bundle.yaml 1.9 MB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358173591736017361173621736317364173651736617367173681736917370173711737217373173741737517376173771737817379173801738117382173831738417385173861738717388173891739017391173921739317394173951739617397173981739917400174011740217403174041740517406174071740817409174101741117412174131741417415174161741717418174191742017421174221742317424174251742617427174281742917430174311743217433174341743517436174371743817439174401744117442174431744417445174461744717448174491745017451174521745317454174551745617457174581745917460174611746217463174641746517466174671746817469174701747117472174731747417475174761747717478174791748017481174821748317484174851748617487174881748917490174911749217493174941749517496174971749817499175001750117502175031750417505175061750717508175091751017511175121751317514175151751617517175181751917520175211752217523175241752517526175271752817529175301753117532175331753417535175361753717538175391754017541175421754317544175451754617547175481754917550175511755217553175541755517556175571755817559175601756117562175631756417565175661756717568175691757017571175721757317574175751757617577175781757917580175811758217583175841758517586175871758817589175901759117592175931759417595175961759717598175991760017601176021760317604176051760617607176081760917610176111761217613176141761517616176171761817619176201762117622176231762417625176261762717628176291763017631176321763317634176351763617637176381763917640176411764217643176441764517646176471764817649176501765117652176531765417655176561765717658176591766017661176621766317664176651766617667176681766917670176711767217673176741767517676176771767817679176801768117682176831768417685176861768717688176891769017691176921769317694176951769617697176981769917700177011770217703177041770517706177071770817709177101771117712177131771417715177161771717718177191772017721177221772317724177251772617727177281772917730177311773217733177341773517736177371773817739177401774117742177431774417745177461774717748177491775017751177521775317754177551775617757177581775917760177611776217763177641776517766177671776817769177701777117772177731777417775177761777717778177791778017781177821778317784177851778617787177881778917790177911779217793177941779517796177971779817799178001780117802178031780417805178061780717808178091781017811178121781317814178151781617817178181781917820178211782217823178241782517826178271782817829178301783117832178331783417835178361783717838178391784017841178421784317844178451784617847178481784917850178511785217853178541785517856178571785817859178601786117862178631786417865178661786717868178691787017871178721787317874178751787617877178781787917880178811788217883178841788517886178871788817889178901789117892178931789417895178961789717898178991790017901179021790317904179051790617907179081790917910179111791217913179141791517916179171791817919179201792117922179231792417925179261792717928179291793017931179321793317934179351793617937179381793917940179411794217943179441794517946179471794817949179501795117952179531795417955179561795717958179591796017961179621796317964179651796617967179681796917970179711797217973179741797517976179771797817979179801798117982179831798417985179861798717988179891799017991179921799317994179951799617997179981799918000180011800218003180041800518006180071800818009180101801118012180131801418015180161801718018180191802018021180221802318024180251802618027180281802918030180311803218033180341803518036180371803818039180401804118042180431804418045180461804718048180491805018051180521805318054180551805618057180581805918060180611806218063180641806518066180671806818069180701807118072180731807418075180761807718078180791808018081180821808318084180851808618087180881808918090180911809218093180941809518096180971809818099181001810118102181031810418105181061810718108181091811018111181121811318114181151811618117181181811918120181211812218123181241812518126181271812818129181301813118132181331813418135181361813718138181391814018141181421814318144181451814618147181481814918150181511815218153181541815518156181571815818159181601816118162181631816418165181661816718168181691817018171181721817318174181751817618177181781817918180181811818218183181841818518186181871818818189181901819118192181931819418195181961819718198181991820018201182021820318204182051820618207182081820918210182111821218213182141821518216182171821818219182201822118222182231822418225182261822718228182291823018231182321823318234182351823618237182381823918240182411824218243182441824518246182471824818249182501825118252182531825418255182561825718258182591826018261182621826318264182651826618267182681826918270182711827218273182741827518276182771827818279182801828118282182831828418285182861828718288182891829018291182921829318294182951829618297182981829918300183011830218303183041830518306183071830818309183101831118312183131831418315183161831718318183191832018321183221832318324183251832618327183281832918330183311833218333183341833518336183371833818339183401834118342183431834418345183461834718348183491835018351183521835318354183551835618357183581835918360183611836218363183641836518366183671836818369183701837118372183731837418375183761837718378183791838018381183821838318384183851838618387183881838918390183911839218393183941839518396183971839818399184001840118402184031840418405184061840718408184091841018411184121841318414184151841618417184181841918420184211842218423184241842518426184271842818429184301843118432184331843418435184361843718438184391844018441184421844318444184451844618447184481844918450184511845218453184541845518456184571845818459184601846118462184631846418465184661846718468184691847018471184721847318474184751847618477184781847918480184811848218483184841848518486184871848818489184901849118492184931849418495184961849718498184991850018501185021850318504185051850618507185081850918510185111851218513185141851518516185171851818519185201852118522185231852418525185261852718528185291853018531185321853318534185351853618537185381853918540185411854218543185441854518546185471854818549185501855118552185531855418555185561855718558185591856018561185621856318564185651856618567185681856918570185711857218573185741857518576185771857818579185801858118582185831858418585185861858718588185891859018591185921859318594185951859618597185981859918600186011860218603186041860518606186071860818609186101861118612186131861418615186161861718618186191862018621186221862318624186251862618627186281862918630186311863218633186341863518636186371863818639186401864118642186431864418645186461864718648186491865018651186521865318654186551865618657186581865918660186611866218663186641866518666186671866818669186701867118672186731867418675186761867718678186791868018681186821868318684186851868618687186881868918690186911869218693186941869518696186971869818699187001870118702187031870418705187061870718708187091871018711187121871318714187151871618717187181871918720187211872218723187241872518726187271872818729187301873118732187331873418735187361873718738187391874018741187421874318744187451874618747187481874918750187511875218753187541875518756187571875818759187601876118762187631876418765187661876718768187691877018771187721877318774187751877618777187781877918780187811878218783187841878518786187871878818789187901879118792187931879418795187961879718798187991880018801188021880318804188051880618807188081880918810188111881218813188141881518816188171881818819188201882118822188231882418825188261882718828188291883018831188321883318834188351883618837188381883918840188411884218843188441884518846188471884818849188501885118852188531885418855188561885718858188591886018861188621886318864188651886618867188681886918870188711887218873188741887518876188771887818879188801888118882188831888418885188861888718888188891889018891188921889318894188951889618897188981889918900189011890218903189041890518906189071890818909189101891118912189131891418915189161891718918189191892018921189221892318924189251892618927189281892918930189311893218933189341893518936189371893818939189401894118942189431894418945189461894718948189491895018951189521895318954189551895618957189581895918960189611896218963189641896518966189671896818969189701897118972189731897418975189761897718978189791898018981189821898318984189851898618987189881898918990189911899218993189941899518996189971899818999190001900119002190031900419005190061900719008190091901019011190121901319014190151901619017190181901919020190211902219023190241902519026190271902819029190301903119032190331903419035190361903719038190391904019041190421904319044190451904619047190481904919050190511905219053190541905519056190571905819059190601906119062190631906419065190661906719068190691907019071190721907319074190751907619077190781907919080190811908219083190841908519086190871908819089190901909119092190931909419095190961909719098190991910019101191021910319104191051910619107191081910919110191111911219113191141911519116191171911819119191201912119122191231912419125191261912719128191291913019131191321913319134191351913619137191381913919140191411914219143191441914519146191471914819149191501915119152191531915419155191561915719158191591916019161191621916319164191651916619167191681916919170191711917219173191741917519176191771917819179191801918119182191831918419185191861918719188191891919019191191921919319194191951919619197191981919919200192011920219203192041920519206192071920819209192101921119212192131921419215192161921719218192191922019221192221922319224192251922619227192281922919230192311923219233192341923519236192371923819239192401924119242192431924419245192461924719248192491925019251192521925319254192551925619257192581925919260192611926219263192641926519266192671926819269192701927119272192731927419275192761927719278192791928019281192821928319284192851928619287192881928919290192911929219293192941929519296192971929819299193001930119302193031930419305193061930719308193091931019311193121931319314193151931619317193181931919320193211932219323193241932519326193271932819329193301933119332193331933419335193361933719338193391934019341193421934319344193451934619347193481934919350193511935219353193541935519356193571935819359193601936119362193631936419365193661936719368193691937019371193721937319374193751937619377193781937919380193811938219383193841938519386193871938819389193901939119392193931939419395193961939719398193991940019401194021940319404194051940619407194081940919410194111941219413194141941519416194171941819419194201942119422194231942419425194261942719428194291943019431194321943319434194351943619437194381943919440194411944219443194441944519446194471944819449194501945119452194531945419455194561945719458194591946019461194621946319464194651946619467194681946919470194711947219473194741947519476194771947819479194801948119482194831948419485194861948719488194891949019491194921949319494194951949619497194981949919500195011950219503195041950519506195071950819509195101951119512195131951419515195161951719518195191952019521195221952319524195251952619527195281952919530195311953219533195341953519536195371953819539195401954119542195431954419545195461954719548195491955019551195521955319554195551955619557195581955919560195611956219563195641956519566195671956819569195701957119572195731957419575195761957719578195791958019581195821958319584195851958619587195881958919590195911959219593195941959519596195971959819599196001960119602196031960419605196061960719608196091961019611196121961319614196151961619617196181961919620196211962219623196241962519626196271962819629196301963119632196331963419635196361963719638196391964019641196421964319644196451964619647196481964919650196511965219653196541965519656196571965819659196601966119662196631966419665196661966719668196691967019671196721967319674196751967619677196781967919680196811968219683196841968519686196871968819689196901969119692196931969419695196961969719698196991970019701197021970319704197051970619707197081970919710197111971219713197141971519716197171971819719197201972119722197231972419725197261972719728197291973019731197321973319734197351973619737197381973919740197411974219743197441974519746197471974819749197501975119752197531975419755197561975719758197591976019761197621976319764197651976619767197681976919770197711977219773197741977519776197771977819779197801978119782197831978419785197861978719788197891979019791197921979319794197951979619797197981979919800198011980219803198041980519806198071980819809198101981119812198131981419815198161981719818198191982019821198221982319824198251982619827198281982919830198311983219833198341983519836198371983819839198401984119842198431984419845198461984719848198491985019851198521985319854198551985619857198581985919860198611986219863198641986519866198671986819869198701987119872198731987419875198761987719878198791988019881198821988319884198851988619887198881988919890198911989219893198941989519896198971989819899199001990119902199031990419905199061990719908199091991019911199121991319914199151991619917199181991919920199211992219923199241992519926199271992819929199301993119932199331993419935199361993719938199391994019941199421994319944199451994619947199481994919950199511995219953199541995519956199571995819959199601996119962199631996419965199661996719968199691997019971199721997319974199751997619977199781997919980199811998219983199841998519986199871998819989199901999119992199931999419995199961999719998199992000020001200022000320004200052000620007200082000920010200112001220013200142001520016200172001820019200202002120022200232002420025200262002720028200292003020031200322003320034200352003620037200382003920040200412004220043200442004520046200472004820049200502005120052200532005420055200562005720058200592006020061200622006320064200652006620067200682006920070200712007220073200742007520076200772007820079200802008120082200832008420085200862008720088200892009020091200922009320094200952009620097200982009920100201012010220103201042010520106201072010820109201102011120112201132011420115201162011720118201192012020121201222012320124201252012620127201282012920130201312013220133201342013520136201372013820139201402014120142201432014420145201462014720148201492015020151201522015320154201552015620157201582015920160201612016220163201642016520166201672016820169201702017120172201732017420175201762017720178201792018020181201822018320184201852018620187201882018920190201912019220193201942019520196201972019820199202002020120202202032020420205202062020720208202092021020211202122021320214202152021620217202182021920220202212022220223202242022520226202272022820229202302023120232202332023420235202362023720238202392024020241202422024320244202452024620247202482024920250202512025220253202542025520256202572025820259202602026120262202632026420265202662026720268202692027020271202722027320274202752027620277202782027920280202812028220283202842028520286202872028820289202902029120292202932029420295202962029720298202992030020301203022030320304203052030620307203082030920310203112031220313203142031520316203172031820319203202032120322203232032420325203262032720328203292033020331203322033320334203352033620337203382033920340203412034220343203442034520346203472034820349203502035120352203532035420355203562035720358203592036020361203622036320364203652036620367203682036920370203712037220373203742037520376203772037820379203802038120382203832038420385203862038720388203892039020391203922039320394203952039620397203982039920400204012040220403204042040520406204072040820409204102041120412204132041420415204162041720418204192042020421204222042320424204252042620427204282042920430204312043220433204342043520436204372043820439204402044120442204432044420445204462044720448204492045020451204522045320454204552045620457204582045920460204612046220463204642046520466204672046820469204702047120472204732047420475204762047720478204792048020481204822048320484204852048620487204882048920490204912049220493204942049520496204972049820499205002050120502205032050420505205062050720508205092051020511205122051320514205152051620517205182051920520205212052220523205242052520526205272052820529205302053120532205332053420535205362053720538205392054020541205422054320544205452054620547205482054920550205512055220553205542055520556205572055820559205602056120562205632056420565205662056720568205692057020571205722057320574205752057620577205782057920580205812058220583205842058520586205872058820589205902059120592205932059420595205962059720598205992060020601206022060320604206052060620607206082060920610206112061220613206142061520616206172061820619206202062120622206232062420625206262062720628206292063020631206322063320634206352063620637206382063920640206412064220643206442064520646206472064820649206502065120652206532065420655206562065720658206592066020661206622066320664206652066620667206682066920670206712067220673206742067520676206772067820679206802068120682206832068420685206862068720688206892069020691206922069320694206952069620697206982069920700207012070220703207042070520706207072070820709207102071120712207132071420715207162071720718207192072020721207222072320724207252072620727207282072920730207312073220733207342073520736207372073820739207402074120742207432074420745207462074720748207492075020751207522075320754207552075620757207582075920760207612076220763207642076520766207672076820769207702077120772207732077420775207762077720778207792078020781207822078320784207852078620787207882078920790207912079220793207942079520796207972079820799208002080120802208032080420805208062080720808208092081020811208122081320814208152081620817208182081920820208212082220823208242082520826208272082820829208302083120832208332083420835208362083720838208392084020841208422084320844208452084620847208482084920850208512085220853208542085520856208572085820859208602086120862208632086420865208662086720868208692087020871208722087320874208752087620877208782087920880208812088220883208842088520886208872088820889208902089120892208932089420895208962089720898208992090020901209022090320904209052090620907209082090920910209112091220913209142091520916209172091820919209202092120922209232092420925209262092720928209292093020931209322093320934209352093620937209382093920940209412094220943209442094520946209472094820949209502095120952209532095420955209562095720958209592096020961209622096320964209652096620967209682096920970209712097220973209742097520976209772097820979209802098120982209832098420985209862098720988209892099020991209922099320994209952099620997209982099921000210012100221003210042100521006210072100821009210102101121012210132101421015210162101721018210192102021021210222102321024210252102621027210282102921030210312103221033210342103521036210372103821039210402104121042210432104421045210462104721048210492105021051210522105321054210552105621057210582105921060210612106221063210642106521066210672106821069210702107121072210732107421075210762107721078210792108021081210822108321084210852108621087210882108921090210912109221093210942109521096210972109821099211002110121102211032110421105211062110721108211092111021111211122111321114211152111621117211182111921120211212112221123211242112521126211272112821129211302113121132211332113421135211362113721138211392114021141211422114321144211452114621147211482114921150211512115221153211542115521156211572115821159211602116121162211632116421165211662116721168211692117021171211722117321174211752117621177211782117921180211812118221183211842118521186211872118821189211902119121192211932119421195211962119721198211992120021201212022120321204212052120621207212082120921210212112121221213212142121521216212172121821219212202122121222212232122421225212262122721228212292123021231212322123321234212352123621237212382123921240212412124221243212442124521246212472124821249212502125121252212532125421255212562125721258212592126021261212622126321264212652126621267212682126921270212712127221273212742127521276212772127821279212802128121282212832128421285212862128721288212892129021291212922129321294212952129621297212982129921300213012130221303213042130521306213072130821309213102131121312213132131421315213162131721318213192132021321213222132321324213252132621327213282132921330213312133221333213342133521336213372133821339213402134121342213432134421345213462134721348213492135021351213522135321354213552135621357213582135921360213612136221363213642136521366213672136821369213702137121372213732137421375213762137721378213792138021381213822138321384213852138621387213882138921390213912139221393213942139521396213972139821399214002140121402214032140421405214062140721408214092141021411214122141321414214152141621417214182141921420214212142221423214242142521426214272142821429214302143121432214332143421435214362143721438214392144021441214422144321444214452144621447214482144921450214512145221453214542145521456214572145821459214602146121462214632146421465214662146721468214692147021471214722147321474214752147621477214782147921480214812148221483214842148521486214872148821489214902149121492214932149421495214962149721498214992150021501215022150321504215052150621507215082150921510215112151221513215142151521516215172151821519215202152121522215232152421525215262152721528215292153021531215322153321534215352153621537215382153921540215412154221543215442154521546215472154821549215502155121552215532155421555215562155721558215592156021561215622156321564215652156621567215682156921570215712157221573215742157521576215772157821579215802158121582215832158421585215862158721588215892159021591215922159321594215952159621597215982159921600216012160221603216042160521606216072160821609216102161121612216132161421615216162161721618216192162021621216222162321624216252162621627216282162921630216312163221633216342163521636216372163821639216402164121642216432164421645216462164721648216492165021651216522165321654216552165621657216582165921660216612166221663216642166521666216672166821669216702167121672216732167421675216762167721678216792168021681216822168321684216852168621687216882168921690216912169221693216942169521696216972169821699217002170121702217032170421705217062170721708217092171021711217122171321714217152171621717217182171921720217212172221723217242172521726217272172821729217302173121732217332173421735217362173721738217392174021741217422174321744217452174621747217482174921750217512175221753217542175521756217572175821759217602176121762217632176421765217662176721768217692177021771217722177321774217752177621777217782177921780217812178221783217842178521786217872178821789217902179121792217932179421795217962179721798217992180021801218022180321804218052180621807218082180921810218112181221813218142181521816218172181821819218202182121822218232182421825218262182721828218292183021831218322183321834218352183621837218382183921840218412184221843218442184521846218472184821849218502185121852218532185421855218562185721858218592186021861218622186321864218652186621867218682186921870218712187221873218742187521876218772187821879218802188121882218832188421885218862188721888218892189021891218922189321894218952189621897218982189921900219012190221903219042190521906219072190821909219102191121912219132191421915219162191721918219192192021921219222192321924219252192621927219282192921930219312193221933219342193521936219372193821939219402194121942219432194421945219462194721948219492195021951219522195321954219552195621957219582195921960219612196221963219642196521966219672196821969219702197121972219732197421975219762197721978219792198021981219822198321984219852198621987219882198921990219912199221993219942199521996219972199821999220002200122002220032200422005220062200722008220092201022011220122201322014220152201622017220182201922020220212202222023220242202522026220272202822029220302203122032220332203422035220362203722038220392204022041220422204322044220452204622047220482204922050220512205222053220542205522056220572205822059220602206122062220632206422065220662206722068220692207022071220722207322074220752207622077220782207922080220812208222083220842208522086220872208822089220902209122092220932209422095220962209722098220992210022101221022210322104221052210622107221082210922110221112211222113221142211522116221172211822119221202212122122221232212422125221262212722128221292213022131221322213322134221352213622137221382213922140221412214222143221442214522146221472214822149221502215122152221532215422155221562215722158221592216022161221622216322164221652216622167221682216922170221712217222173221742217522176221772217822179221802218122182221832218422185221862218722188221892219022191221922219322194221952219622197221982219922200222012220222203222042220522206222072220822209222102221122212222132221422215222162221722218222192222022221222222222322224222252222622227222282222922230222312223222233222342223522236222372223822239222402224122242222432224422245222462224722248222492225022251222522225322254222552225622257222582225922260222612226222263222642226522266222672226822269222702227122272222732227422275222762227722278222792228022281222822228322284222852228622287222882228922290222912229222293222942229522296222972229822299223002230122302223032230422305223062230722308223092231022311223122231322314223152231622317223182231922320223212232222323223242232522326223272232822329223302233122332223332233422335223362233722338223392234022341223422234322344223452234622347223482234922350223512235222353223542235522356223572235822359223602236122362223632236422365223662236722368223692237022371223722237322374223752237622377223782237922380223812238222383223842238522386223872238822389223902239122392223932239422395223962239722398223992240022401224022240322404224052240622407224082240922410224112241222413224142241522416224172241822419224202242122422224232242422425224262242722428224292243022431224322243322434224352243622437224382243922440224412244222443224442244522446224472244822449224502245122452224532245422455224562245722458224592246022461224622246322464224652246622467224682246922470224712247222473224742247522476224772247822479224802248122482224832248422485224862248722488224892249022491224922249322494224952249622497224982249922500225012250222503225042250522506225072250822509225102251122512225132251422515225162251722518225192252022521225222252322524225252252622527225282252922530225312253222533225342253522536225372253822539225402254122542225432254422545225462254722548225492255022551225522255322554225552255622557225582255922560225612256222563225642256522566225672256822569225702257122572225732257422575225762257722578225792258022581225822258322584225852258622587225882258922590225912259222593225942259522596225972259822599226002260122602226032260422605226062260722608226092261022611226122261322614226152261622617226182261922620226212262222623226242262522626226272262822629226302263122632226332263422635226362263722638226392264022641226422264322644226452264622647226482264922650226512265222653226542265522656226572265822659226602266122662226632266422665226662266722668226692267022671226722267322674226752267622677226782267922680226812268222683226842268522686226872268822689226902269122692226932269422695226962269722698226992270022701227022270322704227052270622707227082270922710227112271222713227142271522716227172271822719227202272122722227232272422725227262272722728227292273022731227322273322734227352273622737227382273922740227412274222743227442274522746227472274822749227502275122752227532275422755227562275722758227592276022761227622276322764227652276622767227682276922770227712277222773227742277522776227772277822779227802278122782227832278422785227862278722788227892279022791227922279322794227952279622797227982279922800228012280222803228042280522806228072280822809228102281122812228132281422815228162281722818228192282022821228222282322824228252282622827228282282922830228312283222833228342283522836228372283822839228402284122842228432284422845228462284722848228492285022851228522285322854228552285622857228582285922860228612286222863228642286522866228672286822869228702287122872228732287422875228762287722878228792288022881228822288322884228852288622887228882288922890228912289222893228942289522896228972289822899229002290122902229032290422905229062290722908229092291022911229122291322914229152291622917229182291922920229212292222923229242292522926229272292822929229302293122932229332293422935229362293722938229392294022941229422294322944229452294622947229482294922950229512295222953229542295522956229572295822959229602296122962229632296422965229662296722968229692297022971229722297322974229752297622977229782297922980229812298222983229842298522986229872298822989229902299122992229932299422995229962299722998229992300023001230022300323004230052300623007230082300923010230112301223013230142301523016230172301823019230202302123022230232302423025230262302723028230292303023031230322303323034230352303623037230382303923040230412304223043230442304523046230472304823049230502305123052230532305423055230562305723058230592306023061230622306323064230652306623067230682306923070230712307223073230742307523076230772307823079230802308123082230832308423085230862308723088230892309023091230922309323094230952309623097230982309923100231012310223103231042310523106231072310823109231102311123112231132311423115231162311723118231192312023121231222312323124231252312623127231282312923130231312313223133231342313523136231372313823139231402314123142231432314423145231462314723148231492315023151231522315323154231552315623157231582315923160231612316223163231642316523166231672316823169231702317123172231732317423175231762317723178231792318023181231822318323184231852318623187231882318923190231912319223193231942319523196231972319823199232002320123202232032320423205232062320723208232092321023211232122321323214232152321623217232182321923220232212322223223232242322523226232272322823229232302323123232232332323423235232362323723238232392324023241232422324323244232452324623247232482324923250232512325223253232542325523256232572325823259232602326123262232632326423265232662326723268232692327023271232722327323274232752327623277232782327923280232812328223283232842328523286232872328823289232902329123292232932329423295232962329723298232992330023301233022330323304233052330623307233082330923310233112331223313233142331523316233172331823319233202332123322233232332423325233262332723328233292333023331233322333323334233352333623337233382333923340233412334223343233442334523346233472334823349233502335123352233532335423355233562335723358233592336023361233622336323364233652336623367233682336923370233712337223373233742337523376233772337823379233802338123382233832338423385233862338723388233892339023391233922339323394233952339623397233982339923400234012340223403234042340523406234072340823409234102341123412234132341423415234162341723418234192342023421234222342323424234252342623427234282342923430234312343223433234342343523436234372343823439234402344123442234432344423445234462344723448234492345023451234522345323454234552345623457234582345923460234612346223463234642346523466234672346823469234702347123472234732347423475234762347723478234792348023481234822348323484234852348623487234882348923490234912349223493234942349523496234972349823499235002350123502235032350423505235062350723508235092351023511235122351323514235152351623517235182351923520235212352223523235242352523526235272352823529235302353123532235332353423535235362353723538235392354023541235422354323544235452354623547235482354923550235512355223553235542355523556235572355823559235602356123562235632356423565235662356723568235692357023571235722357323574235752357623577235782357923580235812358223583235842358523586235872358823589235902359123592235932359423595235962359723598235992360023601236022360323604236052360623607236082360923610236112361223613236142361523616236172361823619236202362123622236232362423625236262362723628236292363023631236322363323634236352363623637236382363923640236412364223643236442364523646236472364823649236502365123652236532365423655236562365723658236592366023661236622366323664236652366623667236682366923670236712367223673236742367523676236772367823679236802368123682236832368423685236862368723688236892369023691236922369323694236952369623697236982369923700237012370223703237042370523706237072370823709237102371123712237132371423715237162371723718237192372023721237222372323724237252372623727237282372923730237312373223733237342373523736237372373823739237402374123742237432374423745237462374723748237492375023751237522375323754237552375623757237582375923760237612376223763237642376523766237672376823769237702377123772237732377423775237762377723778237792378023781237822378323784237852378623787237882378923790237912379223793237942379523796237972379823799238002380123802238032380423805238062380723808238092381023811238122381323814238152381623817238182381923820238212382223823238242382523826238272382823829238302383123832238332383423835238362383723838238392384023841238422384323844238452384623847238482384923850238512385223853238542385523856238572385823859238602386123862238632386423865238662386723868238692387023871238722387323874238752387623877238782387923880238812388223883238842388523886238872388823889238902389123892238932389423895238962389723898238992390023901239022390323904239052390623907239082390923910239112391223913239142391523916239172391823919239202392123922239232392423925239262392723928239292393023931239322393323934239352393623937239382393923940239412394223943239442394523946239472394823949239502395123952239532395423955239562395723958239592396023961239622396323964239652396623967239682396923970239712397223973239742397523976239772397823979239802398123982239832398423985239862398723988239892399023991239922399323994239952399623997239982399924000240012400224003240042400524006240072400824009240102401124012240132401424015240162401724018240192402024021240222402324024240252402624027240282402924030240312403224033240342403524036240372403824039240402404124042240432404424045240462404724048240492405024051240522405324054240552405624057240582405924060240612406224063240642406524066240672406824069240702407124072240732407424075240762407724078240792408024081240822408324084240852408624087240882408924090240912409224093240942409524096240972409824099241002410124102241032410424105241062410724108241092411024111241122411324114241152411624117241182411924120241212412224123241242412524126241272412824129241302413124132241332413424135241362413724138241392414024141241422414324144241452414624147241482414924150241512415224153241542415524156241572415824159241602416124162241632416424165241662416724168241692417024171241722417324174241752417624177241782417924180241812418224183241842418524186241872418824189241902419124192241932419424195241962419724198241992420024201242022420324204242052420624207242082420924210242112421224213242142421524216242172421824219242202422124222242232422424225242262422724228242292423024231242322423324234242352423624237242382423924240242412424224243242442424524246242472424824249242502425124252242532425424255242562425724258242592426024261242622426324264242652426624267242682426924270242712427224273242742427524276242772427824279242802428124282242832428424285242862428724288242892429024291242922429324294242952429624297242982429924300243012430224303243042430524306243072430824309243102431124312243132431424315243162431724318243192432024321243222432324324243252432624327243282432924330243312433224333243342433524336243372433824339243402434124342243432434424345243462434724348243492435024351243522435324354243552435624357243582435924360243612436224363243642436524366243672436824369243702437124372243732437424375243762437724378243792438024381243822438324384243852438624387243882438924390243912439224393243942439524396243972439824399244002440124402244032440424405244062440724408244092441024411244122441324414244152441624417244182441924420244212442224423244242442524426244272442824429244302443124432244332443424435244362443724438244392444024441244422444324444244452444624447244482444924450244512445224453244542445524456244572445824459244602446124462244632446424465244662446724468244692447024471244722447324474244752447624477244782447924480244812448224483244842448524486244872448824489244902449124492244932449424495244962449724498244992450024501245022450324504245052450624507245082450924510245112451224513245142451524516245172451824519245202452124522245232452424525245262452724528245292453024531245322453324534245352453624537245382453924540245412454224543245442454524546245472454824549245502455124552245532455424555245562455724558245592456024561245622456324564245652456624567245682456924570245712457224573245742457524576245772457824579245802458124582245832458424585245862458724588245892459024591245922459324594245952459624597245982459924600246012460224603246042460524606246072460824609246102461124612246132461424615246162461724618246192462024621246222462324624246252462624627246282462924630246312463224633246342463524636246372463824639246402464124642246432464424645246462464724648246492465024651246522465324654246552465624657246582465924660246612466224663246642466524666246672466824669246702467124672246732467424675246762467724678246792468024681246822468324684246852468624687246882468924690246912469224693246942469524696246972469824699247002470124702247032470424705247062470724708247092471024711247122471324714247152471624717247182471924720247212472224723247242472524726247272472824729247302473124732247332473424735247362473724738247392474024741247422474324744247452474624747247482474924750247512475224753247542475524756247572475824759247602476124762247632476424765247662476724768247692477024771247722477324774247752477624777247782477924780247812478224783247842478524786247872478824789247902479124792247932479424795247962479724798247992480024801248022480324804248052480624807248082480924810248112481224813248142481524816248172481824819248202482124822248232482424825248262482724828248292483024831248322483324834248352483624837248382483924840248412484224843248442484524846248472484824849248502485124852248532485424855248562485724858248592486024861248622486324864248652486624867248682486924870248712487224873248742487524876248772487824879248802488124882248832488424885248862488724888248892489024891248922489324894248952489624897248982489924900249012490224903249042490524906249072490824909249102491124912249132491424915249162491724918249192492024921249222492324924249252492624927249282492924930249312493224933249342493524936249372493824939249402494124942249432494424945249462494724948249492495024951249522495324954249552495624957249582495924960249612496224963249642496524966249672496824969249702497124972249732497424975249762497724978249792498024981249822498324984249852498624987249882498924990249912499224993249942499524996249972499824999250002500125002250032500425005250062500725008250092501025011250122501325014250152501625017250182501925020250212502225023250242502525026250272502825029250302503125032250332503425035250362503725038250392504025041250422504325044250452504625047250482504925050250512505225053250542505525056250572505825059250602506125062250632506425065250662506725068250692507025071250722507325074250752507625077250782507925080250812508225083250842508525086250872508825089250902509125092250932509425095250962509725098250992510025101251022510325104251052510625107251082510925110251112511225113251142511525116251172511825119251202512125122251232512425125251262512725128251292513025131251322513325134251352513625137251382513925140251412514225143251442514525146251472514825149251502515125152251532515425155251562515725158251592516025161251622516325164251652516625167251682516925170251712517225173251742517525176251772517825179251802518125182251832518425185251862518725188251892519025191251922519325194251952519625197251982519925200252012520225203252042520525206252072520825209252102521125212252132521425215252162521725218252192522025221252222522325224252252522625227252282522925230252312523225233252342523525236252372523825239252402524125242252432524425245252462524725248252492525025251252522525325254252552525625257252582525925260252612526225263252642526525266252672526825269252702527125272252732527425275252762527725278252792528025281252822528325284252852528625287252882528925290252912529225293252942529525296252972529825299253002530125302253032530425305253062530725308253092531025311253122531325314253152531625317253182531925320253212532225323253242532525326253272532825329253302533125332253332533425335253362533725338253392534025341253422534325344253452534625347253482534925350253512535225353253542535525356253572535825359253602536125362253632536425365253662536725368253692537025371253722537325374253752537625377253782537925380253812538225383253842538525386253872538825389253902539125392253932539425395253962539725398253992540025401254022540325404254052540625407254082540925410254112541225413254142541525416254172541825419254202542125422254232542425425254262542725428254292543025431254322543325434254352543625437254382543925440254412544225443254442544525446254472544825449254502545125452254532545425455254562545725458254592546025461254622546325464254652546625467254682546925470254712547225473254742547525476254772547825479254802548125482254832548425485254862548725488254892549025491254922549325494254952549625497254982549925500255012550225503255042550525506255072550825509255102551125512255132551425515255162551725518255192552025521255222552325524255252552625527255282552925530255312553225533255342553525536255372553825539255402554125542255432554425545255462554725548255492555025551255522555325554255552555625557255582555925560255612556225563255642556525566255672556825569255702557125572255732557425575255762557725578255792558025581255822558325584255852558625587255882558925590255912559225593255942559525596255972559825599256002560125602256032560425605256062560725608256092561025611256122561325614256152561625617256182561925620256212562225623256242562525626256272562825629256302563125632256332563425635256362563725638256392564025641256422564325644256452564625647256482564925650256512565225653256542565525656256572565825659256602566125662256632566425665256662566725668256692567025671256722567325674256752567625677256782567925680256812568225683256842568525686256872568825689256902569125692256932569425695256962569725698256992570025701257022570325704257052570625707257082570925710257112571225713257142571525716257172571825719257202572125722257232572425725257262572725728257292573025731257322573325734257352573625737257382573925740257412574225743257442574525746257472574825749257502575125752257532575425755257562575725758257592576025761257622576325764257652576625767257682576925770257712577225773257742577525776257772577825779257802578125782257832578425785257862578725788257892579025791257922579325794257952579625797257982579925800258012580225803258042580525806258072580825809258102581125812258132581425815258162581725818258192582025821258222582325824258252582625827258282582925830258312583225833258342583525836258372583825839258402584125842258432584425845258462584725848258492585025851258522585325854258552585625857258582585925860258612586225863258642586525866258672586825869258702587125872258732587425875258762587725878258792588025881258822588325884258852588625887258882588925890258912589225893258942589525896258972589825899259002590125902259032590425905259062590725908259092591025911259122591325914259152591625917259182591925920259212592225923259242592525926259272592825929259302593125932259332593425935259362593725938259392594025941259422594325944259452594625947259482594925950259512595225953259542595525956259572595825959259602596125962259632596425965259662596725968259692597025971259722597325974259752597625977259782597925980259812598225983259842598525986259872598825989259902599125992259932599425995259962599725998259992600026001260022600326004260052600626007260082600926010260112601226013260142601526016260172601826019260202602126022260232602426025260262602726028260292603026031260322603326034260352603626037260382603926040260412604226043260442604526046260472604826049260502605126052260532605426055260562605726058260592606026061260622606326064260652606626067260682606926070260712607226073260742607526076260772607826079260802608126082260832608426085260862608726088260892609026091260922609326094260952609626097260982609926100261012610226103261042610526106261072610826109261102611126112261132611426115261162611726118261192612026121261222612326124261252612626127261282612926130261312613226133261342613526136261372613826139261402614126142261432614426145261462614726148261492615026151261522615326154261552615626157261582615926160261612616226163261642616526166261672616826169261702617126172261732617426175261762617726178261792618026181261822618326184261852618626187261882618926190261912619226193261942619526196261972619826199262002620126202262032620426205262062620726208262092621026211262122621326214262152621626217262182621926220262212622226223262242622526226262272622826229262302623126232262332623426235262362623726238262392624026241262422624326244262452624626247262482624926250262512625226253262542625526256262572625826259262602626126262262632626426265262662626726268262692627026271262722627326274262752627626277262782627926280262812628226283262842628526286262872628826289262902629126292262932629426295262962629726298262992630026301263022630326304263052630626307263082630926310263112631226313263142631526316263172631826319263202632126322263232632426325263262632726328263292633026331263322633326334263352633626337263382633926340263412634226343263442634526346263472634826349263502635126352263532635426355263562635726358263592636026361263622636326364263652636626367263682636926370263712637226373263742637526376263772637826379263802638126382263832638426385263862638726388263892639026391263922639326394263952639626397263982639926400264012640226403264042640526406264072640826409264102641126412264132641426415264162641726418264192642026421264222642326424264252642626427264282642926430264312643226433264342643526436264372643826439264402644126442264432644426445264462644726448264492645026451264522645326454264552645626457264582645926460264612646226463264642646526466264672646826469264702647126472264732647426475264762647726478264792648026481264822648326484264852648626487264882648926490264912649226493264942649526496264972649826499265002650126502265032650426505265062650726508265092651026511265122651326514265152651626517265182651926520265212652226523265242652526526265272652826529265302653126532265332653426535265362653726538265392654026541265422654326544265452654626547265482654926550265512655226553265542655526556265572655826559265602656126562265632656426565265662656726568265692657026571265722657326574265752657626577265782657926580265812658226583265842658526586265872658826589265902659126592265932659426595265962659726598265992660026601266022660326604266052660626607266082660926610266112661226613266142661526616266172661826619266202662126622266232662426625266262662726628266292663026631266322663326634266352663626637266382663926640266412664226643266442664526646266472664826649266502665126652266532665426655266562665726658266592666026661266622666326664266652666626667266682666926670266712667226673266742667526676266772667826679266802668126682266832668426685266862668726688266892669026691266922669326694266952669626697266982669926700267012670226703267042670526706267072670826709267102671126712267132671426715267162671726718267192672026721267222672326724267252672626727267282672926730267312673226733267342673526736267372673826739267402674126742267432674426745267462674726748267492675026751267522675326754267552675626757267582675926760267612676226763267642676526766267672676826769267702677126772267732677426775267762677726778267792678026781267822678326784267852678626787267882678926790267912679226793267942679526796267972679826799268002680126802268032680426805268062680726808268092681026811268122681326814268152681626817268182681926820268212682226823268242682526826268272682826829268302683126832268332683426835268362683726838268392684026841268422684326844268452684626847268482684926850268512685226853268542685526856268572685826859268602686126862268632686426865268662686726868268692687026871268722687326874268752687626877268782687926880268812688226883268842688526886268872688826889268902689126892268932689426895268962689726898268992690026901269022690326904269052690626907269082690926910269112691226913269142691526916269172691826919269202692126922269232692426925269262692726928269292693026931269322693326934269352693626937269382693926940269412694226943269442694526946269472694826949269502695126952269532695426955269562695726958269592696026961269622696326964269652696626967269682696926970269712697226973269742697526976269772697826979269802698126982269832698426985269862698726988269892699026991269922699326994269952699626997269982699927000270012700227003270042700527006270072700827009270102701127012270132701427015270162701727018270192702027021270222702327024270252702627027270282702927030270312703227033270342703527036270372703827039270402704127042270432704427045270462704727048270492705027051270522705327054270552705627057270582705927060270612706227063270642706527066270672706827069270702707127072270732707427075270762707727078270792708027081270822708327084270852708627087270882708927090270912709227093270942709527096270972709827099271002710127102271032710427105271062710727108271092711027111271122711327114271152711627117271182711927120271212712227123271242712527126271272712827129271302713127132271332713427135271362713727138271392714027141271422714327144271452714627147271482714927150271512715227153271542715527156271572715827159271602716127162271632716427165271662716727168271692717027171271722717327174271752717627177271782717927180271812718227183271842718527186271872718827189271902719127192271932719427195271962719727198271992720027201272022720327204272052720627207272082720927210272112721227213272142721527216272172721827219272202722127222272232722427225272262722727228272292723027231272322723327234272352723627237272382723927240272412724227243272442724527246272472724827249272502725127252272532725427255272562725727258272592726027261272622726327264272652726627267272682726927270272712727227273272742727527276272772727827279272802728127282272832728427285272862728727288272892729027291272922729327294272952729627297272982729927300273012730227303273042730527306273072730827309273102731127312273132731427315273162731727318273192732027321273222732327324273252732627327273282732927330273312733227333273342733527336273372733827339273402734127342273432734427345273462734727348273492735027351273522735327354273552735627357273582735927360273612736227363273642736527366273672736827369273702737127372273732737427375273762737727378273792738027381273822738327384273852738627387273882738927390273912739227393273942739527396273972739827399274002740127402274032740427405274062740727408274092741027411274122741327414274152741627417274182741927420274212742227423274242742527426274272742827429274302743127432274332743427435274362743727438274392744027441274422744327444274452744627447274482744927450274512745227453274542745527456274572745827459274602746127462274632746427465274662746727468274692747027471274722747327474274752747627477274782747927480274812748227483274842748527486274872748827489274902749127492274932749427495274962749727498274992750027501275022750327504275052750627507275082750927510275112751227513275142751527516275172751827519275202752127522275232752427525275262752727528275292753027531275322753327534275352753627537275382753927540275412754227543275442754527546275472754827549275502755127552275532755427555275562755727558275592756027561275622756327564275652756627567275682756927570275712757227573275742757527576275772757827579275802758127582275832758427585275862758727588275892759027591275922759327594275952759627597275982759927600276012760227603276042760527606276072760827609276102761127612276132761427615276162761727618276192762027621276222762327624276252762627627276282762927630276312763227633276342763527636276372763827639276402764127642276432764427645276462764727648276492765027651276522765327654276552765627657276582765927660276612766227663276642766527666276672766827669276702767127672276732767427675276762767727678276792768027681276822768327684276852768627687276882768927690276912769227693276942769527696276972769827699277002770127702277032770427705277062770727708277092771027711277122771327714277152771627717277182771927720277212772227723277242772527726277272772827729277302773127732277332773427735277362773727738277392774027741277422774327744277452774627747277482774927750277512775227753277542775527756277572775827759277602776127762277632776427765277662776727768277692777027771277722777327774277752777627777277782777927780277812778227783277842778527786277872778827789277902779127792277932779427795277962779727798277992780027801278022780327804278052780627807278082780927810278112781227813278142781527816278172781827819278202782127822278232782427825278262782727828278292783027831278322783327834278352783627837278382783927840278412784227843278442784527846278472784827849278502785127852278532785427855278562785727858278592786027861278622786327864278652786627867278682786927870278712787227873278742787527876278772787827879278802788127882278832788427885278862788727888278892789027891278922789327894278952789627897278982789927900279012790227903279042790527906279072790827909279102791127912279132791427915279162791727918279192792027921279222792327924279252792627927279282792927930279312793227933279342793527936279372793827939279402794127942279432794427945279462794727948279492795027951279522795327954279552795627957279582795927960279612796227963279642796527966279672796827969279702797127972279732797427975279762797727978279792798027981279822798327984279852798627987279882798927990279912799227993279942799527996279972799827999280002800128002280032800428005280062800728008280092801028011280122801328014280152801628017280182801928020280212802228023280242802528026280272802828029280302803128032280332803428035280362803728038280392804028041280422804328044280452804628047280482804928050280512805228053280542805528056280572805828059280602806128062280632806428065280662806728068280692807028071280722807328074280752807628077280782807928080280812808228083280842808528086280872808828089280902809128092280932809428095280962809728098280992810028101281022810328104281052810628107281082810928110281112811228113281142811528116281172811828119281202812128122281232812428125281262812728128281292813028131281322813328134281352813628137281382813928140281412814228143281442814528146281472814828149281502815128152281532815428155281562815728158281592816028161281622816328164281652816628167281682816928170281712817228173281742817528176281772817828179281802818128182281832818428185281862818728188281892819028191281922819328194281952819628197281982819928200282012820228203282042820528206282072820828209282102821128212282132821428215282162821728218282192822028221282222822328224282252822628227282282822928230282312823228233282342823528236282372823828239282402824128242282432824428245282462824728248282492825028251282522825328254282552825628257282582825928260282612826228263282642826528266282672826828269282702827128272282732827428275282762827728278282792828028281282822828328284282852828628287282882828928290282912829228293282942829528296282972829828299283002830128302283032830428305283062830728308283092831028311283122831328314283152831628317283182831928320283212832228323283242832528326283272832828329283302833128332283332833428335283362833728338283392834028341283422834328344283452834628347283482834928350283512835228353283542835528356283572835828359283602836128362283632836428365283662836728368283692837028371283722837328374283752837628377283782837928380283812838228383283842838528386283872838828389283902839128392283932839428395283962839728398283992840028401284022840328404284052840628407284082840928410284112841228413284142841528416284172841828419284202842128422284232842428425284262842728428284292843028431284322843328434284352843628437284382843928440284412844228443284442844528446284472844828449284502845128452284532845428455284562845728458284592846028461284622846328464284652846628467284682846928470284712847228473284742847528476284772847828479284802848128482284832848428485284862848728488284892849028491284922849328494284952849628497284982849928500285012850228503285042850528506285072850828509285102851128512285132851428515285162851728518285192852028521285222852328524285252852628527285282852928530285312853228533285342853528536285372853828539285402854128542285432854428545285462854728548285492855028551285522855328554285552855628557285582855928560285612856228563285642856528566285672856828569285702857128572285732857428575285762857728578285792858028581285822858328584285852858628587285882858928590285912859228593285942859528596285972859828599286002860128602286032860428605286062860728608286092861028611286122861328614286152861628617286182861928620286212862228623286242862528626286272862828629286302863128632286332863428635286362863728638286392864028641286422864328644286452864628647286482864928650286512865228653286542865528656286572865828659286602866128662286632866428665286662866728668286692867028671286722867328674286752867628677286782867928680286812868228683286842868528686286872868828689286902869128692286932869428695286962869728698286992870028701287022870328704287052870628707287082870928710287112871228713287142871528716287172871828719287202872128722287232872428725287262872728728287292873028731287322873328734287352873628737287382873928740287412874228743287442874528746287472874828749287502875128752287532875428755287562875728758287592876028761287622876328764287652876628767287682876928770287712877228773287742877528776287772877828779287802878128782287832878428785287862878728788287892879028791287922879328794287952879628797287982879928800288012880228803288042880528806288072880828809288102881128812288132881428815288162881728818288192882028821288222882328824288252882628827288282882928830288312883228833288342883528836288372883828839288402884128842288432884428845288462884728848288492885028851288522885328854288552885628857288582885928860288612886228863288642886528866288672886828869288702887128872288732887428875288762887728878288792888028881288822888328884288852888628887288882888928890288912889228893288942889528896288972889828899289002890128902289032890428905289062890728908289092891028911289122891328914289152891628917289182891928920289212892228923289242892528926289272892828929289302893128932289332893428935289362893728938289392894028941289422894328944289452894628947289482894928950289512895228953289542895528956289572895828959289602896128962289632896428965289662896728968289692897028971289722897328974289752897628977289782897928980289812898228983289842898528986289872898828989289902899128992289932899428995289962899728998289992900029001290022900329004290052900629007290082900929010290112901229013290142901529016290172901829019290202902129022290232902429025290262902729028290292903029031290322903329034290352903629037290382903929040290412904229043290442904529046290472904829049290502905129052290532905429055290562905729058290592906029061290622906329064290652906629067290682906929070290712907229073290742907529076290772907829079290802908129082290832908429085290862908729088290892909029091290922909329094290952909629097290982909929100291012910229103291042910529106291072910829109291102911129112291132911429115291162911729118291192912029121291222912329124291252912629127291282912929130291312913229133291342913529136291372913829139291402914129142291432914429145291462914729148291492915029151291522915329154291552915629157291582915929160291612916229163291642916529166291672916829169291702917129172291732917429175291762917729178291792918029181291822918329184291852918629187291882918929190291912919229193291942919529196291972919829199292002920129202292032920429205292062920729208292092921029211292122921329214292152921629217292182921929220292212922229223292242922529226292272922829229292302923129232292332923429235292362923729238292392924029241292422924329244292452924629247292482924929250292512925229253292542925529256292572925829259292602926129262292632926429265292662926729268292692927029271292722927329274292752927629277292782927929280292812928229283292842928529286292872928829289292902929129292292932929429295292962929729298292992930029301293022930329304293052930629307293082930929310293112931229313293142931529316293172931829319293202932129322293232932429325293262932729328293292933029331293322933329334293352933629337293382933929340293412934229343293442934529346293472934829349293502935129352293532935429355293562935729358293592936029361293622936329364293652936629367293682936929370293712937229373293742937529376293772937829379293802938129382293832938429385293862938729388293892939029391293922939329394293952939629397293982939929400294012940229403294042940529406294072940829409294102941129412294132941429415294162941729418294192942029421294222942329424294252942629427294282942929430294312943229433294342943529436294372943829439294402944129442294432944429445294462944729448294492945029451294522945329454294552945629457294582945929460294612946229463294642946529466294672946829469294702947129472294732947429475294762947729478294792948029481294822948329484294852948629487294882948929490294912949229493294942949529496294972949829499295002950129502295032950429505295062950729508295092951029511295122951329514295152951629517295182951929520295212952229523295242952529526295272952829529295302953129532295332953429535295362953729538295392954029541295422954329544295452954629547295482954929550295512955229553295542955529556295572955829559295602956129562295632956429565295662956729568295692957029571295722957329574295752957629577295782957929580295812958229583295842958529586295872958829589295902959129592295932959429595295962959729598295992960029601296022960329604296052960629607296082960929610296112961229613296142961529616296172961829619296202962129622296232962429625296262962729628296292963029631296322963329634296352963629637296382963929640296412964229643296442964529646296472964829649296502965129652296532965429655296562965729658296592966029661296622966329664296652966629667296682966929670296712967229673296742967529676296772967829679296802968129682296832968429685296862968729688296892969029691296922969329694296952969629697296982969929700297012970229703297042970529706297072970829709297102971129712297132971429715297162971729718297192972029721297222972329724297252972629727297282972929730297312973229733297342973529736297372973829739297402974129742297432974429745297462974729748297492975029751297522975329754297552975629757297582975929760297612976229763297642976529766297672976829769297702977129772297732977429775297762977729778297792978029781297822978329784297852978629787297882978929790297912979229793297942979529796297972979829799298002980129802298032980429805298062980729808298092981029811298122981329814298152981629817298182981929820298212982229823298242982529826298272982829829298302983129832298332983429835298362983729838298392984029841298422984329844298452984629847298482984929850298512985229853298542985529856298572985829859298602986129862298632986429865298662986729868298692987029871298722987329874298752987629877298782987929880298812988229883298842988529886298872988829889298902989129892298932989429895298962989729898298992990029901299022990329904299052990629907299082990929910299112991229913299142991529916299172991829919299202992129922299232992429925299262992729928299292993029931299322993329934299352993629937299382993929940299412994229943299442994529946299472994829949299502995129952299532995429955299562995729958299592996029961299622996329964299652996629967299682996929970299712997229973299742997529976299772997829979299802998129982299832998429985299862998729988299892999029991299922999329994299952999629997299982999930000300013000230003300043000530006300073000830009300103001130012300133001430015300163001730018300193002030021300223002330024300253002630027300283002930030300313003230033300343003530036300373003830039300403004130042300433004430045300463004730048300493005030051300523005330054300553005630057300583005930060300613006230063300643006530066300673006830069300703007130072300733007430075300763007730078300793008030081300823008330084300853008630087300883008930090300913009230093300943009530096300973009830099301003010130102301033010430105301063010730108301093011030111301123011330114301153011630117301183011930120301213012230123301243012530126301273012830129301303013130132301333013430135301363013730138301393014030141301423014330144301453014630147301483014930150301513015230153301543015530156301573015830159301603016130162301633016430165301663016730168301693017030171301723017330174301753017630177301783017930180301813018230183301843018530186301873018830189301903019130192301933019430195301963019730198301993020030201302023020330204302053020630207302083020930210302113021230213302143021530216302173021830219302203022130222302233022430225302263022730228302293023030231302323023330234302353023630237302383023930240302413024230243302443024530246302473024830249302503025130252302533025430255302563025730258302593026030261302623026330264302653026630267302683026930270302713027230273302743027530276302773027830279302803028130282302833028430285302863028730288302893029030291302923029330294302953029630297302983029930300303013030230303303043030530306303073030830309303103031130312303133031430315303163031730318303193032030321303223032330324303253032630327303283032930330303313033230333303343033530336303373033830339303403034130342303433034430345303463034730348303493035030351303523035330354303553035630357303583035930360303613036230363303643036530366303673036830369303703037130372303733037430375303763037730378303793038030381303823038330384303853038630387303883038930390303913039230393303943039530396303973039830399304003040130402304033040430405304063040730408304093041030411304123041330414304153041630417304183041930420304213042230423304243042530426304273042830429304303043130432304333043430435304363043730438304393044030441304423044330444304453044630447304483044930450304513045230453304543045530456304573045830459304603046130462304633046430465304663046730468304693047030471304723047330474304753047630477304783047930480304813048230483304843048530486304873048830489304903049130492304933049430495304963049730498304993050030501305023050330504305053050630507305083050930510305113051230513305143051530516305173051830519305203052130522305233052430525305263052730528305293053030531305323053330534305353053630537305383053930540305413054230543305443054530546305473054830549305503055130552305533055430555305563055730558305593056030561305623056330564305653056630567305683056930570305713057230573305743057530576305773057830579305803058130582305833058430585305863058730588305893059030591305923059330594305953059630597305983059930600306013060230603306043060530606306073060830609306103061130612306133061430615306163061730618306193062030621306223062330624306253062630627306283062930630306313063230633306343063530636306373063830639306403064130642306433064430645306463064730648306493065030651306523065330654306553065630657306583065930660306613066230663306643066530666306673066830669306703067130672306733067430675306763067730678306793068030681306823068330684306853068630687306883068930690306913069230693306943069530696306973069830699307003070130702307033070430705307063070730708307093071030711307123071330714307153071630717307183071930720307213072230723307243072530726307273072830729307303073130732307333073430735307363073730738307393074030741307423074330744307453074630747307483074930750307513075230753307543075530756307573075830759307603076130762307633076430765307663076730768307693077030771307723077330774307753077630777307783077930780307813078230783307843078530786307873078830789307903079130792307933079430795307963079730798307993080030801308023080330804308053080630807308083080930810308113081230813308143081530816308173081830819308203082130822308233082430825308263082730828308293083030831308323083330834308353083630837308383083930840308413084230843308443084530846308473084830849308503085130852308533085430855308563085730858308593086030861308623086330864308653086630867308683086930870308713087230873308743087530876308773087830879308803088130882308833088430885308863088730888308893089030891308923089330894308953089630897308983089930900309013090230903309043090530906309073090830909309103091130912309133091430915309163091730918309193092030921309223092330924309253092630927309283092930930309313093230933309343093530936309373093830939309403094130942309433094430945309463094730948309493095030951309523095330954309553095630957309583095930960309613096230963309643096530966309673096830969309703097130972309733097430975309763097730978309793098030981309823098330984309853098630987309883098930990309913099230993309943099530996309973099830999310003100131002310033100431005310063100731008310093101031011310123101331014310153101631017310183101931020310213102231023310243102531026310273102831029310303103131032310333103431035310363103731038310393104031041310423104331044310453104631047310483104931050310513105231053310543105531056310573105831059310603106131062310633106431065310663106731068310693107031071310723107331074310753107631077310783107931080310813108231083310843108531086310873108831089310903109131092310933109431095310963109731098310993110031101311023110331104311053110631107311083110931110311113111231113311143111531116311173111831119311203112131122311233112431125311263112731128311293113031131311323113331134311353113631137311383113931140311413114231143311443114531146311473114831149311503115131152311533115431155311563115731158311593116031161311623116331164311653116631167311683116931170311713117231173311743117531176311773117831179311803118131182311833118431185311863118731188311893119031191311923119331194311953119631197311983119931200312013120231203312043120531206312073120831209312103121131212312133121431215312163121731218312193122031221312223122331224312253122631227312283122931230312313123231233312343123531236312373123831239312403124131242312433124431245312463124731248312493125031251312523125331254312553125631257312583125931260312613126231263312643126531266312673126831269312703127131272312733127431275312763127731278312793128031281312823128331284312853128631287312883128931290312913129231293312943129531296312973129831299313003130131302313033130431305313063130731308313093131031311313123131331314313153131631317313183131931320313213132231323313243132531326313273132831329313303133131332313333133431335313363133731338313393134031341313423134331344313453134631347313483134931350313513135231353313543135531356313573135831359313603136131362313633136431365313663136731368313693137031371313723137331374313753137631377313783137931380313813138231383313843138531386313873138831389313903139131392313933139431395313963139731398313993140031401314023140331404314053140631407314083140931410314113141231413314143141531416314173141831419314203142131422314233142431425314263142731428314293143031431314323143331434314353143631437314383143931440314413144231443314443144531446314473144831449314503145131452314533145431455314563145731458314593146031461314623146331464314653146631467314683146931470314713147231473314743147531476314773147831479314803148131482314833148431485314863148731488314893149031491314923149331494314953149631497314983149931500315013150231503315043150531506315073150831509315103151131512315133151431515315163151731518315193152031521315223152331524315253152631527315283152931530315313153231533315343153531536315373153831539315403154131542315433154431545315463154731548315493155031551315523155331554315553155631557315583155931560315613156231563315643156531566315673156831569315703157131572315733157431575315763157731578315793158031581315823158331584315853158631587315883158931590315913159231593315943159531596315973159831599316003160131602316033160431605316063160731608316093161031611316123161331614316153161631617316183161931620316213162231623316243162531626316273162831629316303163131632316333163431635316363163731638316393164031641316423164331644316453164631647316483164931650316513165231653316543165531656316573165831659316603166131662316633166431665316663166731668316693167031671316723167331674316753167631677316783167931680316813168231683316843168531686316873168831689316903169131692316933169431695316963169731698316993170031701317023170331704317053170631707317083170931710317113171231713317143171531716317173171831719317203172131722317233172431725317263172731728317293173031731317323173331734317353173631737317383173931740317413174231743317443174531746317473174831749317503175131752317533175431755317563175731758317593176031761317623176331764317653176631767317683176931770317713177231773317743177531776317773177831779317803178131782317833178431785317863178731788317893179031791317923179331794317953179631797317983179931800318013180231803318043180531806318073180831809318103181131812318133181431815318163181731818318193182031821318223182331824318253182631827318283182931830318313183231833318343183531836318373183831839318403184131842318433184431845318463184731848318493185031851318523185331854318553185631857318583185931860318613186231863318643186531866318673186831869318703187131872318733187431875318763187731878318793188031881318823188331884318853188631887318883188931890318913189231893318943189531896318973189831899319003190131902319033190431905319063190731908319093191031911319123191331914319153191631917319183191931920319213192231923319243192531926319273192831929319303193131932319333193431935319363193731938319393194031941319423194331944319453194631947319483194931950319513195231953319543195531956319573195831959319603196131962319633196431965319663196731968319693197031971319723197331974319753197631977319783197931980319813198231983319843198531986319873198831989319903199131992319933199431995319963199731998319993200032001320023200332004320053200632007320083200932010320113201232013320143201532016320173201832019320203202132022320233202432025320263202732028320293203032031320323203332034320353203632037320383203932040320413204232043320443204532046320473204832049320503205132052320533205432055320563205732058320593206032061320623206332064320653206632067320683206932070320713207232073320743207532076320773207832079320803208132082320833208432085320863208732088320893209032091320923209332094320953209632097320983209932100321013210232103321043210532106321073210832109321103211132112321133211432115321163211732118321193212032121321223212332124321253212632127321283212932130321313213232133321343213532136321373213832139321403214132142321433214432145321463214732148321493215032151321523215332154321553215632157321583215932160321613216232163321643216532166321673216832169321703217132172321733217432175321763217732178321793218032181321823218332184321853218632187321883218932190321913219232193321943219532196321973219832199322003220132202322033220432205322063220732208322093221032211322123221332214322153221632217322183221932220322213222232223322243222532226322273222832229322303223132232322333223432235322363223732238322393224032241322423224332244322453224632247322483224932250322513225232253322543225532256322573225832259322603226132262322633226432265322663226732268322693227032271322723227332274322753227632277322783227932280322813228232283322843228532286322873228832289322903229132292322933229432295322963229732298322993230032301323023230332304323053230632307323083230932310323113231232313323143231532316323173231832319323203232132322323233232432325323263232732328323293233032331323323233332334323353233632337323383233932340323413234232343323443234532346323473234832349323503235132352323533235432355323563235732358323593236032361323623236332364323653236632367323683236932370323713237232373323743237532376323773237832379323803238132382323833238432385323863238732388323893239032391323923239332394323953239632397323983239932400324013240232403324043240532406324073240832409324103241132412324133241432415324163241732418324193242032421324223242332424324253242632427324283242932430324313243232433324343243532436324373243832439324403244132442324433244432445324463244732448324493245032451324523245332454324553245632457324583245932460324613246232463324643246532466324673246832469324703247132472324733247432475324763247732478324793248032481324823248332484324853248632487324883248932490324913249232493324943249532496324973249832499325003250132502325033250432505325063250732508325093251032511325123251332514325153251632517325183251932520325213252232523325243252532526325273252832529325303253132532325333253432535325363253732538325393254032541325423254332544325453254632547325483254932550325513255232553325543255532556325573255832559325603256132562325633256432565325663256732568325693257032571325723257332574325753257632577325783257932580325813258232583325843258532586325873258832589325903259132592325933259432595325963259732598325993260032601326023260332604326053260632607326083260932610326113261232613326143261532616326173261832619326203262132622326233262432625326263262732628326293263032631326323263332634326353263632637326383263932640326413264232643
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.19.0
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. default: Default
  92. description: Used to define a conversion Strategy
  93. enum:
  94. - Default
  95. - Unicode
  96. type: string
  97. decodingStrategy:
  98. default: None
  99. description: Used to define a decoding Strategy
  100. enum:
  101. - Auto
  102. - Base64
  103. - Base64URL
  104. - None
  105. type: string
  106. key:
  107. description: Key is the key used in the Provider, mandatory
  108. type: string
  109. metadataPolicy:
  110. default: None
  111. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  112. enum:
  113. - None
  114. - Fetch
  115. type: string
  116. nullBytePolicy:
  117. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  118. enum:
  119. - Ignore
  120. - Fail
  121. type: string
  122. property:
  123. description: Used to select a specific property of the Provider value (if a map), if supported
  124. type: string
  125. version:
  126. description: Used to select a specific version of the Provider value, if supported
  127. type: string
  128. required:
  129. - key
  130. type: object
  131. secretKey:
  132. description: The key in the Kubernetes Secret to store the value.
  133. maxLength: 253
  134. minLength: 1
  135. pattern: ^[-._a-zA-Z0-9]+$
  136. type: string
  137. sourceRef:
  138. description: |-
  139. SourceRef allows you to override the source
  140. from which the value will be pulled.
  141. maxProperties: 1
  142. minProperties: 1
  143. properties:
  144. generatorRef:
  145. description: |-
  146. GeneratorRef points to a generator custom resource.
  147. Deprecated: The generatorRef is not implemented in .data[].
  148. this will be removed with v1.
  149. properties:
  150. apiVersion:
  151. default: generators.external-secrets.io/v1alpha1
  152. description: Specify the apiVersion of the generator resource
  153. type: string
  154. kind:
  155. description: Specify the Kind of the generator resource
  156. enum:
  157. - ACRAccessToken
  158. - BeyondtrustWorkloadCredentialsDynamicSecret
  159. - ClusterGenerator
  160. - CloudsmithAccessToken
  161. - ECRAuthorizationToken
  162. - Fake
  163. - GCRAccessToken
  164. - GithubAccessToken
  165. - GitlabDeployToken
  166. - QuayAccessToken
  167. - Password
  168. - SSHKey
  169. - STSSessionToken
  170. - UUID
  171. - VaultDynamicSecret
  172. - Webhook
  173. - Grafana
  174. - MFA
  175. type: string
  176. name:
  177. description: Specify the name of the generator resource
  178. maxLength: 253
  179. minLength: 1
  180. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  181. type: string
  182. required:
  183. - kind
  184. - name
  185. type: object
  186. storeRef:
  187. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  188. properties:
  189. kind:
  190. description: |-
  191. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  192. Defaults to `SecretStore`
  193. enum:
  194. - SecretStore
  195. - ClusterSecretStore
  196. type: string
  197. name:
  198. description: Name of the SecretStore resource
  199. maxLength: 253
  200. minLength: 1
  201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  202. type: string
  203. type: object
  204. type: object
  205. required:
  206. - remoteRef
  207. - secretKey
  208. type: object
  209. type: array
  210. dataFrom:
  211. description: |-
  212. DataFrom is used to fetch all properties from a specific Provider data
  213. If multiple entries are specified, the Secret keys are merged in the specified order
  214. items:
  215. description: |-
  216. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  217. when using DataFrom to fetch multiple values from a Provider.
  218. properties:
  219. extract:
  220. description: |-
  221. Used to extract multiple key/value pairs from one secret
  222. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  223. properties:
  224. conversionStrategy:
  225. default: Default
  226. description: Used to define a conversion Strategy
  227. enum:
  228. - Default
  229. - Unicode
  230. type: string
  231. decodingStrategy:
  232. default: None
  233. description: Used to define a decoding Strategy
  234. enum:
  235. - Auto
  236. - Base64
  237. - Base64URL
  238. - None
  239. type: string
  240. key:
  241. description: Key is the key used in the Provider, mandatory
  242. type: string
  243. metadataPolicy:
  244. default: None
  245. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  246. enum:
  247. - None
  248. - Fetch
  249. type: string
  250. nullBytePolicy:
  251. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  252. enum:
  253. - Ignore
  254. - Fail
  255. type: string
  256. property:
  257. description: Used to select a specific property of the Provider value (if a map), if supported
  258. type: string
  259. version:
  260. description: Used to select a specific version of the Provider value, if supported
  261. type: string
  262. required:
  263. - key
  264. type: object
  265. find:
  266. description: |-
  267. Used to find secrets based on tags or regular expressions
  268. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  269. properties:
  270. conversionStrategy:
  271. default: Default
  272. description: Used to define a conversion Strategy
  273. enum:
  274. - Default
  275. - Unicode
  276. type: string
  277. decodingStrategy:
  278. default: None
  279. description: Used to define a decoding Strategy
  280. enum:
  281. - Auto
  282. - Base64
  283. - Base64URL
  284. - None
  285. type: string
  286. name:
  287. description: Finds secrets based on the name.
  288. properties:
  289. regexp:
  290. description: Finds secrets base
  291. type: string
  292. type: object
  293. nullBytePolicy:
  294. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  295. enum:
  296. - Ignore
  297. - Fail
  298. type: string
  299. path:
  300. description: A root path to start the find operations.
  301. type: string
  302. tags:
  303. additionalProperties:
  304. type: string
  305. description: Find secrets based on tags.
  306. type: object
  307. type: object
  308. rewrite:
  309. description: |-
  310. Used to rewrite secret Keys after getting them from the secret Provider
  311. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  312. items:
  313. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  314. maxProperties: 1
  315. minProperties: 1
  316. properties:
  317. merge:
  318. description: |-
  319. Used to merge key/values in one single Secret
  320. The resulting key will contain all values from the specified secrets
  321. properties:
  322. conflictPolicy:
  323. default: Error
  324. description: Used to define the policy to use in conflict resolution.
  325. enum:
  326. - Ignore
  327. - Error
  328. type: string
  329. into:
  330. default: ""
  331. description: |-
  332. Used to define the target key of the merge operation.
  333. Required if strategy is JSON. Ignored otherwise.
  334. type: string
  335. priority:
  336. description: Used to define key priority in conflict resolution.
  337. items:
  338. type: string
  339. type: array
  340. priorityPolicy:
  341. default: Strict
  342. description: Used to define the policy when a key in the priority list does not exist in the input.
  343. enum:
  344. - IgnoreNotFound
  345. - Strict
  346. type: string
  347. strategy:
  348. default: Extract
  349. description: Used to define the strategy to use in the merge operation.
  350. enum:
  351. - Extract
  352. - JSON
  353. type: string
  354. type: object
  355. regexp:
  356. description: |-
  357. Used to rewrite with regular expressions.
  358. The resulting key will be the output of a regexp.ReplaceAll operation.
  359. properties:
  360. source:
  361. description: Used to define the regular expression of a re.Compiler.
  362. type: string
  363. target:
  364. description: Used to define the target pattern of a ReplaceAll operation.
  365. type: string
  366. required:
  367. - source
  368. - target
  369. type: object
  370. transform:
  371. description: |-
  372. Used to apply string transformation on the secrets.
  373. The resulting key will be the output of the template applied by the operation.
  374. properties:
  375. template:
  376. description: |-
  377. Used to define the template to apply on the secret name.
  378. `.value ` will specify the secret name in the template.
  379. type: string
  380. required:
  381. - template
  382. type: object
  383. type: object
  384. type: array
  385. sourceRef:
  386. description: |-
  387. SourceRef points to a store or generator
  388. which contains secret values ready to use.
  389. Use this in combination with Extract or Find pull values out of
  390. a specific SecretStore.
  391. When sourceRef points to a generator Extract or Find is not supported.
  392. The generator returns a static map of values
  393. maxProperties: 1
  394. minProperties: 1
  395. properties:
  396. generatorRef:
  397. description: GeneratorRef points to a generator custom resource.
  398. properties:
  399. apiVersion:
  400. default: generators.external-secrets.io/v1alpha1
  401. description: Specify the apiVersion of the generator resource
  402. type: string
  403. kind:
  404. description: Specify the Kind of the generator resource
  405. enum:
  406. - ACRAccessToken
  407. - BeyondtrustWorkloadCredentialsDynamicSecret
  408. - ClusterGenerator
  409. - CloudsmithAccessToken
  410. - ECRAuthorizationToken
  411. - Fake
  412. - GCRAccessToken
  413. - GithubAccessToken
  414. - GitlabDeployToken
  415. - QuayAccessToken
  416. - Password
  417. - SSHKey
  418. - STSSessionToken
  419. - UUID
  420. - VaultDynamicSecret
  421. - Webhook
  422. - Grafana
  423. - MFA
  424. type: string
  425. name:
  426. description: Specify the name of the generator resource
  427. maxLength: 253
  428. minLength: 1
  429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  430. type: string
  431. required:
  432. - kind
  433. - name
  434. type: object
  435. storeRef:
  436. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  437. properties:
  438. kind:
  439. description: |-
  440. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  441. Defaults to `SecretStore`
  442. enum:
  443. - SecretStore
  444. - ClusterSecretStore
  445. type: string
  446. name:
  447. description: Name of the SecretStore resource
  448. maxLength: 253
  449. minLength: 1
  450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  451. type: string
  452. type: object
  453. type: object
  454. type: object
  455. type: array
  456. refreshInterval:
  457. default: 1h0m0s
  458. description: |-
  459. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  460. specified as Golang Duration strings.
  461. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  462. Example values: "1h0m0s", "2h30m0s", "10m0s"
  463. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  464. type: string
  465. refreshPolicy:
  466. description: |-
  467. RefreshPolicy determines how the ExternalSecret should be refreshed:
  468. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  469. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  470. No periodic updates occur if refreshInterval is 0.
  471. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  472. enum:
  473. - CreatedOnce
  474. - Periodic
  475. - OnChange
  476. type: string
  477. secretStoreRef:
  478. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  479. properties:
  480. kind:
  481. description: |-
  482. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  483. Defaults to `SecretStore`
  484. enum:
  485. - SecretStore
  486. - ClusterSecretStore
  487. type: string
  488. name:
  489. description: Name of the SecretStore resource
  490. maxLength: 253
  491. minLength: 1
  492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  493. type: string
  494. type: object
  495. syncWindows:
  496. description: |-
  497. SyncWindows optionally restricts when periodic refreshes may occur.
  498. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  499. properties:
  500. kind:
  501. description: |-
  502. Kind applies to every window in the list.
  503. "allow" -- syncs are permitted only while at least one window is active;
  504. all other times are blocked.
  505. "deny" -- syncs are blocked while any window is active;
  506. all other times are permitted.
  507. enum:
  508. - allow
  509. - deny
  510. type: string
  511. windows:
  512. description: Windows is the list of schedule+duration pairs.
  513. items:
  514. description: |-
  515. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  516. within a SyncWindows block.
  517. properties:
  518. duration:
  519. description: |-
  520. Duration specifies how long the window stays open after each Schedule
  521. firing. Example: "8h".
  522. type: string
  523. schedule:
  524. description: |-
  525. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  526. named shorthand such as @daily or @every 1h. It marks the start time of
  527. each window occurrence.
  528. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  529. minLength: 1
  530. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  531. type: string
  532. required:
  533. - duration
  534. - schedule
  535. type: object
  536. minItems: 1
  537. type: array
  538. required:
  539. - kind
  540. - windows
  541. type: object
  542. target:
  543. default:
  544. creationPolicy: Owner
  545. deletionPolicy: Retain
  546. description: |-
  547. ExternalSecretTarget defines the Kubernetes Secret to be created,
  548. there can be only one target per ExternalSecret.
  549. properties:
  550. creationPolicy:
  551. default: Owner
  552. description: |-
  553. CreationPolicy defines rules on how to create the resulting Secret.
  554. Defaults to "Owner"
  555. enum:
  556. - Owner
  557. - Orphan
  558. - Merge
  559. - None
  560. - CreateOrMerge
  561. type: string
  562. deletionPolicy:
  563. default: Retain
  564. description: |-
  565. DeletionPolicy defines rules on how to delete the resulting Secret.
  566. Defaults to "Retain"
  567. enum:
  568. - Delete
  569. - Merge
  570. - Retain
  571. type: string
  572. immutable:
  573. description: Immutable defines if the final secret will be immutable
  574. type: boolean
  575. manifest:
  576. description: |-
  577. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  578. When specified, ExternalSecret will create the resource type defined here
  579. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  580. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  581. properties:
  582. apiVersion:
  583. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  584. minLength: 1
  585. type: string
  586. kind:
  587. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  588. minLength: 1
  589. type: string
  590. required:
  591. - apiVersion
  592. - kind
  593. type: object
  594. name:
  595. description: |-
  596. The name of the Secret resource to be managed.
  597. Defaults to the .metadata.name of the ExternalSecret resource
  598. maxLength: 253
  599. minLength: 1
  600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  601. type: string
  602. template:
  603. description: Template defines a blueprint for the created Secret resource.
  604. properties:
  605. data:
  606. additionalProperties:
  607. type: string
  608. type: object
  609. engineVersion:
  610. default: v2
  611. description: |-
  612. EngineVersion specifies the template engine version
  613. that should be used to compile/execute the
  614. template specified in .data and .templateFrom[].
  615. enum:
  616. - v2
  617. type: string
  618. mergePolicy:
  619. default: Replace
  620. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  621. enum:
  622. - Replace
  623. - Merge
  624. type: string
  625. metadata:
  626. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  627. properties:
  628. annotations:
  629. additionalProperties:
  630. type: string
  631. type: object
  632. finalizers:
  633. items:
  634. type: string
  635. type: array
  636. labels:
  637. additionalProperties:
  638. type: string
  639. type: object
  640. type: object
  641. templateFrom:
  642. items:
  643. description: |-
  644. TemplateFrom specifies a source for templates.
  645. Each item in the list can either reference a ConfigMap or a Secret resource.
  646. properties:
  647. configMap:
  648. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  649. properties:
  650. items:
  651. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  652. items:
  653. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  654. properties:
  655. key:
  656. description: A key in the ConfigMap/Secret
  657. maxLength: 253
  658. minLength: 1
  659. pattern: ^[-._a-zA-Z0-9]+$
  660. type: string
  661. templateAs:
  662. default: Values
  663. description: TemplateScope specifies how the template keys should be interpreted.
  664. enum:
  665. - Values
  666. - KeysAndValues
  667. type: string
  668. required:
  669. - key
  670. type: object
  671. type: array
  672. name:
  673. description: The name of the ConfigMap/Secret resource
  674. maxLength: 253
  675. minLength: 1
  676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  677. type: string
  678. required:
  679. - items
  680. - name
  681. type: object
  682. literal:
  683. type: string
  684. secret:
  685. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  686. properties:
  687. items:
  688. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  689. items:
  690. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  691. properties:
  692. key:
  693. description: A key in the ConfigMap/Secret
  694. maxLength: 253
  695. minLength: 1
  696. pattern: ^[-._a-zA-Z0-9]+$
  697. type: string
  698. templateAs:
  699. default: Values
  700. description: TemplateScope specifies how the template keys should be interpreted.
  701. enum:
  702. - Values
  703. - KeysAndValues
  704. type: string
  705. required:
  706. - key
  707. type: object
  708. type: array
  709. name:
  710. description: The name of the ConfigMap/Secret resource
  711. maxLength: 253
  712. minLength: 1
  713. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  714. type: string
  715. required:
  716. - items
  717. - name
  718. type: object
  719. target:
  720. default: Data
  721. description: |-
  722. Target specifies where to place the template result.
  723. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  724. any other value is rejected because it would allow writes to privileged Secret fields.
  725. For custom resources (when spec.target.manifest is set), this supports
  726. nested paths like "spec.database.config" or "data".
  727. type: string
  728. valuesDecodingStrategy:
  729. default: None
  730. description: Used to define a decoding Strategy for the rendered template values.
  731. enum:
  732. - Auto
  733. - Base64
  734. - Base64URL
  735. - None
  736. type: string
  737. type: object
  738. type: array
  739. type:
  740. type: string
  741. type: object
  742. type: object
  743. type: object
  744. namespaceSelector:
  745. description: |-
  746. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  747. Deprecated: Use NamespaceSelectors instead.
  748. properties:
  749. matchExpressions:
  750. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  751. items:
  752. description: |-
  753. A label selector requirement is a selector that contains values, a key, and an operator that
  754. relates the key and values.
  755. properties:
  756. key:
  757. description: key is the label key that the selector applies to.
  758. type: string
  759. operator:
  760. description: |-
  761. operator represents a key's relationship to a set of values.
  762. Valid operators are In, NotIn, Exists and DoesNotExist.
  763. type: string
  764. values:
  765. description: |-
  766. values is an array of string values. If the operator is In or NotIn,
  767. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  768. the values array must be empty. This array is replaced during a strategic
  769. merge patch.
  770. items:
  771. type: string
  772. type: array
  773. x-kubernetes-list-type: atomic
  774. required:
  775. - key
  776. - operator
  777. type: object
  778. type: array
  779. x-kubernetes-list-type: atomic
  780. matchLabels:
  781. additionalProperties:
  782. type: string
  783. description: |-
  784. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  785. map is equivalent to an element of matchExpressions, whose key field is "key", the
  786. operator is "In", and the values array contains only "value". The requirements are ANDed.
  787. type: object
  788. type: object
  789. x-kubernetes-map-type: atomic
  790. namespaceSelectors:
  791. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  792. items:
  793. description: |-
  794. A label selector is a label query over a set of resources. The result of matchLabels and
  795. matchExpressions are ANDed. An empty label selector matches all objects. A null
  796. label selector matches no objects.
  797. properties:
  798. matchExpressions:
  799. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  800. items:
  801. description: |-
  802. A label selector requirement is a selector that contains values, a key, and an operator that
  803. relates the key and values.
  804. properties:
  805. key:
  806. description: key is the label key that the selector applies to.
  807. type: string
  808. operator:
  809. description: |-
  810. operator represents a key's relationship to a set of values.
  811. Valid operators are In, NotIn, Exists and DoesNotExist.
  812. type: string
  813. values:
  814. description: |-
  815. values is an array of string values. If the operator is In or NotIn,
  816. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  817. the values array must be empty. This array is replaced during a strategic
  818. merge patch.
  819. items:
  820. type: string
  821. type: array
  822. x-kubernetes-list-type: atomic
  823. required:
  824. - key
  825. - operator
  826. type: object
  827. type: array
  828. x-kubernetes-list-type: atomic
  829. matchLabels:
  830. additionalProperties:
  831. type: string
  832. description: |-
  833. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  834. map is equivalent to an element of matchExpressions, whose key field is "key", the
  835. operator is "In", and the values array contains only "value". The requirements are ANDed.
  836. type: object
  837. type: object
  838. x-kubernetes-map-type: atomic
  839. type: array
  840. namespaces:
  841. description: |-
  842. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  843. Deprecated: Use NamespaceSelectors instead.
  844. items:
  845. maxLength: 63
  846. minLength: 1
  847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  848. type: string
  849. type: array
  850. refreshTime:
  851. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  852. type: string
  853. required:
  854. - externalSecretSpec
  855. type: object
  856. status:
  857. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  858. properties:
  859. conditions:
  860. items:
  861. description: ClusterExternalSecretStatusCondition defines the observed state of a ClusterExternalSecret resource.
  862. properties:
  863. message:
  864. type: string
  865. status:
  866. type: string
  867. type:
  868. description: ClusterExternalSecretConditionType defines a value type for ClusterExternalSecret conditions.
  869. type: string
  870. required:
  871. - status
  872. - type
  873. type: object
  874. type: array
  875. externalSecretName:
  876. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  877. type: string
  878. failedNamespaces:
  879. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  880. items:
  881. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  882. properties:
  883. namespace:
  884. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  885. type: string
  886. reason:
  887. description: Reason is why the ExternalSecret failed to apply to the namespace
  888. type: string
  889. required:
  890. - namespace
  891. type: object
  892. type: array
  893. provisionedNamespaces:
  894. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  895. items:
  896. type: string
  897. type: array
  898. type: object
  899. type: object
  900. served: true
  901. storage: true
  902. subresources:
  903. status: {}
  904. - additionalPrinterColumns:
  905. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  906. name: Store
  907. type: string
  908. - jsonPath: .spec.refreshTime
  909. name: Refresh Interval
  910. type: string
  911. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  912. name: Ready
  913. type: string
  914. deprecated: true
  915. name: v1beta1
  916. schema:
  917. openAPIV3Schema:
  918. description: ClusterExternalSecret is the schema for the clusterexternalsecrets API.
  919. properties:
  920. apiVersion:
  921. description: |-
  922. APIVersion defines the versioned schema of this representation of an object.
  923. Servers should convert recognized schemas to the latest internal value, and
  924. may reject unrecognized values.
  925. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  926. type: string
  927. kind:
  928. description: |-
  929. Kind is a string value representing the REST resource this object represents.
  930. Servers may infer this from the endpoint the client submits requests to.
  931. Cannot be updated.
  932. In CamelCase.
  933. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  934. type: string
  935. metadata:
  936. type: object
  937. spec:
  938. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  939. properties:
  940. externalSecretMetadata:
  941. description: The metadata of the external secrets to be created
  942. properties:
  943. annotations:
  944. additionalProperties:
  945. type: string
  946. type: object
  947. labels:
  948. additionalProperties:
  949. type: string
  950. type: object
  951. type: object
  952. externalSecretName:
  953. description: |-
  954. The name of the external secrets to be created.
  955. Defaults to the name of the ClusterExternalSecret
  956. maxLength: 253
  957. minLength: 1
  958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  959. type: string
  960. externalSecretSpec:
  961. description: The spec for the ExternalSecrets to be created
  962. properties:
  963. data:
  964. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  965. items:
  966. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  967. properties:
  968. remoteRef:
  969. description: |-
  970. RemoteRef points to the remote secret and defines
  971. which secret (version/property/..) to fetch.
  972. properties:
  973. conversionStrategy:
  974. default: Default
  975. description: Used to define a conversion Strategy
  976. enum:
  977. - Default
  978. - Unicode
  979. type: string
  980. decodingStrategy:
  981. default: None
  982. description: Used to define a decoding Strategy
  983. enum:
  984. - Auto
  985. - Base64
  986. - Base64URL
  987. - None
  988. type: string
  989. key:
  990. description: Key is the key used in the Provider, mandatory
  991. type: string
  992. metadataPolicy:
  993. default: None
  994. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  995. enum:
  996. - None
  997. - Fetch
  998. type: string
  999. property:
  1000. description: Used to select a specific property of the Provider value (if a map), if supported
  1001. type: string
  1002. version:
  1003. description: Used to select a specific version of the Provider value, if supported
  1004. type: string
  1005. required:
  1006. - key
  1007. type: object
  1008. secretKey:
  1009. description: The key in the Kubernetes Secret to store the value.
  1010. maxLength: 253
  1011. minLength: 1
  1012. pattern: ^[-._a-zA-Z0-9]+$
  1013. type: string
  1014. sourceRef:
  1015. description: |-
  1016. SourceRef allows you to override the source
  1017. from which the value will be pulled.
  1018. maxProperties: 1
  1019. minProperties: 1
  1020. properties:
  1021. generatorRef:
  1022. description: |-
  1023. GeneratorRef points to a generator custom resource.
  1024. Deprecated: The generatorRef is not implemented in .data[].
  1025. this will be removed with v1.
  1026. properties:
  1027. apiVersion:
  1028. default: generators.external-secrets.io/v1alpha1
  1029. description: Specify the apiVersion of the generator resource
  1030. type: string
  1031. kind:
  1032. description: Specify the Kind of the generator resource
  1033. enum:
  1034. - ACRAccessToken
  1035. - ClusterGenerator
  1036. - ECRAuthorizationToken
  1037. - Fake
  1038. - GCRAccessToken
  1039. - GithubAccessToken
  1040. - QuayAccessToken
  1041. - Password
  1042. - SSHKey
  1043. - STSSessionToken
  1044. - UUID
  1045. - VaultDynamicSecret
  1046. - Webhook
  1047. - Grafana
  1048. type: string
  1049. name:
  1050. description: Specify the name of the generator resource
  1051. maxLength: 253
  1052. minLength: 1
  1053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1054. type: string
  1055. required:
  1056. - kind
  1057. - name
  1058. type: object
  1059. storeRef:
  1060. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1061. properties:
  1062. kind:
  1063. description: |-
  1064. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1065. Defaults to `SecretStore`
  1066. enum:
  1067. - SecretStore
  1068. - ClusterSecretStore
  1069. type: string
  1070. name:
  1071. description: Name of the SecretStore resource
  1072. maxLength: 253
  1073. minLength: 1
  1074. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1075. type: string
  1076. type: object
  1077. type: object
  1078. required:
  1079. - remoteRef
  1080. - secretKey
  1081. type: object
  1082. type: array
  1083. dataFrom:
  1084. description: |-
  1085. DataFrom is used to fetch all properties from a specific Provider data
  1086. If multiple entries are specified, the Secret keys are merged in the specified order
  1087. items:
  1088. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  1089. properties:
  1090. extract:
  1091. description: |-
  1092. Used to extract multiple key/value pairs from one secret
  1093. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1094. properties:
  1095. conversionStrategy:
  1096. default: Default
  1097. description: Used to define a conversion Strategy
  1098. enum:
  1099. - Default
  1100. - Unicode
  1101. type: string
  1102. decodingStrategy:
  1103. default: None
  1104. description: Used to define a decoding Strategy
  1105. enum:
  1106. - Auto
  1107. - Base64
  1108. - Base64URL
  1109. - None
  1110. type: string
  1111. key:
  1112. description: Key is the key used in the Provider, mandatory
  1113. type: string
  1114. metadataPolicy:
  1115. default: None
  1116. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  1117. enum:
  1118. - None
  1119. - Fetch
  1120. type: string
  1121. property:
  1122. description: Used to select a specific property of the Provider value (if a map), if supported
  1123. type: string
  1124. version:
  1125. description: Used to select a specific version of the Provider value, if supported
  1126. type: string
  1127. required:
  1128. - key
  1129. type: object
  1130. find:
  1131. description: |-
  1132. Used to find secrets based on tags or regular expressions
  1133. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  1134. properties:
  1135. conversionStrategy:
  1136. default: Default
  1137. description: Used to define a conversion Strategy
  1138. enum:
  1139. - Default
  1140. - Unicode
  1141. type: string
  1142. decodingStrategy:
  1143. default: None
  1144. description: Used to define a decoding Strategy
  1145. enum:
  1146. - Auto
  1147. - Base64
  1148. - Base64URL
  1149. - None
  1150. type: string
  1151. name:
  1152. description: Finds secrets based on the name.
  1153. properties:
  1154. regexp:
  1155. description: Finds secrets base
  1156. type: string
  1157. type: object
  1158. path:
  1159. description: A root path to start the find operations.
  1160. type: string
  1161. tags:
  1162. additionalProperties:
  1163. type: string
  1164. description: Find secrets based on tags.
  1165. type: object
  1166. type: object
  1167. rewrite:
  1168. description: |-
  1169. Used to rewrite secret Keys after getting them from the secret Provider
  1170. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  1171. items:
  1172. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  1173. maxProperties: 1
  1174. minProperties: 1
  1175. properties:
  1176. regexp:
  1177. description: |-
  1178. Used to rewrite with regular expressions.
  1179. The resulting key will be the output of a regexp.ReplaceAll operation.
  1180. properties:
  1181. source:
  1182. description: Used to define the regular expression of a re.Compiler.
  1183. type: string
  1184. target:
  1185. description: Used to define the target pattern of a ReplaceAll operation.
  1186. type: string
  1187. required:
  1188. - source
  1189. - target
  1190. type: object
  1191. transform:
  1192. description: |-
  1193. Used to apply string transformation on the secrets.
  1194. The resulting key will be the output of the template applied by the operation.
  1195. properties:
  1196. template:
  1197. description: |-
  1198. Used to define the template to apply on the secret name.
  1199. `.value ` will specify the secret name in the template.
  1200. type: string
  1201. required:
  1202. - template
  1203. type: object
  1204. type: object
  1205. type: array
  1206. sourceRef:
  1207. description: |-
  1208. SourceRef points to a store or generator
  1209. which contains secret values ready to use.
  1210. Use this in combination with Extract or Find pull values out of
  1211. a specific SecretStore.
  1212. When sourceRef points to a generator Extract or Find is not supported.
  1213. The generator returns a static map of values
  1214. maxProperties: 1
  1215. minProperties: 1
  1216. properties:
  1217. generatorRef:
  1218. description: GeneratorRef points to a generator custom resource.
  1219. properties:
  1220. apiVersion:
  1221. default: generators.external-secrets.io/v1alpha1
  1222. description: Specify the apiVersion of the generator resource
  1223. type: string
  1224. kind:
  1225. description: Specify the Kind of the generator resource
  1226. enum:
  1227. - ACRAccessToken
  1228. - ClusterGenerator
  1229. - ECRAuthorizationToken
  1230. - Fake
  1231. - GCRAccessToken
  1232. - GithubAccessToken
  1233. - QuayAccessToken
  1234. - Password
  1235. - SSHKey
  1236. - STSSessionToken
  1237. - UUID
  1238. - VaultDynamicSecret
  1239. - Webhook
  1240. - Grafana
  1241. type: string
  1242. name:
  1243. description: Specify the name of the generator resource
  1244. maxLength: 253
  1245. minLength: 1
  1246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1247. type: string
  1248. required:
  1249. - kind
  1250. - name
  1251. type: object
  1252. storeRef:
  1253. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1254. properties:
  1255. kind:
  1256. description: |-
  1257. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1258. Defaults to `SecretStore`
  1259. enum:
  1260. - SecretStore
  1261. - ClusterSecretStore
  1262. type: string
  1263. name:
  1264. description: Name of the SecretStore resource
  1265. maxLength: 253
  1266. minLength: 1
  1267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1268. type: string
  1269. type: object
  1270. type: object
  1271. type: object
  1272. type: array
  1273. refreshInterval:
  1274. default: 1h0m0s
  1275. description: |-
  1276. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  1277. specified as Golang Duration strings.
  1278. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  1279. Example values: "1h0m0s", "2h30m0s", "10m0s"
  1280. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  1281. type: string
  1282. refreshPolicy:
  1283. description: |-
  1284. RefreshPolicy determines how the ExternalSecret should be refreshed:
  1285. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  1286. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  1287. No periodic updates occur if refreshInterval is 0.
