// Copyright 2026 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
//     http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.

syntax = "proto3";

package google.cloud.gkehub.rbacrolebindingactuation.v1;

import "google/api/field_behavior.proto";

option csharp_namespace = "Google.Cloud.GkeHub.RbacRoleBindingActuation.V1";
option go_package = "cloud.google.com/go/gkehub/rbacrolebindingactuation/apiv1/rbacrolebindingactuationpb;rbacrolebindingactuationpb";
option java_multiple_files = true;
option java_outer_classname = "RBACRoleBindingActuationProto";
option java_package = "com.google.cloud.gkehub.rbacrolebindingactuation.v1";
option php_namespace = "Google\\Cloud\\GkeHub\\RbacRoleBindingActuation\\V1";
option ruby_package = "Google::Cloud::GkeHub::RbacRoleBindingActuation::V1";

// **RBAC RoleBinding Actuation**: The Hub-wide input for the
// RBACRoleBindingActuation feature.
message FeatureSpec {
  // The list of allowed custom roles (ClusterRoles). If a ClusterRole is not
  // part of this list, it cannot be used in a Scope RBACRoleBinding. If a
  // ClusterRole in this list is in use, it cannot be removed from the list.
  repeated string allowed_custom_roles = 2;
}

// **RBAC RoleBinding Actuation**: An empty state left as an example Hub-wide
// Feature state.
message FeatureState {}
