Codepop Engineering Appendix D27

Appendix D

4 min read Section 27 of 27

Appendix D. Glossary and Bibliography

D.1 Glossary

Admission. Checking or modifying a request before the Kubernetes API accepts it.

Condition. A typed state signal with status, reason, and generation.

Contract. A declaration of expected secret properties and consumption.

Controller. A process that repeatedly reconciles desired and observed state.

CRD. A definition of a custom resource type in the Kubernetes API.

EnvFrom. A grouped source of environment variables for a container.

EnvVars. This project's name for explicit secretKeyRef mapping mode.

Generation. The version of an object's relevant specification that a controller must observe.

Grant. A protected decision about who may read or modify a specific target.

Idempotence. Repeating the same operation causes no additional unwanted effect.

Informer. A mechanism for watching resources and maintaining local observations.

Mutation. Changing a resource; in this book, mainly PodTemplate references or annotations.

Observation. A snapshot of inputs that the controller actually checked.

Oracle. Output that allows inference about otherwise inaccessible data.

Owner reference. A Kubernetes ownership link; it must not be added to another party's resource without authorization.

PodTemplate. A declaration from which a workload controller creates pods.

Reconcile. One attempt to align the current state.

ResourceVersion. An API-object version identifier; used here for equality checks.

Rotation. Changing the underlying credential, not necessarily every Secret object change.

Secret. A Kubernetes resource for sensitive configuration data.

Status subresource. A separate API path for reporting custom-resource state.

TOCTOU. The gap between checking state and using that state later.

UID. The identity of one object lifetime, distinct from its name.

Workload. A resource managing pod execution, such as a Deployment.

D.2 Primary Sources

The original edition records these sources as checked on October 10, 2026. Documentation using latest or unversioned paths can change. For implementation, use documentation matching the project's pinned versions. These sources do not constitute an audit of our operator.

S01 — Kubernetes — Secrets

Native Secret objects and consumption methods. Open official source.

S02 — External Secrets Operator — ExternalSecret

Synchronization, target, refreshTime, and conditions. Open official source.

S03 — Kubernetes — Operator pattern

Custom resources and the operator pattern. Open official source.

S04 — Kubebuilder — Introduction

Scaffolding and Kubernetes API development. Open official source.

S05 — Kubernetes — API Concepts

Object versioning, reads, and concurrency. Open official source.

S06 — controller-runtime — client package

Clients, readers, and optimistic merge patches. Open official source.

S07 — Kubernetes — RBAC Good Practices

Privileges, Secret reads, and indirect access. Open official source.

S08 — Kubernetes — Good Practices for Secrets

Access controls and secret handling. Open official source.

S09 — Kubebuilder — Generating CRDs

Markers, status subresources, and schema generation. Open official source.

S10 — Kubebuilder — Configuring envtest

API server and etcd without a full workload control plane. Open official source.

S11 — Go — regexp package

Regexp semantics and linear execution. Open official source.

S12 — Go — Fuzzing

Built-in fuzz testing. Open official source.

S13 — Kubernetes — Extend API with CRDs

Structural schemas, defaults, and subresource capabilities. Open official source.

S14 — Kubebuilder — Watching Resources

Watches, event mapping, and predicates. Open official source.

S15 — controller-runtime — cache package

Informer-cache configuration and scope. Open official source.

S16 — Kubernetes — Define Environment Variables

Container environment configuration. Open official source.

S17 — Kubernetes — Distribute Credentials Securely

Secret consumption and environment-value updates. Open official source.

S18 — Kubernetes — Deployments

PodTemplate changes and rollout strategies. Open official source.

S19 — Kubernetes — StatefulSets

RollingUpdate, OnDelete, and partition behavior. Open official source.

S20 — Kubernetes — DaemonSet

DaemonSet lifecycle and updates. Open official source.

S21 — Kubernetes — Disruptions

PDBs and limitations during workload rolling updates. Open official source.

S22 — Kubernetes — Admission Webhook Good Practices

Availability, scope, and admission-control risks. Open official source.

S23 — Prometheus — Metric and Label Naming

Units, naming, and cardinality. Open official source.

S24 — Helm — Custom Resource Definitions

CRD installation and lifecycle limitations. Open official source.

S25 — OpenAI — Custom Instructions with AGENTS.md

Project instructions for a coding agent. Open official source.

S26 — GitHub — Secure Use of Actions

Permissions, untrusted input, and Actions pinning. Open official source.

S27 — Kubernetes — Versions in CRDs

Served/storage versions, conversion, and migration. Open official source.

D.3 Maintaining This Edition

Implementation changes update the canonical specification and tests first, then examples, prompts, and documentation. PDF, EPUB, and combined Markdown must be rebuilt from the same text. Individual chapter files are the editorial source; editing only the PDF manually is not a maintainable workflow.

For the next edition, recheck library dates and behavior, but do not change tool versions without a tested matrix. Add a book changelog for every API, security-guarantee, or lab-code change.

Prepared for Codepop · Project specification and development guide. Licensing and attribution