  1288. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  1289. enum:
  1290. - CreatedOnce
  1291. - Periodic
  1292. - OnChange
  1293. type: string
  1294. secretStoreRef:
  1295. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  1296. properties:
  1297. kind:
  1298. description: |-
  1299. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1300. Defaults to `SecretStore`
  1301. enum:
  1302. - SecretStore
  1303. - ClusterSecretStore
  1304. type: string
  1305. name:
  1306. description: Name of the SecretStore resource
  1307. maxLength: 253
  1308. minLength: 1
  1309. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1310. type: string
  1311. type: object
  1312. target:
  1313. default:
  1314. creationPolicy: Owner
  1315. deletionPolicy: Retain
  1316. description: |-
  1317. ExternalSecretTarget defines the Kubernetes Secret to be created
  1318. There can be only one target per ExternalSecret.
  1319. properties:
  1320. creationPolicy:
  1321. default: Owner
  1322. description: |-
  1323. CreationPolicy defines rules on how to create the resulting Secret.
  1324. Defaults to "Owner"
  1325. enum:
  1326. - Owner
  1327. - Orphan
  1328. - Merge
  1329. - None
  1330. type: string
  1331. deletionPolicy:
  1332. default: Retain
  1333. description: |-
  1334. DeletionPolicy defines rules on how to delete the resulting Secret.
  1335. Defaults to "Retain"
  1336. enum:
  1337. - Delete
  1338. - Merge
  1339. - Retain
  1340. type: string
  1341. immutable:
  1342. description: Immutable defines if the final secret will be immutable
  1343. type: boolean
  1344. name:
  1345. description: |-
  1346. The name of the Secret resource to be managed.
  1347. Defaults to the .metadata.name of the ExternalSecret resource
  1348. maxLength: 253
  1349. minLength: 1
  1350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1351. type: string
  1352. template:
  1353. description: Template defines a blueprint for the created Secret resource.
  1354. properties:
  1355. data:
  1356. additionalProperties:
  1357. type: string
  1358. type: object
  1359. engineVersion:
  1360. default: v2
  1361. description: |-
  1362. EngineVersion specifies the template engine version
  1363. that should be used to compile/execute the
  1364. template specified in .data and .templateFrom[].
  1365. enum:
  1366. - v2
  1367. type: string
  1368. mergePolicy:
  1369. default: Replace
  1370. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  1371. enum:
  1372. - Replace
  1373. - Merge
  1374. type: string
  1375. metadata:
  1376. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  1377. properties:
  1378. annotations:
  1379. additionalProperties:
  1380. type: string
  1381. type: object
  1382. labels:
  1383. additionalProperties:
  1384. type: string
  1385. type: object
  1386. type: object
  1387. templateFrom:
  1388. items:
  1389. description: TemplateFrom defines a source for template data.
  1390. properties:
  1391. configMap:
  1392. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1393. properties:
  1394. items:
  1395. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1396. items:
  1397. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1398. properties:
  1399. key:
  1400. description: A key in the ConfigMap/Secret
  1401. maxLength: 253
  1402. minLength: 1
  1403. pattern: ^[-._a-zA-Z0-9]+$
  1404. type: string
  1405. templateAs:
  1406. default: Values
  1407. description: TemplateScope defines the scope of the template when processing template data.
  1408. enum:
  1409. - Values
  1410. - KeysAndValues
  1411. type: string
  1412. required:
  1413. - key
  1414. type: object
  1415. type: array
  1416. name:
  1417. description: The name of the ConfigMap/Secret resource
  1418. maxLength: 253
  1419. minLength: 1
  1420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1421. type: string
  1422. required:
  1423. - items
  1424. - name
  1425. type: object
  1426. literal:
  1427. type: string
  1428. secret:
  1429. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  1430. properties:
  1431. items:
  1432. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  1433. items:
  1434. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  1435. properties:
  1436. key:
  1437. description: A key in the ConfigMap/Secret
  1438. maxLength: 253
  1439. minLength: 1
  1440. pattern: ^[-._a-zA-Z0-9]+$
  1441. type: string
  1442. templateAs:
  1443. default: Values
  1444. description: TemplateScope defines the scope of the template when processing template data.
  1445. enum:
  1446. - Values
  1447. - KeysAndValues
  1448. type: string
  1449. required:
  1450. - key
  1451. type: object
  1452. type: array
  1453. name:
  1454. description: The name of the ConfigMap/Secret resource
  1455. maxLength: 253
  1456. minLength: 1
  1457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1458. type: string
  1459. required:
  1460. - items
  1461. - name
  1462. type: object
  1463. target:
  1464. default: Data
  1465. description: TemplateTarget defines the target field where the template result will be stored.
  1466. enum:
  1467. - Data
  1468. - Annotations
  1469. - Labels
  1470. type: string
  1471. type: object
  1472. type: array
  1473. type:
  1474. type: string
  1475. type: object
  1476. type: object
  1477. type: object
  1478. namespaceSelector:
  1479. description: The labels to select by to find the Namespaces to create the ExternalSecrets in
  1480. properties:
  1481. matchExpressions:
  1482. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1483. items:
  1484. description: |-
  1485. A label selector requirement is a selector that contains values, a key, and an operator that
  1486. relates the key and values.
  1487. properties:
  1488. key:
  1489. description: key is the label key that the selector applies to.
  1490. type: string
  1491. operator:
  1492. description: |-
  1493. operator represents a key's relationship to a set of values.
  1494. Valid operators are In, NotIn, Exists and DoesNotExist.
  1495. type: string
  1496. values:
  1497. description: |-
  1498. values is an array of string values. If the operator is In or NotIn,
  1499. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1500. the values array must be empty. This array is replaced during a strategic
  1501. merge patch.
  1502. items:
  1503. type: string
  1504. type: array
  1505. x-kubernetes-list-type: atomic
  1506. required:
  1507. - key
  1508. - operator
  1509. type: object
  1510. type: array
  1511. x-kubernetes-list-type: atomic
  1512. matchLabels:
  1513. additionalProperties:
  1514. type: string
  1515. description: |-
  1516. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1517. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1518. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1519. type: object
  1520. type: object
  1521. x-kubernetes-map-type: atomic
  1522. namespaceSelectors:
  1523. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1524. items:
  1525. description: |-
  1526. A label selector is a label query over a set of resources. The result of matchLabels and
  1527. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1528. label selector matches no objects.
  1529. properties:
  1530. matchExpressions:
  1531. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1532. items:
  1533. description: |-
  1534. A label selector requirement is a selector that contains values, a key, and an operator that
  1535. relates the key and values.
  1536. properties:
  1537. key:
  1538. description: key is the label key that the selector applies to.
  1539. type: string
  1540. operator:
  1541. description: |-
  1542. operator represents a key's relationship to a set of values.
  1543. Valid operators are In, NotIn, Exists and DoesNotExist.
  1544. type: string
  1545. values:
  1546. description: |-
  1547. values is an array of string values. If the operator is In or NotIn,
  1548. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1549. the values array must be empty. This array is replaced during a strategic
  1550. merge patch.
  1551. items:
  1552. type: string
  1553. type: array
  1554. x-kubernetes-list-type: atomic
  1555. required:
  1556. - key
  1557. - operator
  1558. type: object
  1559. type: array
  1560. x-kubernetes-list-type: atomic
  1561. matchLabels:
  1562. additionalProperties:
  1563. type: string
  1564. description: |-
  1565. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1566. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1567. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1568. type: object
  1569. type: object
  1570. x-kubernetes-map-type: atomic
  1571. type: array
  1572. namespaces:
  1573. description: |-
  1574. Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  1575. Deprecated: Use NamespaceSelectors instead.
  1576. items:
  1577. maxLength: 63
  1578. minLength: 1
  1579. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1580. type: string
  1581. type: array
  1582. refreshTime:
  1583. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  1584. type: string
  1585. required:
  1586. - externalSecretSpec
  1587. type: object
  1588. status:
  1589. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  1590. properties:
  1591. conditions:
  1592. items:
  1593. description: ClusterExternalSecretStatusCondition indicates the status of the ClusterExternalSecret.
  1594. properties:
  1595. message:
  1596. type: string
  1597. status:
  1598. type: string
  1599. type:
  1600. description: ClusterExternalSecretConditionType indicates the condition of the ClusterExternalSecret.
  1601. type: string
  1602. required:
  1603. - status
  1604. - type
  1605. type: object
  1606. type: array
  1607. externalSecretName:
  1608. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  1609. type: string
  1610. failedNamespaces:
  1611. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  1612. items:
  1613. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  1614. properties:
  1615. namespace:
  1616. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  1617. type: string
  1618. reason:
  1619. description: Reason is why the ExternalSecret failed to apply to the namespace
  1620. type: string
  1621. required:
  1622. - namespace
  1623. type: object
  1624. type: array
  1625. provisionedNamespaces:
  1626. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  1627. items:
  1628. type: string
  1629. type: array
  1630. type: object
  1631. type: object
  1632. served: false
  1633. storage: false
  1634. subresources:
  1635. status: {}
  1636. ---
  1637. apiVersion: apiextensions.k8s.io/v1
  1638. kind: CustomResourceDefinition
  1639. metadata:
  1640. annotations:
  1641. controller-gen.kubebuilder.io/version: v0.19.0
  1642. labels:
  1643. external-secrets.io/component: controller
  1644. name: clusterpushsecrets.external-secrets.io
  1645. spec:
  1646. group: external-secrets.io
  1647. names:
  1648. categories:
  1649. - external-secrets
  1650. kind: ClusterPushSecret
  1651. listKind: ClusterPushSecretList
  1652. plural: clusterpushsecrets
  1653. singular: clusterpushsecret
  1654. scope: Cluster
  1655. versions:
  1656. - additionalPrinterColumns:
  1657. - jsonPath: .metadata.creationTimestamp
  1658. name: AGE
  1659. type: date
  1660. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  1661. name: Status
  1662. type: string
  1663. name: v1alpha1
  1664. schema:
  1665. openAPIV3Schema:
  1666. description: ClusterPushSecret is the Schema for the ClusterPushSecrets API that enables cluster-wide management of pushing Kubernetes secrets to external providers.
  1667. properties:
  1668. apiVersion:
  1669. description: |-
  1670. APIVersion defines the versioned schema of this representation of an object.
  1671. Servers should convert recognized schemas to the latest internal value, and
  1672. may reject unrecognized values.
  1673. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  1674. type: string
  1675. kind:
  1676. description: |-
  1677. Kind is a string value representing the REST resource this object represents.
  1678. Servers may infer this from the endpoint the client submits requests to.
  1679. Cannot be updated.
  1680. In CamelCase.
  1681. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  1682. type: string
  1683. metadata:
  1684. type: object
  1685. spec:
  1686. description: ClusterPushSecretSpec defines the configuration for a ClusterPushSecret resource.
  1687. properties:
  1688. namespaceSelectors:
  1689. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  1690. items:
  1691. description: |-
  1692. A label selector is a label query over a set of resources. The result of matchLabels and
  1693. matchExpressions are ANDed. An empty label selector matches all objects. A null
  1694. label selector matches no objects.
  1695. properties:
  1696. matchExpressions:
  1697. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1698. items:
  1699. description: |-
  1700. A label selector requirement is a selector that contains values, a key, and an operator that
  1701. relates the key and values.
  1702. properties:
  1703. key:
  1704. description: key is the label key that the selector applies to.
  1705. type: string
  1706. operator:
  1707. description: |-
  1708. operator represents a key's relationship to a set of values.
  1709. Valid operators are In, NotIn, Exists and DoesNotExist.
  1710. type: string
  1711. values:
  1712. description: |-
  1713. values is an array of string values. If the operator is In or NotIn,
  1714. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1715. the values array must be empty. This array is replaced during a strategic
  1716. merge patch.
  1717. items:
  1718. type: string
  1719. type: array
  1720. x-kubernetes-list-type: atomic
  1721. required:
  1722. - key
  1723. - operator
  1724. type: object
  1725. type: array
  1726. x-kubernetes-list-type: atomic
  1727. matchLabels:
  1728. additionalProperties:
  1729. type: string
  1730. description: |-
  1731. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1732. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1733. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1734. type: object
  1735. type: object
  1736. x-kubernetes-map-type: atomic
  1737. type: array
  1738. pushSecretMetadata:
  1739. description: The metadata of the external secrets to be created
  1740. properties:
  1741. annotations:
  1742. additionalProperties:
  1743. type: string
  1744. type: object
  1745. labels:
  1746. additionalProperties:
  1747. type: string
  1748. type: object
  1749. type: object
  1750. pushSecretName:
  1751. description: |-
  1752. The name of the push secrets to be created.
  1753. Defaults to the name of the ClusterPushSecret
  1754. maxLength: 253
  1755. minLength: 1
  1756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1757. type: string
  1758. pushSecretSpec:
  1759. description: PushSecretSpec defines what to do with the secrets.
  1760. properties:
  1761. data:
  1762. description: Secret Data that should be pushed to providers
  1763. items:
  1764. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  1765. properties:
  1766. conversionStrategy:
  1767. default: None
  1768. description: Used to define a conversion Strategy for the secret keys
  1769. enum:
  1770. - None
  1771. - ReverseUnicode
  1772. type: string
  1773. match:
  1774. description: Match a given Secret Key to be pushed to the provider.
  1775. properties:
  1776. remoteRef:
  1777. description: Remote Refs to push to providers.
  1778. properties:
  1779. property:
  1780. description: Name of the property in the resulting secret
  1781. type: string
  1782. remoteKey:
  1783. description: Name of the resulting provider secret.
  1784. type: string
  1785. required:
  1786. - remoteKey
  1787. type: object
  1788. secretKey:
  1789. description: Secret Key to be pushed
  1790. type: string
  1791. required:
  1792. - remoteRef
  1793. type: object
  1794. metadata:
  1795. description: |-
  1796. Metadata is metadata attached to the secret.
  1797. The structure of metadata is provider specific, please look it up in the provider documentation.
  1798. x-kubernetes-preserve-unknown-fields: true
  1799. required:
  1800. - match
  1801. type: object
  1802. type: array
  1803. dataTo:
  1804. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  1805. items:
  1806. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  1807. properties:
  1808. conversionStrategy:
  1809. default: None
  1810. description: Used to define a conversion Strategy for the secret keys
  1811. enum:
  1812. - None
  1813. - ReverseUnicode
  1814. type: string
  1815. match:
  1816. description: |-
  1817. Match pattern for selecting keys from the source Secret.
  1818. If not specified, all keys are selected.
  1819. properties:
  1820. regexp:
  1821. description: |-
  1822. Regexp matches keys by regular expression.
  1823. If not specified, all keys are matched.
  1824. type: string
  1825. type: object
  1826. metadata:
  1827. description: |-
  1828. Metadata is metadata attached to the secret.
  1829. The structure of metadata is provider specific, please look it up in the provider documentation.
  1830. x-kubernetes-preserve-unknown-fields: true
  1831. remoteKey:
  1832. description: |-
  1833. RemoteKey is the name of the single provider secret that will receive ALL
  1834. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  1835. When set, per-key expansion is skipped and a single push is performed.
  1836. The provider's store prefix (if any) is still prepended to this value.
  1837. When not set, each matched key is pushed as its own individual provider secret.
  1838. type: string
  1839. rewrite:
  1840. description: |-
  1841. Rewrite operations to transform keys before pushing to the provider.
  1842. Operations are applied sequentially.
  1843. items:
  1844. description: PushSecretRewrite defines how to transform secret keys before pushing.
  1845. properties:
  1846. regexp:
  1847. description: Used to rewrite with regular expressions.
  1848. properties:
  1849. source:
  1850. description: Used to define the regular expression of a re.Compiler.
  1851. type: string
  1852. target:
  1853. description: Used to define the target pattern of a ReplaceAll operation.
  1854. type: string
  1855. required:
  1856. - source
  1857. - target
  1858. type: object
  1859. transform:
  1860. description: Used to apply string transformation on the secrets.
  1861. properties:
  1862. template:
  1863. description: |-
  1864. Used to define the template to apply on the secret name.
  1865. `.value ` will specify the secret name in the template.
  1866. type: string
  1867. required:
  1868. - template
  1869. type: object
  1870. type: object
  1871. x-kubernetes-validations:
  1872. - message: exactly one of regexp or transform must be set
  1873. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  1874. type: array
  1875. storeRef:
  1876. description: StoreRef specifies which SecretStore to push to. Required.
  1877. properties:
  1878. kind:
  1879. default: SecretStore
  1880. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1881. enum:
  1882. - SecretStore
  1883. - ClusterSecretStore
  1884. type: string
  1885. labelSelector:
  1886. description: Optionally, sync to secret stores with label selector
  1887. properties:
  1888. matchExpressions:
  1889. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1890. items:
  1891. description: |-
  1892. A label selector requirement is a selector that contains values, a key, and an operator that
  1893. relates the key and values.
  1894. properties:
  1895. key:
  1896. description: key is the label key that the selector applies to.
  1897. type: string
  1898. operator:
  1899. description: |-
  1900. operator represents a key's relationship to a set of values.
  1901. Valid operators are In, NotIn, Exists and DoesNotExist.
  1902. type: string
  1903. values:
  1904. description: |-
  1905. values is an array of string values. If the operator is In or NotIn,
  1906. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1907. the values array must be empty. This array is replaced during a strategic
  1908. merge patch.
  1909. items:
  1910. type: string
  1911. type: array
  1912. x-kubernetes-list-type: atomic
  1913. required:
  1914. - key
  1915. - operator
  1916. type: object
  1917. type: array
  1918. x-kubernetes-list-type: atomic
  1919. matchLabels:
  1920. additionalProperties:
  1921. type: string
  1922. description: |-
  1923. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  1924. map is equivalent to an element of matchExpressions, whose key field is "key", the
  1925. operator is "In", and the values array contains only "value". The requirements are ANDed.
  1926. type: object
  1927. type: object
  1928. x-kubernetes-map-type: atomic
  1929. name:
  1930. description: Optionally, sync to the SecretStore of the given name
  1931. maxLength: 253
  1932. minLength: 1
  1933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1934. type: string
  1935. type: object
  1936. type: object
  1937. x-kubernetes-validations:
  1938. - message: storeRef must specify either name or labelSelector
  1939. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  1940. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  1941. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  1942. type: array
  1943. deletionPolicy:
  1944. default: None
  1945. description: Deletion Policy to handle Secrets in the provider.
  1946. enum:
  1947. - Delete
  1948. - None
  1949. type: string
  1950. refreshInterval:
  1951. default: 1h0m0s
  1952. description: The Interval to which External Secrets will try to push a secret definition
  1953. type: string
  1954. secretStoreRefs:
  1955. items:
  1956. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  1957. properties:
  1958. kind:
  1959. default: SecretStore
  1960. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  1961. enum:
  1962. - SecretStore
  1963. - ClusterSecretStore
  1964. type: string
  1965. labelSelector:
  1966. description: Optionally, sync to secret stores with label selector
  1967. properties:
  1968. matchExpressions:
  1969. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  1970. items:
  1971. description: |-
  1972. A label selector requirement is a selector that contains values, a key, and an operator that
  1973. relates the key and values.
  1974. properties:
  1975. key:
  1976. description: key is the label key that the selector applies to.
  1977. type: string
  1978. operator:
  1979. description: |-
  1980. operator represents a key's relationship to a set of values.
  1981. Valid operators are In, NotIn, Exists and DoesNotExist.
  1982. type: string
  1983. values:
  1984. description: |-
  1985. values is an array of string values. If the operator is In or NotIn,
  1986. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  1987. the values array must be empty. This array is replaced during a strategic
  1988. merge patch.
  1989. items:
  1990. type: string
  1991. type: array
  1992. x-kubernetes-list-type: atomic
  1993. required:
  1994. - key
  1995. - operator
  1996. type: object
  1997. type: array
  1998. x-kubernetes-list-type: atomic
  1999. matchLabels:
  2000. additionalProperties:
  2001. type: string
  2002. description: |-
  2003. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2004. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2005. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2006. type: object
  2007. type: object
  2008. x-kubernetes-map-type: atomic
  2009. name:
  2010. description: Optionally, sync to the SecretStore of the given name
  2011. maxLength: 253
  2012. minLength: 1
  2013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2014. type: string
  2015. type: object
  2016. type: array
  2017. selector:
  2018. description: The Secret Selector (k8s source) for the Push Secret
  2019. maxProperties: 1
  2020. minProperties: 1
  2021. properties:
  2022. generatorRef:
  2023. description: Point to a generator to create a Secret.
  2024. properties:
  2025. apiVersion:
  2026. default: generators.external-secrets.io/v1alpha1
  2027. description: Specify the apiVersion of the generator resource
  2028. type: string
  2029. kind:
  2030. description: Specify the Kind of the generator resource
  2031. enum:
  2032. - ACRAccessToken
  2033. - BeyondtrustWorkloadCredentialsDynamicSecret
  2034. - ClusterGenerator
  2035. - CloudsmithAccessToken
  2036. - ECRAuthorizationToken
  2037. - Fake
  2038. - GCRAccessToken
  2039. - GithubAccessToken
  2040. - GitlabDeployToken
  2041. - QuayAccessToken
  2042. - Password
  2043. - SSHKey
  2044. - STSSessionToken
  2045. - UUID
  2046. - VaultDynamicSecret
  2047. - Webhook
  2048. - Grafana
  2049. - MFA
  2050. type: string
  2051. name:
  2052. description: Specify the name of the generator resource
  2053. maxLength: 253
  2054. minLength: 1
  2055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2056. type: string
  2057. required:
  2058. - kind
  2059. - name
  2060. type: object
  2061. secret:
  2062. description: Select a Secret to Push.
  2063. properties:
  2064. name:
  2065. description: |-
  2066. Name of the Secret.
  2067. The Secret must exist in the same namespace as the PushSecret manifest.
  2068. maxLength: 253
  2069. minLength: 1
  2070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2071. type: string
  2072. selector:
  2073. description: Selector chooses secrets using a labelSelector.
  2074. properties:
  2075. matchExpressions:
  2076. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2077. items:
  2078. description: |-
  2079. A label selector requirement is a selector that contains values, a key, and an operator that
  2080. relates the key and values.
  2081. properties:
  2082. key:
  2083. description: key is the label key that the selector applies to.
  2084. type: string
  2085. operator:
  2086. description: |-
  2087. operator represents a key's relationship to a set of values.
  2088. Valid operators are In, NotIn, Exists and DoesNotExist.
  2089. type: string
  2090. values:
  2091. description: |-
  2092. values is an array of string values. If the operator is In or NotIn,
  2093. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2094. the values array must be empty. This array is replaced during a strategic
  2095. merge patch.
  2096. items:
  2097. type: string
  2098. type: array
  2099. x-kubernetes-list-type: atomic
  2100. required:
  2101. - key
  2102. - operator
  2103. type: object
  2104. type: array
  2105. x-kubernetes-list-type: atomic
  2106. matchLabels:
  2107. additionalProperties:
  2108. type: string
  2109. description: |-
  2110. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2111. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2112. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2113. type: object
  2114. type: object
  2115. x-kubernetes-map-type: atomic
  2116. type: object
  2117. type: object
  2118. template:
  2119. description: Template defines a blueprint for the created Secret resource.
  2120. properties:
  2121. data:
  2122. additionalProperties:
  2123. type: string
  2124. type: object
  2125. engineVersion:
  2126. default: v2
  2127. description: |-
  2128. EngineVersion specifies the template engine version
  2129. that should be used to compile/execute the
  2130. template specified in .data and .templateFrom[].
  2131. enum:
  2132. - v2
  2133. type: string
  2134. mergePolicy:
  2135. default: Replace
  2136. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  2137. enum:
  2138. - Replace
  2139. - Merge
  2140. type: string
  2141. metadata:
  2142. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  2143. properties:
  2144. annotations:
  2145. additionalProperties:
  2146. type: string
  2147. type: object
  2148. finalizers:
  2149. items:
  2150. type: string
  2151. type: array
  2152. labels:
  2153. additionalProperties:
  2154. type: string
  2155. type: object
  2156. type: object
  2157. templateFrom:
  2158. items:
  2159. description: |-
  2160. TemplateFrom specifies a source for templates.
  2161. Each item in the list can either reference a ConfigMap or a Secret resource.
  2162. properties:
  2163. configMap:
  2164. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2165. properties:
  2166. items:
  2167. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2168. items:
  2169. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2170. properties:
  2171. key:
  2172. description: A key in the ConfigMap/Secret
  2173. maxLength: 253
  2174. minLength: 1
  2175. pattern: ^[-._a-zA-Z0-9]+$
  2176. type: string
  2177. templateAs:
  2178. default: Values
  2179. description: TemplateScope specifies how the template keys should be interpreted.
  2180. enum:
  2181. - Values
  2182. - KeysAndValues
  2183. type: string
  2184. required:
  2185. - key
  2186. type: object
  2187. type: array
  2188. name:
  2189. description: The name of the ConfigMap/Secret resource
  2190. maxLength: 253
  2191. minLength: 1
  2192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2193. type: string
  2194. required:
  2195. - items
  2196. - name
  2197. type: object
  2198. literal:
  2199. type: string
  2200. secret:
  2201. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  2202. properties:
  2203. items:
  2204. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  2205. items:
  2206. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  2207. properties:
  2208. key:
  2209. description: A key in the ConfigMap/Secret
  2210. maxLength: 253
  2211. minLength: 1
  2212. pattern: ^[-._a-zA-Z0-9]+$
  2213. type: string
  2214. templateAs:
  2215. default: Values
  2216. description: TemplateScope specifies how the template keys should be interpreted.
  2217. enum:
  2218. - Values
  2219. - KeysAndValues
  2220. type: string
  2221. required:
  2222. - key
  2223. type: object
  2224. type: array
  2225. name:
  2226. description: The name of the ConfigMap/Secret resource
  2227. maxLength: 253
  2228. minLength: 1
  2229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2230. type: string
  2231. required:
  2232. - items
  2233. - name
  2234. type: object
  2235. target:
  2236. default: Data
  2237. description: |-
  2238. Target specifies where to place the template result.
  2239. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  2240. any other value is rejected because it would allow writes to privileged Secret fields.
  2241. For custom resources (when spec.target.manifest is set), this supports
  2242. nested paths like "spec.database.config" or "data".
  2243. type: string
  2244. valuesDecodingStrategy:
  2245. default: None
  2246. description: Used to define a decoding Strategy for the rendered template values.
  2247. enum:
  2248. - Auto
  2249. - Base64
  2250. - Base64URL
  2251. - None
  2252. type: string
  2253. type: object
  2254. type: array
  2255. type:
  2256. type: string
  2257. type: object
  2258. updatePolicy:
  2259. default: Replace
  2260. description: UpdatePolicy to handle Secrets in the provider.
  2261. enum:
  2262. - Replace
  2263. - IfNotExists
  2264. type: string
  2265. required:
  2266. - secretStoreRefs
  2267. - selector
  2268. type: object
  2269. refreshTime:
  2270. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  2271. type: string
  2272. required:
  2273. - pushSecretSpec
  2274. type: object
  2275. status:
  2276. description: ClusterPushSecretStatus contains the status information for the ClusterPushSecret resource.
  2277. properties:
  2278. conditions:
  2279. items:
  2280. description: PushSecretStatusCondition indicates the status of the PushSecret.
  2281. properties:
  2282. lastTransitionTime:
  2283. format: date-time
  2284. type: string
  2285. message:
  2286. type: string
  2287. reason:
  2288. type: string
  2289. status:
  2290. type: string
  2291. type:
  2292. description: PushSecretConditionType indicates the condition of the PushSecret.
  2293. type: string
  2294. required:
  2295. - status
  2296. - type
  2297. type: object
  2298. type: array
  2299. failedNamespaces:
  2300. description: Failed namespaces are the namespaces that failed to apply an PushSecret
  2301. items:
  2302. description: ClusterPushSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  2303. properties:
  2304. namespace:
  2305. description: Namespace is the namespace that failed when trying to apply an PushSecret
  2306. type: string
  2307. reason:
  2308. description: Reason is why the PushSecret failed to apply to the namespace
  2309. type: string
  2310. required:
  2311. - namespace
  2312. type: object
  2313. type: array
  2314. provisionedNamespaces:
  2315. description: ProvisionedNamespaces are the namespaces where the ClusterPushSecret has secrets
  2316. items:
  2317. type: string
  2318. type: array
  2319. pushSecretName:
  2320. type: string
  2321. type: object
  2322. type: object
  2323. served: true
  2324. storage: true
  2325. subresources:
  2326. status: {}
  2327. ---
  2328. apiVersion: apiextensions.k8s.io/v1
  2329. kind: CustomResourceDefinition
  2330. metadata:
  2331. annotations:
  2332. controller-gen.kubebuilder.io/version: v0.19.0
  2333. labels:
  2334. external-secrets.io/component: controller
  2335. name: clustersecretstores.external-secrets.io
  2336. spec:
  2337. group: external-secrets.io
  2338. names:
  2339. categories:
  2340. - external-secrets
  2341. kind: ClusterSecretStore
  2342. listKind: ClusterSecretStoreList
  2343. plural: clustersecretstores
  2344. shortNames:
  2345. - css
  2346. singular: clustersecretstore
  2347. scope: Cluster
  2348. versions:
  2349. - additionalPrinterColumns:
  2350. - jsonPath: .metadata.creationTimestamp
  2351. name: AGE
  2352. type: date
  2353. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2354. name: Status
  2355. type: string
  2356. - jsonPath: .status.capabilities
  2357. name: Capabilities
  2358. type: string
  2359. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2360. name: Ready
  2361. type: string
  2362. name: v1
  2363. schema:
  2364. openAPIV3Schema:
  2365. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2366. properties:
  2367. apiVersion:
  2368. description: |-
  2369. APIVersion defines the versioned schema of this representation of an object.
  2370. Servers should convert recognized schemas to the latest internal value, and
  2371. may reject unrecognized values.
  2372. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2373. type: string
  2374. kind:
  2375. description: |-
  2376. Kind is a string value representing the REST resource this object represents.
  2377. Servers may infer this from the endpoint the client submits requests to.
  2378. Cannot be updated.
  2379. In CamelCase.
  2380. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2381. type: string
  2382. metadata:
  2383. type: object
  2384. spec:
  2385. description: SecretStoreSpec defines the desired state of SecretStore.
  2386. properties:
  2387. conditions:
  2388. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  2389. items:
  2390. description: |-
  2391. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2392. for a ClusterSecretStore instance.
  2393. properties:
  2394. namespaceRegexes:
  2395. description: Choose namespaces by using regex matching
  2396. items:
  2397. type: string
  2398. type: array
  2399. namespaceSelector:
  2400. description: Choose namespace using a labelSelector
  2401. properties:
  2402. matchExpressions:
  2403. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2404. items:
  2405. description: |-
  2406. A label selector requirement is a selector that contains values, a key, and an operator that
  2407. relates the key and values.
  2408. properties:
  2409. key:
  2410. description: key is the label key that the selector applies to.
  2411. type: string
  2412. operator:
  2413. description: |-
  2414. operator represents a key's relationship to a set of values.
  2415. Valid operators are In, NotIn, Exists and DoesNotExist.
  2416. type: string
  2417. values:
  2418. description: |-
  2419. values is an array of string values. If the operator is In or NotIn,
  2420. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2421. the values array must be empty. This array is replaced during a strategic
  2422. merge patch.
  2423. items:
  2424. type: string
  2425. type: array
  2426. x-kubernetes-list-type: atomic
  2427. required:
  2428. - key
  2429. - operator
  2430. type: object
  2431. type: array
  2432. x-kubernetes-list-type: atomic
  2433. matchLabels:
  2434. additionalProperties:
  2435. type: string
  2436. description: |-
  2437. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2438. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2439. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2440. type: object
  2441. type: object
  2442. x-kubernetes-map-type: atomic
  2443. namespaces:
  2444. description: Choose namespaces by name
  2445. items:
  2446. maxLength: 63
  2447. minLength: 1
  2448. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2449. type: string
  2450. type: array
  2451. type: object
  2452. type: array
  2453. controller:
  2454. description: |-
  2455. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2456. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2457. type: string
  2458. provider:
  2459. description: Used to configure the provider. Only one provider may be set
  2460. maxProperties: 1
  2461. minProperties: 1
  2462. properties:
  2463. akeyless:
  2464. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2465. properties:
  2466. akeylessGWApiURL:
  2467. description: Akeyless GW API Url from which the secrets to be fetched from.
  2468. type: string
  2469. authSecretRef:
  2470. description: Auth configures how the operator authenticates with Akeyless.
  2471. properties:
  2472. kubernetesAuth:
  2473. description: |-
  2474. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2475. token stored in the named Secret resource.
  2476. properties:
  2477. accessID:
  2478. description: the Akeyless Kubernetes auth-method access-id
  2479. type: string
  2480. k8sConfName:
  2481. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2482. type: string
  2483. secretRef:
  2484. description: |-
  2485. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2486. for authenticating with Akeyless. If a name is specified without a key,
  2487. `token` is the default. If one is not specified, the one bound to
  2488. the controller will be used.
  2489. properties:
  2490. key:
  2491. description: |-
  2492. A key in the referenced Secret.
  2493. Some instances of this field may be defaulted, in others it may be required.
  2494. maxLength: 253
  2495. minLength: 1
  2496. pattern: ^[-._a-zA-Z0-9]+$
  2497. type: string
  2498. name:
  2499. description: The name of the Secret resource being referred to.
  2500. maxLength: 253
  2501. minLength: 1
  2502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2503. type: string
  2504. namespace:
  2505. description: |-
  2506. The namespace of the Secret resource being referred to.
  2507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2508. maxLength: 63
  2509. minLength: 1
  2510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2511. type: string
  2512. type: object
  2513. serviceAccountRef:
  2514. description: |-
  2515. Optional service account field containing the name of a kubernetes ServiceAccount.
  2516. If the service account is specified, the service account secret token JWT will be used
  2517. for authenticating with Akeyless. If the service account selector is not supplied,
  2518. the secretRef will be used instead.
  2519. properties:
  2520. audiences:
  2521. description: |-
  2522. Audience specifies the `aud` claim for the service account token
  2523. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2524. then this audiences will be appended to the list
  2525. items:
  2526. type: string
  2527. type: array
  2528. name:
  2529. description: The name of the ServiceAccount resource being referred to.
  2530. maxLength: 253
  2531. minLength: 1
  2532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2533. type: string
  2534. namespace:
  2535. description: |-
  2536. Namespace of the resource being referred to.
  2537. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2538. maxLength: 63
  2539. minLength: 1
  2540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2541. type: string
  2542. required:
  2543. - name
  2544. type: object
  2545. required:
  2546. - accessID
  2547. - k8sConfName
  2548. type: object
  2549. secretRef:
  2550. description: |-
  2551. Reference to a Secret that contains the details
  2552. to authenticate with Akeyless.
  2553. properties:
  2554. accessID:
  2555. description: The SecretAccessID is used for authentication
  2556. properties:
  2557. key:
  2558. description: |-
  2559. A key in the referenced Secret.
  2560. Some instances of this field may be defaulted, in others it may be required.
  2561. maxLength: 253
  2562. minLength: 1
  2563. pattern: ^[-._a-zA-Z0-9]+$
  2564. type: string
  2565. name:
  2566. description: The name of the Secret resource being referred to.
  2567. maxLength: 253
  2568. minLength: 1
  2569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2570. type: string
  2571. namespace:
  2572. description: |-
  2573. The namespace of the Secret resource being referred to.
  2574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2575. maxLength: 63
  2576. minLength: 1
  2577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2578. type: string
  2579. type: object
  2580. accessType:
  2581. description: |-
  2582. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2583. In some instances, `key` is a required field.
  2584. properties:
  2585. key:
  2586. description: |-
  2587. A key in the referenced Secret.
  2588. Some instances of this field may be defaulted, in others it may be required.
  2589. maxLength: 253
  2590. minLength: 1
  2591. pattern: ^[-._a-zA-Z0-9]+$
  2592. type: string
  2593. name:
  2594. description: The name of the Secret resource being referred to.
  2595. maxLength: 253
  2596. minLength: 1
  2597. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2598. type: string
  2599. namespace:
  2600. description: |-
  2601. The namespace of the Secret resource being referred to.
  2602. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2603. maxLength: 63
  2604. minLength: 1
  2605. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2606. type: string
  2607. type: object
  2608. accessTypeParam:
  2609. description: |-
  2610. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  2611. In some instances, `key` is a required field.
  2612. properties:
  2613. key:
  2614. description: |-
  2615. A key in the referenced Secret.
  2616. Some instances of this field may be defaulted, in others it may be required.
  2617. maxLength: 253
  2618. minLength: 1
  2619. pattern: ^[-._a-zA-Z0-9]+$
  2620. type: string
  2621. name:
  2622. description: The name of the Secret resource being referred to.
  2623. maxLength: 253
  2624. minLength: 1
  2625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2626. type: string
  2627. namespace:
  2628. description: |-
  2629. The namespace of the Secret resource being referred to.
  2630. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2631. maxLength: 63
  2632. minLength: 1
  2633. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2634. type: string
  2635. type: object
  2636. type: object
  2637. serviceAccountRef:
  2638. description: |-
  2639. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  2640. authentication on AKS Workload Identity. The operator obtains a federated
  2641. identity token from this ServiceAccount via the TokenRequest API instead
  2642. of using the ESO controller pod identity. Ignored for other access types.
  2643. properties:
  2644. audiences:
  2645. description: |-
  2646. Audience specifies the `aud` claim for the service account token
  2647. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2648. then this audiences will be appended to the list
  2649. items:
  2650. type: string
  2651. type: array
  2652. name:
  2653. description: The name of the ServiceAccount resource being referred to.
  2654. maxLength: 253
  2655. minLength: 1
  2656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2657. type: string
  2658. namespace:
  2659. description: |-
  2660. Namespace of the resource being referred to.
  2661. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2662. maxLength: 63
  2663. minLength: 1
  2664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2665. type: string
  2666. required:
  2667. - name
  2668. type: object
  2669. type: object
  2670. caBundle:
  2671. description: |-
  2672. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2673. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2674. are used to validate the TLS connection.
  2675. format: byte
  2676. type: string
  2677. caProvider:
  2678. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2679. properties:
  2680. key:
  2681. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2682. maxLength: 253
  2683. minLength: 1
  2684. pattern: ^[-._a-zA-Z0-9]+$
  2685. type: string
  2686. name:
  2687. description: The name of the object located at the provider type.
  2688. maxLength: 253
  2689. minLength: 1
  2690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2691. type: string
  2692. namespace:
  2693. description: |-
  2694. The namespace the Provider type is in.
  2695. Can only be defined when used in a ClusterSecretStore.
  2696. maxLength: 63
  2697. minLength: 1
  2698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2699. type: string
  2700. type:
  2701. description: The type of provider to use such as "Secret", or "ConfigMap".
  2702. enum:
  2703. - Secret
  2704. - ConfigMap
  2705. type: string
  2706. required:
  2707. - name
  2708. - type
  2709. type: object
  2710. ignoreCache:
  2711. description: |-
  2712. IgnoreCache bypasses the Gateway cache for secret reads when true.
  2713. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  2714. type: boolean
  2715. required:
  2716. - akeylessGWApiURL
  2717. - authSecretRef
  2718. type: object
  2719. aws:
  2720. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2721. properties:
  2722. additionalRoles:
  2723. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2724. items:
  2725. type: string
  2726. type: array
  2727. auth:
  2728. description: |-
  2729. Auth defines the information necessary to authenticate against AWS
  2730. if not set aws sdk will infer credentials from your environment
  2731. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2732. properties:
  2733. jwt:
  2734. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  2735. properties:
  2736. serviceAccountRef:
  2737. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  2738. properties:
  2739. audiences:
  2740. description: |-
  2741. Audience specifies the `aud` claim for the service account token
  2742. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2743. then this audiences will be appended to the list
  2744. items:
  2745. type: string
  2746. type: array
  2747. name:
  2748. description: The name of the ServiceAccount resource being referred to.
  2749. maxLength: 253
  2750. minLength: 1
  2751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2752. type: string
  2753. namespace:
  2754. description: |-
  2755. Namespace of the resource being referred to.
  2756. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2757. maxLength: 63
  2758. minLength: 1
  2759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2760. type: string
  2761. required:
  2762. - name
  2763. type: object
  2764. type: object
  2765. secretRef:
  2766. description: |-
  2767. AWSAuthSecretRef holds secret references for AWS credentials
  2768. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  2769. properties:
  2770. accessKeyIDSecretRef:
  2771. description: The AccessKeyID is used for authentication
  2772. properties:
  2773. key:
  2774. description: |-
  2775. A key in the referenced Secret.
  2776. Some instances of this field may be defaulted, in others it may be required.
  2777. maxLength: 253
  2778. minLength: 1
  2779. pattern: ^[-._a-zA-Z0-9]+$
  2780. type: string
  2781. name:
  2782. description: The name of the Secret resource being referred to.
  2783. maxLength: 253
  2784. minLength: 1
  2785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2786. type: string
  2787. namespace:
  2788. description: |-
  2789. The namespace of the Secret resource being referred to.
  2790. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2791. maxLength: 63
  2792. minLength: 1
  2793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2794. type: string
  2795. type: object
  2796. secretAccessKeySecretRef:
  2797. description: The SecretAccessKey is used for authentication
  2798. properties:
  2799. key:
  2800. description: |-
  2801. A key in the referenced Secret.
  2802. Some instances of this field may be defaulted, in others it may be required.
  2803. maxLength: 253
  2804. minLength: 1
  2805. pattern: ^[-._a-zA-Z0-9]+$
  2806. type: string
  2807. name:
  2808. description: The name of the Secret resource being referred to.
  2809. maxLength: 253
  2810. minLength: 1
  2811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2812. type: string
  2813. namespace:
  2814. description: |-
  2815. The namespace of the Secret resource being referred to.
  2816. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2817. maxLength: 63
  2818. minLength: 1
  2819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2820. type: string
  2821. type: object
  2822. sessionTokenSecretRef:
  2823. description: |-
  2824. The SessionToken used for authentication
  2825. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  2826. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  2827. properties:
  2828. key:
  2829. description: |-
  2830. A key in the referenced Secret.
  2831. Some instances of this field may be defaulted, in others it may be required.
  2832. maxLength: 253
  2833. minLength: 1
  2834. pattern: ^[-._a-zA-Z0-9]+$
  2835. type: string
  2836. name:
  2837. description: The name of the Secret resource being referred to.
  2838. maxLength: 253
  2839. minLength: 1
  2840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2841. type: string
  2842. namespace:
  2843. description: |-
  2844. The namespace of the Secret resource being referred to.
  2845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2846. maxLength: 63
  2847. minLength: 1
  2848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2849. type: string
  2850. type: object
  2851. type: object
  2852. type: object
  2853. customSessionTags:
  2854. additionalProperties:
  2855. type: string
  2856. description: |-
  2857. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  2858. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  2859. type: object
  2860. x-kubernetes-validations:
  2861. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  2862. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  2863. externalID:
  2864. description: AWS External ID set on assumed IAM roles
  2865. type: string
  2866. prefix:
  2867. description: Prefix adds a prefix to all retrieved values.
  2868. type: string
  2869. region:
  2870. description: AWS Region to be used for the provider
  2871. type: string
  2872. role:
  2873. description: Role is a Role ARN which the provider will assume
  2874. type: string
  2875. secretsManager:
  2876. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  2877. properties:
  2878. forceDeleteWithoutRecovery:
  2879. description: |-
  2880. Specifies whether to delete the secret without any recovery window. You
  2881. can't use both this parameter and RecoveryWindowInDays in the same call.
  2882. If you don't use either, then by default Secrets Manager uses a 30 day
  2883. recovery window.
  2884. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  2885. type: boolean
  2886. recoveryWindowInDays:
  2887. description: |-
  2888. The number of days from 7 to 30 that Secrets Manager waits before
  2889. permanently deleting the secret. You can't use both this parameter and
  2890. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  2891. then by default Secrets Manager uses a 30-day recovery window.
  2892. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  2893. format: int64
  2894. type: integer
  2895. type: object
  2896. service:
  2897. description: Service defines which service should be used to fetch the secrets
  2898. enum:
  2899. - SecretsManager
  2900. - ParameterStore
  2901. - CertificateManager
  2902. type: string
  2903. sessionTags:
  2904. description: AWS STS assume role session tags
  2905. items:
  2906. description: |-
  2907. Tag is a key-value pair that can be attached to an AWS resource.
  2908. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  2909. properties:
  2910. key:
  2911. type: string
  2912. value:
  2913. type: string
  2914. required:
  2915. - key
  2916. - value
  2917. type: object
  2918. type: array
  2919. sessionTagsPolicy:
  2920. default: None
  2921. description: |-
  2922. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  2923. None (default): no tags are added.
  2924. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  2925. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  2926. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  2927. enum:
  2928. - None
  2929. - Simple
  2930. - Custom
  2931. type: string
  2932. transitiveTagKeys:
  2933. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  2934. items:
  2935. type: string
  2936. type: array
  2937. required:
  2938. - region
  2939. - service
  2940. type: object
  2941. azurekv:
  2942. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  2943. properties:
  2944. authSecretRef:
  2945. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  2946. properties:
  2947. clientCertificate:
  2948. description: The Azure ClientCertificate of the service principle used for authentication.
  2949. properties:
  2950. key:
  2951. description: |-
  2952. A key in the referenced Secret.
  2953. Some instances of this field may be defaulted, in others it may be required.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[-._a-zA-Z0-9]+$
  2957. type: string
  2958. name:
  2959. description: The name of the Secret resource being referred to.
  2960. maxLength: 253
  2961. minLength: 1
  2962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2963. type: string
  2964. namespace:
  2965. description: |-
  2966. The namespace of the Secret resource being referred to.
  2967. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2968. maxLength: 63
  2969. minLength: 1
  2970. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2971. type: string
  2972. type: object
  2973. clientId:
  2974. description: The Azure clientId of the service principle or managed identity used for authentication.
  2975. properties:
  2976. key:
  2977. description: |-
  2978. A key in the referenced Secret.
  2979. Some instances of this field may be defaulted, in others it may be required.
  2980. maxLength: 253
  2981. minLength: 1
  2982. pattern: ^[-._a-zA-Z0-9]+$
  2983. type: string
  2984. name:
  2985. description: The name of the Secret resource being referred to.
  2986. maxLength: 253
  2987. minLength: 1
  2988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2989. type: string
  2990. namespace:
  2991. description: |-
  2992. The namespace of the Secret resource being referred to.
  2993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2994. maxLength: 63
  2995. minLength: 1
  2996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2997. type: string
  2998. type: object
  2999. clientSecret:
  3000. description: The Azure ClientSecret of the service principle used for authentication.
  3001. properties:
  3002. key:
  3003. description: |-
  3004. A key in the referenced Secret.
  3005. Some instances of this field may be defaulted, in others it may be required.
  3006. maxLength: 253
  3007. minLength: 1
  3008. pattern: ^[-._a-zA-Z0-9]+$
  3009. type: string
  3010. name:
  3011. description: The name of the Secret resource being referred to.
  3012. maxLength: 253
  3013. minLength: 1
  3014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3015. type: string
  3016. namespace:
  3017. description: |-
  3018. The namespace of the Secret resource being referred to.
  3019. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3020. maxLength: 63
  3021. minLength: 1
  3022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3023. type: string
  3024. type: object
  3025. tenantId:
  3026. description: The Azure tenantId of the managed identity used for authentication.
  3027. properties:
  3028. key:
  3029. description: |-
  3030. A key in the referenced Secret.
  3031. Some instances of this field may be defaulted, in others it may be required.
  3032. maxLength: 253
  3033. minLength: 1
  3034. pattern: ^[-._a-zA-Z0-9]+$
  3035. type: string
  3036. name:
  3037. description: The name of the Secret resource being referred to.
  3038. maxLength: 253
  3039. minLength: 1
  3040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3041. type: string
  3042. namespace:
  3043. description: |-
  3044. The namespace of the Secret resource being referred to.
  3045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3046. maxLength: 63
  3047. minLength: 1
  3048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3049. type: string
  3050. type: object
  3051. type: object
  3052. authType:
  3053. default: ServicePrincipal
  3054. description: |-
  3055. Auth type defines how to authenticate to the keyvault service.
  3056. Valid values are:
  3057. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3058. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3059. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  3060. enum:
  3061. - ServicePrincipal
  3062. - ManagedIdentity
  3063. - WorkloadIdentity
  3064. type: string
  3065. customCloudConfig:
  3066. description: |-
  3067. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  3068. Required when EnvironmentType is AzureStackCloud.
  3069. Optional for other environment types - useful for Azure China when using Workload Identity
  3070. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  3071. standard China Cloud endpoint (login.chinacloudapi.cn).
  3072. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  3073. configuration is not supported with the legacy go-autorest SDK.
  3074. properties:
  3075. activeDirectoryEndpoint:
  3076. description: |-
  3077. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  3078. Required when using custom cloud configuration
  3079. type: string
  3080. keyVaultDNSSuffix:
  3081. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  3082. type: string
  3083. keyVaultEndpoint:
  3084. description: KeyVaultEndpoint is the Key Vault service endpoint
  3085. type: string
  3086. resourceManagerEndpoint:
  3087. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  3088. type: string
  3089. required:
  3090. - activeDirectoryEndpoint
  3091. type: object
  3092. environmentType:
  3093. default: PublicCloud
  3094. description: |-
  3095. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3096. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3097. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3098. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  3099. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  3100. enum:
  3101. - PublicCloud
  3102. - USGovernmentCloud
  3103. - ChinaCloud
  3104. - GermanCloud
  3105. - AzureStackCloud
  3106. type: string
  3107. identityId:
  3108. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3109. type: string
  3110. serviceAccountRef:
  3111. description: |-
  3112. ServiceAccountRef specified the service account
  3113. that should be used when authenticating with WorkloadIdentity.
  3114. properties:
  3115. audiences:
  3116. description: |-
  3117. Audience specifies the `aud` claim for the service account token
  3118. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3119. then this audiences will be appended to the list
  3120. items:
  3121. type: string
  3122. type: array
  3123. name:
  3124. description: The name of the ServiceAccount resource being referred to.
  3125. maxLength: 253
  3126. minLength: 1
  3127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3128. type: string
  3129. namespace:
  3130. description: |-
  3131. Namespace of the resource being referred to.
  3132. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3133. maxLength: 63
  3134. minLength: 1
  3135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3136. type: string
  3137. required:
  3138. - name
  3139. type: object
  3140. tenantId:
  3141. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3142. type: string
  3143. useAzureSDK:
  3144. default: false
  3145. description: |-
  3146. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  3147. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  3148. type: boolean
  3149. vaultUrl:
  3150. description: Vault Url from which the secrets to be fetched from.
  3151. type: string
  3152. required:
  3153. - vaultUrl
  3154. type: object
  3155. barbican:
  3156. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  3157. properties:
  3158. auth:
  3159. description: BarbicanAuth contains the authentication information for Barbican.
  3160. properties:
  3161. password:
  3162. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  3163. properties:
  3164. secretRef:
  3165. description: |-
  3166. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3167. In some instances, `key` is a required field.
  3168. properties:
  3169. key:
  3170. description: |-
  3171. A key in the referenced Secret.
  3172. Some instances of this field may be defaulted, in others it may be required.
  3173. maxLength: 253
  3174. minLength: 1
  3175. pattern: ^[-._a-zA-Z0-9]+$
  3176. type: string
  3177. name:
  3178. description: The name of the Secret resource being referred to.
  3179. maxLength: 253
  3180. minLength: 1
  3181. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3182. type: string
  3183. namespace:
  3184. description: |-
  3185. The namespace of the Secret resource being referred to.
  3186. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3187. maxLength: 63
  3188. minLength: 1
  3189. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3190. type: string
  3191. type: object
  3192. required:
  3193. - secretRef
  3194. type: object
  3195. username:
  3196. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  3197. maxProperties: 1
  3198. minProperties: 1
  3199. properties:
  3200. secretRef:
  3201. description: |-
  3202. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  3203. In some instances, `key` is a required field.
  3204. properties:
  3205. key:
  3206. description: |-
  3207. A key in the referenced Secret.
  3208. Some instances of this field may be defaulted, in others it may be required.
  3209. maxLength: 253
  3210. minLength: 1
  3211. pattern: ^[-._a-zA-Z0-9]+$
  3212. type: string
  3213. name:
  3214. description: The name of the Secret resource being referred to.
  3215. maxLength: 253
  3216. minLength: 1
  3217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3218. type: string
  3219. namespace:
  3220. description: |-
  3221. The namespace of the Secret resource being referred to.
  3222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3223. maxLength: 63
  3224. minLength: 1
  3225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3226. type: string
  3227. type: object
  3228. value:
  3229. type: string
  3230. type: object
  3231. required:
  3232. - password
  3233. - username
  3234. type: object
  3235. authURL:
  3236. type: string
  3237. domainName:
  3238. type: string
  3239. region:
  3240. type: string
  3241. tenantName:
  3242. type: string
  3243. required:
  3244. - auth
  3245. type: object
  3246. beyondtrust:
  3247. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3248. properties:
  3249. auth:
  3250. description: Auth configures how the operator authenticates with Beyondtrust.
  3251. properties:
  3252. apiKey:
  3253. description: APIKey If not provided then ClientID/ClientSecret become required.
  3254. properties:
  3255. secretRef:
  3256. description: SecretRef references a key in a secret that will be used as value.
  3257. properties:
  3258. key:
  3259. description: |-
  3260. A key in the referenced Secret.
  3261. Some instances of this field may be defaulted, in others it may be required.
  3262. maxLength: 253
  3263. minLength: 1
  3264. pattern: ^[-._a-zA-Z0-9]+$
  3265. type: string
  3266. name:
  3267. description: The name of the Secret resource being referred to.
  3268. maxLength: 253
  3269. minLength: 1
  3270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3271. type: string
  3272. namespace:
  3273. description: |-
  3274. The namespace of the Secret resource being referred to.
  3275. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3276. maxLength: 63
  3277. minLength: 1
  3278. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3279. type: string
  3280. type: object
  3281. value:
  3282. description: Value can be specified directly to set a value without using a secret.
  3283. type: string
  3284. type: object
  3285. certificate:
  3286. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3287. properties:
  3288. secretRef:
  3289. description: SecretRef references a key in a secret that will be used as value.
  3290. properties:
  3291. key:
  3292. description: |-
  3293. A key in the referenced Secret.
  3294. Some instances of this field may be defaulted, in others it may be required.
  3295. maxLength: 253
  3296. minLength: 1
  3297. pattern: ^[-._a-zA-Z0-9]+$
  3298. type: string
  3299. name:
  3300. description: The name of the Secret resource being referred to.
  3301. maxLength: 253
  3302. minLength: 1
  3303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3304. type: string
  3305. namespace:
  3306. description: |-
  3307. The namespace of the Secret resource being referred to.
  3308. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3309. maxLength: 63
  3310. minLength: 1
  3311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3312. type: string
  3313. type: object
  3314. value:
  3315. description: Value can be specified directly to set a value without using a secret.
  3316. type: string
  3317. type: object
  3318. certificateKey:
  3319. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3320. properties:
  3321. secretRef:
  3322. description: SecretRef references a key in a secret that will be used as value.
  3323. properties:
  3324. key:
  3325. description: |-
  3326. A key in the referenced Secret.
  3327. Some instances of this field may be defaulted, in others it may be required.
  3328. maxLength: 253
  3329. minLength: 1
  3330. pattern: ^[-._a-zA-Z0-9]+$
  3331. type: string
  3332. name:
  3333. description: The name of the Secret resource being referred to.
  3334. maxLength: 253
  3335. minLength: 1
  3336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3337. type: string
  3338. namespace:
  3339. description: |-
  3340. The namespace of the Secret resource being referred to.
  3341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3342. maxLength: 63
  3343. minLength: 1
  3344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3345. type: string
  3346. type: object
  3347. value:
  3348. description: Value can be specified directly to set a value without using a secret.
  3349. type: string
  3350. type: object
  3351. clientId:
  3352. description: ClientID is the API OAuth Client ID.
  3353. properties:
  3354. secretRef:
  3355. description: SecretRef references a key in a secret that will be used as value.
  3356. properties:
  3357. key:
  3358. description: |-
  3359. A key in the referenced Secret.
  3360. Some instances of this field may be defaulted, in others it may be required.
  3361. maxLength: 253
  3362. minLength: 1
  3363. pattern: ^[-._a-zA-Z0-9]+$
  3364. type: string
  3365. name:
  3366. description: The name of the Secret resource being referred to.
  3367. maxLength: 253
  3368. minLength: 1
  3369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3370. type: string
  3371. namespace:
  3372. description: |-
  3373. The namespace of the Secret resource being referred to.
  3374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3375. maxLength: 63
  3376. minLength: 1
  3377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3378. type: string
  3379. type: object
  3380. value:
  3381. description: Value can be specified directly to set a value without using a secret.
  3382. type: string
  3383. type: object
  3384. clientSecret:
  3385. description: ClientSecret is the API OAuth Client Secret.
  3386. properties:
  3387. secretRef:
  3388. description: SecretRef references a key in a secret that will be used as value.
  3389. properties:
  3390. key:
  3391. description: |-
  3392. A key in the referenced Secret.
  3393. Some instances of this field may be defaulted, in others it may be required.
  3394. maxLength: 253
  3395. minLength: 1
  3396. pattern: ^[-._a-zA-Z0-9]+$
  3397. type: string
  3398. name:
  3399. description: The name of the Secret resource being referred to.
  3400. maxLength: 253
  3401. minLength: 1
  3402. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3403. type: string
  3404. namespace:
  3405. description: |-
  3406. The namespace of the Secret resource being referred to.
  3407. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3408. maxLength: 63
  3409. minLength: 1
  3410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3411. type: string
  3412. type: object
  3413. value:
  3414. description: Value can be specified directly to set a value without using a secret.
  3415. type: string
  3416. type: object
  3417. type: object
  3418. server:
  3419. description: Auth configures how API server works.
  3420. properties:
  3421. apiUrl:
  3422. type: string
  3423. apiVersion:
  3424. type: string
  3425. clientTimeOutSeconds:
  3426. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3427. type: integer
  3428. decrypt:
  3429. default: true
  3430. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  3431. type: boolean
  3432. retrievalType:
  3433. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3434. type: string
  3435. separator:
  3436. description: A character that separates the folder names.
  3437. type: string
  3438. verifyCA:
  3439. type: boolean
  3440. required:
  3441. - apiUrl
  3442. - verifyCA
  3443. type: object
  3444. required:
  3445. - auth
  3446. - server
  3447. type: object
  3448. beyondtrustworkloadcredentials:
  3449. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  3450. properties:
  3451. auth:
  3452. description: |-
  3453. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  3454. Currently supports API key authentication via Kubernetes secret reference.
  3455. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3456. properties:
  3457. apikey:
  3458. description: |-
  3459. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  3460. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  3461. properties:
  3462. token:
  3463. description: |-
  3464. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  3465. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  3466. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  3467. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  3468. properties:
  3469. key:
  3470. description: |-
  3471. A key in the referenced Secret.
  3472. Some instances of this field may be defaulted, in others it may be required.
  3473. maxLength: 253
  3474. minLength: 1
  3475. pattern: ^[-._a-zA-Z0-9]+$
  3476. type: string
  3477. name:
  3478. description: The name of the Secret resource being referred to.
  3479. maxLength: 253
  3480. minLength: 1
  3481. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3482. type: string
  3483. namespace:
  3484. description: |-
  3485. The namespace of the Secret resource being referred to.
  3486. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3487. maxLength: 63
  3488. minLength: 1
  3489. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3490. type: string
  3491. type: object
  3492. required:
  3493. - token
  3494. type: object
  3495. required:
  3496. - apikey
  3497. type: object
  3498. caBundle:
  3499. description: |-
  3500. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3501. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  3502. If not set, the system's trusted root certificates are used.
  3503. format: byte
  3504. type: string
  3505. caProvider:
  3506. description: |-
  3507. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  3508. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  3509. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  3510. properties:
  3511. key:
  3512. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3513. maxLength: 253
  3514. minLength: 1
  3515. pattern: ^[-._a-zA-Z0-9]+$
  3516. type: string
  3517. name:
  3518. description: The name of the object located at the provider type.
  3519. maxLength: 253
  3520. minLength: 1
  3521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3522. type: string
  3523. namespace:
  3524. description: |-
  3525. The namespace the Provider type is in.
  3526. Can only be defined when used in a ClusterSecretStore.
  3527. maxLength: 63
  3528. minLength: 1
  3529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3530. type: string
  3531. type:
  3532. description: The type of provider to use such as "Secret", or "ConfigMap".
  3533. enum:
  3534. - Secret
  3535. - ConfigMap
  3536. type: string
  3537. required:
  3538. - name
  3539. - type
  3540. type: object
  3541. folderPath:
  3542. description: |-
  3543. FolderPath specifies the default folder path for secret retrieval.
  3544. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  3545. Example: "production/database" or "dev/api-keys"
  3546. Leave empty to retrieve secrets from the root folder.
  3547. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  3548. type: string
  3549. server:
  3550. description: |-
  3551. Server configures the BeyondTrust Workload Credentials server connection details.
  3552. Includes the API URL and Site ID for your BeyondTrust instance.
  3553. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3554. properties:
  3555. apiUrl:
  3556. description: |-
  3557. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  3558. This should be the full URL to your BeyondTrust instance.
  3559. Example: https://api.beyondtrust.io/siie
  3560. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  3561. type: string
  3562. siteId:
  3563. description: |-
  3564. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  3565. This identifier is unique to your BeyondTrust Workload Credentials instance.
  3566. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  3567. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  3568. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  3569. type: string
  3570. required:
  3571. - apiUrl
  3572. - siteId
  3573. type: object
  3574. required:
  3575. - auth
  3576. - server
  3577. type: object
  3578. bitwardensecretsmanager:
  3579. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3580. properties:
  3581. apiURL:
  3582. type: string
  3583. auth:
  3584. description: |-
  3585. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3586. Make sure that the token being used has permissions on the given secret.
  3587. properties:
  3588. secretRef:
  3589. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3590. properties:
  3591. credentials:
  3592. description: AccessToken used for the bitwarden instance.
  3593. properties:
  3594. key:
  3595. description: |-
  3596. A key in the referenced Secret.
  3597. Some instances of this field may be defaulted, in others it may be required.
  3598. maxLength: 253
  3599. minLength: 1
  3600. pattern: ^[-._a-zA-Z0-9]+$
  3601. type: string
  3602. name:
  3603. description: The name of the Secret resource being referred to.
  3604. maxLength: 253
  3605. minLength: 1
  3606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3607. type: string
  3608. namespace:
  3609. description: |-
  3610. The namespace of the Secret resource being referred to.
  3611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3612. maxLength: 63
  3613. minLength: 1
  3614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3615. type: string
  3616. type: object
  3617. required:
  3618. - credentials
  3619. type: object
  3620. required:
  3621. - secretRef
  3622. type: object
  3623. bitwardenServerSDKURL:
  3624. type: string
  3625. caBundle:
  3626. description: |-
  3627. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3628. can be performed.
  3629. type: string
  3630. caProvider:
  3631. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3632. properties:
  3633. key:
  3634. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3635. maxLength: 253
  3636. minLength: 1
  3637. pattern: ^[-._a-zA-Z0-9]+$
  3638. type: string
  3639. name:
  3640. description: The name of the object located at the provider type.
  3641. maxLength: 253
  3642. minLength: 1
  3643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3644. type: string
  3645. namespace:
  3646. description: |-
  3647. The namespace the Provider type is in.
  3648. Can only be defined when used in a ClusterSecretStore.
  3649. maxLength: 63
  3650. minLength: 1
  3651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3652. type: string
  3653. type:
  3654. description: The type of provider to use such as "Secret", or "ConfigMap".
  3655. enum:
  3656. - Secret
  3657. - ConfigMap
  3658. type: string
  3659. required:
  3660. - name
  3661. - type
  3662. type: object
  3663. identityURL:
  3664. type: string
  3665. organizationID:
  3666. description: OrganizationID determines which organization this secret store manages.
  3667. type: string
  3668. projectID:
  3669. description: ProjectID determines which project this secret store manages.
  3670. type: string
  3671. required:
  3672. - auth
  3673. - organizationID
  3674. - projectID
  3675. type: object
  3676. chef:
  3677. description: Chef configures this store to sync secrets with chef server
  3678. properties:
  3679. auth:
  3680. description: Auth defines the information necessary to authenticate against chef Server
  3681. properties:
  3682. secretRef:
  3683. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3684. properties:
  3685. privateKeySecretRef:
  3686. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3687. properties:
  3688. key:
  3689. description: |-
  3690. A key in the referenced Secret.
  3691. Some instances of this field may be defaulted, in others it may be required.
  3692. maxLength: 253
  3693. minLength: 1
  3694. pattern: ^[-._a-zA-Z0-9]+$
  3695. type: string
  3696. name:
  3697. description: The name of the Secret resource being referred to.
  3698. maxLength: 253
  3699. minLength: 1
  3700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3701. type: string
  3702. namespace:
  3703. description: |-
  3704. The namespace of the Secret resource being referred to.
  3705. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3706. maxLength: 63
  3707. minLength: 1
  3708. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3709. type: string
  3710. type: object
  3711. required:
  3712. - privateKeySecretRef
  3713. type: object
  3714. required:
  3715. - secretRef
  3716. type: object
  3717. serverUrl:
  3718. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3719. type: string
  3720. username:
  3721. description: UserName should be the user ID on the chef server
  3722. type: string
  3723. required:
  3724. - auth
  3725. - serverUrl
  3726. - username
  3727. type: object
  3728. cloudrusm:
  3729. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  3730. properties:
  3731. auth:
  3732. description: CSMAuth contains a secretRef for credentials.
  3733. properties:
  3734. secretRef:
  3735. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  3736. properties:
  3737. accessKeyIDSecretRef:
  3738. description: The AccessKeyID is used for authentication
  3739. properties:
  3740. key:
  3741. description: |-
  3742. A key in the referenced Secret.
  3743. Some instances of this field may be defaulted, in others it may be required.
  3744. maxLength: 253
  3745. minLength: 1
  3746. pattern: ^[-._a-zA-Z0-9]+$
  3747. type: string
  3748. name:
  3749. description: The name of the Secret resource being referred to.
  3750. maxLength: 253
  3751. minLength: 1
  3752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3753. type: string
  3754. namespace:
  3755. description: |-
  3756. The namespace of the Secret resource being referred to.
  3757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3758. maxLength: 63
  3759. minLength: 1
  3760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3761. type: string
  3762. type: object
  3763. accessKeySecretSecretRef:
  3764. description: The AccessKeySecret is used for authentication
  3765. properties:
  3766. key:
  3767. description: |-
  3768. A key in the referenced Secret.
  3769. Some instances of this field may be defaulted, in others it may be required.
  3770. maxLength: 253
  3771. minLength: 1
  3772. pattern: ^[-._a-zA-Z0-9]+$
  3773. type: string
  3774. name:
  3775. description: The name of the Secret resource being referred to.
  3776. maxLength: 253
  3777. minLength: 1
  3778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3779. type: string
  3780. namespace:
  3781. description: |-
  3782. The namespace of the Secret resource being referred to.
  3783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3784. maxLength: 63
  3785. minLength: 1
  3786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3787. type: string
  3788. type: object
  3789. required:
  3790. - accessKeyIDSecretRef
  3791. - accessKeySecretSecretRef
  3792. type: object
  3793. type: object
  3794. projectID:
  3795. description: ProjectID is the project, which the secrets are stored in.
  3796. type: string
  3797. required:
  3798. - auth
  3799. type: object
  3800. conjur:
  3801. description: Conjur configures this store to sync secrets using conjur provider
  3802. properties:
  3803. auth:
  3804. description: Defines authentication settings for connecting to Conjur.
  3805. maxProperties: 1
  3806. minProperties: 1
  3807. properties:
  3808. apikey:
  3809. description: Authenticates with Conjur using an API key.
  3810. properties:
  3811. account:
  3812. description: Account is the Conjur organization account name.
  3813. type: string
  3814. apiKeyRef:
  3815. description: |-
  3816. A reference to a specific 'key' containing the Conjur API key
  3817. within a Secret resource. In some instances, `key` is a required field.
  3818. properties:
  3819. key:
  3820. description: |-
  3821. A key in the referenced Secret.
  3822. Some instances of this field may be defaulted, in others it may be required.
  3823. maxLength: 253
  3824. minLength: 1
  3825. pattern: ^[-._a-zA-Z0-9]+$
  3826. type: string
  3827. name:
  3828. description: The name of the Secret resource being referred to.
  3829. maxLength: 253
  3830. minLength: 1
  3831. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3832. type: string
  3833. namespace:
  3834. description: |-
  3835. The namespace of the Secret resource being referred to.
  3836. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3837. maxLength: 63
  3838. minLength: 1
  3839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3840. type: string
  3841. type: object
  3842. userRef:
  3843. description: |-
  3844. A reference to a specific 'key' containing the Conjur username
  3845. within a Secret resource. In some instances, `key` is a required field.
  3846. properties:
  3847. key:
  3848. description: |-
  3849. A key in the referenced Secret.
  3850. Some instances of this field may be defaulted, in others it may be required.
  3851. maxLength: 253
  3852. minLength: 1
  3853. pattern: ^[-._a-zA-Z0-9]+$
  3854. type: string
  3855. name:
  3856. description: The name of the Secret resource being referred to.
  3857. maxLength: 253
  3858. minLength: 1
  3859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3860. type: string
  3861. namespace:
  3862. description: |-
  3863. The namespace of the Secret resource being referred to.
  3864. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3865. maxLength: 63
  3866. minLength: 1
  3867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3868. type: string
  3869. type: object
  3870. required:
  3871. - account
  3872. - apiKeyRef
  3873. - userRef
  3874. type: object
  3875. cert:
  3876. description: Cert enables certificate-based authentication using a client certificate and key.
  3877. properties:
  3878. account:
  3879. description: Account is the Conjur organization account name.
  3880. type: string
  3881. clientCertRef:
  3882. description: |-
  3883. ClientCertRef is a reference to a specific 'key' containing the client certificate
  3884. within a Secret resource. The certificate must be PEM-encoded.
  3885. properties:
  3886. key:
  3887. description: |-
  3888. A key in the referenced Secret.
  3889. Some instances of this field may be defaulted, in others it may be required.
  3890. maxLength: 253
  3891. minLength: 1
  3892. pattern: ^[-._a-zA-Z0-9]+$
  3893. type: string
  3894. name:
  3895. description: The name of the Secret resource being referred to.
  3896. maxLength: 253
  3897. minLength: 1
  3898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3899. type: string
  3900. namespace:
  3901. description: |-
  3902. The namespace of the Secret resource being referred to.
  3903. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3904. maxLength: 63
  3905. minLength: 1
  3906. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3907. type: string
  3908. type: object
  3909. clientKeyRef:
  3910. description: |-
  3911. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  3912. within a Secret resource. The key must be PEM-encoded.
  3913. properties:
  3914. key:
  3915. description: |-
  3916. A key in the referenced Secret.
  3917. Some instances of this field may be defaulted, in others it may be required.
  3918. maxLength: 253
  3919. minLength: 1
  3920. pattern: ^[-._a-zA-Z0-9]+$
  3921. type: string
  3922. name:
  3923. description: The name of the Secret resource being referred to.
  3924. maxLength: 253
  3925. minLength: 1
  3926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3927. type: string
  3928. namespace:
  3929. description: |-
  3930. The namespace of the Secret resource being referred to.
  3931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3932. maxLength: 63
  3933. minLength: 1
  3934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3935. type: string
  3936. type: object
  3937. hostId:
  3938. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  3939. type: string
  3940. serviceID:
  3941. description: The conjur authn cert webservice id
  3942. type: string
  3943. required:
  3944. - account
  3945. - clientCertRef
  3946. - clientKeyRef
  3947. - serviceID
  3948. type: object
  3949. jwt:
  3950. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  3951. properties:
  3952. account:
  3953. description: Account is the Conjur organization account name.
  3954. type: string
  3955. hostId:
  3956. description: |-
  3957. Optional HostID for JWT authentication. This may be used depending
  3958. on how the Conjur JWT authenticator policy is configured.
  3959. type: string
  3960. secretRef:
  3961. description: |-
  3962. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3963. authenticate with Conjur using the JWT authentication method.
  3964. properties:
  3965. key:
  3966. description: |-
  3967. A key in the referenced Secret.
  3968. Some instances of this field may be defaulted, in others it may be required.
  3969. maxLength: 253
  3970. minLength: 1
  3971. pattern: ^[-._a-zA-Z0-9]+$
  3972. type: string
  3973. name:
  3974. description: The name of the Secret resource being referred to.
  3975. maxLength: 253
  3976. minLength: 1
  3977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3978. type: string
  3979. namespace:
  3980. description: |-
  3981. The namespace of the Secret resource being referred to.
  3982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3983. maxLength: 63
  3984. minLength: 1
  3985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3986. type: string
  3987. type: object
  3988. serviceAccountRef:
  3989. description: |-
  3990. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3991. a token for with the `TokenRequest` API.
  3992. properties:
  3993. audiences:
  3994. description: |-
  3995. Audience specifies the `aud` claim for the service account token
  3996. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3997. then this audiences will be appended to the list
  3998. items:
  3999. type: string
  4000. type: array
  4001. name:
  4002. description: The name of the ServiceAccount resource being referred to.
  4003. maxLength: 253
  4004. minLength: 1
  4005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4006. type: string
  4007. namespace:
  4008. description: |-
  4009. Namespace of the resource being referred to.
  4010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4011. maxLength: 63
  4012. minLength: 1
  4013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4014. type: string
  4015. required:
  4016. - name
  4017. type: object
  4018. serviceID:
  4019. description: The conjur authn jwt webservice id
  4020. type: string
  4021. required:
  4022. - account
  4023. - serviceID
  4024. type: object
  4025. type: object
  4026. caBundle:
  4027. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  4028. type: string
  4029. caProvider:
  4030. description: |-
  4031. Used to provide custom certificate authority (CA) certificates
  4032. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  4033. that contains a PEM-encoded certificate.
  4034. properties:
  4035. key:
  4036. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4037. maxLength: 253
  4038. minLength: 1
  4039. pattern: ^[-._a-zA-Z0-9]+$
  4040. type: string
  4041. name:
  4042. description: The name of the object located at the provider type.
  4043. maxLength: 253
  4044. minLength: 1
  4045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4046. type: string
  4047. namespace:
  4048. description: |-
  4049. The namespace the Provider type is in.
  4050. Can only be defined when used in a ClusterSecretStore.
  4051. maxLength: 63
  4052. minLength: 1
  4053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4054. type: string
  4055. type:
  4056. description: The type of provider to use such as "Secret", or "ConfigMap".
  4057. enum:
  4058. - Secret
  4059. - ConfigMap
  4060. type: string
  4061. required:
  4062. - name
  4063. - type
  4064. type: object
  4065. url:
  4066. description: URL is the endpoint of the Conjur instance.
  4067. type: string
  4068. required:
  4069. - auth
  4070. - url
  4071. type: object
  4072. crd:
  4073. description: |-
  4074. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  4075. including both custom resources (CRDs) and core API resources. Resources are
  4076. selected by API group, version and kind, where group can be "" (empty string)
  4077. for core resources such as ConfigMap. Reading the core v1 Secret is
  4078. intentionally blocked — use the Kubernetes provider for that.
  4079. properties:
  4080. auth:
  4081. description: |-
  4082. Auth configures authentication to the Kubernetes API, same as the
  4083. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  4084. maxProperties: 1
  4085. minProperties: 1
  4086. properties:
  4087. cert:
  4088. description: has both clientCert and clientKey as secretKeySelector
  4089. properties:
  4090. clientCert:
  4091. description: |-
  4092. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4093. In some instances, `key` is a required field.
  4094. properties:
  4095. key:
  4096. description: |-
  4097. A key in the referenced Secret.
  4098. Some instances of this field may be defaulted, in others it may be required.
  4099. maxLength: 253
  4100. minLength: 1
  4101. pattern: ^[-._a-zA-Z0-9]+$
  4102. type: string
  4103. name:
  4104. description: The name of the Secret resource being referred to.
  4105. maxLength: 253
  4106. minLength: 1
  4107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4108. type: string
  4109. namespace:
  4110. description: |-
  4111. The namespace of the Secret resource being referred to.
  4112. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4113. maxLength: 63
  4114. minLength: 1
  4115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4116. type: string
  4117. type: object
  4118. clientKey:
  4119. description: |-
  4120. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4121. In some instances, `key` is a required field.
  4122. properties:
  4123. key:
  4124. description: |-
  4125. A key in the referenced Secret.
  4126. Some instances of this field may be defaulted, in others it may be required.
  4127. maxLength: 253
  4128. minLength: 1
  4129. pattern: ^[-._a-zA-Z0-9]+$
  4130. type: string
  4131. name:
  4132. description: The name of the Secret resource being referred to.
  4133. maxLength: 253
  4134. minLength: 1
  4135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4136. type: string
  4137. namespace:
  4138. description: |-
  4139. The namespace of the Secret resource being referred to.
  4140. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4141. maxLength: 63
  4142. minLength: 1
  4143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4144. type: string
  4145. type: object
  4146. required:
  4147. - clientCert
  4148. - clientKey
  4149. type: object
  4150. serviceAccount:
  4151. description: points to a service account that should be used for authentication
  4152. properties:
  4153. audiences:
  4154. description: |-
  4155. Audience specifies the `aud` claim for the service account token
  4156. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4157. then this audiences will be appended to the list
  4158. items:
  4159. type: string
  4160. type: array
  4161. name:
  4162. description: The name of the ServiceAccount resource being referred to.
  4163. maxLength: 253
  4164. minLength: 1
  4165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4166. type: string
  4167. namespace:
  4168. description: |-
  4169. Namespace of the resource being referred to.
  4170. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4171. maxLength: 63
  4172. minLength: 1
  4173. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4174. type: string
  4175. required:
  4176. - name
  4177. type: object
  4178. token:
  4179. description: use static token to authenticate with
  4180. properties:
  4181. bearerToken:
  4182. description: |-
  4183. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4184. In some instances, `key` is a required field.
  4185. properties:
  4186. key:
  4187. description: |-
  4188. A key in the referenced Secret.
  4189. Some instances of this field may be defaulted, in others it may be required.
  4190. maxLength: 253
  4191. minLength: 1
  4192. pattern: ^[-._a-zA-Z0-9]+$
  4193. type: string
  4194. name:
  4195. description: The name of the Secret resource being referred to.
  4196. maxLength: 253
  4197. minLength: 1
  4198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4199. type: string
  4200. namespace:
  4201. description: |-
  4202. The namespace of the Secret resource being referred to.
  4203. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4204. maxLength: 63
  4205. minLength: 1
  4206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4207. type: string
  4208. type: object
  4209. required:
  4210. - bearerToken
  4211. type: object
  4212. type: object
  4213. authRef:
  4214. description: |-
  4215. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  4216. Kubernetes provider.
  4217. properties:
  4218. key:
  4219. description: |-
  4220. A key in the referenced Secret.
  4221. Some instances of this field may be defaulted, in others it may be required.
  4222. maxLength: 253
  4223. minLength: 1
  4224. pattern: ^[-._a-zA-Z0-9]+$
  4225. type: string
  4226. name:
  4227. description: The name of the Secret resource being referred to.
  4228. maxLength: 253
  4229. minLength: 1
  4230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4231. type: string
  4232. namespace:
  4233. description: |-
  4234. The namespace of the Secret resource being referred to.
  4235. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4236. maxLength: 63
  4237. minLength: 1
  4238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4239. type: string
  4240. type: object
  4241. resource:
  4242. description: Resource identifies the CRD by its API group, version and kind.
  4243. properties:
  4244. group:
  4245. description: |-
  4246. Group is the API group of the resource. Use "" (empty string) for core
  4247. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  4248. for a CRD. The field is required to be present in the manifest — write
  4249. `group: ""` explicitly for core resources so typos fail at admission
  4250. time rather than later at discovery.
  4251. type: string
  4252. kind:
  4253. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  4254. minLength: 1
  4255. type: string
  4256. version:
  4257. description: Version is the API version of the resource (e.g. "v1alpha1").
  4258. minLength: 1
  4259. type: string
  4260. required:
  4261. - group
  4262. - kind
  4263. - version
  4264. type: object
  4265. server:
  4266. description: |-
  4267. Server configures the Kubernetes API address and TLS trust, same as the
  4268. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  4269. properties:
  4270. caBundle:
  4271. description: CABundle is a base64-encoded CA certificate
  4272. format: byte
  4273. type: string
  4274. caProvider:
  4275. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  4276. properties:
  4277. key:
  4278. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4279. maxLength: 253
  4280. minLength: 1
  4281. pattern: ^[-._a-zA-Z0-9]+$
  4282. type: string
  4283. name:
  4284. description: The name of the object located at the provider type.
  4285. maxLength: 253
  4286. minLength: 1
  4287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4288. type: string
  4289. namespace:
  4290. description: |-
  4291. The namespace the Provider type is in.
  4292. Can only be defined when used in a ClusterSecretStore.
  4293. maxLength: 63
  4294. minLength: 1
  4295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4296. type: string
  4297. type:
  4298. description: The type of provider to use such as "Secret", or "ConfigMap".
  4299. enum:
  4300. - Secret
  4301. - ConfigMap
  4302. type: string
  4303. required:
  4304. - name
  4305. - type
  4306. type: object
  4307. url:
  4308. default: kubernetes.default
  4309. description: configures the Kubernetes server Address.
  4310. type: string
  4311. type: object
  4312. whitelist:
  4313. description: |-
  4314. Whitelist optionally restricts which object names and requested properties
  4315. are allowed to be read.
  4316. properties:
  4317. rules:
  4318. description: |-
  4319. Rules is a list of allow rules. If rules are set, at least one rule must
  4320. match for a request to be allowed.
  4321. items:
  4322. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  4323. properties:
  4324. name:
  4325. description: |-
  4326. Name is an optional regular expression matched against the bare object name.
  4327. For both SecretStore and ClusterSecretStore this is always the object name
  4328. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  4329. type: string
  4330. namespace:
  4331. description: |-
  4332. Namespace is an optional regular expression matched against the namespace of
  4333. the object. Applies only when a ClusterSecretStore is used; it is ignored
  4334. for SecretStore (where the namespace is fixed to the store namespace).
  4335. type: string
  4336. properties:
  4337. description: |-
  4338. Properties is an optional list of regular expressions matched against
  4339. requested property keys (for example: "spec.secretValue").
  4340. items:
  4341. type: string
  4342. type: array
  4343. type: object
  4344. type: array
  4345. type: object
  4346. required:
  4347. - resource
  4348. type: object
  4349. x-kubernetes-validations:
  4350. - message: one of auth or authRef is required
  4351. rule: has(self.auth) || has(self.authRef)
  4352. - message: at most one of the fields in [auth authRef] may be set
  4353. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  4354. delinea:
  4355. description: |-
  4356. Delinea DevOps Secrets Vault
  4357. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  4358. properties:
  4359. clientId:
  4360. description: ClientID is the non-secret part of the credential.
  4361. properties:
  4362. secretRef:
  4363. description: SecretRef references a key in a secret that will be used as value.
  4364. properties:
  4365. key:
  4366. description: |-
  4367. A key in the referenced Secret.
  4368. Some instances of this field may be defaulted, in others it may be required.
  4369. maxLength: 253
  4370. minLength: 1
  4371. pattern: ^[-._a-zA-Z0-9]+$
  4372. type: string
  4373. name:
  4374. description: The name of the Secret resource being referred to.
  4375. maxLength: 253
  4376. minLength: 1
  4377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4378. type: string
  4379. namespace:
  4380. description: |-
  4381. The namespace of the Secret resource being referred to.
  4382. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4383. maxLength: 63
  4384. minLength: 1
  4385. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4386. type: string
  4387. type: object
  4388. value:
  4389. description: Value can be specified directly to set a value without using a secret.
  4390. type: string
  4391. type: object
  4392. clientSecret:
  4393. description: ClientSecret is the secret part of the credential.
  4394. properties:
  4395. secretRef:
  4396. description: SecretRef references a key in a secret that will be used as value.
  4397. properties:
  4398. key:
  4399. description: |-
  4400. A key in the referenced Secret.
  4401. Some instances of this field may be defaulted, in others it may be required.
  4402. maxLength: 253
  4403. minLength: 1
  4404. pattern: ^[-._a-zA-Z0-9]+$
  4405. type: string
  4406. name:
  4407. description: The name of the Secret resource being referred to.
  4408. maxLength: 253
  4409. minLength: 1
  4410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4411. type: string
  4412. namespace:
  4413. description: |-
  4414. The namespace of the Secret resource being referred to.
  4415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4416. maxLength: 63
  4417. minLength: 1
  4418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4419. type: string
  4420. type: object
  4421. value:
  4422. description: Value can be specified directly to set a value without using a secret.
  4423. type: string
  4424. type: object
  4425. tenant:
  4426. description: Tenant is the chosen hostname / site name.
  4427. type: string
  4428. tld:
  4429. description: |-
  4430. TLD is based on the server location that was chosen during provisioning.
  4431. If unset, defaults to "com".
  4432. type: string
  4433. urlTemplate:
  4434. description: |-
  4435. URLTemplate
  4436. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  4437. type: string
  4438. required:
  4439. - clientId
  4440. - clientSecret
  4441. - tenant
  4442. type: object
  4443. doppler:
  4444. description: Doppler configures this store to sync secrets using the Doppler provider
  4445. properties:
  4446. auth:
  4447. description: Auth configures how the Operator authenticates with the Doppler API
  4448. properties:
  4449. oidcConfig:
  4450. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  4451. properties:
  4452. expirationSeconds:
  4453. default: 600
  4454. description: |-
  4455. ExpirationSeconds sets the ServiceAccount token validity duration.
  4456. Defaults to 10 minutes.
  4457. format: int64
  4458. type: integer
  4459. identity:
  4460. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  4461. type: string
  4462. serviceAccountRef:
  4463. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  4464. properties:
  4465. audiences:
  4466. description: |-
  4467. Audience specifies the `aud` claim for the service account token
  4468. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4469. then this audiences will be appended to the list
  4470. items:
  4471. type: string
  4472. type: array
  4473. name:
  4474. description: The name of the ServiceAccount resource being referred to.
  4475. maxLength: 253
  4476. minLength: 1
  4477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4478. type: string
  4479. namespace:
  4480. description: |-
  4481. Namespace of the resource being referred to.
  4482. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4483. maxLength: 63
  4484. minLength: 1
  4485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4486. type: string
  4487. required:
  4488. - name
  4489. type: object
  4490. required:
  4491. - identity
  4492. - serviceAccountRef
  4493. type: object
  4494. secretRef:
  4495. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  4496. properties:
  4497. dopplerToken:
  4498. description: |-
  4499. The DopplerToken is used for authentication.
  4500. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4501. The Key attribute defaults to dopplerToken if not specified.
  4502. properties:
  4503. key:
  4504. description: |-
  4505. A key in the referenced Secret.
  4506. Some instances of this field may be defaulted, in others it may be required.
  4507. maxLength: 253
  4508. minLength: 1
  4509. pattern: ^[-._a-zA-Z0-9]+$
  4510. type: string
  4511. name:
  4512. description: The name of the Secret resource being referred to.
  4513. maxLength: 253
  4514. minLength: 1
  4515. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4516. type: string
  4517. namespace:
  4518. description: |-
  4519. The namespace of the Secret resource being referred to.
  4520. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4521. maxLength: 63
  4522. minLength: 1
  4523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4524. type: string
  4525. type: object
  4526. required:
  4527. - dopplerToken
  4528. type: object
  4529. type: object
  4530. x-kubernetes-validations:
  4531. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  4532. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  4533. config:
  4534. description: Doppler config (required if not using a Service Token)
  4535. type: string
  4536. format:
  4537. description: Format enables the downloading of secrets as a file (string)
  4538. enum:
  4539. - json
  4540. - dotnet-json
  4541. - env
  4542. - yaml
  4543. - docker
  4544. type: string
  4545. nameTransformer:
  4546. description: Environment variable compatible name transforms that change secret names to a different format
  4547. enum:
  4548. - upper-camel
  4549. - camel
  4550. - lower-snake
  4551. - tf-var
  4552. - dotnet-env
  4553. - lower-kebab
  4554. type: string
  4555. project:
  4556. description: Doppler project (required if not using a Service Token)
  4557. type: string
  4558. required:
  4559. - auth
  4560. type: object
  4561. dvls:
  4562. description: DVLS configures this store to sync secrets using Devolutions Server provider
  4563. properties:
  4564. auth:
  4565. description: Auth defines the authentication method to use.
  4566. properties:
  4567. secretRef:
  4568. description: SecretRef contains the Application ID and Application Secret for authentication.
  4569. properties:
  4570. appId:
  4571. description: AppID is the reference to the secret containing the Application ID.
  4572. properties:
  4573. key:
  4574. description: |-
  4575. A key in the referenced Secret.
  4576. Some instances of this field may be defaulted, in others it may be required.
  4577. maxLength: 253
  4578. minLength: 1
  4579. pattern: ^[-._a-zA-Z0-9]+$
  4580. type: string
  4581. name:
  4582. description: The name of the Secret resource being referred to.
  4583. maxLength: 253
  4584. minLength: 1
  4585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4586. type: string
  4587. namespace:
  4588. description: |-
  4589. The namespace of the Secret resource being referred to.
  4590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4591. maxLength: 63
  4592. minLength: 1
  4593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4594. type: string
  4595. type: object
  4596. appSecret:
  4597. description: AppSecret is the reference to the secret containing the Application Secret.
  4598. properties:
  4599. key:
  4600. description: |-
  4601. A key in the referenced Secret.
  4602. Some instances of this field may be defaulted, in others it may be required.
  4603. maxLength: 253
  4604. minLength: 1
  4605. pattern: ^[-._a-zA-Z0-9]+$
  4606. type: string
  4607. name:
  4608. description: The name of the Secret resource being referred to.
  4609. maxLength: 253
  4610. minLength: 1
  4611. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4612. type: string
  4613. namespace:
  4614. description: |-
  4615. The namespace of the Secret resource being referred to.
  4616. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4617. maxLength: 63
  4618. minLength: 1
  4619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4620. type: string
  4621. type: object
  4622. required:
  4623. - appId
  4624. - appSecret
  4625. type: object
  4626. required:
  4627. - secretRef
  4628. type: object
  4629. insecure:
  4630. description: |-
  4631. Insecure allows connecting to DVLS over plain HTTP.
  4632. This is NOT RECOMMENDED for production use.
  4633. Set to true only if you understand the security implications.
  4634. type: boolean
  4635. serverUrl:
  4636. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  4637. type: string
  4638. vault:
  4639. description: |-
  4640. Vault is the name or UUID of the vault to fetch secrets from.
  4641. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  4642. type: string
  4643. required:
  4644. - auth
  4645. - serverUrl
  4646. type: object
  4647. fake:
  4648. description: Fake configures a store with static key/value pairs
  4649. properties:
  4650. data:
  4651. items:
  4652. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  4653. properties:
  4654. key:
  4655. type: string
  4656. value:
  4657. type: string
  4658. version:
  4659. type: string
  4660. required:
  4661. - key
  4662. - value
  4663. type: object
  4664. type: array
  4665. validationResult:
  4666. description: ValidationResult is defined type for the number of validation results.
  4667. type: integer
  4668. required:
  4669. - data
  4670. type: object
  4671. fortanix:
  4672. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4673. properties:
  4674. apiKey:
  4675. description: APIKey is the API token to access SDKMS Applications.
  4676. properties:
  4677. secretRef:
  4678. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4679. properties:
  4680. key:
  4681. description: |-
  4682. A key in the referenced Secret.
  4683. Some instances of this field may be defaulted, in others it may be required.
  4684. maxLength: 253
  4685. minLength: 1
  4686. pattern: ^[-._a-zA-Z0-9]+$
  4687. type: string
  4688. name:
  4689. description: The name of the Secret resource being referred to.
  4690. maxLength: 253
  4691. minLength: 1
  4692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4693. type: string
  4694. namespace:
  4695. description: |-
  4696. The namespace of the Secret resource being referred to.
  4697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4698. maxLength: 63
  4699. minLength: 1
  4700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4701. type: string
  4702. type: object
  4703. type: object
  4704. apiUrl:
  4705. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4706. type: string
  4707. type: object
  4708. gcpsm:
  4709. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4710. properties:
  4711. auth:
  4712. description: Auth defines the information necessary to authenticate against GCP
  4713. properties:
  4714. secretRef:
  4715. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  4716. properties:
  4717. secretAccessKeySecretRef:
  4718. description: The SecretAccessKey is used for authentication
  4719. properties:
  4720. key:
  4721. description: |-
  4722. A key in the referenced Secret.
  4723. Some instances of this field may be defaulted, in others it may be required.
  4724. maxLength: 253
  4725. minLength: 1
  4726. pattern: ^[-._a-zA-Z0-9]+$
  4727. type: string
  4728. name:
  4729. description: The name of the Secret resource being referred to.
