{% raw %} apiVersion: external-secrets.io/v1 kind: ExternalSecret metadata: name: template spec: # ... target: template: type: kubernetes.io/tls engineVersion: v2 data: tls.crt: "{{ .mysecret | pkcs12cert }}" tls.key: "{{ .mysecret | pkcs12key }}" # if needed unlock the pkcs12 with the password tls.crt: "{{ .mysecret | pkcs12certPass "my-password" }}" {% endraw %}