproxy.io apiVersion: v1alpha1 bundle: file: json-schema/envoy-gateway-crds.yaml documents: 8 totalSchemaProperties: 4080 # JSON Pointer into each CRD document reaching the schema itself: schemaPointer: /spec/versions/0/schema/openAPIV3Schema notes: - >- Every resource is Namespaced and every schema is served and is the storage version at v1alpha1; Envoy Gateway has not yet promoted its own API group past alpha, which is a real and readable stability signal for an integrator. - >- The Gateway API resources Envoy Gateway implements (GatewayClass, Gateway, HTTPRoute, GRPCRoute, TLSRoute, TCPRoute, UDPRoute, ReferenceGrant, BackendTLSPolicy, ListenerSet) are NOT catalogued here — they are published by the upstream Kubernetes SIG-Network Gateway API project, not by Envoy Gateway, and attributing them to this provider would misstate authorship. Envoy Gateway's conformance against them is recorded in conformance/envoy-gateway-conformance.yml. schemas: - kind: Backend plural: backends shortNames: [be] scope: Namespaced version: v1alpha1 schemaProperties: 47 description: >- Configures the endpoints of a backend and the behaviour of the connection from Envoy Proxy to it, including endpoints of type FQDN, IP, Unix socket and DynamicResolver, plus per-backend TLS and application protocol settings. docs: https://gateway.envoyproxy.io/docs/api/extension_types/#backend - kind: BackendTrafficPolicy plural: backendtrafficpolicies shortNames: [btp] scope: Namespaced version: v1alpha1 schemaProperties: 415 description: >- Traffic behaviour toward a backend — load balancing, global and local rate limiting, circuit breaking, retries, health checking, connection settings, compression, response override, fault injection and per-policy telemetry. docs: https://gateway.envoyproxy.io/docs/api/extension_types/#backendtrafficpolicy - kind: ClientTrafficPolicy plural: clienttrafficpolicies shortNames: [ctp] scope: Namespaced version: v1alpha1 schemaProperties: 197 description: >- Traffic behaviour from the downstream client to the Gateway listener — TLS termination and client certificate validation, HTTP/1, HTTP/2 and HTTP/3 settings, client IP detection (XFF, PROXY protocol, direct source IP), header handling, timeouts and connection limits. docs: https://gateway.envoyproxy.io/docs/api/extension_types/#clienttrafficpolicy - kind: EnvoyExtensionPolicy plural: envoyextensionpolicies shortNames: [eep] scope: Namespaced version: v1alpha1 schemaProperties: 280 description: >- Attaches extension filters to the request path — WebAssembly modules (HTTP and OCI image sourced), external processing (ExtProc) services, and Lua scripts. docs: https://gateway.envoyproxy.io/docs/api/extension_types/#envoyextensionpolicy - kind: EnvoyPatchPolicy plural: envoypatchpolicies shortNames: [epp] scope: Namespaced version: v1alpha1 schemaProperties: 36 description: >- Applies JSON Patch operations directly to the xDS configuration Envoy Gateway generates — the documented escape hatch for Envoy features the CRDs do not model. docs: https://gateway.envoyproxy.io/docs/api/extension_types/#envoypatchpolicy - kind: EnvoyProxy plural: envoyproxies shortNames: [eproxy] scope: Namespaced version: v1alpha1 schemaProperties: 2169 description: >- Infrastructure and runtime configuration of the managed Envoy Proxy fleet — Kubernetes Deployment/DaemonSet/Service/HPA/PDB shape, bootstrap override, telemetry (access logs, metrics, tracing), shutdown behaviour, filter ordering and backend TLS. The largest schema in the group by an order of magnitude. docs: https://gateway.envoyproxy.io/docs/api/extension_types/#envoyproxy - kind: HTTPRouteFilter plural: httproutefilters shortNames: [hrf] scope: Namespaced version: v1alpha1 schemaProperties: 49 description: >- Envoy Gateway's implementation-specific HTTPRoute filter, referenced from a Gateway API HTTPRoute or GRPCRoute rule via extensionRef — URL rewrite with regex captures, direct response, credential injection and cookie-based matching. docs: https://gateway.envoyproxy.io/docs/api/extension_types/#httproutefilter - kind: SecurityPolicy plural: securitypolicies shortNames: [sp] scope: Namespaced version: v1alpha1 schemaProperties: 887 description: >- Authentication and authorization at the gateway — JWT validation, OIDC login, OAuth2, API key auth, Basic auth, mutual TLS, external authorization, CORS, CSRF and CEL-expression authorization rules. docs: https://gateway.envoyproxy.io/docs/api/extension_types/#securitypolicy maintainers: - FN: Kin Lane email: kin@apievangelist.com