  4730. maxLength: 253
  4731. minLength: 1
  4732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4733. type: string
  4734. namespace:
  4735. description: |-
  4736. The namespace of the Secret resource being referred to.
  4737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4738. maxLength: 63
  4739. minLength: 1
  4740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4741. type: string
  4742. type: object
  4743. type: object
  4744. workloadIdentity:
  4745. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  4746. properties:
  4747. clusterLocation:
  4748. description: |-
  4749. ClusterLocation is the location of the cluster
  4750. If not specified, it fetches information from the metadata server
  4751. type: string
  4752. clusterName:
  4753. description: |-
  4754. ClusterName is the name of the cluster
  4755. If not specified, it fetches information from the metadata server
  4756. type: string
  4757. clusterProjectID:
  4758. description: |-
  4759. ClusterProjectID is the project ID of the cluster
  4760. If not specified, it fetches information from the metadata server
  4761. type: string
  4762. serviceAccountRef:
  4763. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  4764. properties:
  4765. audiences:
  4766. description: |-
  4767. Audience specifies the `aud` claim for the service account token
  4768. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4769. then this audiences will be appended to the list
  4770. items:
  4771. type: string
  4772. type: array
  4773. name:
  4774. description: The name of the ServiceAccount resource being referred to.
  4775. maxLength: 253
  4776. minLength: 1
  4777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4778. type: string
  4779. namespace:
  4780. description: |-
  4781. Namespace of the resource being referred to.
  4782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4783. maxLength: 63
  4784. minLength: 1
  4785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4786. type: string
  4787. required:
  4788. - name
  4789. type: object
  4790. required:
  4791. - serviceAccountRef
  4792. type: object
  4793. workloadIdentityFederation:
  4794. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  4795. properties:
  4796. audience:
  4797. description: |-
  4798. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  4799. If specified, Audience found in the external account credential config will be overridden with the configured value.
  4800. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  4801. type: string
  4802. awsSecurityCredentials:
  4803. description: |-
  4804. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  4805. when using the AWS metadata server is not an option.
  4806. properties:
  4807. awsCredentialsSecretRef:
  4808. description: |-
  4809. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  4810. Secret should be created with below names for keys
  4811. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  4812. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  4813. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  4814. properties:
  4815. name:
  4816. description: name of the secret.
  4817. maxLength: 253
  4818. minLength: 1
  4819. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4820. type: string
  4821. namespace:
  4822. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  4823. maxLength: 63
  4824. minLength: 1
  4825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4826. type: string
  4827. required:
  4828. - name
  4829. type: object
  4830. region:
  4831. description: region is for configuring the AWS region to be used.
  4832. example: ap-south-1
  4833. maxLength: 50
  4834. minLength: 1
  4835. pattern: ^[a-z0-9-]+$
  4836. type: string
  4837. required:
  4838. - awsCredentialsSecretRef
  4839. - region
  4840. type: object
  4841. credConfig:
  4842. description: |-
  4843. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  4844. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  4845. serviceAccountRef must be used by providing operators service account details.
  4846. properties:
  4847. key:
  4848. description: key name holding the external account credential config.
  4849. maxLength: 253
  4850. minLength: 1
  4851. pattern: ^[-._a-zA-Z0-9]+$
  4852. type: string
  4853. name:
  4854. description: name of the configmap.
  4855. maxLength: 253
  4856. minLength: 1
  4857. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4858. type: string
  4859. namespace:
  4860. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  4861. maxLength: 63
  4862. minLength: 1
  4863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4864. type: string
  4865. required:
  4866. - key
  4867. - name
  4868. type: object
  4869. externalTokenEndpoint:
  4870. description: |-
  4871. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  4872. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  4873. URL is having the expected value.
  4874. type: string
  4875. gcpServiceAccountEmail:
  4876. description: |-
  4877. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  4878. after Workload Identity Federation. Use this to grant access through the service account's
  4879. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  4880. service_account_impersonation_url in the external account JSON from credConfig;
  4881. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  4882. on that ServiceAccount.
  4883. example: my-gsa@my-project.iam.gserviceaccount.com
  4884. minLength: 1
  4885. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  4886. type: string
  4887. serviceAccountRef:
  4888. description: |-
  4889. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  4890. when Kubernetes is configured as provider in workload identity pool.
  4891. properties:
  4892. audiences:
  4893. description: |-
  4894. Audience specifies the `aud` claim for the service account token
  4895. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4896. then this audiences will be appended to the list
  4897. items:
  4898. type: string
  4899. type: array
  4900. name:
  4901. description: The name of the ServiceAccount resource being referred to.
  4902. maxLength: 253
  4903. minLength: 1
  4904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4905. type: string
  4906. namespace:
  4907. description: |-
  4908. Namespace of the resource being referred to.
  4909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4910. maxLength: 63
  4911. minLength: 1
  4912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4913. type: string
  4914. required:
  4915. - name
  4916. type: object
  4917. type: object
  4918. type: object
  4919. location:
  4920. description: Location optionally defines a location for a secret
  4921. type: string
  4922. projectID:
  4923. description: ProjectID project where secret is located
  4924. type: string
  4925. secretVersionSelectionPolicy:
  4926. default: LatestOrFail
  4927. description: |-
  4928. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  4929. when "latest" is disabled or destroyed.
  4930. Possible values are:
  4931. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  4932. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  4933. type: string
  4934. type: object
  4935. github:
  4936. description: |-
  4937. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  4938. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  4939. properties:
  4940. appID:
  4941. description: appID specifies the Github APP that will be used to authenticate the client
  4942. format: int64
  4943. type: integer
  4944. auth:
  4945. description: auth configures how secret-manager authenticates with a Github instance.
  4946. properties:
  4947. privateKey:
  4948. description: |-
  4949. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  4950. In some instances, `key` is a required field.
  4951. properties:
  4952. key:
  4953. description: |-
  4954. A key in the referenced Secret.
  4955. Some instances of this field may be defaulted, in others it may be required.
  4956. maxLength: 253
  4957. minLength: 1
  4958. pattern: ^[-._a-zA-Z0-9]+$
  4959. type: string
  4960. name:
  4961. description: The name of the Secret resource being referred to.
  4962. maxLength: 253
  4963. minLength: 1
  4964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4965. type: string
  4966. namespace:
  4967. description: |-
  4968. The namespace of the Secret resource being referred to.
  4969. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4970. maxLength: 63
  4971. minLength: 1
  4972. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4973. type: string
  4974. type: object
  4975. required:
  4976. - privateKey
  4977. type: object
  4978. environment:
  4979. description: environment will be used to fetch secrets from a particular environment within a github repository
  4980. type: string
  4981. installationID:
  4982. description: installationID specifies the Github APP installation that will be used to authenticate the client
  4983. format: int64
  4984. type: integer
  4985. orgSecretVisibility:
  4986. description: |-
  4987. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  4988. Valid values are "all" or "private".
  4989. When unset, new secrets are created with visibility "all" and existing secrets preserve
  4990. whatever visibility they already have in GitHub.
  4991. enum:
  4992. - all
  4993. - private
  4994. type: string
  4995. organization:
  4996. description: organization will be used to fetch secrets from the Github organization
  4997. type: string
  4998. repository:
  4999. description: repository will be used to fetch secrets from the Github repository within an organization
  5000. type: string
  5001. uploadURL:
  5002. description: Upload URL for enterprise instances. Default to URL.
  5003. type: string
  5004. url:
  5005. default: https://github.com/
  5006. description: URL configures the Github instance URL. Defaults to https://github.com/.
  5007. type: string
  5008. required:
  5009. - appID
  5010. - auth
  5011. - installationID
  5012. - organization
  5013. type: object
  5014. gitlab:
  5015. description: GitLab configures this store to sync secrets using GitLab Variables provider
  5016. properties:
  5017. auth:
  5018. description: Auth configures how secret-manager authenticates with a GitLab instance.
  5019. properties:
  5020. SecretRef:
  5021. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  5022. properties:
  5023. accessToken:
  5024. description: AccessToken is used for authentication.
  5025. properties:
  5026. key:
  5027. description: |-
  5028. A key in the referenced Secret.
  5029. Some instances of this field may be defaulted, in others it may be required.
  5030. maxLength: 253
  5031. minLength: 1
  5032. pattern: ^[-._a-zA-Z0-9]+$
  5033. type: string
  5034. name:
  5035. description: The name of the Secret resource being referred to.
  5036. maxLength: 253
  5037. minLength: 1
  5038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5039. type: string
  5040. namespace:
  5041. description: |-
  5042. The namespace of the Secret resource being referred to.
  5043. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5044. maxLength: 63
  5045. minLength: 1
  5046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5047. type: string
  5048. type: object
  5049. type: object
  5050. required:
  5051. - SecretRef
  5052. type: object
  5053. caBundle:
  5054. description: |-
  5055. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  5056. can be performed.
  5057. format: byte
  5058. type: string
  5059. caProvider:
  5060. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  5061. properties:
  5062. key:
  5063. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5064. maxLength: 253
  5065. minLength: 1
  5066. pattern: ^[-._a-zA-Z0-9]+$
  5067. type: string
  5068. name:
  5069. description: The name of the object located at the provider type.
  5070. maxLength: 253
  5071. minLength: 1
  5072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5073. type: string
  5074. namespace:
  5075. description: |-
  5076. The namespace the Provider type is in.
  5077. Can only be defined when used in a ClusterSecretStore.
  5078. maxLength: 63
  5079. minLength: 1
  5080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5081. type: string
  5082. type:
  5083. description: The type of provider to use such as "Secret", or "ConfigMap".
  5084. enum:
  5085. - Secret
  5086. - ConfigMap
  5087. type: string
  5088. required:
  5089. - name
  5090. - type
  5091. type: object
  5092. environment:
  5093. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  5094. type: string
  5095. groupIDs:
  5096. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  5097. items:
  5098. type: string
  5099. type: array
  5100. inheritFromGroups:
  5101. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  5102. type: boolean
  5103. projectID:
  5104. description: ProjectID specifies a project where secrets are located.
  5105. type: string
  5106. url:
  5107. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  5108. type: string
  5109. required:
  5110. - auth
  5111. type: object
  5112. ibm:
  5113. description: IBM configures this store to sync secrets using IBM Cloud provider
  5114. properties:
  5115. auth:
  5116. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  5117. maxProperties: 1
  5118. minProperties: 1
  5119. properties:
  5120. containerAuth:
  5121. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  5122. properties:
  5123. iamEndpoint:
  5124. type: string
  5125. profile:
  5126. description: the IBM Trusted Profile
  5127. type: string
  5128. tokenLocation:
  5129. description: Location the token is mounted on the pod
  5130. type: string
  5131. required:
  5132. - profile
  5133. type: object
  5134. secretRef:
  5135. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  5136. properties:
  5137. iamEndpoint:
  5138. description: The IAM endpoint used to obain a token
  5139. type: string
  5140. secretApiKeySecretRef:
  5141. description: The SecretAccessKey is used for authentication
  5142. properties:
  5143. key:
  5144. description: |-
  5145. A key in the referenced Secret.
  5146. Some instances of this field may be defaulted, in others it may be required.
  5147. maxLength: 253
  5148. minLength: 1
  5149. pattern: ^[-._a-zA-Z0-9]+$
  5150. type: string
  5151. name:
  5152. description: The name of the Secret resource being referred to.
  5153. maxLength: 253
  5154. minLength: 1
  5155. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5156. type: string
  5157. namespace:
  5158. description: |-
  5159. The namespace of the Secret resource being referred to.
  5160. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5161. maxLength: 63
  5162. minLength: 1
  5163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5164. type: string
  5165. type: object
  5166. type: object
  5167. type: object
  5168. serviceUrl:
  5169. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  5170. type: string
  5171. required:
  5172. - auth
  5173. type: object
  5174. infisical:
  5175. description: Infisical configures this store to sync secrets using the Infisical provider
  5176. properties:
  5177. auth:
  5178. description: Auth configures how the Operator authenticates with the Infisical API
  5179. properties:
  5180. awsAuthCredentials:
  5181. description: AwsAuthCredentials represents the credentials for AWS authentication.
  5182. properties:
  5183. identityId:
  5184. description: |-
  5185. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5186. In some instances, `key` is a required field.
  5187. properties:
  5188. key:
  5189. description: |-
  5190. A key in the referenced Secret.
  5191. Some instances of this field may be defaulted, in others it may be required.
  5192. maxLength: 253
  5193. minLength: 1
  5194. pattern: ^[-._a-zA-Z0-9]+$
  5195. type: string
  5196. name:
  5197. description: The name of the Secret resource being referred to.
  5198. maxLength: 253
  5199. minLength: 1
  5200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5201. type: string
  5202. namespace:
  5203. description: |-
  5204. The namespace of the Secret resource being referred to.
  5205. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5206. maxLength: 63
  5207. minLength: 1
  5208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5209. type: string
  5210. type: object
  5211. required:
  5212. - identityId
  5213. type: object
  5214. azureAuthCredentials:
  5215. description: AzureAuthCredentials represents the credentials for Azure authentication.
  5216. properties:
  5217. identityId:
  5218. description: |-
  5219. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5220. In some instances, `key` is a required field.
  5221. properties:
  5222. key:
  5223. description: |-
  5224. A key in the referenced Secret.
  5225. Some instances of this field may be defaulted, in others it may be required.
  5226. maxLength: 253
  5227. minLength: 1
  5228. pattern: ^[-._a-zA-Z0-9]+$
  5229. type: string
  5230. name:
  5231. description: The name of the Secret resource being referred to.
  5232. maxLength: 253
  5233. minLength: 1
  5234. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5235. type: string
  5236. namespace:
  5237. description: |-
  5238. The namespace of the Secret resource being referred to.
  5239. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5240. maxLength: 63
  5241. minLength: 1
  5242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5243. type: string
  5244. type: object
  5245. resource:
  5246. description: |-
  5247. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5248. In some instances, `key` is a required field.
  5249. properties:
  5250. key:
  5251. description: |-
  5252. A key in the referenced Secret.
  5253. Some instances of this field may be defaulted, in others it may be required.
  5254. maxLength: 253
  5255. minLength: 1
  5256. pattern: ^[-._a-zA-Z0-9]+$
  5257. type: string
  5258. name:
  5259. description: The name of the Secret resource being referred to.
  5260. maxLength: 253
  5261. minLength: 1
  5262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5263. type: string
  5264. namespace:
  5265. description: |-
  5266. The namespace of the Secret resource being referred to.
  5267. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5268. maxLength: 63
  5269. minLength: 1
  5270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5271. type: string
  5272. type: object
  5273. required:
  5274. - identityId
  5275. type: object
  5276. gcpIamAuthCredentials:
  5277. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  5278. properties:
  5279. identityId:
  5280. description: |-
  5281. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5282. In some instances, `key` is a required field.
  5283. properties:
  5284. key:
  5285. description: |-
  5286. A key in the referenced Secret.
  5287. Some instances of this field may be defaulted, in others it may be required.
  5288. maxLength: 253
  5289. minLength: 1
  5290. pattern: ^[-._a-zA-Z0-9]+$
  5291. type: string
  5292. name:
  5293. description: The name of the Secret resource being referred to.
  5294. maxLength: 253
  5295. minLength: 1
  5296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5297. type: string
  5298. namespace:
  5299. description: |-
  5300. The namespace of the Secret resource being referred to.
  5301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5302. maxLength: 63
  5303. minLength: 1
  5304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5305. type: string
  5306. type: object
  5307. serviceAccountKeyFilePath:
  5308. description: |-
  5309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5310. In some instances, `key` is a required field.
  5311. properties:
  5312. key:
  5313. description: |-
  5314. A key in the referenced Secret.
  5315. Some instances of this field may be defaulted, in others it may be required.
  5316. maxLength: 253
  5317. minLength: 1
  5318. pattern: ^[-._a-zA-Z0-9]+$
  5319. type: string
  5320. name:
  5321. description: The name of the Secret resource being referred to.
  5322. maxLength: 253
  5323. minLength: 1
  5324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5325. type: string
  5326. namespace:
  5327. description: |-
  5328. The namespace of the Secret resource being referred to.
  5329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5330. maxLength: 63
  5331. minLength: 1
  5332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5333. type: string
  5334. type: object
  5335. required:
  5336. - identityId
  5337. - serviceAccountKeyFilePath
  5338. type: object
  5339. gcpIdTokenAuthCredentials:
  5340. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  5341. properties:
  5342. identityId:
  5343. description: |-
  5344. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5345. In some instances, `key` is a required field.
  5346. properties:
  5347. key:
  5348. description: |-
  5349. A key in the referenced Secret.
  5350. Some instances of this field may be defaulted, in others it may be required.
  5351. maxLength: 253
  5352. minLength: 1
  5353. pattern: ^[-._a-zA-Z0-9]+$
  5354. type: string
  5355. name:
  5356. description: The name of the Secret resource being referred to.
  5357. maxLength: 253
  5358. minLength: 1
  5359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5360. type: string
  5361. namespace:
  5362. description: |-
  5363. The namespace of the Secret resource being referred to.
  5364. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5365. maxLength: 63
  5366. minLength: 1
  5367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5368. type: string
  5369. type: object
  5370. required:
  5371. - identityId
  5372. type: object
  5373. jwtAuthCredentials:
  5374. description: JwtAuthCredentials represents the credentials for JWT authentication.
  5375. properties:
  5376. identityId:
  5377. description: |-
  5378. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5379. In some instances, `key` is a required field.
  5380. properties:
  5381. key:
  5382. description: |-
  5383. A key in the referenced Secret.
  5384. Some instances of this field may be defaulted, in others it may be required.
  5385. maxLength: 253
  5386. minLength: 1
  5387. pattern: ^[-._a-zA-Z0-9]+$
  5388. type: string
  5389. name:
  5390. description: The name of the Secret resource being referred to.
  5391. maxLength: 253
  5392. minLength: 1
  5393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5394. type: string
  5395. namespace:
  5396. description: |-
  5397. The namespace of the Secret resource being referred to.
  5398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5399. maxLength: 63
  5400. minLength: 1
  5401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5402. type: string
  5403. type: object
  5404. jwt:
  5405. description: |-
  5406. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5407. In some instances, `key` is a required field.
  5408. properties:
  5409. key:
  5410. description: |-
  5411. A key in the referenced Secret.
  5412. Some instances of this field may be defaulted, in others it may be required.
  5413. maxLength: 253
  5414. minLength: 1
  5415. pattern: ^[-._a-zA-Z0-9]+$
  5416. type: string
  5417. name:
  5418. description: The name of the Secret resource being referred to.
  5419. maxLength: 253
  5420. minLength: 1
  5421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5422. type: string
  5423. namespace:
  5424. description: |-
  5425. The namespace of the Secret resource being referred to.
  5426. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5427. maxLength: 63
  5428. minLength: 1
  5429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5430. type: string
  5431. type: object
  5432. required:
  5433. - identityId
  5434. - jwt
  5435. type: object
  5436. kubernetesAuthCredentials:
  5437. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  5438. properties:
  5439. identityId:
  5440. description: |-
  5441. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5442. In some instances, `key` is a required field.
  5443. properties:
  5444. key:
  5445. description: |-
  5446. A key in the referenced Secret.
  5447. Some instances of this field may be defaulted, in others it may be required.
  5448. maxLength: 253
  5449. minLength: 1
  5450. pattern: ^[-._a-zA-Z0-9]+$
  5451. type: string
  5452. name:
  5453. description: The name of the Secret resource being referred to.
  5454. maxLength: 253
  5455. minLength: 1
  5456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5457. type: string
  5458. namespace:
  5459. description: |-
  5460. The namespace of the Secret resource being referred to.
  5461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5462. maxLength: 63
  5463. minLength: 1
  5464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5465. type: string
  5466. type: object
  5467. serviceAccountTokenPath:
  5468. description: |-
  5469. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5470. In some instances, `key` is a required field.
  5471. properties:
  5472. key:
  5473. description: |-
  5474. A key in the referenced Secret.
  5475. Some instances of this field may be defaulted, in others it may be required.
  5476. maxLength: 253
  5477. minLength: 1
  5478. pattern: ^[-._a-zA-Z0-9]+$
  5479. type: string
  5480. name:
  5481. description: The name of the Secret resource being referred to.
  5482. maxLength: 253
  5483. minLength: 1
  5484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5485. type: string
  5486. namespace:
  5487. description: |-
  5488. The namespace of the Secret resource being referred to.
  5489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5490. maxLength: 63
  5491. minLength: 1
  5492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5493. type: string
  5494. type: object
  5495. required:
  5496. - identityId
  5497. type: object
  5498. ldapAuthCredentials:
  5499. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  5500. properties:
  5501. identityId:
  5502. description: |-
  5503. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5504. In some instances, `key` is a required field.
  5505. properties:
  5506. key:
  5507. description: |-
  5508. A key in the referenced Secret.
  5509. Some instances of this field may be defaulted, in others it may be required.
  5510. maxLength: 253
  5511. minLength: 1
  5512. pattern: ^[-._a-zA-Z0-9]+$
  5513. type: string
  5514. name:
  5515. description: The name of the Secret resource being referred to.
  5516. maxLength: 253
  5517. minLength: 1
  5518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5519. type: string
  5520. namespace:
  5521. description: |-
  5522. The namespace of the Secret resource being referred to.
  5523. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5524. maxLength: 63
  5525. minLength: 1
  5526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5527. type: string
  5528. type: object
  5529. ldapPassword:
  5530. description: |-
  5531. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5532. In some instances, `key` is a required field.
  5533. properties:
  5534. key:
  5535. description: |-
  5536. A key in the referenced Secret.
  5537. Some instances of this field may be defaulted, in others it may be required.
  5538. maxLength: 253
  5539. minLength: 1
  5540. pattern: ^[-._a-zA-Z0-9]+$
  5541. type: string
  5542. name:
  5543. description: The name of the Secret resource being referred to.
  5544. maxLength: 253
  5545. minLength: 1
  5546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5547. type: string
  5548. namespace:
  5549. description: |-
  5550. The namespace of the Secret resource being referred to.
  5551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5552. maxLength: 63
  5553. minLength: 1
  5554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5555. type: string
  5556. type: object
  5557. ldapUsername:
  5558. description: |-
  5559. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5560. In some instances, `key` is a required field.
  5561. properties:
  5562. key:
  5563. description: |-
  5564. A key in the referenced Secret.
  5565. Some instances of this field may be defaulted, in others it may be required.
  5566. maxLength: 253
  5567. minLength: 1
  5568. pattern: ^[-._a-zA-Z0-9]+$
  5569. type: string
  5570. name:
  5571. description: The name of the Secret resource being referred to.
  5572. maxLength: 253
  5573. minLength: 1
  5574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5575. type: string
  5576. namespace:
  5577. description: |-
  5578. The namespace of the Secret resource being referred to.
  5579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5580. maxLength: 63
  5581. minLength: 1
  5582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5583. type: string
  5584. type: object
  5585. required:
  5586. - identityId
  5587. - ldapPassword
  5588. - ldapUsername
  5589. type: object
  5590. ociAuthCredentials:
  5591. description: OciAuthCredentials represents the credentials for OCI authentication.
  5592. properties:
  5593. fingerprint:
  5594. description: |-
  5595. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5596. In some instances, `key` is a required field.
  5597. properties:
  5598. key:
  5599. description: |-
  5600. A key in the referenced Secret.
  5601. Some instances of this field may be defaulted, in others it may be required.
  5602. maxLength: 253
  5603. minLength: 1
  5604. pattern: ^[-._a-zA-Z0-9]+$
  5605. type: string
  5606. name:
  5607. description: The name of the Secret resource being referred to.
  5608. maxLength: 253
  5609. minLength: 1
  5610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5611. type: string
  5612. namespace:
  5613. description: |-
  5614. The namespace of the Secret resource being referred to.
  5615. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5616. maxLength: 63
  5617. minLength: 1
  5618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5619. type: string
  5620. type: object
  5621. identityId:
  5622. description: |-
  5623. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5624. In some instances, `key` is a required field.
  5625. properties:
  5626. key:
  5627. description: |-
  5628. A key in the referenced Secret.
  5629. Some instances of this field may be defaulted, in others it may be required.
  5630. maxLength: 253
  5631. minLength: 1
  5632. pattern: ^[-._a-zA-Z0-9]+$
  5633. type: string
  5634. name:
  5635. description: The name of the Secret resource being referred to.
  5636. maxLength: 253
  5637. minLength: 1
  5638. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5639. type: string
  5640. namespace:
  5641. description: |-
  5642. The namespace of the Secret resource being referred to.
  5643. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5644. maxLength: 63
  5645. minLength: 1
  5646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5647. type: string
  5648. type: object
  5649. privateKey:
  5650. description: |-
  5651. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5652. In some instances, `key` is a required field.
  5653. properties:
  5654. key:
  5655. description: |-
  5656. A key in the referenced Secret.
  5657. Some instances of this field may be defaulted, in others it may be required.
  5658. maxLength: 253
  5659. minLength: 1
  5660. pattern: ^[-._a-zA-Z0-9]+$
  5661. type: string
  5662. name:
  5663. description: The name of the Secret resource being referred to.
  5664. maxLength: 253
  5665. minLength: 1
  5666. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5667. type: string
  5668. namespace:
  5669. description: |-
  5670. The namespace of the Secret resource being referred to.
  5671. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5672. maxLength: 63
  5673. minLength: 1
  5674. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5675. type: string
  5676. type: object
  5677. privateKeyPassphrase:
  5678. description: |-
  5679. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5680. In some instances, `key` is a required field.
  5681. properties:
  5682. key:
  5683. description: |-
  5684. A key in the referenced Secret.
  5685. Some instances of this field may be defaulted, in others it may be required.
  5686. maxLength: 253
  5687. minLength: 1
  5688. pattern: ^[-._a-zA-Z0-9]+$
  5689. type: string
  5690. name:
  5691. description: The name of the Secret resource being referred to.
  5692. maxLength: 253
  5693. minLength: 1
  5694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5695. type: string
  5696. namespace:
  5697. description: |-
  5698. The namespace of the Secret resource being referred to.
  5699. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5700. maxLength: 63
  5701. minLength: 1
  5702. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5703. type: string
  5704. type: object
  5705. region:
  5706. description: |-
  5707. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5708. In some instances, `key` is a required field.
  5709. properties:
  5710. key:
  5711. description: |-
  5712. A key in the referenced Secret.
  5713. Some instances of this field may be defaulted, in others it may be required.
  5714. maxLength: 253
  5715. minLength: 1
  5716. pattern: ^[-._a-zA-Z0-9]+$
  5717. type: string
  5718. name:
  5719. description: The name of the Secret resource being referred to.
  5720. maxLength: 253
  5721. minLength: 1
  5722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5723. type: string
  5724. namespace:
  5725. description: |-
  5726. The namespace of the Secret resource being referred to.
  5727. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5728. maxLength: 63
  5729. minLength: 1
  5730. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5731. type: string
  5732. type: object
  5733. tenancyId:
  5734. description: |-
  5735. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5736. In some instances, `key` is a required field.
  5737. properties:
  5738. key:
  5739. description: |-
  5740. A key in the referenced Secret.
  5741. Some instances of this field may be defaulted, in others it may be required.
  5742. maxLength: 253
  5743. minLength: 1
  5744. pattern: ^[-._a-zA-Z0-9]+$
  5745. type: string
  5746. name:
  5747. description: The name of the Secret resource being referred to.
  5748. maxLength: 253
  5749. minLength: 1
  5750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5751. type: string
  5752. namespace:
  5753. description: |-
  5754. The namespace of the Secret resource being referred to.
  5755. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5756. maxLength: 63
  5757. minLength: 1
  5758. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5759. type: string
  5760. type: object
  5761. userId:
  5762. description: |-
  5763. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5764. In some instances, `key` is a required field.
  5765. properties:
  5766. key:
  5767. description: |-
  5768. A key in the referenced Secret.
  5769. Some instances of this field may be defaulted, in others it may be required.
  5770. maxLength: 253
  5771. minLength: 1
  5772. pattern: ^[-._a-zA-Z0-9]+$
  5773. type: string
  5774. name:
  5775. description: The name of the Secret resource being referred to.
  5776. maxLength: 253
  5777. minLength: 1
  5778. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5779. type: string
  5780. namespace:
  5781. description: |-
  5782. The namespace of the Secret resource being referred to.
  5783. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5784. maxLength: 63
  5785. minLength: 1
  5786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5787. type: string
  5788. type: object
  5789. required:
  5790. - fingerprint
  5791. - identityId
  5792. - privateKey
  5793. - region
  5794. - tenancyId
  5795. - userId
  5796. type: object
  5797. tokenAuthCredentials:
  5798. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  5799. properties:
  5800. accessToken:
  5801. description: |-
  5802. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5803. In some instances, `key` is a required field.
  5804. properties:
  5805. key:
  5806. description: |-
  5807. A key in the referenced Secret.
  5808. Some instances of this field may be defaulted, in others it may be required.
  5809. maxLength: 253
  5810. minLength: 1
  5811. pattern: ^[-._a-zA-Z0-9]+$
  5812. type: string
  5813. name:
  5814. description: The name of the Secret resource being referred to.
  5815. maxLength: 253
  5816. minLength: 1
  5817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5818. type: string
  5819. namespace:
  5820. description: |-
  5821. The namespace of the Secret resource being referred to.
  5822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5823. maxLength: 63
  5824. minLength: 1
  5825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5826. type: string
  5827. type: object
  5828. required:
  5829. - accessToken
  5830. type: object
  5831. universalAuthCredentials:
  5832. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  5833. properties:
  5834. clientId:
  5835. description: |-
  5836. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5837. In some instances, `key` is a required field.
  5838. properties:
  5839. key:
  5840. description: |-
  5841. A key in the referenced Secret.
  5842. Some instances of this field may be defaulted, in others it may be required.
  5843. maxLength: 253
  5844. minLength: 1
  5845. pattern: ^[-._a-zA-Z0-9]+$
  5846. type: string
  5847. name:
  5848. description: The name of the Secret resource being referred to.
  5849. maxLength: 253
  5850. minLength: 1
  5851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5852. type: string
  5853. namespace:
  5854. description: |-
  5855. The namespace of the Secret resource being referred to.
  5856. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5857. maxLength: 63
  5858. minLength: 1
  5859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5860. type: string
  5861. type: object
  5862. clientSecret:
  5863. description: |-
  5864. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5865. In some instances, `key` is a required field.
  5866. properties:
  5867. key:
  5868. description: |-
  5869. A key in the referenced Secret.
  5870. Some instances of this field may be defaulted, in others it may be required.
  5871. maxLength: 253
  5872. minLength: 1
  5873. pattern: ^[-._a-zA-Z0-9]+$
  5874. type: string
  5875. name:
  5876. description: The name of the Secret resource being referred to.
  5877. maxLength: 253
  5878. minLength: 1
  5879. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5880. type: string
  5881. namespace:
  5882. description: |-
  5883. The namespace of the Secret resource being referred to.
  5884. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5885. maxLength: 63
  5886. minLength: 1
  5887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5888. type: string
  5889. type: object
  5890. required:
  5891. - clientId
  5892. - clientSecret
  5893. type: object
  5894. type: object
  5895. caBundle:
  5896. description: |-
  5897. CABundle is a PEM-encoded CA certificate bundle used to validate
  5898. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  5899. format: byte
  5900. type: string
  5901. caProvider:
  5902. description: |-
  5903. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  5904. The certificate is used to validate the Infisical server's TLS certificate.
  5905. Mutually exclusive with CABundle.
  5906. properties:
  5907. key:
  5908. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[-._a-zA-Z0-9]+$
  5912. type: string
  5913. name:
  5914. description: The name of the object located at the provider type.
  5915. maxLength: 253
  5916. minLength: 1
  5917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5918. type: string
  5919. namespace:
  5920. description: |-
  5921. The namespace the Provider type is in.
  5922. Can only be defined when used in a ClusterSecretStore.
  5923. maxLength: 63
  5924. minLength: 1
  5925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5926. type: string
  5927. type:
  5928. description: The type of provider to use such as "Secret", or "ConfigMap".
  5929. enum:
  5930. - Secret
  5931. - ConfigMap
  5932. type: string
  5933. required:
  5934. - name
  5935. - type
  5936. type: object
  5937. hostAPI:
  5938. default: https://app.infisical.com/api
  5939. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  5940. type: string
  5941. secretsScope:
  5942. description: SecretsScope defines the scope of the secrets within the workspace
  5943. properties:
  5944. environmentSlug:
  5945. description: EnvironmentSlug is the required slug identifier for the environment.
  5946. type: string
  5947. expandSecretReferences:
  5948. default: true
  5949. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  5950. type: boolean
  5951. organizationSlug:
  5952. description: |-
  5953. OrganizationSlug is the optional slug that identifies the organization that will be used
  5954. during authentication. Useful for sub-organization setups
  5955. type: string
  5956. projectSlug:
  5957. description: ProjectSlug is the required slug identifier for the project.
  5958. type: string
  5959. recursive:
  5960. default: false
  5961. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  5962. type: boolean
  5963. secretsPath:
  5964. default: /
  5965. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  5966. type: string
  5967. required:
  5968. - environmentSlug
  5969. - projectSlug
  5970. type: object
  5971. required:
  5972. - auth
  5973. - secretsScope
  5974. type: object
  5975. keepersecurity:
  5976. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  5977. properties:
  5978. authRef:
  5979. description: |-
  5980. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  5981. In some instances, `key` is a required field.
  5982. properties:
  5983. key:
  5984. description: |-
  5985. A key in the referenced Secret.
  5986. Some instances of this field may be defaulted, in others it may be required.
  5987. maxLength: 253
  5988. minLength: 1
  5989. pattern: ^[-._a-zA-Z0-9]+$
  5990. type: string
  5991. name:
  5992. description: The name of the Secret resource being referred to.
  5993. maxLength: 253
  5994. minLength: 1
  5995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5996. type: string
  5997. namespace:
  5998. description: |-
  5999. The namespace of the Secret resource being referred to.
  6000. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6001. maxLength: 63
  6002. minLength: 1
  6003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6004. type: string
  6005. type: object
  6006. folderID:
  6007. type: string
  6008. getByTitleFallback:
  6009. type: boolean
  6010. required:
  6011. - authRef
  6012. - folderID
  6013. type: object
  6014. kubernetes:
  6015. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  6016. properties:
  6017. auth:
  6018. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  6019. maxProperties: 1
  6020. minProperties: 1
  6021. properties:
  6022. cert:
  6023. description: has both clientCert and clientKey as secretKeySelector
  6024. properties:
  6025. clientCert:
  6026. description: |-
  6027. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6028. In some instances, `key` is a required field.
  6029. properties:
  6030. key:
  6031. description: |-
  6032. A key in the referenced Secret.
  6033. Some instances of this field may be defaulted, in others it may be required.
  6034. maxLength: 253
  6035. minLength: 1
  6036. pattern: ^[-._a-zA-Z0-9]+$
  6037. type: string
  6038. name:
  6039. description: The name of the Secret resource being referred to.
  6040. maxLength: 253
  6041. minLength: 1
  6042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6043. type: string
  6044. namespace:
  6045. description: |-
  6046. The namespace of the Secret resource being referred to.
  6047. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6048. maxLength: 63
  6049. minLength: 1
  6050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6051. type: string
  6052. type: object
  6053. clientKey:
  6054. description: |-
  6055. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6056. In some instances, `key` is a required field.
  6057. properties:
  6058. key:
  6059. description: |-
  6060. A key in the referenced Secret.
  6061. Some instances of this field may be defaulted, in others it may be required.
  6062. maxLength: 253
  6063. minLength: 1
  6064. pattern: ^[-._a-zA-Z0-9]+$
  6065. type: string
  6066. name:
  6067. description: The name of the Secret resource being referred to.
  6068. maxLength: 253
  6069. minLength: 1
  6070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6071. type: string
  6072. namespace:
  6073. description: |-
  6074. The namespace of the Secret resource being referred to.
  6075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6076. maxLength: 63
  6077. minLength: 1
  6078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6079. type: string
  6080. type: object
  6081. required:
  6082. - clientCert
  6083. - clientKey
  6084. type: object
  6085. serviceAccount:
  6086. description: points to a service account that should be used for authentication
  6087. properties:
  6088. audiences:
  6089. description: |-
  6090. Audience specifies the `aud` claim for the service account token
  6091. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6092. then this audiences will be appended to the list
  6093. items:
  6094. type: string
  6095. type: array
  6096. name:
  6097. description: The name of the ServiceAccount resource being referred to.
  6098. maxLength: 253
  6099. minLength: 1
  6100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6101. type: string
  6102. namespace:
  6103. description: |-
  6104. Namespace of the resource being referred to.
  6105. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6106. maxLength: 63
  6107. minLength: 1
  6108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6109. type: string
  6110. required:
  6111. - name
  6112. type: object
  6113. token:
  6114. description: use static token to authenticate with
  6115. properties:
  6116. bearerToken:
  6117. description: |-
  6118. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6119. In some instances, `key` is a required field.
  6120. properties:
  6121. key:
  6122. description: |-
  6123. A key in the referenced Secret.
  6124. Some instances of this field may be defaulted, in others it may be required.
  6125. maxLength: 253
  6126. minLength: 1
  6127. pattern: ^[-._a-zA-Z0-9]+$
  6128. type: string
  6129. name:
  6130. description: The name of the Secret resource being referred to.
  6131. maxLength: 253
  6132. minLength: 1
  6133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6134. type: string
  6135. namespace:
  6136. description: |-
  6137. The namespace of the Secret resource being referred to.
  6138. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6139. maxLength: 63
  6140. minLength: 1
  6141. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6142. type: string
  6143. type: object
  6144. required:
  6145. - bearerToken
  6146. type: object
  6147. type: object
  6148. authRef:
  6149. description: A reference to a secret that contains the auth information.
  6150. properties:
  6151. key:
  6152. description: |-
  6153. A key in the referenced Secret.
  6154. Some instances of this field may be defaulted, in others it may be required.
  6155. maxLength: 253
  6156. minLength: 1
  6157. pattern: ^[-._a-zA-Z0-9]+$
  6158. type: string
  6159. name:
  6160. description: The name of the Secret resource being referred to.
  6161. maxLength: 253
  6162. minLength: 1
  6163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6164. type: string
  6165. namespace:
  6166. description: |-
  6167. The namespace of the Secret resource being referred to.
  6168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6169. maxLength: 63
  6170. minLength: 1
  6171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6172. type: string
  6173. type: object
  6174. remoteNamespace:
  6175. default: default
  6176. description: Remote namespace to fetch the secrets from
  6177. maxLength: 63
  6178. minLength: 1
  6179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6180. type: string
  6181. server:
  6182. description: configures the Kubernetes server Address.
  6183. properties:
  6184. caBundle:
  6185. description: CABundle is a base64-encoded CA certificate
  6186. format: byte
  6187. type: string
  6188. caProvider:
  6189. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  6190. properties:
  6191. key:
  6192. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6193. maxLength: 253
  6194. minLength: 1
  6195. pattern: ^[-._a-zA-Z0-9]+$
  6196. type: string
  6197. name:
  6198. description: The name of the object located at the provider type.
  6199. maxLength: 253
  6200. minLength: 1
  6201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6202. type: string
  6203. namespace:
  6204. description: |-
  6205. The namespace the Provider type is in.
  6206. Can only be defined when used in a ClusterSecretStore.
  6207. maxLength: 63
  6208. minLength: 1
  6209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6210. type: string
  6211. type:
  6212. description: The type of provider to use such as "Secret", or "ConfigMap".
  6213. enum:
  6214. - Secret
  6215. - ConfigMap
  6216. type: string
  6217. required:
  6218. - name
  6219. - type
  6220. type: object
  6221. url:
  6222. default: kubernetes.default
  6223. description: configures the Kubernetes server Address.
  6224. type: string
  6225. type: object
  6226. type: object
  6227. nebiusmysterybox:
  6228. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  6229. properties:
  6230. apiDomain:
  6231. description: NebiusMysterybox API endpoint
  6232. type: string
  6233. auth:
  6234. description: Auth defines parameters to authenticate in MysteryBox
  6235. properties:
  6236. serviceAccountCredsSecretRef:
  6237. description: |-
  6238. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  6239. document with service account credentials used to get an IAM token.
  6240. Expected JSON structure:
  6241. {
  6242. "subject-credentials": {
  6243. "alg": "RS256",
  6244. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  6245. "kid": "<public-key-id>",
  6246. "iss": "<issuer-service-account-id>",
  6247. "sub": "<subject-service-account-id>"
  6248. }
  6249. }
  6250. properties:
  6251. key:
  6252. description: |-
  6253. A key in the referenced Secret.
  6254. Some instances of this field may be defaulted, in others it may be required.
  6255. maxLength: 253
  6256. minLength: 1
  6257. pattern: ^[-._a-zA-Z0-9]+$
  6258. type: string
  6259. name:
  6260. description: The name of the Secret resource being referred to.
  6261. maxLength: 253
  6262. minLength: 1
  6263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6264. type: string
  6265. namespace:
  6266. description: |-
  6267. The namespace of the Secret resource being referred to.
  6268. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6269. maxLength: 63
  6270. minLength: 1
  6271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6272. type: string
  6273. type: object
  6274. tokenSecretRef:
  6275. description: Token authenticates with Nebius Mysterybox by presenting a token.
  6276. properties:
  6277. key:
  6278. description: |-
  6279. A key in the referenced Secret.
  6280. Some instances of this field may be defaulted, in others it may be required.
  6281. maxLength: 253
  6282. minLength: 1
  6283. pattern: ^[-._a-zA-Z0-9]+$
  6284. type: string
  6285. name:
  6286. description: The name of the Secret resource being referred to.
  6287. maxLength: 253
  6288. minLength: 1
  6289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6290. type: string
  6291. namespace:
  6292. description: |-
  6293. The namespace of the Secret resource being referred to.
  6294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6295. maxLength: 63
  6296. minLength: 1
  6297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6298. type: string
  6299. type: object
  6300. type: object
  6301. x-kubernetes-validations:
  6302. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  6303. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  6304. caProvider:
  6305. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  6306. properties:
  6307. certSecretRef:
  6308. description: |-
  6309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  6310. In some instances, `key` is a required field.
  6311. properties:
  6312. key:
  6313. description: |-
  6314. A key in the referenced Secret.
  6315. Some instances of this field may be defaulted, in others it may be required.
  6316. maxLength: 253
  6317. minLength: 1
  6318. pattern: ^[-._a-zA-Z0-9]+$
  6319. type: string
  6320. name:
  6321. description: The name of the Secret resource being referred to.
  6322. maxLength: 253
  6323. minLength: 1
  6324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6325. type: string
  6326. namespace:
  6327. description: |-
  6328. The namespace of the Secret resource being referred to.
  6329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6330. maxLength: 63
  6331. minLength: 1
  6332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6333. type: string
  6334. type: object
  6335. type: object
  6336. required:
  6337. - apiDomain
  6338. - auth
  6339. type: object
  6340. ngrok:
  6341. description: Ngrok configures this store to sync secrets using the ngrok provider.
  6342. properties:
  6343. apiUrl:
  6344. default: https://api.ngrok.com
  6345. description: APIURL is the URL of the ngrok API.
  6346. type: string
  6347. auth:
  6348. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  6349. maxProperties: 1
  6350. minProperties: 1
  6351. properties:
  6352. apiKey:
  6353. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  6354. properties:
  6355. secretRef:
  6356. description: SecretRef is a reference to a secret containing the ngrok API key.
  6357. properties:
  6358. key:
  6359. description: |-
  6360. A key in the referenced Secret.
  6361. Some instances of this field may be defaulted, in others it may be required.
  6362. maxLength: 253
  6363. minLength: 1
  6364. pattern: ^[-._a-zA-Z0-9]+$
  6365. type: string
  6366. name:
  6367. description: The name of the Secret resource being referred to.
  6368. maxLength: 253
  6369. minLength: 1
  6370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6371. type: string
  6372. namespace:
  6373. description: |-
  6374. The namespace of the Secret resource being referred to.
  6375. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6376. maxLength: 63
  6377. minLength: 1
  6378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6379. type: string
  6380. type: object
  6381. type: object
  6382. type: object
  6383. vault:
  6384. description: Vault configures the ngrok vault to sync secrets with.
  6385. properties:
  6386. name:
  6387. description: Name is the name of the ngrok vault to sync secrets with.
  6388. type: string
  6389. required:
  6390. - name
  6391. type: object
  6392. required:
  6393. - auth
  6394. - vault
  6395. type: object
  6396. onboardbase:
  6397. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  6398. properties:
  6399. apiHost:
  6400. default: https://public.onboardbase.com/api/v1/
  6401. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  6402. type: string
  6403. auth:
  6404. description: Auth configures how the Operator authenticates with the Onboardbase API
  6405. properties:
  6406. apiKeyRef:
  6407. description: |-
  6408. OnboardbaseAPIKey is the APIKey generated by an admin account.
  6409. It is used to recognize and authorize access to a project and environment within onboardbase
  6410. properties:
  6411. key:
  6412. description: |-
  6413. A key in the referenced Secret.
  6414. Some instances of this field may be defaulted, in others it may be required.
  6415. maxLength: 253
  6416. minLength: 1
  6417. pattern: ^[-._a-zA-Z0-9]+$
  6418. type: string
  6419. name:
  6420. description: The name of the Secret resource being referred to.
  6421. maxLength: 253
  6422. minLength: 1
  6423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6424. type: string
  6425. namespace:
  6426. description: |-
  6427. The namespace of the Secret resource being referred to.
  6428. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6429. maxLength: 63
  6430. minLength: 1
  6431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6432. type: string
  6433. type: object
  6434. passcodeRef:
  6435. description: OnboardbasePasscode is the passcode attached to the API Key
  6436. properties:
  6437. key:
  6438. description: |-
  6439. A key in the referenced Secret.
  6440. Some instances of this field may be defaulted, in others it may be required.
  6441. maxLength: 253
  6442. minLength: 1
  6443. pattern: ^[-._a-zA-Z0-9]+$
  6444. type: string
  6445. name:
  6446. description: The name of the Secret resource being referred to.
  6447. maxLength: 253
  6448. minLength: 1
  6449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6450. type: string
  6451. namespace:
  6452. description: |-
  6453. The namespace of the Secret resource being referred to.
  6454. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6455. maxLength: 63
  6456. minLength: 1
  6457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6458. type: string
  6459. type: object
  6460. required:
  6461. - apiKeyRef
  6462. - passcodeRef
  6463. type: object
  6464. environment:
  6465. default: development
  6466. description: Environment is the name of an environmnent within a project to pull the secrets from
  6467. type: string
  6468. project:
  6469. default: development
  6470. description: Project is an onboardbase project that the secrets should be pulled from
  6471. type: string
  6472. required:
  6473. - apiHost
  6474. - auth
  6475. - environment
  6476. - project
  6477. type: object
  6478. onepassword:
  6479. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  6480. properties:
  6481. auth:
  6482. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  6483. properties:
  6484. secretRef:
  6485. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  6486. properties:
  6487. connectTokenSecretRef:
  6488. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  6489. properties:
  6490. key:
  6491. description: |-
  6492. A key in the referenced Secret.
  6493. Some instances of this field may be defaulted, in others it may be required.
  6494. maxLength: 253
  6495. minLength: 1
  6496. pattern: ^[-._a-zA-Z0-9]+$
  6497. type: string
  6498. name:
  6499. description: The name of the Secret resource being referred to.
  6500. maxLength: 253
  6501. minLength: 1
  6502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6503. type: string
  6504. namespace:
  6505. description: |-
  6506. The namespace of the Secret resource being referred to.
  6507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6508. maxLength: 63
  6509. minLength: 1
  6510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6511. type: string
  6512. type: object
  6513. required:
  6514. - connectTokenSecretRef
  6515. type: object
  6516. required:
  6517. - secretRef
  6518. type: object
  6519. connectHost:
  6520. description: ConnectHost defines the OnePassword Connect Server to connect to
  6521. type: string
  6522. vaults:
  6523. additionalProperties:
  6524. type: integer
  6525. description: Vaults defines which OnePassword vaults to search in which order
  6526. type: object
  6527. required:
  6528. - auth
  6529. - connectHost
  6530. - vaults
  6531. type: object
  6532. onepasswordSDK:
  6533. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  6534. properties:
  6535. auth:
  6536. description: Auth defines the information necessary to authenticate against OnePassword API.
  6537. properties:
  6538. serviceAccountSecretRef:
  6539. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  6540. properties:
  6541. key:
  6542. description: |-
  6543. A key in the referenced Secret.
  6544. Some instances of this field may be defaulted, in others it may be required.
  6545. maxLength: 253
  6546. minLength: 1
  6547. pattern: ^[-._a-zA-Z0-9]+$
  6548. type: string
  6549. name:
  6550. description: The name of the Secret resource being referred to.
  6551. maxLength: 253
  6552. minLength: 1
  6553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6554. type: string
  6555. namespace:
  6556. description: |-
  6557. The namespace of the Secret resource being referred to.
  6558. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6559. maxLength: 63
  6560. minLength: 1
  6561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6562. type: string
  6563. type: object
  6564. required:
  6565. - serviceAccountSecretRef
  6566. type: object
  6567. cache:
  6568. description: |-
  6569. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  6570. When enabled, secrets are cached with the specified TTL.
  6571. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  6572. If omitted, caching is disabled (default).
  6573. cache: {} is a valid option to set.
  6574. properties:
  6575. maxSize:
  6576. default: 100
  6577. description: |-
  6578. MaxSize is the maximum number of secrets to cache.
  6579. When the cache is full, least-recently-used entries are evicted.
  6580. minimum: 1
  6581. type: integer
  6582. ttl:
  6583. default: 5m
  6584. description: |-
  6585. TTL is the time-to-live for cached secrets.
  6586. Format: duration string (e.g., "5m", "1h", "30s")
  6587. type: string
  6588. type: object
  6589. environment:
  6590. description: |-
  6591. Environment defines the 1Password Environment ID to read variables from.
  6592. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  6593. Mutually exclusive with Vault.
  6594. type: string
  6595. integrationInfo:
  6596. description: |-
  6597. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  6598. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  6599. properties:
  6600. name:
  6601. default: 1Password SDK
  6602. description: Name defaults to "1Password SDK".
  6603. type: string
  6604. version:
  6605. default: v1.0.0
  6606. description: Version defaults to "v1.0.0".
  6607. type: string
  6608. type: object
  6609. vault:
  6610. description: |-
  6611. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  6612. Mutually exclusive with Environment.
  6613. type: string
  6614. required:
  6615. - auth
  6616. type: object
  6617. x-kubernetes-validations:
  6618. - message: at most one of the fields in [vault environment] may be set
  6619. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  6620. openBao:
  6621. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  6622. properties:
  6623. auth:
  6624. description: Auth configures how secret-manager authenticates with the OpenBao server.
  6625. properties:
  6626. appRole:
  6627. description: |-
  6628. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  6629. with the role and secret stored in a Kubernetes Secret resource.
  6630. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  6631. properties:
  6632. path:
  6633. default: approle
  6634. description: |-
  6635. Path where the App Role authentication backend is mounted
  6636. in OpenBao, e.g: "approle"
  6637. type: string
  6638. roleId:
  6639. description: |-
  6640. RoleID configured in the App Role authentication backend when setting
  6641. up the authentication backend in OpenBao.
  6642. minLength: 1
  6643. type: string
  6644. roleRef:
  6645. description: |-
  6646. Reference to a key in a Secret that contains the App Role ID used
  6647. to authenticate with OpenBao.
  6648. The `key` field must be specified and denotes which entry within the Secret
  6649. resource is used as the app role id.
  6650. properties:
  6651. key:
  6652. description: |-
  6653. A key in the referenced Secret.
  6654. Some instances of this field may be defaulted, in others it may be required.
  6655. maxLength: 253
  6656. minLength: 1
  6657. pattern: ^[-._a-zA-Z0-9]+$
  6658. type: string
  6659. name:
  6660. description: The name of the Secret resource being referred to.
  6661. maxLength: 253
  6662. minLength: 1
  6663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6664. type: string
  6665. namespace:
  6666. description: |-
  6667. The namespace of the Secret resource being referred to.
  6668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6669. maxLength: 63
  6670. minLength: 1
  6671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6672. type: string
  6673. type: object
  6674. secretRef:
  6675. description: |-
  6676. Reference to a key in a Secret that contains the App Role secret used
  6677. to authenticate with OpenBao.
  6678. The `key` field must be specified and denotes which entry within the Secret
  6679. resource is used as the app role secret.
  6680. properties:
  6681. key:
  6682. description: |-
  6683. A key in the referenced Secret.
  6684. Some instances of this field may be defaulted, in others it may be required.
  6685. maxLength: 253
  6686. minLength: 1
  6687. pattern: ^[-._a-zA-Z0-9]+$
  6688. type: string
  6689. name:
  6690. description: The name of the Secret resource being referred to.
  6691. maxLength: 253
  6692. minLength: 1
  6693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6694. type: string
  6695. namespace:
  6696. description: |-
  6697. The namespace of the Secret resource being referred to.
  6698. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6699. maxLength: 63
  6700. minLength: 1
  6701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6702. type: string
  6703. type: object
  6704. required:
  6705. - path
  6706. - secretRef
  6707. type: object
  6708. x-kubernetes-validations:
  6709. - message: exactly one of the fields in [roleId roleRef] must be set
  6710. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  6711. namespace:
  6712. description: |-
  6713. Name of the [OpenBao Namespace] to authenticate to. This can be different
  6714. than the namespace your secret is in. Namespaces is a set of features
  6715. within OpenBao that allows OpenBao environments to support secure
  6716. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  6717. if set, or empty otherwise
  6718. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6719. type: string
  6720. tokenSecretRef:
  6721. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  6722. properties:
  6723. key:
  6724. description: |-
  6725. A key in the referenced Secret.
  6726. Some instances of this field may be defaulted, in others it may be required.
  6727. maxLength: 253
  6728. minLength: 1
  6729. pattern: ^[-._a-zA-Z0-9]+$
  6730. type: string
  6731. name:
  6732. description: The name of the Secret resource being referred to.
  6733. maxLength: 253
  6734. minLength: 1
  6735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6736. type: string
  6737. namespace:
  6738. description: |-
  6739. The namespace of the Secret resource being referred to.
  6740. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6741. maxLength: 63
  6742. minLength: 1
  6743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6744. type: string
  6745. type: object
  6746. userPass:
  6747. description: UserPass authenticates with OpenBao by passing a username/password pair
  6748. properties:
  6749. path:
  6750. default: userpass
  6751. description: |-
  6752. Path where the UserPassword authentication backend is mounted
  6753. in OpenBao, e.g: "userpass"
  6754. type: string
  6755. secretRef:
  6756. description: |-
  6757. SecretRef to a key in a Secret resource containing password for the user
  6758. used to authenticate with OpenBao using the [UserPass authentication
  6759. method]
  6760. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6761. properties:
  6762. key:
  6763. description: |-
  6764. A key in the referenced Secret.
  6765. Some instances of this field may be defaulted, in others it may be required.
  6766. maxLength: 253
  6767. minLength: 1
  6768. pattern: ^[-._a-zA-Z0-9]+$
  6769. type: string
  6770. name:
  6771. description: The name of the Secret resource being referred to.
  6772. maxLength: 253
  6773. minLength: 1
  6774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6775. type: string
  6776. namespace:
  6777. description: |-
  6778. The namespace of the Secret resource being referred to.
  6779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6780. maxLength: 63
  6781. minLength: 1
  6782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6783. type: string
  6784. type: object
  6785. username:
  6786. description: |-
  6787. Username is a username used to authenticate using the [UserPass
  6788. authentication method]
  6789. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  6790. type: string
  6791. required:
  6792. - path
  6793. - username
  6794. type: object
  6795. type: object
  6796. x-kubernetes-validations:
  6797. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  6798. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  6799. caBundle:
  6800. description: |-
  6801. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  6802. this and `caProvider` are not set the system root certificates are used
  6803. to validate the TLS connection.
  6804. format: byte
  6805. type: string
  6806. caProvider:
  6807. description: |-
  6808. The provider for the CA bundle to use to validate OpenBao server
  6809. certificate. If this and `caBundle` are not set the system root
  6810. certificates are used to validate the TLS connection.
  6811. properties:
  6812. key:
  6813. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6814. maxLength: 253
  6815. minLength: 1
  6816. pattern: ^[-._a-zA-Z0-9]+$
  6817. type: string
  6818. name:
  6819. description: The name of the object located at the provider type.
  6820. maxLength: 253
  6821. minLength: 1
  6822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6823. type: string
  6824. namespace:
  6825. description: |-
  6826. The namespace the Provider type is in.
  6827. Can only be defined when used in a ClusterSecretStore.
  6828. maxLength: 63
  6829. minLength: 1
  6830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6831. type: string
  6832. type:
  6833. description: The type of provider to use such as "Secret", or "ConfigMap".
  6834. enum:
  6835. - Secret
  6836. - ConfigMap
  6837. type: string
  6838. required:
  6839. - name
  6840. - type
  6841. type: object
  6842. namespace:
  6843. description: |-
  6844. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  6845. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  6846. e.g: "ns1".
  6847. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  6848. type: string
  6849. path:
  6850. description: |-
  6851. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  6852. "secret". The v2 KV secret engine version specific "/data" path suffix
  6853. for fetching secrets from OpenBao is optional and will be appended
  6854. if not present in specified path.
  6855. type: string
  6856. server:
  6857. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  6858. type: string
  6859. version:
  6860. default: v2
  6861. description: |-
  6862. Version is the OpenBao KV secret engine version. This can be either "v1" or
  6863. "v2". Version defaults to "v2".
  6864. enum:
  6865. - v1
  6866. - v2
  6867. type: string
  6868. required:
  6869. - server
  6870. type: object
  6871. x-kubernetes-validations:
  6872. - message: at most one of the fields in [caBundle caProvider] may be set
  6873. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  6874. oracle:
  6875. description: Oracle configures this store to sync secrets using Oracle Vault provider
  6876. properties:
  6877. auth:
  6878. description: |-
  6879. Auth configures how secret-manager authenticates with the Oracle Vault.
  6880. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  6881. properties:
  6882. secretRef:
  6883. description: SecretRef to pass through sensitive information.
  6884. properties:
  6885. fingerprint:
  6886. description: Fingerprint is the fingerprint of the API private key.
  6887. properties:
  6888. key:
  6889. description: |-
  6890. A key in the referenced Secret.
  6891. Some instances of this field may be defaulted, in others it may be required.
  6892. maxLength: 253
  6893. minLength: 1
  6894. pattern: ^[-._a-zA-Z0-9]+$
  6895. type: string
  6896. name:
  6897. description: The name of the Secret resource being referred to.
  6898. maxLength: 253
  6899. minLength: 1
  6900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6901. type: string
  6902. namespace:
  6903. description: |-
  6904. The namespace of the Secret resource being referred to.
  6905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6906. maxLength: 63
  6907. minLength: 1
  6908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6909. type: string
  6910. type: object
  6911. privatekey:
  6912. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  6913. properties:
  6914. key:
  6915. description: |-
  6916. A key in the referenced Secret.
  6917. Some instances of this field may be defaulted, in others it may be required.
  6918. maxLength: 253
  6919. minLength: 1
  6920. pattern: ^[-._a-zA-Z0-9]+$
  6921. type: string
  6922. name:
  6923. description: The name of the Secret resource being referred to.
  6924. maxLength: 253
  6925. minLength: 1
  6926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6927. type: string
  6928. namespace:
  6929. description: |-
  6930. The namespace of the Secret resource being referred to.
  6931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6932. maxLength: 63
  6933. minLength: 1
  6934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6935. type: string
  6936. type: object
  6937. required:
  6938. - fingerprint
  6939. - privatekey
  6940. type: object
  6941. tenancy:
  6942. description: Tenancy is the tenancy OCID where user is located.
  6943. type: string
  6944. user:
  6945. description: User is an access OCID specific to the account.
  6946. type: string
  6947. required:
  6948. - secretRef
  6949. - tenancy
  6950. - user
  6951. type: object
  6952. compartment:
  6953. description: |-
  6954. Compartment is the vault compartment OCID.
  6955. Required for PushSecret
  6956. type: string
  6957. encryptionKey:
  6958. description: |-
  6959. EncryptionKey is the OCID of the encryption key within the vault.
  6960. Required for PushSecret
  6961. type: string
  6962. principalType:
  6963. description: |-
  6964. The type of principal to use for authentication. If left blank, the Auth struct will
  6965. determine the principal type. This optional field must be specified if using
  6966. workload identity.
  6967. enum:
  6968. - ""
  6969. - UserPrincipal
  6970. - InstancePrincipal
  6971. - Workload
  6972. type: string
  6973. region:
  6974. description: Region is the region where vault is located.
  6975. type: string
  6976. serviceAccountRef:
  6977. description: |-
  6978. ServiceAccountRef specified the service account
  6979. that should be used when authenticating with WorkloadIdentity.
  6980. properties:
  6981. audiences:
  6982. description: |-
  6983. Audience specifies the `aud` claim for the service account token
  6984. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  6985. then this audiences will be appended to the list
  6986. items:
  6987. type: string
  6988. type: array
  6989. name:
  6990. description: The name of the ServiceAccount resource being referred to.
  6991. maxLength: 253
  6992. minLength: 1
  6993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6994. type: string
  6995. namespace:
  6996. description: |-
  6997. Namespace of the resource being referred to.
  6998. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6999. maxLength: 63
  7000. minLength: 1
  7001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7002. type: string
  7003. required:
  7004. - name
  7005. type: object
  7006. vault:
  7007. description: Vault is the vault's OCID of the specific vault where secret is located.
  7008. type: string
  7009. required:
  7010. - region
  7011. - vault
  7012. type: object
  7013. ovh:
  7014. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  7015. properties:
  7016. auth:
  7017. description: Authentication method (mtls or token).
  7018. properties:
  7019. mtls:
  7020. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  7021. properties:
  7022. caBundle:
  7023. format: byte
  7024. type: string
  7025. caProvider:
  7026. description: |-
  7027. CAProvider provides a custom certificate authority for accessing the provider's store.
  7028. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  7029. properties:
  7030. key:
  7031. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7032. maxLength: 253
  7033. minLength: 1
  7034. pattern: ^[-._a-zA-Z0-9]+$
  7035. type: string
  7036. name:
  7037. description: The name of the object located at the provider type.
  7038. maxLength: 253
  7039. minLength: 1
  7040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7041. type: string
  7042. namespace:
  7043. description: |-
  7044. The namespace the Provider type is in.
  7045. Can only be defined when used in a ClusterSecretStore.
  7046. maxLength: 63
  7047. minLength: 1
  7048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7049. type: string
  7050. type:
  7051. description: The type of provider to use such as "Secret", or "ConfigMap".
  7052. enum:
  7053. - Secret
  7054. - ConfigMap
  7055. type: string
  7056. required:
  7057. - name
  7058. - type
  7059. type: object
  7060. certSecretRef:
  7061. description: |-
  7062. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7063. In some instances, `key` is a required field.
  7064. properties:
  7065. key:
  7066. description: |-
  7067. A key in the referenced Secret.
  7068. Some instances of this field may be defaulted, in others it may be required.
  7069. maxLength: 253
  7070. minLength: 1
  7071. pattern: ^[-._a-zA-Z0-9]+$
  7072. type: string
  7073. name:
  7074. description: The name of the Secret resource being referred to.
  7075. maxLength: 253
  7076. minLength: 1
  7077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7078. type: string
  7079. namespace:
  7080. description: |-
  7081. The namespace of the Secret resource being referred to.
  7082. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7083. maxLength: 63
  7084. minLength: 1
  7085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7086. type: string
  7087. type: object
  7088. keySecretRef:
  7089. description: |-
  7090. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7091. In some instances, `key` is a required field.
  7092. properties:
  7093. key:
  7094. description: |-
  7095. A key in the referenced Secret.
  7096. Some instances of this field may be defaulted, in others it may be required.
  7097. maxLength: 253
  7098. minLength: 1
  7099. pattern: ^[-._a-zA-Z0-9]+$
  7100. type: string
  7101. name:
  7102. description: The name of the Secret resource being referred to.
  7103. maxLength: 253
  7104. minLength: 1
  7105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7106. type: string
  7107. namespace:
  7108. description: |-
  7109. The namespace of the Secret resource being referred to.
  7110. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7111. maxLength: 63
  7112. minLength: 1
  7113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7114. type: string
  7115. type: object
  7116. required:
  7117. - certSecretRef
  7118. - keySecretRef
  7119. type: object
  7120. token:
  7121. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  7122. properties:
  7123. tokenSecretRef:
  7124. description: |-
  7125. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7126. In some instances, `key` is a required field.
  7127. properties:
  7128. key:
  7129. description: |-
  7130. A key in the referenced Secret.
  7131. Some instances of this field may be defaulted, in others it may be required.
  7132. maxLength: 253
  7133. minLength: 1
  7134. pattern: ^[-._a-zA-Z0-9]+$
  7135. type: string
  7136. name:
  7137. description: The name of the Secret resource being referred to.
  7138. maxLength: 253
  7139. minLength: 1
  7140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7141. type: string
  7142. namespace:
  7143. description: |-
  7144. The namespace of the Secret resource being referred to.
  7145. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7146. maxLength: 63
  7147. minLength: 1
  7148. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7149. type: string
  7150. type: object
  7151. required:
  7152. - tokenSecretRef
  7153. type: object
  7154. type: object
  7155. casRequired:
  7156. description: 'Enables or disables check-and-set (CAS) (default: false).'
  7157. type: boolean
  7158. okmsTimeout:
  7159. default: 30
  7160. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  7161. format: int32
  7162. minimum: 1
  7163. type: integer
  7164. okmsid:
  7165. description: specifies the OKMS ID.
  7166. type: string
  7167. server:
  7168. description: specifies the OKMS server endpoint.
  7169. type: string
  7170. required:
  7171. - auth
  7172. - okmsid
  7173. - server
  7174. type: object
  7175. passbolt:
  7176. description: |-
  7177. PassboltProvider provides access to Passbolt secrets manager.
  7178. See: https://www.passbolt.com.
  7179. properties:
  7180. auth:
  7181. description: Auth defines the information necessary to authenticate against Passbolt Server
  7182. properties:
  7183. passwordSecretRef:
  7184. description: |-
  7185. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7186. In some instances, `key` is a required field.
  7187. properties:
  7188. key:
  7189. description: |-
  7190. A key in the referenced Secret.
  7191. Some instances of this field may be defaulted, in others it may be required.
  7192. maxLength: 253
  7193. minLength: 1
  7194. pattern: ^[-._a-zA-Z0-9]+$
  7195. type: string
  7196. name:
  7197. description: The name of the Secret resource being referred to.
  7198. maxLength: 253
  7199. minLength: 1
  7200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7201. type: string
  7202. namespace:
  7203. description: |-
  7204. The namespace of the Secret resource being referred to.
  7205. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7206. maxLength: 63
  7207. minLength: 1
  7208. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7209. type: string
  7210. type: object
  7211. privateKeySecretRef:
  7212. description: |-
  7213. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7214. In some instances, `key` is a required field.
  7215. properties:
  7216. key:
  7217. description: |-
  7218. A key in the referenced Secret.
  7219. Some instances of this field may be defaulted, in others it may be required.
  7220. maxLength: 253
  7221. minLength: 1
  7222. pattern: ^[-._a-zA-Z0-9]+$
  7223. type: string
  7224. name:
  7225. description: The name of the Secret resource being referred to.
  7226. maxLength: 253
  7227. minLength: 1
  7228. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7229. type: string
  7230. namespace:
  7231. description: |-
  7232. The namespace of the Secret resource being referred to.
  7233. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7234. maxLength: 63
  7235. minLength: 1
  7236. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7237. type: string
  7238. type: object
  7239. required:
  7240. - passwordSecretRef
  7241. - privateKeySecretRef
  7242. type: object
  7243. caBundle:
  7244. description: |-
  7245. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  7246. if the Host URL is using HTTPS protocol. If not set the system root certificates
  7247. are used to validate the TLS connection.
  7248. format: byte
  7249. type: string
  7250. caProvider:
  7251. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  7252. properties:
  7253. key:
  7254. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7255. maxLength: 253
  7256. minLength: 1
  7257. pattern: ^[-._a-zA-Z0-9]+$
  7258. type: string
  7259. name:
  7260. description: The name of the object located at the provider type.
  7261. maxLength: 253
  7262. minLength: 1
  7263. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7264. type: string
  7265. namespace:
  7266. description: |-
  7267. The namespace the Provider type is in.
  7268. Can only be defined when used in a ClusterSecretStore.
  7269. maxLength: 63
  7270. minLength: 1
  7271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7272. type: string
  7273. type:
  7274. description: The type of provider to use such as "Secret", or "ConfigMap".
  7275. enum:
  7276. - Secret
  7277. - ConfigMap
  7278. type: string
  7279. required:
  7280. - name
  7281. - type
  7282. type: object
  7283. host:
  7284. description: Host defines the Passbolt Server to connect to
  7285. type: string
  7286. required:
  7287. - auth
  7288. - host
  7289. type: object
  7290. passworddepot:
  7291. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  7292. properties:
  7293. auth:
  7294. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  7295. properties:
  7296. secretRef:
  7297. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  7298. properties:
  7299. credentials:
  7300. description: Username / Password is used for authentication.
  7301. properties:
  7302. key:
  7303. description: |-
  7304. A key in the referenced Secret.
  7305. Some instances of this field may be defaulted, in others it may be required.
  7306. maxLength: 253
  7307. minLength: 1
  7308. pattern: ^[-._a-zA-Z0-9]+$
  7309. type: string
  7310. name:
  7311. description: The name of the Secret resource being referred to.
  7312. maxLength: 253
  7313. minLength: 1
  7314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7315. type: string
  7316. namespace:
  7317. description: |-
  7318. The namespace of the Secret resource being referred to.
  7319. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7320. maxLength: 63
  7321. minLength: 1
  7322. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7323. type: string
  7324. type: object
  7325. type: object
  7326. required:
  7327. - secretRef
  7328. type: object
  7329. database:
  7330. description: Database to use as source
  7331. type: string
  7332. host:
  7333. description: URL configures the Password Depot instance URL.
  7334. type: string
  7335. required:
  7336. - auth
  7337. - database
  7338. - host
  7339. type: object
  7340. previder:
  7341. description: Previder configures this store to sync secrets using the Previder provider
  7342. properties:
  7343. auth:
  7344. description: PreviderAuth contains a secretRef for credentials.
  7345. properties:
  7346. secretRef:
  7347. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  7348. properties:
  7349. accessToken:
  7350. description: The AccessToken is used for authentication
  7351. properties:
  7352. key:
  7353. description: |-
  7354. A key in the referenced Secret.
  7355. Some instances of this field may be defaulted, in others it may be required.
  7356. maxLength: 253
  7357. minLength: 1
  7358. pattern: ^[-._a-zA-Z0-9]+$
  7359. type: string
  7360. name:
  7361. description: The name of the Secret resource being referred to.
  7362. maxLength: 253
  7363. minLength: 1
  7364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7365. type: string
  7366. namespace:
  7367. description: |-
  7368. The namespace of the Secret resource being referred to.
  7369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7370. maxLength: 63
  7371. minLength: 1
  7372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7373. type: string
  7374. type: object
  7375. required:
  7376. - accessToken
  7377. type: object
  7378. type: object
  7379. baseUri:
  7380. type: string
  7381. required:
  7382. - auth
  7383. type: object
  7384. pulumi:
  7385. description: Pulumi configures this store to sync secrets using the Pulumi provider
  7386. properties:
  7387. accessToken:
  7388. description: |-
  7389. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  7390. Deprecated: Use auth.accessToken instead.
  7391. properties:
  7392. secretRef:
  7393. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7394. properties:
  7395. key:
  7396. description: |-
  7397. A key in the referenced Secret.
  7398. Some instances of this field may be defaulted, in others it may be required.
  7399. maxLength: 253
  7400. minLength: 1
  7401. pattern: ^[-._a-zA-Z0-9]+$
  7402. type: string
  7403. name:
  7404. description: The name of the Secret resource being referred to.
  7405. maxLength: 253
  7406. minLength: 1
  7407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7408. type: string
  7409. namespace:
  7410. description: |-
  7411. The namespace of the Secret resource being referred to.
  7412. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7413. maxLength: 63
  7414. minLength: 1
  7415. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7416. type: string
  7417. type: object
  7418. type: object
  7419. apiUrl:
  7420. default: https://api.pulumi.com/api/esc
  7421. description: APIURL is the URL of the Pulumi API.
  7422. type: string
  7423. auth:
  7424. description: |-
  7425. Auth configures how the Operator authenticates with the Pulumi API.
  7426. Either auth or the deprecated accessToken field must be specified.
  7427. properties:
  7428. accessToken:
  7429. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  7430. properties:
  7431. secretRef:
  7432. description: SecretRef is a reference to a secret containing the Pulumi API token.
  7433. properties:
  7434. key:
  7435. description: |-
  7436. A key in the referenced Secret.
  7437. Some instances of this field may be defaulted, in others it may be required.
  7438. maxLength: 253
  7439. minLength: 1
  7440. pattern: ^[-._a-zA-Z0-9]+$
  7441. type: string
  7442. name:
  7443. description: The name of the Secret resource being referred to.
  7444. maxLength: 253
  7445. minLength: 1
  7446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7447. type: string
  7448. namespace:
  7449. description: |-
  7450. The namespace of the Secret resource being referred to.
  7451. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7452. maxLength: 63
  7453. minLength: 1
  7454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7455. type: string
  7456. type: object
  7457. type: object
  7458. oidcConfig:
  7459. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  7460. properties:
  7461. expirationSeconds:
  7462. default: 600
  7463. description: |-
  7464. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  7465. Defaults to 10 minutes.
  7466. format: int64
  7467. minimum: 600
  7468. type: integer
  7469. organization:
  7470. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  7471. type: string
  7472. serviceAccountRef:
  7473. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  7474. properties:
  7475. audiences:
  7476. description: |-
  7477. Audience specifies the `aud` claim for the service account token
  7478. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7479. then this audiences will be appended to the list
  7480. items:
  7481. type: string
  7482. type: array
  7483. name:
  7484. description: The name of the ServiceAccount resource being referred to.
  7485. maxLength: 253
  7486. minLength: 1
  7487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7488. type: string
  7489. namespace:
  7490. description: |-
  7491. Namespace of the resource being referred to.
  7492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7493. maxLength: 63
  7494. minLength: 1
  7495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7496. type: string
  7497. required:
  7498. - name
  7499. type: object
  7500. required:
  7501. - organization
  7502. - serviceAccountRef
  7503. type: object
  7504. type: object
  7505. x-kubernetes-validations:
  7506. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  7507. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  7508. environment:
  7509. description: |-
  7510. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  7511. dynamically retrieved values from supported providers including all major clouds,
  7512. and other Pulumi ESC environments.
  7513. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  7514. type: string
  7515. organization:
  7516. description: |-
  7517. Organization are a space to collaborate on shared projects and stacks.
  7518. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  7519. type: string
  7520. project:
  7521. description: Project is the name of the Pulumi ESC project the environment belongs to.
  7522. type: string
  7523. required:
  7524. - environment
  7525. - organization
  7526. - project
  7527. type: object
  7528. x-kubernetes-validations:
  7529. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  7530. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  7531. scaleway:
  7532. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  7533. properties:
  7534. accessKey:
  7535. description: AccessKey is the non-secret part of the api key.
  7536. properties:
  7537. secretRef:
  7538. description: SecretRef references a key in a secret that will be used as value.
  7539. properties:
  7540. key:
  7541. description: |-
  7542. A key in the referenced Secret.
  7543. Some instances of this field may be defaulted, in others it may be required.
  7544. maxLength: 253
  7545. minLength: 1
  7546. pattern: ^[-._a-zA-Z0-9]+$
  7547. type: string
  7548. name:
  7549. description: The name of the Secret resource being referred to.
  7550. maxLength: 253
  7551. minLength: 1
  7552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7553. type: string
  7554. namespace:
  7555. description: |-
  7556. The namespace of the Secret resource being referred to.
  7557. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7558. maxLength: 63
  7559. minLength: 1
  7560. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7561. type: string
  7562. type: object
  7563. value:
  7564. description: Value can be specified directly to set a value without using a secret.
  7565. type: string
  7566. type: object
  7567. apiUrl:
  7568. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  7569. type: string
  7570. projectId:
  7571. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  7572. type: string
  7573. region:
  7574. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  7575. type: string
  7576. secretKey:
  7577. description: SecretKey is the non-secret part of the api key.
  7578. properties:
  7579. secretRef:
  7580. description: SecretRef references a key in a secret that will be used as value.
  7581. properties:
  7582. key:
  7583. description: |-
  7584. A key in the referenced Secret.
  7585. Some instances of this field may be defaulted, in others it may be required.
  7586. maxLength: 253
  7587. minLength: 1
  7588. pattern: ^[-._a-zA-Z0-9]+$
  7589. type: string
  7590. name:
  7591. description: The name of the Secret resource being referred to.
  7592. maxLength: 253
  7593. minLength: 1
  7594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7595. type: string
  7596. namespace:
  7597. description: |-
  7598. The namespace of the Secret resource being referred to.
  7599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7600. maxLength: 63
  7601. minLength: 1
  7602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7603. type: string
  7604. type: object
  7605. value:
  7606. description: Value can be specified directly to set a value without using a secret.
  7607. type: string
  7608. type: object
  7609. required:
  7610. - accessKey
  7611. - projectId
  7612. - region
  7613. - secretKey
  7614. type: object
  7615. secretserver:
  7616. description: |-
  7617. SecretServer configures this store to sync secrets using SecretServer provider
  7618. https://docs.delinea.com/online-help/secret-server/start.htm
  7619. properties:
  7620. caBundle:
  7621. description: |-
  7622. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  7623. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  7624. are used to validate the TLS connection.
  7625. format: byte
  7626. type: string
  7627. caProvider:
  7628. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  7629. properties:
  7630. key:
  7631. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  7632. maxLength: 253
  7633. minLength: 1
  7634. pattern: ^[-._a-zA-Z0-9]+$
  7635. type: string
  7636. name:
  7637. description: The name of the object located at the provider type.
  7638. maxLength: 253
  7639. minLength: 1
  7640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7641. type: string
  7642. namespace:
  7643. description: |-
  7644. The namespace the Provider type is in.
  7645. Can only be defined when used in a ClusterSecretStore.
  7646. maxLength: 63
  7647. minLength: 1
  7648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7649. type: string
  7650. type:
  7651. description: The type of provider to use such as "Secret", or "ConfigMap".
  7652. enum:
  7653. - Secret
  7654. - ConfigMap
  7655. type: string
  7656. required:
  7657. - name
  7658. - type
  7659. type: object
  7660. domain:
  7661. description: Domain is the secret server domain.
  7662. type: string
  7663. password:
  7664. description: |-
  7665. Password is the secret server account password.
  7666. Required unless Token is set.
  7667. properties:
  7668. secretRef:
  7669. description: SecretRef references a key in a secret that will be used as value.
  7670. properties:
  7671. key:
  7672. description: |-
  7673. A key in the referenced Secret.
  7674. Some instances of this field may be defaulted, in others it may be required.
  7675. maxLength: 253
  7676. minLength: 1
  7677. pattern: ^[-._a-zA-Z0-9]+$
  7678. type: string
  7679. name:
  7680. description: The name of the Secret resource being referred to.
  7681. maxLength: 253
  7682. minLength: 1
  7683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7684. type: string
  7685. namespace:
  7686. description: |-
  7687. The namespace of the Secret resource being referred to.
  7688. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7689. maxLength: 63
  7690. minLength: 1
  7691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7692. type: string
  7693. type: object
  7694. value:
  7695. description: Value can be specified directly to set a value without using a secret.
  7696. minLength: 1
  7697. type: string
  7698. type: object
  7699. x-kubernetes-validations:
  7700. - message: exactly one of value or secretRef must be set
  7701. rule: has(self.value) != has(self.secretRef)
  7702. serverURL:
  7703. description: |-
  7704. ServerURL
  7705. URL to your secret server installation
  7706. type: string
  7707. token:
  7708. description: |-
  7709. Token is an access token used to authenticate to the secret server,
  7710. as an alternative to Username and Password. When set, Username and
  7711. Password are not required and are ignored.
  7712. properties:
  7713. secretRef:
  7714. description: SecretRef references a key in a secret that will be used as value.
  7715. properties:
  7716. key:
  7717. description: |-
  7718. A key in the referenced Secret.
  7719. Some instances of this field may be defaulted, in others it may be required.
  7720. maxLength: 253
  7721. minLength: 1
  7722. pattern: ^[-._a-zA-Z0-9]+$
  7723. type: string
  7724. name:
  7725. description: The name of the Secret resource being referred to.
  7726. maxLength: 253
  7727. minLength: 1
  7728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7729. type: string
  7730. namespace:
  7731. description: |-
  7732. The namespace of the Secret resource being referred to.
  7733. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7734. maxLength: 63
  7735. minLength: 1
  7736. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7737. type: string
  7738. type: object
  7739. value:
  7740. description: Value can be specified directly to set a value without using a secret.
  7741. minLength: 1
  7742. type: string
  7743. type: object
  7744. x-kubernetes-validations:
  7745. - message: exactly one of value or secretRef must be set
  7746. rule: has(self.value) != has(self.secretRef)
  7747. username:
  7748. description: |-
  7749. Username is the secret server account username.
  7750. Required unless Token is set.
  7751. properties:
  7752. secretRef:
  7753. description: SecretRef references a key in a secret that will be used as value.
  7754. properties:
  7755. key:
  7756. description: |-
  7757. A key in the referenced Secret.
  7758. Some instances of this field may be defaulted, in others it may be required.
  7759. maxLength: 253
  7760. minLength: 1
  7761. pattern: ^[-._a-zA-Z0-9]+$
  7762. type: string
  7763. name:
  7764. description: The name of the Secret resource being referred to.
  7765. maxLength: 253
  7766. minLength: 1
  7767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7768. type: string
  7769. namespace:
  7770. description: |-
  7771. The namespace of the Secret resource being referred to.
  7772. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7773. maxLength: 63
  7774. minLength: 1
  7775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7776. type: string
  7777. type: object
  7778. value:
  7779. description: Value can be specified directly to set a value without using a secret.
  7780. minLength: 1
  7781. type: string
  7782. type: object
  7783. x-kubernetes-validations:
  7784. - message: exactly one of value or secretRef must be set
  7785. rule: has(self.value) != has(self.secretRef)
  7786. required:
  7787. - serverURL
  7788. type: object
  7789. x-kubernetes-validations:
  7790. - message: either token, or both username and password, must be set
  7791. rule: has(self.token) || (has(self.username) && has(self.password))
  7792. senhasegura:
  7793. description: Senhasegura configures this store to sync secrets using senhasegura provider
  7794. properties:
  7795. auth:
  7796. description: Auth defines parameters to authenticate in senhasegura
  7797. properties:
  7798. clientId:
  7799. type: string
  7800. clientSecretSecretRef:
  7801. description: |-
  7802. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  7803. In some instances, `key` is a required field.
  7804. properties:
  7805. key:
  7806. description: |-
  7807. A key in the referenced Secret.
  7808. Some instances of this field may be defaulted, in others it may be required.
  7809. maxLength: 253
  7810. minLength: 1
  7811. pattern: ^[-._a-zA-Z0-9]+$
  7812. type: string
  7813. name:
  7814. description: The name of the Secret resource being referred to.
  7815. maxLength: 253
  7816. minLength: 1
  7817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7818. type: string
  7819. namespace:
  7820. description: |-
  7821. The namespace of the Secret resource being referred to.
  7822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7823. maxLength: 63
  7824. minLength: 1
  7825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7826. type: string
  7827. type: object
  7828. required:
  7829. - clientId
  7830. - clientSecretSecretRef
  7831. type: object
  7832. ignoreSslCertificate:
  7833. default: false
  7834. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  7835. type: boolean
  7836. module:
  7837. description: Module defines which senhasegura module should be used to get secrets
  7838. type: string
  7839. url:
  7840. description: URL of senhasegura
  7841. type: string
  7842. required:
  7843. - auth
  7844. - module
  7845. - url
  7846. type: object
  7847. vault:
  7848. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  7849. properties:
  7850. auth:
  7851. description: Auth configures how secret-manager authenticates with the Vault server.
  7852. properties:
  7853. appRole:
  7854. description: |-
  7855. AppRole authenticates with Vault using the App Role auth mechanism,
  7856. with the role and secret stored in a Kubernetes Secret resource.
  7857. properties:
  7858. path:
  7859. default: approle
  7860. description: |-
  7861. Path where the App Role authentication backend is mounted
  7862. in Vault, e.g: "approle"
  7863. type: string
  7864. roleId:
  7865. description: |-
  7866. RoleID configured in the App Role authentication backend when setting
  7867. up the authentication backend in Vault.
  7868. type: string
  7869. roleRef:
  7870. description: |-
  7871. Reference to a key in a Secret that contains the App Role ID used
  7872. to authenticate with Vault.
  7873. The `key` field must be specified and denotes which entry within the Secret
  7874. resource is used as the app role id.
  7875. properties:
  7876. key:
  7877. description: |-
  7878. A key in the referenced Secret.
  7879. Some instances of this field may be defaulted, in others it may be required.
  7880. maxLength: 253
  7881. minLength: 1
  7882. pattern: ^[-._a-zA-Z0-9]+$
  7883. type: string
  7884. name:
  7885. description: The name of the Secret resource being referred to.
  7886. maxLength: 253
  7887. minLength: 1
  7888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7889. type: string
  7890. namespace:
  7891. description: |-
  7892. The namespace of the Secret resource being referred to.
  7893. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7894. maxLength: 63
  7895. minLength: 1
  7896. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7897. type: string
  7898. type: object
  7899. secretRef:
  7900. description: |-
  7901. Reference to a key in a Secret that contains the App Role secret used
  7902. to authenticate with Vault.
  7903. The `key` field must be specified and denotes which entry within the Secret
  7904. resource is used as the app role secret.
  7905. properties:
  7906. key:
  7907. description: |-
  7908. A key in the referenced Secret.
  7909. Some instances of this field may be defaulted, in others it may be required.
  7910. maxLength: 253
  7911. minLength: 1
  7912. pattern: ^[-._a-zA-Z0-9]+$
  7913. type: string
  7914. name:
  7915. description: The name of the Secret resource being referred to.
  7916. maxLength: 253
  7917. minLength: 1
  7918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7919. type: string
  7920. namespace:
  7921. description: |-
  7922. The namespace of the Secret resource being referred to.
  7923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7924. maxLength: 63
  7925. minLength: 1
  7926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7927. type: string
  7928. type: object
  7929. required:
  7930. - path
  7931. - secretRef
  7932. type: object
  7933. cert:
  7934. description: |-
  7935. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  7936. Cert authentication method
  7937. properties:
  7938. clientCert:
  7939. description: |-
  7940. ClientCert is a certificate to authenticate using the Cert Vault
  7941. authentication method
  7942. properties:
  7943. key:
  7944. description: |-
  7945. A key in the referenced Secret.
  7946. Some instances of this field may be defaulted, in others it may be required.
  7947. maxLength: 253
  7948. minLength: 1
  7949. pattern: ^[-._a-zA-Z0-9]+$
  7950. type: string
  7951. name:
  7952. description: The name of the Secret resource being referred to.
  7953. maxLength: 253
  7954. minLength: 1
  7955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7956. type: string
  7957. namespace:
  7958. description: |-
  7959. The namespace of the Secret resource being referred to.
  7960. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7961. maxLength: 63
  7962. minLength: 1
  7963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7964. type: string
  7965. type: object
  7966. path:
  7967. default: cert
  7968. description: |-
  7969. Path where the Certificate authentication backend is mounted
  7970. in Vault, e.g: "cert"
  7971. type: string
  7972. secretRef:
  7973. description: |-
  7974. SecretRef to a key in a Secret resource containing client private key to
  7975. authenticate with Vault using the Cert authentication method
  7976. properties:
  7977. key:
  7978. description: |-
  7979. A key in the referenced Secret.
  7980. Some instances of this field may be defaulted, in others it may be required.
  7981. maxLength: 253
  7982. minLength: 1
  7983. pattern: ^[-._a-zA-Z0-9]+$
  7984. type: string
  7985. name:
  7986. description: The name of the Secret resource being referred to.
  7987. maxLength: 253
  7988. minLength: 1
  7989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7990. type: string
  7991. namespace:
  7992. description: |-
  7993. The namespace of the Secret resource being referred to.
  7994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7995. maxLength: 63
  7996. minLength: 1
  7997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7998. type: string
  7999. type: object
  8000. vaultRole:
  8001. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  8002. type: string
  8003. type: object
  8004. gcp:
  8005. description: |-
  8006. Gcp authenticates with Vault using Google Cloud Platform authentication method
  8007. GCP authentication method
  8008. properties:
  8009. location:
  8010. description: Location optionally defines a location/region for the secret
  8011. type: string
  8012. path:
  8013. default: gcp
  8014. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  8015. type: string
  8016. projectID:
  8017. description: Project ID of the Google Cloud Platform project
  8018. type: string
  8019. role:
  8020. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  8021. type: string
  8022. secretRef:
  8023. description: Specify credentials in a Secret object
  8024. properties:
  8025. secretAccessKeySecretRef:
  8026. description: The SecretAccessKey is used for authentication
  8027. properties:
  8028. key:
  8029. description: |-
  8030. A key in the referenced Secret.
  8031. Some instances of this field may be defaulted, in others it may be required.
  8032. maxLength: 253
  8033. minLength: 1
  8034. pattern: ^[-._a-zA-Z0-9]+$
  8035. type: string
  8036. name:
  8037. description: The name of the Secret resource being referred to.
  8038. maxLength: 253
  8039. minLength: 1
  8040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8041. type: string
  8042. namespace:
  8043. description: |-
  8044. The namespace of the Secret resource being referred to.
  8045. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8046. maxLength: 63
  8047. minLength: 1
  8048. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8049. type: string
  8050. type: object
  8051. type: object
  8052. serviceAccountRef:
  8053. description: ServiceAccountRef to a service account for impersonation
  8054. properties:
  8055. audiences:
  8056. description: |-
  8057. Audience specifies the `aud` claim for the service account token
  8058. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8059. then this audiences will be appended to the list
  8060. items:
  8061. type: string
  8062. type: array
  8063. name:
  8064. description: The name of the ServiceAccount resource being referred to.
  8065. maxLength: 253
  8066. minLength: 1
  8067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8068. type: string
  8069. namespace:
  8070. description: |-
  8071. Namespace of the resource being referred to.
  8072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8073. maxLength: 63
  8074. minLength: 1
  8075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8076. type: string
  8077. required:
  8078. - name
  8079. type: object
  8080. workloadIdentity:
  8081. description: Specify a service account with Workload Identity
  8082. properties:
  8083. clusterLocation:
  8084. description: |-
  8085. ClusterLocation is the location of the cluster
  8086. If not specified, it fetches information from the metadata server
  8087. type: string
  8088. clusterName:
  8089. description: |-
  8090. ClusterName is the name of the cluster
  8091. If not specified, it fetches information from the metadata server
  8092. type: string
  8093. clusterProjectID:
  8094. description: |-
  8095. ClusterProjectID is the project ID of the cluster
  8096. If not specified, it fetches information from the metadata server
  8097. type: string
  8098. serviceAccountRef:
  8099. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8100. properties:
  8101. audiences:
  8102. description: |-
  8103. Audience specifies the `aud` claim for the service account token
  8104. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8105. then this audiences will be appended to the list
  8106. items:
  8107. type: string
  8108. type: array
  8109. name:
  8110. description: The name of the ServiceAccount resource being referred to.
