|
|
@@ -203,8 +203,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -331,8 +331,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -436,8 +436,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -836,8 +836,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -1790,8 +1790,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -1958,8 +1958,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -2293,8 +2293,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -2619,8 +2619,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -2754,8 +2754,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -4035,8 +4035,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -4705,6 +4705,97 @@ spec:
|
|
|
must be set
|
|
|
rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size()
|
|
|
== 1'
|
|
|
+ kubernetes:
|
|
|
+ description: |-
|
|
|
+ Kubernetes authenticates with OpenBao by passing a ServiceAccount
|
|
|
+ token to the [Kubernetes auth mechanism].
|
|
|
+
|
|
|
+ [Kubernetes auth mechanism]: https://openbao.org/docs/auth/kubernetes/
|
|
|
+ properties:
|
|
|
+ path:
|
|
|
+ default: kubernetes
|
|
|
+ description: |-
|
|
|
+ Path where the Kubernetes authentication backend is mounted in OpenBao, e.g:
|
|
|
+ "kubernetes"
|
|
|
+ type: string
|
|
|
+ role:
|
|
|
+ description: |-
|
|
|
+ A required field containing the OpenBao Role to assume. A Role binds a
|
|
|
+ Kubernetes ServiceAccount with a set of OpenBao policies.
|
|
|
+ minLength: 1
|
|
|
+ type: string
|
|
|
+ secretRef:
|
|
|
+ description: |-
|
|
|
+ Optional secret field containing a Kubernetes ServiceAccount JWT used
|
|
|
+ for authenticating with OpenBao. If a name is specified without a key,
|
|
|
+ `token` is the default.
|
|
|
+ properties:
|
|
|
+ key:
|
|
|
+ description: |-
|
|
|
+ A key in the referenced Secret.
|
|
|
+ Some instances of this field may be defaulted, in others it may be required.
|
|
|
+ maxLength: 253
|
|
|
+ minLength: 1
|
|
|
+ pattern: ^[-._a-zA-Z0-9]+$
|
|
|
+ type: string
|
|
|
+ name:
|
|
|
+ description: The name of the Secret resource being
|
|
|
+ referred to.
|
|
|
+ maxLength: 253
|
|
|
+ minLength: 1
|
|
|
+ pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
|
|
|
+ type: string
|
|
|
+ namespace:
|
|
|
+ description: |-
|
|
|
+ The namespace of the Secret resource being referred to.
|
|
|
+ Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
|
|
|
+ maxLength: 63
|
|
|
+ minLength: 1
|
|
|
+ pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
|
|
|
+ type: string
|
|
|
+ type: object
|
|
|
+ serviceAccountRef:
|
|
|
+ description: |-
|
|
|
+ Optional service account field containing the name of a Kubernetes ServiceAccount.
|
|
|
+ If the service account is specified, a token will be requested from the Kubernetes
|
|
|
+ TokenRequest API for authenticating with OpenBao.
|
|
|
+ Any configured audiences will be passed to the TokenRequest as-is.
|
|
|
+ properties:
|
|
|
+ audiences:
|
|
|
+ description: |-
|
|
|
+ Audience specifies the `aud` claim for the service account token
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
+ items:
|
|
|
+ type: string
|
|
|
+ type: array
|
|
|
+ name:
|
|
|
+ description: The name of the ServiceAccount resource
|
|
|
+ being referred to.
|
|
|
+ maxLength: 253
|
|
|
+ minLength: 1
|
|
|
+ pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
|
|
|
+ type: string
|
|
|
+ namespace:
|
|
|
+ description: |-
|
|
|
+ Namespace of the resource being referred to.
|
|
|
+ Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
|
|
|
+ maxLength: 63
|
|
|
+ minLength: 1
|
|
|
+ pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
|
|
|
+ type: string
|
|
|
+ required:
|
|
|
+ - name
|
|
|
+ type: object
|
|
|
+ required:
|
|
|
+ - path
|
|
|
+ - role
|
|
|
+ type: object
|
|
|
+ x-kubernetes-validations:
|
|
|
+ - message: exactly one of the fields in [serviceAccountRef
|
|
|
+ secretRef] must be set
|
|
|
+ rule: '[has(self.serviceAccountRef),has(self.secretRef)].filter(x,x==true).size()
|
|
|
+ == 1'
|
|
|
namespace:
|
|
|
description: |-
|
|
|
Name of the [OpenBao Namespace] to authenticate to. This can be different
|
|
|
@@ -4799,8 +4890,8 @@ spec:
|
|
|
type: object
|
|
|
x-kubernetes-validations:
|
|
|
- message: exactly one of the fields in [appRole tokenSecretRef
|
|
|
- userPass] must be set
|
|
|
- rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size()
|
|
|
+ userPass kubernetes] must be set
|
|
|
+ rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass),has(self.kubernetes)].filter(x,x==true).size()
|
|
|
== 1'
|
|
|
caBundle:
|
|
|
description: |-
|
|
|
@@ -5000,8 +5091,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -5532,8 +5623,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -6160,8 +6251,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -6209,8 +6300,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -6256,8 +6347,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -6431,8 +6522,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -6557,8 +6648,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -7637,8 +7728,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -7927,8 +8018,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -8266,8 +8357,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -8901,8 +8992,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -9336,8 +9427,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -9860,8 +9951,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -10268,8 +10359,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -10950,8 +11041,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -11125,8 +11216,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|
|
|
@@ -11251,8 +11342,8 @@ spec:
|
|
|
audiences:
|
|
|
description: |-
|
|
|
Audience specifies the `aud` claim for the service account token
|
|
|
- If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
|
|
|
- then this audiences will be appended to the list
|
|
|
+ Some providers automatically extend the audience field based on well-known annotations for workload
|
|
|
+ identity (e.g. IRSA or GCP Workload Identity)
|
|
|
items:
|
|
|
type: string
|
|
|
type: array
|