Reference Annotations and CRDs
kix.run/cede-fields
Records the field paths that Kix may omit when another server-side apply manager owns them.
This annotation is generated from a resource’s ownership.cede argument:
ownership.cede = [ "spec.versions" "webhooks[*].rules"];The rendered value is a comma-separated list:
kix.run/cede-fields: spec.versions,webhooks[*].rulesPaths use the field notation returned in Kubernetes server-side apply
conflicts, without the leading dot. A declared path is a prefix: ceding
spec.versions covers fields below spec.versions. The [*] segment matches
any indexed or keyed list element.
When an apply returns 409 Conflict, Kix reads the conflicting paths from the
API server’s message. It retries once with the conflicting fields removed only
when all of them are covered by this annotation. No retry occurs when:
- the resource has no ceded paths;
- the response contains no parseable field path;
- any conflicting path falls outside the declaration.
The retry uses ordinary server-side apply with the kix field manager. When
--force-conflicts is active, the API server transfers ownership instead of
returning the conflict that triggers this behavior.
Prefer ownership.cede over writing the annotation directly. The Nix API
checks that the declaration is a list of strings and keeps the annotation in
sync with the resource definition.