  8111. maxLength: 253
  8112. minLength: 1
  8113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8114. type: string
  8115. namespace:
  8116. description: |-
  8117. Namespace of the resource being referred to.
  8118. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8119. maxLength: 63
  8120. minLength: 1
  8121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8122. type: string
  8123. required:
  8124. - name
  8125. type: object
  8126. required:
  8127. - serviceAccountRef
  8128. type: object
  8129. required:
  8130. - role
  8131. type: object
  8132. iam:
  8133. description: |-
  8134. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  8135. AWS IAM authentication method
  8136. properties:
  8137. externalID:
  8138. description: AWS External ID set on assumed IAM roles
  8139. type: string
  8140. jwt:
  8141. description: Specify a service account with IRSA enabled
  8142. properties:
  8143. serviceAccountRef:
  8144. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  8145. properties:
  8146. audiences:
  8147. description: |-
  8148. Audience specifies the `aud` claim for the service account token
  8149. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8150. then this audiences will be appended to the list
  8151. items:
  8152. type: string
  8153. type: array
  8154. name:
  8155. description: The name of the ServiceAccount resource being referred to.
  8156. maxLength: 253
  8157. minLength: 1
  8158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8159. type: string
  8160. namespace:
  8161. description: |-
  8162. Namespace of the resource being referred to.
  8163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8164. maxLength: 63
  8165. minLength: 1
  8166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8167. type: string
  8168. required:
  8169. - name
  8170. type: object
  8171. type: object
  8172. path:
  8173. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  8174. type: string
  8175. region:
  8176. description: AWS region
  8177. type: string
  8178. role:
  8179. description: This is the AWS role to be assumed before talking to vault
  8180. type: string
  8181. secretRef:
  8182. description: Specify credentials in a Secret object
  8183. properties:
  8184. accessKeyIDSecretRef:
  8185. description: The AccessKeyID is used for authentication
  8186. properties:
  8187. key:
  8188. description: |-
  8189. A key in the referenced Secret.
  8190. Some instances of this field may be defaulted, in others it may be required.
  8191. maxLength: 253
  8192. minLength: 1
  8193. pattern: ^[-._a-zA-Z0-9]+$
  8194. type: string
  8195. name:
  8196. description: The name of the Secret resource being referred to.
  8197. maxLength: 253
  8198. minLength: 1
  8199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8200. type: string
  8201. namespace:
  8202. description: |-
  8203. The namespace of the Secret resource being referred to.
  8204. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8205. maxLength: 63
  8206. minLength: 1
  8207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8208. type: string
  8209. type: object
  8210. secretAccessKeySecretRef:
  8211. description: The SecretAccessKey is used for authentication
  8212. properties:
  8213. key:
  8214. description: |-
  8215. A key in the referenced Secret.
  8216. Some instances of this field may be defaulted, in others it may be required.
  8217. maxLength: 253
  8218. minLength: 1
  8219. pattern: ^[-._a-zA-Z0-9]+$
  8220. type: string
  8221. name:
  8222. description: The name of the Secret resource being referred to.
  8223. maxLength: 253
  8224. minLength: 1
  8225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8226. type: string
  8227. namespace:
  8228. description: |-
  8229. The namespace of the Secret resource being referred to.
  8230. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8231. maxLength: 63
  8232. minLength: 1
  8233. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8234. type: string
  8235. type: object
  8236. sessionTokenSecretRef:
  8237. description: |-
  8238. The SessionToken used for authentication
  8239. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  8240. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  8241. properties:
  8242. key:
  8243. description: |-
  8244. A key in the referenced Secret.
  8245. Some instances of this field may be defaulted, in others it may be required.
  8246. maxLength: 253
  8247. minLength: 1
  8248. pattern: ^[-._a-zA-Z0-9]+$
  8249. type: string
  8250. name:
  8251. description: The name of the Secret resource being referred to.
  8252. maxLength: 253
  8253. minLength: 1
  8254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8255. type: string
  8256. namespace:
  8257. description: |-
  8258. The namespace of the Secret resource being referred to.
  8259. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8260. maxLength: 63
  8261. minLength: 1
  8262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8263. type: string
  8264. type: object
  8265. type: object
  8266. vaultAwsIamServerID:
  8267. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  8268. type: string
  8269. vaultRole:
  8270. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  8271. type: string
  8272. required:
  8273. - vaultRole
  8274. type: object
  8275. jwt:
  8276. description: |-
  8277. Jwt authenticates with Vault by passing role and JWT token using the
  8278. JWT/OIDC authentication method
  8279. properties:
  8280. kubernetesServiceAccountToken:
  8281. description: |-
  8282. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  8283. a token for with the `TokenRequest` API.
  8284. properties:
  8285. audiences:
  8286. description: |-
  8287. Optional audiences field that will be used to request a temporary Kubernetes service
  8288. account token for the service account referenced by `serviceAccountRef`.
  8289. Defaults to a single audience `vault` it not specified.
  8290. Deprecated: use serviceAccountRef.Audiences instead
  8291. items:
  8292. type: string
  8293. type: array
  8294. expirationSeconds:
  8295. description: |-
  8296. Optional expiration time in seconds that will be used to request a temporary
  8297. Kubernetes service account token for the service account referenced by
  8298. `serviceAccountRef`.
  8299. Deprecated: this will be removed in the future.
  8300. Defaults to 10 minutes.
  8301. format: int64
  8302. type: integer
  8303. serviceAccountRef:
  8304. description: Service account field containing the name of a kubernetes ServiceAccount.
  8305. properties:
  8306. audiences:
  8307. description: |-
  8308. Audience specifies the `aud` claim for the service account token
  8309. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8310. then this audiences will be appended to the list
  8311. items:
  8312. type: string
  8313. type: array
  8314. name:
  8315. description: The name of the ServiceAccount resource being referred to.
  8316. maxLength: 253
  8317. minLength: 1
  8318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8319. type: string
  8320. namespace:
  8321. description: |-
  8322. Namespace of the resource being referred to.
  8323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8324. maxLength: 63
  8325. minLength: 1
  8326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8327. type: string
  8328. required:
  8329. - name
  8330. type: object
  8331. required:
  8332. - serviceAccountRef
  8333. type: object
  8334. path:
  8335. default: jwt
  8336. description: |-
  8337. Path where the JWT authentication backend is mounted
  8338. in Vault, e.g: "jwt"
  8339. type: string
  8340. role:
  8341. description: |-
  8342. Role is a JWT role to authenticate using the JWT/OIDC Vault
  8343. authentication method
  8344. type: string
  8345. secretRef:
  8346. description: |-
  8347. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  8348. authenticate with Vault using the JWT/OIDC authentication method.
  8349. properties:
  8350. key:
  8351. description: |-
  8352. A key in the referenced Secret.
  8353. Some instances of this field may be defaulted, in others it may be required.
  8354. maxLength: 253
  8355. minLength: 1
  8356. pattern: ^[-._a-zA-Z0-9]+$
  8357. type: string
  8358. name:
  8359. description: The name of the Secret resource being referred to.
  8360. maxLength: 253
  8361. minLength: 1
  8362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8363. type: string
  8364. namespace:
  8365. description: |-
  8366. The namespace of the Secret resource being referred to.
  8367. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8368. maxLength: 63
  8369. minLength: 1
  8370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8371. type: string
  8372. type: object
  8373. required:
  8374. - path
  8375. type: object
  8376. kubernetes:
  8377. description: |-
  8378. Kubernetes authenticates with Vault by passing the ServiceAccount
  8379. token stored in the named Secret resource to the Vault server.
  8380. properties:
  8381. mountPath:
  8382. default: kubernetes
  8383. description: |-
  8384. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  8385. "kubernetes"
  8386. type: string
  8387. role:
  8388. description: |-
  8389. A required field containing the Vault Role to assume. A Role binds a
  8390. Kubernetes ServiceAccount with a set of Vault policies.
  8391. type: string
  8392. secretRef:
  8393. description: |-
  8394. Optional secret field containing a Kubernetes ServiceAccount JWT used
  8395. for authenticating with Vault. If a name is specified without a key,
  8396. `token` is the default. If one is not specified, the one bound to
  8397. the controller will be used.
  8398. properties:
  8399. key:
  8400. description: |-
  8401. A key in the referenced Secret.
  8402. Some instances of this field may be defaulted, in others it may be required.
  8403. maxLength: 253
  8404. minLength: 1
  8405. pattern: ^[-._a-zA-Z0-9]+$
  8406. type: string
  8407. name:
  8408. description: The name of the Secret resource being referred to.
  8409. maxLength: 253
  8410. minLength: 1
  8411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8412. type: string
  8413. namespace:
  8414. description: |-
  8415. The namespace of the Secret resource being referred to.
  8416. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8417. maxLength: 63
  8418. minLength: 1
  8419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8420. type: string
  8421. type: object
  8422. serviceAccountRef:
  8423. description: |-
  8424. Optional service account field containing the name of a kubernetes ServiceAccount.
  8425. If the service account is specified, the service account secret token JWT will be used
  8426. for authenticating with Vault. If the service account selector is not supplied,
  8427. the secretRef will be used instead.
  8428. properties:
  8429. audiences:
  8430. description: |-
  8431. Audience specifies the `aud` claim for the service account token
  8432. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8433. then this audiences will be appended to the list
  8434. items:
  8435. type: string
  8436. type: array
  8437. name:
  8438. description: The name of the ServiceAccount resource being referred to.
  8439. maxLength: 253
  8440. minLength: 1
  8441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8442. type: string
  8443. namespace:
  8444. description: |-
  8445. Namespace of the resource being referred to.
  8446. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8447. maxLength: 63
  8448. minLength: 1
  8449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8450. type: string
  8451. required:
  8452. - name
  8453. type: object
  8454. required:
  8455. - mountPath
  8456. - role
  8457. type: object
  8458. ldap:
  8459. description: |-
  8460. Ldap authenticates with Vault by passing username/password pair using
  8461. the LDAP authentication method
  8462. properties:
  8463. path:
  8464. default: ldap
  8465. description: |-
  8466. Path where the LDAP authentication backend is mounted
  8467. in Vault, e.g: "ldap"
  8468. type: string
  8469. secretRef:
  8470. description: |-
  8471. SecretRef to a key in a Secret resource containing password for the LDAP
  8472. user used to authenticate with Vault using the LDAP authentication
  8473. method
  8474. properties:
  8475. key:
  8476. description: |-
  8477. A key in the referenced Secret.
  8478. Some instances of this field may be defaulted, in others it may be required.
  8479. maxLength: 253
  8480. minLength: 1
  8481. pattern: ^[-._a-zA-Z0-9]+$
  8482. type: string
  8483. name:
  8484. description: The name of the Secret resource being referred to.
  8485. maxLength: 253
  8486. minLength: 1
  8487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8488. type: string
  8489. namespace:
  8490. description: |-
  8491. The namespace of the Secret resource being referred to.
  8492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8493. maxLength: 63
  8494. minLength: 1
  8495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8496. type: string
  8497. type: object
  8498. username:
  8499. description: |-
  8500. Username is an LDAP username used to authenticate using the LDAP Vault
  8501. authentication method
  8502. type: string
  8503. required:
  8504. - path
  8505. - username
  8506. type: object
  8507. namespace:
  8508. description: |-
  8509. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  8510. Namespaces is a set of features within Vault Enterprise that allows
  8511. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8512. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8513. This will default to Vault.Namespace field if set, or empty otherwise
  8514. type: string
  8515. tokenSecretRef:
  8516. description: TokenSecretRef authenticates with Vault by presenting a token.
  8517. properties:
  8518. key:
  8519. description: |-
  8520. A key in the referenced Secret.
  8521. Some instances of this field may be defaulted, in others it may be required.
  8522. maxLength: 253
  8523. minLength: 1
  8524. pattern: ^[-._a-zA-Z0-9]+$
  8525. type: string
  8526. name:
  8527. description: The name of the Secret resource being referred to.
  8528. maxLength: 253
  8529. minLength: 1
  8530. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8531. type: string
  8532. namespace:
  8533. description: |-
  8534. The namespace of the Secret resource being referred to.
  8535. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8536. maxLength: 63
  8537. minLength: 1
  8538. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8539. type: string
  8540. type: object
  8541. userPass:
  8542. description: UserPass authenticates with Vault by passing username/password pair
  8543. properties:
  8544. path:
  8545. default: userpass
  8546. description: |-
  8547. Path where the UserPassword authentication backend is mounted
  8548. in Vault, e.g: "userpass"
  8549. type: string
  8550. secretRef:
  8551. description: |-
  8552. SecretRef to a key in a Secret resource containing password for the
  8553. user used to authenticate with Vault using the UserPass authentication
  8554. method
  8555. properties:
  8556. key:
  8557. description: |-
  8558. A key in the referenced Secret.
  8559. Some instances of this field may be defaulted, in others it may be required.
  8560. maxLength: 253
  8561. minLength: 1
  8562. pattern: ^[-._a-zA-Z0-9]+$
  8563. type: string
  8564. name:
  8565. description: The name of the Secret resource being referred to.
  8566. maxLength: 253
  8567. minLength: 1
  8568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8569. type: string
  8570. namespace:
  8571. description: |-
  8572. The namespace of the Secret resource being referred to.
  8573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8574. maxLength: 63
  8575. minLength: 1
  8576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8577. type: string
  8578. type: object
  8579. username:
  8580. description: |-
  8581. Username is a username used to authenticate using the UserPass Vault
  8582. authentication method
  8583. type: string
  8584. required:
  8585. - path
  8586. - username
  8587. type: object
  8588. type: object
  8589. caBundle:
  8590. description: |-
  8591. PEM encoded CA bundle used to validate Vault server certificate. Only used
  8592. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8593. plain HTTP protocol connection. If not set the system root certificates
  8594. are used to validate the TLS connection.
  8595. format: byte
  8596. type: string
  8597. caProvider:
  8598. description: The provider for the CA bundle to use to validate Vault server certificate.
  8599. properties:
  8600. key:
  8601. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8602. maxLength: 253
  8603. minLength: 1
  8604. pattern: ^[-._a-zA-Z0-9]+$
  8605. type: string
  8606. name:
  8607. description: The name of the object located at the provider type.
  8608. maxLength: 253
  8609. minLength: 1
  8610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8611. type: string
  8612. namespace:
  8613. description: |-
  8614. The namespace the Provider type is in.
  8615. Can only be defined when used in a ClusterSecretStore.
  8616. maxLength: 63
  8617. minLength: 1
  8618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8619. type: string
  8620. type:
  8621. description: The type of provider to use such as "Secret", or "ConfigMap".
  8622. enum:
  8623. - Secret
  8624. - ConfigMap
  8625. type: string
  8626. required:
  8627. - name
  8628. - type
  8629. type: object
  8630. checkAndSet:
  8631. description: |-
  8632. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  8633. Only applies to Vault KV v2 stores. When enabled, write operations must include
  8634. the current version of the secret to prevent unintentional overwrites.
  8635. properties:
  8636. required:
  8637. description: |-
  8638. Required when true, all write operations must include a check-and-set parameter.
  8639. This helps prevent unintentional overwrites of secrets.
  8640. type: boolean
  8641. type: object
  8642. forwardInconsistent:
  8643. description: |-
  8644. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  8645. leader instead of simply retrying within a loop. This can increase performance if
  8646. the option is enabled serverside.
  8647. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  8648. type: boolean
  8649. headers:
  8650. additionalProperties:
  8651. type: string
  8652. description: Headers to be added in Vault request
  8653. type: object
  8654. namespace:
  8655. description: |-
  8656. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  8657. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  8658. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  8659. type: string
  8660. path:
  8661. description: |-
  8662. Path is the mount path of the Vault KV backend endpoint, e.g:
  8663. "secret". The v2 KV secret engine version specific "/data" path suffix
  8664. for fetching secrets from Vault is optional and will be appended
  8665. if not present in specified path.
  8666. type: string
  8667. readYourWrites:
  8668. description: |-
  8669. ReadYourWrites ensures isolated read-after-write semantics by
  8670. providing discovered cluster replication states in each request.
  8671. More information about eventual consistency in Vault can be found here
  8672. https://www.vaultproject.io/docs/enterprise/consistency
  8673. type: boolean
  8674. server:
  8675. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  8676. type: string
  8677. tls:
  8678. description: |-
  8679. The configuration used for client side related TLS communication, when the Vault server
  8680. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  8681. This parameter is ignored for plain HTTP protocol connection.
  8682. It's worth noting this configuration is different from the "TLS certificates auth method",
  8683. which is available under the `auth.cert` section.
  8684. properties:
  8685. certSecretRef:
  8686. description: |-
  8687. CertSecretRef is a certificate added to the transport layer
  8688. when communicating with the Vault server.
  8689. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  8690. properties:
  8691. key:
  8692. description: |-
  8693. A key in the referenced Secret.
  8694. Some instances of this field may be defaulted, in others it may be required.
  8695. maxLength: 253
  8696. minLength: 1
  8697. pattern: ^[-._a-zA-Z0-9]+$
  8698. type: string
  8699. name:
  8700. description: The name of the Secret resource being referred to.
  8701. maxLength: 253
  8702. minLength: 1
  8703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8704. type: string
  8705. namespace:
  8706. description: |-
  8707. The namespace of the Secret resource being referred to.
  8708. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8709. maxLength: 63
  8710. minLength: 1
  8711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8712. type: string
  8713. type: object
  8714. keySecretRef:
  8715. description: |-
  8716. KeySecretRef to a key in a Secret resource containing client private key
  8717. added to the transport layer when communicating with the Vault server.
  8718. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  8719. properties:
  8720. key:
  8721. description: |-
  8722. A key in the referenced Secret.
  8723. Some instances of this field may be defaulted, in others it may be required.
  8724. maxLength: 253
  8725. minLength: 1
  8726. pattern: ^[-._a-zA-Z0-9]+$
  8727. type: string
  8728. name:
  8729. description: The name of the Secret resource being referred to.
  8730. maxLength: 253
  8731. minLength: 1
  8732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8733. type: string
  8734. namespace:
  8735. description: |-
  8736. The namespace of the Secret resource being referred to.
  8737. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8738. maxLength: 63
  8739. minLength: 1
  8740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8741. type: string
  8742. type: object
  8743. type: object
  8744. version:
  8745. default: v2
  8746. description: |-
  8747. Version is the Vault KV secret engine version. This can be either "v1" or
  8748. "v2". Version defaults to "v2".
  8749. enum:
  8750. - v1
  8751. - v2
  8752. type: string
  8753. required:
  8754. - server
  8755. type: object
  8756. volcengine:
  8757. description: Volcengine configures this store to sync secrets using the Volcengine provider
  8758. properties:
  8759. auth:
  8760. description: |-
  8761. Auth defines the authentication method to use.
  8762. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  8763. properties:
  8764. secretRef:
  8765. description: |-
  8766. SecretRef defines the static credentials to use for authentication.
  8767. If not set, IRSA is used.
  8768. properties:
  8769. accessKeyID:
  8770. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  8771. properties:
  8772. key:
  8773. description: |-
  8774. A key in the referenced Secret.
  8775. Some instances of this field may be defaulted, in others it may be required.
  8776. maxLength: 253
  8777. minLength: 1
  8778. pattern: ^[-._a-zA-Z0-9]+$
  8779. type: string
  8780. name:
  8781. description: The name of the Secret resource being referred to.
  8782. maxLength: 253
  8783. minLength: 1
  8784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8785. type: string
  8786. namespace:
  8787. description: |-
  8788. The namespace of the Secret resource being referred to.
  8789. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8790. maxLength: 63
  8791. minLength: 1
  8792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8793. type: string
  8794. type: object
  8795. secretAccessKey:
  8796. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  8797. properties:
  8798. key:
  8799. description: |-
  8800. A key in the referenced Secret.
  8801. Some instances of this field may be defaulted, in others it may be required.
  8802. maxLength: 253
  8803. minLength: 1
  8804. pattern: ^[-._a-zA-Z0-9]+$
  8805. type: string
  8806. name:
  8807. description: The name of the Secret resource being referred to.
  8808. maxLength: 253
  8809. minLength: 1
  8810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8811. type: string
  8812. namespace:
  8813. description: |-
  8814. The namespace of the Secret resource being referred to.
  8815. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8816. maxLength: 63
  8817. minLength: 1
  8818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8819. type: string
  8820. type: object
  8821. token:
  8822. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  8823. properties:
  8824. key:
  8825. description: |-
  8826. A key in the referenced Secret.
  8827. Some instances of this field may be defaulted, in others it may be required.
  8828. maxLength: 253
  8829. minLength: 1
  8830. pattern: ^[-._a-zA-Z0-9]+$
  8831. type: string
  8832. name:
  8833. description: The name of the Secret resource being referred to.
  8834. maxLength: 253
  8835. minLength: 1
  8836. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8837. type: string
  8838. namespace:
  8839. description: |-
  8840. The namespace of the Secret resource being referred to.
  8841. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8842. maxLength: 63
  8843. minLength: 1
  8844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8845. type: string
  8846. type: object
  8847. required:
  8848. - accessKeyID
  8849. - secretAccessKey
  8850. type: object
  8851. type: object
  8852. region:
  8853. description: Region specifies the Volcengine region to connect to.
  8854. type: string
  8855. required:
  8856. - region
  8857. type: object
  8858. webhook:
  8859. description: Webhook configures this store to sync secrets using a generic templated webhook
  8860. properties:
  8861. auth:
  8862. description: Auth specifies a authorization protocol. Only one protocol may be set.
  8863. maxProperties: 1
  8864. minProperties: 1
  8865. properties:
  8866. ntlm:
  8867. description: NTLMProtocol configures the store to use NTLM for auth
  8868. properties:
  8869. passwordSecret:
  8870. description: |-
  8871. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8872. In some instances, `key` is a required field.
  8873. properties:
  8874. key:
  8875. description: |-
  8876. A key in the referenced Secret.
  8877. Some instances of this field may be defaulted, in others it may be required.
  8878. maxLength: 253
  8879. minLength: 1
  8880. pattern: ^[-._a-zA-Z0-9]+$
  8881. type: string
  8882. name:
  8883. description: The name of the Secret resource being referred to.
  8884. maxLength: 253
  8885. minLength: 1
  8886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8887. type: string
  8888. namespace:
  8889. description: |-
  8890. The namespace of the Secret resource being referred to.
  8891. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8892. maxLength: 63
  8893. minLength: 1
  8894. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8895. type: string
  8896. type: object
  8897. usernameSecret:
  8898. description: |-
  8899. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  8900. In some instances, `key` is a required field.
  8901. properties:
  8902. key:
  8903. description: |-
  8904. A key in the referenced Secret.
  8905. Some instances of this field may be defaulted, in others it may be required.
  8906. maxLength: 253
  8907. minLength: 1
  8908. pattern: ^[-._a-zA-Z0-9]+$
  8909. type: string
  8910. name:
  8911. description: The name of the Secret resource being referred to.
  8912. maxLength: 253
  8913. minLength: 1
  8914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8915. type: string
  8916. namespace:
  8917. description: |-
  8918. The namespace of the Secret resource being referred to.
  8919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8920. maxLength: 63
  8921. minLength: 1
  8922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8923. type: string
  8924. type: object
  8925. required:
  8926. - passwordSecret
  8927. - usernameSecret
  8928. type: object
  8929. type: object
  8930. body:
  8931. description: Body
  8932. type: string
  8933. caBundle:
  8934. description: |-
  8935. PEM encoded CA bundle used to validate webhook server certificate. Only used
  8936. if the Server URL is using HTTPS protocol. This parameter is ignored for
  8937. plain HTTP protocol connection. If not set the system root certificates
  8938. are used to validate the TLS connection.
  8939. format: byte
  8940. type: string
  8941. caProvider:
  8942. description: The provider for the CA bundle to use to validate webhook server certificate.
  8943. properties:
  8944. key:
  8945. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8946. maxLength: 253
  8947. minLength: 1
  8948. pattern: ^[-._a-zA-Z0-9]+$
  8949. type: string
  8950. name:
  8951. description: The name of the object located at the provider type.
  8952. maxLength: 253
  8953. minLength: 1
  8954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8955. type: string
  8956. namespace:
  8957. description: The namespace the Provider type is in.
  8958. maxLength: 63
  8959. minLength: 1
  8960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8961. type: string
  8962. type:
  8963. description: The type of provider to use such as "Secret", or "ConfigMap".
  8964. enum:
  8965. - Secret
  8966. - ConfigMap
  8967. type: string
  8968. required:
  8969. - name
  8970. - type
  8971. type: object
  8972. headers:
  8973. additionalProperties:
  8974. type: string
  8975. description: Headers
  8976. type: object
  8977. method:
  8978. description: Webhook Method
  8979. type: string
  8980. result:
  8981. description: Result formatting
  8982. properties:
  8983. jsonPath:
  8984. description: Json path of return value
  8985. type: string
  8986. type: object
  8987. secrets:
  8988. description: |-
  8989. Secrets to fill in templates
  8990. These secrets will be passed to the templating function as key value pairs under the given name
  8991. items:
  8992. description: WebhookSecret defines a secret that will be passed to the webhook request.
  8993. properties:
  8994. name:
  8995. description: Name of this secret in templates
  8996. type: string
  8997. secretRef:
  8998. description: Secret ref to fill in credentials
  8999. properties:
  9000. key:
  9001. description: |-
  9002. A key in the referenced Secret.
  9003. Some instances of this field may be defaulted, in others it may be required.
  9004. maxLength: 253
  9005. minLength: 1
  9006. pattern: ^[-._a-zA-Z0-9]+$
  9007. type: string
  9008. name:
  9009. description: The name of the Secret resource being referred to.
  9010. maxLength: 253
  9011. minLength: 1
  9012. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9013. type: string
  9014. namespace:
  9015. description: |-
  9016. The namespace of the Secret resource being referred to.
  9017. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9018. maxLength: 63
  9019. minLength: 1
  9020. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9021. type: string
  9022. type: object
  9023. required:
  9024. - name
  9025. - secretRef
  9026. type: object
  9027. type: array
  9028. timeout:
  9029. description: Timeout
  9030. type: string
  9031. url:
  9032. description: Webhook url to call
  9033. type: string
  9034. required:
  9035. - url
  9036. type: object
  9037. yandexcertificatemanager:
  9038. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  9039. properties:
  9040. apiEndpoint:
  9041. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9042. type: string
  9043. auth:
  9044. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9045. properties:
  9046. authorizedKeySecretRef:
  9047. description: The authorized key used for authentication
  9048. properties:
  9049. key:
  9050. description: |-
  9051. A key in the referenced Secret.
  9052. Some instances of this field may be defaulted, in others it may be required.
  9053. maxLength: 253
  9054. minLength: 1
  9055. pattern: ^[-._a-zA-Z0-9]+$
  9056. type: string
  9057. name:
  9058. description: The name of the Secret resource being referred to.
  9059. maxLength: 253
  9060. minLength: 1
  9061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9062. type: string
  9063. namespace:
  9064. description: |-
  9065. The namespace of the Secret resource being referred to.
  9066. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9067. maxLength: 63
  9068. minLength: 1
  9069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9070. type: string
  9071. type: object
  9072. type: object
  9073. caProvider:
  9074. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9075. properties:
  9076. certSecretRef:
  9077. description: |-
  9078. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9079. In some instances, `key` is a required field.
  9080. properties:
  9081. key:
  9082. description: |-
  9083. A key in the referenced Secret.
  9084. Some instances of this field may be defaulted, in others it may be required.
  9085. maxLength: 253
  9086. minLength: 1
  9087. pattern: ^[-._a-zA-Z0-9]+$
  9088. type: string
  9089. name:
  9090. description: The name of the Secret resource being referred to.
  9091. maxLength: 253
  9092. minLength: 1
  9093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9094. type: string
  9095. namespace:
  9096. description: |-
  9097. The namespace of the Secret resource being referred to.
  9098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9099. maxLength: 63
  9100. minLength: 1
  9101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9102. type: string
  9103. type: object
  9104. type: object
  9105. fetching:
  9106. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  9107. maxProperties: 1
  9108. minProperties: 1
  9109. properties:
  9110. byID:
  9111. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9112. type: object
  9113. byName:
  9114. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9115. properties:
  9116. folderID:
  9117. description: The folder to fetch secrets from
  9118. type: string
  9119. required:
  9120. - folderID
  9121. type: object
  9122. type: object
  9123. required:
  9124. - auth
  9125. type: object
  9126. yandexlockbox:
  9127. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9128. properties:
  9129. apiEndpoint:
  9130. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9131. type: string
  9132. auth:
  9133. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  9134. properties:
  9135. authorizedKeySecretRef:
  9136. description: The authorized key used for authentication
  9137. properties:
  9138. key:
  9139. description: |-
  9140. A key in the referenced Secret.
  9141. Some instances of this field may be defaulted, in others it may be required.
  9142. maxLength: 253
  9143. minLength: 1
  9144. pattern: ^[-._a-zA-Z0-9]+$
  9145. type: string
  9146. name:
  9147. description: The name of the Secret resource being referred to.
  9148. maxLength: 253
  9149. minLength: 1
  9150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9151. type: string
  9152. namespace:
  9153. description: |-
  9154. The namespace of the Secret resource being referred to.
  9155. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9156. maxLength: 63
  9157. minLength: 1
  9158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9159. type: string
  9160. type: object
  9161. type: object
  9162. caProvider:
  9163. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9164. properties:
  9165. certSecretRef:
  9166. description: |-
  9167. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9168. In some instances, `key` is a required field.
  9169. properties:
  9170. key:
  9171. description: |-
  9172. A key in the referenced Secret.
  9173. Some instances of this field may be defaulted, in others it may be required.
  9174. maxLength: 253
  9175. minLength: 1
  9176. pattern: ^[-._a-zA-Z0-9]+$
  9177. type: string
  9178. name:
  9179. description: The name of the Secret resource being referred to.
  9180. maxLength: 253
  9181. minLength: 1
  9182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9183. type: string
  9184. namespace:
  9185. description: |-
  9186. The namespace of the Secret resource being referred to.
  9187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9188. maxLength: 63
  9189. minLength: 1
  9190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9191. type: string
  9192. type: object
  9193. type: object
  9194. fetching:
  9195. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  9196. maxProperties: 1
  9197. minProperties: 1
  9198. properties:
  9199. byID:
  9200. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  9201. type: object
  9202. byName:
  9203. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  9204. properties:
  9205. folderID:
  9206. description: The folder to fetch secrets from
  9207. type: string
  9208. required:
  9209. - folderID
  9210. type: object
  9211. type: object
  9212. required:
  9213. - auth
  9214. type: object
  9215. type: object
  9216. refreshInterval:
  9217. anyOf:
  9218. - type: integer
  9219. - type: string
  9220. description: |-
  9221. Used to configure store refresh interval. Accepts either an integer number
  9222. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  9223. 0 will default to the controller config.
  9224. x-kubernetes-int-or-string: true
  9225. retrySettings:
  9226. description: Used to configure HTTP retries on failures.
  9227. properties:
  9228. maxRetries:
  9229. format: int32
  9230. type: integer
  9231. retryInterval:
  9232. type: string
  9233. type: object
  9234. required:
  9235. - provider
  9236. type: object
  9237. status:
  9238. description: SecretStoreStatus defines the observed state of the SecretStore.
  9239. properties:
  9240. capabilities:
  9241. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  9242. type: string
  9243. conditions:
  9244. items:
  9245. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  9246. properties:
  9247. lastTransitionTime:
  9248. format: date-time
  9249. type: string
  9250. message:
  9251. type: string
  9252. reason:
  9253. type: string
  9254. status:
  9255. type: string
  9256. type:
  9257. description: SecretStoreConditionType represents the condition of the SecretStore.
  9258. type: string
  9259. required:
  9260. - status
  9261. - type
  9262. type: object
  9263. type: array
  9264. type: object
  9265. type: object
  9266. served: true
  9267. storage: true
  9268. subresources:
  9269. status: {}
  9270. - additionalPrinterColumns:
  9271. - jsonPath: .metadata.creationTimestamp
  9272. name: AGE
  9273. type: date
  9274. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9275. name: Status
  9276. type: string
  9277. - jsonPath: .status.capabilities
  9278. name: Capabilities
  9279. type: string
  9280. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9281. name: Ready
  9282. type: string
  9283. deprecated: true
  9284. name: v1beta1
  9285. schema:
  9286. openAPIV3Schema:
  9287. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9288. properties:
  9289. apiVersion:
  9290. description: |-
  9291. APIVersion defines the versioned schema of this representation of an object.
  9292. Servers should convert recognized schemas to the latest internal value, and
  9293. may reject unrecognized values.
  9294. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9295. type: string
  9296. kind:
  9297. description: |-
  9298. Kind is a string value representing the REST resource this object represents.
  9299. Servers may infer this from the endpoint the client submits requests to.
  9300. Cannot be updated.
  9301. In CamelCase.
  9302. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9303. type: string
  9304. metadata:
  9305. type: object
  9306. spec:
  9307. description: SecretStoreSpec defines the desired state of SecretStore.
  9308. properties:
  9309. conditions:
  9310. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  9311. items:
  9312. description: |-
  9313. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9314. for a ClusterSecretStore instance.
  9315. properties:
  9316. namespaceRegexes:
  9317. description: Choose namespaces by using regex matching
  9318. items:
  9319. type: string
  9320. type: array
  9321. namespaceSelector:
  9322. description: Choose namespace using a labelSelector
  9323. properties:
  9324. matchExpressions:
  9325. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9326. items:
  9327. description: |-
  9328. A label selector requirement is a selector that contains values, a key, and an operator that
  9329. relates the key and values.
  9330. properties:
  9331. key:
  9332. description: key is the label key that the selector applies to.
  9333. type: string
  9334. operator:
  9335. description: |-
  9336. operator represents a key's relationship to a set of values.
  9337. Valid operators are In, NotIn, Exists and DoesNotExist.
  9338. type: string
  9339. values:
  9340. description: |-
  9341. values is an array of string values. If the operator is In or NotIn,
  9342. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9343. the values array must be empty. This array is replaced during a strategic
  9344. merge patch.
  9345. items:
  9346. type: string
  9347. type: array
  9348. x-kubernetes-list-type: atomic
  9349. required:
  9350. - key
  9351. - operator
  9352. type: object
  9353. type: array
  9354. x-kubernetes-list-type: atomic
  9355. matchLabels:
  9356. additionalProperties:
  9357. type: string
  9358. description: |-
  9359. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9360. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9361. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9362. type: object
  9363. type: object
  9364. x-kubernetes-map-type: atomic
  9365. namespaces:
  9366. description: Choose namespaces by name
  9367. items:
  9368. maxLength: 63
  9369. minLength: 1
  9370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9371. type: string
  9372. type: array
  9373. type: object
  9374. type: array
  9375. controller:
  9376. description: |-
  9377. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9378. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9379. type: string
  9380. provider:
  9381. description: Used to configure the provider. Only one provider may be set
  9382. maxProperties: 1
  9383. minProperties: 1
  9384. properties:
  9385. akeyless:
  9386. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9387. properties:
  9388. akeylessGWApiURL:
  9389. description: Akeyless GW API Url from which the secrets to be fetched from.
  9390. type: string
  9391. authSecretRef:
  9392. description: Auth configures how the operator authenticates with Akeyless.
  9393. properties:
  9394. kubernetesAuth:
  9395. description: |-
  9396. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9397. token stored in the named Secret resource.
  9398. properties:
  9399. accessID:
  9400. description: the Akeyless Kubernetes auth-method access-id
  9401. type: string
  9402. k8sConfName:
  9403. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9404. type: string
  9405. secretRef:
  9406. description: |-
  9407. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9408. for authenticating with Akeyless. If a name is specified without a key,
  9409. `token` is the default. If one is not specified, the one bound to
  9410. the controller will be used.
  9411. properties:
  9412. key:
  9413. description: |-
  9414. A key in the referenced Secret.
  9415. Some instances of this field may be defaulted, in others it may be required.
  9416. maxLength: 253
  9417. minLength: 1
  9418. pattern: ^[-._a-zA-Z0-9]+$
  9419. type: string
  9420. name:
  9421. description: The name of the Secret resource being referred to.
  9422. maxLength: 253
  9423. minLength: 1
  9424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9425. type: string
  9426. namespace:
  9427. description: |-
  9428. The namespace of the Secret resource being referred to.
  9429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9430. maxLength: 63
  9431. minLength: 1
  9432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9433. type: string
  9434. type: object
  9435. serviceAccountRef:
  9436. description: |-
  9437. Optional service account field containing the name of a kubernetes ServiceAccount.
  9438. If the service account is specified, the service account secret token JWT will be used
  9439. for authenticating with Akeyless. If the service account selector is not supplied,
  9440. the secretRef will be used instead.
  9441. properties:
  9442. audiences:
  9443. description: |-
  9444. Audience specifies the `aud` claim for the service account token
  9445. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9446. then this audiences will be appended to the list
  9447. items:
  9448. type: string
  9449. type: array
  9450. name:
  9451. description: The name of the ServiceAccount resource being referred to.
  9452. maxLength: 253
  9453. minLength: 1
  9454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9455. type: string
  9456. namespace:
  9457. description: |-
  9458. Namespace of the resource being referred to.
  9459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9460. maxLength: 63
  9461. minLength: 1
  9462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9463. type: string
  9464. required:
  9465. - name
  9466. type: object
  9467. required:
  9468. - accessID
  9469. - k8sConfName
  9470. type: object
  9471. secretRef:
  9472. description: |-
  9473. Reference to a Secret that contains the details
  9474. to authenticate with Akeyless.
  9475. properties:
  9476. accessID:
  9477. description: The SecretAccessID is used for authentication
  9478. properties:
  9479. key:
  9480. description: |-
  9481. A key in the referenced Secret.
  9482. Some instances of this field may be defaulted, in others it may be required.
  9483. maxLength: 253
  9484. minLength: 1
  9485. pattern: ^[-._a-zA-Z0-9]+$
  9486. type: string
  9487. name:
  9488. description: The name of the Secret resource being referred to.
  9489. maxLength: 253
  9490. minLength: 1
  9491. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9492. type: string
  9493. namespace:
  9494. description: |-
  9495. The namespace of the Secret resource being referred to.
  9496. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9497. maxLength: 63
  9498. minLength: 1
  9499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9500. type: string
  9501. type: object
  9502. accessType:
  9503. description: |-
  9504. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9505. In some instances, `key` is a required field.
  9506. properties:
  9507. key:
  9508. description: |-
  9509. A key in the referenced Secret.
  9510. Some instances of this field may be defaulted, in others it may be required.
  9511. maxLength: 253
  9512. minLength: 1
  9513. pattern: ^[-._a-zA-Z0-9]+$
  9514. type: string
  9515. name:
  9516. description: The name of the Secret resource being referred to.
  9517. maxLength: 253
  9518. minLength: 1
  9519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9520. type: string
  9521. namespace:
  9522. description: |-
  9523. The namespace of the Secret resource being referred to.
  9524. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9525. maxLength: 63
  9526. minLength: 1
  9527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9528. type: string
  9529. type: object
  9530. accessTypeParam:
  9531. description: |-
  9532. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  9533. In some instances, `key` is a required field.
  9534. properties:
  9535. key:
  9536. description: |-
  9537. A key in the referenced Secret.
  9538. Some instances of this field may be defaulted, in others it may be required.
  9539. maxLength: 253
  9540. minLength: 1
  9541. pattern: ^[-._a-zA-Z0-9]+$
  9542. type: string
  9543. name:
  9544. description: The name of the Secret resource being referred to.
  9545. maxLength: 253
  9546. minLength: 1
  9547. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9548. type: string
  9549. namespace:
  9550. description: |-
  9551. The namespace of the Secret resource being referred to.
  9552. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9553. maxLength: 63
  9554. minLength: 1
  9555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9556. type: string
  9557. type: object
  9558. type: object
  9559. type: object
  9560. caBundle:
  9561. description: |-
  9562. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9563. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9564. are used to validate the TLS connection.
  9565. format: byte
  9566. type: string
  9567. caProvider:
  9568. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9569. properties:
  9570. key:
  9571. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9572. maxLength: 253
  9573. minLength: 1
  9574. pattern: ^[-._a-zA-Z0-9]+$
  9575. type: string
  9576. name:
  9577. description: The name of the object located at the provider type.
  9578. maxLength: 253
  9579. minLength: 1
  9580. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9581. type: string
  9582. namespace:
  9583. description: |-
  9584. The namespace the Provider type is in.
  9585. Can only be defined when used in a ClusterSecretStore.
  9586. maxLength: 63
  9587. minLength: 1
  9588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9589. type: string
  9590. type:
  9591. description: The type of provider to use such as "Secret", or "ConfigMap".
  9592. enum:
  9593. - Secret
  9594. - ConfigMap
  9595. type: string
  9596. required:
  9597. - name
  9598. - type
  9599. type: object
  9600. required:
  9601. - akeylessGWApiURL
  9602. - authSecretRef
  9603. type: object
  9604. alibaba:
  9605. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9606. properties:
  9607. auth:
  9608. description: AlibabaAuth contains a secretRef for credentials.
  9609. properties:
  9610. rrsa:
  9611. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  9612. properties:
  9613. oidcProviderArn:
  9614. type: string
  9615. oidcTokenFilePath:
  9616. type: string
  9617. roleArn:
  9618. type: string
  9619. sessionName:
  9620. type: string
  9621. required:
  9622. - oidcProviderArn
  9623. - oidcTokenFilePath
  9624. - roleArn
  9625. - sessionName
  9626. type: object
  9627. secretRef:
  9628. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9629. properties:
  9630. accessKeyIDSecretRef:
  9631. description: The AccessKeyID is used for authentication
  9632. properties:
  9633. key:
  9634. description: |-
  9635. A key in the referenced Secret.
  9636. Some instances of this field may be defaulted, in others it may be required.
  9637. maxLength: 253
  9638. minLength: 1
  9639. pattern: ^[-._a-zA-Z0-9]+$
  9640. type: string
  9641. name:
  9642. description: The name of the Secret resource being referred to.
  9643. maxLength: 253
  9644. minLength: 1
  9645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9646. type: string
  9647. namespace:
  9648. description: |-
  9649. The namespace of the Secret resource being referred to.
  9650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9651. maxLength: 63
  9652. minLength: 1
  9653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9654. type: string
  9655. type: object
  9656. accessKeySecretSecretRef:
  9657. description: The AccessKeySecret is used for authentication
  9658. properties:
  9659. key:
  9660. description: |-
  9661. A key in the referenced Secret.
  9662. Some instances of this field may be defaulted, in others it may be required.
  9663. maxLength: 253
  9664. minLength: 1
  9665. pattern: ^[-._a-zA-Z0-9]+$
  9666. type: string
  9667. name:
  9668. description: The name of the Secret resource being referred to.
  9669. maxLength: 253
  9670. minLength: 1
  9671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9672. type: string
  9673. namespace:
  9674. description: |-
  9675. The namespace of the Secret resource being referred to.
  9676. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9677. maxLength: 63
  9678. minLength: 1
  9679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9680. type: string
  9681. type: object
  9682. required:
  9683. - accessKeyIDSecretRef
  9684. - accessKeySecretSecretRef
  9685. type: object
  9686. type: object
  9687. regionID:
  9688. description: Alibaba Region to be used for the provider
  9689. type: string
  9690. required:
  9691. - auth
  9692. - regionID
  9693. type: object
  9694. aws:
  9695. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  9696. properties:
  9697. additionalRoles:
  9698. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  9699. items:
  9700. type: string
  9701. type: array
  9702. auth:
  9703. description: |-
  9704. Auth defines the information necessary to authenticate against AWS
  9705. if not set aws sdk will infer credentials from your environment
  9706. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  9707. properties:
  9708. jwt:
  9709. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  9710. properties:
  9711. serviceAccountRef:
  9712. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  9713. properties:
  9714. audiences:
  9715. description: |-
  9716. Audience specifies the `aud` claim for the service account token
  9717. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9718. then this audiences will be appended to the list
  9719. items:
  9720. type: string
  9721. type: array
  9722. name:
  9723. description: The name of the ServiceAccount resource being referred to.
  9724. maxLength: 253
  9725. minLength: 1
  9726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9727. type: string
  9728. namespace:
  9729. description: |-
  9730. Namespace of the resource being referred to.
  9731. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9732. maxLength: 63
  9733. minLength: 1
  9734. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9735. type: string
  9736. required:
  9737. - name
  9738. type: object
  9739. type: object
  9740. secretRef:
  9741. description: |-
  9742. AWSAuthSecretRef holds secret references for AWS credentials
  9743. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  9744. properties:
  9745. accessKeyIDSecretRef:
  9746. description: The AccessKeyID is used for authentication
  9747. properties:
  9748. key:
  9749. description: |-
  9750. A key in the referenced Secret.
  9751. Some instances of this field may be defaulted, in others it may be required.
  9752. maxLength: 253
  9753. minLength: 1
  9754. pattern: ^[-._a-zA-Z0-9]+$
  9755. type: string
  9756. name:
  9757. description: The name of the Secret resource being referred to.
  9758. maxLength: 253
  9759. minLength: 1
  9760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9761. type: string
  9762. namespace:
  9763. description: |-
  9764. The namespace of the Secret resource being referred to.
  9765. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9766. maxLength: 63
  9767. minLength: 1
  9768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9769. type: string
  9770. type: object
  9771. secretAccessKeySecretRef:
  9772. description: The SecretAccessKey is used for authentication
  9773. properties:
  9774. key:
  9775. description: |-
  9776. A key in the referenced Secret.
  9777. Some instances of this field may be defaulted, in others it may be required.
  9778. maxLength: 253
  9779. minLength: 1
  9780. pattern: ^[-._a-zA-Z0-9]+$
  9781. type: string
  9782. name:
  9783. description: The name of the Secret resource being referred to.
  9784. maxLength: 253
  9785. minLength: 1
  9786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9787. type: string
  9788. namespace:
  9789. description: |-
  9790. The namespace of the Secret resource being referred to.
  9791. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9792. maxLength: 63
  9793. minLength: 1
  9794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9795. type: string
  9796. type: object
  9797. sessionTokenSecretRef:
  9798. description: |-
  9799. The SessionToken used for authentication
  9800. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  9801. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  9802. properties:
  9803. key:
  9804. description: |-
  9805. A key in the referenced Secret.
  9806. Some instances of this field may be defaulted, in others it may be required.
  9807. maxLength: 253
  9808. minLength: 1
  9809. pattern: ^[-._a-zA-Z0-9]+$
  9810. type: string
  9811. name:
  9812. description: The name of the Secret resource being referred to.
  9813. maxLength: 253
  9814. minLength: 1
  9815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9816. type: string
  9817. namespace:
  9818. description: |-
  9819. The namespace of the Secret resource being referred to.
  9820. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9821. maxLength: 63
  9822. minLength: 1
  9823. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9824. type: string
  9825. type: object
  9826. type: object
  9827. type: object
  9828. externalID:
  9829. description: AWS External ID set on assumed IAM roles
  9830. type: string
  9831. prefix:
  9832. description: Prefix adds a prefix to all retrieved values.
  9833. type: string
  9834. region:
  9835. description: AWS Region to be used for the provider
  9836. type: string
  9837. role:
  9838. description: Role is a Role ARN which the provider will assume
  9839. type: string
  9840. secretsManager:
  9841. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  9842. properties:
  9843. forceDeleteWithoutRecovery:
  9844. description: |-
  9845. Specifies whether to delete the secret without any recovery window. You
  9846. can't use both this parameter and RecoveryWindowInDays in the same call.
  9847. If you don't use either, then by default Secrets Manager uses a 30 day
  9848. recovery window.
  9849. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  9850. type: boolean
  9851. recoveryWindowInDays:
  9852. description: |-
  9853. The number of days from 7 to 30 that Secrets Manager waits before
  9854. permanently deleting the secret. You can't use both this parameter and
  9855. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  9856. then by default Secrets Manager uses a 30 day recovery window.
  9857. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  9858. format: int64
  9859. type: integer
  9860. type: object
  9861. service:
  9862. description: Service defines which service should be used to fetch the secrets
  9863. enum:
  9864. - SecretsManager
  9865. - ParameterStore
  9866. type: string
  9867. sessionTags:
  9868. description: AWS STS assume role session tags
  9869. items:
  9870. description: Tag defines a tag key and value for AWS resources.
  9871. properties:
  9872. key:
  9873. type: string
  9874. value:
  9875. type: string
  9876. required:
  9877. - key
  9878. - value
  9879. type: object
  9880. type: array
  9881. transitiveTagKeys:
  9882. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  9883. items:
  9884. type: string
  9885. type: array
  9886. required:
  9887. - region
  9888. - service
  9889. type: object
  9890. azurekv:
  9891. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  9892. properties:
  9893. authSecretRef:
  9894. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  9895. properties:
  9896. clientCertificate:
  9897. description: The Azure ClientCertificate of the service principle used for authentication.
  9898. properties:
  9899. key:
  9900. description: |-
  9901. A key in the referenced Secret.
  9902. Some instances of this field may be defaulted, in others it may be required.
  9903. maxLength: 253
  9904. minLength: 1
  9905. pattern: ^[-._a-zA-Z0-9]+$
  9906. type: string
  9907. name:
  9908. description: The name of the Secret resource being referred to.
  9909. maxLength: 253
  9910. minLength: 1
  9911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9912. type: string
  9913. namespace:
  9914. description: |-
  9915. The namespace of the Secret resource being referred to.
  9916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9917. maxLength: 63
  9918. minLength: 1
  9919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9920. type: string
  9921. type: object
  9922. clientId:
  9923. description: The Azure clientId of the service principle or managed identity used for authentication.
  9924. properties:
  9925. key:
  9926. description: |-
  9927. A key in the referenced Secret.
  9928. Some instances of this field may be defaulted, in others it may be required.
  9929. maxLength: 253
  9930. minLength: 1
  9931. pattern: ^[-._a-zA-Z0-9]+$
  9932. type: string
  9933. name:
  9934. description: The name of the Secret resource being referred to.
  9935. maxLength: 253
  9936. minLength: 1
  9937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9938. type: string
  9939. namespace:
  9940. description: |-
  9941. The namespace of the Secret resource being referred to.
  9942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9943. maxLength: 63
  9944. minLength: 1
  9945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9946. type: string
  9947. type: object
  9948. clientSecret:
  9949. description: The Azure ClientSecret of the service principle used for authentication.
  9950. properties:
  9951. key:
  9952. description: |-
  9953. A key in the referenced Secret.
  9954. Some instances of this field may be defaulted, in others it may be required.
  9955. maxLength: 253
  9956. minLength: 1
  9957. pattern: ^[-._a-zA-Z0-9]+$
  9958. type: string
  9959. name:
  9960. description: The name of the Secret resource being referred to.
  9961. maxLength: 253
  9962. minLength: 1
  9963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9964. type: string
  9965. namespace:
  9966. description: |-
  9967. The namespace of the Secret resource being referred to.
  9968. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9969. maxLength: 63
  9970. minLength: 1
  9971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9972. type: string
  9973. type: object
  9974. tenantId:
  9975. description: The Azure tenantId of the managed identity used for authentication.
  9976. properties:
  9977. key:
  9978. description: |-
  9979. A key in the referenced Secret.
  9980. Some instances of this field may be defaulted, in others it may be required.
  9981. maxLength: 253
  9982. minLength: 1
  9983. pattern: ^[-._a-zA-Z0-9]+$
  9984. type: string
  9985. name:
  9986. description: The name of the Secret resource being referred to.
  9987. maxLength: 253
  9988. minLength: 1
  9989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9990. type: string
  9991. namespace:
  9992. description: |-
  9993. The namespace of the Secret resource being referred to.
  9994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9995. maxLength: 63
  9996. minLength: 1
  9997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9998. type: string
  9999. type: object
  10000. type: object
  10001. authType:
  10002. default: ServicePrincipal
  10003. description: |-
  10004. Auth type defines how to authenticate to the keyvault service.
  10005. Valid values are:
  10006. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10007. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10008. enum:
  10009. - ServicePrincipal
  10010. - ManagedIdentity
  10011. - WorkloadIdentity
  10012. type: string
  10013. environmentType:
  10014. default: PublicCloud
  10015. description: |-
  10016. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10017. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10018. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10019. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10020. enum:
  10021. - PublicCloud
  10022. - USGovernmentCloud
  10023. - ChinaCloud
  10024. - GermanCloud
  10025. type: string
  10026. identityId:
  10027. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10028. type: string
  10029. serviceAccountRef:
  10030. description: |-
  10031. ServiceAccountRef specified the service account
  10032. that should be used when authenticating with WorkloadIdentity.
  10033. properties:
  10034. audiences:
  10035. description: |-
  10036. Audience specifies the `aud` claim for the service account token
  10037. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10038. then this audiences will be appended to the list
  10039. items:
  10040. type: string
  10041. type: array
  10042. name:
  10043. description: The name of the ServiceAccount resource being referred to.
  10044. maxLength: 253
  10045. minLength: 1
  10046. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10047. type: string
  10048. namespace:
  10049. description: |-
  10050. Namespace of the resource being referred to.
  10051. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10052. maxLength: 63
  10053. minLength: 1
  10054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10055. type: string
  10056. required:
  10057. - name
  10058. type: object
  10059. tenantId:
  10060. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10061. type: string
  10062. vaultUrl:
  10063. description: Vault Url from which the secrets to be fetched from.
  10064. type: string
  10065. required:
  10066. - vaultUrl
  10067. type: object
  10068. beyondtrust:
  10069. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10070. properties:
  10071. auth:
  10072. description: Auth configures how the operator authenticates with Beyondtrust.
  10073. properties:
  10074. apiKey:
  10075. description: APIKey If not provided then ClientID/ClientSecret become required.
  10076. properties:
  10077. secretRef:
  10078. description: SecretRef references a key in a secret that will be used as value.
  10079. properties:
  10080. key:
  10081. description: |-
  10082. A key in the referenced Secret.
  10083. Some instances of this field may be defaulted, in others it may be required.
  10084. maxLength: 253
  10085. minLength: 1
  10086. pattern: ^[-._a-zA-Z0-9]+$
  10087. type: string
  10088. name:
  10089. description: The name of the Secret resource being referred to.
  10090. maxLength: 253
  10091. minLength: 1
  10092. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10093. type: string
  10094. namespace:
  10095. description: |-
  10096. The namespace of the Secret resource being referred to.
  10097. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10098. maxLength: 63
  10099. minLength: 1
  10100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10101. type: string
  10102. type: object
  10103. value:
  10104. description: Value can be specified directly to set a value without using a secret.
  10105. type: string
  10106. type: object
  10107. certificate:
  10108. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10109. properties:
  10110. secretRef:
  10111. description: SecretRef references a key in a secret that will be used as value.
  10112. properties:
  10113. key:
  10114. description: |-
  10115. A key in the referenced Secret.
  10116. Some instances of this field may be defaulted, in others it may be required.
  10117. maxLength: 253
  10118. minLength: 1
  10119. pattern: ^[-._a-zA-Z0-9]+$
  10120. type: string
  10121. name:
  10122. description: The name of the Secret resource being referred to.
  10123. maxLength: 253
  10124. minLength: 1
  10125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10126. type: string
  10127. namespace:
  10128. description: |-
  10129. The namespace of the Secret resource being referred to.
  10130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10131. maxLength: 63
  10132. minLength: 1
  10133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10134. type: string
  10135. type: object
  10136. value:
  10137. description: Value can be specified directly to set a value without using a secret.
  10138. type: string
  10139. type: object
  10140. certificateKey:
  10141. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10142. properties:
  10143. secretRef:
  10144. description: SecretRef references a key in a secret that will be used as value.
  10145. properties:
  10146. key:
  10147. description: |-
  10148. A key in the referenced Secret.
  10149. Some instances of this field may be defaulted, in others it may be required.
  10150. maxLength: 253
  10151. minLength: 1
  10152. pattern: ^[-._a-zA-Z0-9]+$
  10153. type: string
  10154. name:
  10155. description: The name of the Secret resource being referred to.
  10156. maxLength: 253
  10157. minLength: 1
  10158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10159. type: string
  10160. namespace:
  10161. description: |-
  10162. The namespace of the Secret resource being referred to.
  10163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10164. maxLength: 63
  10165. minLength: 1
  10166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10167. type: string
  10168. type: object
  10169. value:
  10170. description: Value can be specified directly to set a value without using a secret.
  10171. type: string
  10172. type: object
  10173. clientId:
  10174. description: ClientID is the API OAuth Client ID.
  10175. properties:
  10176. secretRef:
  10177. description: SecretRef references a key in a secret that will be used as value.
  10178. properties:
  10179. key:
  10180. description: |-
  10181. A key in the referenced Secret.
  10182. Some instances of this field may be defaulted, in others it may be required.
  10183. maxLength: 253
  10184. minLength: 1
  10185. pattern: ^[-._a-zA-Z0-9]+$
  10186. type: string
  10187. name:
  10188. description: The name of the Secret resource being referred to.
  10189. maxLength: 253
  10190. minLength: 1
  10191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10192. type: string
  10193. namespace:
  10194. description: |-
  10195. The namespace of the Secret resource being referred to.
  10196. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10197. maxLength: 63
  10198. minLength: 1
  10199. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10200. type: string
  10201. type: object
  10202. value:
  10203. description: Value can be specified directly to set a value without using a secret.
  10204. type: string
  10205. type: object
  10206. clientSecret:
  10207. description: ClientSecret is the API OAuth Client Secret.
  10208. properties:
  10209. secretRef:
  10210. description: SecretRef references a key in a secret that will be used as value.
  10211. properties:
  10212. key:
  10213. description: |-
  10214. A key in the referenced Secret.
  10215. Some instances of this field may be defaulted, in others it may be required.
  10216. maxLength: 253
  10217. minLength: 1
  10218. pattern: ^[-._a-zA-Z0-9]+$
  10219. type: string
  10220. name:
  10221. description: The name of the Secret resource being referred to.
  10222. maxLength: 253
  10223. minLength: 1
  10224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10225. type: string
  10226. namespace:
  10227. description: |-
  10228. The namespace of the Secret resource being referred to.
  10229. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10230. maxLength: 63
  10231. minLength: 1
  10232. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10233. type: string
  10234. type: object
  10235. value:
  10236. description: Value can be specified directly to set a value without using a secret.
  10237. type: string
  10238. type: object
  10239. type: object
  10240. server:
  10241. description: Auth configures how API server works.
  10242. properties:
  10243. apiUrl:
  10244. type: string
  10245. apiVersion:
  10246. type: string
  10247. clientTimeOutSeconds:
  10248. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10249. type: integer
  10250. decrypt:
  10251. default: true
  10252. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  10253. type: boolean
  10254. retrievalType:
  10255. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10256. type: string
  10257. separator:
  10258. description: A character that separates the folder names.
  10259. type: string
  10260. verifyCA:
  10261. type: boolean
  10262. required:
  10263. - apiUrl
  10264. - verifyCA
  10265. type: object
  10266. required:
  10267. - auth
  10268. - server
  10269. type: object
  10270. bitwardensecretsmanager:
  10271. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10272. properties:
  10273. apiURL:
  10274. type: string
  10275. auth:
  10276. description: |-
  10277. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10278. Make sure that the token being used has permissions on the given secret.
  10279. properties:
  10280. secretRef:
  10281. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10282. properties:
  10283. credentials:
  10284. description: AccessToken used for the bitwarden instance.
  10285. properties:
  10286. key:
  10287. description: |-
  10288. A key in the referenced Secret.
  10289. Some instances of this field may be defaulted, in others it may be required.
  10290. maxLength: 253
  10291. minLength: 1
  10292. pattern: ^[-._a-zA-Z0-9]+$
  10293. type: string
  10294. name:
  10295. description: The name of the Secret resource being referred to.
  10296. maxLength: 253
  10297. minLength: 1
  10298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10299. type: string
  10300. namespace:
  10301. description: |-
  10302. The namespace of the Secret resource being referred to.
  10303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10304. maxLength: 63
  10305. minLength: 1
  10306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10307. type: string
  10308. type: object
  10309. required:
  10310. - credentials
  10311. type: object
  10312. required:
  10313. - secretRef
  10314. type: object
  10315. bitwardenServerSDKURL:
  10316. type: string
  10317. caBundle:
  10318. description: |-
  10319. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10320. can be performed.
  10321. type: string
  10322. caProvider:
  10323. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10324. properties:
  10325. key:
  10326. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10327. maxLength: 253
  10328. minLength: 1
  10329. pattern: ^[-._a-zA-Z0-9]+$
  10330. type: string
  10331. name:
  10332. description: The name of the object located at the provider type.
  10333. maxLength: 253
  10334. minLength: 1
  10335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10336. type: string
  10337. namespace:
  10338. description: |-
  10339. The namespace the Provider type is in.
  10340. Can only be defined when used in a ClusterSecretStore.
  10341. maxLength: 63
  10342. minLength: 1
  10343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10344. type: string
  10345. type:
  10346. description: The type of provider to use such as "Secret", or "ConfigMap".
  10347. enum:
  10348. - Secret
  10349. - ConfigMap
  10350. type: string
  10351. required:
  10352. - name
  10353. - type
  10354. type: object
  10355. identityURL:
  10356. type: string
  10357. organizationID:
  10358. description: OrganizationID determines which organization this secret store manages.
  10359. type: string
  10360. projectID:
  10361. description: ProjectID determines which project this secret store manages.
  10362. type: string
  10363. required:
  10364. - auth
  10365. - organizationID
  10366. - projectID
  10367. type: object
  10368. chef:
  10369. description: Chef configures this store to sync secrets with chef server
  10370. properties:
  10371. auth:
  10372. description: Auth defines the information necessary to authenticate against chef Server
  10373. properties:
  10374. secretRef:
  10375. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10376. properties:
  10377. privateKeySecretRef:
  10378. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10379. properties:
  10380. key:
  10381. description: |-
  10382. A key in the referenced Secret.
  10383. Some instances of this field may be defaulted, in others it may be required.
  10384. maxLength: 253
  10385. minLength: 1
  10386. pattern: ^[-._a-zA-Z0-9]+$
  10387. type: string
  10388. name:
  10389. description: The name of the Secret resource being referred to.
  10390. maxLength: 253
  10391. minLength: 1
  10392. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10393. type: string
  10394. namespace:
  10395. description: |-
  10396. The namespace of the Secret resource being referred to.
  10397. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10398. maxLength: 63
  10399. minLength: 1
  10400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10401. type: string
  10402. type: object
  10403. required:
  10404. - privateKeySecretRef
  10405. type: object
  10406. required:
  10407. - secretRef
  10408. type: object
  10409. serverUrl:
  10410. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10411. type: string
  10412. username:
  10413. description: UserName should be the user ID on the chef server
  10414. type: string
  10415. required:
  10416. - auth
  10417. - serverUrl
  10418. - username
  10419. type: object
  10420. cloudrusm:
  10421. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  10422. properties:
  10423. auth:
  10424. description: CSMAuth contains a secretRef for credentials.
  10425. properties:
  10426. secretRef:
  10427. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  10428. properties:
  10429. accessKeyIDSecretRef:
  10430. description: The AccessKeyID is used for authentication
  10431. properties:
  10432. key:
  10433. description: |-
  10434. A key in the referenced Secret.
  10435. Some instances of this field may be defaulted, in others it may be required.
  10436. maxLength: 253
  10437. minLength: 1
  10438. pattern: ^[-._a-zA-Z0-9]+$
  10439. type: string
  10440. name:
  10441. description: The name of the Secret resource being referred to.
  10442. maxLength: 253
  10443. minLength: 1
  10444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10445. type: string
  10446. namespace:
  10447. description: |-
  10448. The namespace of the Secret resource being referred to.
  10449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10450. maxLength: 63
  10451. minLength: 1
  10452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10453. type: string
  10454. type: object
  10455. accessKeySecretSecretRef:
  10456. description: The AccessKeySecret is used for authentication
  10457. properties:
  10458. key:
  10459. description: |-
  10460. A key in the referenced Secret.
  10461. Some instances of this field may be defaulted, in others it may be required.
  10462. maxLength: 253
  10463. minLength: 1
  10464. pattern: ^[-._a-zA-Z0-9]+$
  10465. type: string
  10466. name:
  10467. description: The name of the Secret resource being referred to.
  10468. maxLength: 253
  10469. minLength: 1
  10470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10471. type: string
  10472. namespace:
  10473. description: |-
  10474. The namespace of the Secret resource being referred to.
  10475. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10476. maxLength: 63
  10477. minLength: 1
  10478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10479. type: string
  10480. type: object
  10481. required:
  10482. - accessKeyIDSecretRef
  10483. - accessKeySecretSecretRef
  10484. type: object
  10485. type: object
  10486. projectID:
  10487. description: ProjectID is the project, which the secrets are stored in.
  10488. type: string
  10489. required:
  10490. - auth
  10491. type: object
  10492. conjur:
  10493. description: Conjur configures this store to sync secrets using conjur provider
  10494. properties:
  10495. auth:
  10496. description: Defines authentication settings for connecting to Conjur.
  10497. properties:
  10498. apikey:
  10499. description: Authenticates with Conjur using an API key.
  10500. properties:
  10501. account:
  10502. description: Account is the Conjur organization account name.
  10503. type: string
  10504. apiKeyRef:
  10505. description: |-
  10506. A reference to a specific 'key' containing the Conjur API key
  10507. within a Secret resource. In some instances, `key` is a required field.
  10508. properties:
  10509. key:
  10510. description: |-
  10511. A key in the referenced Secret.
  10512. Some instances of this field may be defaulted, in others it may be required.
  10513. maxLength: 253
  10514. minLength: 1
  10515. pattern: ^[-._a-zA-Z0-9]+$
  10516. type: string
  10517. name:
  10518. description: The name of the Secret resource being referred to.
  10519. maxLength: 253
  10520. minLength: 1
  10521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10522. type: string
  10523. namespace:
  10524. description: |-
  10525. The namespace of the Secret resource being referred to.
  10526. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10527. maxLength: 63
  10528. minLength: 1
  10529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10530. type: string
  10531. type: object
  10532. userRef:
  10533. description: |-
  10534. A reference to a specific 'key' containing the Conjur username
  10535. within a Secret resource. In some instances, `key` is a required field.
  10536. properties:
  10537. key:
  10538. description: |-
  10539. A key in the referenced Secret.
  10540. Some instances of this field may be defaulted, in others it may be required.
  10541. maxLength: 253
  10542. minLength: 1
  10543. pattern: ^[-._a-zA-Z0-9]+$
  10544. type: string
  10545. name:
  10546. description: The name of the Secret resource being referred to.
  10547. maxLength: 253
  10548. minLength: 1
  10549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10550. type: string
  10551. namespace:
  10552. description: |-
  10553. The namespace of the Secret resource being referred to.
  10554. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10555. maxLength: 63
  10556. minLength: 1
  10557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10558. type: string
  10559. type: object
  10560. required:
  10561. - account
  10562. - apiKeyRef
  10563. - userRef
  10564. type: object
  10565. jwt:
  10566. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  10567. properties:
  10568. account:
  10569. description: Account is the Conjur organization account name.
  10570. type: string
  10571. hostId:
  10572. description: |-
  10573. Optional HostID for JWT authentication. This may be used depending
  10574. on how the Conjur JWT authenticator policy is configured.
  10575. type: string
  10576. secretRef:
  10577. description: |-
  10578. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10579. authenticate with Conjur using the JWT authentication method.
  10580. properties:
  10581. key:
  10582. description: |-
  10583. A key in the referenced Secret.
  10584. Some instances of this field may be defaulted, in others it may be required.
  10585. maxLength: 253
  10586. minLength: 1
  10587. pattern: ^[-._a-zA-Z0-9]+$
  10588. type: string
  10589. name:
  10590. description: The name of the Secret resource being referred to.
  10591. maxLength: 253
  10592. minLength: 1
  10593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10594. type: string
  10595. namespace:
  10596. description: |-
  10597. The namespace of the Secret resource being referred to.
  10598. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10599. maxLength: 63
  10600. minLength: 1
  10601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10602. type: string
  10603. type: object
  10604. serviceAccountRef:
  10605. description: |-
  10606. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10607. a token for with the `TokenRequest` API.
  10608. properties:
  10609. audiences:
  10610. description: |-
  10611. Audience specifies the `aud` claim for the service account token
  10612. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10613. then this audiences will be appended to the list
  10614. items:
  10615. type: string
  10616. type: array
  10617. name:
  10618. description: The name of the ServiceAccount resource being referred to.
  10619. maxLength: 253
  10620. minLength: 1
  10621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10622. type: string
  10623. namespace:
  10624. description: |-
  10625. Namespace of the resource being referred to.
  10626. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10627. maxLength: 63
  10628. minLength: 1
  10629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10630. type: string
  10631. required:
  10632. - name
  10633. type: object
  10634. serviceID:
  10635. description: The conjur authn jwt webservice id
  10636. type: string
  10637. required:
  10638. - account
  10639. - serviceID
  10640. type: object
  10641. type: object
  10642. caBundle:
  10643. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  10644. type: string
  10645. caProvider:
  10646. description: |-
  10647. Used to provide custom certificate authority (CA) certificates
  10648. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10649. that contains a PEM-encoded certificate.
  10650. properties:
  10651. key:
  10652. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10653. maxLength: 253
  10654. minLength: 1
  10655. pattern: ^[-._a-zA-Z0-9]+$
  10656. type: string
  10657. name:
  10658. description: The name of the object located at the provider type.
  10659. maxLength: 253
  10660. minLength: 1
  10661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10662. type: string
  10663. namespace:
  10664. description: |-
  10665. The namespace the Provider type is in.
  10666. Can only be defined when used in a ClusterSecretStore.
  10667. maxLength: 63
  10668. minLength: 1
  10669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10670. type: string
  10671. type:
  10672. description: The type of provider to use such as "Secret", or "ConfigMap".
  10673. enum:
  10674. - Secret
  10675. - ConfigMap
  10676. type: string
  10677. required:
  10678. - name
  10679. - type
  10680. type: object
  10681. url:
  10682. description: URL is the endpoint of the Conjur instance.
  10683. type: string
  10684. required:
  10685. - auth
  10686. - url
  10687. type: object
  10688. delinea:
  10689. description: |-
  10690. Delinea DevOps Secrets Vault
  10691. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10692. properties:
  10693. clientId:
  10694. description: ClientID is the non-secret part of the credential.
  10695. properties:
  10696. secretRef:
  10697. description: SecretRef references a key in a secret that will be used as value.
  10698. properties:
  10699. key:
  10700. description: |-
  10701. A key in the referenced Secret.
  10702. Some instances of this field may be defaulted, in others it may be required.
  10703. maxLength: 253
  10704. minLength: 1
  10705. pattern: ^[-._a-zA-Z0-9]+$
  10706. type: string
  10707. name:
  10708. description: The name of the Secret resource being referred to.
  10709. maxLength: 253
  10710. minLength: 1
  10711. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10712. type: string
  10713. namespace:
  10714. description: |-
  10715. The namespace of the Secret resource being referred to.
  10716. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10717. maxLength: 63
  10718. minLength: 1
  10719. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10720. type: string
  10721. type: object
  10722. value:
  10723. description: Value can be specified directly to set a value without using a secret.
  10724. type: string
  10725. type: object
  10726. clientSecret:
  10727. description: ClientSecret is the secret part of the credential.
  10728. properties:
  10729. secretRef:
  10730. description: SecretRef references a key in a secret that will be used as value.
  10731. properties:
  10732. key:
  10733. description: |-
  10734. A key in the referenced Secret.
  10735. Some instances of this field may be defaulted, in others it may be required.
  10736. maxLength: 253
  10737. minLength: 1
  10738. pattern: ^[-._a-zA-Z0-9]+$
  10739. type: string
  10740. name:
  10741. description: The name of the Secret resource being referred to.
  10742. maxLength: 253
  10743. minLength: 1
  10744. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10745. type: string
  10746. namespace:
  10747. description: |-
  10748. The namespace of the Secret resource being referred to.
  10749. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10750. maxLength: 63
  10751. minLength: 1
  10752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10753. type: string
  10754. type: object
  10755. value:
  10756. description: Value can be specified directly to set a value without using a secret.
  10757. type: string
  10758. type: object
  10759. tenant:
  10760. description: Tenant is the chosen hostname / site name.
  10761. type: string
  10762. tld:
  10763. description: |-
  10764. TLD is based on the server location that was chosen during provisioning.
  10765. If unset, defaults to "com".
  10766. type: string
  10767. urlTemplate:
  10768. description: |-
  10769. URLTemplate
  10770. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  10771. type: string
  10772. required:
  10773. - clientId
  10774. - clientSecret
  10775. - tenant
  10776. type: object
  10777. device42:
  10778. description: Device42 configures this store to sync secrets using the Device42 provider
  10779. properties:
  10780. auth:
  10781. description: Auth configures how secret-manager authenticates with a Device42 instance.
  10782. properties:
  10783. secretRef:
  10784. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  10785. properties:
  10786. credentials:
  10787. description: Username / Password is used for authentication.
  10788. properties:
  10789. key:
  10790. description: |-
  10791. A key in the referenced Secret.
  10792. Some instances of this field may be defaulted, in others it may be required.
  10793. maxLength: 253
  10794. minLength: 1
  10795. pattern: ^[-._a-zA-Z0-9]+$
  10796. type: string
  10797. name:
  10798. description: The name of the Secret resource being referred to.
  10799. maxLength: 253
  10800. minLength: 1
  10801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10802. type: string
  10803. namespace:
  10804. description: |-
  10805. The namespace of the Secret resource being referred to.
  10806. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10807. maxLength: 63
  10808. minLength: 1
  10809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10810. type: string
  10811. type: object
  10812. type: object
  10813. required:
  10814. - secretRef
  10815. type: object
  10816. host:
  10817. description: URL configures the Device42 instance URL.
  10818. type: string
  10819. required:
  10820. - auth
  10821. - host
  10822. type: object
  10823. doppler:
  10824. description: Doppler configures this store to sync secrets using the Doppler provider
  10825. properties:
  10826. auth:
  10827. description: Auth configures how the Operator authenticates with the Doppler API
  10828. properties:
  10829. secretRef:
  10830. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  10831. properties:
  10832. dopplerToken:
  10833. description: |-
  10834. The DopplerToken is used for authentication.
  10835. See https://docs.doppler.com/reference/api#authentication for auth token types.
  10836. The Key attribute defaults to dopplerToken if not specified.
  10837. properties:
  10838. key:
  10839. description: |-
  10840. A key in the referenced Secret.
  10841. Some instances of this field may be defaulted, in others it may be required.
  10842. maxLength: 253
  10843. minLength: 1
  10844. pattern: ^[-._a-zA-Z0-9]+$
  10845. type: string
  10846. name:
  10847. description: The name of the Secret resource being referred to.
  10848. maxLength: 253
  10849. minLength: 1
  10850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10851. type: string
  10852. namespace:
  10853. description: |-
  10854. The namespace of the Secret resource being referred to.
  10855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10856. maxLength: 63
  10857. minLength: 1
  10858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10859. type: string
  10860. type: object
  10861. required:
  10862. - dopplerToken
  10863. type: object
  10864. required:
  10865. - secretRef
  10866. type: object
  10867. config:
  10868. description: Doppler config (required if not using a Service Token)
  10869. type: string
  10870. format:
  10871. description: Format enables the downloading of secrets as a file (string)
  10872. enum:
  10873. - json
  10874. - dotnet-json
  10875. - env
  10876. - yaml
  10877. - docker
  10878. type: string
  10879. nameTransformer:
  10880. description: Environment variable compatible name transforms that change secret names to a different format
  10881. enum:
  10882. - upper-camel
  10883. - camel
  10884. - lower-snake
  10885. - tf-var
  10886. - dotnet-env
  10887. - lower-kebab
  10888. type: string
  10889. project:
  10890. description: Doppler project (required if not using a Service Token)
  10891. type: string
  10892. required:
  10893. - auth
  10894. type: object
  10895. fake:
  10896. description: Fake configures a store with static key/value pairs
  10897. properties:
  10898. data:
  10899. items:
  10900. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  10901. properties:
  10902. key:
  10903. type: string
  10904. value:
  10905. type: string
  10906. version:
  10907. type: string
  10908. required:
  10909. - key
  10910. - value
  10911. type: object
  10912. type: array
  10913. required:
  10914. - data
  10915. type: object
  10916. fortanix:
  10917. description: Fortanix configures this store to sync secrets using the Fortanix provider
  10918. properties:
  10919. apiKey:
  10920. description: APIKey is the API token to access SDKMS Applications.
  10921. properties:
  10922. secretRef:
  10923. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  10924. properties:
  10925. key:
  10926. description: |-
  10927. A key in the referenced Secret.
  10928. Some instances of this field may be defaulted, in others it may be required.
  10929. maxLength: 253
  10930. minLength: 1
  10931. pattern: ^[-._a-zA-Z0-9]+$
  10932. type: string
  10933. name:
  10934. description: The name of the Secret resource being referred to.
  10935. maxLength: 253
  10936. minLength: 1
  10937. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10938. type: string
  10939. namespace:
  10940. description: |-
  10941. The namespace of the Secret resource being referred to.
  10942. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10943. maxLength: 63
  10944. minLength: 1
  10945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10946. type: string
  10947. type: object
  10948. type: object
  10949. apiUrl:
  10950. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  10951. type: string
  10952. type: object
  10953. gcpsm:
  10954. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  10955. properties:
  10956. auth:
  10957. description: Auth defines the information necessary to authenticate against GCP
  10958. properties:
  10959. secretRef:
  10960. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  10961. properties:
  10962. secretAccessKeySecretRef:
  10963. description: The SecretAccessKey is used for authentication
  10964. properties:
  10965. key:
  10966. description: |-
  10967. A key in the referenced Secret.
  10968. Some instances of this field may be defaulted, in others it may be required.
  10969. maxLength: 253
  10970. minLength: 1
  10971. pattern: ^[-._a-zA-Z0-9]+$
  10972. type: string
  10973. name:
  10974. description: The name of the Secret resource being referred to.
  10975. maxLength: 253
  10976. minLength: 1
  10977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10978. type: string
  10979. namespace:
  10980. description: |-
  10981. The namespace of the Secret resource being referred to.
  10982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10983. maxLength: 63
  10984. minLength: 1
  10985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10986. type: string
  10987. type: object
  10988. type: object
  10989. workloadIdentity:
  10990. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  10991. properties:
  10992. clusterLocation:
  10993. description: |-
  10994. ClusterLocation is the location of the cluster
  10995. If not specified, it fetches information from the metadata server
  10996. type: string
  10997. clusterName:
  10998. description: |-
  10999. ClusterName is the name of the cluster
  11000. If not specified, it fetches information from the metadata server
  11001. type: string
  11002. clusterProjectID:
  11003. description: |-
  11004. ClusterProjectID is the project ID of the cluster
  11005. If not specified, it fetches information from the metadata server
  11006. type: string
  11007. serviceAccountRef:
  11008. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  11009. properties:
  11010. audiences:
  11011. description: |-
  11012. Audience specifies the `aud` claim for the service account token
  11013. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11014. then this audiences will be appended to the list
  11015. items:
  11016. type: string
  11017. type: array
  11018. name:
  11019. description: The name of the ServiceAccount resource being referred to.
  11020. maxLength: 253
  11021. minLength: 1
  11022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11023. type: string
  11024. namespace:
  11025. description: |-
  11026. Namespace of the resource being referred to.
  11027. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11028. maxLength: 63
  11029. minLength: 1
  11030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11031. type: string
  11032. required:
  11033. - name
  11034. type: object
  11035. required:
  11036. - serviceAccountRef
  11037. type: object
  11038. type: object
  11039. location:
  11040. description: Location optionally defines a location for a secret
  11041. type: string
  11042. projectID:
  11043. description: ProjectID project where secret is located
  11044. type: string
  11045. type: object
  11046. github:
  11047. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  11048. properties:
  11049. appID:
  11050. description: appID specifies the Github APP that will be used to authenticate the client
  11051. format: int64
  11052. type: integer
  11053. auth:
  11054. description: auth configures how secret-manager authenticates with a Github instance.
  11055. properties:
  11056. privateKey:
  11057. description: |-
  11058. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11059. In some instances, `key` is a required field.
  11060. properties:
  11061. key:
  11062. description: |-
  11063. A key in the referenced Secret.
  11064. Some instances of this field may be defaulted, in others it may be required.
  11065. maxLength: 253
  11066. minLength: 1
  11067. pattern: ^[-._a-zA-Z0-9]+$
  11068. type: string
  11069. name:
  11070. description: The name of the Secret resource being referred to.
  11071. maxLength: 253
  11072. minLength: 1
  11073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11074. type: string
  11075. namespace:
  11076. description: |-
  11077. The namespace of the Secret resource being referred to.
  11078. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11079. maxLength: 63
  11080. minLength: 1
  11081. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11082. type: string
  11083. type: object
  11084. required:
  11085. - privateKey
  11086. type: object
  11087. environment:
  11088. description: environment will be used to fetch secrets from a particular environment within a github repository
  11089. type: string
  11090. installationID:
  11091. description: installationID specifies the Github APP installation that will be used to authenticate the client
  11092. format: int64
  11093. type: integer
  11094. organization:
  11095. description: organization will be used to fetch secrets from the Github organization
  11096. type: string
  11097. repository:
  11098. description: repository will be used to fetch secrets from the Github repository within an organization
  11099. type: string
  11100. uploadURL:
  11101. description: Upload URL for enterprise instances. Default to URL.
  11102. type: string
  11103. url:
  11104. default: https://github.com/
  11105. description: URL configures the Github instance URL. Defaults to https://github.com/.
  11106. type: string
  11107. required:
  11108. - appID
  11109. - auth
  11110. - installationID
  11111. - organization
  11112. type: object
  11113. gitlab:
  11114. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11115. properties:
  11116. auth:
  11117. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11118. properties:
  11119. SecretRef:
  11120. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  11121. properties:
  11122. accessToken:
  11123. description: AccessToken is used for authentication.
  11124. properties:
  11125. key:
  11126. description: |-
  11127. A key in the referenced Secret.
  11128. Some instances of this field may be defaulted, in others it may be required.
  11129. maxLength: 253
  11130. minLength: 1
  11131. pattern: ^[-._a-zA-Z0-9]+$
  11132. type: string
  11133. name:
  11134. description: The name of the Secret resource being referred to.
  11135. maxLength: 253
  11136. minLength: 1
  11137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11138. type: string
  11139. namespace:
  11140. description: |-
  11141. The namespace of the Secret resource being referred to.
  11142. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11143. maxLength: 63
  11144. minLength: 1
  11145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11146. type: string
  11147. type: object
  11148. type: object
  11149. required:
  11150. - SecretRef
  11151. type: object
  11152. caBundle:
  11153. description: |-
  11154. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  11155. can be performed.
  11156. format: byte
  11157. type: string
  11158. caProvider:
  11159. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  11160. properties:
  11161. key:
  11162. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11163. maxLength: 253
  11164. minLength: 1
  11165. pattern: ^[-._a-zA-Z0-9]+$
  11166. type: string
  11167. name:
  11168. description: The name of the object located at the provider type.
  11169. maxLength: 253
  11170. minLength: 1
  11171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11172. type: string
  11173. namespace:
  11174. description: |-
  11175. The namespace the Provider type is in.
  11176. Can only be defined when used in a ClusterSecretStore.
  11177. maxLength: 63
  11178. minLength: 1
  11179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11180. type: string
  11181. type:
  11182. description: The type of provider to use such as "Secret", or "ConfigMap".
  11183. enum:
  11184. - Secret
  11185. - ConfigMap
  11186. type: string
  11187. required:
  11188. - name
  11189. - type
  11190. type: object
  11191. environment:
  11192. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11193. type: string
  11194. groupIDs:
  11195. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11196. items:
  11197. type: string
  11198. type: array
  11199. inheritFromGroups:
  11200. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11201. type: boolean
  11202. projectID:
  11203. description: ProjectID specifies a project where secrets are located.
  11204. type: string
  11205. url:
  11206. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11207. type: string
  11208. required:
  11209. - auth
  11210. type: object
  11211. ibm:
  11212. description: IBM configures this store to sync secrets using IBM Cloud provider
  11213. properties:
  11214. auth:
  11215. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11216. maxProperties: 1
  11217. minProperties: 1
  11218. properties:
  11219. containerAuth:
  11220. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  11221. properties:
  11222. iamEndpoint:
  11223. type: string
  11224. profile:
  11225. description: the IBM Trusted Profile
  11226. type: string
  11227. tokenLocation:
  11228. description: Location the token is mounted on the pod
  11229. type: string
  11230. required:
  11231. - profile
  11232. type: object
  11233. secretRef:
  11234. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  11235. properties:
  11236. secretApiKeySecretRef:
  11237. description: The SecretAccessKey is used for authentication
  11238. properties:
  11239. key:
  11240. description: |-
  11241. A key in the referenced Secret.
  11242. Some instances of this field may be defaulted, in others it may be required.
  11243. maxLength: 253
  11244. minLength: 1
  11245. pattern: ^[-._a-zA-Z0-9]+$
  11246. type: string
  11247. name:
  11248. description: The name of the Secret resource being referred to.
  11249. maxLength: 253
  11250. minLength: 1
  11251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11252. type: string
  11253. namespace:
  11254. description: |-
  11255. The namespace of the Secret resource being referred to.
  11256. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11257. maxLength: 63
  11258. minLength: 1
  11259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11260. type: string
  11261. type: object
  11262. type: object
  11263. type: object
  11264. serviceUrl:
  11265. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11266. type: string
  11267. required:
  11268. - auth
  11269. type: object
  11270. infisical:
  11271. description: Infisical configures this store to sync secrets using the Infisical provider
  11272. properties:
  11273. auth:
  11274. description: Auth configures how the Operator authenticates with the Infisical API
  11275. properties:
  11276. universalAuthCredentials:
  11277. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  11278. properties:
  11279. clientId:
  11280. description: |-
  11281. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11282. In some instances, `key` is a required field.
  11283. properties:
  11284. key:
  11285. description: |-
  11286. A key in the referenced Secret.
  11287. Some instances of this field may be defaulted, in others it may be required.
  11288. maxLength: 253
  11289. minLength: 1
  11290. pattern: ^[-._a-zA-Z0-9]+$
  11291. type: string
  11292. name:
  11293. description: The name of the Secret resource being referred to.
  11294. maxLength: 253
  11295. minLength: 1
  11296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11297. type: string
  11298. namespace:
  11299. description: |-
  11300. The namespace of the Secret resource being referred to.
  11301. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11302. maxLength: 63
  11303. minLength: 1
  11304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11305. type: string
  11306. type: object
  11307. clientSecret:
  11308. description: |-
  11309. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11310. In some instances, `key` is a required field.
  11311. properties:
  11312. key:
  11313. description: |-
  11314. A key in the referenced Secret.
  11315. Some instances of this field may be defaulted, in others it may be required.
  11316. maxLength: 253
  11317. minLength: 1
  11318. pattern: ^[-._a-zA-Z0-9]+$
  11319. type: string
  11320. name:
  11321. description: The name of the Secret resource being referred to.
  11322. maxLength: 253
  11323. minLength: 1
  11324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11325. type: string
  11326. namespace:
  11327. description: |-
  11328. The namespace of the Secret resource being referred to.
  11329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11330. maxLength: 63
  11331. minLength: 1
  11332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11333. type: string
  11334. type: object
  11335. required:
  11336. - clientId
  11337. - clientSecret
  11338. type: object
  11339. type: object
  11340. hostAPI:
  11341. default: https://app.infisical.com/api
  11342. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  11343. type: string
  11344. secretsScope:
  11345. description: SecretsScope defines the scope of the secrets within the workspace
  11346. properties:
  11347. environmentSlug:
  11348. description: EnvironmentSlug is the required slug identifier for the environment.
  11349. type: string
  11350. expandSecretReferences:
  11351. default: true
  11352. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  11353. type: boolean
  11354. projectSlug:
  11355. description: ProjectSlug is the required slug identifier for the project.
  11356. type: string
  11357. recursive:
  11358. default: false
  11359. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  11360. type: boolean
  11361. secretsPath:
  11362. default: /
  11363. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  11364. type: string
  11365. required:
  11366. - environmentSlug
  11367. - projectSlug
  11368. type: object
  11369. required:
  11370. - auth
  11371. - secretsScope
  11372. type: object
  11373. keepersecurity:
  11374. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11375. properties:
  11376. authRef:
  11377. description: |-
  11378. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11379. In some instances, `key` is a required field.
  11380. properties:
  11381. key:
  11382. description: |-
  11383. A key in the referenced Secret.
  11384. Some instances of this field may be defaulted, in others it may be required.
  11385. maxLength: 253
  11386. minLength: 1
  11387. pattern: ^[-._a-zA-Z0-9]+$
  11388. type: string
  11389. name:
  11390. description: The name of the Secret resource being referred to.
  11391. maxLength: 253
  11392. minLength: 1
  11393. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11394. type: string
  11395. namespace:
  11396. description: |-
  11397. The namespace of the Secret resource being referred to.
  11398. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11399. maxLength: 63
  11400. minLength: 1
  11401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11402. type: string
  11403. type: object
  11404. folderID:
  11405. type: string
  11406. required:
  11407. - authRef
  11408. - folderID
  11409. type: object
  11410. kubernetes:
  11411. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11412. properties:
  11413. auth:
  11414. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11415. maxProperties: 1
  11416. minProperties: 1
  11417. properties:
  11418. cert:
  11419. description: has both clientCert and clientKey as secretKeySelector
  11420. properties:
  11421. clientCert:
  11422. description: |-
  11423. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11424. In some instances, `key` is a required field.
  11425. properties:
  11426. key:
  11427. description: |-
  11428. A key in the referenced Secret.
  11429. Some instances of this field may be defaulted, in others it may be required.
  11430. maxLength: 253
  11431. minLength: 1
  11432. pattern: ^[-._a-zA-Z0-9]+$
  11433. type: string
  11434. name:
  11435. description: The name of the Secret resource being referred to.
  11436. maxLength: 253
  11437. minLength: 1
  11438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11439. type: string
  11440. namespace:
  11441. description: |-
  11442. The namespace of the Secret resource being referred to.
  11443. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11444. maxLength: 63
  11445. minLength: 1
  11446. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11447. type: string
  11448. type: object
  11449. clientKey:
  11450. description: |-
  11451. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11452. In some instances, `key` is a required field.
  11453. properties:
  11454. key:
  11455. description: |-
  11456. A key in the referenced Secret.
  11457. Some instances of this field may be defaulted, in others it may be required.
  11458. maxLength: 253
  11459. minLength: 1
  11460. pattern: ^[-._a-zA-Z0-9]+$
  11461. type: string
  11462. name:
  11463. description: The name of the Secret resource being referred to.
  11464. maxLength: 253
  11465. minLength: 1
  11466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11467. type: string
  11468. namespace:
  11469. description: |-
  11470. The namespace of the Secret resource being referred to.
  11471. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11472. maxLength: 63
  11473. minLength: 1
  11474. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11475. type: string
  11476. type: object
  11477. type: object
  11478. serviceAccount:
  11479. description: points to a service account that should be used for authentication
  11480. properties:
  11481. audiences:
  11482. description: |-
  11483. Audience specifies the `aud` claim for the service account token
  11484. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11485. then this audiences will be appended to the list
  11486. items:
  11487. type: string
  11488. type: array
  11489. name:
  11490. description: The name of the ServiceAccount resource being referred to.
  11491. maxLength: 253
  11492. minLength: 1
  11493. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11494. type: string
  11495. namespace:
  11496. description: |-
  11497. Namespace of the resource being referred to.
  11498. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11499. maxLength: 63
  11500. minLength: 1
  11501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11502. type: string
  11503. required:
  11504. - name
  11505. type: object
  11506. token:
  11507. description: use static token to authenticate with
  11508. properties:
  11509. bearerToken:
  11510. description: |-
  11511. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  11512. In some instances, `key` is a required field.
  11513. properties:
  11514. key:
  11515. description: |-
  11516. A key in the referenced Secret.
  11517. Some instances of this field may be defaulted, in others it may be required.
  11518. maxLength: 253
  11519. minLength: 1
  11520. pattern: ^[-._a-zA-Z0-9]+$
  11521. type: string
  11522. name:
  11523. description: The name of the Secret resource being referred to.
  11524. maxLength: 253
  11525. minLength: 1
  11526. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11527. type: string
  11528. namespace:
  11529. description: |-
  11530. The namespace of the Secret resource being referred to.
  11531. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11532. maxLength: 63
  11533. minLength: 1
  11534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11535. type: string
  11536. type: object
  11537. type: object
  11538. type: object
  11539. authRef:
  11540. description: A reference to a secret that contains the auth information.
  11541. properties:
  11542. key:
  11543. description: |-
  11544. A key in the referenced Secret.
  11545. Some instances of this field may be defaulted, in others it may be required.
  11546. maxLength: 253
  11547. minLength: 1
  11548. pattern: ^[-._a-zA-Z0-9]+$
  11549. type: string
  11550. name:
  11551. description: The name of the Secret resource being referred to.
  11552. maxLength: 253
  11553. minLength: 1
  11554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11555. type: string
  11556. namespace:
  11557. description: |-
  11558. The namespace of the Secret resource being referred to.
  11559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11560. maxLength: 63
  11561. minLength: 1
  11562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11563. type: string
  11564. type: object
  11565. remoteNamespace:
  11566. default: default
  11567. description: Remote namespace to fetch the secrets from
  11568. maxLength: 63
  11569. minLength: 1
  11570. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11571. type: string
  11572. server:
  11573. description: configures the Kubernetes server Address.
  11574. properties:
  11575. caBundle:
  11576. description: CABundle is a base64-encoded CA certificate
  11577. format: byte
  11578. type: string
  11579. caProvider:
  11580. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11581. properties:
  11582. key:
  11583. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11584. maxLength: 253
  11585. minLength: 1
  11586. pattern: ^[-._a-zA-Z0-9]+$
  11587. type: string
  11588. name:
  11589. description: The name of the object located at the provider type.
  11590. maxLength: 253
  11591. minLength: 1
  11592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11593. type: string
  11594. namespace:
  11595. description: |-
  11596. The namespace the Provider type is in.
  11597. Can only be defined when used in a ClusterSecretStore.
  11598. maxLength: 63
  11599. minLength: 1
  11600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11601. type: string
  11602. type:
  11603. description: The type of provider to use such as "Secret", or "ConfigMap".
  11604. enum:
  11605. - Secret
  11606. - ConfigMap
  11607. type: string
  11608. required:
  11609. - name
  11610. - type
  11611. type: object
  11612. url:
  11613. default: kubernetes.default
  11614. description: configures the Kubernetes server Address.
  11615. type: string
  11616. type: object
  11617. type: object
  11618. onboardbase:
  11619. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11620. properties:
  11621. apiHost:
  11622. default: https://public.onboardbase.com/api/v1/
  11623. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11624. type: string
  11625. auth:
  11626. description: Auth configures how the Operator authenticates with the Onboardbase API
  11627. properties:
  11628. apiKeyRef:
  11629. description: |-
  11630. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11631. It is used to recognize and authorize access to a project and environment within onboardbase
  11632. properties:
  11633. key:
  11634. description: |-
  11635. A key in the referenced Secret.
  11636. Some instances of this field may be defaulted, in others it may be required.
  11637. maxLength: 253
  11638. minLength: 1
  11639. pattern: ^[-._a-zA-Z0-9]+$
  11640. type: string
  11641. name:
  11642. description: The name of the Secret resource being referred to.
  11643. maxLength: 253
  11644. minLength: 1
  11645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11646. type: string
  11647. namespace:
  11648. description: |-
  11649. The namespace of the Secret resource being referred to.
  11650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11651. maxLength: 63
  11652. minLength: 1
  11653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11654. type: string
  11655. type: object
  11656. passcodeRef:
  11657. description: OnboardbasePasscode is the passcode attached to the API Key
  11658. properties:
  11659. key:
  11660. description: |-
  11661. A key in the referenced Secret.
  11662. Some instances of this field may be defaulted, in others it may be required.
  11663. maxLength: 253
  11664. minLength: 1
  11665. pattern: ^[-._a-zA-Z0-9]+$
  11666. type: string
  11667. name:
  11668. description: The name of the Secret resource being referred to.
  11669. maxLength: 253
  11670. minLength: 1
  11671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11672. type: string
  11673. namespace:
  11674. description: |-
  11675. The namespace of the Secret resource being referred to.
  11676. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11677. maxLength: 63
  11678. minLength: 1
  11679. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11680. type: string
  11681. type: object
  11682. required:
  11683. - apiKeyRef
  11684. - passcodeRef
  11685. type: object
  11686. environment:
  11687. default: development
  11688. description: Environment is the name of an environmnent within a project to pull the secrets from
  11689. type: string
  11690. project:
  11691. default: development
  11692. description: Project is an onboardbase project that the secrets should be pulled from
  11693. type: string
  11694. required:
  11695. - apiHost
  11696. - auth
  11697. - environment
  11698. - project
  11699. type: object
  11700. onepassword:
  11701. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11702. properties:
  11703. auth:
  11704. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11705. properties:
  11706. secretRef:
  11707. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11708. properties:
  11709. connectTokenSecretRef:
  11710. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11711. properties:
  11712. key:
  11713. description: |-
  11714. A key in the referenced Secret.
  11715. Some instances of this field may be defaulted, in others it may be required.
  11716. maxLength: 253
  11717. minLength: 1
  11718. pattern: ^[-._a-zA-Z0-9]+$
  11719. type: string
  11720. name:
  11721. description: The name of the Secret resource being referred to.
  11722. maxLength: 253
  11723. minLength: 1
  11724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11725. type: string
  11726. namespace:
  11727. description: |-
  11728. The namespace of the Secret resource being referred to.
  11729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11730. maxLength: 63
  11731. minLength: 1
  11732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11733. type: string
  11734. type: object
  11735. required:
  11736. - connectTokenSecretRef
  11737. type: object
  11738. required:
  11739. - secretRef
  11740. type: object
  11741. connectHost:
  11742. description: ConnectHost defines the OnePassword Connect Server to connect to
  11743. type: string
  11744. vaults:
  11745. additionalProperties:
  11746. type: integer
  11747. description: Vaults defines which OnePassword vaults to search in which order
  11748. type: object
  11749. required:
  11750. - auth
  11751. - connectHost
  11752. - vaults
  11753. type: object
  11754. oracle:
  11755. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11756. properties:
  11757. auth:
  11758. description: |-
  11759. Auth configures how secret-manager authenticates with the Oracle Vault.
  11760. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11761. properties:
  11762. secretRef:
  11763. description: SecretRef to pass through sensitive information.
  11764. properties:
  11765. fingerprint:
  11766. description: Fingerprint is the fingerprint of the API private key.
  11767. properties:
  11768. key:
  11769. description: |-
  11770. A key in the referenced Secret.
  11771. Some instances of this field may be defaulted, in others it may be required.
  11772. maxLength: 253
  11773. minLength: 1
  11774. pattern: ^[-._a-zA-Z0-9]+$
  11775. type: string
  11776. name:
  11777. description: The name of the Secret resource being referred to.
  11778. maxLength: 253
  11779. minLength: 1
  11780. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11781. type: string
  11782. namespace:
  11783. description: |-
  11784. The namespace of the Secret resource being referred to.
  11785. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11786. maxLength: 63
  11787. minLength: 1
  11788. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11789. type: string
  11790. type: object
  11791. privatekey:
  11792. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11793. properties:
  11794. key:
  11795. description: |-
  11796. A key in the referenced Secret.
  11797. Some instances of this field may be defaulted, in others it may be required.
  11798. maxLength: 253
  11799. minLength: 1
  11800. pattern: ^[-._a-zA-Z0-9]+$
  11801. type: string
  11802. name:
  11803. description: The name of the Secret resource being referred to.
  11804. maxLength: 253
  11805. minLength: 1
  11806. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11807. type: string
  11808. namespace:
  11809. description: |-
  11810. The namespace of the Secret resource being referred to.
  11811. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11812. maxLength: 63
  11813. minLength: 1
  11814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11815. type: string
  11816. type: object
  11817. required:
  11818. - fingerprint
  11819. - privatekey
  11820. type: object
  11821. tenancy:
  11822. description: Tenancy is the tenancy OCID where user is located.
  11823. type: string
  11824. user:
  11825. description: User is an access OCID specific to the account.
  11826. type: string
  11827. required:
  11828. - secretRef
  11829. - tenancy
  11830. - user
  11831. type: object
  11832. compartment:
  11833. description: |-
  11834. Compartment is the vault compartment OCID.
  11835. Required for PushSecret
  11836. type: string
  11837. encryptionKey:
  11838. description: |-
  11839. EncryptionKey is the OCID of the encryption key within the vault.
  11840. Required for PushSecret
  11841. type: string
  11842. principalType:
  11843. description: |-
  11844. The type of principal to use for authentication. If left blank, the Auth struct will
  11845. determine the principal type. This optional field must be specified if using
  11846. workload identity.
  11847. enum:
  11848. - ""
  11849. - UserPrincipal
  11850. - InstancePrincipal
  11851. - Workload
  11852. type: string
  11853. region:
  11854. description: Region is the region where vault is located.
  11855. type: string
  11856. serviceAccountRef:
  11857. description: |-
  11858. ServiceAccountRef specified the service account
  11859. that should be used when authenticating with WorkloadIdentity.
  11860. properties:
  11861. audiences:
  11862. description: |-
  11863. Audience specifies the `aud` claim for the service account token
  11864. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11865. then this audiences will be appended to the list
  11866. items:
  11867. type: string
  11868. type: array
  11869. name:
  11870. description: The name of the ServiceAccount resource being referred to.
  11871. maxLength: 253
  11872. minLength: 1
  11873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11874. type: string
  11875. namespace:
  11876. description: |-
  11877. Namespace of the resource being referred to.
  11878. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11879. maxLength: 63
  11880. minLength: 1
  11881. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11882. type: string
  11883. required:
  11884. - name
  11885. type: object
  11886. vault:
  11887. description: Vault is the vault's OCID of the specific vault where secret is located.
  11888. type: string
  11889. required:
  11890. - region
  11891. - vault
  11892. type: object
  11893. passbolt:
  11894. description: PassboltProvider defines configuration for the Passbolt provider.
  11895. properties:
  11896. auth:
  11897. description: Auth defines the information necessary to authenticate against Passbolt Server
  11898. properties:
  11899. passwordSecretRef:
  11900. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  11901. properties:
  11902. key:
  11903. description: |-
  11904. A key in the referenced Secret.
  11905. Some instances of this field may be defaulted, in others it may be required.
  11906. maxLength: 253
  11907. minLength: 1
  11908. pattern: ^[-._a-zA-Z0-9]+$
  11909. type: string
  11910. name:
  11911. description: The name of the Secret resource being referred to.
  11912. maxLength: 253
  11913. minLength: 1
  11914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11915. type: string
  11916. namespace:
  11917. description: |-
  11918. The namespace of the Secret resource being referred to.
  11919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11920. maxLength: 63
  11921. minLength: 1
  11922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11923. type: string
  11924. type: object
  11925. privateKeySecretRef:
  11926. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  11927. properties:
  11928. key:
  11929. description: |-
  11930. A key in the referenced Secret.
  11931. Some instances of this field may be defaulted, in others it may be required.
  11932. maxLength: 253
  11933. minLength: 1
  11934. pattern: ^[-._a-zA-Z0-9]+$
  11935. type: string
  11936. name:
  11937. description: The name of the Secret resource being referred to.
  11938. maxLength: 253
  11939. minLength: 1
  11940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11941. type: string
  11942. namespace:
  11943. description: |-
  11944. The namespace of the Secret resource being referred to.
  11945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11946. maxLength: 63
  11947. minLength: 1
  11948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11949. type: string
  11950. type: object
  11951. required:
  11952. - passwordSecretRef
  11953. - privateKeySecretRef
  11954. type: object
  11955. host:
  11956. description: Host defines the Passbolt Server to connect to
  11957. type: string
  11958. required:
  11959. - auth
  11960. - host
  11961. type: object
  11962. passworddepot:
  11963. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  11964. properties:
  11965. auth:
  11966. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  11967. properties:
  11968. secretRef:
  11969. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  11970. properties:
  11971. credentials:
  11972. description: Username / Password is used for authentication.
  11973. properties:
  11974. key:
  11975. description: |-
  11976. A key in the referenced Secret.
  11977. Some instances of this field may be defaulted, in others it may be required.
  11978. maxLength: 253
  11979. minLength: 1
  11980. pattern: ^[-._a-zA-Z0-9]+$
  11981. type: string
  11982. name:
  11983. description: The name of the Secret resource being referred to.
  11984. maxLength: 253
  11985. minLength: 1
  11986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11987. type: string
  11988. namespace:
  11989. description: |-
  11990. The namespace of the Secret resource being referred to.
  11991. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11992. maxLength: 63
  11993. minLength: 1
  11994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11995. type: string
  11996. type: object
  11997. type: object
  11998. required:
  11999. - secretRef
  12000. type: object
  12001. database:
  12002. description: Database to use as source
  12003. type: string
  12004. host:
  12005. description: URL configures the Password Depot instance URL.
  12006. type: string
  12007. required:
  12008. - auth
  12009. - database
  12010. - host
  12011. type: object
  12012. previder:
  12013. description: Previder configures this store to sync secrets using the Previder provider
  12014. properties:
  12015. auth:
  12016. description: PreviderAuth contains a secretRef for credentials.
  12017. properties:
  12018. secretRef:
  12019. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12020. properties:
  12021. accessToken:
  12022. description: The AccessToken is used for authentication
  12023. properties:
  12024. key:
  12025. description: |-
  12026. A key in the referenced Secret.
  12027. Some instances of this field may be defaulted, in others it may be required.
  12028. maxLength: 253
  12029. minLength: 1
  12030. pattern: ^[-._a-zA-Z0-9]+$
  12031. type: string
  12032. name:
  12033. description: The name of the Secret resource being referred to.
  12034. maxLength: 253
  12035. minLength: 1
  12036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12037. type: string
  12038. namespace:
  12039. description: |-
  12040. The namespace of the Secret resource being referred to.
  12041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12042. maxLength: 63
  12043. minLength: 1
  12044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12045. type: string
  12046. type: object
  12047. required:
  12048. - accessToken
  12049. type: object
  12050. type: object
  12051. baseUri:
  12052. type: string
  12053. required:
  12054. - auth
  12055. type: object
  12056. pulumi:
  12057. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12058. properties:
  12059. accessToken:
  12060. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12061. properties:
  12062. secretRef:
  12063. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12064. properties:
  12065. key:
  12066. description: |-
  12067. A key in the referenced Secret.
  12068. Some instances of this field may be defaulted, in others it may be required.
  12069. maxLength: 253
  12070. minLength: 1
  12071. pattern: ^[-._a-zA-Z0-9]+$
  12072. type: string
  12073. name:
  12074. description: The name of the Secret resource being referred to.
  12075. maxLength: 253
  12076. minLength: 1
  12077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12078. type: string
  12079. namespace:
  12080. description: |-
  12081. The namespace of the Secret resource being referred to.
  12082. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12083. maxLength: 63
  12084. minLength: 1
  12085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12086. type: string
  12087. type: object
  12088. type: object
  12089. apiUrl:
  12090. default: https://api.pulumi.com/api/esc
  12091. description: APIURL is the URL of the Pulumi API.
  12092. type: string
  12093. environment:
  12094. description: |-
  12095. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12096. dynamically retrieved values from supported providers including all major clouds,
  12097. and other Pulumi ESC environments.
  12098. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12099. type: string
  12100. organization:
  12101. description: |-
  12102. Organization are a space to collaborate on shared projects and stacks.
  12103. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12104. type: string
  12105. project:
  12106. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12107. type: string
  12108. required:
  12109. - accessToken
  12110. - environment
  12111. - organization
  12112. - project
  12113. type: object
  12114. scaleway:
  12115. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  12116. properties:
  12117. accessKey:
  12118. description: AccessKey is the non-secret part of the api key.
  12119. properties:
  12120. secretRef:
  12121. description: SecretRef references a key in a secret that will be used as value.
  12122. properties:
  12123. key:
  12124. description: |-
  12125. A key in the referenced Secret.
  12126. Some instances of this field may be defaulted, in others it may be required.
  12127. maxLength: 253
  12128. minLength: 1
  12129. pattern: ^[-._a-zA-Z0-9]+$
  12130. type: string
  12131. name:
  12132. description: The name of the Secret resource being referred to.
  12133. maxLength: 253
  12134. minLength: 1
  12135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12136. type: string
  12137. namespace:
  12138. description: |-
  12139. The namespace of the Secret resource being referred to.
  12140. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12141. maxLength: 63
  12142. minLength: 1
  12143. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12144. type: string
  12145. type: object
  12146. value:
  12147. description: Value can be specified directly to set a value without using a secret.
  12148. type: string
  12149. type: object
  12150. apiUrl:
  12151. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12152. type: string
  12153. projectId:
  12154. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12155. type: string
  12156. region:
  12157. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12158. type: string
  12159. secretKey:
  12160. description: SecretKey is the non-secret part of the api key.
  12161. properties:
  12162. secretRef:
  12163. description: SecretRef references a key in a secret that will be used as value.
  12164. properties:
  12165. key:
  12166. description: |-
  12167. A key in the referenced Secret.
  12168. Some instances of this field may be defaulted, in others it may be required.
  12169. maxLength: 253
  12170. minLength: 1
  12171. pattern: ^[-._a-zA-Z0-9]+$
  12172. type: string
  12173. name:
  12174. description: The name of the Secret resource being referred to.
  12175. maxLength: 253
  12176. minLength: 1
  12177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12178. type: string
  12179. namespace:
  12180. description: |-
  12181. The namespace of the Secret resource being referred to.
  12182. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12183. maxLength: 63
  12184. minLength: 1
  12185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12186. type: string
  12187. type: object
  12188. value:
  12189. description: Value can be specified directly to set a value without using a secret.
  12190. type: string
  12191. type: object
  12192. required:
  12193. - accessKey
  12194. - projectId
  12195. - region
  12196. - secretKey
  12197. type: object
  12198. secretserver:
  12199. description: |-
  12200. SecretServer configures this store to sync secrets using SecretServer provider
  12201. https://docs.delinea.com/online-help/secret-server/start.htm
  12202. properties:
  12203. password:
  12204. description: Password is the secret server account password.
  12205. properties:
  12206. secretRef:
  12207. description: SecretRef references a key in a secret that will be used as value.
  12208. properties:
  12209. key:
  12210. description: |-
  12211. A key in the referenced Secret.
  12212. Some instances of this field may be defaulted, in others it may be required.
  12213. maxLength: 253
  12214. minLength: 1
  12215. pattern: ^[-._a-zA-Z0-9]+$
  12216. type: string
  12217. name:
  12218. description: The name of the Secret resource being referred to.
  12219. maxLength: 253
  12220. minLength: 1
  12221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12222. type: string
  12223. namespace:
  12224. description: |-
  12225. The namespace of the Secret resource being referred to.
  12226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12227. maxLength: 63
  12228. minLength: 1
  12229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12230. type: string
  12231. type: object
  12232. value:
  12233. description: Value can be specified directly to set a value without using a secret.
  12234. type: string
  12235. type: object
  12236. serverURL:
  12237. description: |-
  12238. ServerURL
  12239. URL to your secret server installation
  12240. type: string
  12241. username:
  12242. description: Username is the secret server account username.
  12243. properties:
  12244. secretRef:
  12245. description: SecretRef references a key in a secret that will be used as value.
  12246. properties:
  12247. key:
  12248. description: |-
  12249. A key in the referenced Secret.
  12250. Some instances of this field may be defaulted, in others it may be required.
  12251. maxLength: 253
  12252. minLength: 1
  12253. pattern: ^[-._a-zA-Z0-9]+$
  12254. type: string
  12255. name:
  12256. description: The name of the Secret resource being referred to.
  12257. maxLength: 253
  12258. minLength: 1
  12259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12260. type: string
  12261. namespace:
  12262. description: |-
  12263. The namespace of the Secret resource being referred to.
  12264. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12265. maxLength: 63
  12266. minLength: 1
  12267. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12268. type: string
  12269. type: object
  12270. value:
  12271. description: Value can be specified directly to set a value without using a secret.
  12272. type: string
  12273. type: object
  12274. required:
  12275. - password
  12276. - serverURL
  12277. - username
  12278. type: object
  12279. senhasegura:
  12280. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12281. properties:
  12282. auth:
  12283. description: Auth defines parameters to authenticate in senhasegura
  12284. properties:
  12285. clientId:
  12286. type: string
  12287. clientSecretSecretRef:
  12288. description: |-
  12289. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  12290. In some instances, `key` is a required field.
  12291. properties:
  12292. key:
  12293. description: |-
  12294. A key in the referenced Secret.
  12295. Some instances of this field may be defaulted, in others it may be required.
  12296. maxLength: 253
  12297. minLength: 1
  12298. pattern: ^[-._a-zA-Z0-9]+$
  12299. type: string
  12300. name:
  12301. description: The name of the Secret resource being referred to.
  12302. maxLength: 253
  12303. minLength: 1
  12304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12305. type: string
  12306. namespace:
  12307. description: |-
  12308. The namespace of the Secret resource being referred to.
  12309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12310. maxLength: 63
  12311. minLength: 1
  12312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12313. type: string
  12314. type: object
  12315. required:
  12316. - clientId
  12317. - clientSecretSecretRef
  12318. type: object
  12319. ignoreSslCertificate:
  12320. default: false
  12321. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12322. type: boolean
  12323. module:
  12324. description: Module defines which senhasegura module should be used to get secrets
  12325. type: string
  12326. url:
  12327. description: URL of senhasegura
  12328. type: string
  12329. required:
  12330. - auth
  12331. - module
  12332. - url
  12333. type: object
  12334. vault:
  12335. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  12336. properties:
  12337. auth:
  12338. description: Auth configures how secret-manager authenticates with the Vault server.
  12339. properties:
  12340. appRole:
  12341. description: |-
  12342. AppRole authenticates with Vault using the App Role auth mechanism,
  12343. with the role and secret stored in a Kubernetes Secret resource.
  12344. properties:
  12345. path:
  12346. default: approle
  12347. description: |-
  12348. Path where the App Role authentication backend is mounted
  12349. in Vault, e.g: "approle"
  12350. type: string
  12351. roleId:
  12352. description: |-
  12353. RoleID configured in the App Role authentication backend when setting
  12354. up the authentication backend in Vault.
  12355. type: string
  12356. roleRef:
  12357. description: |-
  12358. Reference to a key in a Secret that contains the App Role ID used
  12359. to authenticate with Vault.
  12360. The `key` field must be specified and denotes which entry within the Secret
  12361. resource is used as the app role id.
  12362. properties:
  12363. key:
  12364. description: |-
  12365. A key in the referenced Secret.
  12366. Some instances of this field may be defaulted, in others it may be required.
  12367. maxLength: 253
  12368. minLength: 1
  12369. pattern: ^[-._a-zA-Z0-9]+$
  12370. type: string
  12371. name:
  12372. description: The name of the Secret resource being referred to.
  12373. maxLength: 253
  12374. minLength: 1
  12375. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12376. type: string
  12377. namespace:
  12378. description: |-
  12379. The namespace of the Secret resource being referred to.
  12380. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12381. maxLength: 63
  12382. minLength: 1
  12383. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12384. type: string
  12385. type: object
  12386. secretRef:
  12387. description: |-
  12388. Reference to a key in a Secret that contains the App Role secret used
  12389. to authenticate with Vault.
  12390. The `key` field must be specified and denotes which entry within the Secret
  12391. resource is used as the app role secret.
  12392. properties:
  12393. key:
  12394. description: |-
  12395. A key in the referenced Secret.
  12396. Some instances of this field may be defaulted, in others it may be required.
  12397. maxLength: 253
  12398. minLength: 1
  12399. pattern: ^[-._a-zA-Z0-9]+$
  12400. type: string
  12401. name:
  12402. description: The name of the Secret resource being referred to.
  12403. maxLength: 253
  12404. minLength: 1
  12405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12406. type: string
  12407. namespace:
  12408. description: |-
  12409. The namespace of the Secret resource being referred to.
  12410. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12411. maxLength: 63
  12412. minLength: 1
  12413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12414. type: string
  12415. type: object
  12416. required:
  12417. - path
  12418. - secretRef
  12419. type: object
  12420. cert:
  12421. description: |-
  12422. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12423. Cert authentication method
  12424. properties:
  12425. clientCert:
  12426. description: |-
  12427. ClientCert is a certificate to authenticate using the Cert Vault
  12428. authentication method
  12429. properties:
  12430. key:
  12431. description: |-
  12432. A key in the referenced Secret.
  12433. Some instances of this field may be defaulted, in others it may be required.
  12434. maxLength: 253
  12435. minLength: 1
  12436. pattern: ^[-._a-zA-Z0-9]+$
  12437. type: string
  12438. name:
  12439. description: The name of the Secret resource being referred to.
  12440. maxLength: 253
  12441. minLength: 1
  12442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12443. type: string
  12444. namespace:
  12445. description: |-
  12446. The namespace of the Secret resource being referred to.
  12447. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12448. maxLength: 63
  12449. minLength: 1
  12450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12451. type: string
  12452. type: object
  12453. secretRef:
  12454. description: |-
  12455. SecretRef to a key in a Secret resource containing client private key to
  12456. authenticate with Vault using the Cert authentication method
  12457. properties:
  12458. key:
  12459. description: |-
  12460. A key in the referenced Secret.
  12461. Some instances of this field may be defaulted, in others it may be required.
  12462. maxLength: 253
  12463. minLength: 1
  12464. pattern: ^[-._a-zA-Z0-9]+$
  12465. type: string
  12466. name:
  12467. description: The name of the Secret resource being referred to.
  12468. maxLength: 253
  12469. minLength: 1
  12470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12471. type: string
  12472. namespace:
  12473. description: |-
  12474. The namespace of the Secret resource being referred to.
  12475. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12476. maxLength: 63
  12477. minLength: 1
  12478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12479. type: string
  12480. type: object
  12481. type: object
  12482. iam:
  12483. description: |-
  12484. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12485. AWS IAM authentication method
  12486. properties:
  12487. externalID:
  12488. description: AWS External ID set on assumed IAM roles
  12489. type: string
  12490. jwt:
  12491. description: Specify a service account with IRSA enabled
  12492. properties:
  12493. serviceAccountRef:
  12494. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  12495. properties:
  12496. audiences:
  12497. description: |-
  12498. Audience specifies the `aud` claim for the service account token
  12499. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12500. then this audiences will be appended to the list
  12501. items:
  12502. type: string
  12503. type: array
  12504. name:
  12505. description: The name of the ServiceAccount resource being referred to.
  12506. maxLength: 253
  12507. minLength: 1
  12508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12509. type: string
  12510. namespace:
  12511. description: |-
  12512. Namespace of the resource being referred to.
  12513. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12514. maxLength: 63
  12515. minLength: 1
  12516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12517. type: string
  12518. required:
  12519. - name
  12520. type: object
  12521. type: object
  12522. path:
  12523. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12524. type: string
  12525. region:
  12526. description: AWS region
  12527. type: string
  12528. role:
  12529. description: This is the AWS role to be assumed before talking to vault
  12530. type: string
  12531. secretRef:
  12532. description: Specify credentials in a Secret object
  12533. properties:
  12534. accessKeyIDSecretRef:
  12535. description: The AccessKeyID is used for authentication
  12536. properties:
  12537. key:
  12538. description: |-
  12539. A key in the referenced Secret.
  12540. Some instances of this field may be defaulted, in others it may be required.
  12541. maxLength: 253
  12542. minLength: 1
  12543. pattern: ^[-._a-zA-Z0-9]+$
  12544. type: string
  12545. name:
  12546. description: The name of the Secret resource being referred to.
  12547. maxLength: 253
  12548. minLength: 1
  12549. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12550. type: string
  12551. namespace:
  12552. description: |-
  12553. The namespace of the Secret resource being referred to.
  12554. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12555. maxLength: 63
  12556. minLength: 1
  12557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12558. type: string
  12559. type: object
  12560. secretAccessKeySecretRef:
  12561. description: The SecretAccessKey is used for authentication
  12562. properties:
  12563. key:
  12564. description: |-
  12565. A key in the referenced Secret.
  12566. Some instances of this field may be defaulted, in others it may be required.
  12567. maxLength: 253
  12568. minLength: 1
  12569. pattern: ^[-._a-zA-Z0-9]+$
  12570. type: string
  12571. name:
  12572. description: The name of the Secret resource being referred to.
  12573. maxLength: 253
  12574. minLength: 1
  12575. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12576. type: string
  12577. namespace:
  12578. description: |-
  12579. The namespace of the Secret resource being referred to.
  12580. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12581. maxLength: 63
  12582. minLength: 1
  12583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12584. type: string
  12585. type: object
  12586. sessionTokenSecretRef:
  12587. description: |-
  12588. The SessionToken used for authentication
  12589. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12590. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12591. properties:
  12592. key:
  12593. description: |-
  12594. A key in the referenced Secret.
  12595. Some instances of this field may be defaulted, in others it may be required.
  12596. maxLength: 253
  12597. minLength: 1
  12598. pattern: ^[-._a-zA-Z0-9]+$
  12599. type: string
  12600. name:
  12601. description: The name of the Secret resource being referred to.
  12602. maxLength: 253
  12603. minLength: 1
  12604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12605. type: string
  12606. namespace:
  12607. description: |-
  12608. The namespace of the Secret resource being referred to.
  12609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12610. maxLength: 63
  12611. minLength: 1
  12612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12613. type: string
  12614. type: object
  12615. type: object
  12616. vaultAwsIamServerID:
  12617. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12618. type: string
  12619. vaultRole:
  12620. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12621. type: string
  12622. required:
  12623. - vaultRole
  12624. type: object
  12625. jwt:
  12626. description: |-
  12627. Jwt authenticates with Vault by passing role and JWT token using the
  12628. JWT/OIDC authentication method
  12629. properties:
  12630. kubernetesServiceAccountToken:
  12631. description: |-
  12632. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12633. a token for with the `TokenRequest` API.
  12634. properties:
  12635. audiences:
  12636. description: |-
  12637. Optional audiences field that will be used to request a temporary Kubernetes service
  12638. account token for the service account referenced by `serviceAccountRef`.
  12639. Defaults to a single audience `vault` it not specified.
  12640. Deprecated: use serviceAccountRef.Audiences instead
  12641. items:
  12642. type: string
  12643. type: array
  12644. expirationSeconds:
  12645. description: |-
  12646. Optional expiration time in seconds that will be used to request a temporary
  12647. Kubernetes service account token for the service account referenced by
  12648. `serviceAccountRef`.
  12649. Deprecated: this will be removed in the future.
  12650. Defaults to 10 minutes.
  12651. format: int64
  12652. type: integer
  12653. serviceAccountRef:
  12654. description: Service account field containing the name of a kubernetes ServiceAccount.
  12655. properties:
  12656. audiences:
  12657. description: |-
  12658. Audience specifies the `aud` claim for the service account token
  12659. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12660. then this audiences will be appended to the list
  12661. items:
  12662. type: string
  12663. type: array
  12664. name:
  12665. description: The name of the ServiceAccount resource being referred to.
  12666. maxLength: 253
  12667. minLength: 1
  12668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12669. type: string
  12670. namespace:
  12671. description: |-
  12672. Namespace of the resource being referred to.
  12673. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12674. maxLength: 63
  12675. minLength: 1
  12676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12677. type: string
  12678. required:
  12679. - name
  12680. type: object
  12681. required:
  12682. - serviceAccountRef
  12683. type: object
  12684. path:
  12685. default: jwt
  12686. description: |-
  12687. Path where the JWT authentication backend is mounted
  12688. in Vault, e.g: "jwt"
  12689. type: string
  12690. role:
  12691. description: |-
  12692. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12693. authentication method
  12694. type: string
  12695. secretRef:
  12696. description: |-
  12697. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12698. authenticate with Vault using the JWT/OIDC authentication method.
  12699. properties:
  12700. key:
  12701. description: |-
  12702. A key in the referenced Secret.
  12703. Some instances of this field may be defaulted, in others it may be required.
  12704. maxLength: 253
  12705. minLength: 1
  12706. pattern: ^[-._a-zA-Z0-9]+$
  12707. type: string
  12708. name:
  12709. description: The name of the Secret resource being referred to.
  12710. maxLength: 253
  12711. minLength: 1
  12712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12713. type: string
  12714. namespace:
  12715. description: |-
  12716. The namespace of the Secret resource being referred to.
  12717. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12718. maxLength: 63
  12719. minLength: 1
  12720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12721. type: string
  12722. type: object
  12723. required:
  12724. - path
  12725. type: object
  12726. kubernetes:
  12727. description: |-
  12728. Kubernetes authenticates with Vault by passing the ServiceAccount
  12729. token stored in the named Secret resource to the Vault server.
  12730. properties:
  12731. mountPath:
  12732. default: kubernetes
  12733. description: |-
  12734. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12735. "kubernetes"
  12736. type: string
  12737. role:
  12738. description: |-
  12739. A required field containing the Vault Role to assume. A Role binds a
  12740. Kubernetes ServiceAccount with a set of Vault policies.
  12741. type: string
  12742. secretRef:
  12743. description: |-
  12744. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12745. for authenticating with Vault. If a name is specified without a key,
  12746. `token` is the default. If one is not specified, the one bound to
  12747. the controller will be used.
  12748. properties:
  12749. key:
  12750. description: |-
  12751. A key in the referenced Secret.
  12752. Some instances of this field may be defaulted, in others it may be required.
  12753. maxLength: 253
  12754. minLength: 1
  12755. pattern: ^[-._a-zA-Z0-9]+$
  12756. type: string
  12757. name:
  12758. description: The name of the Secret resource being referred to.
  12759. maxLength: 253
  12760. minLength: 1
  12761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12762. type: string
  12763. namespace:
  12764. description: |-
  12765. The namespace of the Secret resource being referred to.
  12766. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12767. maxLength: 63
  12768. minLength: 1
  12769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12770. type: string
  12771. type: object
  12772. serviceAccountRef:
  12773. description: |-
  12774. Optional service account field containing the name of a kubernetes ServiceAccount.
  12775. If the service account is specified, the service account secret token JWT will be used
  12776. for authenticating with Vault. If the service account selector is not supplied,
  12777. the secretRef will be used instead.
  12778. properties:
  12779. audiences:
  12780. description: |-
  12781. Audience specifies the `aud` claim for the service account token
  12782. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12783. then this audiences will be appended to the list
  12784. items:
  12785. type: string
  12786. type: array
  12787. name:
  12788. description: The name of the ServiceAccount resource being referred to.
  12789. maxLength: 253
  12790. minLength: 1
  12791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12792. type: string
  12793. namespace:
  12794. description: |-
  12795. Namespace of the resource being referred to.
  12796. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12797. maxLength: 63
  12798. minLength: 1
  12799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12800. type: string
  12801. required:
  12802. - name
  12803. type: object
  12804. required:
  12805. - mountPath
  12806. - role
  12807. type: object
  12808. ldap:
  12809. description: |-
  12810. Ldap authenticates with Vault by passing username/password pair using
  12811. the LDAP authentication method
  12812. properties:
  12813. path:
  12814. default: ldap
  12815. description: |-
  12816. Path where the LDAP authentication backend is mounted
  12817. in Vault, e.g: "ldap"
  12818. type: string
  12819. secretRef:
  12820. description: |-
  12821. SecretRef to a key in a Secret resource containing password for the LDAP
  12822. user used to authenticate with Vault using the LDAP authentication
  12823. method
  12824. properties:
  12825. key:
  12826. description: |-
  12827. A key in the referenced Secret.
  12828. Some instances of this field may be defaulted, in others it may be required.
  12829. maxLength: 253
  12830. minLength: 1
  12831. pattern: ^[-._a-zA-Z0-9]+$
  12832. type: string
  12833. name:
  12834. description: The name of the Secret resource being referred to.
  12835. maxLength: 253
  12836. minLength: 1
  12837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12838. type: string
  12839. namespace:
  12840. description: |-
  12841. The namespace of the Secret resource being referred to.
  12842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12843. maxLength: 63
  12844. minLength: 1
  12845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12846. type: string
  12847. type: object
  12848. username:
  12849. description: |-
  12850. Username is an LDAP username used to authenticate using the LDAP Vault
  12851. authentication method
  12852. type: string
  12853. required:
  12854. - path
  12855. - username
  12856. type: object
  12857. namespace:
  12858. description: |-
  12859. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  12860. Namespaces is a set of features within Vault Enterprise that allows
  12861. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12862. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12863. This will default to Vault.Namespace field if set, or empty otherwise
  12864. type: string
  12865. tokenSecretRef:
  12866. description: TokenSecretRef authenticates with Vault by presenting a token.
  12867. properties:
  12868. key:
  12869. description: |-
  12870. A key in the referenced Secret.
  12871. Some instances of this field may be defaulted, in others it may be required.
  12872. maxLength: 253
  12873. minLength: 1
  12874. pattern: ^[-._a-zA-Z0-9]+$
  12875. type: string
  12876. name:
  12877. description: The name of the Secret resource being referred to.
  12878. maxLength: 253
  12879. minLength: 1
  12880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12881. type: string
  12882. namespace:
  12883. description: |-
  12884. The namespace of the Secret resource being referred to.
  12885. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12886. maxLength: 63
  12887. minLength: 1
  12888. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12889. type: string
  12890. type: object
  12891. userPass:
  12892. description: UserPass authenticates with Vault by passing username/password pair
  12893. properties:
  12894. path:
  12895. default: userpass
  12896. description: |-
  12897. Path where the UserPassword authentication backend is mounted
  12898. in Vault, e.g: "userpass"
  12899. type: string
  12900. secretRef:
  12901. description: |-
  12902. SecretRef to a key in a Secret resource containing password for the
  12903. user used to authenticate with Vault using the UserPass authentication
  12904. method
  12905. properties:
  12906. key:
  12907. description: |-
  12908. A key in the referenced Secret.
  12909. Some instances of this field may be defaulted, in others it may be required.
  12910. maxLength: 253
  12911. minLength: 1
  12912. pattern: ^[-._a-zA-Z0-9]+$
  12913. type: string
  12914. name:
  12915. description: The name of the Secret resource being referred to.
  12916. maxLength: 253
  12917. minLength: 1
  12918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12919. type: string
  12920. namespace:
  12921. description: |-
  12922. The namespace of the Secret resource being referred to.
  12923. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12924. maxLength: 63
  12925. minLength: 1
  12926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12927. type: string
  12928. type: object
  12929. username:
  12930. description: |-
  12931. Username is a username used to authenticate using the UserPass Vault
  12932. authentication method
  12933. type: string
  12934. required:
  12935. - path
  12936. - username
  12937. type: object
  12938. type: object
  12939. caBundle:
  12940. description: |-
  12941. PEM encoded CA bundle used to validate Vault server certificate. Only used
  12942. if the Server URL is using HTTPS protocol. This parameter is ignored for
  12943. plain HTTP protocol connection. If not set the system root certificates
  12944. are used to validate the TLS connection.
  12945. format: byte
  12946. type: string
  12947. caProvider:
  12948. description: The provider for the CA bundle to use to validate Vault server certificate.
  12949. properties:
  12950. key:
  12951. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  12952. maxLength: 253
  12953. minLength: 1
  12954. pattern: ^[-._a-zA-Z0-9]+$
  12955. type: string
  12956. name:
  12957. description: The name of the object located at the provider type.
  12958. maxLength: 253
  12959. minLength: 1
  12960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12961. type: string
  12962. namespace:
  12963. description: |-
  12964. The namespace the Provider type is in.
  12965. Can only be defined when used in a ClusterSecretStore.
  12966. maxLength: 63
  12967. minLength: 1
  12968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12969. type: string
  12970. type:
  12971. description: The type of provider to use such as "Secret", or "ConfigMap".
  12972. enum:
  12973. - Secret
  12974. - ConfigMap
  12975. type: string
  12976. required:
  12977. - name
  12978. - type
  12979. type: object
  12980. forwardInconsistent:
  12981. description: |-
  12982. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  12983. leader instead of simply retrying within a loop. This can increase performance if
  12984. the option is enabled serverside.
  12985. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  12986. type: boolean
  12987. headers:
  12988. additionalProperties:
  12989. type: string
  12990. description: Headers to be added in Vault request
  12991. type: object
  12992. namespace:
  12993. description: |-
  12994. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  12995. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  12996. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  12997. type: string
  12998. path:
  12999. description: |-
  13000. Path is the mount path of the Vault KV backend endpoint, e.g:
  13001. "secret". The v2 KV secret engine version specific "/data" path suffix
  13002. for fetching secrets from Vault is optional and will be appended
  13003. if not present in specified path.
  13004. type: string
  13005. readYourWrites:
  13006. description: |-
  13007. ReadYourWrites ensures isolated read-after-write semantics by
  13008. providing discovered cluster replication states in each request.
  13009. More information about eventual consistency in Vault can be found here
  13010. https://www.vaultproject.io/docs/enterprise/consistency
  13011. type: boolean
  13012. server:
  13013. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13014. type: string
  13015. tls:
  13016. description: |-
  13017. The configuration used for client side related TLS communication, when the Vault server
  13018. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13019. This parameter is ignored for plain HTTP protocol connection.
  13020. It's worth noting this configuration is different from the "TLS certificates auth method",
  13021. which is available under the `auth.cert` section.
  13022. properties:
  13023. certSecretRef:
  13024. description: |-
  13025. CertSecretRef is a certificate added to the transport layer
  13026. when communicating with the Vault server.
  13027. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13028. properties:
  13029. key:
  13030. description: |-
  13031. A key in the referenced Secret.
  13032. Some instances of this field may be defaulted, in others it may be required.
  13033. maxLength: 253
  13034. minLength: 1
  13035. pattern: ^[-._a-zA-Z0-9]+$
  13036. type: string
  13037. name:
  13038. description: The name of the Secret resource being referred to.
  13039. maxLength: 253
  13040. minLength: 1
  13041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13042. type: string
  13043. namespace:
  13044. description: |-
  13045. The namespace of the Secret resource being referred to.
  13046. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13047. maxLength: 63
  13048. minLength: 1
  13049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13050. type: string
  13051. type: object
  13052. keySecretRef:
  13053. description: |-
  13054. KeySecretRef to a key in a Secret resource containing client private key
  13055. added to the transport layer when communicating with the Vault server.
  13056. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13057. properties:
  13058. key:
  13059. description: |-
  13060. A key in the referenced Secret.
  13061. Some instances of this field may be defaulted, in others it may be required.
  13062. maxLength: 253
  13063. minLength: 1
  13064. pattern: ^[-._a-zA-Z0-9]+$
  13065. type: string
  13066. name:
  13067. description: The name of the Secret resource being referred to.
  13068. maxLength: 253
  13069. minLength: 1
  13070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13071. type: string
  13072. namespace:
  13073. description: |-
  13074. The namespace of the Secret resource being referred to.
  13075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13076. maxLength: 63
  13077. minLength: 1
  13078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13079. type: string
  13080. type: object
  13081. type: object
  13082. version:
  13083. default: v2
  13084. description: |-
  13085. Version is the Vault KV secret engine version. This can be either "v1" or
  13086. "v2". Version defaults to "v2".
  13087. enum:
  13088. - v1
  13089. - v2
  13090. type: string
  13091. required:
  13092. - server
  13093. type: object
  13094. webhook:
  13095. description: Webhook configures this store to sync secrets using a generic templated webhook
  13096. properties:
  13097. auth:
  13098. description: Auth specifies a authorization protocol. Only one protocol may be set.
  13099. maxProperties: 1
  13100. minProperties: 1
  13101. properties:
  13102. ntlm:
  13103. description: NTLMProtocol configures the store to use NTLM for auth
  13104. properties:
  13105. passwordSecret:
  13106. description: |-
  13107. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13108. In some instances, `key` is a required field.
  13109. properties:
  13110. key:
  13111. description: |-
  13112. A key in the referenced Secret.
  13113. Some instances of this field may be defaulted, in others it may be required.
  13114. maxLength: 253
  13115. minLength: 1
  13116. pattern: ^[-._a-zA-Z0-9]+$
  13117. type: string
  13118. name:
  13119. description: The name of the Secret resource being referred to.
  13120. maxLength: 253
  13121. minLength: 1
  13122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13123. type: string
  13124. namespace:
  13125. description: |-
  13126. The namespace of the Secret resource being referred to.
  13127. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13128. maxLength: 63
  13129. minLength: 1
  13130. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13131. type: string
  13132. type: object
  13133. usernameSecret:
  13134. description: |-
  13135. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13136. In some instances, `key` is a required field.
  13137. properties:
  13138. key:
  13139. description: |-
  13140. A key in the referenced Secret.
  13141. Some instances of this field may be defaulted, in others it may be required.
  13142. maxLength: 253
  13143. minLength: 1
  13144. pattern: ^[-._a-zA-Z0-9]+$
  13145. type: string
  13146. name:
  13147. description: The name of the Secret resource being referred to.
  13148. maxLength: 253
  13149. minLength: 1
  13150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13151. type: string
  13152. namespace:
  13153. description: |-
  13154. The namespace of the Secret resource being referred to.
  13155. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13156. maxLength: 63
  13157. minLength: 1
  13158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13159. type: string
  13160. type: object
  13161. required:
  13162. - passwordSecret
  13163. - usernameSecret
  13164. type: object
  13165. type: object
  13166. body:
  13167. description: Body
  13168. type: string
  13169. caBundle:
  13170. description: |-
  13171. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13172. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13173. plain HTTP protocol connection. If not set the system root certificates
  13174. are used to validate the TLS connection.
  13175. format: byte
  13176. type: string
  13177. caProvider:
  13178. description: The provider for the CA bundle to use to validate webhook server certificate.
  13179. properties:
  13180. key:
  13181. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13182. maxLength: 253
  13183. minLength: 1
  13184. pattern: ^[-._a-zA-Z0-9]+$
  13185. type: string
  13186. name:
  13187. description: The name of the object located at the provider type.
  13188. maxLength: 253
  13189. minLength: 1
  13190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13191. type: string
  13192. namespace:
  13193. description: The namespace the Provider type is in.
  13194. maxLength: 63
  13195. minLength: 1
  13196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13197. type: string
  13198. type:
  13199. description: The type of provider to use such as "Secret", or "ConfigMap".
  13200. enum:
  13201. - Secret
  13202. - ConfigMap
  13203. type: string
  13204. required:
  13205. - name
  13206. - type
  13207. type: object
  13208. headers:
  13209. additionalProperties:
  13210. type: string
  13211. description: Headers
  13212. type: object
  13213. method:
  13214. description: Webhook Method
  13215. type: string
  13216. result:
  13217. description: Result formatting
  13218. properties:
  13219. jsonPath:
  13220. description: Json path of return value
  13221. type: string
  13222. type: object
  13223. secrets:
  13224. description: |-
  13225. Secrets to fill in templates
  13226. These secrets will be passed to the templating function as key value pairs under the given name
  13227. items:
  13228. description: WebhookSecret defines a secret to be used in webhook templates.
  13229. properties:
  13230. name:
  13231. description: Name of this secret in templates
  13232. type: string
  13233. secretRef:
  13234. description: Secret ref to fill in credentials
  13235. properties:
  13236. key:
  13237. description: |-
  13238. A key in the referenced Secret.
  13239. Some instances of this field may be defaulted, in others it may be required.
  13240. maxLength: 253
  13241. minLength: 1
  13242. pattern: ^[-._a-zA-Z0-9]+$
  13243. type: string
  13244. name:
  13245. description: The name of the Secret resource being referred to.
  13246. maxLength: 253
  13247. minLength: 1
  13248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13249. type: string
  13250. namespace:
  13251. description: |-
  13252. The namespace of the Secret resource being referred to.
  13253. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13254. maxLength: 63
  13255. minLength: 1
  13256. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13257. type: string
  13258. type: object
  13259. required:
  13260. - name
  13261. - secretRef
  13262. type: object
  13263. type: array
  13264. timeout:
  13265. description: Timeout
  13266. type: string
  13267. url:
  13268. description: Webhook url to call
  13269. type: string
  13270. required:
  13271. - result
  13272. - url
  13273. type: object
  13274. yandexcertificatemanager:
  13275. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13276. properties:
  13277. apiEndpoint:
  13278. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13279. type: string
  13280. auth:
  13281. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13282. properties:
  13283. authorizedKeySecretRef:
  13284. description: The authorized key used for authentication
  13285. properties:
  13286. key:
  13287. description: |-
  13288. A key in the referenced Secret.
  13289. Some instances of this field may be defaulted, in others it may be required.
  13290. maxLength: 253
  13291. minLength: 1
  13292. pattern: ^[-._a-zA-Z0-9]+$
  13293. type: string
  13294. name:
  13295. description: The name of the Secret resource being referred to.
  13296. maxLength: 253
  13297. minLength: 1
  13298. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13299. type: string
  13300. namespace:
  13301. description: |-
  13302. The namespace of the Secret resource being referred to.
  13303. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13304. maxLength: 63
  13305. minLength: 1
  13306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13307. type: string
  13308. type: object
  13309. type: object
  13310. caProvider:
  13311. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13312. properties:
  13313. certSecretRef:
  13314. description: |-
  13315. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13316. In some instances, `key` is a required field.
  13317. properties:
  13318. key:
  13319. description: |-
  13320. A key in the referenced Secret.
  13321. Some instances of this field may be defaulted, in others it may be required.
  13322. maxLength: 253
  13323. minLength: 1
  13324. pattern: ^[-._a-zA-Z0-9]+$
  13325. type: string
  13326. name:
  13327. description: The name of the Secret resource being referred to.
  13328. maxLength: 253
  13329. minLength: 1
  13330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13331. type: string
  13332. namespace:
  13333. description: |-
  13334. The namespace of the Secret resource being referred to.
  13335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13336. maxLength: 63
  13337. minLength: 1
  13338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13339. type: string
  13340. type: object
  13341. type: object
  13342. required:
  13343. - auth
  13344. type: object
  13345. yandexlockbox:
  13346. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13347. properties:
  13348. apiEndpoint:
  13349. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13350. type: string
  13351. auth:
  13352. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13353. properties:
  13354. authorizedKeySecretRef:
  13355. description: The authorized key used for authentication
  13356. properties:
  13357. key:
  13358. description: |-
  13359. A key in the referenced Secret.
  13360. Some instances of this field may be defaulted, in others it may be required.
  13361. maxLength: 253
  13362. minLength: 1
  13363. pattern: ^[-._a-zA-Z0-9]+$
  13364. type: string
  13365. name:
  13366. description: The name of the Secret resource being referred to.
  13367. maxLength: 253
  13368. minLength: 1
  13369. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13370. type: string
  13371. namespace:
  13372. description: |-
  13373. The namespace of the Secret resource being referred to.
  13374. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13375. maxLength: 63
  13376. minLength: 1
  13377. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13378. type: string
  13379. type: object
  13380. type: object
  13381. caProvider:
  13382. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13383. properties:
  13384. certSecretRef:
  13385. description: |-
  13386. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  13387. In some instances, `key` is a required field.
  13388. properties:
  13389. key:
  13390. description: |-
  13391. A key in the referenced Secret.
  13392. Some instances of this field may be defaulted, in others it may be required.
  13393. maxLength: 253
  13394. minLength: 1
  13395. pattern: ^[-._a-zA-Z0-9]+$
  13396. type: string
  13397. name:
  13398. description: The name of the Secret resource being referred to.
  13399. maxLength: 253
  13400. minLength: 1
  13401. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13402. type: string
  13403. namespace:
  13404. description: |-
  13405. The namespace of the Secret resource being referred to.
  13406. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13407. maxLength: 63
  13408. minLength: 1
  13409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13410. type: string
  13411. type: object
  13412. type: object
  13413. required:
  13414. - auth
  13415. type: object
  13416. type: object
  13417. refreshInterval:
  13418. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13419. type: integer
  13420. retrySettings:
  13421. description: Used to configure HTTP retries on failures.
  13422. properties:
  13423. maxRetries:
  13424. description: MaxRetries is the maximum number of retry attempts.
  13425. format: int32
  13426. type: integer
  13427. retryInterval:
  13428. description: RetryInterval is the interval between retry attempts.
  13429. type: string
  13430. type: object
  13431. required:
  13432. - provider
  13433. type: object
  13434. status:
  13435. description: SecretStoreStatus defines the observed state of the SecretStore.
  13436. properties:
  13437. capabilities:
  13438. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13439. type: string
  13440. conditions:
  13441. items:
  13442. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  13443. properties:
  13444. lastTransitionTime:
  13445. format: date-time
  13446. type: string
  13447. message:
  13448. type: string
  13449. reason:
  13450. type: string
  13451. status:
  13452. type: string
  13453. type:
  13454. description: SecretStoreConditionType represents the condition type of the SecretStore.
  13455. type: string
  13456. required:
  13457. - status
  13458. - type
  13459. type: object
  13460. type: array
  13461. type: object
  13462. type: object
  13463. served: false
  13464. storage: false
  13465. subresources:
  13466. status: {}
  13467. ---
  13468. apiVersion: apiextensions.k8s.io/v1
  13469. kind: CustomResourceDefinition
  13470. metadata:
  13471. annotations:
  13472. controller-gen.kubebuilder.io/version: v0.19.0
  13473. labels:
  13474. external-secrets.io/component: controller
  13475. name: externalsecrets.external-secrets.io
  13476. spec:
  13477. group: external-secrets.io
  13478. names:
  13479. categories:
  13480. - external-secrets
  13481. kind: ExternalSecret
  13482. listKind: ExternalSecretList
  13483. plural: externalsecrets
  13484. shortNames:
  13485. - es
  13486. singular: externalsecret
  13487. scope: Namespaced
  13488. versions:
  13489. - additionalPrinterColumns:
  13490. - jsonPath: .spec.secretStoreRef.kind
  13491. name: StoreType
  13492. type: string
  13493. - jsonPath: .spec.secretStoreRef.name
  13494. name: Store
  13495. type: string
  13496. - jsonPath: .spec.refreshInterval
  13497. name: Refresh Interval
  13498. type: string
  13499. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  13500. name: Status
  13501. type: string
  13502. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  13503. name: Ready
  13504. type: string
  13505. - jsonPath: .status.refreshTime
  13506. name: Last Sync
  13507. type: date
  13508. name: v1
  13509. schema:
  13510. openAPIV3Schema:
  13511. description: |-
  13512. ExternalSecret is the Schema for the external-secrets API.
  13513. It defines how to fetch data from external APIs and make it available as Kubernetes Secrets.
  13514. properties:
  13515. apiVersion:
  13516. description: |-
  13517. APIVersion defines the versioned schema of this representation of an object.
  13518. Servers should convert recognized schemas to the latest internal value, and
  13519. may reject unrecognized values.
  13520. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13521. type: string
  13522. kind:
  13523. description: |-
  13524. Kind is a string value representing the REST resource this object represents.
  13525. Servers may infer this from the endpoint the client submits requests to.
  13526. Cannot be updated.
  13527. In CamelCase.
  13528. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13529. type: string
  13530. metadata:
  13531. type: object
  13532. spec:
  13533. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  13534. properties:
  13535. data:
  13536. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  13537. items:
  13538. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  13539. properties:
  13540. remoteRef:
  13541. description: |-
  13542. RemoteRef points to the remote secret and defines
  13543. which secret (version/property/..) to fetch.
  13544. properties:
  13545. conversionStrategy:
  13546. default: Default
  13547. description: Used to define a conversion Strategy
  13548. enum:
  13549. - Default
  13550. - Unicode
  13551. type: string
  13552. decodingStrategy:
  13553. default: None
  13554. description: Used to define a decoding Strategy
  13555. enum:
  13556. - Auto
  13557. - Base64
  13558. - Base64URL
  13559. - None
  13560. type: string
  13561. key:
  13562. description: Key is the key used in the Provider, mandatory
  13563. type: string
  13564. metadataPolicy:
  13565. default: None
  13566. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13567. enum:
  13568. - None
  13569. - Fetch
  13570. type: string
  13571. nullBytePolicy:
  13572. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13573. enum:
  13574. - Ignore
  13575. - Fail
  13576. type: string
  13577. property:
  13578. description: Used to select a specific property of the Provider value (if a map), if supported
  13579. type: string
  13580. version:
  13581. description: Used to select a specific version of the Provider value, if supported
  13582. type: string
  13583. required:
  13584. - key
  13585. type: object
  13586. secretKey:
  13587. description: The key in the Kubernetes Secret to store the value.
  13588. maxLength: 253
  13589. minLength: 1
  13590. pattern: ^[-._a-zA-Z0-9]+$
  13591. type: string
  13592. sourceRef:
  13593. description: |-
  13594. SourceRef allows you to override the source
  13595. from which the value will be pulled.
  13596. maxProperties: 1
  13597. minProperties: 1
  13598. properties:
  13599. generatorRef:
  13600. description: |-
  13601. GeneratorRef points to a generator custom resource.
  13602. Deprecated: The generatorRef is not implemented in .data[].
  13603. this will be removed with v1.
  13604. properties:
  13605. apiVersion:
  13606. default: generators.external-secrets.io/v1alpha1
  13607. description: Specify the apiVersion of the generator resource
  13608. type: string
  13609. kind:
  13610. description: Specify the Kind of the generator resource
  13611. enum:
  13612. - ACRAccessToken
  13613. - BeyondtrustWorkloadCredentialsDynamicSecret
  13614. - ClusterGenerator
  13615. - CloudsmithAccessToken
  13616. - ECRAuthorizationToken
  13617. - Fake
  13618. - GCRAccessToken
  13619. - GithubAccessToken
  13620. - GitlabDeployToken
  13621. - QuayAccessToken
  13622. - Password
  13623. - SSHKey
  13624. - STSSessionToken
  13625. - UUID
  13626. - VaultDynamicSecret
  13627. - Webhook
  13628. - Grafana
  13629. - MFA
  13630. type: string
  13631. name:
  13632. description: Specify the name of the generator resource
  13633. maxLength: 253
  13634. minLength: 1
  13635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13636. type: string
  13637. required:
  13638. - kind
  13639. - name
  13640. type: object
  13641. storeRef:
  13642. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13643. properties:
  13644. kind:
  13645. description: |-
  13646. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13647. Defaults to `SecretStore`
  13648. enum:
  13649. - SecretStore
  13650. - ClusterSecretStore
  13651. type: string
  13652. name:
  13653. description: Name of the SecretStore resource
  13654. maxLength: 253
  13655. minLength: 1
  13656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13657. type: string
  13658. type: object
  13659. type: object
  13660. required:
  13661. - remoteRef
  13662. - secretKey
  13663. type: object
  13664. type: array
  13665. dataFrom:
  13666. description: |-
  13667. DataFrom is used to fetch all properties from a specific Provider data
  13668. If multiple entries are specified, the Secret keys are merged in the specified order
  13669. items:
  13670. description: |-
  13671. ExternalSecretDataFromRemoteRef defines the connection between the Kubernetes Secret keys and the Provider data
  13672. when using DataFrom to fetch multiple values from a Provider.
  13673. properties:
  13674. extract:
  13675. description: |-
  13676. Used to extract multiple key/value pairs from one secret
  13677. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13678. properties:
  13679. conversionStrategy:
  13680. default: Default
  13681. description: Used to define a conversion Strategy
  13682. enum:
  13683. - Default
  13684. - Unicode
  13685. type: string
  13686. decodingStrategy:
  13687. default: None
  13688. description: Used to define a decoding Strategy
  13689. enum:
  13690. - Auto
  13691. - Base64
  13692. - Base64URL
  13693. - None
  13694. type: string
  13695. key:
  13696. description: Key is the key used in the Provider, mandatory
  13697. type: string
  13698. metadataPolicy:
  13699. default: None
  13700. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  13701. enum:
  13702. - None
  13703. - Fetch
  13704. type: string
  13705. nullBytePolicy:
  13706. description: Controls how ESO handles fetched secret data containing NUL bytes for this source.
  13707. enum:
  13708. - Ignore
  13709. - Fail
  13710. type: string
  13711. property:
  13712. description: Used to select a specific property of the Provider value (if a map), if supported
  13713. type: string
  13714. version:
  13715. description: Used to select a specific version of the Provider value, if supported
  13716. type: string
  13717. required:
  13718. - key
  13719. type: object
  13720. find:
  13721. description: |-
  13722. Used to find secrets based on tags or regular expressions
  13723. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  13724. properties:
  13725. conversionStrategy:
  13726. default: Default
  13727. description: Used to define a conversion Strategy
  13728. enum:
  13729. - Default
  13730. - Unicode
  13731. type: string
  13732. decodingStrategy:
  13733. default: None
  13734. description: Used to define a decoding Strategy
  13735. enum:
  13736. - Auto
  13737. - Base64
  13738. - Base64URL
  13739. - None
  13740. type: string
  13741. name:
  13742. description: Finds secrets based on the name.
  13743. properties:
  13744. regexp:
  13745. description: Finds secrets base
  13746. type: string
  13747. type: object
  13748. nullBytePolicy:
  13749. description: Controls how ESO handles fetched secret data containing NUL bytes for this find source.
  13750. enum:
  13751. - Ignore
  13752. - Fail
  13753. type: string
  13754. path:
  13755. description: A root path to start the find operations.
  13756. type: string
  13757. tags:
  13758. additionalProperties:
  13759. type: string
  13760. description: Find secrets based on tags.
  13761. type: object
  13762. type: object
  13763. rewrite:
  13764. description: |-
  13765. Used to rewrite secret Keys after getting them from the secret Provider
  13766. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  13767. items:
  13768. description: ExternalSecretRewrite defines how to rewrite secret data values before they are written to the Secret.
  13769. maxProperties: 1
  13770. minProperties: 1
  13771. properties:
  13772. merge:
  13773. description: |-
  13774. Used to merge key/values in one single Secret
  13775. The resulting key will contain all values from the specified secrets
  13776. properties:
  13777. conflictPolicy:
  13778. default: Error
  13779. description: Used to define the policy to use in conflict resolution.
  13780. enum:
  13781. - Ignore
  13782. - Error
  13783. type: string
  13784. into:
  13785. default: ""
  13786. description: |-
  13787. Used to define the target key of the merge operation.
  13788. Required if strategy is JSON. Ignored otherwise.
  13789. type: string
  13790. priority:
  13791. description: Used to define key priority in conflict resolution.
  13792. items:
  13793. type: string
  13794. type: array
  13795. priorityPolicy:
  13796. default: Strict
  13797. description: Used to define the policy when a key in the priority list does not exist in the input.
  13798. enum:
  13799. - IgnoreNotFound
  13800. - Strict
  13801. type: string
  13802. strategy:
  13803. default: Extract
  13804. description: Used to define the strategy to use in the merge operation.
  13805. enum:
  13806. - Extract
  13807. - JSON
  13808. type: string
  13809. type: object
  13810. regexp:
  13811. description: |-
  13812. Used to rewrite with regular expressions.
  13813. The resulting key will be the output of a regexp.ReplaceAll operation.
  13814. properties:
  13815. source:
  13816. description: Used to define the regular expression of a re.Compiler.
  13817. type: string
  13818. target:
  13819. description: Used to define the target pattern of a ReplaceAll operation.
  13820. type: string
  13821. required:
  13822. - source
  13823. - target
  13824. type: object
  13825. transform:
  13826. description: |-
  13827. Used to apply string transformation on the secrets.
  13828. The resulting key will be the output of the template applied by the operation.
  13829. properties:
  13830. template:
  13831. description: |-
  13832. Used to define the template to apply on the secret name.
  13833. `.value ` will specify the secret name in the template.
  13834. type: string
  13835. required:
  13836. - template
  13837. type: object
  13838. type: object
  13839. type: array
  13840. sourceRef:
  13841. description: |-
  13842. SourceRef points to a store or generator
  13843. which contains secret values ready to use.
  13844. Use this in combination with Extract or Find pull values out of
  13845. a specific SecretStore.
  13846. When sourceRef points to a generator Extract or Find is not supported.
  13847. The generator returns a static map of values
  13848. maxProperties: 1
  13849. minProperties: 1
  13850. properties:
  13851. generatorRef:
  13852. description: GeneratorRef points to a generator custom resource.
  13853. properties:
  13854. apiVersion:
  13855. default: generators.external-secrets.io/v1alpha1
  13856. description: Specify the apiVersion of the generator resource
  13857. type: string
  13858. kind:
  13859. description: Specify the Kind of the generator resource
  13860. enum:
  13861. - ACRAccessToken
  13862. - BeyondtrustWorkloadCredentialsDynamicSecret
  13863. - ClusterGenerator
  13864. - CloudsmithAccessToken
  13865. - ECRAuthorizationToken
  13866. - Fake
  13867. - GCRAccessToken
  13868. - GithubAccessToken
  13869. - GitlabDeployToken
  13870. - QuayAccessToken
  13871. - Password
  13872. - SSHKey
  13873. - STSSessionToken
  13874. - UUID
  13875. - VaultDynamicSecret
  13876. - Webhook
  13877. - Grafana
  13878. - MFA
  13879. type: string
  13880. name:
  13881. description: Specify the name of the generator resource
  13882. maxLength: 253
  13883. minLength: 1
  13884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13885. type: string
  13886. required:
  13887. - kind
  13888. - name
  13889. type: object
  13890. storeRef:
  13891. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13892. properties:
  13893. kind:
  13894. description: |-
  13895. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13896. Defaults to `SecretStore`
  13897. enum:
  13898. - SecretStore
  13899. - ClusterSecretStore
  13900. type: string
  13901. name:
  13902. description: Name of the SecretStore resource
  13903. maxLength: 253
  13904. minLength: 1
  13905. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13906. type: string
  13907. type: object
  13908. type: object
  13909. type: object
  13910. type: array
  13911. refreshInterval:
  13912. default: 1h0m0s
  13913. description: |-
  13914. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  13915. specified as Golang Duration strings.
  13916. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  13917. Example values: "1h0m0s", "2h30m0s", "10m0s"
  13918. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  13919. type: string
  13920. refreshPolicy:
  13921. description: |-
  13922. RefreshPolicy determines how the ExternalSecret should be refreshed:
  13923. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  13924. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  13925. No periodic updates occur if refreshInterval is 0.
  13926. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  13927. enum:
  13928. - CreatedOnce
  13929. - Periodic
  13930. - OnChange
  13931. type: string
  13932. secretStoreRef:
  13933. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  13934. properties:
  13935. kind:
  13936. description: |-
  13937. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  13938. Defaults to `SecretStore`
  13939. enum:
  13940. - SecretStore
  13941. - ClusterSecretStore
  13942. type: string
  13943. name:
  13944. description: Name of the SecretStore resource
  13945. maxLength: 253
  13946. minLength: 1
  13947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13948. type: string
  13949. type: object
  13950. syncWindows:
  13951. description: |-
  13952. SyncWindows optionally restricts when periodic refreshes may occur.
  13953. Evaluated in UTC, only for Periodic refresh policy (or when refreshPolicy is unset).
  13954. properties:
  13955. kind:
  13956. description: |-
  13957. Kind applies to every window in the list.
  13958. "allow" -- syncs are permitted only while at least one window is active;
  13959. all other times are blocked.
  13960. "deny" -- syncs are blocked while any window is active;
  13961. all other times are permitted.
  13962. enum:
  13963. - allow
  13964. - deny
  13965. type: string
  13966. windows:
  13967. description: Windows is the list of schedule+duration pairs.
  13968. items:
  13969. description: |-
  13970. ExternalSecretSyncWindowEntry defines a single cron-schedule + duration pair
  13971. within a SyncWindows block.
  13972. properties:
  13973. duration:
  13974. description: |-
  13975. Duration specifies how long the window stays open after each Schedule
  13976. firing. Example: "8h".
  13977. type: string
  13978. schedule:
  13979. description: |-
  13980. Schedule is a standard 5-field cron expression evaluated in UTC, or a
  13981. named shorthand such as @daily or @every 1h. It marks the start time of
  13982. each window occurrence.
  13983. Example: "0 22 * * 1-5" opens a window every weekday at 22:00 UTC.
  13984. minLength: 1
  13985. pattern: ^(@(annually|yearly|monthly|weekly|daily|midnight|hourly)|@every [^\s]+.*|[^\s]+( [^\s]+){4})$
  13986. type: string
  13987. required:
  13988. - duration
  13989. - schedule
  13990. type: object
  13991. minItems: 1
  13992. type: array
  13993. required:
  13994. - kind
  13995. - windows
  13996. type: object
  13997. target:
  13998. default:
  13999. creationPolicy: Owner
  14000. deletionPolicy: Retain
  14001. description: |-
  14002. ExternalSecretTarget defines the Kubernetes Secret to be created,
  14003. there can be only one target per ExternalSecret.
  14004. properties:
  14005. creationPolicy:
  14006. default: Owner
  14007. description: |-
  14008. CreationPolicy defines rules on how to create the resulting Secret.
  14009. Defaults to "Owner"
  14010. enum:
  14011. - Owner
  14012. - Orphan
  14013. - Merge
  14014. - None
  14015. - CreateOrMerge
  14016. type: string
  14017. deletionPolicy:
  14018. default: Retain
  14019. description: |-
  14020. DeletionPolicy defines rules on how to delete the resulting Secret.
  14021. Defaults to "Retain"
  14022. enum:
  14023. - Delete
  14024. - Merge
  14025. - Retain
  14026. type: string
  14027. immutable:
  14028. description: Immutable defines if the final secret will be immutable
  14029. type: boolean
  14030. manifest:
  14031. description: |-
  14032. Manifest defines a custom Kubernetes resource to create instead of a Secret.
  14033. When specified, ExternalSecret will create the resource type defined here
  14034. (e.g., ConfigMap, Custom Resource) instead of a Secret.
  14035. Warning: Using Generic target. Make sure access policies and encryption are properly configured.
  14036. properties:
  14037. apiVersion:
  14038. description: APIVersion of the target resource (e.g., "v1" for ConfigMap, "argoproj.io/v1alpha1" for ArgoCD Application)
  14039. minLength: 1
  14040. type: string
  14041. kind:
  14042. description: Kind of the target resource (e.g., "ConfigMap", "Application")
  14043. minLength: 1
  14044. type: string
  14045. required:
  14046. - apiVersion
  14047. - kind
  14048. type: object
  14049. name:
  14050. description: |-
  14051. The name of the Secret resource to be managed.
  14052. Defaults to the .metadata.name of the ExternalSecret resource
  14053. maxLength: 253
  14054. minLength: 1
  14055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14056. type: string
  14057. template:
  14058. description: Template defines a blueprint for the created Secret resource.
  14059. properties:
  14060. data:
  14061. additionalProperties:
  14062. type: string
  14063. type: object
  14064. engineVersion:
  14065. default: v2
  14066. description: |-
  14067. EngineVersion specifies the template engine version
  14068. that should be used to compile/execute the
  14069. template specified in .data and .templateFrom[].
  14070. enum:
  14071. - v2
  14072. type: string
  14073. mergePolicy:
  14074. default: Replace
  14075. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  14076. enum:
  14077. - Replace
  14078. - Merge
  14079. type: string
  14080. metadata:
  14081. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14082. properties:
  14083. annotations:
  14084. additionalProperties:
  14085. type: string
  14086. type: object
  14087. finalizers:
  14088. items:
  14089. type: string
  14090. type: array
  14091. labels:
  14092. additionalProperties:
  14093. type: string
  14094. type: object
  14095. type: object
  14096. templateFrom:
  14097. items:
  14098. description: |-
  14099. TemplateFrom specifies a source for templates.
  14100. Each item in the list can either reference a ConfigMap or a Secret resource.
  14101. properties:
  14102. configMap:
  14103. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14104. properties:
  14105. items:
  14106. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14107. items:
  14108. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14109. properties:
  14110. key:
  14111. description: A key in the ConfigMap/Secret
  14112. maxLength: 253
  14113. minLength: 1
  14114. pattern: ^[-._a-zA-Z0-9]+$
  14115. type: string
  14116. templateAs:
  14117. default: Values
  14118. description: TemplateScope specifies how the template keys should be interpreted.
  14119. enum:
  14120. - Values
  14121. - KeysAndValues
  14122. type: string
  14123. required:
  14124. - key
  14125. type: object
  14126. type: array
  14127. name:
  14128. description: The name of the ConfigMap/Secret resource
  14129. maxLength: 253
  14130. minLength: 1
  14131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14132. type: string
  14133. required:
  14134. - items
  14135. - name
  14136. type: object
  14137. literal:
  14138. type: string
  14139. secret:
  14140. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  14141. properties:
  14142. items:
  14143. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14144. items:
  14145. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  14146. properties:
  14147. key:
  14148. description: A key in the ConfigMap/Secret
  14149. maxLength: 253
  14150. minLength: 1
  14151. pattern: ^[-._a-zA-Z0-9]+$
  14152. type: string
  14153. templateAs:
  14154. default: Values
  14155. description: TemplateScope specifies how the template keys should be interpreted.
  14156. enum:
  14157. - Values
  14158. - KeysAndValues
  14159. type: string
  14160. required:
  14161. - key
  14162. type: object
  14163. type: array
  14164. name:
  14165. description: The name of the ConfigMap/Secret resource
  14166. maxLength: 253
  14167. minLength: 1
  14168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14169. type: string
  14170. required:
  14171. - items
  14172. - name
  14173. type: object
  14174. target:
  14175. default: Data
  14176. description: |-
  14177. Target specifies where to place the template result.
  14178. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  14179. any other value is rejected because it would allow writes to privileged Secret fields.
  14180. For custom resources (when spec.target.manifest is set), this supports
  14181. nested paths like "spec.database.config" or "data".
  14182. type: string
  14183. valuesDecodingStrategy:
  14184. default: None
  14185. description: Used to define a decoding Strategy for the rendered template values.
  14186. enum:
  14187. - Auto
  14188. - Base64
  14189. - Base64URL
  14190. - None
  14191. type: string
  14192. type: object
  14193. type: array
  14194. type:
  14195. type: string
  14196. type: object
  14197. type: object
  14198. type: object
  14199. status:
  14200. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14201. properties:
  14202. binding:
  14203. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14204. properties:
  14205. name:
  14206. default: ""
  14207. description: |-
  14208. Name of the referent.
  14209. This field is effectively required, but due to backwards compatibility is
  14210. allowed to be empty. Instances of this type with an empty value here are
  14211. almost certainly wrong.
  14212. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14213. type: string
  14214. type: object
  14215. x-kubernetes-map-type: atomic
  14216. conditions:
  14217. items:
  14218. description: ExternalSecretStatusCondition defines a status condition of an ExternalSecret resource.
  14219. properties:
  14220. lastTransitionTime:
  14221. format: date-time
  14222. type: string
  14223. message:
  14224. type: string
  14225. reason:
  14226. type: string
  14227. status:
  14228. type: string
  14229. type:
  14230. description: ExternalSecretConditionType defines a value type for ExternalSecret conditions.
  14231. enum:
  14232. - Ready
  14233. - Deleted
  14234. type: string
  14235. required:
  14236. - status
  14237. - type
  14238. type: object
  14239. type: array
  14240. refreshTime:
  14241. description: |-
  14242. refreshTime is the time and date the external secret was fetched and
  14243. the target secret updated
  14244. format: date-time
  14245. nullable: true
  14246. type: string
  14247. syncedResourceVersion:
  14248. description: SyncedResourceVersion keeps track of the last synced version
  14249. type: string
  14250. type: object
  14251. type: object
  14252. selectableFields:
  14253. - jsonPath: .spec.secretStoreRef.name
  14254. - jsonPath: .spec.secretStoreRef.kind
  14255. - jsonPath: .spec.target.name
  14256. - jsonPath: .spec.refreshInterval
  14257. served: true
  14258. storage: true
  14259. subresources:
  14260. status: {}
  14261. - additionalPrinterColumns:
  14262. - jsonPath: .spec.secretStoreRef.kind
  14263. name: StoreType
  14264. type: string
  14265. - jsonPath: .spec.secretStoreRef.name
  14266. name: Store
  14267. type: string
  14268. - jsonPath: .spec.refreshInterval
  14269. name: Refresh Interval
  14270. type: string
  14271. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14272. name: Status
  14273. type: string
  14274. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  14275. name: Ready
  14276. type: string
  14277. - jsonPath: .status.refreshTime
  14278. name: Last Sync
  14279. type: date
  14280. deprecated: true
  14281. name: v1beta1
  14282. schema:
  14283. openAPIV3Schema:
  14284. description: ExternalSecret is the schema for the external-secrets API.
  14285. properties:
  14286. apiVersion:
  14287. description: |-
  14288. APIVersion defines the versioned schema of this representation of an object.
  14289. Servers should convert recognized schemas to the latest internal value, and
  14290. may reject unrecognized values.
  14291. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14292. type: string
  14293. kind:
  14294. description: |-
  14295. Kind is a string value representing the REST resource this object represents.
  14296. Servers may infer this from the endpoint the client submits requests to.
  14297. Cannot be updated.
  14298. In CamelCase.
  14299. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14300. type: string
  14301. metadata:
  14302. type: object
  14303. spec:
  14304. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  14305. properties:
  14306. data:
  14307. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  14308. items:
  14309. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  14310. properties:
  14311. remoteRef:
  14312. description: |-
  14313. RemoteRef points to the remote secret and defines
  14314. which secret (version/property/..) to fetch.
  14315. properties:
  14316. conversionStrategy:
  14317. default: Default
  14318. description: Used to define a conversion Strategy
  14319. enum:
  14320. - Default
  14321. - Unicode
  14322. type: string
  14323. decodingStrategy:
  14324. default: None
  14325. description: Used to define a decoding Strategy
  14326. enum:
  14327. - Auto
  14328. - Base64
  14329. - Base64URL
  14330. - None
  14331. type: string
  14332. key:
  14333. description: Key is the key used in the Provider, mandatory
  14334. type: string
  14335. metadataPolicy:
  14336. default: None
  14337. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14338. enum:
  14339. - None
  14340. - Fetch
  14341. type: string
  14342. property:
  14343. description: Used to select a specific property of the Provider value (if a map), if supported
  14344. type: string
  14345. version:
  14346. description: Used to select a specific version of the Provider value, if supported
  14347. type: string
  14348. required:
  14349. - key
  14350. type: object
  14351. secretKey:
  14352. description: The key in the Kubernetes Secret to store the value.
  14353. maxLength: 253
  14354. minLength: 1
  14355. pattern: ^[-._a-zA-Z0-9]+$
  14356. type: string
  14357. sourceRef:
  14358. description: |-
  14359. SourceRef allows you to override the source
  14360. from which the value will be pulled.
  14361. maxProperties: 1
  14362. minProperties: 1
  14363. properties:
  14364. generatorRef:
  14365. description: |-
  14366. GeneratorRef points to a generator custom resource.
  14367. Deprecated: The generatorRef is not implemented in .data[].
  14368. this will be removed with v1.
  14369. properties:
  14370. apiVersion:
  14371. default: generators.external-secrets.io/v1alpha1
  14372. description: Specify the apiVersion of the generator resource
  14373. type: string
  14374. kind:
  14375. description: Specify the Kind of the generator resource
  14376. enum:
  14377. - ACRAccessToken
  14378. - ClusterGenerator
  14379. - ECRAuthorizationToken
  14380. - Fake
  14381. - GCRAccessToken
  14382. - GithubAccessToken
  14383. - QuayAccessToken
  14384. - Password
  14385. - SSHKey
  14386. - STSSessionToken
  14387. - UUID
  14388. - VaultDynamicSecret
  14389. - Webhook
  14390. - Grafana
  14391. type: string
  14392. name:
  14393. description: Specify the name of the generator resource
  14394. maxLength: 253
  14395. minLength: 1
  14396. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14397. type: string
  14398. required:
  14399. - kind
  14400. - name
  14401. type: object
  14402. storeRef:
  14403. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14404. properties:
  14405. kind:
  14406. description: |-
  14407. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14408. Defaults to `SecretStore`
  14409. enum:
  14410. - SecretStore
  14411. - ClusterSecretStore
  14412. type: string
  14413. name:
  14414. description: Name of the SecretStore resource
  14415. maxLength: 253
  14416. minLength: 1
  14417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14418. type: string
  14419. type: object
  14420. type: object
  14421. required:
  14422. - remoteRef
  14423. - secretKey
  14424. type: object
  14425. type: array
  14426. dataFrom:
  14427. description: |-
  14428. DataFrom is used to fetch all properties from a specific Provider data
  14429. If multiple entries are specified, the Secret keys are merged in the specified order
  14430. items:
  14431. description: ExternalSecretDataFromRemoteRef defines a reference to multiple secrets in the provider to be fetched using options.
  14432. properties:
  14433. extract:
  14434. description: |-
  14435. Used to extract multiple key/value pairs from one secret
  14436. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14437. properties:
  14438. conversionStrategy:
  14439. default: Default
  14440. description: Used to define a conversion Strategy
  14441. enum:
  14442. - Default
  14443. - Unicode
  14444. type: string
  14445. decodingStrategy:
  14446. default: None
  14447. description: Used to define a decoding Strategy
  14448. enum:
  14449. - Auto
  14450. - Base64
  14451. - Base64URL
  14452. - None
  14453. type: string
  14454. key:
  14455. description: Key is the key used in the Provider, mandatory
  14456. type: string
  14457. metadataPolicy:
  14458. default: None
  14459. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  14460. enum:
  14461. - None
  14462. - Fetch
  14463. type: string
  14464. property:
  14465. description: Used to select a specific property of the Provider value (if a map), if supported
  14466. type: string
  14467. version:
  14468. description: Used to select a specific version of the Provider value, if supported
  14469. type: string
  14470. required:
  14471. - key
  14472. type: object
  14473. find:
  14474. description: |-
  14475. Used to find secrets based on tags or regular expressions
  14476. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  14477. properties:
  14478. conversionStrategy:
  14479. default: Default
  14480. description: Used to define a conversion Strategy
  14481. enum:
  14482. - Default
  14483. - Unicode
  14484. type: string
  14485. decodingStrategy:
  14486. default: None
  14487. description: Used to define a decoding Strategy
  14488. enum:
  14489. - Auto
  14490. - Base64
  14491. - Base64URL
  14492. - None
  14493. type: string
  14494. name:
  14495. description: Finds secrets based on the name.
  14496. properties:
  14497. regexp:
  14498. description: Finds secrets base
  14499. type: string
  14500. type: object
  14501. path:
  14502. description: A root path to start the find operations.
  14503. type: string
  14504. tags:
  14505. additionalProperties:
  14506. type: string
  14507. description: Find secrets based on tags.
  14508. type: object
  14509. type: object
  14510. rewrite:
  14511. description: |-
  14512. Used to rewrite secret Keys after getting them from the secret Provider
  14513. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  14514. items:
  14515. description: ExternalSecretRewrite defines rules on how to rewrite secret keys.
  14516. maxProperties: 1
  14517. minProperties: 1
  14518. properties:
  14519. regexp:
  14520. description: |-
  14521. Used to rewrite with regular expressions.
  14522. The resulting key will be the output of a regexp.ReplaceAll operation.
  14523. properties:
  14524. source:
  14525. description: Used to define the regular expression of a re.Compiler.
  14526. type: string
  14527. target:
  14528. description: Used to define the target pattern of a ReplaceAll operation.
  14529. type: string
  14530. required:
  14531. - source
  14532. - target
  14533. type: object
  14534. transform:
  14535. description: |-
  14536. Used to apply string transformation on the secrets.
  14537. The resulting key will be the output of the template applied by the operation.
  14538. properties:
  14539. template:
  14540. description: |-
  14541. Used to define the template to apply on the secret name.
  14542. `.value ` will specify the secret name in the template.
  14543. type: string
  14544. required:
  14545. - template
  14546. type: object
  14547. type: object
  14548. type: array
  14549. sourceRef:
  14550. description: |-
  14551. SourceRef points to a store or generator
  14552. which contains secret values ready to use.
  14553. Use this in combination with Extract or Find pull values out of
  14554. a specific SecretStore.
  14555. When sourceRef points to a generator Extract or Find is not supported.
  14556. The generator returns a static map of values
  14557. maxProperties: 1
  14558. minProperties: 1
  14559. properties:
  14560. generatorRef:
  14561. description: GeneratorRef points to a generator custom resource.
  14562. properties:
  14563. apiVersion:
  14564. default: generators.external-secrets.io/v1alpha1
  14565. description: Specify the apiVersion of the generator resource
  14566. type: string
  14567. kind:
  14568. description: Specify the Kind of the generator resource
  14569. enum:
  14570. - ACRAccessToken
  14571. - ClusterGenerator
  14572. - ECRAuthorizationToken
  14573. - Fake
  14574. - GCRAccessToken
  14575. - GithubAccessToken
  14576. - QuayAccessToken
  14577. - Password
  14578. - SSHKey
  14579. - STSSessionToken
  14580. - UUID
  14581. - VaultDynamicSecret
  14582. - Webhook
  14583. - Grafana
  14584. type: string
  14585. name:
  14586. description: Specify the name of the generator resource
  14587. maxLength: 253
  14588. minLength: 1
  14589. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14590. type: string
  14591. required:
  14592. - kind
  14593. - name
  14594. type: object
  14595. storeRef:
  14596. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14597. properties:
  14598. kind:
  14599. description: |-
  14600. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14601. Defaults to `SecretStore`
  14602. enum:
  14603. - SecretStore
  14604. - ClusterSecretStore
  14605. type: string
  14606. name:
  14607. description: Name of the SecretStore resource
  14608. maxLength: 253
  14609. minLength: 1
  14610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14611. type: string
  14612. type: object
  14613. type: object
  14614. type: object
  14615. type: array
  14616. refreshInterval:
  14617. default: 1h0m0s
  14618. description: |-
  14619. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  14620. specified as Golang Duration strings.
  14621. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  14622. Example values: "1h0m0s", "2h30m0s", "10m0s"
  14623. May be set to "0s" to fetch and create it once. Defaults to 1h0m0s.
  14624. type: string
  14625. refreshPolicy:
  14626. description: |-
  14627. RefreshPolicy determines how the ExternalSecret should be refreshed:
  14628. - CreatedOnce: Creates the Secret only if it does not exist and does not update it thereafter
  14629. - Periodic: Synchronizes the Secret from the external source at regular intervals specified by refreshInterval.
  14630. No periodic updates occur if refreshInterval is 0.
  14631. - OnChange: Only synchronizes the Secret when the ExternalSecret's metadata or specification changes
  14632. enum:
  14633. - CreatedOnce
  14634. - Periodic
  14635. - OnChange
  14636. type: string
  14637. secretStoreRef:
  14638. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  14639. properties:
  14640. kind:
  14641. description: |-
  14642. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  14643. Defaults to `SecretStore`
  14644. enum:
  14645. - SecretStore
  14646. - ClusterSecretStore
  14647. type: string
  14648. name:
  14649. description: Name of the SecretStore resource
  14650. maxLength: 253
  14651. minLength: 1
  14652. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14653. type: string
  14654. type: object
  14655. target:
  14656. default:
  14657. creationPolicy: Owner
  14658. deletionPolicy: Retain
  14659. description: |-
  14660. ExternalSecretTarget defines the Kubernetes Secret to be created
  14661. There can be only one target per ExternalSecret.
  14662. properties:
  14663. creationPolicy:
  14664. default: Owner
  14665. description: |-
  14666. CreationPolicy defines rules on how to create the resulting Secret.
  14667. Defaults to "Owner"
  14668. enum:
  14669. - Owner
  14670. - Orphan
  14671. - Merge
  14672. - None
  14673. type: string
  14674. deletionPolicy:
  14675. default: Retain
  14676. description: |-
  14677. DeletionPolicy defines rules on how to delete the resulting Secret.
  14678. Defaults to "Retain"
  14679. enum:
  14680. - Delete
  14681. - Merge
  14682. - Retain
  14683. type: string
  14684. immutable:
  14685. description: Immutable defines if the final secret will be immutable
  14686. type: boolean
  14687. name:
  14688. description: |-
  14689. The name of the Secret resource to be managed.
  14690. Defaults to the .metadata.name of the ExternalSecret resource
  14691. maxLength: 253
  14692. minLength: 1
  14693. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14694. type: string
  14695. template:
  14696. description: Template defines a blueprint for the created Secret resource.
  14697. properties:
  14698. data:
  14699. additionalProperties:
  14700. type: string
  14701. type: object
  14702. engineVersion:
  14703. default: v2
  14704. description: |-
  14705. EngineVersion specifies the template engine version
  14706. that should be used to compile/execute the
  14707. template specified in .data and .templateFrom[].
  14708. enum:
  14709. - v2
  14710. type: string
  14711. mergePolicy:
  14712. default: Replace
  14713. description: TemplateMergePolicy defines how template values should be merged when generating a secret.
  14714. enum:
  14715. - Replace
  14716. - Merge
  14717. type: string
  14718. metadata:
  14719. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  14720. properties:
  14721. annotations:
  14722. additionalProperties:
  14723. type: string
  14724. type: object
  14725. labels:
  14726. additionalProperties:
  14727. type: string
  14728. type: object
  14729. type: object
  14730. templateFrom:
  14731. items:
  14732. description: TemplateFrom defines a source for template data.
  14733. properties:
  14734. configMap:
  14735. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14736. properties:
  14737. items:
  14738. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14739. items:
  14740. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14741. properties:
  14742. key:
  14743. description: A key in the ConfigMap/Secret
  14744. maxLength: 253
  14745. minLength: 1
  14746. pattern: ^[-._a-zA-Z0-9]+$
  14747. type: string
  14748. templateAs:
  14749. default: Values
  14750. description: TemplateScope defines the scope of the template when processing template data.
  14751. enum:
  14752. - Values
  14753. - KeysAndValues
  14754. type: string
  14755. required:
  14756. - key
  14757. type: object
  14758. type: array
  14759. name:
  14760. description: The name of the ConfigMap/Secret resource
  14761. maxLength: 253
  14762. minLength: 1
  14763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14764. type: string
  14765. required:
  14766. - items
  14767. - name
  14768. type: object
  14769. literal:
  14770. type: string
  14771. secret:
  14772. description: TemplateRef defines a reference to a template source in a ConfigMap or Secret.
  14773. properties:
  14774. items:
  14775. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  14776. items:
  14777. description: TemplateRefItem defines which key in the referenced ConfigMap or Secret to use as a template.
  14778. properties:
  14779. key:
  14780. description: A key in the ConfigMap/Secret
  14781. maxLength: 253
  14782. minLength: 1
  14783. pattern: ^[-._a-zA-Z0-9]+$
  14784. type: string
  14785. templateAs:
  14786. default: Values
  14787. description: TemplateScope defines the scope of the template when processing template data.
  14788. enum:
  14789. - Values
  14790. - KeysAndValues
  14791. type: string
  14792. required:
  14793. - key
  14794. type: object
  14795. type: array
  14796. name:
  14797. description: The name of the ConfigMap/Secret resource
  14798. maxLength: 253
  14799. minLength: 1
  14800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14801. type: string
  14802. required:
  14803. - items
  14804. - name
  14805. type: object
  14806. target:
  14807. default: Data
  14808. description: TemplateTarget defines the target field where the template result will be stored.
  14809. enum:
  14810. - Data
  14811. - Annotations
  14812. - Labels
  14813. type: string
  14814. type: object
  14815. type: array
  14816. type:
  14817. type: string
  14818. type: object
  14819. type: object
  14820. type: object
  14821. status:
  14822. description: ExternalSecretStatus defines the observed state of ExternalSecret.
  14823. properties:
  14824. binding:
  14825. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  14826. properties:
  14827. name:
  14828. default: ""
  14829. description: |-
  14830. Name of the referent.
  14831. This field is effectively required, but due to backwards compatibility is
  14832. allowed to be empty. Instances of this type with an empty value here are
  14833. almost certainly wrong.
  14834. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  14835. type: string
  14836. type: object
  14837. x-kubernetes-map-type: atomic
  14838. conditions:
  14839. items:
  14840. description: ExternalSecretStatusCondition contains condition information for an ExternalSecret.
  14841. properties:
  14842. lastTransitionTime:
  14843. format: date-time
  14844. type: string
  14845. message:
  14846. type: string
  14847. reason:
  14848. type: string
  14849. status:
  14850. type: string
  14851. type:
  14852. description: ExternalSecretConditionType defines the condition type for an ExternalSecret.
  14853. type: string
  14854. required:
  14855. - status
  14856. - type
  14857. type: object
  14858. type: array
  14859. refreshTime:
  14860. description: |-
  14861. refreshTime is the time and date the external secret was fetched and
  14862. the target secret updated
  14863. format: date-time
  14864. nullable: true
  14865. type: string
  14866. syncedResourceVersion:
  14867. description: SyncedResourceVersion keeps track of the last synced version
  14868. type: string
  14869. type: object
  14870. type: object
  14871. served: false
  14872. storage: false
  14873. subresources:
  14874. status: {}
  14875. ---
  14876. apiVersion: apiextensions.k8s.io/v1
  14877. kind: CustomResourceDefinition
  14878. metadata:
  14879. annotations:
  14880. controller-gen.kubebuilder.io/version: v0.19.0
  14881. labels:
  14882. external-secrets.io/component: controller
  14883. name: pushsecrets.external-secrets.io
  14884. spec:
  14885. group: external-secrets.io
  14886. names:
  14887. categories:
  14888. - external-secrets
  14889. kind: PushSecret
  14890. listKind: PushSecretList
  14891. plural: pushsecrets
  14892. shortNames:
  14893. - ps
  14894. singular: pushsecret
  14895. scope: Namespaced
  14896. versions:
  14897. - additionalPrinterColumns:
  14898. - jsonPath: .metadata.creationTimestamp
  14899. name: AGE
  14900. type: date
  14901. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  14902. name: Status
  14903. type: string
  14904. - jsonPath: .status.refreshTime
  14905. name: Last Sync
  14906. type: date
  14907. name: v1alpha1
  14908. schema:
  14909. openAPIV3Schema:
  14910. description: PushSecret is the Schema for the PushSecrets API that enables pushing Kubernetes secrets to external secret providers.
  14911. properties:
  14912. apiVersion:
  14913. description: |-
  14914. APIVersion defines the versioned schema of this representation of an object.
  14915. Servers should convert recognized schemas to the latest internal value, and
  14916. may reject unrecognized values.
  14917. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  14918. type: string
  14919. kind:
  14920. description: |-
  14921. Kind is a string value representing the REST resource this object represents.
  14922. Servers may infer this from the endpoint the client submits requests to.
  14923. Cannot be updated.
  14924. In CamelCase.
  14925. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  14926. type: string
  14927. metadata:
  14928. type: object
  14929. spec:
  14930. description: PushSecretSpec configures the behavior of the PushSecret.
  14931. properties:
  14932. data:
  14933. description: Secret Data that should be pushed to providers
  14934. items:
  14935. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  14936. properties:
  14937. conversionStrategy:
  14938. default: None
  14939. description: Used to define a conversion Strategy for the secret keys
  14940. enum:
  14941. - None
  14942. - ReverseUnicode
  14943. type: string
  14944. match:
  14945. description: Match a given Secret Key to be pushed to the provider.
  14946. properties:
  14947. remoteRef:
  14948. description: Remote Refs to push to providers.
  14949. properties:
  14950. property:
  14951. description: Name of the property in the resulting secret
  14952. type: string
  14953. remoteKey:
  14954. description: Name of the resulting provider secret.
  14955. type: string
  14956. required:
  14957. - remoteKey
  14958. type: object
  14959. secretKey:
  14960. description: Secret Key to be pushed
  14961. type: string
  14962. required:
  14963. - remoteRef
  14964. type: object
  14965. metadata:
  14966. description: |-
  14967. Metadata is metadata attached to the secret.
  14968. The structure of metadata is provider specific, please look it up in the provider documentation.
  14969. x-kubernetes-preserve-unknown-fields: true
  14970. required:
  14971. - match
  14972. type: object
  14973. type: array
  14974. dataTo:
  14975. description: DataTo defines bulk push rules that expand source Secret keys into provider entries.
  14976. items:
  14977. description: PushSecretDataTo defines how to bulk-push secrets to providers without explicit per-key mappings.
  14978. properties:
  14979. conversionStrategy:
  14980. default: None
  14981. description: Used to define a conversion Strategy for the secret keys
  14982. enum:
  14983. - None
  14984. - ReverseUnicode
  14985. type: string
  14986. match:
  14987. description: |-
  14988. Match pattern for selecting keys from the source Secret.
  14989. If not specified, all keys are selected.
  14990. properties:
  14991. regexp:
  14992. description: |-
  14993. Regexp matches keys by regular expression.
  14994. If not specified, all keys are matched.
  14995. type: string
  14996. type: object
  14997. metadata:
  14998. description: |-
  14999. Metadata is metadata attached to the secret.
  15000. The structure of metadata is provider specific, please look it up in the provider documentation.
  15001. x-kubernetes-preserve-unknown-fields: true
  15002. remoteKey:
  15003. description: |-
  15004. RemoteKey is the name of the single provider secret that will receive ALL
  15005. matched keys bundled as a JSON object (e.g. {"DB_HOST":"...","DB_USER":"..."}).
  15006. When set, per-key expansion is skipped and a single push is performed.
  15007. The provider's store prefix (if any) is still prepended to this value.
  15008. When not set, each matched key is pushed as its own individual provider secret.
  15009. type: string
  15010. rewrite:
  15011. description: |-
  15012. Rewrite operations to transform keys before pushing to the provider.
  15013. Operations are applied sequentially.
  15014. items:
  15015. description: PushSecretRewrite defines how to transform secret keys before pushing.
  15016. properties:
  15017. regexp:
  15018. description: Used to rewrite with regular expressions.
  15019. properties:
  15020. source:
  15021. description: Used to define the regular expression of a re.Compiler.
  15022. type: string
  15023. target:
  15024. description: Used to define the target pattern of a ReplaceAll operation.
  15025. type: string
  15026. required:
  15027. - source
  15028. - target
  15029. type: object
  15030. transform:
  15031. description: Used to apply string transformation on the secrets.
  15032. properties:
  15033. template:
  15034. description: |-
  15035. Used to define the template to apply on the secret name.
  15036. `.value ` will specify the secret name in the template.
  15037. type: string
  15038. required:
  15039. - template
  15040. type: object
  15041. type: object
  15042. x-kubernetes-validations:
  15043. - message: exactly one of regexp or transform must be set
  15044. rule: (has(self.regexp) && !has(self.transform)) || (!has(self.regexp) && has(self.transform))
  15045. type: array
  15046. storeRef:
  15047. description: StoreRef specifies which SecretStore to push to. Required.
  15048. properties:
  15049. kind:
  15050. default: SecretStore
  15051. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15052. enum:
  15053. - SecretStore
  15054. - ClusterSecretStore
  15055. type: string
  15056. labelSelector:
  15057. description: Optionally, sync to secret stores with label selector
  15058. properties:
  15059. matchExpressions:
  15060. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15061. items:
  15062. description: |-
  15063. A label selector requirement is a selector that contains values, a key, and an operator that
  15064. relates the key and values.
  15065. properties:
  15066. key:
  15067. description: key is the label key that the selector applies to.
  15068. type: string
  15069. operator:
  15070. description: |-
  15071. operator represents a key's relationship to a set of values.
  15072. Valid operators are In, NotIn, Exists and DoesNotExist.
  15073. type: string
  15074. values:
  15075. description: |-
  15076. values is an array of string values. If the operator is In or NotIn,
  15077. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15078. the values array must be empty. This array is replaced during a strategic
  15079. merge patch.
  15080. items:
  15081. type: string
  15082. type: array
  15083. x-kubernetes-list-type: atomic
  15084. required:
  15085. - key
  15086. - operator
  15087. type: object
  15088. type: array
  15089. x-kubernetes-list-type: atomic
  15090. matchLabels:
  15091. additionalProperties:
  15092. type: string
  15093. description: |-
  15094. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15095. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15096. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15097. type: object
  15098. type: object
  15099. x-kubernetes-map-type: atomic
  15100. name:
  15101. description: Optionally, sync to the SecretStore of the given name
  15102. maxLength: 253
  15103. minLength: 1
  15104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15105. type: string
  15106. type: object
  15107. type: object
  15108. x-kubernetes-validations:
  15109. - message: storeRef must specify either name or labelSelector
  15110. rule: has(self.storeRef) && (has(self.storeRef.name) || has(self.storeRef.labelSelector))
  15111. - message: 'remoteKey and rewrite are mutually exclusive: rewrite is only supported in per-key mode (without remoteKey)'
  15112. rule: '!has(self.remoteKey) || !has(self.rewrite) || size(self.rewrite) == 0'
  15113. type: array
  15114. deletionPolicy:
  15115. default: None
  15116. description: Deletion Policy to handle Secrets in the provider.
  15117. enum:
  15118. - Delete
  15119. - None
  15120. type: string
  15121. refreshInterval:
  15122. default: 1h0m0s
  15123. description: The Interval to which External Secrets will try to push a secret definition
  15124. type: string
  15125. secretStoreRefs:
  15126. items:
  15127. description: PushSecretStoreRef contains a reference on how to sync to a SecretStore.
  15128. properties:
  15129. kind:
  15130. default: SecretStore
  15131. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  15132. enum:
  15133. - SecretStore
  15134. - ClusterSecretStore
  15135. type: string
  15136. labelSelector:
  15137. description: Optionally, sync to secret stores with label selector
  15138. properties:
  15139. matchExpressions:
  15140. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15141. items:
  15142. description: |-
  15143. A label selector requirement is a selector that contains values, a key, and an operator that
  15144. relates the key and values.
  15145. properties:
  15146. key:
  15147. description: key is the label key that the selector applies to.
  15148. type: string
  15149. operator:
  15150. description: |-
  15151. operator represents a key's relationship to a set of values.
  15152. Valid operators are In, NotIn, Exists and DoesNotExist.
  15153. type: string
  15154. values:
  15155. description: |-
  15156. values is an array of string values. If the operator is In or NotIn,
  15157. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15158. the values array must be empty. This array is replaced during a strategic
  15159. merge patch.
  15160. items:
  15161. type: string
  15162. type: array
  15163. x-kubernetes-list-type: atomic
  15164. required:
  15165. - key
  15166. - operator
  15167. type: object
  15168. type: array
  15169. x-kubernetes-list-type: atomic
  15170. matchLabels:
  15171. additionalProperties:
  15172. type: string
  15173. description: |-
  15174. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15175. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15176. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15177. type: object
  15178. type: object
  15179. x-kubernetes-map-type: atomic
  15180. name:
  15181. description: Optionally, sync to the SecretStore of the given name
  15182. maxLength: 253
  15183. minLength: 1
  15184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15185. type: string
  15186. type: object
  15187. type: array
  15188. selector:
  15189. description: The Secret Selector (k8s source) for the Push Secret
  15190. maxProperties: 1
  15191. minProperties: 1
  15192. properties:
  15193. generatorRef:
  15194. description: Point to a generator to create a Secret.
  15195. properties:
  15196. apiVersion:
  15197. default: generators.external-secrets.io/v1alpha1
  15198. description: Specify the apiVersion of the generator resource
  15199. type: string
  15200. kind:
  15201. description: Specify the Kind of the generator resource
  15202. enum:
  15203. - ACRAccessToken
  15204. - BeyondtrustWorkloadCredentialsDynamicSecret
  15205. - ClusterGenerator
  15206. - CloudsmithAccessToken
  15207. - ECRAuthorizationToken
  15208. - Fake
  15209. - GCRAccessToken
  15210. - GithubAccessToken
  15211. - GitlabDeployToken
  15212. - QuayAccessToken
  15213. - Password
  15214. - SSHKey
  15215. - STSSessionToken
  15216. - UUID
  15217. - VaultDynamicSecret
  15218. - Webhook
  15219. - Grafana
  15220. - MFA
  15221. type: string
  15222. name:
  15223. description: Specify the name of the generator resource
  15224. maxLength: 253
  15225. minLength: 1
  15226. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15227. type: string
  15228. required:
  15229. - kind
  15230. - name
  15231. type: object
  15232. secret:
  15233. description: Select a Secret to Push.
  15234. properties:
  15235. name:
  15236. description: |-
  15237. Name of the Secret.
  15238. The Secret must exist in the same namespace as the PushSecret manifest.
  15239. maxLength: 253
  15240. minLength: 1
  15241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15242. type: string
  15243. selector:
  15244. description: Selector chooses secrets using a labelSelector.
  15245. properties:
  15246. matchExpressions:
  15247. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15248. items:
  15249. description: |-
  15250. A label selector requirement is a selector that contains values, a key, and an operator that
  15251. relates the key and values.
  15252. properties:
  15253. key:
  15254. description: key is the label key that the selector applies to.
  15255. type: string
  15256. operator:
  15257. description: |-
  15258. operator represents a key's relationship to a set of values.
  15259. Valid operators are In, NotIn, Exists and DoesNotExist.
  15260. type: string
  15261. values:
  15262. description: |-
  15263. values is an array of string values. If the operator is In or NotIn,
  15264. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15265. the values array must be empty. This array is replaced during a strategic
  15266. merge patch.
  15267. items:
  15268. type: string
  15269. type: array
  15270. x-kubernetes-list-type: atomic
  15271. required:
  15272. - key
  15273. - operator
  15274. type: object
  15275. type: array
  15276. x-kubernetes-list-type: atomic
  15277. matchLabels:
  15278. additionalProperties:
  15279. type: string
  15280. description: |-
  15281. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15282. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15283. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15284. type: object
  15285. type: object
  15286. x-kubernetes-map-type: atomic
  15287. type: object
  15288. type: object
  15289. template:
  15290. description: Template defines a blueprint for the created Secret resource.
  15291. properties:
  15292. data:
  15293. additionalProperties:
  15294. type: string
  15295. type: object
  15296. engineVersion:
  15297. default: v2
  15298. description: |-
  15299. EngineVersion specifies the template engine version
  15300. that should be used to compile/execute the
  15301. template specified in .data and .templateFrom[].
  15302. enum:
  15303. - v2
  15304. type: string
  15305. mergePolicy:
  15306. default: Replace
  15307. description: TemplateMergePolicy defines how the rendered template should be merged with the existing Secret data.
  15308. enum:
  15309. - Replace
  15310. - Merge
  15311. type: string
  15312. metadata:
  15313. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  15314. properties:
  15315. annotations:
  15316. additionalProperties:
  15317. type: string
  15318. type: object
  15319. finalizers:
  15320. items:
  15321. type: string
  15322. type: array
  15323. labels:
  15324. additionalProperties:
  15325. type: string
  15326. type: object
  15327. type: object
  15328. templateFrom:
  15329. items:
  15330. description: |-
  15331. TemplateFrom specifies a source for templates.
  15332. Each item in the list can either reference a ConfigMap or a Secret resource.
  15333. properties:
  15334. configMap:
  15335. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15336. properties:
  15337. items:
  15338. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15339. items:
  15340. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15341. properties:
  15342. key:
  15343. description: A key in the ConfigMap/Secret
  15344. maxLength: 253
  15345. minLength: 1
  15346. pattern: ^[-._a-zA-Z0-9]+$
  15347. type: string
  15348. templateAs:
  15349. default: Values
  15350. description: TemplateScope specifies how the template keys should be interpreted.
  15351. enum:
  15352. - Values
  15353. - KeysAndValues
  15354. type: string
  15355. required:
  15356. - key
  15357. type: object
  15358. type: array
  15359. name:
  15360. description: The name of the ConfigMap/Secret resource
  15361. maxLength: 253
  15362. minLength: 1
  15363. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15364. type: string
  15365. required:
  15366. - items
  15367. - name
  15368. type: object
  15369. literal:
  15370. type: string
  15371. secret:
  15372. description: TemplateRef specifies a reference to either a ConfigMap or a Secret resource.
  15373. properties:
  15374. items:
  15375. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  15376. items:
  15377. description: TemplateRefItem specifies a key in the ConfigMap/Secret to use as a template for Secret data.
  15378. properties:
  15379. key:
  15380. description: A key in the ConfigMap/Secret
  15381. maxLength: 253
  15382. minLength: 1
  15383. pattern: ^[-._a-zA-Z0-9]+$
  15384. type: string
  15385. templateAs:
  15386. default: Values
  15387. description: TemplateScope specifies how the template keys should be interpreted.
  15388. enum:
  15389. - Values
  15390. - KeysAndValues
  15391. type: string
  15392. required:
  15393. - key
  15394. type: object
  15395. type: array
  15396. name:
  15397. description: The name of the ConfigMap/Secret resource
  15398. maxLength: 253
  15399. minLength: 1
  15400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15401. type: string
  15402. required:
  15403. - items
  15404. - name
  15405. type: object
  15406. target:
  15407. default: Data
  15408. description: |-
  15409. Target specifies where to place the template result.
  15410. For Secret resources the accepted values are empty, "Data", "Annotations" and "Labels";
  15411. any other value is rejected because it would allow writes to privileged Secret fields.
  15412. For custom resources (when spec.target.manifest is set), this supports
  15413. nested paths like "spec.database.config" or "data".
  15414. type: string
  15415. valuesDecodingStrategy:
  15416. default: None
  15417. description: Used to define a decoding Strategy for the rendered template values.
  15418. enum:
  15419. - Auto
  15420. - Base64
  15421. - Base64URL
  15422. - None
  15423. type: string
  15424. type: object
  15425. type: array
  15426. type:
  15427. type: string
  15428. type: object
  15429. updatePolicy:
  15430. default: Replace
  15431. description: UpdatePolicy to handle Secrets in the provider.
  15432. enum:
  15433. - Replace
  15434. - IfNotExists
  15435. type: string
  15436. required:
  15437. - secretStoreRefs
  15438. - selector
  15439. type: object
  15440. status:
  15441. description: PushSecretStatus indicates the history of the status of PushSecret.
  15442. properties:
  15443. conditions:
  15444. items:
  15445. description: PushSecretStatusCondition indicates the status of the PushSecret.
  15446. properties:
  15447. lastTransitionTime:
  15448. format: date-time
  15449. type: string
  15450. message:
  15451. type: string
  15452. reason:
  15453. type: string
  15454. status:
  15455. type: string
  15456. type:
  15457. description: PushSecretConditionType indicates the condition of the PushSecret.
  15458. type: string
  15459. required:
  15460. - status
  15461. - type
  15462. type: object
  15463. type: array
  15464. refreshTime:
  15465. description: |-
  15466. refreshTime is the time and date the external secret was fetched and
  15467. the target secret updated
  15468. format: date-time
  15469. nullable: true
  15470. type: string
  15471. syncedPushSecrets:
  15472. additionalProperties:
  15473. additionalProperties:
  15474. description: PushSecretData defines data to be pushed to the provider and associated metadata.
  15475. properties:
  15476. conversionStrategy:
  15477. default: None
  15478. description: Used to define a conversion Strategy for the secret keys
  15479. enum:
  15480. - None
  15481. - ReverseUnicode
  15482. type: string
  15483. match:
  15484. description: Match a given Secret Key to be pushed to the provider.
  15485. properties:
  15486. remoteRef:
  15487. description: Remote Refs to push to providers.
  15488. properties:
  15489. property:
  15490. description: Name of the property in the resulting secret
  15491. type: string
  15492. remoteKey:
  15493. description: Name of the resulting provider secret.
  15494. type: string
  15495. required:
  15496. - remoteKey
  15497. type: object
  15498. secretKey:
  15499. description: Secret Key to be pushed
  15500. type: string
  15501. required:
  15502. - remoteRef
  15503. type: object
  15504. metadata:
  15505. description: |-
  15506. Metadata is metadata attached to the secret.
  15507. The structure of metadata is provider specific, please look it up in the provider documentation.
  15508. x-kubernetes-preserve-unknown-fields: true
  15509. required:
  15510. - match
  15511. type: object
  15512. type: object
  15513. description: |-
  15514. Synced PushSecrets, including secrets that already exist in provider.
  15515. Matches secret stores to PushSecretData that was stored to that secret store.
  15516. type: object
  15517. syncedResourceVersion:
  15518. description: SyncedResourceVersion keeps track of the last synced version.
  15519. type: string
  15520. type: object
  15521. type: object
  15522. served: true
  15523. storage: true
  15524. subresources:
  15525. status: {}
  15526. ---
  15527. apiVersion: apiextensions.k8s.io/v1
  15528. kind: CustomResourceDefinition
  15529. metadata:
  15530. annotations:
  15531. controller-gen.kubebuilder.io/version: v0.19.0
  15532. labels:
  15533. external-secrets.io/component: controller
  15534. name: secretstores.external-secrets.io
  15535. spec:
  15536. group: external-secrets.io
  15537. names:
  15538. categories:
  15539. - external-secrets
  15540. kind: SecretStore
  15541. listKind: SecretStoreList
  15542. plural: secretstores
  15543. shortNames:
  15544. - ss
  15545. singular: secretstore
  15546. scope: Namespaced
  15547. versions:
  15548. - additionalPrinterColumns:
  15549. - jsonPath: .metadata.creationTimestamp
  15550. name: AGE
  15551. type: date
  15552. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  15553. name: Status
  15554. type: string
  15555. - jsonPath: .status.capabilities
  15556. name: Capabilities
  15557. type: string
  15558. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  15559. name: Ready
  15560. type: string
  15561. name: v1
  15562. schema:
  15563. openAPIV3Schema:
  15564. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  15565. properties:
  15566. apiVersion:
  15567. description: |-
  15568. APIVersion defines the versioned schema of this representation of an object.
  15569. Servers should convert recognized schemas to the latest internal value, and
  15570. may reject unrecognized values.
  15571. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15572. type: string
  15573. kind:
  15574. description: |-
  15575. Kind is a string value representing the REST resource this object represents.
  15576. Servers may infer this from the endpoint the client submits requests to.
  15577. Cannot be updated.
  15578. In CamelCase.
  15579. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15580. type: string
  15581. metadata:
  15582. type: object
  15583. spec:
  15584. description: SecretStoreSpec defines the desired state of SecretStore.
  15585. properties:
  15586. conditions:
  15587. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  15588. items:
  15589. description: |-
  15590. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  15591. for a ClusterSecretStore instance.
  15592. properties:
  15593. namespaceRegexes:
  15594. description: Choose namespaces by using regex matching
  15595. items:
  15596. type: string
  15597. type: array
  15598. namespaceSelector:
  15599. description: Choose namespace using a labelSelector
  15600. properties:
  15601. matchExpressions:
  15602. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  15603. items:
  15604. description: |-
  15605. A label selector requirement is a selector that contains values, a key, and an operator that
  15606. relates the key and values.
  15607. properties:
  15608. key:
  15609. description: key is the label key that the selector applies to.
  15610. type: string
  15611. operator:
  15612. description: |-
  15613. operator represents a key's relationship to a set of values.
  15614. Valid operators are In, NotIn, Exists and DoesNotExist.
  15615. type: string
  15616. values:
  15617. description: |-
  15618. values is an array of string values. If the operator is In or NotIn,
  15619. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  15620. the values array must be empty. This array is replaced during a strategic
  15621. merge patch.
  15622. items:
  15623. type: string
  15624. type: array
  15625. x-kubernetes-list-type: atomic
  15626. required:
  15627. - key
  15628. - operator
  15629. type: object
  15630. type: array
  15631. x-kubernetes-list-type: atomic
  15632. matchLabels:
  15633. additionalProperties:
  15634. type: string
  15635. description: |-
  15636. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  15637. map is equivalent to an element of matchExpressions, whose key field is "key", the
  15638. operator is "In", and the values array contains only "value". The requirements are ANDed.
  15639. type: object
  15640. type: object
  15641. x-kubernetes-map-type: atomic
  15642. namespaces:
  15643. description: Choose namespaces by name
  15644. items:
  15645. maxLength: 63
  15646. minLength: 1
  15647. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15648. type: string
  15649. type: array
  15650. type: object
  15651. type: array
  15652. controller:
  15653. description: |-
  15654. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15655. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  15656. type: string
  15657. provider:
  15658. description: Used to configure the provider. Only one provider may be set
  15659. maxProperties: 1
  15660. minProperties: 1
  15661. properties:
  15662. akeyless:
  15663. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  15664. properties:
  15665. akeylessGWApiURL:
  15666. description: Akeyless GW API Url from which the secrets to be fetched from.
  15667. type: string
  15668. authSecretRef:
  15669. description: Auth configures how the operator authenticates with Akeyless.
  15670. properties:
  15671. kubernetesAuth:
  15672. description: |-
  15673. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  15674. token stored in the named Secret resource.
  15675. properties:
  15676. accessID:
  15677. description: the Akeyless Kubernetes auth-method access-id
  15678. type: string
  15679. k8sConfName:
  15680. description: Kubernetes-auth configuration name in Akeyless-Gateway
  15681. type: string
  15682. secretRef:
  15683. description: |-
  15684. Optional secret field containing a Kubernetes ServiceAccount JWT used
  15685. for authenticating with Akeyless. If a name is specified without a key,
  15686. `token` is the default. If one is not specified, the one bound to
  15687. the controller will be used.
  15688. properties:
  15689. key:
  15690. description: |-
  15691. A key in the referenced Secret.
  15692. Some instances of this field may be defaulted, in others it may be required.
  15693. maxLength: 253
  15694. minLength: 1
  15695. pattern: ^[-._a-zA-Z0-9]+$
  15696. type: string
  15697. name:
  15698. description: The name of the Secret resource being referred to.
  15699. maxLength: 253
  15700. minLength: 1
  15701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15702. type: string
  15703. namespace:
  15704. description: |-
  15705. The namespace of the Secret resource being referred to.
  15706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15707. maxLength: 63
  15708. minLength: 1
  15709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15710. type: string
  15711. type: object
  15712. serviceAccountRef:
  15713. description: |-
  15714. Optional service account field containing the name of a kubernetes ServiceAccount.
  15715. If the service account is specified, the service account secret token JWT will be used
  15716. for authenticating with Akeyless. If the service account selector is not supplied,
  15717. the secretRef will be used instead.
  15718. properties:
  15719. audiences:
  15720. description: |-
  15721. Audience specifies the `aud` claim for the service account token
  15722. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15723. then this audiences will be appended to the list
  15724. items:
  15725. type: string
  15726. type: array
  15727. name:
  15728. description: The name of the ServiceAccount resource being referred to.
  15729. maxLength: 253
  15730. minLength: 1
  15731. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15732. type: string
  15733. namespace:
  15734. description: |-
  15735. Namespace of the resource being referred to.
  15736. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15737. maxLength: 63
  15738. minLength: 1
  15739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15740. type: string
  15741. required:
  15742. - name
  15743. type: object
  15744. required:
  15745. - accessID
  15746. - k8sConfName
  15747. type: object
  15748. secretRef:
  15749. description: |-
  15750. Reference to a Secret that contains the details
  15751. to authenticate with Akeyless.
  15752. properties:
  15753. accessID:
  15754. description: The SecretAccessID is used for authentication
  15755. properties:
  15756. key:
  15757. description: |-
  15758. A key in the referenced Secret.
  15759. Some instances of this field may be defaulted, in others it may be required.
  15760. maxLength: 253
  15761. minLength: 1
  15762. pattern: ^[-._a-zA-Z0-9]+$
  15763. type: string
  15764. name:
  15765. description: The name of the Secret resource being referred to.
  15766. maxLength: 253
  15767. minLength: 1
  15768. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15769. type: string
  15770. namespace:
  15771. description: |-
  15772. The namespace of the Secret resource being referred to.
  15773. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15774. maxLength: 63
  15775. minLength: 1
  15776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15777. type: string
  15778. type: object
  15779. accessType:
  15780. description: |-
  15781. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15782. In some instances, `key` is a required field.
  15783. properties:
  15784. key:
  15785. description: |-
  15786. A key in the referenced Secret.
  15787. Some instances of this field may be defaulted, in others it may be required.
  15788. maxLength: 253
  15789. minLength: 1
  15790. pattern: ^[-._a-zA-Z0-9]+$
  15791. type: string
  15792. name:
  15793. description: The name of the Secret resource being referred to.
  15794. maxLength: 253
  15795. minLength: 1
  15796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15797. type: string
  15798. namespace:
  15799. description: |-
  15800. The namespace of the Secret resource being referred to.
  15801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15802. maxLength: 63
  15803. minLength: 1
  15804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15805. type: string
  15806. type: object
  15807. accessTypeParam:
  15808. description: |-
  15809. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  15810. In some instances, `key` is a required field.
  15811. properties:
  15812. key:
  15813. description: |-
  15814. A key in the referenced Secret.
  15815. Some instances of this field may be defaulted, in others it may be required.
  15816. maxLength: 253
  15817. minLength: 1
  15818. pattern: ^[-._a-zA-Z0-9]+$
  15819. type: string
  15820. name:
  15821. description: The name of the Secret resource being referred to.
  15822. maxLength: 253
  15823. minLength: 1
  15824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15825. type: string
  15826. namespace:
  15827. description: |-
  15828. The namespace of the Secret resource being referred to.
  15829. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15830. maxLength: 63
  15831. minLength: 1
  15832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15833. type: string
  15834. type: object
  15835. type: object
  15836. serviceAccountRef:
  15837. description: |-
  15838. ServiceAccountRef specifies a Kubernetes ServiceAccount used for azure_ad
  15839. authentication on AKS Workload Identity. The operator obtains a federated
  15840. identity token from this ServiceAccount via the TokenRequest API instead
  15841. of using the ESO controller pod identity. Ignored for other access types.
  15842. properties:
  15843. audiences:
  15844. description: |-
  15845. Audience specifies the `aud` claim for the service account token
  15846. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15847. then this audiences will be appended to the list
  15848. items:
  15849. type: string
  15850. type: array
  15851. name:
  15852. description: The name of the ServiceAccount resource being referred to.
  15853. maxLength: 253
  15854. minLength: 1
  15855. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15856. type: string
  15857. namespace:
  15858. description: |-
  15859. Namespace of the resource being referred to.
  15860. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15861. maxLength: 63
  15862. minLength: 1
  15863. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15864. type: string
  15865. required:
  15866. - name
  15867. type: object
  15868. type: object
  15869. caBundle:
  15870. description: |-
  15871. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  15872. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  15873. are used to validate the TLS connection.
  15874. format: byte
  15875. type: string
  15876. caProvider:
  15877. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  15878. properties:
  15879. key:
  15880. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15881. maxLength: 253
  15882. minLength: 1
  15883. pattern: ^[-._a-zA-Z0-9]+$
  15884. type: string
  15885. name:
  15886. description: The name of the object located at the provider type.
  15887. maxLength: 253
  15888. minLength: 1
  15889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15890. type: string
  15891. namespace:
  15892. description: |-
  15893. The namespace the Provider type is in.
  15894. Can only be defined when used in a ClusterSecretStore.
  15895. maxLength: 63
  15896. minLength: 1
  15897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15898. type: string
  15899. type:
  15900. description: The type of provider to use such as "Secret", or "ConfigMap".
  15901. enum:
  15902. - Secret
  15903. - ConfigMap
  15904. type: string
  15905. required:
  15906. - name
  15907. - type
  15908. type: object
  15909. ignoreCache:
  15910. description: |-
  15911. IgnoreCache bypasses the Gateway cache for secret reads when true.
  15912. Only relevant when akeylessGWApiURL points to an Akeyless Gateway.
  15913. type: boolean
  15914. required:
  15915. - akeylessGWApiURL
  15916. - authSecretRef
  15917. type: object
  15918. aws:
  15919. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  15920. properties:
  15921. additionalRoles:
  15922. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  15923. items:
  15924. type: string
  15925. type: array
  15926. auth:
  15927. description: |-
  15928. Auth defines the information necessary to authenticate against AWS
  15929. if not set aws sdk will infer credentials from your environment
  15930. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  15931. properties:
  15932. jwt:
  15933. description: AWSJWTAuth stores reference to Authenticate against AWS using service account tokens.
  15934. properties:
  15935. serviceAccountRef:
  15936. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  15937. properties:
  15938. audiences:
  15939. description: |-
  15940. Audience specifies the `aud` claim for the service account token
  15941. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15942. then this audiences will be appended to the list
  15943. items:
  15944. type: string
  15945. type: array
  15946. name:
  15947. description: The name of the ServiceAccount resource being referred to.
  15948. maxLength: 253
  15949. minLength: 1
  15950. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15951. type: string
  15952. namespace:
  15953. description: |-
  15954. Namespace of the resource being referred to.
  15955. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15956. maxLength: 63
  15957. minLength: 1
  15958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15959. type: string
  15960. required:
  15961. - name
  15962. type: object
  15963. type: object
  15964. secretRef:
  15965. description: |-
  15966. AWSAuthSecretRef holds secret references for AWS credentials
  15967. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15968. properties:
  15969. accessKeyIDSecretRef:
  15970. description: The AccessKeyID is used for authentication
  15971. properties:
  15972. key:
  15973. description: |-
  15974. A key in the referenced Secret.
  15975. Some instances of this field may be defaulted, in others it may be required.
  15976. maxLength: 253
  15977. minLength: 1
  15978. pattern: ^[-._a-zA-Z0-9]+$
  15979. type: string
  15980. name:
  15981. description: The name of the Secret resource being referred to.
  15982. maxLength: 253
  15983. minLength: 1
  15984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15985. type: string
  15986. namespace:
  15987. description: |-
  15988. The namespace of the Secret resource being referred to.
  15989. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15990. maxLength: 63
  15991. minLength: 1
  15992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15993. type: string
  15994. type: object
  15995. secretAccessKeySecretRef:
  15996. description: The SecretAccessKey is used for authentication
  15997. properties:
  15998. key:
  15999. description: |-
  16000. A key in the referenced Secret.
  16001. Some instances of this field may be defaulted, in others it may be required.
  16002. maxLength: 253
  16003. minLength: 1
  16004. pattern: ^[-._a-zA-Z0-9]+$
  16005. type: string
  16006. name:
  16007. description: The name of the Secret resource being referred to.
  16008. maxLength: 253
  16009. minLength: 1
  16010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16011. type: string
  16012. namespace:
  16013. description: |-
  16014. The namespace of the Secret resource being referred to.
  16015. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16016. maxLength: 63
  16017. minLength: 1
  16018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16019. type: string
  16020. type: object
  16021. sessionTokenSecretRef:
  16022. description: |-
  16023. The SessionToken used for authentication
  16024. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16025. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16026. properties:
  16027. key:
  16028. description: |-
  16029. A key in the referenced Secret.
  16030. Some instances of this field may be defaulted, in others it may be required.
  16031. maxLength: 253
  16032. minLength: 1
  16033. pattern: ^[-._a-zA-Z0-9]+$
  16034. type: string
  16035. name:
  16036. description: The name of the Secret resource being referred to.
  16037. maxLength: 253
  16038. minLength: 1
  16039. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16040. type: string
  16041. namespace:
  16042. description: |-
  16043. The namespace of the Secret resource being referred to.
  16044. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16045. maxLength: 63
  16046. minLength: 1
  16047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16048. type: string
  16049. type: object
  16050. type: object
  16051. type: object
  16052. customSessionTags:
  16053. additionalProperties:
  16054. type: string
  16055. description: |-
  16056. CustomSessionTags defines additional STS session tags to include when SessionTagsPolicy is Custom.
  16057. These are merged with the automatically injected esoNamespace, esoStoreName, and esoStoreKind tags.
  16058. type: object
  16059. x-kubernetes-validations:
  16060. - message: 'customSessionTags cannot contain automatically injected reserved keys: esoNamespace, esoStoreName, esoStoreKind'
  16061. rule: '!(''esoNamespace'' in self) && !(''esoStoreName'' in self) && !(''esoStoreKind'' in self)'
  16062. externalID:
  16063. description: AWS External ID set on assumed IAM roles
  16064. type: string
  16065. prefix:
  16066. description: Prefix adds a prefix to all retrieved values.
  16067. type: string
  16068. region:
  16069. description: AWS Region to be used for the provider
  16070. type: string
  16071. role:
  16072. description: Role is a Role ARN which the provider will assume
  16073. type: string
  16074. secretsManager:
  16075. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  16076. properties:
  16077. forceDeleteWithoutRecovery:
  16078. description: |-
  16079. Specifies whether to delete the secret without any recovery window. You
  16080. can't use both this parameter and RecoveryWindowInDays in the same call.
  16081. If you don't use either, then by default Secrets Manager uses a 30 day
  16082. recovery window.
  16083. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  16084. type: boolean
  16085. recoveryWindowInDays:
  16086. description: |-
  16087. The number of days from 7 to 30 that Secrets Manager waits before
  16088. permanently deleting the secret. You can't use both this parameter and
  16089. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  16090. then by default Secrets Manager uses a 30-day recovery window.
  16091. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  16092. format: int64
  16093. type: integer
  16094. type: object
  16095. service:
  16096. description: Service defines which service should be used to fetch the secrets
  16097. enum:
  16098. - SecretsManager
  16099. - ParameterStore
  16100. - CertificateManager
  16101. type: string
  16102. sessionTags:
  16103. description: AWS STS assume role session tags
  16104. items:
  16105. description: |-
  16106. Tag is a key-value pair that can be attached to an AWS resource.
  16107. see: https://docs.aws.amazon.com/general/latest/gr/aws_tagging.html
  16108. properties:
  16109. key:
  16110. type: string
  16111. value:
  16112. type: string
  16113. required:
  16114. - key
  16115. - value
  16116. type: object
  16117. type: array
  16118. sessionTagsPolicy:
  16119. default: None
  16120. description: |-
  16121. SessionTagsPolicy controls whether and how STS session tags are added when assuming roles.
  16122. None (default): no tags are added.
  16123. Simple: automatically adds esoNamespace (from the ExternalSecret), esoStoreName, and esoStoreKind tags.
  16124. Custom: adds esoNamespace, esoStoreName, and esoStoreKind plus any tags defined in CustomSessionTags.
  16125. Note: the IAM role must have sts:TagSession permission when using Simple or Custom.
  16126. enum:
  16127. - None
  16128. - Simple
  16129. - Custom
  16130. type: string
  16131. transitiveTagKeys:
  16132. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  16133. items:
  16134. type: string
  16135. type: array
  16136. required:
  16137. - region
  16138. - service
  16139. type: object
  16140. azurekv:
  16141. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  16142. properties:
  16143. authSecretRef:
  16144. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16145. properties:
  16146. clientCertificate:
  16147. description: The Azure ClientCertificate of the service principle used for authentication.
  16148. properties:
  16149. key:
  16150. description: |-
  16151. A key in the referenced Secret.
  16152. Some instances of this field may be defaulted, in others it may be required.
  16153. maxLength: 253
  16154. minLength: 1
  16155. pattern: ^[-._a-zA-Z0-9]+$
  16156. type: string
  16157. name:
  16158. description: The name of the Secret resource being referred to.
  16159. maxLength: 253
  16160. minLength: 1
  16161. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16162. type: string
  16163. namespace:
  16164. description: |-
  16165. The namespace of the Secret resource being referred to.
  16166. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16167. maxLength: 63
  16168. minLength: 1
  16169. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16170. type: string
  16171. type: object
  16172. clientId:
  16173. description: The Azure clientId of the service principle or managed identity used for authentication.
  16174. properties:
  16175. key:
  16176. description: |-
  16177. A key in the referenced Secret.
  16178. Some instances of this field may be defaulted, in others it may be required.
  16179. maxLength: 253
  16180. minLength: 1
  16181. pattern: ^[-._a-zA-Z0-9]+$
  16182. type: string
  16183. name:
  16184. description: The name of the Secret resource being referred to.
  16185. maxLength: 253
  16186. minLength: 1
  16187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16188. type: string
  16189. namespace:
  16190. description: |-
  16191. The namespace of the Secret resource being referred to.
  16192. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16193. maxLength: 63
  16194. minLength: 1
  16195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16196. type: string
  16197. type: object
  16198. clientSecret:
  16199. description: The Azure ClientSecret of the service principle used for authentication.
  16200. properties:
  16201. key:
  16202. description: |-
  16203. A key in the referenced Secret.
  16204. Some instances of this field may be defaulted, in others it may be required.
  16205. maxLength: 253
  16206. minLength: 1
  16207. pattern: ^[-._a-zA-Z0-9]+$
  16208. type: string
  16209. name:
  16210. description: The name of the Secret resource being referred to.
  16211. maxLength: 253
  16212. minLength: 1
  16213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16214. type: string
  16215. namespace:
  16216. description: |-
  16217. The namespace of the Secret resource being referred to.
  16218. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16219. maxLength: 63
  16220. minLength: 1
  16221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16222. type: string
  16223. type: object
  16224. tenantId:
  16225. description: The Azure tenantId of the managed identity used for authentication.
  16226. properties:
  16227. key:
  16228. description: |-
  16229. A key in the referenced Secret.
  16230. Some instances of this field may be defaulted, in others it may be required.
  16231. maxLength: 253
  16232. minLength: 1
  16233. pattern: ^[-._a-zA-Z0-9]+$
  16234. type: string
  16235. name:
  16236. description: The name of the Secret resource being referred to.
  16237. maxLength: 253
  16238. minLength: 1
  16239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16240. type: string
  16241. namespace:
  16242. description: |-
  16243. The namespace of the Secret resource being referred to.
  16244. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16245. maxLength: 63
  16246. minLength: 1
  16247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16248. type: string
  16249. type: object
  16250. type: object
  16251. authType:
  16252. default: ServicePrincipal
  16253. description: |-
  16254. Auth type defines how to authenticate to the keyvault service.
  16255. Valid values are:
  16256. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  16257. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  16258. - "WorkloadIdentity": Using a Kubernetes ServiceAccount federated with Entra ID
  16259. enum:
  16260. - ServicePrincipal
  16261. - ManagedIdentity
  16262. - WorkloadIdentity
  16263. type: string
  16264. customCloudConfig:
  16265. description: |-
  16266. CustomCloudConfig defines custom Azure endpoints for non-standard clouds.
  16267. Required when EnvironmentType is AzureStackCloud.
  16268. Optional for other environment types - useful for Azure China when using Workload Identity
  16269. with AKS, where the OIDC issuer (login.partner.microsoftonline.cn) differs from the
  16270. standard China Cloud endpoint (login.chinacloudapi.cn).
  16271. IMPORTANT: This feature REQUIRES UseAzureSDK to be set to true. Custom cloud
  16272. configuration is not supported with the legacy go-autorest SDK.
  16273. properties:
  16274. activeDirectoryEndpoint:
  16275. description: |-
  16276. ActiveDirectoryEndpoint is the AAD endpoint for authentication
  16277. Required when using custom cloud configuration
  16278. type: string
  16279. keyVaultDNSSuffix:
  16280. description: KeyVaultDNSSuffix is the DNS suffix for Key Vault URLs
  16281. type: string
  16282. keyVaultEndpoint:
  16283. description: KeyVaultEndpoint is the Key Vault service endpoint
  16284. type: string
  16285. resourceManagerEndpoint:
  16286. description: ResourceManagerEndpoint is the Azure Resource Manager endpoint
  16287. type: string
  16288. required:
  16289. - activeDirectoryEndpoint
  16290. type: object
  16291. environmentType:
  16292. default: PublicCloud
  16293. description: |-
  16294. EnvironmentType specifies the Azure cloud environment endpoints to use for
  16295. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  16296. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  16297. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud, AzureStackCloud
  16298. Use AzureStackCloud when you need to configure custom Azure Stack Hub or Azure Stack Edge endpoints.
  16299. enum:
  16300. - PublicCloud
  16301. - USGovernmentCloud
  16302. - ChinaCloud
  16303. - GermanCloud
  16304. - AzureStackCloud
  16305. type: string
  16306. identityId:
  16307. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  16308. type: string
  16309. serviceAccountRef:
  16310. description: |-
  16311. ServiceAccountRef specified the service account
  16312. that should be used when authenticating with WorkloadIdentity.
  16313. properties:
  16314. audiences:
  16315. description: |-
  16316. Audience specifies the `aud` claim for the service account token
  16317. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16318. then this audiences will be appended to the list
  16319. items:
  16320. type: string
  16321. type: array
  16322. name:
  16323. description: The name of the ServiceAccount resource being referred to.
  16324. maxLength: 253
  16325. minLength: 1
  16326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16327. type: string
  16328. namespace:
  16329. description: |-
  16330. Namespace of the resource being referred to.
  16331. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16332. maxLength: 63
  16333. minLength: 1
  16334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16335. type: string
  16336. required:
  16337. - name
  16338. type: object
  16339. tenantId:
  16340. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  16341. type: string
  16342. useAzureSDK:
  16343. default: false
  16344. description: |-
  16345. UseAzureSDK enables the use of the new Azure SDK for Go (azcore-based) instead of the legacy go-autorest SDK.
  16346. This is experimental and may have behavioral differences. Defaults to false (legacy SDK).
  16347. type: boolean
  16348. vaultUrl:
  16349. description: Vault Url from which the secrets to be fetched from.
  16350. type: string
  16351. required:
  16352. - vaultUrl
  16353. type: object
  16354. barbican:
  16355. description: Barbican configures this store to sync secrets using the OpenStack Barbican provider
  16356. properties:
  16357. auth:
  16358. description: BarbicanAuth contains the authentication information for Barbican.
  16359. properties:
  16360. password:
  16361. description: BarbicanProviderPasswordRef defines a reference to a secret containing password for the Barbican provider.
  16362. properties:
  16363. secretRef:
  16364. description: |-
  16365. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16366. In some instances, `key` is a required field.
  16367. properties:
  16368. key:
  16369. description: |-
  16370. A key in the referenced Secret.
  16371. Some instances of this field may be defaulted, in others it may be required.
  16372. maxLength: 253
  16373. minLength: 1
  16374. pattern: ^[-._a-zA-Z0-9]+$
  16375. type: string
  16376. name:
  16377. description: The name of the Secret resource being referred to.
  16378. maxLength: 253
  16379. minLength: 1
  16380. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16381. type: string
  16382. namespace:
  16383. description: |-
  16384. The namespace of the Secret resource being referred to.
  16385. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16386. maxLength: 63
  16387. minLength: 1
  16388. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16389. type: string
  16390. type: object
  16391. required:
  16392. - secretRef
  16393. type: object
  16394. username:
  16395. description: BarbicanProviderUsernameRef defines a reference to a secret containing username for the Barbican provider.
  16396. maxProperties: 1
  16397. minProperties: 1
  16398. properties:
  16399. secretRef:
  16400. description: |-
  16401. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  16402. In some instances, `key` is a required field.
  16403. properties:
  16404. key:
  16405. description: |-
  16406. A key in the referenced Secret.
  16407. Some instances of this field may be defaulted, in others it may be required.
  16408. maxLength: 253
  16409. minLength: 1
  16410. pattern: ^[-._a-zA-Z0-9]+$
  16411. type: string
  16412. name:
  16413. description: The name of the Secret resource being referred to.
  16414. maxLength: 253
  16415. minLength: 1
  16416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16417. type: string
  16418. namespace:
  16419. description: |-
  16420. The namespace of the Secret resource being referred to.
  16421. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16422. maxLength: 63
  16423. minLength: 1
  16424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16425. type: string
  16426. type: object
  16427. value:
  16428. type: string
  16429. type: object
  16430. required:
  16431. - password
  16432. - username
  16433. type: object
  16434. authURL:
  16435. type: string
  16436. domainName:
  16437. type: string
  16438. region:
  16439. type: string
  16440. tenantName:
  16441. type: string
  16442. required:
  16443. - auth
  16444. type: object
  16445. beyondtrust:
  16446. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  16447. properties:
  16448. auth:
  16449. description: Auth configures how the operator authenticates with Beyondtrust.
  16450. properties:
  16451. apiKey:
  16452. description: APIKey If not provided then ClientID/ClientSecret become required.
  16453. properties:
  16454. secretRef:
  16455. description: SecretRef references a key in a secret that will be used as value.
  16456. properties:
  16457. key:
  16458. description: |-
  16459. A key in the referenced Secret.
  16460. Some instances of this field may be defaulted, in others it may be required.
  16461. maxLength: 253
  16462. minLength: 1
  16463. pattern: ^[-._a-zA-Z0-9]+$
  16464. type: string
  16465. name:
  16466. description: The name of the Secret resource being referred to.
  16467. maxLength: 253
  16468. minLength: 1
  16469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16470. type: string
  16471. namespace:
  16472. description: |-
  16473. The namespace of the Secret resource being referred to.
  16474. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16475. maxLength: 63
  16476. minLength: 1
  16477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16478. type: string
  16479. type: object
  16480. value:
  16481. description: Value can be specified directly to set a value without using a secret.
  16482. type: string
  16483. type: object
  16484. certificate:
  16485. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  16486. properties:
  16487. secretRef:
  16488. description: SecretRef references a key in a secret that will be used as value.
  16489. properties:
  16490. key:
  16491. description: |-
  16492. A key in the referenced Secret.
  16493. Some instances of this field may be defaulted, in others it may be required.
  16494. maxLength: 253
  16495. minLength: 1
  16496. pattern: ^[-._a-zA-Z0-9]+$
  16497. type: string
  16498. name:
  16499. description: The name of the Secret resource being referred to.
  16500. maxLength: 253
  16501. minLength: 1
  16502. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16503. type: string
  16504. namespace:
  16505. description: |-
  16506. The namespace of the Secret resource being referred to.
  16507. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16508. maxLength: 63
  16509. minLength: 1
  16510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16511. type: string
  16512. type: object
  16513. value:
  16514. description: Value can be specified directly to set a value without using a secret.
  16515. type: string
  16516. type: object
  16517. certificateKey:
  16518. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  16519. properties:
  16520. secretRef:
  16521. description: SecretRef references a key in a secret that will be used as value.
  16522. properties:
  16523. key:
  16524. description: |-
  16525. A key in the referenced Secret.
  16526. Some instances of this field may be defaulted, in others it may be required.
  16527. maxLength: 253
  16528. minLength: 1
  16529. pattern: ^[-._a-zA-Z0-9]+$
  16530. type: string
  16531. name:
  16532. description: The name of the Secret resource being referred to.
  16533. maxLength: 253
  16534. minLength: 1
  16535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16536. type: string
  16537. namespace:
  16538. description: |-
  16539. The namespace of the Secret resource being referred to.
  16540. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16541. maxLength: 63
  16542. minLength: 1
  16543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16544. type: string
  16545. type: object
  16546. value:
  16547. description: Value can be specified directly to set a value without using a secret.
  16548. type: string
  16549. type: object
  16550. clientId:
  16551. description: ClientID is the API OAuth Client ID.
  16552. properties:
  16553. secretRef:
  16554. description: SecretRef references a key in a secret that will be used as value.
  16555. properties:
  16556. key:
  16557. description: |-
  16558. A key in the referenced Secret.
  16559. Some instances of this field may be defaulted, in others it may be required.
  16560. maxLength: 253
  16561. minLength: 1
  16562. pattern: ^[-._a-zA-Z0-9]+$
  16563. type: string
  16564. name:
  16565. description: The name of the Secret resource being referred to.
  16566. maxLength: 253
  16567. minLength: 1
  16568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16569. type: string
  16570. namespace:
  16571. description: |-
  16572. The namespace of the Secret resource being referred to.
  16573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16574. maxLength: 63
  16575. minLength: 1
  16576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16577. type: string
  16578. type: object
  16579. value:
  16580. description: Value can be specified directly to set a value without using a secret.
  16581. type: string
  16582. type: object
  16583. clientSecret:
  16584. description: ClientSecret is the API OAuth Client Secret.
  16585. properties:
  16586. secretRef:
  16587. description: SecretRef references a key in a secret that will be used as value.
  16588. properties:
  16589. key:
  16590. description: |-
  16591. A key in the referenced Secret.
  16592. Some instances of this field may be defaulted, in others it may be required.
  16593. maxLength: 253
  16594. minLength: 1
  16595. pattern: ^[-._a-zA-Z0-9]+$
  16596. type: string
  16597. name:
  16598. description: The name of the Secret resource being referred to.
  16599. maxLength: 253
  16600. minLength: 1
  16601. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16602. type: string
  16603. namespace:
  16604. description: |-
  16605. The namespace of the Secret resource being referred to.
  16606. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16607. maxLength: 63
  16608. minLength: 1
  16609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16610. type: string
  16611. type: object
  16612. value:
  16613. description: Value can be specified directly to set a value without using a secret.
  16614. type: string
  16615. type: object
  16616. type: object
  16617. server:
  16618. description: Auth configures how API server works.
  16619. properties:
  16620. apiUrl:
  16621. type: string
  16622. apiVersion:
  16623. type: string
  16624. clientTimeOutSeconds:
  16625. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  16626. type: integer
  16627. decrypt:
  16628. default: true
  16629. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  16630. type: boolean
  16631. retrievalType:
  16632. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  16633. type: string
  16634. separator:
  16635. description: A character that separates the folder names.
  16636. type: string
  16637. verifyCA:
  16638. type: boolean
  16639. required:
  16640. - apiUrl
  16641. - verifyCA
  16642. type: object
  16643. required:
  16644. - auth
  16645. - server
  16646. type: object
  16647. beyondtrustworkloadcredentials:
  16648. description: BeyondtrustWorkloadCredentials configures this store to sync secrets using the BeyondTrust Workload Credentials provider.
  16649. properties:
  16650. auth:
  16651. description: |-
  16652. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  16653. Currently supports API key authentication via Kubernetes secret reference.
  16654. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16655. properties:
  16656. apikey:
  16657. description: |-
  16658. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  16659. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  16660. properties:
  16661. token:
  16662. description: |-
  16663. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  16664. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  16665. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  16666. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  16667. properties:
  16668. key:
  16669. description: |-
  16670. A key in the referenced Secret.
  16671. Some instances of this field may be defaulted, in others it may be required.
  16672. maxLength: 253
  16673. minLength: 1
  16674. pattern: ^[-._a-zA-Z0-9]+$
  16675. type: string
  16676. name:
  16677. description: The name of the Secret resource being referred to.
  16678. maxLength: 253
  16679. minLength: 1
  16680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16681. type: string
  16682. namespace:
  16683. description: |-
  16684. The namespace of the Secret resource being referred to.
  16685. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16686. maxLength: 63
  16687. minLength: 1
  16688. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16689. type: string
  16690. type: object
  16691. required:
  16692. - token
  16693. type: object
  16694. required:
  16695. - apikey
  16696. type: object
  16697. caBundle:
  16698. description: |-
  16699. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16700. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  16701. If not set, the system's trusted root certificates are used.
  16702. format: byte
  16703. type: string
  16704. caProvider:
  16705. description: |-
  16706. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  16707. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  16708. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  16709. properties:
  16710. key:
  16711. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16712. maxLength: 253
  16713. minLength: 1
  16714. pattern: ^[-._a-zA-Z0-9]+$
  16715. type: string
  16716. name:
  16717. description: The name of the object located at the provider type.
  16718. maxLength: 253
  16719. minLength: 1
  16720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16721. type: string
  16722. namespace:
  16723. description: |-
  16724. The namespace the Provider type is in.
  16725. Can only be defined when used in a ClusterSecretStore.
  16726. maxLength: 63
  16727. minLength: 1
  16728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16729. type: string
  16730. type:
  16731. description: The type of provider to use such as "Secret", or "ConfigMap".
  16732. enum:
  16733. - Secret
  16734. - ConfigMap
  16735. type: string
  16736. required:
  16737. - name
  16738. - type
  16739. type: object
  16740. folderPath:
  16741. description: |-
  16742. FolderPath specifies the default folder path for secret retrieval.
  16743. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  16744. Example: "production/database" or "dev/api-keys"
  16745. Leave empty to retrieve secrets from the root folder.
  16746. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  16747. type: string
  16748. server:
  16749. description: |-
  16750. Server configures the BeyondTrust Workload Credentials server connection details.
  16751. Includes the API URL and Site ID for your BeyondTrust instance.
  16752. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16753. properties:
  16754. apiUrl:
  16755. description: |-
  16756. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  16757. This should be the full URL to your BeyondTrust instance.
  16758. Example: https://api.beyondtrust.io/siie
  16759. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  16760. type: string
  16761. siteId:
  16762. description: |-
  16763. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  16764. This identifier is unique to your BeyondTrust Workload Credentials instance.
  16765. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  16766. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  16767. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  16768. type: string
  16769. required:
  16770. - apiUrl
  16771. - siteId
  16772. type: object
  16773. required:
  16774. - auth
  16775. - server
  16776. type: object
  16777. bitwardensecretsmanager:
  16778. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  16779. properties:
  16780. apiURL:
  16781. type: string
  16782. auth:
  16783. description: |-
  16784. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  16785. Make sure that the token being used has permissions on the given secret.
  16786. properties:
  16787. secretRef:
  16788. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  16789. properties:
  16790. credentials:
  16791. description: AccessToken used for the bitwarden instance.
  16792. properties:
  16793. key:
  16794. description: |-
  16795. A key in the referenced Secret.
  16796. Some instances of this field may be defaulted, in others it may be required.
  16797. maxLength: 253
  16798. minLength: 1
  16799. pattern: ^[-._a-zA-Z0-9]+$
  16800. type: string
  16801. name:
  16802. description: The name of the Secret resource being referred to.
  16803. maxLength: 253
  16804. minLength: 1
  16805. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16806. type: string
  16807. namespace:
  16808. description: |-
  16809. The namespace of the Secret resource being referred to.
  16810. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16811. maxLength: 63
  16812. minLength: 1
  16813. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16814. type: string
  16815. type: object
  16816. required:
  16817. - credentials
  16818. type: object
  16819. required:
  16820. - secretRef
  16821. type: object
  16822. bitwardenServerSDKURL:
  16823. type: string
  16824. caBundle:
  16825. description: |-
  16826. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  16827. can be performed.
  16828. type: string
  16829. caProvider:
  16830. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  16831. properties:
  16832. key:
  16833. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  16834. maxLength: 253
  16835. minLength: 1
  16836. pattern: ^[-._a-zA-Z0-9]+$
  16837. type: string
  16838. name:
  16839. description: The name of the object located at the provider type.
  16840. maxLength: 253
  16841. minLength: 1
  16842. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16843. type: string
  16844. namespace:
  16845. description: |-
  16846. The namespace the Provider type is in.
  16847. Can only be defined when used in a ClusterSecretStore.
  16848. maxLength: 63
  16849. minLength: 1
  16850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16851. type: string
  16852. type:
  16853. description: The type of provider to use such as "Secret", or "ConfigMap".
  16854. enum:
  16855. - Secret
  16856. - ConfigMap
  16857. type: string
  16858. required:
  16859. - name
  16860. - type
  16861. type: object
  16862. identityURL:
  16863. type: string
  16864. organizationID:
  16865. description: OrganizationID determines which organization this secret store manages.
  16866. type: string
  16867. projectID:
  16868. description: ProjectID determines which project this secret store manages.
  16869. type: string
  16870. required:
  16871. - auth
  16872. - organizationID
  16873. - projectID
  16874. type: object
  16875. chef:
  16876. description: Chef configures this store to sync secrets with chef server
  16877. properties:
  16878. auth:
  16879. description: Auth defines the information necessary to authenticate against chef Server
  16880. properties:
  16881. secretRef:
  16882. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  16883. properties:
  16884. privateKeySecretRef:
  16885. description: SecretKey is the Signing Key in PEM format, used for authentication.
  16886. properties:
  16887. key:
  16888. description: |-
  16889. A key in the referenced Secret.
  16890. Some instances of this field may be defaulted, in others it may be required.
  16891. maxLength: 253
  16892. minLength: 1
  16893. pattern: ^[-._a-zA-Z0-9]+$
  16894. type: string
  16895. name:
  16896. description: The name of the Secret resource being referred to.
  16897. maxLength: 253
  16898. minLength: 1
  16899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16900. type: string
  16901. namespace:
  16902. description: |-
  16903. The namespace of the Secret resource being referred to.
  16904. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16905. maxLength: 63
  16906. minLength: 1
  16907. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16908. type: string
  16909. type: object
  16910. required:
  16911. - privateKeySecretRef
  16912. type: object
  16913. required:
  16914. - secretRef
  16915. type: object
  16916. serverUrl:
  16917. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  16918. type: string
  16919. username:
  16920. description: UserName should be the user ID on the chef server
  16921. type: string
  16922. required:
  16923. - auth
  16924. - serverUrl
  16925. - username
  16926. type: object
  16927. cloudrusm:
  16928. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  16929. properties:
  16930. auth:
  16931. description: CSMAuth contains a secretRef for credentials.
  16932. properties:
  16933. secretRef:
  16934. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  16935. properties:
  16936. accessKeyIDSecretRef:
  16937. description: The AccessKeyID is used for authentication
  16938. properties:
  16939. key:
  16940. description: |-
  16941. A key in the referenced Secret.
  16942. Some instances of this field may be defaulted, in others it may be required.
  16943. maxLength: 253
  16944. minLength: 1
  16945. pattern: ^[-._a-zA-Z0-9]+$
  16946. type: string
  16947. name:
  16948. description: The name of the Secret resource being referred to.
  16949. maxLength: 253
  16950. minLength: 1
  16951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16952. type: string
  16953. namespace:
  16954. description: |-
  16955. The namespace of the Secret resource being referred to.
  16956. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16957. maxLength: 63
  16958. minLength: 1
  16959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16960. type: string
  16961. type: object
  16962. accessKeySecretSecretRef:
  16963. description: The AccessKeySecret is used for authentication
  16964. properties:
  16965. key:
  16966. description: |-
  16967. A key in the referenced Secret.
  16968. Some instances of this field may be defaulted, in others it may be required.
  16969. maxLength: 253
  16970. minLength: 1
  16971. pattern: ^[-._a-zA-Z0-9]+$
  16972. type: string
  16973. name:
  16974. description: The name of the Secret resource being referred to.
  16975. maxLength: 253
  16976. minLength: 1
  16977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16978. type: string
  16979. namespace:
  16980. description: |-
  16981. The namespace of the Secret resource being referred to.
  16982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16983. maxLength: 63
  16984. minLength: 1
  16985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16986. type: string
  16987. type: object
  16988. required:
  16989. - accessKeyIDSecretRef
  16990. - accessKeySecretSecretRef
  16991. type: object
  16992. type: object
  16993. projectID:
  16994. description: ProjectID is the project, which the secrets are stored in.
  16995. type: string
  16996. required:
  16997. - auth
  16998. type: object
  16999. conjur:
  17000. description: Conjur configures this store to sync secrets using conjur provider
  17001. properties:
  17002. auth:
  17003. description: Defines authentication settings for connecting to Conjur.
  17004. maxProperties: 1
  17005. minProperties: 1
  17006. properties:
  17007. apikey:
  17008. description: Authenticates with Conjur using an API key.
  17009. properties:
  17010. account:
  17011. description: Account is the Conjur organization account name.
  17012. type: string
  17013. apiKeyRef:
  17014. description: |-
  17015. A reference to a specific 'key' containing the Conjur API key
  17016. within a Secret resource. In some instances, `key` is a required field.
  17017. properties:
  17018. key:
  17019. description: |-
  17020. A key in the referenced Secret.
  17021. Some instances of this field may be defaulted, in others it may be required.
  17022. maxLength: 253
  17023. minLength: 1
  17024. pattern: ^[-._a-zA-Z0-9]+$
  17025. type: string
  17026. name:
  17027. description: The name of the Secret resource being referred to.
  17028. maxLength: 253
  17029. minLength: 1
  17030. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17031. type: string
  17032. namespace:
  17033. description: |-
  17034. The namespace of the Secret resource being referred to.
  17035. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17036. maxLength: 63
  17037. minLength: 1
  17038. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17039. type: string
  17040. type: object
  17041. userRef:
  17042. description: |-
  17043. A reference to a specific 'key' containing the Conjur username
  17044. within a Secret resource. In some instances, `key` is a required field.
  17045. properties:
  17046. key:
  17047. description: |-
  17048. A key in the referenced Secret.
  17049. Some instances of this field may be defaulted, in others it may be required.
  17050. maxLength: 253
  17051. minLength: 1
  17052. pattern: ^[-._a-zA-Z0-9]+$
  17053. type: string
  17054. name:
  17055. description: The name of the Secret resource being referred to.
  17056. maxLength: 253
  17057. minLength: 1
  17058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17059. type: string
  17060. namespace:
  17061. description: |-
  17062. The namespace of the Secret resource being referred to.
  17063. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17064. maxLength: 63
  17065. minLength: 1
  17066. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17067. type: string
  17068. type: object
  17069. required:
  17070. - account
  17071. - apiKeyRef
  17072. - userRef
  17073. type: object
  17074. cert:
  17075. description: Cert enables certificate-based authentication using a client certificate and key.
  17076. properties:
  17077. account:
  17078. description: Account is the Conjur organization account name.
  17079. type: string
  17080. clientCertRef:
  17081. description: |-
  17082. ClientCertRef is a reference to a specific 'key' containing the client certificate
  17083. within a Secret resource. The certificate must be PEM-encoded.
  17084. properties:
  17085. key:
  17086. description: |-
  17087. A key in the referenced Secret.
  17088. Some instances of this field may be defaulted, in others it may be required.
  17089. maxLength: 253
  17090. minLength: 1
  17091. pattern: ^[-._a-zA-Z0-9]+$
  17092. type: string
  17093. name:
  17094. description: The name of the Secret resource being referred to.
  17095. maxLength: 253
  17096. minLength: 1
  17097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17098. type: string
  17099. namespace:
  17100. description: |-
  17101. The namespace of the Secret resource being referred to.
  17102. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17103. maxLength: 63
  17104. minLength: 1
  17105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17106. type: string
  17107. type: object
  17108. clientKeyRef:
  17109. description: |-
  17110. ClientKeyRef is a reference to a specific 'key' containing the private RSA client key
  17111. within a Secret resource. The key must be PEM-encoded.
  17112. properties:
  17113. key:
  17114. description: |-
  17115. A key in the referenced Secret.
  17116. Some instances of this field may be defaulted, in others it may be required.
  17117. maxLength: 253
  17118. minLength: 1
  17119. pattern: ^[-._a-zA-Z0-9]+$
  17120. type: string
  17121. name:
  17122. description: The name of the Secret resource being referred to.
  17123. maxLength: 253
  17124. minLength: 1
  17125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17126. type: string
  17127. namespace:
  17128. description: |-
  17129. The namespace of the Secret resource being referred to.
  17130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17131. maxLength: 63
  17132. minLength: 1
  17133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17134. type: string
  17135. type: object
  17136. hostId:
  17137. description: Optional HostID for cert authentication (can be omitted when using 'spiffe' mode).
  17138. type: string
  17139. serviceID:
  17140. description: The conjur authn cert webservice id
  17141. type: string
  17142. required:
  17143. - account
  17144. - clientCertRef
  17145. - clientKeyRef
  17146. - serviceID
  17147. type: object
  17148. jwt:
  17149. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  17150. properties:
  17151. account:
  17152. description: Account is the Conjur organization account name.
  17153. type: string
  17154. hostId:
  17155. description: |-
  17156. Optional HostID for JWT authentication. This may be used depending
  17157. on how the Conjur JWT authenticator policy is configured.
  17158. type: string
  17159. secretRef:
  17160. description: |-
  17161. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  17162. authenticate with Conjur using the JWT authentication method.
  17163. properties:
  17164. key:
  17165. description: |-
  17166. A key in the referenced Secret.
  17167. Some instances of this field may be defaulted, in others it may be required.
  17168. maxLength: 253
  17169. minLength: 1
  17170. pattern: ^[-._a-zA-Z0-9]+$
  17171. type: string
  17172. name:
  17173. description: The name of the Secret resource being referred to.
  17174. maxLength: 253
  17175. minLength: 1
  17176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17177. type: string
  17178. namespace:
  17179. description: |-
  17180. The namespace of the Secret resource being referred to.
  17181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17182. maxLength: 63
  17183. minLength: 1
  17184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17185. type: string
  17186. type: object
  17187. serviceAccountRef:
  17188. description: |-
  17189. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  17190. a token for with the `TokenRequest` API.
  17191. properties:
  17192. audiences:
  17193. description: |-
  17194. Audience specifies the `aud` claim for the service account token
  17195. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17196. then this audiences will be appended to the list
  17197. items:
  17198. type: string
  17199. type: array
  17200. name:
  17201. description: The name of the ServiceAccount resource being referred to.
  17202. maxLength: 253
  17203. minLength: 1
  17204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17205. type: string
  17206. namespace:
  17207. description: |-
  17208. Namespace of the resource being referred to.
  17209. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17210. maxLength: 63
  17211. minLength: 1
  17212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17213. type: string
  17214. required:
  17215. - name
  17216. type: object
  17217. serviceID:
  17218. description: The conjur authn jwt webservice id
  17219. type: string
  17220. required:
  17221. - account
  17222. - serviceID
  17223. type: object
  17224. type: object
  17225. caBundle:
  17226. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  17227. type: string
  17228. caProvider:
  17229. description: |-
  17230. Used to provide custom certificate authority (CA) certificates
  17231. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  17232. that contains a PEM-encoded certificate.
  17233. properties:
  17234. key:
  17235. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17236. maxLength: 253
  17237. minLength: 1
  17238. pattern: ^[-._a-zA-Z0-9]+$
  17239. type: string
  17240. name:
  17241. description: The name of the object located at the provider type.
  17242. maxLength: 253
  17243. minLength: 1
  17244. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17245. type: string
  17246. namespace:
  17247. description: |-
  17248. The namespace the Provider type is in.
  17249. Can only be defined when used in a ClusterSecretStore.
  17250. maxLength: 63
  17251. minLength: 1
  17252. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17253. type: string
  17254. type:
  17255. description: The type of provider to use such as "Secret", or "ConfigMap".
  17256. enum:
  17257. - Secret
  17258. - ConfigMap
  17259. type: string
  17260. required:
  17261. - name
  17262. - type
  17263. type: object
  17264. url:
  17265. description: URL is the endpoint of the Conjur instance.
  17266. type: string
  17267. required:
  17268. - auth
  17269. - url
  17270. type: object
  17271. crd:
  17272. description: |-
  17273. CRD configures this store to sync secrets from arbitrary Kubernetes resources,
  17274. including both custom resources (CRDs) and core API resources. Resources are
  17275. selected by API group, version and kind, where group can be "" (empty string)
  17276. for core resources such as ConfigMap. Reading the core v1 Secret is
  17277. intentionally blocked — use the Kubernetes provider for that.
  17278. properties:
  17279. auth:
  17280. description: |-
  17281. Auth configures authentication to the Kubernetes API, same as the
  17282. Kubernetes provider. Required when Server.URL is set (unless using AuthRef).
  17283. maxProperties: 1
  17284. minProperties: 1
  17285. properties:
  17286. cert:
  17287. description: has both clientCert and clientKey as secretKeySelector
  17288. properties:
  17289. clientCert:
  17290. description: |-
  17291. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17292. In some instances, `key` is a required field.
  17293. properties:
  17294. key:
  17295. description: |-
  17296. A key in the referenced Secret.
  17297. Some instances of this field may be defaulted, in others it may be required.
  17298. maxLength: 253
  17299. minLength: 1
  17300. pattern: ^[-._a-zA-Z0-9]+$
  17301. type: string
  17302. name:
  17303. description: The name of the Secret resource being referred to.
  17304. maxLength: 253
  17305. minLength: 1
  17306. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17307. type: string
  17308. namespace:
  17309. description: |-
  17310. The namespace of the Secret resource being referred to.
  17311. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17312. maxLength: 63
  17313. minLength: 1
  17314. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17315. type: string
  17316. type: object
  17317. clientKey:
  17318. description: |-
  17319. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17320. In some instances, `key` is a required field.
  17321. properties:
  17322. key:
  17323. description: |-
  17324. A key in the referenced Secret.
  17325. Some instances of this field may be defaulted, in others it may be required.
  17326. maxLength: 253
  17327. minLength: 1
  17328. pattern: ^[-._a-zA-Z0-9]+$
  17329. type: string
  17330. name:
  17331. description: The name of the Secret resource being referred to.
  17332. maxLength: 253
  17333. minLength: 1
  17334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17335. type: string
  17336. namespace:
  17337. description: |-
  17338. The namespace of the Secret resource being referred to.
  17339. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17340. maxLength: 63
  17341. minLength: 1
  17342. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17343. type: string
  17344. type: object
  17345. required:
  17346. - clientCert
  17347. - clientKey
  17348. type: object
  17349. serviceAccount:
  17350. description: points to a service account that should be used for authentication
  17351. properties:
  17352. audiences:
  17353. description: |-
  17354. Audience specifies the `aud` claim for the service account token
  17355. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17356. then this audiences will be appended to the list
  17357. items:
  17358. type: string
  17359. type: array
  17360. name:
  17361. description: The name of the ServiceAccount resource being referred to.
  17362. maxLength: 253
  17363. minLength: 1
  17364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17365. type: string
  17366. namespace:
  17367. description: |-
  17368. Namespace of the resource being referred to.
  17369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17370. maxLength: 63
  17371. minLength: 1
  17372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17373. type: string
  17374. required:
  17375. - name
  17376. type: object
  17377. token:
  17378. description: use static token to authenticate with
  17379. properties:
  17380. bearerToken:
  17381. description: |-
  17382. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  17383. In some instances, `key` is a required field.
  17384. properties:
  17385. key:
  17386. description: |-
  17387. A key in the referenced Secret.
  17388. Some instances of this field may be defaulted, in others it may be required.
  17389. maxLength: 253
  17390. minLength: 1
  17391. pattern: ^[-._a-zA-Z0-9]+$
  17392. type: string
  17393. name:
  17394. description: The name of the Secret resource being referred to.
  17395. maxLength: 253
  17396. minLength: 1
  17397. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17398. type: string
  17399. namespace:
  17400. description: |-
  17401. The namespace of the Secret resource being referred to.
  17402. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17403. maxLength: 63
  17404. minLength: 1
  17405. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17406. type: string
  17407. type: object
  17408. required:
  17409. - bearerToken
  17410. type: object
  17411. type: object
  17412. authRef:
  17413. description: |-
  17414. AuthRef references a Secret containing a kubeconfig. Same semantics as the
  17415. Kubernetes provider.
  17416. properties:
  17417. key:
  17418. description: |-
  17419. A key in the referenced Secret.
  17420. Some instances of this field may be defaulted, in others it may be required.
  17421. maxLength: 253
  17422. minLength: 1
  17423. pattern: ^[-._a-zA-Z0-9]+$
  17424. type: string
  17425. name:
  17426. description: The name of the Secret resource being referred to.
  17427. maxLength: 253
  17428. minLength: 1
  17429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17430. type: string
  17431. namespace:
  17432. description: |-
  17433. The namespace of the Secret resource being referred to.
  17434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17435. maxLength: 63
  17436. minLength: 1
  17437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17438. type: string
  17439. type: object
  17440. resource:
  17441. description: Resource identifies the CRD by its API group, version and kind.
  17442. properties:
  17443. group:
  17444. description: |-
  17445. Group is the API group of the resource. Use "" (empty string) for core
  17446. Kubernetes resources such as ConfigMap; use e.g. "config.example.io"
  17447. for a CRD. The field is required to be present in the manifest — write
  17448. `group: ""` explicitly for core resources so typos fail at admission
  17449. time rather than later at discovery.
  17450. type: string
  17451. kind:
  17452. description: Kind is the Kubernetes resource kind (e.g. "MyCustomResource").
  17453. minLength: 1
  17454. type: string
  17455. version:
  17456. description: Version is the API version of the resource (e.g. "v1alpha1").
  17457. minLength: 1
  17458. type: string
  17459. required:
  17460. - group
  17461. - kind
  17462. - version
  17463. type: object
  17464. server:
  17465. description: |-
  17466. Server configures the Kubernetes API address and TLS trust, same as the
  17467. Kubernetes provider. When omitted, the URL defaults to the in-cluster API.
  17468. properties:
  17469. caBundle:
  17470. description: CABundle is a base64-encoded CA certificate
  17471. format: byte
  17472. type: string
  17473. caProvider:
  17474. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  17475. properties:
  17476. key:
  17477. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17478. maxLength: 253
  17479. minLength: 1
  17480. pattern: ^[-._a-zA-Z0-9]+$
  17481. type: string
  17482. name:
  17483. description: The name of the object located at the provider type.
  17484. maxLength: 253
  17485. minLength: 1
  17486. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17487. type: string
  17488. namespace:
  17489. description: |-
  17490. The namespace the Provider type is in.
  17491. Can only be defined when used in a ClusterSecretStore.
  17492. maxLength: 63
  17493. minLength: 1
  17494. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17495. type: string
  17496. type:
  17497. description: The type of provider to use such as "Secret", or "ConfigMap".
  17498. enum:
  17499. - Secret
  17500. - ConfigMap
  17501. type: string
  17502. required:
  17503. - name
  17504. - type
  17505. type: object
  17506. url:
  17507. default: kubernetes.default
  17508. description: configures the Kubernetes server Address.
  17509. type: string
  17510. type: object
  17511. whitelist:
  17512. description: |-
  17513. Whitelist optionally restricts which object names and requested properties
  17514. are allowed to be read.
  17515. properties:
  17516. rules:
  17517. description: |-
  17518. Rules is a list of allow rules. If rules are set, at least one rule must
  17519. match for a request to be allowed.
  17520. items:
  17521. description: CRDProviderWhitelistRule defines a single allow rule for CRD reads.
  17522. properties:
  17523. name:
  17524. description: |-
  17525. Name is an optional regular expression matched against the bare object name.
  17526. For both SecretStore and ClusterSecretStore this is always the object name
  17527. without any namespace prefix (e.g. "my-db-spec", not "prod/my-db-spec").
  17528. type: string
  17529. namespace:
  17530. description: |-
  17531. Namespace is an optional regular expression matched against the namespace of
  17532. the object. Applies only when a ClusterSecretStore is used; it is ignored
  17533. for SecretStore (where the namespace is fixed to the store namespace).
  17534. type: string
  17535. properties:
  17536. description: |-
  17537. Properties is an optional list of regular expressions matched against
  17538. requested property keys (for example: "spec.secretValue").
  17539. items:
  17540. type: string
  17541. type: array
  17542. type: object
  17543. type: array
  17544. type: object
  17545. required:
  17546. - resource
  17547. type: object
  17548. x-kubernetes-validations:
  17549. - message: one of auth or authRef is required
  17550. rule: has(self.auth) || has(self.authRef)
  17551. - message: at most one of the fields in [auth authRef] may be set
  17552. rule: '[has(self.auth),has(self.authRef)].filter(x,x==true).size() <= 1'
  17553. delinea:
  17554. description: |-
  17555. Delinea DevOps Secrets Vault
  17556. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  17557. properties:
  17558. clientId:
  17559. description: ClientID is the non-secret part of the credential.
  17560. properties:
  17561. secretRef:
  17562. description: SecretRef references a key in a secret that will be used as value.
  17563. properties:
  17564. key:
  17565. description: |-
  17566. A key in the referenced Secret.
  17567. Some instances of this field may be defaulted, in others it may be required.
  17568. maxLength: 253
  17569. minLength: 1
  17570. pattern: ^[-._a-zA-Z0-9]+$
  17571. type: string
  17572. name:
  17573. description: The name of the Secret resource being referred to.
  17574. maxLength: 253
  17575. minLength: 1
  17576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17577. type: string
  17578. namespace:
  17579. description: |-
  17580. The namespace of the Secret resource being referred to.
  17581. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17582. maxLength: 63
  17583. minLength: 1
  17584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17585. type: string
  17586. type: object
  17587. value:
  17588. description: Value can be specified directly to set a value without using a secret.
  17589. type: string
  17590. type: object
  17591. clientSecret:
  17592. description: ClientSecret is the secret part of the credential.
  17593. properties:
  17594. secretRef:
  17595. description: SecretRef references a key in a secret that will be used as value.
  17596. properties:
  17597. key:
  17598. description: |-
  17599. A key in the referenced Secret.
  17600. Some instances of this field may be defaulted, in others it may be required.
  17601. maxLength: 253
  17602. minLength: 1
  17603. pattern: ^[-._a-zA-Z0-9]+$
  17604. type: string
  17605. name:
  17606. description: The name of the Secret resource being referred to.
  17607. maxLength: 253
  17608. minLength: 1
  17609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17610. type: string
  17611. namespace:
  17612. description: |-
  17613. The namespace of the Secret resource being referred to.
  17614. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17615. maxLength: 63
  17616. minLength: 1
  17617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17618. type: string
  17619. type: object
  17620. value:
  17621. description: Value can be specified directly to set a value without using a secret.
  17622. type: string
  17623. type: object
  17624. tenant:
  17625. description: Tenant is the chosen hostname / site name.
  17626. type: string
  17627. tld:
  17628. description: |-
  17629. TLD is based on the server location that was chosen during provisioning.
  17630. If unset, defaults to "com".
  17631. type: string
  17632. urlTemplate:
  17633. description: |-
  17634. URLTemplate
  17635. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  17636. type: string
  17637. required:
  17638. - clientId
  17639. - clientSecret
  17640. - tenant
  17641. type: object
  17642. doppler:
  17643. description: Doppler configures this store to sync secrets using the Doppler provider
  17644. properties:
  17645. auth:
  17646. description: Auth configures how the Operator authenticates with the Doppler API
  17647. properties:
  17648. oidcConfig:
  17649. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  17650. properties:
  17651. expirationSeconds:
  17652. default: 600
  17653. description: |-
  17654. ExpirationSeconds sets the ServiceAccount token validity duration.
  17655. Defaults to 10 minutes.
  17656. format: int64
  17657. type: integer
  17658. identity:
  17659. description: Identity is the Doppler Service Account Identity ID configured for OIDC authentication.
  17660. type: string
  17661. serviceAccountRef:
  17662. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  17663. properties:
  17664. audiences:
  17665. description: |-
  17666. Audience specifies the `aud` claim for the service account token
  17667. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17668. then this audiences will be appended to the list
  17669. items:
  17670. type: string
  17671. type: array
  17672. name:
  17673. description: The name of the ServiceAccount resource being referred to.
  17674. maxLength: 253
  17675. minLength: 1
  17676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17677. type: string
  17678. namespace:
  17679. description: |-
  17680. Namespace of the resource being referred to.
  17681. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17682. maxLength: 63
  17683. minLength: 1
  17684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17685. type: string
  17686. required:
  17687. - name
  17688. type: object
  17689. required:
  17690. - identity
  17691. - serviceAccountRef
  17692. type: object
  17693. secretRef:
  17694. description: SecretRef authenticates using a Doppler service token stored in a Kubernetes Secret.
  17695. properties:
  17696. dopplerToken:
  17697. description: |-
  17698. The DopplerToken is used for authentication.
  17699. See https://docs.doppler.com/reference/api#authentication for auth token types.
  17700. The Key attribute defaults to dopplerToken if not specified.
  17701. properties:
  17702. key:
  17703. description: |-
  17704. A key in the referenced Secret.
  17705. Some instances of this field may be defaulted, in others it may be required.
  17706. maxLength: 253
  17707. minLength: 1
  17708. pattern: ^[-._a-zA-Z0-9]+$
  17709. type: string
  17710. name:
  17711. description: The name of the Secret resource being referred to.
  17712. maxLength: 253
  17713. minLength: 1
  17714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17715. type: string
  17716. namespace:
  17717. description: |-
  17718. The namespace of the Secret resource being referred to.
  17719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17720. maxLength: 63
  17721. minLength: 1
  17722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17723. type: string
  17724. type: object
  17725. required:
  17726. - dopplerToken
  17727. type: object
  17728. type: object
  17729. x-kubernetes-validations:
  17730. - message: Exactly one of 'secretRef' or 'oidcConfig' must be specified
  17731. rule: (has(self.secretRef) && !has(self.oidcConfig)) || (!has(self.secretRef) && has(self.oidcConfig))
  17732. config:
  17733. description: Doppler config (required if not using a Service Token)
  17734. type: string
  17735. format:
  17736. description: Format enables the downloading of secrets as a file (string)
  17737. enum:
  17738. - json
  17739. - dotnet-json
  17740. - env
  17741. - yaml
  17742. - docker
  17743. type: string
  17744. nameTransformer:
  17745. description: Environment variable compatible name transforms that change secret names to a different format
  17746. enum:
  17747. - upper-camel
  17748. - camel
  17749. - lower-snake
  17750. - tf-var
  17751. - dotnet-env
  17752. - lower-kebab
  17753. type: string
  17754. project:
  17755. description: Doppler project (required if not using a Service Token)
  17756. type: string
  17757. required:
  17758. - auth
  17759. type: object
  17760. dvls:
  17761. description: DVLS configures this store to sync secrets using Devolutions Server provider
  17762. properties:
  17763. auth:
  17764. description: Auth defines the authentication method to use.
  17765. properties:
  17766. secretRef:
  17767. description: SecretRef contains the Application ID and Application Secret for authentication.
  17768. properties:
  17769. appId:
  17770. description: AppID is the reference to the secret containing the Application ID.
  17771. properties:
  17772. key:
  17773. description: |-
  17774. A key in the referenced Secret.
  17775. Some instances of this field may be defaulted, in others it may be required.
  17776. maxLength: 253
  17777. minLength: 1
  17778. pattern: ^[-._a-zA-Z0-9]+$
  17779. type: string
  17780. name:
  17781. description: The name of the Secret resource being referred to.
  17782. maxLength: 253
  17783. minLength: 1
  17784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17785. type: string
  17786. namespace:
  17787. description: |-
  17788. The namespace of the Secret resource being referred to.
  17789. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17790. maxLength: 63
  17791. minLength: 1
  17792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17793. type: string
  17794. type: object
  17795. appSecret:
  17796. description: AppSecret is the reference to the secret containing the Application Secret.
  17797. properties:
  17798. key:
  17799. description: |-
  17800. A key in the referenced Secret.
  17801. Some instances of this field may be defaulted, in others it may be required.
  17802. maxLength: 253
  17803. minLength: 1
  17804. pattern: ^[-._a-zA-Z0-9]+$
  17805. type: string
  17806. name:
  17807. description: The name of the Secret resource being referred to.
  17808. maxLength: 253
  17809. minLength: 1
  17810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17811. type: string
  17812. namespace:
  17813. description: |-
  17814. The namespace of the Secret resource being referred to.
  17815. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17816. maxLength: 63
  17817. minLength: 1
  17818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17819. type: string
  17820. type: object
  17821. required:
  17822. - appId
  17823. - appSecret
  17824. type: object
  17825. required:
  17826. - secretRef
  17827. type: object
  17828. insecure:
  17829. description: |-
  17830. Insecure allows connecting to DVLS over plain HTTP.
  17831. This is NOT RECOMMENDED for production use.
  17832. Set to true only if you understand the security implications.
  17833. type: boolean
  17834. serverUrl:
  17835. description: ServerURL is the DVLS instance URL (e.g., https://dvls.example.com).
  17836. type: string
  17837. vault:
  17838. description: |-
  17839. Vault is the name or UUID of the vault to fetch secrets from.
  17840. When omitted, the vault must be specified in the secret key using the legacy format "<vault-id>/<entry-id>".
  17841. type: string
  17842. required:
  17843. - auth
  17844. - serverUrl
  17845. type: object
  17846. fake:
  17847. description: Fake configures a store with static key/value pairs
  17848. properties:
  17849. data:
  17850. items:
  17851. description: FakeProviderData defines a key-value pair with optional version for the fake provider.
  17852. properties:
  17853. key:
  17854. type: string
  17855. value:
  17856. type: string
  17857. version:
  17858. type: string
  17859. required:
  17860. - key
  17861. - value
  17862. type: object
  17863. type: array
  17864. validationResult:
  17865. description: ValidationResult is defined type for the number of validation results.
  17866. type: integer
  17867. required:
  17868. - data
  17869. type: object
  17870. fortanix:
  17871. description: Fortanix configures this store to sync secrets using the Fortanix provider
  17872. properties:
  17873. apiKey:
  17874. description: APIKey is the API token to access SDKMS Applications.
  17875. properties:
  17876. secretRef:
  17877. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  17878. properties:
  17879. key:
  17880. description: |-
  17881. A key in the referenced Secret.
  17882. Some instances of this field may be defaulted, in others it may be required.
  17883. maxLength: 253
  17884. minLength: 1
  17885. pattern: ^[-._a-zA-Z0-9]+$
  17886. type: string
  17887. name:
  17888. description: The name of the Secret resource being referred to.
  17889. maxLength: 253
  17890. minLength: 1
  17891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17892. type: string
  17893. namespace:
  17894. description: |-
  17895. The namespace of the Secret resource being referred to.
  17896. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17897. maxLength: 63
  17898. minLength: 1
  17899. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17900. type: string
  17901. type: object
  17902. type: object
  17903. apiUrl:
  17904. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  17905. type: string
  17906. type: object
  17907. gcpsm:
  17908. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  17909. properties:
  17910. auth:
  17911. description: Auth defines the information necessary to authenticate against GCP
  17912. properties:
  17913. secretRef:
  17914. description: GCPSMAuthSecretRef contains the secret references for GCP Secret Manager authentication.
  17915. properties:
  17916. secretAccessKeySecretRef:
  17917. description: The SecretAccessKey is used for authentication
  17918. properties:
  17919. key:
  17920. description: |-
  17921. A key in the referenced Secret.
  17922. Some instances of this field may be defaulted, in others it may be required.
  17923. maxLength: 253
  17924. minLength: 1
  17925. pattern: ^[-._a-zA-Z0-9]+$
  17926. type: string
  17927. name:
  17928. description: The name of the Secret resource being referred to.
  17929. maxLength: 253
  17930. minLength: 1
  17931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17932. type: string
  17933. namespace:
  17934. description: |-
  17935. The namespace of the Secret resource being referred to.
  17936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17937. maxLength: 63
  17938. minLength: 1
  17939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17940. type: string
  17941. type: object
  17942. type: object
  17943. workloadIdentity:
  17944. description: GCPWorkloadIdentity defines configuration for workload identity authentication to GCP.
  17945. properties:
  17946. clusterLocation:
  17947. description: |-
  17948. ClusterLocation is the location of the cluster
  17949. If not specified, it fetches information from the metadata server
  17950. type: string
  17951. clusterName:
  17952. description: |-
  17953. ClusterName is the name of the cluster
  17954. If not specified, it fetches information from the metadata server
  17955. type: string
  17956. clusterProjectID:
  17957. description: |-
  17958. ClusterProjectID is the project ID of the cluster
  17959. If not specified, it fetches information from the metadata server
  17960. type: string
  17961. serviceAccountRef:
  17962. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  17963. properties:
  17964. audiences:
  17965. description: |-
  17966. Audience specifies the `aud` claim for the service account token
  17967. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  17968. then this audiences will be appended to the list
  17969. items:
  17970. type: string
  17971. type: array
  17972. name:
  17973. description: The name of the ServiceAccount resource being referred to.
  17974. maxLength: 253
  17975. minLength: 1
  17976. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17977. type: string
  17978. namespace:
  17979. description: |-
  17980. Namespace of the resource being referred to.
  17981. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17982. maxLength: 63
  17983. minLength: 1
  17984. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17985. type: string
  17986. required:
  17987. - name
  17988. type: object
  17989. required:
  17990. - serviceAccountRef
  17991. type: object
  17992. workloadIdentityFederation:
  17993. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  17994. properties:
  17995. audience:
  17996. description: |-
  17997. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  17998. If specified, Audience found in the external account credential config will be overridden with the configured value.
  17999. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  18000. type: string
  18001. awsSecurityCredentials:
  18002. description: |-
  18003. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  18004. when using the AWS metadata server is not an option.
  18005. properties:
  18006. awsCredentialsSecretRef:
  18007. description: |-
  18008. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  18009. Secret should be created with below names for keys
  18010. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  18011. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  18012. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  18013. properties:
  18014. name:
  18015. description: name of the secret.
  18016. maxLength: 253
  18017. minLength: 1
  18018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18019. type: string
  18020. namespace:
  18021. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  18022. maxLength: 63
  18023. minLength: 1
  18024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18025. type: string
  18026. required:
  18027. - name
  18028. type: object
  18029. region:
  18030. description: region is for configuring the AWS region to be used.
  18031. example: ap-south-1
  18032. maxLength: 50
  18033. minLength: 1
  18034. pattern: ^[a-z0-9-]+$
  18035. type: string
  18036. required:
  18037. - awsCredentialsSecretRef
  18038. - region
  18039. type: object
  18040. credConfig:
  18041. description: |-
  18042. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  18043. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  18044. serviceAccountRef must be used by providing operators service account details.
  18045. properties:
  18046. key:
  18047. description: key name holding the external account credential config.
  18048. maxLength: 253
  18049. minLength: 1
  18050. pattern: ^[-._a-zA-Z0-9]+$
  18051. type: string
  18052. name:
  18053. description: name of the configmap.
  18054. maxLength: 253
  18055. minLength: 1
  18056. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18057. type: string
  18058. namespace:
  18059. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  18060. maxLength: 63
  18061. minLength: 1
  18062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18063. type: string
  18064. required:
  18065. - key
  18066. - name
  18067. type: object
  18068. externalTokenEndpoint:
  18069. description: |-
  18070. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  18071. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  18072. URL is having the expected value.
  18073. type: string
  18074. gcpServiceAccountEmail:
  18075. description: |-
  18076. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  18077. after Workload Identity Federation. Use this to grant access through the service account's
  18078. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  18079. service_account_impersonation_url in the external account JSON from credConfig;
  18080. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  18081. on that ServiceAccount.
  18082. example: my-gsa@my-project.iam.gserviceaccount.com
  18083. minLength: 1
  18084. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  18085. type: string
  18086. serviceAccountRef:
  18087. description: |-
  18088. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  18089. when Kubernetes is configured as provider in workload identity pool.
  18090. properties:
  18091. audiences:
  18092. description: |-
  18093. Audience specifies the `aud` claim for the service account token
  18094. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  18095. then this audiences will be appended to the list
  18096. items:
  18097. type: string
  18098. type: array
  18099. name:
  18100. description: The name of the ServiceAccount resource being referred to.
  18101. maxLength: 253
  18102. minLength: 1
  18103. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18104. type: string
  18105. namespace:
  18106. description: |-
  18107. Namespace of the resource being referred to.
  18108. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18109. maxLength: 63
  18110. minLength: 1
  18111. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18112. type: string
  18113. required:
  18114. - name
  18115. type: object
  18116. type: object
  18117. type: object
  18118. location:
  18119. description: Location optionally defines a location for a secret
  18120. type: string
  18121. projectID:
  18122. description: ProjectID project where secret is located
  18123. type: string
  18124. secretVersionSelectionPolicy:
  18125. default: LatestOrFail
  18126. description: |-
  18127. SecretVersionSelectionPolicy specifies how the provider selects a secret version
  18128. when "latest" is disabled or destroyed.
  18129. Possible values are:
  18130. - LatestOrFail: the provider always uses "latest", or fails if that version is disabled/destroyed.
  18131. - LatestOrFetch: the provider falls back to fetching the latest version if the version is DESTROYED or DISABLED
  18132. type: string
  18133. type: object
  18134. github:
  18135. description: |-
  18136. Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  18137. Note: This provider only supports write operations (PushSecret) and cannot fetch secrets from GitHub
  18138. properties:
  18139. appID:
  18140. description: appID specifies the Github APP that will be used to authenticate the client
  18141. format: int64
  18142. type: integer
  18143. auth:
  18144. description: auth configures how secret-manager authenticates with a Github instance.
  18145. properties:
  18146. privateKey:
  18147. description: |-
  18148. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18149. In some instances, `key` is a required field.
  18150. properties:
  18151. key:
  18152. description: |-
  18153. A key in the referenced Secret.
  18154. Some instances of this field may be defaulted, in others it may be required.
  18155. maxLength: 253
  18156. minLength: 1
  18157. pattern: ^[-._a-zA-Z0-9]+$
  18158. type: string
  18159. name:
  18160. description: The name of the Secret resource being referred to.
  18161. maxLength: 253
  18162. minLength: 1
  18163. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18164. type: string
  18165. namespace:
  18166. description: |-
  18167. The namespace of the Secret resource being referred to.
  18168. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18169. maxLength: 63
  18170. minLength: 1
  18171. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18172. type: string
  18173. type: object
  18174. required:
  18175. - privateKey
  18176. type: object
  18177. environment:
  18178. description: environment will be used to fetch secrets from a particular environment within a github repository
  18179. type: string
  18180. installationID:
  18181. description: installationID specifies the Github APP installation that will be used to authenticate the client
  18182. format: int64
  18183. type: integer
  18184. orgSecretVisibility:
  18185. description: |-
  18186. orgSecretVisibility controls the visibility of organization secrets pushed via PushSecret.
  18187. Valid values are "all" or "private".
  18188. When unset, new secrets are created with visibility "all" and existing secrets preserve
  18189. whatever visibility they already have in GitHub.
  18190. enum:
  18191. - all
  18192. - private
  18193. type: string
  18194. organization:
  18195. description: organization will be used to fetch secrets from the Github organization
  18196. type: string
  18197. repository:
  18198. description: repository will be used to fetch secrets from the Github repository within an organization
  18199. type: string
  18200. uploadURL:
  18201. description: Upload URL for enterprise instances. Default to URL.
  18202. type: string
  18203. url:
  18204. default: https://github.com/
  18205. description: URL configures the Github instance URL. Defaults to https://github.com/.
  18206. type: string
  18207. required:
  18208. - appID
  18209. - auth
  18210. - installationID
  18211. - organization
  18212. type: object
  18213. gitlab:
  18214. description: GitLab configures this store to sync secrets using GitLab Variables provider
  18215. properties:
  18216. auth:
  18217. description: Auth configures how secret-manager authenticates with a GitLab instance.
  18218. properties:
  18219. SecretRef:
  18220. description: GitlabSecretRef contains the secret reference for GitLab authentication credentials.
  18221. properties:
  18222. accessToken:
  18223. description: AccessToken is used for authentication.
  18224. properties:
  18225. key:
  18226. description: |-
  18227. A key in the referenced Secret.
  18228. Some instances of this field may be defaulted, in others it may be required.
  18229. maxLength: 253
  18230. minLength: 1
  18231. pattern: ^[-._a-zA-Z0-9]+$
  18232. type: string
  18233. name:
  18234. description: The name of the Secret resource being referred to.
  18235. maxLength: 253
  18236. minLength: 1
  18237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18238. type: string
  18239. namespace:
  18240. description: |-
  18241. The namespace of the Secret resource being referred to.
  18242. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18243. maxLength: 63
  18244. minLength: 1
  18245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18246. type: string
  18247. type: object
  18248. type: object
  18249. required:
  18250. - SecretRef
  18251. type: object
  18252. caBundle:
  18253. description: |-
  18254. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  18255. can be performed.
  18256. format: byte
  18257. type: string
  18258. caProvider:
  18259. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  18260. properties:
  18261. key:
  18262. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  18263. maxLength: 253
  18264. minLength: 1
  18265. pattern: ^[-._a-zA-Z0-9]+$
  18266. type: string
  18267. name:
  18268. description: The name of the object located at the provider type.
  18269. maxLength: 253
  18270. minLength: 1
  18271. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18272. type: string
  18273. namespace:
  18274. description: |-
  18275. The namespace the Provider type is in.
  18276. Can only be defined when used in a ClusterSecretStore.
  18277. maxLength: 63
  18278. minLength: 1
  18279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18280. type: string
  18281. type:
  18282. description: The type of provider to use such as "Secret", or "ConfigMap".
  18283. enum:
  18284. - Secret
  18285. - ConfigMap
  18286. type: string
  18287. required:
  18288. - name
  18289. - type
  18290. type: object
  18291. environment:
  18292. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  18293. type: string
  18294. groupIDs:
  18295. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  18296. items:
  18297. type: string
  18298. type: array
  18299. inheritFromGroups:
  18300. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  18301. type: boolean
  18302. projectID:
  18303. description: ProjectID specifies a project where secrets are located.
  18304. type: string
  18305. url:
  18306. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  18307. type: string
  18308. required:
  18309. - auth
  18310. type: object
  18311. ibm:
  18312. description: IBM configures this store to sync secrets using IBM Cloud provider
  18313. properties:
  18314. auth:
  18315. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  18316. maxProperties: 1
  18317. minProperties: 1
  18318. properties:
  18319. containerAuth:
  18320. description: IBMAuthContainerAuth defines container-based authentication with IAM Trusted Profile.
  18321. properties:
  18322. iamEndpoint:
  18323. type: string
  18324. profile:
  18325. description: the IBM Trusted Profile
  18326. type: string
  18327. tokenLocation:
  18328. description: Location the token is mounted on the pod
  18329. type: string
  18330. required:
  18331. - profile
  18332. type: object
  18333. secretRef:
  18334. description: IBMAuthSecretRef contains the secret reference for IBM Cloud API key authentication.
  18335. properties:
  18336. iamEndpoint:
  18337. description: The IAM endpoint used to obain a token
  18338. type: string
  18339. secretApiKeySecretRef:
  18340. description: The SecretAccessKey is used for authentication
  18341. properties:
  18342. key:
  18343. description: |-
  18344. A key in the referenced Secret.
  18345. Some instances of this field may be defaulted, in others it may be required.
  18346. maxLength: 253
  18347. minLength: 1
  18348. pattern: ^[-._a-zA-Z0-9]+$
  18349. type: string
  18350. name:
  18351. description: The name of the Secret resource being referred to.
  18352. maxLength: 253
  18353. minLength: 1
  18354. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18355. type: string
  18356. namespace:
  18357. description: |-
  18358. The namespace of the Secret resource being referred to.
  18359. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18360. maxLength: 63
  18361. minLength: 1
  18362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18363. type: string
  18364. type: object
  18365. type: object
  18366. type: object
  18367. serviceUrl:
  18368. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  18369. type: string
  18370. required:
  18371. - auth
  18372. type: object
  18373. infisical:
  18374. description: Infisical configures this store to sync secrets using the Infisical provider
  18375. properties:
  18376. auth:
  18377. description: Auth configures how the Operator authenticates with the Infisical API
  18378. properties:
  18379. awsAuthCredentials:
  18380. description: AwsAuthCredentials represents the credentials for AWS authentication.
  18381. properties:
  18382. identityId:
  18383. description: |-
  18384. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18385. In some instances, `key` is a required field.
  18386. properties:
  18387. key:
  18388. description: |-
  18389. A key in the referenced Secret.
  18390. Some instances of this field may be defaulted, in others it may be required.
  18391. maxLength: 253
  18392. minLength: 1
  18393. pattern: ^[-._a-zA-Z0-9]+$
  18394. type: string
  18395. name:
  18396. description: The name of the Secret resource being referred to.
  18397. maxLength: 253
  18398. minLength: 1
  18399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18400. type: string
  18401. namespace:
  18402. description: |-
  18403. The namespace of the Secret resource being referred to.
  18404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18405. maxLength: 63
  18406. minLength: 1
  18407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18408. type: string
  18409. type: object
  18410. required:
  18411. - identityId
  18412. type: object
  18413. azureAuthCredentials:
  18414. description: AzureAuthCredentials represents the credentials for Azure authentication.
  18415. properties:
  18416. identityId:
  18417. description: |-
  18418. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18419. In some instances, `key` is a required field.
  18420. properties:
  18421. key:
  18422. description: |-
  18423. A key in the referenced Secret.
  18424. Some instances of this field may be defaulted, in others it may be required.
  18425. maxLength: 253
  18426. minLength: 1
  18427. pattern: ^[-._a-zA-Z0-9]+$
  18428. type: string
  18429. name:
  18430. description: The name of the Secret resource being referred to.
  18431. maxLength: 253
  18432. minLength: 1
  18433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18434. type: string
  18435. namespace:
  18436. description: |-
  18437. The namespace of the Secret resource being referred to.
  18438. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18439. maxLength: 63
  18440. minLength: 1
  18441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18442. type: string
  18443. type: object
  18444. resource:
  18445. description: |-
  18446. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18447. In some instances, `key` is a required field.
  18448. properties:
  18449. key:
  18450. description: |-
  18451. A key in the referenced Secret.
  18452. Some instances of this field may be defaulted, in others it may be required.
  18453. maxLength: 253
  18454. minLength: 1
  18455. pattern: ^[-._a-zA-Z0-9]+$
  18456. type: string
  18457. name:
  18458. description: The name of the Secret resource being referred to.
  18459. maxLength: 253
  18460. minLength: 1
  18461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18462. type: string
  18463. namespace:
  18464. description: |-
  18465. The namespace of the Secret resource being referred to.
  18466. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18467. maxLength: 63
  18468. minLength: 1
  18469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18470. type: string
  18471. type: object
  18472. required:
  18473. - identityId
  18474. type: object
  18475. gcpIamAuthCredentials:
  18476. description: GcpIamAuthCredentials represents the credentials for GCP IAM authentication.
  18477. properties:
  18478. identityId:
  18479. description: |-
  18480. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18481. In some instances, `key` is a required field.
  18482. properties:
  18483. key:
  18484. description: |-
  18485. A key in the referenced Secret.
  18486. Some instances of this field may be defaulted, in others it may be required.
  18487. maxLength: 253
  18488. minLength: 1
  18489. pattern: ^[-._a-zA-Z0-9]+$
  18490. type: string
  18491. name:
  18492. description: The name of the Secret resource being referred to.
  18493. maxLength: 253
  18494. minLength: 1
  18495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18496. type: string
  18497. namespace:
  18498. description: |-
  18499. The namespace of the Secret resource being referred to.
  18500. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18501. maxLength: 63
  18502. minLength: 1
  18503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18504. type: string
  18505. type: object
  18506. serviceAccountKeyFilePath:
  18507. description: |-
  18508. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18509. In some instances, `key` is a required field.
  18510. properties:
  18511. key:
  18512. description: |-
  18513. A key in the referenced Secret.
  18514. Some instances of this field may be defaulted, in others it may be required.
  18515. maxLength: 253
  18516. minLength: 1
  18517. pattern: ^[-._a-zA-Z0-9]+$
  18518. type: string
  18519. name:
  18520. description: The name of the Secret resource being referred to.
  18521. maxLength: 253
  18522. minLength: 1
  18523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18524. type: string
  18525. namespace:
  18526. description: |-
  18527. The namespace of the Secret resource being referred to.
  18528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18529. maxLength: 63
  18530. minLength: 1
  18531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18532. type: string
  18533. type: object
  18534. required:
  18535. - identityId
  18536. - serviceAccountKeyFilePath
  18537. type: object
  18538. gcpIdTokenAuthCredentials:
  18539. description: GcpIDTokenAuthCredentials represents the credentials for GCP ID token authentication.
  18540. properties:
  18541. identityId:
  18542. description: |-
  18543. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18544. In some instances, `key` is a required field.
  18545. properties:
  18546. key:
  18547. description: |-
  18548. A key in the referenced Secret.
  18549. Some instances of this field may be defaulted, in others it may be required.
  18550. maxLength: 253
  18551. minLength: 1
  18552. pattern: ^[-._a-zA-Z0-9]+$
  18553. type: string
  18554. name:
  18555. description: The name of the Secret resource being referred to.
  18556. maxLength: 253
  18557. minLength: 1
  18558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18559. type: string
  18560. namespace:
  18561. description: |-
  18562. The namespace of the Secret resource being referred to.
  18563. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18564. maxLength: 63
  18565. minLength: 1
  18566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18567. type: string
  18568. type: object
  18569. required:
  18570. - identityId
  18571. type: object
  18572. jwtAuthCredentials:
  18573. description: JwtAuthCredentials represents the credentials for JWT authentication.
  18574. properties:
  18575. identityId:
  18576. description: |-
  18577. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18578. In some instances, `key` is a required field.
  18579. properties:
  18580. key:
  18581. description: |-
  18582. A key in the referenced Secret.
  18583. Some instances of this field may be defaulted, in others it may be required.
  18584. maxLength: 253
  18585. minLength: 1
  18586. pattern: ^[-._a-zA-Z0-9]+$
  18587. type: string
  18588. name:
  18589. description: The name of the Secret resource being referred to.
  18590. maxLength: 253
  18591. minLength: 1
  18592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18593. type: string
  18594. namespace:
  18595. description: |-
  18596. The namespace of the Secret resource being referred to.
  18597. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18598. maxLength: 63
  18599. minLength: 1
  18600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18601. type: string
  18602. type: object
  18603. jwt:
  18604. description: |-
  18605. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18606. In some instances, `key` is a required field.
  18607. properties:
  18608. key:
  18609. description: |-
  18610. A key in the referenced Secret.
  18611. Some instances of this field may be defaulted, in others it may be required.
  18612. maxLength: 253
  18613. minLength: 1
  18614. pattern: ^[-._a-zA-Z0-9]+$
  18615. type: string
  18616. name:
  18617. description: The name of the Secret resource being referred to.
  18618. maxLength: 253
  18619. minLength: 1
  18620. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18621. type: string
  18622. namespace:
  18623. description: |-
  18624. The namespace of the Secret resource being referred to.
  18625. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18626. maxLength: 63
  18627. minLength: 1
  18628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18629. type: string
  18630. type: object
  18631. required:
  18632. - identityId
  18633. - jwt
  18634. type: object
  18635. kubernetesAuthCredentials:
  18636. description: KubernetesAuthCredentials represents the credentials for Kubernetes authentication.
  18637. properties:
  18638. identityId:
  18639. description: |-
  18640. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18641. In some instances, `key` is a required field.
  18642. properties:
  18643. key:
  18644. description: |-
  18645. A key in the referenced Secret.
  18646. Some instances of this field may be defaulted, in others it may be required.
  18647. maxLength: 253
  18648. minLength: 1
  18649. pattern: ^[-._a-zA-Z0-9]+$
  18650. type: string
  18651. name:
  18652. description: The name of the Secret resource being referred to.
  18653. maxLength: 253
  18654. minLength: 1
  18655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18656. type: string
  18657. namespace:
  18658. description: |-
  18659. The namespace of the Secret resource being referred to.
  18660. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18661. maxLength: 63
  18662. minLength: 1
  18663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18664. type: string
  18665. type: object
  18666. serviceAccountTokenPath:
  18667. description: |-
  18668. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18669. In some instances, `key` is a required field.
  18670. properties:
  18671. key:
  18672. description: |-
  18673. A key in the referenced Secret.
  18674. Some instances of this field may be defaulted, in others it may be required.
  18675. maxLength: 253
  18676. minLength: 1
  18677. pattern: ^[-._a-zA-Z0-9]+$
  18678. type: string
  18679. name:
  18680. description: The name of the Secret resource being referred to.
  18681. maxLength: 253
  18682. minLength: 1
  18683. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18684. type: string
  18685. namespace:
  18686. description: |-
  18687. The namespace of the Secret resource being referred to.
  18688. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18689. maxLength: 63
  18690. minLength: 1
  18691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18692. type: string
  18693. type: object
  18694. required:
  18695. - identityId
  18696. type: object
  18697. ldapAuthCredentials:
  18698. description: LdapAuthCredentials represents the credentials for LDAP authentication.
  18699. properties:
  18700. identityId:
  18701. description: |-
  18702. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18703. In some instances, `key` is a required field.
  18704. properties:
  18705. key:
  18706. description: |-
  18707. A key in the referenced Secret.
  18708. Some instances of this field may be defaulted, in others it may be required.
  18709. maxLength: 253
  18710. minLength: 1
  18711. pattern: ^[-._a-zA-Z0-9]+$
  18712. type: string
  18713. name:
  18714. description: The name of the Secret resource being referred to.
  18715. maxLength: 253
  18716. minLength: 1
  18717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18718. type: string
  18719. namespace:
  18720. description: |-
  18721. The namespace of the Secret resource being referred to.
  18722. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18723. maxLength: 63
  18724. minLength: 1
  18725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18726. type: string
  18727. type: object
  18728. ldapPassword:
  18729. description: |-
  18730. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18731. In some instances, `key` is a required field.
  18732. properties:
  18733. key:
  18734. description: |-
  18735. A key in the referenced Secret.
  18736. Some instances of this field may be defaulted, in others it may be required.
  18737. maxLength: 253
  18738. minLength: 1
  18739. pattern: ^[-._a-zA-Z0-9]+$
  18740. type: string
  18741. name:
  18742. description: The name of the Secret resource being referred to.
  18743. maxLength: 253
  18744. minLength: 1
  18745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18746. type: string
  18747. namespace:
  18748. description: |-
  18749. The namespace of the Secret resource being referred to.
  18750. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18751. maxLength: 63
  18752. minLength: 1
  18753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18754. type: string
  18755. type: object
  18756. ldapUsername:
  18757. description: |-
  18758. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18759. In some instances, `key` is a required field.
  18760. properties:
  18761. key:
  18762. description: |-
  18763. A key in the referenced Secret.
  18764. Some instances of this field may be defaulted, in others it may be required.
  18765. maxLength: 253
  18766. minLength: 1
  18767. pattern: ^[-._a-zA-Z0-9]+$
  18768. type: string
  18769. name:
  18770. description: The name of the Secret resource being referred to.
  18771. maxLength: 253
  18772. minLength: 1
  18773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18774. type: string
  18775. namespace:
  18776. description: |-
  18777. The namespace of the Secret resource being referred to.
  18778. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18779. maxLength: 63
  18780. minLength: 1
  18781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18782. type: string
  18783. type: object
  18784. required:
  18785. - identityId
  18786. - ldapPassword
  18787. - ldapUsername
  18788. type: object
  18789. ociAuthCredentials:
  18790. description: OciAuthCredentials represents the credentials for OCI authentication.
  18791. properties:
  18792. fingerprint:
  18793. description: |-
  18794. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18795. In some instances, `key` is a required field.
  18796. properties:
  18797. key:
  18798. description: |-
  18799. A key in the referenced Secret.
  18800. Some instances of this field may be defaulted, in others it may be required.
  18801. maxLength: 253
  18802. minLength: 1
  18803. pattern: ^[-._a-zA-Z0-9]+$
  18804. type: string
  18805. name:
  18806. description: The name of the Secret resource being referred to.
  18807. maxLength: 253
  18808. minLength: 1
  18809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18810. type: string
  18811. namespace:
  18812. description: |-
  18813. The namespace of the Secret resource being referred to.
  18814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18815. maxLength: 63
  18816. minLength: 1
  18817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18818. type: string
  18819. type: object
  18820. identityId:
  18821. description: |-
  18822. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18823. In some instances, `key` is a required field.
  18824. properties:
  18825. key:
  18826. description: |-
  18827. A key in the referenced Secret.
  18828. Some instances of this field may be defaulted, in others it may be required.
  18829. maxLength: 253
  18830. minLength: 1
  18831. pattern: ^[-._a-zA-Z0-9]+$
  18832. type: string
  18833. name:
  18834. description: The name of the Secret resource being referred to.
  18835. maxLength: 253
  18836. minLength: 1
  18837. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18838. type: string
  18839. namespace:
  18840. description: |-
  18841. The namespace of the Secret resource being referred to.
  18842. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18843. maxLength: 63
  18844. minLength: 1
  18845. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18846. type: string
  18847. type: object
  18848. privateKey:
  18849. description: |-
  18850. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18851. In some instances, `key` is a required field.
  18852. properties:
  18853. key:
  18854. description: |-
  18855. A key in the referenced Secret.
  18856. Some instances of this field may be defaulted, in others it may be required.
  18857. maxLength: 253
  18858. minLength: 1
  18859. pattern: ^[-._a-zA-Z0-9]+$
  18860. type: string
  18861. name:
  18862. description: The name of the Secret resource being referred to.
  18863. maxLength: 253
  18864. minLength: 1
  18865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18866. type: string
  18867. namespace:
  18868. description: |-
  18869. The namespace of the Secret resource being referred to.
  18870. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18871. maxLength: 63
  18872. minLength: 1
  18873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18874. type: string
  18875. type: object
  18876. privateKeyPassphrase:
  18877. description: |-
  18878. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18879. In some instances, `key` is a required field.
  18880. properties:
  18881. key:
  18882. description: |-
  18883. A key in the referenced Secret.
  18884. Some instances of this field may be defaulted, in others it may be required.
  18885. maxLength: 253
  18886. minLength: 1
  18887. pattern: ^[-._a-zA-Z0-9]+$
  18888. type: string
  18889. name:
  18890. description: The name of the Secret resource being referred to.
  18891. maxLength: 253
  18892. minLength: 1
  18893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18894. type: string
  18895. namespace:
  18896. description: |-
  18897. The namespace of the Secret resource being referred to.
  18898. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18899. maxLength: 63
  18900. minLength: 1
  18901. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18902. type: string
  18903. type: object
  18904. region:
  18905. description: |-
  18906. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18907. In some instances, `key` is a required field.
  18908. properties:
  18909. key:
  18910. description: |-
  18911. A key in the referenced Secret.
  18912. Some instances of this field may be defaulted, in others it may be required.
  18913. maxLength: 253
  18914. minLength: 1
  18915. pattern: ^[-._a-zA-Z0-9]+$
  18916. type: string
  18917. name:
  18918. description: The name of the Secret resource being referred to.
  18919. maxLength: 253
  18920. minLength: 1
  18921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18922. type: string
  18923. namespace:
  18924. description: |-
  18925. The namespace of the Secret resource being referred to.
  18926. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18927. maxLength: 63
  18928. minLength: 1
  18929. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18930. type: string
  18931. type: object
  18932. tenancyId:
  18933. description: |-
  18934. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18935. In some instances, `key` is a required field.
  18936. properties:
  18937. key:
  18938. description: |-
  18939. A key in the referenced Secret.
  18940. Some instances of this field may be defaulted, in others it may be required.
  18941. maxLength: 253
  18942. minLength: 1
  18943. pattern: ^[-._a-zA-Z0-9]+$
  18944. type: string
  18945. name:
  18946. description: The name of the Secret resource being referred to.
  18947. maxLength: 253
  18948. minLength: 1
  18949. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18950. type: string
  18951. namespace:
  18952. description: |-
  18953. The namespace of the Secret resource being referred to.
  18954. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18955. maxLength: 63
  18956. minLength: 1
  18957. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18958. type: string
  18959. type: object
  18960. userId:
  18961. description: |-
  18962. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  18963. In some instances, `key` is a required field.
  18964. properties:
  18965. key:
  18966. description: |-
  18967. A key in the referenced Secret.
  18968. Some instances of this field may be defaulted, in others it may be required.
  18969. maxLength: 253
  18970. minLength: 1
  18971. pattern: ^[-._a-zA-Z0-9]+$
  18972. type: string
  18973. name:
  18974. description: The name of the Secret resource being referred to.
  18975. maxLength: 253
  18976. minLength: 1
  18977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  18978. type: string
  18979. namespace:
  18980. description: |-
  18981. The namespace of the Secret resource being referred to.
  18982. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  18983. maxLength: 63
  18984. minLength: 1
  18985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  18986. type: string
  18987. type: object
  18988. required:
  18989. - fingerprint
  18990. - identityId
  18991. - privateKey
  18992. - region
  18993. - tenancyId
  18994. - userId
  18995. type: object
  18996. tokenAuthCredentials:
  18997. description: TokenAuthCredentials represents the credentials for access token-based authentication.
  18998. properties:
  18999. accessToken:
  19000. description: |-
  19001. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19002. In some instances, `key` is a required field.
  19003. properties:
  19004. key:
  19005. description: |-
  19006. A key in the referenced Secret.
  19007. Some instances of this field may be defaulted, in others it may be required.
  19008. maxLength: 253
  19009. minLength: 1
  19010. pattern: ^[-._a-zA-Z0-9]+$
  19011. type: string
  19012. name:
  19013. description: The name of the Secret resource being referred to.
  19014. maxLength: 253
  19015. minLength: 1
  19016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19017. type: string
  19018. namespace:
  19019. description: |-
  19020. The namespace of the Secret resource being referred to.
  19021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19022. maxLength: 63
  19023. minLength: 1
  19024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19025. type: string
  19026. type: object
  19027. required:
  19028. - accessToken
  19029. type: object
  19030. universalAuthCredentials:
  19031. description: UniversalAuthCredentials represents the client credentials for universal authentication.
  19032. properties:
  19033. clientId:
  19034. description: |-
  19035. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19036. In some instances, `key` is a required field.
  19037. properties:
  19038. key:
  19039. description: |-
  19040. A key in the referenced Secret.
  19041. Some instances of this field may be defaulted, in others it may be required.
  19042. maxLength: 253
  19043. minLength: 1
  19044. pattern: ^[-._a-zA-Z0-9]+$
  19045. type: string
  19046. name:
  19047. description: The name of the Secret resource being referred to.
  19048. maxLength: 253
  19049. minLength: 1
  19050. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19051. type: string
  19052. namespace:
  19053. description: |-
  19054. The namespace of the Secret resource being referred to.
  19055. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19056. maxLength: 63
  19057. minLength: 1
  19058. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19059. type: string
  19060. type: object
  19061. clientSecret:
  19062. description: |-
  19063. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19064. In some instances, `key` is a required field.
  19065. properties:
  19066. key:
  19067. description: |-
  19068. A key in the referenced Secret.
  19069. Some instances of this field may be defaulted, in others it may be required.
  19070. maxLength: 253
  19071. minLength: 1
  19072. pattern: ^[-._a-zA-Z0-9]+$
  19073. type: string
  19074. name:
  19075. description: The name of the Secret resource being referred to.
  19076. maxLength: 253
  19077. minLength: 1
  19078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19079. type: string
  19080. namespace:
  19081. description: |-
  19082. The namespace of the Secret resource being referred to.
  19083. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19084. maxLength: 63
  19085. minLength: 1
  19086. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19087. type: string
  19088. type: object
  19089. required:
  19090. - clientId
  19091. - clientSecret
  19092. type: object
  19093. type: object
  19094. caBundle:
  19095. description: |-
  19096. CABundle is a PEM-encoded CA certificate bundle used to validate
  19097. the Infisical server's TLS certificate. Mutually exclusive with CAProvider.
  19098. format: byte
  19099. type: string
  19100. caProvider:
  19101. description: |-
  19102. CAProvider is a reference to a Secret or ConfigMap that contains a CA certificate.
  19103. The certificate is used to validate the Infisical server's TLS certificate.
  19104. Mutually exclusive with CABundle.
  19105. properties:
  19106. key:
  19107. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19108. maxLength: 253
  19109. minLength: 1
  19110. pattern: ^[-._a-zA-Z0-9]+$
  19111. type: string
  19112. name:
  19113. description: The name of the object located at the provider type.
  19114. maxLength: 253
  19115. minLength: 1
  19116. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19117. type: string
  19118. namespace:
  19119. description: |-
  19120. The namespace the Provider type is in.
  19121. Can only be defined when used in a ClusterSecretStore.
  19122. maxLength: 63
  19123. minLength: 1
  19124. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19125. type: string
  19126. type:
  19127. description: The type of provider to use such as "Secret", or "ConfigMap".
  19128. enum:
  19129. - Secret
  19130. - ConfigMap
  19131. type: string
  19132. required:
  19133. - name
  19134. - type
  19135. type: object
  19136. hostAPI:
  19137. default: https://app.infisical.com/api
  19138. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  19139. type: string
  19140. secretsScope:
  19141. description: SecretsScope defines the scope of the secrets within the workspace
  19142. properties:
  19143. environmentSlug:
  19144. description: EnvironmentSlug is the required slug identifier for the environment.
  19145. type: string
  19146. expandSecretReferences:
  19147. default: true
  19148. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  19149. type: boolean
  19150. organizationSlug:
  19151. description: |-
  19152. OrganizationSlug is the optional slug that identifies the organization that will be used
  19153. during authentication. Useful for sub-organization setups
  19154. type: string
  19155. projectSlug:
  19156. description: ProjectSlug is the required slug identifier for the project.
  19157. type: string
  19158. recursive:
  19159. default: false
  19160. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  19161. type: boolean
  19162. secretsPath:
  19163. default: /
  19164. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  19165. type: string
  19166. required:
  19167. - environmentSlug
  19168. - projectSlug
  19169. type: object
  19170. required:
  19171. - auth
  19172. - secretsScope
  19173. type: object
  19174. keepersecurity:
  19175. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  19176. properties:
  19177. authRef:
  19178. description: |-
  19179. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19180. In some instances, `key` is a required field.
  19181. properties:
  19182. key:
  19183. description: |-
  19184. A key in the referenced Secret.
  19185. Some instances of this field may be defaulted, in others it may be required.
  19186. maxLength: 253
  19187. minLength: 1
  19188. pattern: ^[-._a-zA-Z0-9]+$
  19189. type: string
  19190. name:
  19191. description: The name of the Secret resource being referred to.
  19192. maxLength: 253
  19193. minLength: 1
  19194. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19195. type: string
  19196. namespace:
  19197. description: |-
  19198. The namespace of the Secret resource being referred to.
  19199. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19200. maxLength: 63
  19201. minLength: 1
  19202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19203. type: string
  19204. type: object
  19205. folderID:
  19206. type: string
  19207. getByTitleFallback:
  19208. type: boolean
  19209. required:
  19210. - authRef
  19211. - folderID
  19212. type: object
  19213. kubernetes:
  19214. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  19215. properties:
  19216. auth:
  19217. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  19218. maxProperties: 1
  19219. minProperties: 1
  19220. properties:
  19221. cert:
  19222. description: has both clientCert and clientKey as secretKeySelector
  19223. properties:
  19224. clientCert:
  19225. description: |-
  19226. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19227. In some instances, `key` is a required field.
  19228. properties:
  19229. key:
  19230. description: |-
  19231. A key in the referenced Secret.
  19232. Some instances of this field may be defaulted, in others it may be required.
  19233. maxLength: 253
  19234. minLength: 1
  19235. pattern: ^[-._a-zA-Z0-9]+$
  19236. type: string
  19237. name:
  19238. description: The name of the Secret resource being referred to.
  19239. maxLength: 253
  19240. minLength: 1
  19241. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19242. type: string
  19243. namespace:
  19244. description: |-
  19245. The namespace of the Secret resource being referred to.
  19246. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19247. maxLength: 63
  19248. minLength: 1
  19249. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19250. type: string
  19251. type: object
  19252. clientKey:
  19253. description: |-
  19254. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19255. In some instances, `key` is a required field.
  19256. properties:
  19257. key:
  19258. description: |-
  19259. A key in the referenced Secret.
  19260. Some instances of this field may be defaulted, in others it may be required.
  19261. maxLength: 253
  19262. minLength: 1
  19263. pattern: ^[-._a-zA-Z0-9]+$
  19264. type: string
  19265. name:
  19266. description: The name of the Secret resource being referred to.
  19267. maxLength: 253
  19268. minLength: 1
  19269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19270. type: string
  19271. namespace:
  19272. description: |-
  19273. The namespace of the Secret resource being referred to.
  19274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19275. maxLength: 63
  19276. minLength: 1
  19277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19278. type: string
  19279. type: object
  19280. required:
  19281. - clientCert
  19282. - clientKey
  19283. type: object
  19284. serviceAccount:
  19285. description: points to a service account that should be used for authentication
  19286. properties:
  19287. audiences:
  19288. description: |-
  19289. Audience specifies the `aud` claim for the service account token
  19290. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  19291. then this audiences will be appended to the list
  19292. items:
  19293. type: string
  19294. type: array
  19295. name:
  19296. description: The name of the ServiceAccount resource being referred to.
  19297. maxLength: 253
  19298. minLength: 1
  19299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19300. type: string
  19301. namespace:
  19302. description: |-
  19303. Namespace of the resource being referred to.
  19304. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19305. maxLength: 63
  19306. minLength: 1
  19307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19308. type: string
  19309. required:
  19310. - name
  19311. type: object
  19312. token:
  19313. description: use static token to authenticate with
  19314. properties:
  19315. bearerToken:
  19316. description: |-
  19317. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19318. In some instances, `key` is a required field.
  19319. properties:
  19320. key:
  19321. description: |-
  19322. A key in the referenced Secret.
  19323. Some instances of this field may be defaulted, in others it may be required.
  19324. maxLength: 253
  19325. minLength: 1
  19326. pattern: ^[-._a-zA-Z0-9]+$
  19327. type: string
  19328. name:
  19329. description: The name of the Secret resource being referred to.
  19330. maxLength: 253
  19331. minLength: 1
  19332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19333. type: string
  19334. namespace:
  19335. description: |-
  19336. The namespace of the Secret resource being referred to.
  19337. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19338. maxLength: 63
  19339. minLength: 1
  19340. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19341. type: string
  19342. type: object
  19343. required:
  19344. - bearerToken
  19345. type: object
  19346. type: object
  19347. authRef:
  19348. description: A reference to a secret that contains the auth information.
  19349. properties:
  19350. key:
  19351. description: |-
  19352. A key in the referenced Secret.
  19353. Some instances of this field may be defaulted, in others it may be required.
  19354. maxLength: 253
  19355. minLength: 1
  19356. pattern: ^[-._a-zA-Z0-9]+$
  19357. type: string
  19358. name:
  19359. description: The name of the Secret resource being referred to.
  19360. maxLength: 253
  19361. minLength: 1
  19362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19363. type: string
  19364. namespace:
  19365. description: |-
  19366. The namespace of the Secret resource being referred to.
  19367. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19368. maxLength: 63
  19369. minLength: 1
  19370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19371. type: string
  19372. type: object
  19373. remoteNamespace:
  19374. default: default
  19375. description: Remote namespace to fetch the secrets from
  19376. maxLength: 63
  19377. minLength: 1
  19378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19379. type: string
  19380. server:
  19381. description: configures the Kubernetes server Address.
  19382. properties:
  19383. caBundle:
  19384. description: CABundle is a base64-encoded CA certificate
  19385. format: byte
  19386. type: string
  19387. caProvider:
  19388. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  19389. properties:
  19390. key:
  19391. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  19392. maxLength: 253
  19393. minLength: 1
  19394. pattern: ^[-._a-zA-Z0-9]+$
  19395. type: string
  19396. name:
  19397. description: The name of the object located at the provider type.
  19398. maxLength: 253
  19399. minLength: 1
  19400. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19401. type: string
  19402. namespace:
  19403. description: |-
  19404. The namespace the Provider type is in.
  19405. Can only be defined when used in a ClusterSecretStore.
  19406. maxLength: 63
  19407. minLength: 1
  19408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19409. type: string
  19410. type:
  19411. description: The type of provider to use such as "Secret", or "ConfigMap".
  19412. enum:
  19413. - Secret
  19414. - ConfigMap
  19415. type: string
  19416. required:
  19417. - name
  19418. - type
  19419. type: object
  19420. url:
  19421. default: kubernetes.default
  19422. description: configures the Kubernetes server Address.
  19423. type: string
  19424. type: object
  19425. type: object
  19426. nebiusmysterybox:
  19427. description: NebiusMysterybox configures this store to sync secrets using NebiusMysterybox provider
  19428. properties:
  19429. apiDomain:
  19430. description: NebiusMysterybox API endpoint
  19431. type: string
  19432. auth:
  19433. description: Auth defines parameters to authenticate in MysteryBox
  19434. properties:
  19435. serviceAccountCredsSecretRef:
  19436. description: |-
  19437. ServiceAccountCreds references a Kubernetes Secret key that contains a JSON
  19438. document with service account credentials used to get an IAM token.
  19439. Expected JSON structure:
  19440. {
  19441. "subject-credentials": {
  19442. "alg": "RS256",
  19443. "private-key": "-----BEGIN PRIVATE KEY-----\n<private-key>\n-----END PRIVATE KEY-----\n",
  19444. "kid": "<public-key-id>",
  19445. "iss": "<issuer-service-account-id>",
  19446. "sub": "<subject-service-account-id>"
  19447. }
  19448. }
  19449. properties:
  19450. key:
  19451. description: |-
  19452. A key in the referenced Secret.
  19453. Some instances of this field may be defaulted, in others it may be required.
  19454. maxLength: 253
  19455. minLength: 1
  19456. pattern: ^[-._a-zA-Z0-9]+$
  19457. type: string
  19458. name:
  19459. description: The name of the Secret resource being referred to.
  19460. maxLength: 253
  19461. minLength: 1
  19462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19463. type: string
  19464. namespace:
  19465. description: |-
  19466. The namespace of the Secret resource being referred to.
  19467. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19468. maxLength: 63
  19469. minLength: 1
  19470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19471. type: string
  19472. type: object
  19473. tokenSecretRef:
  19474. description: Token authenticates with Nebius Mysterybox by presenting a token.
  19475. properties:
  19476. key:
  19477. description: |-
  19478. A key in the referenced Secret.
  19479. Some instances of this field may be defaulted, in others it may be required.
  19480. maxLength: 253
  19481. minLength: 1
  19482. pattern: ^[-._a-zA-Z0-9]+$
  19483. type: string
  19484. name:
  19485. description: The name of the Secret resource being referred to.
  19486. maxLength: 253
  19487. minLength: 1
  19488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19489. type: string
  19490. namespace:
  19491. description: |-
  19492. The namespace of the Secret resource being referred to.
  19493. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19494. maxLength: 63
  19495. minLength: 1
  19496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19497. type: string
  19498. type: object
  19499. type: object
  19500. x-kubernetes-validations:
  19501. - message: either serviceAccountCredsSecretRef or tokenSecretRef must be set
  19502. rule: has(self.serviceAccountCredsSecretRef) || has(self.tokenSecretRef)
  19503. caProvider:
  19504. description: The provider for the CA bundle to use to validate NebiusMysterybox server certificate.
  19505. properties:
  19506. certSecretRef:
  19507. description: |-
  19508. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  19509. In some instances, `key` is a required field.
  19510. properties:
  19511. key:
  19512. description: |-
  19513. A key in the referenced Secret.
  19514. Some instances of this field may be defaulted, in others it may be required.
  19515. maxLength: 253
  19516. minLength: 1
  19517. pattern: ^[-._a-zA-Z0-9]+$
  19518. type: string
  19519. name:
  19520. description: The name of the Secret resource being referred to.
  19521. maxLength: 253
  19522. minLength: 1
  19523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19524. type: string
  19525. namespace:
  19526. description: |-
  19527. The namespace of the Secret resource being referred to.
  19528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19529. maxLength: 63
  19530. minLength: 1
  19531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19532. type: string
  19533. type: object
  19534. type: object
  19535. required:
  19536. - apiDomain
  19537. - auth
  19538. type: object
  19539. ngrok:
  19540. description: Ngrok configures this store to sync secrets using the ngrok provider.
  19541. properties:
  19542. apiUrl:
  19543. default: https://api.ngrok.com
  19544. description: APIURL is the URL of the ngrok API.
  19545. type: string
  19546. auth:
  19547. description: Auth configures how the ngrok provider authenticates with the ngrok API.
  19548. maxProperties: 1
  19549. minProperties: 1
  19550. properties:
  19551. apiKey:
  19552. description: APIKey is the API Key used to authenticate with ngrok. See https://ngrok.com/docs/api/#authentication
  19553. properties:
  19554. secretRef:
  19555. description: SecretRef is a reference to a secret containing the ngrok API key.
  19556. properties:
  19557. key:
  19558. description: |-
  19559. A key in the referenced Secret.
  19560. Some instances of this field may be defaulted, in others it may be required.
  19561. maxLength: 253
  19562. minLength: 1
  19563. pattern: ^[-._a-zA-Z0-9]+$
  19564. type: string
  19565. name:
  19566. description: The name of the Secret resource being referred to.
  19567. maxLength: 253
  19568. minLength: 1
  19569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19570. type: string
  19571. namespace:
  19572. description: |-
  19573. The namespace of the Secret resource being referred to.
  19574. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19575. maxLength: 63
  19576. minLength: 1
  19577. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19578. type: string
  19579. type: object
  19580. type: object
  19581. type: object
  19582. vault:
  19583. description: Vault configures the ngrok vault to sync secrets with.
  19584. properties:
  19585. name:
  19586. description: Name is the name of the ngrok vault to sync secrets with.
  19587. type: string
  19588. required:
  19589. - name
  19590. type: object
  19591. required:
  19592. - auth
  19593. - vault
  19594. type: object
  19595. onboardbase:
  19596. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  19597. properties:
  19598. apiHost:
  19599. default: https://public.onboardbase.com/api/v1/
  19600. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  19601. type: string
  19602. auth:
  19603. description: Auth configures how the Operator authenticates with the Onboardbase API
  19604. properties:
  19605. apiKeyRef:
  19606. description: |-
  19607. OnboardbaseAPIKey is the APIKey generated by an admin account.
  19608. It is used to recognize and authorize access to a project and environment within onboardbase
  19609. properties:
  19610. key:
  19611. description: |-
  19612. A key in the referenced Secret.
  19613. Some instances of this field may be defaulted, in others it may be required.
  19614. maxLength: 253
  19615. minLength: 1
  19616. pattern: ^[-._a-zA-Z0-9]+$
  19617. type: string
  19618. name:
  19619. description: The name of the Secret resource being referred to.
  19620. maxLength: 253
  19621. minLength: 1
  19622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19623. type: string
  19624. namespace:
  19625. description: |-
  19626. The namespace of the Secret resource being referred to.
  19627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19628. maxLength: 63
  19629. minLength: 1
  19630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19631. type: string
  19632. type: object
  19633. passcodeRef:
  19634. description: OnboardbasePasscode is the passcode attached to the API Key
  19635. properties:
  19636. key:
  19637. description: |-
  19638. A key in the referenced Secret.
  19639. Some instances of this field may be defaulted, in others it may be required.
  19640. maxLength: 253
  19641. minLength: 1
  19642. pattern: ^[-._a-zA-Z0-9]+$
  19643. type: string
  19644. name:
  19645. description: The name of the Secret resource being referred to.
  19646. maxLength: 253
  19647. minLength: 1
  19648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19649. type: string
  19650. namespace:
  19651. description: |-
  19652. The namespace of the Secret resource being referred to.
  19653. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19654. maxLength: 63
  19655. minLength: 1
  19656. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19657. type: string
  19658. type: object
  19659. required:
  19660. - apiKeyRef
  19661. - passcodeRef
  19662. type: object
  19663. environment:
  19664. default: development
  19665. description: Environment is the name of an environmnent within a project to pull the secrets from
  19666. type: string
  19667. project:
  19668. default: development
  19669. description: Project is an onboardbase project that the secrets should be pulled from
  19670. type: string
  19671. required:
  19672. - apiHost
  19673. - auth
  19674. - environment
  19675. - project
  19676. type: object
  19677. onepassword:
  19678. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  19679. properties:
  19680. auth:
  19681. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  19682. properties:
  19683. secretRef:
  19684. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  19685. properties:
  19686. connectTokenSecretRef:
  19687. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  19688. properties:
  19689. key:
  19690. description: |-
  19691. A key in the referenced Secret.
  19692. Some instances of this field may be defaulted, in others it may be required.
  19693. maxLength: 253
  19694. minLength: 1
  19695. pattern: ^[-._a-zA-Z0-9]+$
  19696. type: string
  19697. name:
  19698. description: The name of the Secret resource being referred to.
  19699. maxLength: 253
  19700. minLength: 1
  19701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19702. type: string
  19703. namespace:
  19704. description: |-
  19705. The namespace of the Secret resource being referred to.
  19706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19707. maxLength: 63
  19708. minLength: 1
  19709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19710. type: string
  19711. type: object
  19712. required:
  19713. - connectTokenSecretRef
  19714. type: object
  19715. required:
  19716. - secretRef
  19717. type: object
  19718. connectHost:
  19719. description: ConnectHost defines the OnePassword Connect Server to connect to
  19720. type: string
  19721. vaults:
  19722. additionalProperties:
  19723. type: integer
  19724. description: Vaults defines which OnePassword vaults to search in which order
  19725. type: object
  19726. required:
  19727. - auth
  19728. - connectHost
  19729. - vaults
  19730. type: object
  19731. onepasswordSDK:
  19732. description: OnePasswordSDK configures this store to use 1Password's new Go SDK to sync secrets.
  19733. properties:
  19734. auth:
  19735. description: Auth defines the information necessary to authenticate against OnePassword API.
  19736. properties:
  19737. serviceAccountSecretRef:
  19738. description: ServiceAccountSecretRef points to the secret containing the token to access 1Password vault.
  19739. properties:
  19740. key:
  19741. description: |-
  19742. A key in the referenced Secret.
  19743. Some instances of this field may be defaulted, in others it may be required.
  19744. maxLength: 253
  19745. minLength: 1
  19746. pattern: ^[-._a-zA-Z0-9]+$
  19747. type: string
  19748. name:
  19749. description: The name of the Secret resource being referred to.
  19750. maxLength: 253
  19751. minLength: 1
  19752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19753. type: string
  19754. namespace:
  19755. description: |-
  19756. The namespace of the Secret resource being referred to.
  19757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19758. maxLength: 63
  19759. minLength: 1
  19760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19761. type: string
  19762. type: object
  19763. required:
  19764. - serviceAccountSecretRef
  19765. type: object
  19766. cache:
  19767. description: |-
  19768. Cache configures client-side caching for read operations (GetSecret, GetSecretMap).
  19769. When enabled, secrets are cached with the specified TTL.
  19770. Write operations (PushSecret, DeleteSecret) automatically invalidate relevant cache entries.
  19771. If omitted, caching is disabled (default).
  19772. cache: {} is a valid option to set.
  19773. properties:
  19774. maxSize:
  19775. default: 100
  19776. description: |-
  19777. MaxSize is the maximum number of secrets to cache.
  19778. When the cache is full, least-recently-used entries are evicted.
  19779. minimum: 1
  19780. type: integer
  19781. ttl:
  19782. default: 5m
  19783. description: |-
  19784. TTL is the time-to-live for cached secrets.
  19785. Format: duration string (e.g., "5m", "1h", "30s")
  19786. type: string
  19787. type: object
  19788. environment:
  19789. description: |-
  19790. Environment defines the 1Password Environment ID to read variables from.
  19791. Environments are read-only: PushSecret, DeleteSecret, and SecretExists return an error when set.
  19792. Mutually exclusive with Vault.
  19793. type: string
  19794. integrationInfo:
  19795. description: |-
  19796. IntegrationInfo specifies the name and version of the integration built using the 1Password Go SDK.
  19797. If you don't know which name and version to use, use `DefaultIntegrationName` and `DefaultIntegrationVersion`, respectively.
  19798. properties:
  19799. name:
  19800. default: 1Password SDK
  19801. description: Name defaults to "1Password SDK".
  19802. type: string
  19803. version:
  19804. default: v1.0.0
  19805. description: Version defaults to "v1.0.0".
  19806. type: string
  19807. type: object
  19808. vault:
  19809. description: |-
  19810. Vault defines the vault's name or uuid to access. Do NOT add op:// prefix. This will be done automatically.
  19811. Mutually exclusive with Environment.
  19812. type: string
  19813. required:
  19814. - auth
  19815. type: object
  19816. x-kubernetes-validations:
  19817. - message: at most one of the fields in [vault environment] may be set
  19818. rule: '[has(self.vault),has(self.environment)].filter(x,x==true).size() <= 1'
  19819. openBao:
  19820. description: OpenBao configures this store to sync secrets using the OpenBao provider.
  19821. properties:
  19822. auth:
  19823. description: Auth configures how secret-manager authenticates with the OpenBao server.
  19824. properties:
  19825. appRole:
  19826. description: |-
  19827. AppRole authenticates with OpenBao using the [App Role auth mechanism],
  19828. with the role and secret stored in a Kubernetes Secret resource.
  19829. [App Role auth mechanism]: https://openbao.org/docs/auth/approle/
  19830. properties:
  19831. path:
  19832. default: approle
  19833. description: |-
  19834. Path where the App Role authentication backend is mounted
  19835. in OpenBao, e.g: "approle"
  19836. type: string
  19837. roleId:
  19838. description: |-
  19839. RoleID configured in the App Role authentication backend when setting
  19840. up the authentication backend in OpenBao.
  19841. minLength: 1
  19842. type: string
  19843. roleRef:
  19844. description: |-
  19845. Reference to a key in a Secret that contains the App Role ID used
  19846. to authenticate with OpenBao.
  19847. The `key` field must be specified and denotes which entry within the Secret
  19848. resource is used as the app role id.
  19849. properties:
  19850. key:
  19851. description: |-
  19852. A key in the referenced Secret.
  19853. Some instances of this field may be defaulted, in others it may be required.
  19854. maxLength: 253
  19855. minLength: 1
  19856. pattern: ^[-._a-zA-Z0-9]+$
  19857. type: string
  19858. name:
  19859. description: The name of the Secret resource being referred to.
  19860. maxLength: 253
  19861. minLength: 1
  19862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19863. type: string
  19864. namespace:
  19865. description: |-
  19866. The namespace of the Secret resource being referred to.
  19867. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19868. maxLength: 63
  19869. minLength: 1
  19870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19871. type: string
  19872. type: object
  19873. secretRef:
  19874. description: |-
  19875. Reference to a key in a Secret that contains the App Role secret used
  19876. to authenticate with OpenBao.
  19877. The `key` field must be specified and denotes which entry within the Secret
  19878. resource is used as the app role secret.
  19879. properties:
  19880. key:
  19881. description: |-
  19882. A key in the referenced Secret.
  19883. Some instances of this field may be defaulted, in others it may be required.
  19884. maxLength: 253
  19885. minLength: 1
  19886. pattern: ^[-._a-zA-Z0-9]+$
  19887. type: string
  19888. name:
  19889. description: The name of the Secret resource being referred to.
  19890. maxLength: 253
  19891. minLength: 1
  19892. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19893. type: string
  19894. namespace:
  19895. description: |-
  19896. The namespace of the Secret resource being referred to.
  19897. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19898. maxLength: 63
  19899. minLength: 1
  19900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19901. type: string
  19902. type: object
  19903. required:
  19904. - path
  19905. - secretRef
  19906. type: object
  19907. x-kubernetes-validations:
  19908. - message: exactly one of the fields in [roleId roleRef] must be set
  19909. rule: '[has(self.roleId),has(self.roleRef)].filter(x,x==true).size() == 1'
  19910. namespace:
  19911. description: |-
  19912. Name of the [OpenBao Namespace] to authenticate to. This can be different
  19913. than the namespace your secret is in. Namespaces is a set of features
  19914. within OpenBao that allows OpenBao environments to support secure
  19915. multi-tenancy. e.g: "ns1". This will default to OpenBao.Namespace field
  19916. if set, or empty otherwise
  19917. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  19918. type: string
  19919. tokenSecretRef:
  19920. description: TokenSecretRef authenticates with OpenBao by presenting a token.
  19921. properties:
  19922. key:
  19923. description: |-
  19924. A key in the referenced Secret.
  19925. Some instances of this field may be defaulted, in others it may be required.
  19926. maxLength: 253
  19927. minLength: 1
  19928. pattern: ^[-._a-zA-Z0-9]+$
  19929. type: string
  19930. name:
  19931. description: The name of the Secret resource being referred to.
  19932. maxLength: 253
  19933. minLength: 1
  19934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19935. type: string
  19936. namespace:
  19937. description: |-
  19938. The namespace of the Secret resource being referred to.
  19939. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19940. maxLength: 63
  19941. minLength: 1
  19942. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19943. type: string
  19944. type: object
  19945. userPass:
  19946. description: UserPass authenticates with OpenBao by passing a username/password pair
  19947. properties:
  19948. path:
  19949. default: userpass
  19950. description: |-
  19951. Path where the UserPassword authentication backend is mounted
  19952. in OpenBao, e.g: "userpass"
  19953. type: string
  19954. secretRef:
  19955. description: |-
  19956. SecretRef to a key in a Secret resource containing password for the user
  19957. used to authenticate with OpenBao using the [UserPass authentication
  19958. method]
  19959. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19960. properties:
  19961. key:
  19962. description: |-
  19963. A key in the referenced Secret.
  19964. Some instances of this field may be defaulted, in others it may be required.
  19965. maxLength: 253
  19966. minLength: 1
  19967. pattern: ^[-._a-zA-Z0-9]+$
  19968. type: string
  19969. name:
  19970. description: The name of the Secret resource being referred to.
  19971. maxLength: 253
  19972. minLength: 1
  19973. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  19974. type: string
  19975. namespace:
  19976. description: |-
  19977. The namespace of the Secret resource being referred to.
  19978. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  19979. maxLength: 63
  19980. minLength: 1
  19981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  19982. type: string
  19983. type: object
  19984. username:
  19985. description: |-
  19986. Username is a username used to authenticate using the [UserPass
  19987. authentication method]
  19988. [UserPass authentication method]: https://openbao.org/docs/auth/userpass/
  19989. type: string
  19990. required:
  19991. - path
  19992. - username
  19993. type: object
  19994. type: object
  19995. x-kubernetes-validations:
  19996. - message: exactly one of the fields in [appRole tokenSecretRef userPass] must be set
  19997. rule: '[has(self.appRole),has(self.tokenSecretRef),has(self.userPass)].filter(x,x==true).size() == 1'
  19998. caBundle:
  19999. description: |-
  20000. PEM encoded CA bundle used to validate the OpenBao server certificate. If
  20001. this and `caProvider` are not set the system root certificates are used
  20002. to validate the TLS connection.
  20003. format: byte
  20004. type: string
  20005. caProvider:
  20006. description: |-
  20007. The provider for the CA bundle to use to validate OpenBao server
  20008. certificate. If this and `caBundle` are not set the system root
  20009. certificates are used to validate the TLS connection.
  20010. properties:
  20011. key:
  20012. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20013. maxLength: 253
  20014. minLength: 1
  20015. pattern: ^[-._a-zA-Z0-9]+$
  20016. type: string
  20017. name:
  20018. description: The name of the object located at the provider type.
  20019. maxLength: 253
  20020. minLength: 1
  20021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20022. type: string
  20023. namespace:
  20024. description: |-
  20025. The namespace the Provider type is in.
  20026. Can only be defined when used in a ClusterSecretStore.
  20027. maxLength: 63
  20028. minLength: 1
  20029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20030. type: string
  20031. type:
  20032. description: The type of provider to use such as "Secret", or "ConfigMap".
  20033. enum:
  20034. - Secret
  20035. - ConfigMap
  20036. type: string
  20037. required:
  20038. - name
  20039. - type
  20040. type: object
  20041. namespace:
  20042. description: |-
  20043. Name of the [OpenBao Namespace]. Namespaces is a set of features within
  20044. OpenBao that allows OpenBao environments to support secure multi-tenancy.
  20045. e.g: "ns1".
  20046. [OpenBao Namespace]: https://openbao.org/docs/concepts/namespaces/
  20047. type: string
  20048. path:
  20049. description: |-
  20050. Path is the mount path of the OpenBao KV backend endpoint, e.g:
  20051. "secret". The v2 KV secret engine version specific "/data" path suffix
  20052. for fetching secrets from OpenBao is optional and will be appended
  20053. if not present in specified path.
  20054. type: string
  20055. server:
  20056. description: 'Server is the connection address for the OpenBao server, e.g: `https://openbao.example.com:8200`.'
  20057. type: string
  20058. version:
  20059. default: v2
  20060. description: |-
  20061. Version is the OpenBao KV secret engine version. This can be either "v1" or
  20062. "v2". Version defaults to "v2".
  20063. enum:
  20064. - v1
  20065. - v2
  20066. type: string
  20067. required:
  20068. - server
  20069. type: object
  20070. x-kubernetes-validations:
  20071. - message: at most one of the fields in [caBundle caProvider] may be set
  20072. rule: '[has(self.caBundle),has(self.caProvider)].filter(x,x==true).size() <= 1'
  20073. oracle:
  20074. description: Oracle configures this store to sync secrets using Oracle Vault provider
  20075. properties:
  20076. auth:
  20077. description: |-
  20078. Auth configures how secret-manager authenticates with the Oracle Vault.
  20079. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  20080. properties:
  20081. secretRef:
  20082. description: SecretRef to pass through sensitive information.
  20083. properties:
  20084. fingerprint:
  20085. description: Fingerprint is the fingerprint of the API private key.
  20086. properties:
  20087. key:
  20088. description: |-
  20089. A key in the referenced Secret.
  20090. Some instances of this field may be defaulted, in others it may be required.
  20091. maxLength: 253
  20092. minLength: 1
  20093. pattern: ^[-._a-zA-Z0-9]+$
  20094. type: string
  20095. name:
  20096. description: The name of the Secret resource being referred to.
  20097. maxLength: 253
  20098. minLength: 1
  20099. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20100. type: string
  20101. namespace:
  20102. description: |-
  20103. The namespace of the Secret resource being referred to.
  20104. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20105. maxLength: 63
  20106. minLength: 1
  20107. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20108. type: string
  20109. type: object
  20110. privatekey:
  20111. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  20112. properties:
  20113. key:
  20114. description: |-
  20115. A key in the referenced Secret.
  20116. Some instances of this field may be defaulted, in others it may be required.
  20117. maxLength: 253
  20118. minLength: 1
  20119. pattern: ^[-._a-zA-Z0-9]+$
  20120. type: string
  20121. name:
  20122. description: The name of the Secret resource being referred to.
  20123. maxLength: 253
  20124. minLength: 1
  20125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20126. type: string
  20127. namespace:
  20128. description: |-
  20129. The namespace of the Secret resource being referred to.
  20130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20131. maxLength: 63
  20132. minLength: 1
  20133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20134. type: string
  20135. type: object
  20136. required:
  20137. - fingerprint
  20138. - privatekey
  20139. type: object
  20140. tenancy:
  20141. description: Tenancy is the tenancy OCID where user is located.
  20142. type: string
  20143. user:
  20144. description: User is an access OCID specific to the account.
  20145. type: string
  20146. required:
  20147. - secretRef
  20148. - tenancy
  20149. - user
  20150. type: object
  20151. compartment:
  20152. description: |-
  20153. Compartment is the vault compartment OCID.
  20154. Required for PushSecret
  20155. type: string
  20156. encryptionKey:
  20157. description: |-
  20158. EncryptionKey is the OCID of the encryption key within the vault.
  20159. Required for PushSecret
  20160. type: string
  20161. principalType:
  20162. description: |-
  20163. The type of principal to use for authentication. If left blank, the Auth struct will
  20164. determine the principal type. This optional field must be specified if using
  20165. workload identity.
  20166. enum:
  20167. - ""
  20168. - UserPrincipal
  20169. - InstancePrincipal
  20170. - Workload
  20171. type: string
  20172. region:
  20173. description: Region is the region where vault is located.
  20174. type: string
  20175. serviceAccountRef:
  20176. description: |-
  20177. ServiceAccountRef specified the service account
  20178. that should be used when authenticating with WorkloadIdentity.
  20179. properties:
  20180. audiences:
  20181. description: |-
  20182. Audience specifies the `aud` claim for the service account token
  20183. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20184. then this audiences will be appended to the list
  20185. items:
  20186. type: string
  20187. type: array
  20188. name:
  20189. description: The name of the ServiceAccount resource being referred to.
  20190. maxLength: 253
  20191. minLength: 1
  20192. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20193. type: string
  20194. namespace:
  20195. description: |-
  20196. Namespace of the resource being referred to.
  20197. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20198. maxLength: 63
  20199. minLength: 1
  20200. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20201. type: string
  20202. required:
  20203. - name
  20204. type: object
  20205. vault:
  20206. description: Vault is the vault's OCID of the specific vault where secret is located.
  20207. type: string
  20208. required:
  20209. - region
  20210. - vault
  20211. type: object
  20212. ovh:
  20213. description: OVHcloud configures this store to sync secrets using the OVHcloud provider.
  20214. properties:
  20215. auth:
  20216. description: Authentication method (mtls or token).
  20217. properties:
  20218. mtls:
  20219. description: OvhClientMTLS defines the configuration required to authenticate to OVHcloud's Secret Manager using mTLS.
  20220. properties:
  20221. caBundle:
  20222. format: byte
  20223. type: string
  20224. caProvider:
  20225. description: |-
  20226. CAProvider provides a custom certificate authority for accessing the provider's store.
  20227. The CAProvider points to a Secret or ConfigMap resource that contains a PEM-encoded certificate.
  20228. properties:
  20229. key:
  20230. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20231. maxLength: 253
  20232. minLength: 1
  20233. pattern: ^[-._a-zA-Z0-9]+$
  20234. type: string
  20235. name:
  20236. description: The name of the object located at the provider type.
  20237. maxLength: 253
  20238. minLength: 1
  20239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20240. type: string
  20241. namespace:
  20242. description: |-
  20243. The namespace the Provider type is in.
  20244. Can only be defined when used in a ClusterSecretStore.
  20245. maxLength: 63
  20246. minLength: 1
  20247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20248. type: string
  20249. type:
  20250. description: The type of provider to use such as "Secret", or "ConfigMap".
  20251. enum:
  20252. - Secret
  20253. - ConfigMap
  20254. type: string
  20255. required:
  20256. - name
  20257. - type
  20258. type: object
  20259. certSecretRef:
  20260. description: |-
  20261. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20262. In some instances, `key` is a required field.
  20263. properties:
  20264. key:
  20265. description: |-
  20266. A key in the referenced Secret.
  20267. Some instances of this field may be defaulted, in others it may be required.
  20268. maxLength: 253
  20269. minLength: 1
  20270. pattern: ^[-._a-zA-Z0-9]+$
  20271. type: string
  20272. name:
  20273. description: The name of the Secret resource being referred to.
  20274. maxLength: 253
  20275. minLength: 1
  20276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20277. type: string
  20278. namespace:
  20279. description: |-
  20280. The namespace of the Secret resource being referred to.
  20281. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20282. maxLength: 63
  20283. minLength: 1
  20284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20285. type: string
  20286. type: object
  20287. keySecretRef:
  20288. description: |-
  20289. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20290. In some instances, `key` is a required field.
  20291. properties:
  20292. key:
  20293. description: |-
  20294. A key in the referenced Secret.
  20295. Some instances of this field may be defaulted, in others it may be required.
  20296. maxLength: 253
  20297. minLength: 1
  20298. pattern: ^[-._a-zA-Z0-9]+$
  20299. type: string
  20300. name:
  20301. description: The name of the Secret resource being referred to.
  20302. maxLength: 253
  20303. minLength: 1
  20304. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20305. type: string
  20306. namespace:
  20307. description: |-
  20308. The namespace of the Secret resource being referred to.
  20309. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20310. maxLength: 63
  20311. minLength: 1
  20312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20313. type: string
  20314. type: object
  20315. required:
  20316. - certSecretRef
  20317. - keySecretRef
  20318. type: object
  20319. token:
  20320. description: OvhClientToken defines the configuration required to authenticate to OVHcloud's Secret Manager using a token.
  20321. properties:
  20322. tokenSecretRef:
  20323. description: |-
  20324. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20325. In some instances, `key` is a required field.
  20326. properties:
  20327. key:
  20328. description: |-
  20329. A key in the referenced Secret.
  20330. Some instances of this field may be defaulted, in others it may be required.
  20331. maxLength: 253
  20332. minLength: 1
  20333. pattern: ^[-._a-zA-Z0-9]+$
  20334. type: string
  20335. name:
  20336. description: The name of the Secret resource being referred to.
  20337. maxLength: 253
  20338. minLength: 1
  20339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20340. type: string
  20341. namespace:
  20342. description: |-
  20343. The namespace of the Secret resource being referred to.
  20344. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20345. maxLength: 63
  20346. minLength: 1
  20347. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20348. type: string
  20349. type: object
  20350. required:
  20351. - tokenSecretRef
  20352. type: object
  20353. type: object
  20354. casRequired:
  20355. description: 'Enables or disables check-and-set (CAS) (default: false).'
  20356. type: boolean
  20357. okmsTimeout:
  20358. default: 30
  20359. description: 'Setup a timeout in seconds when requests to the KMS are made (default: 30).'
  20360. format: int32
  20361. minimum: 1
  20362. type: integer
  20363. okmsid:
  20364. description: specifies the OKMS ID.
  20365. type: string
  20366. server:
  20367. description: specifies the OKMS server endpoint.
  20368. type: string
  20369. required:
  20370. - auth
  20371. - okmsid
  20372. - server
  20373. type: object
  20374. passbolt:
  20375. description: |-
  20376. PassboltProvider provides access to Passbolt secrets manager.
  20377. See: https://www.passbolt.com.
  20378. properties:
  20379. auth:
  20380. description: Auth defines the information necessary to authenticate against Passbolt Server
  20381. properties:
  20382. passwordSecretRef:
  20383. description: |-
  20384. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20385. In some instances, `key` is a required field.
  20386. properties:
  20387. key:
  20388. description: |-
  20389. A key in the referenced Secret.
  20390. Some instances of this field may be defaulted, in others it may be required.
  20391. maxLength: 253
  20392. minLength: 1
  20393. pattern: ^[-._a-zA-Z0-9]+$
  20394. type: string
  20395. name:
  20396. description: The name of the Secret resource being referred to.
  20397. maxLength: 253
  20398. minLength: 1
  20399. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20400. type: string
  20401. namespace:
  20402. description: |-
  20403. The namespace of the Secret resource being referred to.
  20404. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20405. maxLength: 63
  20406. minLength: 1
  20407. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20408. type: string
  20409. type: object
  20410. privateKeySecretRef:
  20411. description: |-
  20412. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  20413. In some instances, `key` is a required field.
  20414. properties:
  20415. key:
  20416. description: |-
  20417. A key in the referenced Secret.
  20418. Some instances of this field may be defaulted, in others it may be required.
  20419. maxLength: 253
  20420. minLength: 1
  20421. pattern: ^[-._a-zA-Z0-9]+$
  20422. type: string
  20423. name:
  20424. description: The name of the Secret resource being referred to.
  20425. maxLength: 253
  20426. minLength: 1
  20427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20428. type: string
  20429. namespace:
  20430. description: |-
  20431. The namespace of the Secret resource being referred to.
  20432. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20433. maxLength: 63
  20434. minLength: 1
  20435. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20436. type: string
  20437. type: object
  20438. required:
  20439. - passwordSecretRef
  20440. - privateKeySecretRef
  20441. type: object
  20442. caBundle:
  20443. description: |-
  20444. PEM encoded CA bundle used to validate Passbolt server certificate. Only used
  20445. if the Host URL is using HTTPS protocol. If not set the system root certificates
  20446. are used to validate the TLS connection.
  20447. format: byte
  20448. type: string
  20449. caProvider:
  20450. description: The provider for the CA bundle to use to validate Passbolt server certificate.
  20451. properties:
  20452. key:
  20453. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20454. maxLength: 253
  20455. minLength: 1
  20456. pattern: ^[-._a-zA-Z0-9]+$
  20457. type: string
  20458. name:
  20459. description: The name of the object located at the provider type.
  20460. maxLength: 253
  20461. minLength: 1
  20462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20463. type: string
  20464. namespace:
  20465. description: |-
  20466. The namespace the Provider type is in.
  20467. Can only be defined when used in a ClusterSecretStore.
  20468. maxLength: 63
  20469. minLength: 1
  20470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20471. type: string
  20472. type:
  20473. description: The type of provider to use such as "Secret", or "ConfigMap".
  20474. enum:
  20475. - Secret
  20476. - ConfigMap
  20477. type: string
  20478. required:
  20479. - name
  20480. - type
  20481. type: object
  20482. host:
  20483. description: Host defines the Passbolt Server to connect to
  20484. type: string
  20485. required:
  20486. - auth
  20487. - host
  20488. type: object
  20489. passworddepot:
  20490. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  20491. properties:
  20492. auth:
  20493. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  20494. properties:
  20495. secretRef:
  20496. description: PasswordDepotSecretRef contains the secret reference for Password Depot authentication.
  20497. properties:
  20498. credentials:
  20499. description: Username / Password is used for authentication.
  20500. properties:
  20501. key:
  20502. description: |-
  20503. A key in the referenced Secret.
  20504. Some instances of this field may be defaulted, in others it may be required.
  20505. maxLength: 253
  20506. minLength: 1
  20507. pattern: ^[-._a-zA-Z0-9]+$
  20508. type: string
  20509. name:
  20510. description: The name of the Secret resource being referred to.
  20511. maxLength: 253
  20512. minLength: 1
  20513. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20514. type: string
  20515. namespace:
  20516. description: |-
  20517. The namespace of the Secret resource being referred to.
  20518. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20519. maxLength: 63
  20520. minLength: 1
  20521. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20522. type: string
  20523. type: object
  20524. type: object
  20525. required:
  20526. - secretRef
  20527. type: object
  20528. database:
  20529. description: Database to use as source
  20530. type: string
  20531. host:
  20532. description: URL configures the Password Depot instance URL.
  20533. type: string
  20534. required:
  20535. - auth
  20536. - database
  20537. - host
  20538. type: object
  20539. previder:
  20540. description: Previder configures this store to sync secrets using the Previder provider
  20541. properties:
  20542. auth:
  20543. description: PreviderAuth contains a secretRef for credentials.
  20544. properties:
  20545. secretRef:
  20546. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  20547. properties:
  20548. accessToken:
  20549. description: The AccessToken is used for authentication
  20550. properties:
  20551. key:
  20552. description: |-
  20553. A key in the referenced Secret.
  20554. Some instances of this field may be defaulted, in others it may be required.
  20555. maxLength: 253
  20556. minLength: 1
  20557. pattern: ^[-._a-zA-Z0-9]+$
  20558. type: string
  20559. name:
  20560. description: The name of the Secret resource being referred to.
  20561. maxLength: 253
  20562. minLength: 1
  20563. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20564. type: string
  20565. namespace:
  20566. description: |-
  20567. The namespace of the Secret resource being referred to.
  20568. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20569. maxLength: 63
  20570. minLength: 1
  20571. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20572. type: string
  20573. type: object
  20574. required:
  20575. - accessToken
  20576. type: object
  20577. type: object
  20578. baseUri:
  20579. type: string
  20580. required:
  20581. - auth
  20582. type: object
  20583. pulumi:
  20584. description: Pulumi configures this store to sync secrets using the Pulumi provider
  20585. properties:
  20586. accessToken:
  20587. description: |-
  20588. AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  20589. Deprecated: Use auth.accessToken instead.
  20590. properties:
  20591. secretRef:
  20592. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20593. properties:
  20594. key:
  20595. description: |-
  20596. A key in the referenced Secret.
  20597. Some instances of this field may be defaulted, in others it may be required.
  20598. maxLength: 253
  20599. minLength: 1
  20600. pattern: ^[-._a-zA-Z0-9]+$
  20601. type: string
  20602. name:
  20603. description: The name of the Secret resource being referred to.
  20604. maxLength: 253
  20605. minLength: 1
  20606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20607. type: string
  20608. namespace:
  20609. description: |-
  20610. The namespace of the Secret resource being referred to.
  20611. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20612. maxLength: 63
  20613. minLength: 1
  20614. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20615. type: string
  20616. type: object
  20617. type: object
  20618. apiUrl:
  20619. default: https://api.pulumi.com/api/esc
  20620. description: APIURL is the URL of the Pulumi API.
  20621. type: string
  20622. auth:
  20623. description: |-
  20624. Auth configures how the Operator authenticates with the Pulumi API.
  20625. Either auth or the deprecated accessToken field must be specified.
  20626. properties:
  20627. accessToken:
  20628. description: AccessToken authenticates using a Pulumi access token stored in a Kubernetes Secret.
  20629. properties:
  20630. secretRef:
  20631. description: SecretRef is a reference to a secret containing the Pulumi API token.
  20632. properties:
  20633. key:
  20634. description: |-
  20635. A key in the referenced Secret.
  20636. Some instances of this field may be defaulted, in others it may be required.
  20637. maxLength: 253
  20638. minLength: 1
  20639. pattern: ^[-._a-zA-Z0-9]+$
  20640. type: string
  20641. name:
  20642. description: The name of the Secret resource being referred to.
  20643. maxLength: 253
  20644. minLength: 1
  20645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20646. type: string
  20647. namespace:
  20648. description: |-
  20649. The namespace of the Secret resource being referred to.
  20650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20651. maxLength: 63
  20652. minLength: 1
  20653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20654. type: string
  20655. type: object
  20656. type: object
  20657. oidcConfig:
  20658. description: OIDCConfig authenticates using Kubernetes ServiceAccount tokens via OIDC.
  20659. properties:
  20660. expirationSeconds:
  20661. default: 600
  20662. description: |-
  20663. ExpirationSeconds sets the token validity duration for service account and OIDC token.
  20664. Defaults to 10 minutes.
  20665. format: int64
  20666. minimum: 600
  20667. type: integer
  20668. organization:
  20669. description: Organization is the name of the Pulumi organization configured for OIDC authentication.
  20670. type: string
  20671. serviceAccountRef:
  20672. description: ServiceAccountRef specifies the Kubernetes ServiceAccount to use for authentication.
  20673. properties:
  20674. audiences:
  20675. description: |-
  20676. Audience specifies the `aud` claim for the service account token
  20677. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  20678. then this audiences will be appended to the list
  20679. items:
  20680. type: string
  20681. type: array
  20682. name:
  20683. description: The name of the ServiceAccount resource being referred to.
  20684. maxLength: 253
  20685. minLength: 1
  20686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20687. type: string
  20688. namespace:
  20689. description: |-
  20690. Namespace of the resource being referred to.
  20691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20692. maxLength: 63
  20693. minLength: 1
  20694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20695. type: string
  20696. required:
  20697. - name
  20698. type: object
  20699. required:
  20700. - organization
  20701. - serviceAccountRef
  20702. type: object
  20703. type: object
  20704. x-kubernetes-validations:
  20705. - message: Exactly one of 'accessToken' or 'oidcConfig' must be specified
  20706. rule: (has(self.accessToken) && !has(self.oidcConfig)) || (!has(self.accessToken) && has(self.oidcConfig))
  20707. environment:
  20708. description: |-
  20709. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  20710. dynamically retrieved values from supported providers including all major clouds,
  20711. and other Pulumi ESC environments.
  20712. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  20713. type: string
  20714. organization:
  20715. description: |-
  20716. Organization are a space to collaborate on shared projects and stacks.
  20717. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  20718. type: string
  20719. project:
  20720. description: Project is the name of the Pulumi ESC project the environment belongs to.
  20721. type: string
  20722. required:
  20723. - environment
  20724. - organization
  20725. - project
  20726. type: object
  20727. x-kubernetes-validations:
  20728. - message: Exactly one of 'auth' or deprecated 'accessToken' must be specified
  20729. rule: (has(self.auth) && !has(self.accessToken)) || (!has(self.auth) && has(self.accessToken))
  20730. scaleway:
  20731. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  20732. properties:
  20733. accessKey:
  20734. description: AccessKey is the non-secret part of the api key.
  20735. properties:
  20736. secretRef:
  20737. description: SecretRef references a key in a secret that will be used as value.
  20738. properties:
  20739. key:
  20740. description: |-
  20741. A key in the referenced Secret.
  20742. Some instances of this field may be defaulted, in others it may be required.
  20743. maxLength: 253
  20744. minLength: 1
  20745. pattern: ^[-._a-zA-Z0-9]+$
  20746. type: string
  20747. name:
  20748. description: The name of the Secret resource being referred to.
  20749. maxLength: 253
  20750. minLength: 1
  20751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20752. type: string
  20753. namespace:
  20754. description: |-
  20755. The namespace of the Secret resource being referred to.
  20756. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20757. maxLength: 63
  20758. minLength: 1
  20759. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20760. type: string
  20761. type: object
  20762. value:
  20763. description: Value can be specified directly to set a value without using a secret.
  20764. type: string
  20765. type: object
  20766. apiUrl:
  20767. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  20768. type: string
  20769. projectId:
  20770. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  20771. type: string
  20772. region:
  20773. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  20774. type: string
  20775. secretKey:
  20776. description: SecretKey is the non-secret part of the api key.
  20777. properties:
  20778. secretRef:
  20779. description: SecretRef references a key in a secret that will be used as value.
  20780. properties:
  20781. key:
  20782. description: |-
  20783. A key in the referenced Secret.
  20784. Some instances of this field may be defaulted, in others it may be required.
  20785. maxLength: 253
  20786. minLength: 1
  20787. pattern: ^[-._a-zA-Z0-9]+$
  20788. type: string
  20789. name:
  20790. description: The name of the Secret resource being referred to.
  20791. maxLength: 253
  20792. minLength: 1
  20793. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20794. type: string
  20795. namespace:
  20796. description: |-
  20797. The namespace of the Secret resource being referred to.
  20798. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20799. maxLength: 63
  20800. minLength: 1
  20801. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20802. type: string
  20803. type: object
  20804. value:
  20805. description: Value can be specified directly to set a value without using a secret.
  20806. type: string
  20807. type: object
  20808. required:
  20809. - accessKey
  20810. - projectId
  20811. - region
  20812. - secretKey
  20813. type: object
  20814. secretserver:
  20815. description: |-
  20816. SecretServer configures this store to sync secrets using SecretServer provider
  20817. https://docs.delinea.com/online-help/secret-server/start.htm
  20818. properties:
  20819. caBundle:
  20820. description: |-
  20821. PEM/base64 encoded CA bundle used to validate Secret ServerURL. Only used
  20822. if the ServerURL URL is using HTTPS protocol. If not set the system root certificates
  20823. are used to validate the TLS connection.
  20824. format: byte
  20825. type: string
  20826. caProvider:
  20827. description: The provider for the CA bundle to use to validate Secret ServerURL certificate.
  20828. properties:
  20829. key:
  20830. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  20831. maxLength: 253
  20832. minLength: 1
  20833. pattern: ^[-._a-zA-Z0-9]+$
  20834. type: string
  20835. name:
  20836. description: The name of the object located at the provider type.
  20837. maxLength: 253
  20838. minLength: 1
  20839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20840. type: string
  20841. namespace:
  20842. description: |-
  20843. The namespace the Provider type is in.
  20844. Can only be defined when used in a ClusterSecretStore.
  20845. maxLength: 63
  20846. minLength: 1
  20847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20848. type: string
  20849. type:
  20850. description: The type of provider to use such as "Secret", or "ConfigMap".
  20851. enum:
  20852. - Secret
  20853. - ConfigMap
  20854. type: string
  20855. required:
  20856. - name
  20857. - type
  20858. type: object
  20859. domain:
  20860. description: Domain is the secret server domain.
  20861. type: string
  20862. password:
  20863. description: |-
  20864. Password is the secret server account password.
  20865. Required unless Token is set.
  20866. properties:
  20867. secretRef:
  20868. description: SecretRef references a key in a secret that will be used as value.
  20869. properties:
  20870. key:
  20871. description: |-
  20872. A key in the referenced Secret.
  20873. Some instances of this field may be defaulted, in others it may be required.
  20874. maxLength: 253
  20875. minLength: 1
  20876. pattern: ^[-._a-zA-Z0-9]+$
  20877. type: string
  20878. name:
  20879. description: The name of the Secret resource being referred to.
  20880. maxLength: 253
  20881. minLength: 1
  20882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20883. type: string
  20884. namespace:
  20885. description: |-
  20886. The namespace of the Secret resource being referred to.
  20887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20888. maxLength: 63
  20889. minLength: 1
  20890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20891. type: string
  20892. type: object
  20893. value:
  20894. description: Value can be specified directly to set a value without using a secret.
  20895. minLength: 1
  20896. type: string
  20897. type: object
  20898. x-kubernetes-validations:
  20899. - message: exactly one of value or secretRef must be set
  20900. rule: has(self.value) != has(self.secretRef)
  20901. serverURL:
  20902. description: |-
  20903. ServerURL
  20904. URL to your secret server installation
  20905. type: string
  20906. token:
  20907. description: |-
  20908. Token is an access token used to authenticate to the secret server,
  20909. as an alternative to Username and Password. When set, Username and
  20910. Password are not required and are ignored.
  20911. properties:
  20912. secretRef:
  20913. description: SecretRef references a key in a secret that will be used as value.
  20914. properties:
  20915. key:
  20916. description: |-
  20917. A key in the referenced Secret.
  20918. Some instances of this field may be defaulted, in others it may be required.
  20919. maxLength: 253
  20920. minLength: 1
  20921. pattern: ^[-._a-zA-Z0-9]+$
  20922. type: string
  20923. name:
  20924. description: The name of the Secret resource being referred to.
  20925. maxLength: 253
  20926. minLength: 1
  20927. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20928. type: string
  20929. namespace:
  20930. description: |-
  20931. The namespace of the Secret resource being referred to.
  20932. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20933. maxLength: 63
  20934. minLength: 1
  20935. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20936. type: string
  20937. type: object
  20938. value:
  20939. description: Value can be specified directly to set a value without using a secret.
  20940. minLength: 1
  20941. type: string
  20942. type: object
  20943. x-kubernetes-validations:
  20944. - message: exactly one of value or secretRef must be set
  20945. rule: has(self.value) != has(self.secretRef)
  20946. username:
  20947. description: |-
  20948. Username is the secret server account username.
  20949. Required unless Token is set.
  20950. properties:
  20951. secretRef:
  20952. description: SecretRef references a key in a secret that will be used as value.
  20953. properties:
  20954. key:
  20955. description: |-
  20956. A key in the referenced Secret.
  20957. Some instances of this field may be defaulted, in others it may be required.
  20958. maxLength: 253
  20959. minLength: 1
  20960. pattern: ^[-._a-zA-Z0-9]+$
  20961. type: string
  20962. name:
  20963. description: The name of the Secret resource being referred to.
  20964. maxLength: 253
  20965. minLength: 1
  20966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  20967. type: string
  20968. namespace:
  20969. description: |-
  20970. The namespace of the Secret resource being referred to.
  20971. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  20972. maxLength: 63
  20973. minLength: 1
  20974. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  20975. type: string
  20976. type: object
  20977. value:
  20978. description: Value can be specified directly to set a value without using a secret.
  20979. minLength: 1
  20980. type: string
  20981. type: object
  20982. x-kubernetes-validations:
  20983. - message: exactly one of value or secretRef must be set
  20984. rule: has(self.value) != has(self.secretRef)
  20985. required:
  20986. - serverURL
  20987. type: object
  20988. x-kubernetes-validations:
  20989. - message: either token, or both username and password, must be set
  20990. rule: has(self.token) || (has(self.username) && has(self.password))
  20991. senhasegura:
  20992. description: Senhasegura configures this store to sync secrets using senhasegura provider
  20993. properties:
  20994. auth:
  20995. description: Auth defines parameters to authenticate in senhasegura
  20996. properties:
  20997. clientId:
  20998. type: string
  20999. clientSecretSecretRef:
  21000. description: |-
  21001. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  21002. In some instances, `key` is a required field.
  21003. properties:
  21004. key:
  21005. description: |-
  21006. A key in the referenced Secret.
  21007. Some instances of this field may be defaulted, in others it may be required.
  21008. maxLength: 253
  21009. minLength: 1
  21010. pattern: ^[-._a-zA-Z0-9]+$
  21011. type: string
  21012. name:
  21013. description: The name of the Secret resource being referred to.
  21014. maxLength: 253
  21015. minLength: 1
  21016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21017. type: string
  21018. namespace:
  21019. description: |-
  21020. The namespace of the Secret resource being referred to.
  21021. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21022. maxLength: 63
  21023. minLength: 1
  21024. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21025. type: string
  21026. type: object
  21027. required:
  21028. - clientId
  21029. - clientSecretSecretRef
  21030. type: object
  21031. ignoreSslCertificate:
  21032. default: false
  21033. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  21034. type: boolean
  21035. module:
  21036. description: Module defines which senhasegura module should be used to get secrets
  21037. type: string
  21038. url:
  21039. description: URL of senhasegura
  21040. type: string
  21041. required:
  21042. - auth
  21043. - module
  21044. - url
  21045. type: object
  21046. vault:
  21047. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  21048. properties:
  21049. auth:
  21050. description: Auth configures how secret-manager authenticates with the Vault server.
  21051. properties:
  21052. appRole:
  21053. description: |-
  21054. AppRole authenticates with Vault using the App Role auth mechanism,
  21055. with the role and secret stored in a Kubernetes Secret resource.
  21056. properties:
  21057. path:
  21058. default: approle
  21059. description: |-
  21060. Path where the App Role authentication backend is mounted
  21061. in Vault, e.g: "approle"
  21062. type: string
  21063. roleId:
  21064. description: |-
  21065. RoleID configured in the App Role authentication backend when setting
  21066. up the authentication backend in Vault.
  21067. type: string
  21068. roleRef:
  21069. description: |-
  21070. Reference to a key in a Secret that contains the App Role ID used
  21071. to authenticate with Vault.
  21072. The `key` field must be specified and denotes which entry within the Secret
  21073. resource is used as the app role id.
  21074. properties:
  21075. key:
  21076. description: |-
  21077. A key in the referenced Secret.
  21078. Some instances of this field may be defaulted, in others it may be required.
  21079. maxLength: 253
  21080. minLength: 1
  21081. pattern: ^[-._a-zA-Z0-9]+$
  21082. type: string
  21083. name:
  21084. description: The name of the Secret resource being referred to.
  21085. maxLength: 253
  21086. minLength: 1
  21087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21088. type: string
  21089. namespace:
  21090. description: |-
  21091. The namespace of the Secret resource being referred to.
  21092. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21093. maxLength: 63
  21094. minLength: 1
  21095. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21096. type: string
  21097. type: object
  21098. secretRef:
  21099. description: |-
  21100. Reference to a key in a Secret that contains the App Role secret used
  21101. to authenticate with Vault.
  21102. The `key` field must be specified and denotes which entry within the Secret
  21103. resource is used as the app role secret.
  21104. properties:
  21105. key:
  21106. description: |-
  21107. A key in the referenced Secret.
  21108. Some instances of this field may be defaulted, in others it may be required.
  21109. maxLength: 253
  21110. minLength: 1
  21111. pattern: ^[-._a-zA-Z0-9]+$
  21112. type: string
  21113. name:
  21114. description: The name of the Secret resource being referred to.
  21115. maxLength: 253
  21116. minLength: 1
  21117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21118. type: string
  21119. namespace:
  21120. description: |-
  21121. The namespace of the Secret resource being referred to.
  21122. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21123. maxLength: 63
  21124. minLength: 1
  21125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21126. type: string
  21127. type: object
  21128. required:
  21129. - path
  21130. - secretRef
  21131. type: object
  21132. cert:
  21133. description: |-
  21134. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  21135. Cert authentication method
  21136. properties:
  21137. clientCert:
  21138. description: |-
  21139. ClientCert is a certificate to authenticate using the Cert Vault
  21140. authentication method
  21141. properties:
  21142. key:
  21143. description: |-
  21144. A key in the referenced Secret.
  21145. Some instances of this field may be defaulted, in others it may be required.
  21146. maxLength: 253
  21147. minLength: 1
  21148. pattern: ^[-._a-zA-Z0-9]+$
  21149. type: string
  21150. name:
  21151. description: The name of the Secret resource being referred to.
  21152. maxLength: 253
  21153. minLength: 1
  21154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21155. type: string
  21156. namespace:
  21157. description: |-
  21158. The namespace of the Secret resource being referred to.
  21159. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21160. maxLength: 63
  21161. minLength: 1
  21162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21163. type: string
  21164. type: object
  21165. path:
  21166. default: cert
  21167. description: |-
  21168. Path where the Certificate authentication backend is mounted
  21169. in Vault, e.g: "cert"
  21170. type: string
  21171. secretRef:
  21172. description: |-
  21173. SecretRef to a key in a Secret resource containing client private key to
  21174. authenticate with Vault using the Cert authentication method
  21175. properties:
  21176. key:
  21177. description: |-
  21178. A key in the referenced Secret.
  21179. Some instances of this field may be defaulted, in others it may be required.
  21180. maxLength: 253
  21181. minLength: 1
  21182. pattern: ^[-._a-zA-Z0-9]+$
  21183. type: string
  21184. name:
  21185. description: The name of the Secret resource being referred to.
  21186. maxLength: 253
  21187. minLength: 1
  21188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21189. type: string
  21190. namespace:
  21191. description: |-
  21192. The namespace of the Secret resource being referred to.
  21193. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21194. maxLength: 63
  21195. minLength: 1
  21196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21197. type: string
  21198. type: object
  21199. vaultRole:
  21200. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  21201. type: string
  21202. type: object
  21203. gcp:
  21204. description: |-
  21205. Gcp authenticates with Vault using Google Cloud Platform authentication method
  21206. GCP authentication method
  21207. properties:
  21208. location:
  21209. description: Location optionally defines a location/region for the secret
  21210. type: string
  21211. path:
  21212. default: gcp
  21213. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  21214. type: string
  21215. projectID:
  21216. description: Project ID of the Google Cloud Platform project
  21217. type: string
  21218. role:
  21219. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  21220. type: string
  21221. secretRef:
  21222. description: Specify credentials in a Secret object
  21223. properties:
  21224. secretAccessKeySecretRef:
  21225. description: The SecretAccessKey is used for authentication
  21226. properties:
  21227. key:
  21228. description: |-
  21229. A key in the referenced Secret.
  21230. Some instances of this field may be defaulted, in others it may be required.
  21231. maxLength: 253
  21232. minLength: 1
  21233. pattern: ^[-._a-zA-Z0-9]+$
  21234. type: string
  21235. name:
  21236. description: The name of the Secret resource being referred to.
  21237. maxLength: 253
  21238. minLength: 1
  21239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21240. type: string
  21241. namespace:
  21242. description: |-
  21243. The namespace of the Secret resource being referred to.
  21244. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21245. maxLength: 63
  21246. minLength: 1
  21247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21248. type: string
  21249. type: object
  21250. type: object
  21251. serviceAccountRef:
  21252. description: ServiceAccountRef to a service account for impersonation
  21253. properties:
  21254. audiences:
  21255. description: |-
  21256. Audience specifies the `aud` claim for the service account token
  21257. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21258. then this audiences will be appended to the list
  21259. items:
  21260. type: string
  21261. type: array
  21262. name:
  21263. description: The name of the ServiceAccount resource being referred to.
  21264. maxLength: 253
  21265. minLength: 1
  21266. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21267. type: string
  21268. namespace:
  21269. description: |-
  21270. Namespace of the resource being referred to.
  21271. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21272. maxLength: 63
  21273. minLength: 1
  21274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21275. type: string
  21276. required:
  21277. - name
  21278. type: object
  21279. workloadIdentity:
  21280. description: Specify a service account with Workload Identity
  21281. properties:
  21282. clusterLocation:
  21283. description: |-
  21284. ClusterLocation is the location of the cluster
  21285. If not specified, it fetches information from the metadata server
  21286. type: string
  21287. clusterName:
  21288. description: |-
  21289. ClusterName is the name of the cluster
  21290. If not specified, it fetches information from the metadata server
  21291. type: string
  21292. clusterProjectID:
  21293. description: |-
  21294. ClusterProjectID is the project ID of the cluster
  21295. If not specified, it fetches information from the metadata server
  21296. type: string
  21297. serviceAccountRef:
  21298. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21299. properties:
  21300. audiences:
  21301. description: |-
  21302. Audience specifies the `aud` claim for the service account token
  21303. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21304. then this audiences will be appended to the list
  21305. items:
  21306. type: string
  21307. type: array
  21308. name:
  21309. description: The name of the ServiceAccount resource being referred to.
  21310. maxLength: 253
  21311. minLength: 1
  21312. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21313. type: string
  21314. namespace:
  21315. description: |-
  21316. Namespace of the resource being referred to.
  21317. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21318. maxLength: 63
  21319. minLength: 1
  21320. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21321. type: string
  21322. required:
  21323. - name
  21324. type: object
  21325. required:
  21326. - serviceAccountRef
  21327. type: object
  21328. required:
  21329. - role
  21330. type: object
  21331. iam:
  21332. description: |-
  21333. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  21334. AWS IAM authentication method
  21335. properties:
  21336. externalID:
  21337. description: AWS External ID set on assumed IAM roles
  21338. type: string
  21339. jwt:
  21340. description: Specify a service account with IRSA enabled
  21341. properties:
  21342. serviceAccountRef:
  21343. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  21344. properties:
  21345. audiences:
  21346. description: |-
  21347. Audience specifies the `aud` claim for the service account token
  21348. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21349. then this audiences will be appended to the list
  21350. items:
  21351. type: string
  21352. type: array
  21353. name:
  21354. description: The name of the ServiceAccount resource being referred to.
  21355. maxLength: 253
  21356. minLength: 1
  21357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21358. type: string
  21359. namespace:
  21360. description: |-
  21361. Namespace of the resource being referred to.
  21362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21363. maxLength: 63
  21364. minLength: 1
  21365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21366. type: string
  21367. required:
  21368. - name
  21369. type: object
  21370. type: object
  21371. path:
  21372. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  21373. type: string
  21374. region:
  21375. description: AWS region
  21376. type: string
  21377. role:
  21378. description: This is the AWS role to be assumed before talking to vault
  21379. type: string
  21380. secretRef:
  21381. description: Specify credentials in a Secret object
  21382. properties:
  21383. accessKeyIDSecretRef:
  21384. description: The AccessKeyID is used for authentication
  21385. properties:
  21386. key:
  21387. description: |-
  21388. A key in the referenced Secret.
  21389. Some instances of this field may be defaulted, in others it may be required.
  21390. maxLength: 253
  21391. minLength: 1
  21392. pattern: ^[-._a-zA-Z0-9]+$
  21393. type: string
  21394. name:
  21395. description: The name of the Secret resource being referred to.
  21396. maxLength: 253
  21397. minLength: 1
  21398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21399. type: string
  21400. namespace:
  21401. description: |-
  21402. The namespace of the Secret resource being referred to.
  21403. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21404. maxLength: 63
  21405. minLength: 1
  21406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21407. type: string
  21408. type: object
  21409. secretAccessKeySecretRef:
  21410. description: The SecretAccessKey is used for authentication
  21411. properties:
  21412. key:
  21413. description: |-
  21414. A key in the referenced Secret.
  21415. Some instances of this field may be defaulted, in others it may be required.
  21416. maxLength: 253
  21417. minLength: 1
  21418. pattern: ^[-._a-zA-Z0-9]+$
  21419. type: string
  21420. name:
  21421. description: The name of the Secret resource being referred to.
  21422. maxLength: 253
  21423. minLength: 1
  21424. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21425. type: string
  21426. namespace:
  21427. description: |-
  21428. The namespace of the Secret resource being referred to.
  21429. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21430. maxLength: 63
  21431. minLength: 1
  21432. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21433. type: string
  21434. type: object
  21435. sessionTokenSecretRef:
  21436. description: |-
  21437. The SessionToken used for authentication
  21438. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  21439. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  21440. properties:
  21441. key:
  21442. description: |-
  21443. A key in the referenced Secret.
  21444. Some instances of this field may be defaulted, in others it may be required.
  21445. maxLength: 253
  21446. minLength: 1
  21447. pattern: ^[-._a-zA-Z0-9]+$
  21448. type: string
  21449. name:
  21450. description: The name of the Secret resource being referred to.
  21451. maxLength: 253
  21452. minLength: 1
  21453. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21454. type: string
  21455. namespace:
  21456. description: |-
  21457. The namespace of the Secret resource being referred to.
  21458. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21459. maxLength: 63
  21460. minLength: 1
  21461. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21462. type: string
  21463. type: object
  21464. type: object
  21465. vaultAwsIamServerID:
  21466. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  21467. type: string
  21468. vaultRole:
  21469. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  21470. type: string
  21471. required:
  21472. - vaultRole
  21473. type: object
  21474. jwt:
  21475. description: |-
  21476. Jwt authenticates with Vault by passing role and JWT token using the
  21477. JWT/OIDC authentication method
  21478. properties:
  21479. kubernetesServiceAccountToken:
  21480. description: |-
  21481. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  21482. a token for with the `TokenRequest` API.
  21483. properties:
  21484. audiences:
  21485. description: |-
  21486. Optional audiences field that will be used to request a temporary Kubernetes service
  21487. account token for the service account referenced by `serviceAccountRef`.
  21488. Defaults to a single audience `vault` it not specified.
  21489. Deprecated: use serviceAccountRef.Audiences instead
  21490. items:
  21491. type: string
  21492. type: array
  21493. expirationSeconds:
  21494. description: |-
  21495. Optional expiration time in seconds that will be used to request a temporary
  21496. Kubernetes service account token for the service account referenced by
  21497. `serviceAccountRef`.
  21498. Deprecated: this will be removed in the future.
  21499. Defaults to 10 minutes.
  21500. format: int64
  21501. type: integer
  21502. serviceAccountRef:
  21503. description: Service account field containing the name of a kubernetes ServiceAccount.
  21504. properties:
  21505. audiences:
  21506. description: |-
  21507. Audience specifies the `aud` claim for the service account token
  21508. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21509. then this audiences will be appended to the list
  21510. items:
  21511. type: string
  21512. type: array
  21513. name:
  21514. description: The name of the ServiceAccount resource being referred to.
  21515. maxLength: 253
  21516. minLength: 1
  21517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21518. type: string
  21519. namespace:
  21520. description: |-
  21521. Namespace of the resource being referred to.
  21522. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21523. maxLength: 63
  21524. minLength: 1
  21525. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21526. type: string
  21527. required:
  21528. - name
  21529. type: object
  21530. required:
  21531. - serviceAccountRef
  21532. type: object
  21533. path:
  21534. default: jwt
  21535. description: |-
  21536. Path where the JWT authentication backend is mounted
  21537. in Vault, e.g: "jwt"
  21538. type: string
  21539. role:
  21540. description: |-
  21541. Role is a JWT role to authenticate using the JWT/OIDC Vault
  21542. authentication method
  21543. type: string
  21544. secretRef:
  21545. description: |-
  21546. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  21547. authenticate with Vault using the JWT/OIDC authentication method.
  21548. properties:
  21549. key:
  21550. description: |-
  21551. A key in the referenced Secret.
  21552. Some instances of this field may be defaulted, in others it may be required.
  21553. maxLength: 253
  21554. minLength: 1
  21555. pattern: ^[-._a-zA-Z0-9]+$
  21556. type: string
  21557. name:
  21558. description: The name of the Secret resource being referred to.
  21559. maxLength: 253
  21560. minLength: 1
  21561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21562. type: string
  21563. namespace:
  21564. description: |-
  21565. The namespace of the Secret resource being referred to.
  21566. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21567. maxLength: 63
  21568. minLength: 1
  21569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21570. type: string
  21571. type: object
  21572. required:
  21573. - path
  21574. type: object
  21575. kubernetes:
  21576. description: |-
  21577. Kubernetes authenticates with Vault by passing the ServiceAccount
  21578. token stored in the named Secret resource to the Vault server.
  21579. properties:
  21580. mountPath:
  21581. default: kubernetes
  21582. description: |-
  21583. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  21584. "kubernetes"
  21585. type: string
  21586. role:
  21587. description: |-
  21588. A required field containing the Vault Role to assume. A Role binds a
  21589. Kubernetes ServiceAccount with a set of Vault policies.
  21590. type: string
  21591. secretRef:
  21592. description: |-
  21593. Optional secret field containing a Kubernetes ServiceAccount JWT used
  21594. for authenticating with Vault. If a name is specified without a key,
  21595. `token` is the default. If one is not specified, the one bound to
  21596. the controller will be used.
  21597. properties:
  21598. key:
  21599. description: |-
  21600. A key in the referenced Secret.
  21601. Some instances of this field may be defaulted, in others it may be required.
  21602. maxLength: 253
  21603. minLength: 1
  21604. pattern: ^[-._a-zA-Z0-9]+$
  21605. type: string
  21606. name:
  21607. description: The name of the Secret resource being referred to.
  21608. maxLength: 253
  21609. minLength: 1
  21610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21611. type: string
  21612. namespace:
  21613. description: |-
  21614. The namespace of the Secret resource being referred to.
  21615. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21616. maxLength: 63
  21617. minLength: 1
  21618. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21619. type: string
  21620. type: object
  21621. serviceAccountRef:
  21622. description: |-
  21623. Optional service account field containing the name of a kubernetes ServiceAccount.
  21624. If the service account is specified, the service account secret token JWT will be used
  21625. for authenticating with Vault. If the service account selector is not supplied,
  21626. the secretRef will be used instead.
  21627. properties:
  21628. audiences:
  21629. description: |-
  21630. Audience specifies the `aud` claim for the service account token
  21631. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  21632. then this audiences will be appended to the list
  21633. items:
  21634. type: string
  21635. type: array
  21636. name:
  21637. description: The name of the ServiceAccount resource being referred to.
  21638. maxLength: 253
  21639. minLength: 1
  21640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21641. type: string
  21642. namespace:
  21643. description: |-
  21644. Namespace of the resource being referred to.
  21645. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21646. maxLength: 63
  21647. minLength: 1
  21648. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21649. type: string
  21650. required:
  21651. - name
  21652. type: object
  21653. required:
  21654. - mountPath
  21655. - role
  21656. type: object
  21657. ldap:
  21658. description: |-
  21659. Ldap authenticates with Vault by passing username/password pair using
  21660. the LDAP authentication method
  21661. properties:
  21662. path:
  21663. default: ldap
  21664. description: |-
  21665. Path where the LDAP authentication backend is mounted
  21666. in Vault, e.g: "ldap"
  21667. type: string
  21668. secretRef:
  21669. description: |-
  21670. SecretRef to a key in a Secret resource containing password for the LDAP
  21671. user used to authenticate with Vault using the LDAP authentication
  21672. method
  21673. properties:
  21674. key:
  21675. description: |-
  21676. A key in the referenced Secret.
  21677. Some instances of this field may be defaulted, in others it may be required.
  21678. maxLength: 253
  21679. minLength: 1
  21680. pattern: ^[-._a-zA-Z0-9]+$
  21681. type: string
  21682. name:
  21683. description: The name of the Secret resource being referred to.
  21684. maxLength: 253
  21685. minLength: 1
  21686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21687. type: string
  21688. namespace:
  21689. description: |-
  21690. The namespace of the Secret resource being referred to.
  21691. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21692. maxLength: 63
  21693. minLength: 1
  21694. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21695. type: string
  21696. type: object
  21697. username:
  21698. description: |-
  21699. Username is an LDAP username used to authenticate using the LDAP Vault
  21700. authentication method
  21701. type: string
  21702. required:
  21703. - path
  21704. - username
  21705. type: object
  21706. namespace:
  21707. description: |-
  21708. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  21709. Namespaces is a set of features within Vault Enterprise that allows
  21710. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21711. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21712. This will default to Vault.Namespace field if set, or empty otherwise
  21713. type: string
  21714. tokenSecretRef:
  21715. description: TokenSecretRef authenticates with Vault by presenting a token.
  21716. properties:
  21717. key:
  21718. description: |-
  21719. A key in the referenced Secret.
  21720. Some instances of this field may be defaulted, in others it may be required.
  21721. maxLength: 253
  21722. minLength: 1
  21723. pattern: ^[-._a-zA-Z0-9]+$
  21724. type: string
  21725. name:
  21726. description: The name of the Secret resource being referred to.
  21727. maxLength: 253
  21728. minLength: 1
  21729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21730. type: string
  21731. namespace:
  21732. description: |-
  21733. The namespace of the Secret resource being referred to.
  21734. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21735. maxLength: 63
  21736. minLength: 1
  21737. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21738. type: string
  21739. type: object
  21740. userPass:
  21741. description: UserPass authenticates with Vault by passing username/password pair
  21742. properties:
  21743. path:
  21744. default: userpass
  21745. description: |-
  21746. Path where the UserPassword authentication backend is mounted
  21747. in Vault, e.g: "userpass"
  21748. type: string
  21749. secretRef:
  21750. description: |-
  21751. SecretRef to a key in a Secret resource containing password for the
  21752. user used to authenticate with Vault using the UserPass authentication
  21753. method
  21754. properties:
  21755. key:
  21756. description: |-
  21757. A key in the referenced Secret.
  21758. Some instances of this field may be defaulted, in others it may be required.
  21759. maxLength: 253
  21760. minLength: 1
  21761. pattern: ^[-._a-zA-Z0-9]+$
  21762. type: string
  21763. name:
  21764. description: The name of the Secret resource being referred to.
  21765. maxLength: 253
  21766. minLength: 1
  21767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21768. type: string
  21769. namespace:
  21770. description: |-
  21771. The namespace of the Secret resource being referred to.
  21772. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21773. maxLength: 63
  21774. minLength: 1
  21775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21776. type: string
  21777. type: object
  21778. username:
  21779. description: |-
  21780. Username is a username used to authenticate using the UserPass Vault
  21781. authentication method
  21782. type: string
  21783. required:
  21784. - path
  21785. - username
  21786. type: object
  21787. type: object
  21788. caBundle:
  21789. description: |-
  21790. PEM encoded CA bundle used to validate Vault server certificate. Only used
  21791. if the Server URL is using HTTPS protocol. This parameter is ignored for
  21792. plain HTTP protocol connection. If not set the system root certificates
  21793. are used to validate the TLS connection.
  21794. format: byte
  21795. type: string
  21796. caProvider:
  21797. description: The provider for the CA bundle to use to validate Vault server certificate.
  21798. properties:
  21799. key:
  21800. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  21801. maxLength: 253
  21802. minLength: 1
  21803. pattern: ^[-._a-zA-Z0-9]+$
  21804. type: string
  21805. name:
  21806. description: The name of the object located at the provider type.
  21807. maxLength: 253
  21808. minLength: 1
  21809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21810. type: string
  21811. namespace:
  21812. description: |-
  21813. The namespace the Provider type is in.
  21814. Can only be defined when used in a ClusterSecretStore.
  21815. maxLength: 63
  21816. minLength: 1
  21817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21818. type: string
  21819. type:
  21820. description: The type of provider to use such as "Secret", or "ConfigMap".
  21821. enum:
  21822. - Secret
  21823. - ConfigMap
  21824. type: string
  21825. required:
  21826. - name
  21827. - type
  21828. type: object
  21829. checkAndSet:
  21830. description: |-
  21831. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  21832. Only applies to Vault KV v2 stores. When enabled, write operations must include
  21833. the current version of the secret to prevent unintentional overwrites.
  21834. properties:
  21835. required:
  21836. description: |-
  21837. Required when true, all write operations must include a check-and-set parameter.
  21838. This helps prevent unintentional overwrites of secrets.
  21839. type: boolean
  21840. type: object
  21841. forwardInconsistent:
  21842. description: |-
  21843. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  21844. leader instead of simply retrying within a loop. This can increase performance if
  21845. the option is enabled serverside.
  21846. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  21847. type: boolean
  21848. headers:
  21849. additionalProperties:
  21850. type: string
  21851. description: Headers to be added in Vault request
  21852. type: object
  21853. namespace:
  21854. description: |-
  21855. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  21856. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  21857. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  21858. type: string
  21859. path:
  21860. description: |-
  21861. Path is the mount path of the Vault KV backend endpoint, e.g:
  21862. "secret". The v2 KV secret engine version specific "/data" path suffix
  21863. for fetching secrets from Vault is optional and will be appended
  21864. if not present in specified path.
  21865. type: string
  21866. readYourWrites:
  21867. description: |-
  21868. ReadYourWrites ensures isolated read-after-write semantics by
  21869. providing discovered cluster replication states in each request.
  21870. More information about eventual consistency in Vault can be found here
  21871. https://www.vaultproject.io/docs/enterprise/consistency
  21872. type: boolean
  21873. server:
  21874. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  21875. type: string
  21876. tls:
  21877. description: |-
  21878. The configuration used for client side related TLS communication, when the Vault server
  21879. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  21880. This parameter is ignored for plain HTTP protocol connection.
  21881. It's worth noting this configuration is different from the "TLS certificates auth method",
  21882. which is available under the `auth.cert` section.
  21883. properties:
  21884. certSecretRef:
  21885. description: |-
  21886. CertSecretRef is a certificate added to the transport layer
  21887. when communicating with the Vault server.
  21888. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  21889. properties:
  21890. key:
  21891. description: |-
  21892. A key in the referenced Secret.
  21893. Some instances of this field may be defaulted, in others it may be required.
  21894. maxLength: 253
  21895. minLength: 1
  21896. pattern: ^[-._a-zA-Z0-9]+$
  21897. type: string
  21898. name:
  21899. description: The name of the Secret resource being referred to.
  21900. maxLength: 253
  21901. minLength: 1
  21902. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21903. type: string
  21904. namespace:
  21905. description: |-
  21906. The namespace of the Secret resource being referred to.
  21907. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21908. maxLength: 63
  21909. minLength: 1
  21910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21911. type: string
  21912. type: object
  21913. keySecretRef:
  21914. description: |-
  21915. KeySecretRef to a key in a Secret resource containing client private key
  21916. added to the transport layer when communicating with the Vault server.
  21917. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  21918. properties:
  21919. key:
  21920. description: |-
  21921. A key in the referenced Secret.
  21922. Some instances of this field may be defaulted, in others it may be required.
  21923. maxLength: 253
  21924. minLength: 1
  21925. pattern: ^[-._a-zA-Z0-9]+$
  21926. type: string
  21927. name:
  21928. description: The name of the Secret resource being referred to.
  21929. maxLength: 253
  21930. minLength: 1
  21931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21932. type: string
  21933. namespace:
  21934. description: |-
  21935. The namespace of the Secret resource being referred to.
  21936. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21937. maxLength: 63
  21938. minLength: 1
  21939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21940. type: string
  21941. type: object
  21942. type: object
  21943. version:
  21944. default: v2
  21945. description: |-
  21946. Version is the Vault KV secret engine version. This can be either "v1" or
  21947. "v2". Version defaults to "v2".
  21948. enum:
  21949. - v1
  21950. - v2
  21951. type: string
  21952. required:
  21953. - server
  21954. type: object
  21955. volcengine:
  21956. description: Volcengine configures this store to sync secrets using the Volcengine provider
  21957. properties:
  21958. auth:
  21959. description: |-
  21960. Auth defines the authentication method to use.
  21961. If not specified, the provider will try to use IRSA (IAM Role for Service Account).
  21962. properties:
  21963. secretRef:
  21964. description: |-
  21965. SecretRef defines the static credentials to use for authentication.
  21966. If not set, IRSA is used.
  21967. properties:
  21968. accessKeyID:
  21969. description: AccessKeyID is the reference to the secret containing the Access Key ID.
  21970. properties:
  21971. key:
  21972. description: |-
  21973. A key in the referenced Secret.
  21974. Some instances of this field may be defaulted, in others it may be required.
  21975. maxLength: 253
  21976. minLength: 1
  21977. pattern: ^[-._a-zA-Z0-9]+$
  21978. type: string
  21979. name:
  21980. description: The name of the Secret resource being referred to.
  21981. maxLength: 253
  21982. minLength: 1
  21983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  21984. type: string
  21985. namespace:
  21986. description: |-
  21987. The namespace of the Secret resource being referred to.
  21988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  21989. maxLength: 63
  21990. minLength: 1
  21991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  21992. type: string
  21993. type: object
  21994. secretAccessKey:
  21995. description: SecretAccessKey is the reference to the secret containing the Secret Access Key.
  21996. properties:
  21997. key:
  21998. description: |-
  21999. A key in the referenced Secret.
  22000. Some instances of this field may be defaulted, in others it may be required.
  22001. maxLength: 253
  22002. minLength: 1
  22003. pattern: ^[-._a-zA-Z0-9]+$
  22004. type: string
  22005. name:
  22006. description: The name of the Secret resource being referred to.
  22007. maxLength: 253
  22008. minLength: 1
  22009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22010. type: string
  22011. namespace:
  22012. description: |-
  22013. The namespace of the Secret resource being referred to.
  22014. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22015. maxLength: 63
  22016. minLength: 1
  22017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22018. type: string
  22019. type: object
  22020. token:
  22021. description: Token is the reference to the secret containing the STS(Security Token Service) Token.
  22022. properties:
  22023. key:
  22024. description: |-
  22025. A key in the referenced Secret.
  22026. Some instances of this field may be defaulted, in others it may be required.
  22027. maxLength: 253
  22028. minLength: 1
  22029. pattern: ^[-._a-zA-Z0-9]+$
  22030. type: string
  22031. name:
  22032. description: The name of the Secret resource being referred to.
  22033. maxLength: 253
  22034. minLength: 1
  22035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22036. type: string
  22037. namespace:
  22038. description: |-
  22039. The namespace of the Secret resource being referred to.
  22040. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22041. maxLength: 63
  22042. minLength: 1
  22043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22044. type: string
  22045. type: object
  22046. required:
  22047. - accessKeyID
  22048. - secretAccessKey
  22049. type: object
  22050. type: object
  22051. region:
  22052. description: Region specifies the Volcengine region to connect to.
  22053. type: string
  22054. required:
  22055. - region
  22056. type: object
  22057. webhook:
  22058. description: Webhook configures this store to sync secrets using a generic templated webhook
  22059. properties:
  22060. auth:
  22061. description: Auth specifies a authorization protocol. Only one protocol may be set.
  22062. maxProperties: 1
  22063. minProperties: 1
  22064. properties:
  22065. ntlm:
  22066. description: NTLMProtocol configures the store to use NTLM for auth
  22067. properties:
  22068. passwordSecret:
  22069. description: |-
  22070. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22071. In some instances, `key` is a required field.
  22072. properties:
  22073. key:
  22074. description: |-
  22075. A key in the referenced Secret.
  22076. Some instances of this field may be defaulted, in others it may be required.
  22077. maxLength: 253
  22078. minLength: 1
  22079. pattern: ^[-._a-zA-Z0-9]+$
  22080. type: string
  22081. name:
  22082. description: The name of the Secret resource being referred to.
  22083. maxLength: 253
  22084. minLength: 1
  22085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22086. type: string
  22087. namespace:
  22088. description: |-
  22089. The namespace of the Secret resource being referred to.
  22090. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22091. maxLength: 63
  22092. minLength: 1
  22093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22094. type: string
  22095. type: object
  22096. usernameSecret:
  22097. description: |-
  22098. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22099. In some instances, `key` is a required field.
  22100. properties:
  22101. key:
  22102. description: |-
  22103. A key in the referenced Secret.
  22104. Some instances of this field may be defaulted, in others it may be required.
  22105. maxLength: 253
  22106. minLength: 1
  22107. pattern: ^[-._a-zA-Z0-9]+$
  22108. type: string
  22109. name:
  22110. description: The name of the Secret resource being referred to.
  22111. maxLength: 253
  22112. minLength: 1
  22113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22114. type: string
  22115. namespace:
  22116. description: |-
  22117. The namespace of the Secret resource being referred to.
  22118. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22119. maxLength: 63
  22120. minLength: 1
  22121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22122. type: string
  22123. type: object
  22124. required:
  22125. - passwordSecret
  22126. - usernameSecret
  22127. type: object
  22128. type: object
  22129. body:
  22130. description: Body
  22131. type: string
  22132. caBundle:
  22133. description: |-
  22134. PEM encoded CA bundle used to validate webhook server certificate. Only used
  22135. if the Server URL is using HTTPS protocol. This parameter is ignored for
  22136. plain HTTP protocol connection. If not set the system root certificates
  22137. are used to validate the TLS connection.
  22138. format: byte
  22139. type: string
  22140. caProvider:
  22141. description: The provider for the CA bundle to use to validate webhook server certificate.
  22142. properties:
  22143. key:
  22144. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22145. maxLength: 253
  22146. minLength: 1
  22147. pattern: ^[-._a-zA-Z0-9]+$
  22148. type: string
  22149. name:
  22150. description: The name of the object located at the provider type.
  22151. maxLength: 253
  22152. minLength: 1
  22153. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22154. type: string
  22155. namespace:
  22156. description: The namespace the Provider type is in.
  22157. maxLength: 63
  22158. minLength: 1
  22159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22160. type: string
  22161. type:
  22162. description: The type of provider to use such as "Secret", or "ConfigMap".
  22163. enum:
  22164. - Secret
  22165. - ConfigMap
  22166. type: string
  22167. required:
  22168. - name
  22169. - type
  22170. type: object
  22171. headers:
  22172. additionalProperties:
  22173. type: string
  22174. description: Headers
  22175. type: object
  22176. method:
  22177. description: Webhook Method
  22178. type: string
  22179. result:
  22180. description: Result formatting
  22181. properties:
  22182. jsonPath:
  22183. description: Json path of return value
  22184. type: string
  22185. type: object
  22186. secrets:
  22187. description: |-
  22188. Secrets to fill in templates
  22189. These secrets will be passed to the templating function as key value pairs under the given name
  22190. items:
  22191. description: WebhookSecret defines a secret that will be passed to the webhook request.
  22192. properties:
  22193. name:
  22194. description: Name of this secret in templates
  22195. type: string
  22196. secretRef:
  22197. description: Secret ref to fill in credentials
  22198. properties:
  22199. key:
  22200. description: |-
  22201. A key in the referenced Secret.
  22202. Some instances of this field may be defaulted, in others it may be required.
  22203. maxLength: 253
  22204. minLength: 1
  22205. pattern: ^[-._a-zA-Z0-9]+$
  22206. type: string
  22207. name:
  22208. description: The name of the Secret resource being referred to.
  22209. maxLength: 253
  22210. minLength: 1
  22211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22212. type: string
  22213. namespace:
  22214. description: |-
  22215. The namespace of the Secret resource being referred to.
  22216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22217. maxLength: 63
  22218. minLength: 1
  22219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22220. type: string
  22221. type: object
  22222. required:
  22223. - name
  22224. - secretRef
  22225. type: object
  22226. type: array
  22227. timeout:
  22228. description: Timeout
  22229. type: string
  22230. url:
  22231. description: Webhook url to call
  22232. type: string
  22233. required:
  22234. - url
  22235. type: object
  22236. yandexcertificatemanager:
  22237. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  22238. properties:
  22239. apiEndpoint:
  22240. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22241. type: string
  22242. auth:
  22243. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22244. properties:
  22245. authorizedKeySecretRef:
  22246. description: The authorized key used for authentication
  22247. properties:
  22248. key:
  22249. description: |-
  22250. A key in the referenced Secret.
  22251. Some instances of this field may be defaulted, in others it may be required.
  22252. maxLength: 253
  22253. minLength: 1
  22254. pattern: ^[-._a-zA-Z0-9]+$
  22255. type: string
  22256. name:
  22257. description: The name of the Secret resource being referred to.
  22258. maxLength: 253
  22259. minLength: 1
  22260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22261. type: string
  22262. namespace:
  22263. description: |-
  22264. The namespace of the Secret resource being referred to.
  22265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22266. maxLength: 63
  22267. minLength: 1
  22268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22269. type: string
  22270. type: object
  22271. type: object
  22272. caProvider:
  22273. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22274. properties:
  22275. certSecretRef:
  22276. description: |-
  22277. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22278. In some instances, `key` is a required field.
  22279. properties:
  22280. key:
  22281. description: |-
  22282. A key in the referenced Secret.
  22283. Some instances of this field may be defaulted, in others it may be required.
  22284. maxLength: 253
  22285. minLength: 1
  22286. pattern: ^[-._a-zA-Z0-9]+$
  22287. type: string
  22288. name:
  22289. description: The name of the Secret resource being referred to.
  22290. maxLength: 253
  22291. minLength: 1
  22292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22293. type: string
  22294. namespace:
  22295. description: |-
  22296. The namespace of the Secret resource being referred to.
  22297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22298. maxLength: 63
  22299. minLength: 1
  22300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22301. type: string
  22302. type: object
  22303. type: object
  22304. fetching:
  22305. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as certificate ID or certificate name
  22306. maxProperties: 1
  22307. minProperties: 1
  22308. properties:
  22309. byID:
  22310. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22311. type: object
  22312. byName:
  22313. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22314. properties:
  22315. folderID:
  22316. description: The folder to fetch secrets from
  22317. type: string
  22318. required:
  22319. - folderID
  22320. type: object
  22321. type: object
  22322. required:
  22323. - auth
  22324. type: object
  22325. yandexlockbox:
  22326. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  22327. properties:
  22328. apiEndpoint:
  22329. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  22330. type: string
  22331. auth:
  22332. description: Auth defines the information necessary to authenticate against Yandex.Cloud
  22333. properties:
  22334. authorizedKeySecretRef:
  22335. description: The authorized key used for authentication
  22336. properties:
  22337. key:
  22338. description: |-
  22339. A key in the referenced Secret.
  22340. Some instances of this field may be defaulted, in others it may be required.
  22341. maxLength: 253
  22342. minLength: 1
  22343. pattern: ^[-._a-zA-Z0-9]+$
  22344. type: string
  22345. name:
  22346. description: The name of the Secret resource being referred to.
  22347. maxLength: 253
  22348. minLength: 1
  22349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22350. type: string
  22351. namespace:
  22352. description: |-
  22353. The namespace of the Secret resource being referred to.
  22354. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22355. maxLength: 63
  22356. minLength: 1
  22357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22358. type: string
  22359. type: object
  22360. type: object
  22361. caProvider:
  22362. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  22363. properties:
  22364. certSecretRef:
  22365. description: |-
  22366. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22367. In some instances, `key` is a required field.
  22368. properties:
  22369. key:
  22370. description: |-
  22371. A key in the referenced Secret.
  22372. Some instances of this field may be defaulted, in others it may be required.
  22373. maxLength: 253
  22374. minLength: 1
  22375. pattern: ^[-._a-zA-Z0-9]+$
  22376. type: string
  22377. name:
  22378. description: The name of the Secret resource being referred to.
  22379. maxLength: 253
  22380. minLength: 1
  22381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22382. type: string
  22383. namespace:
  22384. description: |-
  22385. The namespace of the Secret resource being referred to.
  22386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22387. maxLength: 63
  22388. minLength: 1
  22389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22390. type: string
  22391. type: object
  22392. type: object
  22393. fetching:
  22394. description: FetchingPolicy configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID or secret name
  22395. maxProperties: 1
  22396. minProperties: 1
  22397. properties:
  22398. byID:
  22399. description: ByID configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret ID.
  22400. type: object
  22401. byName:
  22402. description: ByName configures the provider to interpret the `data.secretKey.remoteRef.key` field in ExternalSecret as secret name.
  22403. properties:
  22404. folderID:
  22405. description: The folder to fetch secrets from
  22406. type: string
  22407. required:
  22408. - folderID
  22409. type: object
  22410. type: object
  22411. required:
  22412. - auth
  22413. type: object
  22414. type: object
  22415. refreshInterval:
  22416. anyOf:
  22417. - type: integer
  22418. - type: string
  22419. description: |-
  22420. Used to configure store refresh interval. Accepts either an integer number
  22421. of seconds (legacy) or a Go duration string such as "1h" or "5m". Empty or
  22422. 0 will default to the controller config.
  22423. x-kubernetes-int-or-string: true
  22424. retrySettings:
  22425. description: Used to configure HTTP retries on failures.
  22426. properties:
  22427. maxRetries:
  22428. format: int32
  22429. type: integer
  22430. retryInterval:
  22431. type: string
  22432. type: object
  22433. required:
  22434. - provider
  22435. type: object
  22436. status:
  22437. description: SecretStoreStatus defines the observed state of the SecretStore.
  22438. properties:
  22439. capabilities:
  22440. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  22441. type: string
  22442. conditions:
  22443. items:
  22444. description: SecretStoreStatusCondition contains condition information for a SecretStore.
  22445. properties:
  22446. lastTransitionTime:
  22447. format: date-time
  22448. type: string
  22449. message:
  22450. type: string
  22451. reason:
  22452. type: string
  22453. status:
  22454. type: string
  22455. type:
  22456. description: SecretStoreConditionType represents the condition of the SecretStore.
  22457. type: string
  22458. required:
  22459. - status
  22460. - type
  22461. type: object
  22462. type: array
  22463. type: object
  22464. type: object
  22465. served: true
  22466. storage: true
  22467. subresources:
  22468. status: {}
  22469. - additionalPrinterColumns:
  22470. - jsonPath: .metadata.creationTimestamp
  22471. name: AGE
  22472. type: date
  22473. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  22474. name: Status
  22475. type: string
  22476. - jsonPath: .status.capabilities
  22477. name: Capabilities
  22478. type: string
  22479. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  22480. name: Ready
  22481. type: string
  22482. deprecated: true
  22483. name: v1beta1
  22484. schema:
  22485. openAPIV3Schema:
  22486. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  22487. properties:
  22488. apiVersion:
  22489. description: |-
  22490. APIVersion defines the versioned schema of this representation of an object.
  22491. Servers should convert recognized schemas to the latest internal value, and
  22492. may reject unrecognized values.
  22493. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  22494. type: string
  22495. kind:
  22496. description: |-
  22497. Kind is a string value representing the REST resource this object represents.
  22498. Servers may infer this from the endpoint the client submits requests to.
  22499. Cannot be updated.
  22500. In CamelCase.
  22501. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  22502. type: string
  22503. metadata:
  22504. type: object
  22505. spec:
  22506. description: SecretStoreSpec defines the desired state of SecretStore.
  22507. properties:
  22508. conditions:
  22509. description: Used to constrain a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore.
  22510. items:
  22511. description: |-
  22512. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  22513. for a ClusterSecretStore instance.
  22514. properties:
  22515. namespaceRegexes:
  22516. description: Choose namespaces by using regex matching
  22517. items:
  22518. type: string
  22519. type: array
  22520. namespaceSelector:
  22521. description: Choose namespace using a labelSelector
  22522. properties:
  22523. matchExpressions:
  22524. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  22525. items:
  22526. description: |-
  22527. A label selector requirement is a selector that contains values, a key, and an operator that
  22528. relates the key and values.
  22529. properties:
  22530. key:
  22531. description: key is the label key that the selector applies to.
  22532. type: string
  22533. operator:
  22534. description: |-
  22535. operator represents a key's relationship to a set of values.
  22536. Valid operators are In, NotIn, Exists and DoesNotExist.
  22537. type: string
  22538. values:
  22539. description: |-
  22540. values is an array of string values. If the operator is In or NotIn,
  22541. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  22542. the values array must be empty. This array is replaced during a strategic
  22543. merge patch.
  22544. items:
  22545. type: string
  22546. type: array
  22547. x-kubernetes-list-type: atomic
  22548. required:
  22549. - key
  22550. - operator
  22551. type: object
  22552. type: array
  22553. x-kubernetes-list-type: atomic
  22554. matchLabels:
  22555. additionalProperties:
  22556. type: string
  22557. description: |-
  22558. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  22559. map is equivalent to an element of matchExpressions, whose key field is "key", the
  22560. operator is "In", and the values array contains only "value". The requirements are ANDed.
  22561. type: object
  22562. type: object
  22563. x-kubernetes-map-type: atomic
  22564. namespaces:
  22565. description: Choose namespaces by name
  22566. items:
  22567. maxLength: 63
  22568. minLength: 1
  22569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22570. type: string
  22571. type: array
  22572. type: object
  22573. type: array
  22574. controller:
  22575. description: |-
  22576. Used to select the correct ESO controller (think: ingress.ingressClassName)
  22577. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  22578. type: string
  22579. provider:
  22580. description: Used to configure the provider. Only one provider may be set
  22581. maxProperties: 1
  22582. minProperties: 1
  22583. properties:
  22584. akeyless:
  22585. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  22586. properties:
  22587. akeylessGWApiURL:
  22588. description: Akeyless GW API Url from which the secrets to be fetched from.
  22589. type: string
  22590. authSecretRef:
  22591. description: Auth configures how the operator authenticates with Akeyless.
  22592. properties:
  22593. kubernetesAuth:
  22594. description: |-
  22595. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  22596. token stored in the named Secret resource.
  22597. properties:
  22598. accessID:
  22599. description: the Akeyless Kubernetes auth-method access-id
  22600. type: string
  22601. k8sConfName:
  22602. description: Kubernetes-auth configuration name in Akeyless-Gateway
  22603. type: string
  22604. secretRef:
  22605. description: |-
  22606. Optional secret field containing a Kubernetes ServiceAccount JWT used
  22607. for authenticating with Akeyless. If a name is specified without a key,
  22608. `token` is the default. If one is not specified, the one bound to
  22609. the controller will be used.
  22610. properties:
  22611. key:
  22612. description: |-
  22613. A key in the referenced Secret.
  22614. Some instances of this field may be defaulted, in others it may be required.
  22615. maxLength: 253
  22616. minLength: 1
  22617. pattern: ^[-._a-zA-Z0-9]+$
  22618. type: string
  22619. name:
  22620. description: The name of the Secret resource being referred to.
  22621. maxLength: 253
  22622. minLength: 1
  22623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22624. type: string
  22625. namespace:
  22626. description: |-
  22627. The namespace of the Secret resource being referred to.
  22628. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22629. maxLength: 63
  22630. minLength: 1
  22631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22632. type: string
  22633. type: object
  22634. serviceAccountRef:
  22635. description: |-
  22636. Optional service account field containing the name of a kubernetes ServiceAccount.
  22637. If the service account is specified, the service account secret token JWT will be used
  22638. for authenticating with Akeyless. If the service account selector is not supplied,
  22639. the secretRef will be used instead.
  22640. properties:
  22641. audiences:
  22642. description: |-
  22643. Audience specifies the `aud` claim for the service account token
  22644. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22645. then this audiences will be appended to the list
  22646. items:
  22647. type: string
  22648. type: array
  22649. name:
  22650. description: The name of the ServiceAccount resource being referred to.
  22651. maxLength: 253
  22652. minLength: 1
  22653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22654. type: string
  22655. namespace:
  22656. description: |-
  22657. Namespace of the resource being referred to.
  22658. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22659. maxLength: 63
  22660. minLength: 1
  22661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22662. type: string
  22663. required:
  22664. - name
  22665. type: object
  22666. required:
  22667. - accessID
  22668. - k8sConfName
  22669. type: object
  22670. secretRef:
  22671. description: |-
  22672. Reference to a Secret that contains the details
  22673. to authenticate with Akeyless.
  22674. properties:
  22675. accessID:
  22676. description: The SecretAccessID is used for authentication
  22677. properties:
  22678. key:
  22679. description: |-
  22680. A key in the referenced Secret.
  22681. Some instances of this field may be defaulted, in others it may be required.
  22682. maxLength: 253
  22683. minLength: 1
  22684. pattern: ^[-._a-zA-Z0-9]+$
  22685. type: string
  22686. name:
  22687. description: The name of the Secret resource being referred to.
  22688. maxLength: 253
  22689. minLength: 1
  22690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22691. type: string
  22692. namespace:
  22693. description: |-
  22694. The namespace of the Secret resource being referred to.
  22695. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22696. maxLength: 63
  22697. minLength: 1
  22698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22699. type: string
  22700. type: object
  22701. accessType:
  22702. description: |-
  22703. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22704. In some instances, `key` is a required field.
  22705. properties:
  22706. key:
  22707. description: |-
  22708. A key in the referenced Secret.
  22709. Some instances of this field may be defaulted, in others it may be required.
  22710. maxLength: 253
  22711. minLength: 1
  22712. pattern: ^[-._a-zA-Z0-9]+$
  22713. type: string
  22714. name:
  22715. description: The name of the Secret resource being referred to.
  22716. maxLength: 253
  22717. minLength: 1
  22718. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22719. type: string
  22720. namespace:
  22721. description: |-
  22722. The namespace of the Secret resource being referred to.
  22723. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22724. maxLength: 63
  22725. minLength: 1
  22726. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22727. type: string
  22728. type: object
  22729. accessTypeParam:
  22730. description: |-
  22731. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  22732. In some instances, `key` is a required field.
  22733. properties:
  22734. key:
  22735. description: |-
  22736. A key in the referenced Secret.
  22737. Some instances of this field may be defaulted, in others it may be required.
  22738. maxLength: 253
  22739. minLength: 1
  22740. pattern: ^[-._a-zA-Z0-9]+$
  22741. type: string
  22742. name:
  22743. description: The name of the Secret resource being referred to.
  22744. maxLength: 253
  22745. minLength: 1
  22746. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22747. type: string
  22748. namespace:
  22749. description: |-
  22750. The namespace of the Secret resource being referred to.
  22751. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22752. maxLength: 63
  22753. minLength: 1
  22754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22755. type: string
  22756. type: object
  22757. type: object
  22758. type: object
  22759. caBundle:
  22760. description: |-
  22761. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  22762. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  22763. are used to validate the TLS connection.
  22764. format: byte
  22765. type: string
  22766. caProvider:
  22767. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  22768. properties:
  22769. key:
  22770. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  22771. maxLength: 253
  22772. minLength: 1
  22773. pattern: ^[-._a-zA-Z0-9]+$
  22774. type: string
  22775. name:
  22776. description: The name of the object located at the provider type.
  22777. maxLength: 253
  22778. minLength: 1
  22779. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22780. type: string
  22781. namespace:
  22782. description: |-
  22783. The namespace the Provider type is in.
  22784. Can only be defined when used in a ClusterSecretStore.
  22785. maxLength: 63
  22786. minLength: 1
  22787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22788. type: string
  22789. type:
  22790. description: The type of provider to use such as "Secret", or "ConfigMap".
  22791. enum:
  22792. - Secret
  22793. - ConfigMap
  22794. type: string
  22795. required:
  22796. - name
  22797. - type
  22798. type: object
  22799. required:
  22800. - akeylessGWApiURL
  22801. - authSecretRef
  22802. type: object
  22803. alibaba:
  22804. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  22805. properties:
  22806. auth:
  22807. description: AlibabaAuth contains a secretRef for credentials.
  22808. properties:
  22809. rrsa:
  22810. description: AlibabaRRSAAuth authenticates against Alibaba using RRSA (Resource-oriented RAM-based Service Authentication).
  22811. properties:
  22812. oidcProviderArn:
  22813. type: string
  22814. oidcTokenFilePath:
  22815. type: string
  22816. roleArn:
  22817. type: string
  22818. sessionName:
  22819. type: string
  22820. required:
  22821. - oidcProviderArn
  22822. - oidcTokenFilePath
  22823. - roleArn
  22824. - sessionName
  22825. type: object
  22826. secretRef:
  22827. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  22828. properties:
  22829. accessKeyIDSecretRef:
  22830. description: The AccessKeyID is used for authentication
  22831. properties:
  22832. key:
  22833. description: |-
  22834. A key in the referenced Secret.
  22835. Some instances of this field may be defaulted, in others it may be required.
  22836. maxLength: 253
  22837. minLength: 1
  22838. pattern: ^[-._a-zA-Z0-9]+$
  22839. type: string
  22840. name:
  22841. description: The name of the Secret resource being referred to.
  22842. maxLength: 253
  22843. minLength: 1
  22844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22845. type: string
  22846. namespace:
  22847. description: |-
  22848. The namespace of the Secret resource being referred to.
  22849. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22850. maxLength: 63
  22851. minLength: 1
  22852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22853. type: string
  22854. type: object
  22855. accessKeySecretSecretRef:
  22856. description: The AccessKeySecret is used for authentication
  22857. properties:
  22858. key:
  22859. description: |-
  22860. A key in the referenced Secret.
  22861. Some instances of this field may be defaulted, in others it may be required.
  22862. maxLength: 253
  22863. minLength: 1
  22864. pattern: ^[-._a-zA-Z0-9]+$
  22865. type: string
  22866. name:
  22867. description: The name of the Secret resource being referred to.
  22868. maxLength: 253
  22869. minLength: 1
  22870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22871. type: string
  22872. namespace:
  22873. description: |-
  22874. The namespace of the Secret resource being referred to.
  22875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22876. maxLength: 63
  22877. minLength: 1
  22878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22879. type: string
  22880. type: object
  22881. required:
  22882. - accessKeyIDSecretRef
  22883. - accessKeySecretSecretRef
  22884. type: object
  22885. type: object
  22886. regionID:
  22887. description: Alibaba Region to be used for the provider
  22888. type: string
  22889. required:
  22890. - auth
  22891. - regionID
  22892. type: object
  22893. aws:
  22894. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  22895. properties:
  22896. additionalRoles:
  22897. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  22898. items:
  22899. type: string
  22900. type: array
  22901. auth:
  22902. description: |-
  22903. Auth defines the information necessary to authenticate against AWS
  22904. if not set aws sdk will infer credentials from your environment
  22905. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  22906. properties:
  22907. jwt:
  22908. description: AWSJWTAuth authenticates against AWS using service account tokens from the Kubernetes cluster.
  22909. properties:
  22910. serviceAccountRef:
  22911. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  22912. properties:
  22913. audiences:
  22914. description: |-
  22915. Audience specifies the `aud` claim for the service account token
  22916. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  22917. then this audiences will be appended to the list
  22918. items:
  22919. type: string
  22920. type: array
  22921. name:
  22922. description: The name of the ServiceAccount resource being referred to.
  22923. maxLength: 253
  22924. minLength: 1
  22925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22926. type: string
  22927. namespace:
  22928. description: |-
  22929. Namespace of the resource being referred to.
  22930. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22931. maxLength: 63
  22932. minLength: 1
  22933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22934. type: string
  22935. required:
  22936. - name
  22937. type: object
  22938. type: object
  22939. secretRef:
  22940. description: |-
  22941. AWSAuthSecretRef holds secret references for AWS credentials
  22942. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  22943. properties:
  22944. accessKeyIDSecretRef:
  22945. description: The AccessKeyID is used for authentication
  22946. properties:
  22947. key:
  22948. description: |-
  22949. A key in the referenced Secret.
  22950. Some instances of this field may be defaulted, in others it may be required.
  22951. maxLength: 253
  22952. minLength: 1
  22953. pattern: ^[-._a-zA-Z0-9]+$
  22954. type: string
  22955. name:
  22956. description: The name of the Secret resource being referred to.
  22957. maxLength: 253
  22958. minLength: 1
  22959. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22960. type: string
  22961. namespace:
  22962. description: |-
  22963. The namespace of the Secret resource being referred to.
  22964. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22965. maxLength: 63
  22966. minLength: 1
  22967. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22968. type: string
  22969. type: object
  22970. secretAccessKeySecretRef:
  22971. description: The SecretAccessKey is used for authentication
  22972. properties:
  22973. key:
  22974. description: |-
  22975. A key in the referenced Secret.
  22976. Some instances of this field may be defaulted, in others it may be required.
  22977. maxLength: 253
  22978. minLength: 1
  22979. pattern: ^[-._a-zA-Z0-9]+$
  22980. type: string
  22981. name:
  22982. description: The name of the Secret resource being referred to.
  22983. maxLength: 253
  22984. minLength: 1
  22985. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  22986. type: string
  22987. namespace:
  22988. description: |-
  22989. The namespace of the Secret resource being referred to.
  22990. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  22991. maxLength: 63
  22992. minLength: 1
  22993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  22994. type: string
  22995. type: object
  22996. sessionTokenSecretRef:
  22997. description: |-
  22998. The SessionToken used for authentication
  22999. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  23000. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  23001. properties:
  23002. key:
  23003. description: |-
  23004. A key in the referenced Secret.
  23005. Some instances of this field may be defaulted, in others it may be required.
  23006. maxLength: 253
  23007. minLength: 1
  23008. pattern: ^[-._a-zA-Z0-9]+$
  23009. type: string
  23010. name:
  23011. description: The name of the Secret resource being referred to.
  23012. maxLength: 253
  23013. minLength: 1
  23014. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23015. type: string
  23016. namespace:
  23017. description: |-
  23018. The namespace of the Secret resource being referred to.
  23019. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23020. maxLength: 63
  23021. minLength: 1
  23022. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23023. type: string
  23024. type: object
  23025. type: object
  23026. type: object
  23027. externalID:
  23028. description: AWS External ID set on assumed IAM roles
  23029. type: string
  23030. prefix:
  23031. description: Prefix adds a prefix to all retrieved values.
  23032. type: string
  23033. region:
  23034. description: AWS Region to be used for the provider
  23035. type: string
  23036. role:
  23037. description: Role is a Role ARN which the provider will assume
  23038. type: string
  23039. secretsManager:
  23040. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  23041. properties:
  23042. forceDeleteWithoutRecovery:
  23043. description: |-
  23044. Specifies whether to delete the secret without any recovery window. You
  23045. can't use both this parameter and RecoveryWindowInDays in the same call.
  23046. If you don't use either, then by default Secrets Manager uses a 30 day
  23047. recovery window.
  23048. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  23049. type: boolean
  23050. recoveryWindowInDays:
  23051. description: |-
  23052. The number of days from 7 to 30 that Secrets Manager waits before
  23053. permanently deleting the secret. You can't use both this parameter and
  23054. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  23055. then by default Secrets Manager uses a 30 day recovery window.
  23056. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  23057. format: int64
  23058. type: integer
  23059. type: object
  23060. service:
  23061. description: Service defines which service should be used to fetch the secrets
  23062. enum:
  23063. - SecretsManager
  23064. - ParameterStore
  23065. type: string
  23066. sessionTags:
  23067. description: AWS STS assume role session tags
  23068. items:
  23069. description: Tag defines a tag key and value for AWS resources.
  23070. properties:
  23071. key:
  23072. type: string
  23073. value:
  23074. type: string
  23075. required:
  23076. - key
  23077. - value
  23078. type: object
  23079. type: array
  23080. transitiveTagKeys:
  23081. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  23082. items:
  23083. type: string
  23084. type: array
  23085. required:
  23086. - region
  23087. - service
  23088. type: object
  23089. azurekv:
  23090. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  23091. properties:
  23092. authSecretRef:
  23093. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23094. properties:
  23095. clientCertificate:
  23096. description: The Azure ClientCertificate of the service principle used for authentication.
  23097. properties:
  23098. key:
  23099. description: |-
  23100. A key in the referenced Secret.
  23101. Some instances of this field may be defaulted, in others it may be required.
  23102. maxLength: 253
  23103. minLength: 1
  23104. pattern: ^[-._a-zA-Z0-9]+$
  23105. type: string
  23106. name:
  23107. description: The name of the Secret resource being referred to.
  23108. maxLength: 253
  23109. minLength: 1
  23110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23111. type: string
  23112. namespace:
  23113. description: |-
  23114. The namespace of the Secret resource being referred to.
  23115. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23116. maxLength: 63
  23117. minLength: 1
  23118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23119. type: string
  23120. type: object
  23121. clientId:
  23122. description: The Azure clientId of the service principle or managed identity used for authentication.
  23123. properties:
  23124. key:
  23125. description: |-
  23126. A key in the referenced Secret.
  23127. Some instances of this field may be defaulted, in others it may be required.
  23128. maxLength: 253
  23129. minLength: 1
  23130. pattern: ^[-._a-zA-Z0-9]+$
  23131. type: string
  23132. name:
  23133. description: The name of the Secret resource being referred to.
  23134. maxLength: 253
  23135. minLength: 1
  23136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23137. type: string
  23138. namespace:
  23139. description: |-
  23140. The namespace of the Secret resource being referred to.
  23141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23142. maxLength: 63
  23143. minLength: 1
  23144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23145. type: string
  23146. type: object
  23147. clientSecret:
  23148. description: The Azure ClientSecret of the service principle used for authentication.
  23149. properties:
  23150. key:
  23151. description: |-
  23152. A key in the referenced Secret.
  23153. Some instances of this field may be defaulted, in others it may be required.
  23154. maxLength: 253
  23155. minLength: 1
  23156. pattern: ^[-._a-zA-Z0-9]+$
  23157. type: string
  23158. name:
  23159. description: The name of the Secret resource being referred to.
  23160. maxLength: 253
  23161. minLength: 1
  23162. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23163. type: string
  23164. namespace:
  23165. description: |-
  23166. The namespace of the Secret resource being referred to.
  23167. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23168. maxLength: 63
  23169. minLength: 1
  23170. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23171. type: string
  23172. type: object
  23173. tenantId:
  23174. description: The Azure tenantId of the managed identity used for authentication.
  23175. properties:
  23176. key:
  23177. description: |-
  23178. A key in the referenced Secret.
  23179. Some instances of this field may be defaulted, in others it may be required.
  23180. maxLength: 253
  23181. minLength: 1
  23182. pattern: ^[-._a-zA-Z0-9]+$
  23183. type: string
  23184. name:
  23185. description: The name of the Secret resource being referred to.
  23186. maxLength: 253
  23187. minLength: 1
  23188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23189. type: string
  23190. namespace:
  23191. description: |-
  23192. The namespace of the Secret resource being referred to.
  23193. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23194. maxLength: 63
  23195. minLength: 1
  23196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23197. type: string
  23198. type: object
  23199. type: object
  23200. authType:
  23201. default: ServicePrincipal
  23202. description: |-
  23203. Auth type defines how to authenticate to the keyvault service.
  23204. Valid values are:
  23205. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  23206. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  23207. enum:
  23208. - ServicePrincipal
  23209. - ManagedIdentity
  23210. - WorkloadIdentity
  23211. type: string
  23212. environmentType:
  23213. default: PublicCloud
  23214. description: |-
  23215. EnvironmentType specifies the Azure cloud environment endpoints to use for
  23216. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  23217. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  23218. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  23219. enum:
  23220. - PublicCloud
  23221. - USGovernmentCloud
  23222. - ChinaCloud
  23223. - GermanCloud
  23224. type: string
  23225. identityId:
  23226. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  23227. type: string
  23228. serviceAccountRef:
  23229. description: |-
  23230. ServiceAccountRef specified the service account
  23231. that should be used when authenticating with WorkloadIdentity.
  23232. properties:
  23233. audiences:
  23234. description: |-
  23235. Audience specifies the `aud` claim for the service account token
  23236. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23237. then this audiences will be appended to the list
  23238. items:
  23239. type: string
  23240. type: array
  23241. name:
  23242. description: The name of the ServiceAccount resource being referred to.
  23243. maxLength: 253
  23244. minLength: 1
  23245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23246. type: string
  23247. namespace:
  23248. description: |-
  23249. Namespace of the resource being referred to.
  23250. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23251. maxLength: 63
  23252. minLength: 1
  23253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23254. type: string
  23255. required:
  23256. - name
  23257. type: object
  23258. tenantId:
  23259. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  23260. type: string
  23261. vaultUrl:
  23262. description: Vault Url from which the secrets to be fetched from.
  23263. type: string
  23264. required:
  23265. - vaultUrl
  23266. type: object
  23267. beyondtrust:
  23268. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  23269. properties:
  23270. auth:
  23271. description: Auth configures how the operator authenticates with Beyondtrust.
  23272. properties:
  23273. apiKey:
  23274. description: APIKey If not provided then ClientID/ClientSecret become required.
  23275. properties:
  23276. secretRef:
  23277. description: SecretRef references a key in a secret that will be used as value.
  23278. properties:
  23279. key:
  23280. description: |-
  23281. A key in the referenced Secret.
  23282. Some instances of this field may be defaulted, in others it may be required.
  23283. maxLength: 253
  23284. minLength: 1
  23285. pattern: ^[-._a-zA-Z0-9]+$
  23286. type: string
  23287. name:
  23288. description: The name of the Secret resource being referred to.
  23289. maxLength: 253
  23290. minLength: 1
  23291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23292. type: string
  23293. namespace:
  23294. description: |-
  23295. The namespace of the Secret resource being referred to.
  23296. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23297. maxLength: 63
  23298. minLength: 1
  23299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23300. type: string
  23301. type: object
  23302. value:
  23303. description: Value can be specified directly to set a value without using a secret.
  23304. type: string
  23305. type: object
  23306. certificate:
  23307. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  23308. properties:
  23309. secretRef:
  23310. description: SecretRef references a key in a secret that will be used as value.
  23311. properties:
  23312. key:
  23313. description: |-
  23314. A key in the referenced Secret.
  23315. Some instances of this field may be defaulted, in others it may be required.
  23316. maxLength: 253
  23317. minLength: 1
  23318. pattern: ^[-._a-zA-Z0-9]+$
  23319. type: string
  23320. name:
  23321. description: The name of the Secret resource being referred to.
  23322. maxLength: 253
  23323. minLength: 1
  23324. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23325. type: string
  23326. namespace:
  23327. description: |-
  23328. The namespace of the Secret resource being referred to.
  23329. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23330. maxLength: 63
  23331. minLength: 1
  23332. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23333. type: string
  23334. type: object
  23335. value:
  23336. description: Value can be specified directly to set a value without using a secret.
  23337. type: string
  23338. type: object
  23339. certificateKey:
  23340. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  23341. properties:
  23342. secretRef:
  23343. description: SecretRef references a key in a secret that will be used as value.
  23344. properties:
  23345. key:
  23346. description: |-
  23347. A key in the referenced Secret.
  23348. Some instances of this field may be defaulted, in others it may be required.
  23349. maxLength: 253
  23350. minLength: 1
  23351. pattern: ^[-._a-zA-Z0-9]+$
  23352. type: string
  23353. name:
  23354. description: The name of the Secret resource being referred to.
  23355. maxLength: 253
  23356. minLength: 1
  23357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23358. type: string
  23359. namespace:
  23360. description: |-
  23361. The namespace of the Secret resource being referred to.
  23362. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23363. maxLength: 63
  23364. minLength: 1
  23365. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23366. type: string
  23367. type: object
  23368. value:
  23369. description: Value can be specified directly to set a value without using a secret.
  23370. type: string
  23371. type: object
  23372. clientId:
  23373. description: ClientID is the API OAuth Client ID.
  23374. properties:
  23375. secretRef:
  23376. description: SecretRef references a key in a secret that will be used as value.
  23377. properties:
  23378. key:
  23379. description: |-
  23380. A key in the referenced Secret.
  23381. Some instances of this field may be defaulted, in others it may be required.
  23382. maxLength: 253
  23383. minLength: 1
  23384. pattern: ^[-._a-zA-Z0-9]+$
  23385. type: string
  23386. name:
  23387. description: The name of the Secret resource being referred to.
  23388. maxLength: 253
  23389. minLength: 1
  23390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23391. type: string
  23392. namespace:
  23393. description: |-
  23394. The namespace of the Secret resource being referred to.
  23395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23396. maxLength: 63
  23397. minLength: 1
  23398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23399. type: string
  23400. type: object
  23401. value:
  23402. description: Value can be specified directly to set a value without using a secret.
  23403. type: string
  23404. type: object
  23405. clientSecret:
  23406. description: ClientSecret is the API OAuth Client Secret.
  23407. properties:
  23408. secretRef:
  23409. description: SecretRef references a key in a secret that will be used as value.
  23410. properties:
  23411. key:
  23412. description: |-
  23413. A key in the referenced Secret.
  23414. Some instances of this field may be defaulted, in others it may be required.
  23415. maxLength: 253
  23416. minLength: 1
  23417. pattern: ^[-._a-zA-Z0-9]+$
  23418. type: string
  23419. name:
  23420. description: The name of the Secret resource being referred to.
  23421. maxLength: 253
  23422. minLength: 1
  23423. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23424. type: string
  23425. namespace:
  23426. description: |-
  23427. The namespace of the Secret resource being referred to.
  23428. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23429. maxLength: 63
  23430. minLength: 1
  23431. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23432. type: string
  23433. type: object
  23434. value:
  23435. description: Value can be specified directly to set a value without using a secret.
  23436. type: string
  23437. type: object
  23438. type: object
  23439. server:
  23440. description: Auth configures how API server works.
  23441. properties:
  23442. apiUrl:
  23443. type: string
  23444. apiVersion:
  23445. type: string
  23446. clientTimeOutSeconds:
  23447. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  23448. type: integer
  23449. decrypt:
  23450. default: true
  23451. description: 'When true, the response includes the decrypted password. When false, the password field is omitted. This option only applies to the SECRET retrieval type. Default: true.'
  23452. type: boolean
  23453. retrievalType:
  23454. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  23455. type: string
  23456. separator:
  23457. description: A character that separates the folder names.
  23458. type: string
  23459. verifyCA:
  23460. type: boolean
  23461. required:
  23462. - apiUrl
  23463. - verifyCA
  23464. type: object
  23465. required:
  23466. - auth
  23467. - server
  23468. type: object
  23469. bitwardensecretsmanager:
  23470. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  23471. properties:
  23472. apiURL:
  23473. type: string
  23474. auth:
  23475. description: |-
  23476. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  23477. Make sure that the token being used has permissions on the given secret.
  23478. properties:
  23479. secretRef:
  23480. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  23481. properties:
  23482. credentials:
  23483. description: AccessToken used for the bitwarden instance.
  23484. properties:
  23485. key:
  23486. description: |-
  23487. A key in the referenced Secret.
  23488. Some instances of this field may be defaulted, in others it may be required.
  23489. maxLength: 253
  23490. minLength: 1
  23491. pattern: ^[-._a-zA-Z0-9]+$
  23492. type: string
  23493. name:
  23494. description: The name of the Secret resource being referred to.
  23495. maxLength: 253
  23496. minLength: 1
  23497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23498. type: string
  23499. namespace:
  23500. description: |-
  23501. The namespace of the Secret resource being referred to.
  23502. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23503. maxLength: 63
  23504. minLength: 1
  23505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23506. type: string
  23507. type: object
  23508. required:
  23509. - credentials
  23510. type: object
  23511. required:
  23512. - secretRef
  23513. type: object
  23514. bitwardenServerSDKURL:
  23515. type: string
  23516. caBundle:
  23517. description: |-
  23518. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  23519. can be performed.
  23520. type: string
  23521. caProvider:
  23522. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  23523. properties:
  23524. key:
  23525. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23526. maxLength: 253
  23527. minLength: 1
  23528. pattern: ^[-._a-zA-Z0-9]+$
  23529. type: string
  23530. name:
  23531. description: The name of the object located at the provider type.
  23532. maxLength: 253
  23533. minLength: 1
  23534. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23535. type: string
  23536. namespace:
  23537. description: |-
  23538. The namespace the Provider type is in.
  23539. Can only be defined when used in a ClusterSecretStore.
  23540. maxLength: 63
  23541. minLength: 1
  23542. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23543. type: string
  23544. type:
  23545. description: The type of provider to use such as "Secret", or "ConfigMap".
  23546. enum:
  23547. - Secret
  23548. - ConfigMap
  23549. type: string
  23550. required:
  23551. - name
  23552. - type
  23553. type: object
  23554. identityURL:
  23555. type: string
  23556. organizationID:
  23557. description: OrganizationID determines which organization this secret store manages.
  23558. type: string
  23559. projectID:
  23560. description: ProjectID determines which project this secret store manages.
  23561. type: string
  23562. required:
  23563. - auth
  23564. - organizationID
  23565. - projectID
  23566. type: object
  23567. chef:
  23568. description: Chef configures this store to sync secrets with chef server
  23569. properties:
  23570. auth:
  23571. description: Auth defines the information necessary to authenticate against chef Server
  23572. properties:
  23573. secretRef:
  23574. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  23575. properties:
  23576. privateKeySecretRef:
  23577. description: SecretKey is the Signing Key in PEM format, used for authentication.
  23578. properties:
  23579. key:
  23580. description: |-
  23581. A key in the referenced Secret.
  23582. Some instances of this field may be defaulted, in others it may be required.
  23583. maxLength: 253
  23584. minLength: 1
  23585. pattern: ^[-._a-zA-Z0-9]+$
  23586. type: string
  23587. name:
  23588. description: The name of the Secret resource being referred to.
  23589. maxLength: 253
  23590. minLength: 1
  23591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23592. type: string
  23593. namespace:
  23594. description: |-
  23595. The namespace of the Secret resource being referred to.
  23596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23597. maxLength: 63
  23598. minLength: 1
  23599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23600. type: string
  23601. type: object
  23602. required:
  23603. - privateKeySecretRef
  23604. type: object
  23605. required:
  23606. - secretRef
  23607. type: object
  23608. serverUrl:
  23609. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  23610. type: string
  23611. username:
  23612. description: UserName should be the user ID on the chef server
  23613. type: string
  23614. required:
  23615. - auth
  23616. - serverUrl
  23617. - username
  23618. type: object
  23619. cloudrusm:
  23620. description: CloudruSM configures this store to sync secrets using the Cloud.ru Secret Manager provider
  23621. properties:
  23622. auth:
  23623. description: CSMAuth contains a secretRef for credentials.
  23624. properties:
  23625. secretRef:
  23626. description: CSMAuthSecretRef holds secret references for Cloud.ru credentials.
  23627. properties:
  23628. accessKeyIDSecretRef:
  23629. description: The AccessKeyID is used for authentication
  23630. properties:
  23631. key:
  23632. description: |-
  23633. A key in the referenced Secret.
  23634. Some instances of this field may be defaulted, in others it may be required.
  23635. maxLength: 253
  23636. minLength: 1
  23637. pattern: ^[-._a-zA-Z0-9]+$
  23638. type: string
  23639. name:
  23640. description: The name of the Secret resource being referred to.
  23641. maxLength: 253
  23642. minLength: 1
  23643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23644. type: string
  23645. namespace:
  23646. description: |-
  23647. The namespace of the Secret resource being referred to.
  23648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23649. maxLength: 63
  23650. minLength: 1
  23651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23652. type: string
  23653. type: object
  23654. accessKeySecretSecretRef:
  23655. description: The AccessKeySecret is used for authentication
  23656. properties:
  23657. key:
  23658. description: |-
  23659. A key in the referenced Secret.
  23660. Some instances of this field may be defaulted, in others it may be required.
  23661. maxLength: 253
  23662. minLength: 1
  23663. pattern: ^[-._a-zA-Z0-9]+$
  23664. type: string
  23665. name:
  23666. description: The name of the Secret resource being referred to.
  23667. maxLength: 253
  23668. minLength: 1
  23669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23670. type: string
  23671. namespace:
  23672. description: |-
  23673. The namespace of the Secret resource being referred to.
  23674. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23675. maxLength: 63
  23676. minLength: 1
  23677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23678. type: string
  23679. type: object
  23680. required:
  23681. - accessKeyIDSecretRef
  23682. - accessKeySecretSecretRef
  23683. type: object
  23684. type: object
  23685. projectID:
  23686. description: ProjectID is the project, which the secrets are stored in.
  23687. type: string
  23688. required:
  23689. - auth
  23690. type: object
  23691. conjur:
  23692. description: Conjur configures this store to sync secrets using conjur provider
  23693. properties:
  23694. auth:
  23695. description: Defines authentication settings for connecting to Conjur.
  23696. properties:
  23697. apikey:
  23698. description: Authenticates with Conjur using an API key.
  23699. properties:
  23700. account:
  23701. description: Account is the Conjur organization account name.
  23702. type: string
  23703. apiKeyRef:
  23704. description: |-
  23705. A reference to a specific 'key' containing the Conjur API key
  23706. within a Secret resource. In some instances, `key` is a required field.
  23707. properties:
  23708. key:
  23709. description: |-
  23710. A key in the referenced Secret.
  23711. Some instances of this field may be defaulted, in others it may be required.
  23712. maxLength: 253
  23713. minLength: 1
  23714. pattern: ^[-._a-zA-Z0-9]+$
  23715. type: string
  23716. name:
  23717. description: The name of the Secret resource being referred to.
  23718. maxLength: 253
  23719. minLength: 1
  23720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23721. type: string
  23722. namespace:
  23723. description: |-
  23724. The namespace of the Secret resource being referred to.
  23725. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23726. maxLength: 63
  23727. minLength: 1
  23728. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23729. type: string
  23730. type: object
  23731. userRef:
  23732. description: |-
  23733. A reference to a specific 'key' containing the Conjur username
  23734. within a Secret resource. In some instances, `key` is a required field.
  23735. properties:
  23736. key:
  23737. description: |-
  23738. A key in the referenced Secret.
  23739. Some instances of this field may be defaulted, in others it may be required.
  23740. maxLength: 253
  23741. minLength: 1
  23742. pattern: ^[-._a-zA-Z0-9]+$
  23743. type: string
  23744. name:
  23745. description: The name of the Secret resource being referred to.
  23746. maxLength: 253
  23747. minLength: 1
  23748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23749. type: string
  23750. namespace:
  23751. description: |-
  23752. The namespace of the Secret resource being referred to.
  23753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23754. maxLength: 63
  23755. minLength: 1
  23756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23757. type: string
  23758. type: object
  23759. required:
  23760. - account
  23761. - apiKeyRef
  23762. - userRef
  23763. type: object
  23764. jwt:
  23765. description: Jwt enables JWT authentication using Kubernetes service account tokens.
  23766. properties:
  23767. account:
  23768. description: Account is the Conjur organization account name.
  23769. type: string
  23770. hostId:
  23771. description: |-
  23772. Optional HostID for JWT authentication. This may be used depending
  23773. on how the Conjur JWT authenticator policy is configured.
  23774. type: string
  23775. secretRef:
  23776. description: |-
  23777. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  23778. authenticate with Conjur using the JWT authentication method.
  23779. properties:
  23780. key:
  23781. description: |-
  23782. A key in the referenced Secret.
  23783. Some instances of this field may be defaulted, in others it may be required.
  23784. maxLength: 253
  23785. minLength: 1
  23786. pattern: ^[-._a-zA-Z0-9]+$
  23787. type: string
  23788. name:
  23789. description: The name of the Secret resource being referred to.
  23790. maxLength: 253
  23791. minLength: 1
  23792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23793. type: string
  23794. namespace:
  23795. description: |-
  23796. The namespace of the Secret resource being referred to.
  23797. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23798. maxLength: 63
  23799. minLength: 1
  23800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23801. type: string
  23802. type: object
  23803. serviceAccountRef:
  23804. description: |-
  23805. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  23806. a token for with the `TokenRequest` API.
  23807. properties:
  23808. audiences:
  23809. description: |-
  23810. Audience specifies the `aud` claim for the service account token
  23811. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  23812. then this audiences will be appended to the list
  23813. items:
  23814. type: string
  23815. type: array
  23816. name:
  23817. description: The name of the ServiceAccount resource being referred to.
  23818. maxLength: 253
  23819. minLength: 1
  23820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23821. type: string
  23822. namespace:
  23823. description: |-
  23824. Namespace of the resource being referred to.
  23825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23826. maxLength: 63
  23827. minLength: 1
  23828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23829. type: string
  23830. required:
  23831. - name
  23832. type: object
  23833. serviceID:
  23834. description: The conjur authn jwt webservice id
  23835. type: string
  23836. required:
  23837. - account
  23838. - serviceID
  23839. type: object
  23840. type: object
  23841. caBundle:
  23842. description: CABundle is a PEM encoded CA bundle that will be used to validate the Conjur server certificate.
  23843. type: string
  23844. caProvider:
  23845. description: |-
  23846. Used to provide custom certificate authority (CA) certificates
  23847. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  23848. that contains a PEM-encoded certificate.
  23849. properties:
  23850. key:
  23851. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  23852. maxLength: 253
  23853. minLength: 1
  23854. pattern: ^[-._a-zA-Z0-9]+$
  23855. type: string
  23856. name:
  23857. description: The name of the object located at the provider type.
  23858. maxLength: 253
  23859. minLength: 1
  23860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23861. type: string
  23862. namespace:
  23863. description: |-
  23864. The namespace the Provider type is in.
  23865. Can only be defined when used in a ClusterSecretStore.
  23866. maxLength: 63
  23867. minLength: 1
  23868. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23869. type: string
  23870. type:
  23871. description: The type of provider to use such as "Secret", or "ConfigMap".
  23872. enum:
  23873. - Secret
  23874. - ConfigMap
  23875. type: string
  23876. required:
  23877. - name
  23878. - type
  23879. type: object
  23880. url:
  23881. description: URL is the endpoint of the Conjur instance.
  23882. type: string
  23883. required:
  23884. - auth
  23885. - url
  23886. type: object
  23887. delinea:
  23888. description: |-
  23889. Delinea DevOps Secrets Vault
  23890. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  23891. properties:
  23892. clientId:
  23893. description: ClientID is the non-secret part of the credential.
  23894. properties:
  23895. secretRef:
  23896. description: SecretRef references a key in a secret that will be used as value.
  23897. properties:
  23898. key:
  23899. description: |-
  23900. A key in the referenced Secret.
  23901. Some instances of this field may be defaulted, in others it may be required.
  23902. maxLength: 253
  23903. minLength: 1
  23904. pattern: ^[-._a-zA-Z0-9]+$
  23905. type: string
  23906. name:
  23907. description: The name of the Secret resource being referred to.
  23908. maxLength: 253
  23909. minLength: 1
  23910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23911. type: string
  23912. namespace:
  23913. description: |-
  23914. The namespace of the Secret resource being referred to.
  23915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23916. maxLength: 63
  23917. minLength: 1
  23918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23919. type: string
  23920. type: object
  23921. value:
  23922. description: Value can be specified directly to set a value without using a secret.
  23923. type: string
  23924. type: object
  23925. clientSecret:
  23926. description: ClientSecret is the secret part of the credential.
  23927. properties:
  23928. secretRef:
  23929. description: SecretRef references a key in a secret that will be used as value.
  23930. properties:
  23931. key:
  23932. description: |-
  23933. A key in the referenced Secret.
  23934. Some instances of this field may be defaulted, in others it may be required.
  23935. maxLength: 253
  23936. minLength: 1
  23937. pattern: ^[-._a-zA-Z0-9]+$
  23938. type: string
  23939. name:
  23940. description: The name of the Secret resource being referred to.
  23941. maxLength: 253
  23942. minLength: 1
  23943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  23944. type: string
  23945. namespace:
  23946. description: |-
  23947. The namespace of the Secret resource being referred to.
  23948. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  23949. maxLength: 63
  23950. minLength: 1
  23951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  23952. type: string
  23953. type: object
  23954. value:
  23955. description: Value can be specified directly to set a value without using a secret.
  23956. type: string
  23957. type: object
  23958. tenant:
  23959. description: Tenant is the chosen hostname / site name.
  23960. type: string
  23961. tld:
  23962. description: |-
  23963. TLD is based on the server location that was chosen during provisioning.
  23964. If unset, defaults to "com".
  23965. type: string
  23966. urlTemplate:
  23967. description: |-
  23968. URLTemplate
  23969. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  23970. type: string
  23971. required:
  23972. - clientId
  23973. - clientSecret
  23974. - tenant
  23975. type: object
  23976. device42:
  23977. description: Device42 configures this store to sync secrets using the Device42 provider
  23978. properties:
  23979. auth:
  23980. description: Auth configures how secret-manager authenticates with a Device42 instance.
  23981. properties:
  23982. secretRef:
  23983. description: Device42SecretRef defines a reference to a secret containing credentials for the Device42 provider.
  23984. properties:
  23985. credentials:
  23986. description: Username / Password is used for authentication.
  23987. properties:
  23988. key:
  23989. description: |-
  23990. A key in the referenced Secret.
  23991. Some instances of this field may be defaulted, in others it may be required.
  23992. maxLength: 253
  23993. minLength: 1
  23994. pattern: ^[-._a-zA-Z0-9]+$
  23995. type: string
  23996. name:
  23997. description: The name of the Secret resource being referred to.
  23998. maxLength: 253
  23999. minLength: 1
  24000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24001. type: string
  24002. namespace:
  24003. description: |-
  24004. The namespace of the Secret resource being referred to.
  24005. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24006. maxLength: 63
  24007. minLength: 1
  24008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24009. type: string
  24010. type: object
  24011. type: object
  24012. required:
  24013. - secretRef
  24014. type: object
  24015. host:
  24016. description: URL configures the Device42 instance URL.
  24017. type: string
  24018. required:
  24019. - auth
  24020. - host
  24021. type: object
  24022. doppler:
  24023. description: Doppler configures this store to sync secrets using the Doppler provider
  24024. properties:
  24025. auth:
  24026. description: Auth configures how the Operator authenticates with the Doppler API
  24027. properties:
  24028. secretRef:
  24029. description: DopplerAuthSecretRef defines a reference to a secret containing credentials for the Doppler provider.
  24030. properties:
  24031. dopplerToken:
  24032. description: |-
  24033. The DopplerToken is used for authentication.
  24034. See https://docs.doppler.com/reference/api#authentication for auth token types.
  24035. The Key attribute defaults to dopplerToken if not specified.
  24036. properties:
  24037. key:
  24038. description: |-
  24039. A key in the referenced Secret.
  24040. Some instances of this field may be defaulted, in others it may be required.
  24041. maxLength: 253
  24042. minLength: 1
  24043. pattern: ^[-._a-zA-Z0-9]+$
  24044. type: string
  24045. name:
  24046. description: The name of the Secret resource being referred to.
  24047. maxLength: 253
  24048. minLength: 1
  24049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24050. type: string
  24051. namespace:
  24052. description: |-
  24053. The namespace of the Secret resource being referred to.
  24054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24055. maxLength: 63
  24056. minLength: 1
  24057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24058. type: string
  24059. type: object
  24060. required:
  24061. - dopplerToken
  24062. type: object
  24063. required:
  24064. - secretRef
  24065. type: object
  24066. config:
  24067. description: Doppler config (required if not using a Service Token)
  24068. type: string
  24069. format:
  24070. description: Format enables the downloading of secrets as a file (string)
  24071. enum:
  24072. - json
  24073. - dotnet-json
  24074. - env
  24075. - yaml
  24076. - docker
  24077. type: string
  24078. nameTransformer:
  24079. description: Environment variable compatible name transforms that change secret names to a different format
  24080. enum:
  24081. - upper-camel
  24082. - camel
  24083. - lower-snake
  24084. - tf-var
  24085. - dotnet-env
  24086. - lower-kebab
  24087. type: string
  24088. project:
  24089. description: Doppler project (required if not using a Service Token)
  24090. type: string
  24091. required:
  24092. - auth
  24093. type: object
  24094. fake:
  24095. description: Fake configures a store with static key/value pairs
  24096. properties:
  24097. data:
  24098. items:
  24099. description: FakeProviderData defines a key-value pair for the fake provider used in testing.
  24100. properties:
  24101. key:
  24102. type: string
  24103. value:
  24104. type: string
  24105. version:
  24106. type: string
  24107. required:
  24108. - key
  24109. - value
  24110. type: object
  24111. type: array
  24112. required:
  24113. - data
  24114. type: object
  24115. fortanix:
  24116. description: Fortanix configures this store to sync secrets using the Fortanix provider
  24117. properties:
  24118. apiKey:
  24119. description: APIKey is the API token to access SDKMS Applications.
  24120. properties:
  24121. secretRef:
  24122. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  24123. properties:
  24124. key:
  24125. description: |-
  24126. A key in the referenced Secret.
  24127. Some instances of this field may be defaulted, in others it may be required.
  24128. maxLength: 253
  24129. minLength: 1
  24130. pattern: ^[-._a-zA-Z0-9]+$
  24131. type: string
  24132. name:
  24133. description: The name of the Secret resource being referred to.
  24134. maxLength: 253
  24135. minLength: 1
  24136. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24137. type: string
  24138. namespace:
  24139. description: |-
  24140. The namespace of the Secret resource being referred to.
  24141. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24142. maxLength: 63
  24143. minLength: 1
  24144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24145. type: string
  24146. type: object
  24147. type: object
  24148. apiUrl:
  24149. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  24150. type: string
  24151. type: object
  24152. gcpsm:
  24153. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  24154. properties:
  24155. auth:
  24156. description: Auth defines the information necessary to authenticate against GCP
  24157. properties:
  24158. secretRef:
  24159. description: GCPSMAuthSecretRef defines a reference to a secret containing credentials for the GCP Secret Manager provider.
  24160. properties:
  24161. secretAccessKeySecretRef:
  24162. description: The SecretAccessKey is used for authentication
  24163. properties:
  24164. key:
  24165. description: |-
  24166. A key in the referenced Secret.
  24167. Some instances of this field may be defaulted, in others it may be required.
  24168. maxLength: 253
  24169. minLength: 1
  24170. pattern: ^[-._a-zA-Z0-9]+$
  24171. type: string
  24172. name:
  24173. description: The name of the Secret resource being referred to.
  24174. maxLength: 253
  24175. minLength: 1
  24176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24177. type: string
  24178. namespace:
  24179. description: |-
  24180. The namespace of the Secret resource being referred to.
  24181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24182. maxLength: 63
  24183. minLength: 1
  24184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24185. type: string
  24186. type: object
  24187. type: object
  24188. workloadIdentity:
  24189. description: GCPWorkloadIdentity defines configuration for using GCP Workload Identity authentication.
  24190. properties:
  24191. clusterLocation:
  24192. description: |-
  24193. ClusterLocation is the location of the cluster
  24194. If not specified, it fetches information from the metadata server
  24195. type: string
  24196. clusterName:
  24197. description: |-
  24198. ClusterName is the name of the cluster
  24199. If not specified, it fetches information from the metadata server
  24200. type: string
  24201. clusterProjectID:
  24202. description: |-
  24203. ClusterProjectID is the project ID of the cluster
  24204. If not specified, it fetches information from the metadata server
  24205. type: string
  24206. serviceAccountRef:
  24207. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  24208. properties:
  24209. audiences:
  24210. description: |-
  24211. Audience specifies the `aud` claim for the service account token
  24212. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24213. then this audiences will be appended to the list
  24214. items:
  24215. type: string
  24216. type: array
  24217. name:
  24218. description: The name of the ServiceAccount resource being referred to.
  24219. maxLength: 253
  24220. minLength: 1
  24221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24222. type: string
  24223. namespace:
  24224. description: |-
  24225. Namespace of the resource being referred to.
  24226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24227. maxLength: 63
  24228. minLength: 1
  24229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24230. type: string
  24231. required:
  24232. - name
  24233. type: object
  24234. required:
  24235. - serviceAccountRef
  24236. type: object
  24237. type: object
  24238. location:
  24239. description: Location optionally defines a location for a secret
  24240. type: string
  24241. projectID:
  24242. description: ProjectID project where secret is located
  24243. type: string
  24244. type: object
  24245. github:
  24246. description: Github configures this store to push GitHub Actions secrets using the GitHub API provider.
  24247. properties:
  24248. appID:
  24249. description: appID specifies the Github APP that will be used to authenticate the client
  24250. format: int64
  24251. type: integer
  24252. auth:
  24253. description: auth configures how secret-manager authenticates with a Github instance.
  24254. properties:
  24255. privateKey:
  24256. description: |-
  24257. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24258. In some instances, `key` is a required field.
  24259. properties:
  24260. key:
  24261. description: |-
  24262. A key in the referenced Secret.
  24263. Some instances of this field may be defaulted, in others it may be required.
  24264. maxLength: 253
  24265. minLength: 1
  24266. pattern: ^[-._a-zA-Z0-9]+$
  24267. type: string
  24268. name:
  24269. description: The name of the Secret resource being referred to.
  24270. maxLength: 253
  24271. minLength: 1
  24272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24273. type: string
  24274. namespace:
  24275. description: |-
  24276. The namespace of the Secret resource being referred to.
  24277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24278. maxLength: 63
  24279. minLength: 1
  24280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24281. type: string
  24282. type: object
  24283. required:
  24284. - privateKey
  24285. type: object
  24286. environment:
  24287. description: environment will be used to fetch secrets from a particular environment within a github repository
  24288. type: string
  24289. installationID:
  24290. description: installationID specifies the Github APP installation that will be used to authenticate the client
  24291. format: int64
  24292. type: integer
  24293. organization:
  24294. description: organization will be used to fetch secrets from the Github organization
  24295. type: string
  24296. repository:
  24297. description: repository will be used to fetch secrets from the Github repository within an organization
  24298. type: string
  24299. uploadURL:
  24300. description: Upload URL for enterprise instances. Default to URL.
  24301. type: string
  24302. url:
  24303. default: https://github.com/
  24304. description: URL configures the Github instance URL. Defaults to https://github.com/.
  24305. type: string
  24306. required:
  24307. - appID
  24308. - auth
  24309. - installationID
  24310. - organization
  24311. type: object
  24312. gitlab:
  24313. description: GitLab configures this store to sync secrets using GitLab Variables provider
  24314. properties:
  24315. auth:
  24316. description: Auth configures how secret-manager authenticates with a GitLab instance.
  24317. properties:
  24318. SecretRef:
  24319. description: GitlabSecretRef defines a reference to a secret containing credentials for the GitLab provider.
  24320. properties:
  24321. accessToken:
  24322. description: AccessToken is used for authentication.
  24323. properties:
  24324. key:
  24325. description: |-
  24326. A key in the referenced Secret.
  24327. Some instances of this field may be defaulted, in others it may be required.
  24328. maxLength: 253
  24329. minLength: 1
  24330. pattern: ^[-._a-zA-Z0-9]+$
  24331. type: string
  24332. name:
  24333. description: The name of the Secret resource being referred to.
  24334. maxLength: 253
  24335. minLength: 1
  24336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24337. type: string
  24338. namespace:
  24339. description: |-
  24340. The namespace of the Secret resource being referred to.
  24341. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24342. maxLength: 63
  24343. minLength: 1
  24344. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24345. type: string
  24346. type: object
  24347. type: object
  24348. required:
  24349. - SecretRef
  24350. type: object
  24351. caBundle:
  24352. description: |-
  24353. Base64 encoded certificate for the GitLab server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  24354. can be performed.
  24355. format: byte
  24356. type: string
  24357. caProvider:
  24358. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  24359. properties:
  24360. key:
  24361. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24362. maxLength: 253
  24363. minLength: 1
  24364. pattern: ^[-._a-zA-Z0-9]+$
  24365. type: string
  24366. name:
  24367. description: The name of the object located at the provider type.
  24368. maxLength: 253
  24369. minLength: 1
  24370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24371. type: string
  24372. namespace:
  24373. description: |-
  24374. The namespace the Provider type is in.
  24375. Can only be defined when used in a ClusterSecretStore.
  24376. maxLength: 63
  24377. minLength: 1
  24378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24379. type: string
  24380. type:
  24381. description: The type of provider to use such as "Secret", or "ConfigMap".
  24382. enum:
  24383. - Secret
  24384. - ConfigMap
  24385. type: string
  24386. required:
  24387. - name
  24388. - type
  24389. type: object
  24390. environment:
  24391. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  24392. type: string
  24393. groupIDs:
  24394. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  24395. items:
  24396. type: string
  24397. type: array
  24398. inheritFromGroups:
  24399. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  24400. type: boolean
  24401. projectID:
  24402. description: ProjectID specifies a project where secrets are located.
  24403. type: string
  24404. url:
  24405. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  24406. type: string
  24407. required:
  24408. - auth
  24409. type: object
  24410. ibm:
  24411. description: IBM configures this store to sync secrets using IBM Cloud provider
  24412. properties:
  24413. auth:
  24414. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  24415. maxProperties: 1
  24416. minProperties: 1
  24417. properties:
  24418. containerAuth:
  24419. description: IBMAuthContainerAuth defines authentication using IBM Container-based auth with IAM Trusted Profile.
  24420. properties:
  24421. iamEndpoint:
  24422. type: string
  24423. profile:
  24424. description: the IBM Trusted Profile
  24425. type: string
  24426. tokenLocation:
  24427. description: Location the token is mounted on the pod
  24428. type: string
  24429. required:
  24430. - profile
  24431. type: object
  24432. secretRef:
  24433. description: IBMAuthSecretRef defines a reference to a secret containing credentials for the IBM provider.
  24434. properties:
  24435. secretApiKeySecretRef:
  24436. description: The SecretAccessKey is used for authentication
  24437. properties:
  24438. key:
  24439. description: |-
  24440. A key in the referenced Secret.
  24441. Some instances of this field may be defaulted, in others it may be required.
  24442. maxLength: 253
  24443. minLength: 1
  24444. pattern: ^[-._a-zA-Z0-9]+$
  24445. type: string
  24446. name:
  24447. description: The name of the Secret resource being referred to.
  24448. maxLength: 253
  24449. minLength: 1
  24450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24451. type: string
  24452. namespace:
  24453. description: |-
  24454. The namespace of the Secret resource being referred to.
  24455. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24456. maxLength: 63
  24457. minLength: 1
  24458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24459. type: string
  24460. type: object
  24461. type: object
  24462. type: object
  24463. serviceUrl:
  24464. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  24465. type: string
  24466. required:
  24467. - auth
  24468. type: object
  24469. infisical:
  24470. description: Infisical configures this store to sync secrets using the Infisical provider
  24471. properties:
  24472. auth:
  24473. description: Auth configures how the Operator authenticates with the Infisical API
  24474. properties:
  24475. universalAuthCredentials:
  24476. description: UniversalAuthCredentials defines the credentials for Infisical Universal Auth.
  24477. properties:
  24478. clientId:
  24479. description: |-
  24480. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24481. In some instances, `key` is a required field.
  24482. properties:
  24483. key:
  24484. description: |-
  24485. A key in the referenced Secret.
  24486. Some instances of this field may be defaulted, in others it may be required.
  24487. maxLength: 253
  24488. minLength: 1
  24489. pattern: ^[-._a-zA-Z0-9]+$
  24490. type: string
  24491. name:
  24492. description: The name of the Secret resource being referred to.
  24493. maxLength: 253
  24494. minLength: 1
  24495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24496. type: string
  24497. namespace:
  24498. description: |-
  24499. The namespace of the Secret resource being referred to.
  24500. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24501. maxLength: 63
  24502. minLength: 1
  24503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24504. type: string
  24505. type: object
  24506. clientSecret:
  24507. description: |-
  24508. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24509. In some instances, `key` is a required field.
  24510. properties:
  24511. key:
  24512. description: |-
  24513. A key in the referenced Secret.
  24514. Some instances of this field may be defaulted, in others it may be required.
  24515. maxLength: 253
  24516. minLength: 1
  24517. pattern: ^[-._a-zA-Z0-9]+$
  24518. type: string
  24519. name:
  24520. description: The name of the Secret resource being referred to.
  24521. maxLength: 253
  24522. minLength: 1
  24523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24524. type: string
  24525. namespace:
  24526. description: |-
  24527. The namespace of the Secret resource being referred to.
  24528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24529. maxLength: 63
  24530. minLength: 1
  24531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24532. type: string
  24533. type: object
  24534. required:
  24535. - clientId
  24536. - clientSecret
  24537. type: object
  24538. type: object
  24539. hostAPI:
  24540. default: https://app.infisical.com/api
  24541. description: HostAPI specifies the base URL of the Infisical API. If not provided, it defaults to "https://app.infisical.com/api".
  24542. type: string
  24543. secretsScope:
  24544. description: SecretsScope defines the scope of the secrets within the workspace
  24545. properties:
  24546. environmentSlug:
  24547. description: EnvironmentSlug is the required slug identifier for the environment.
  24548. type: string
  24549. expandSecretReferences:
  24550. default: true
  24551. description: ExpandSecretReferences indicates whether secret references should be expanded. Defaults to true if not provided.
  24552. type: boolean
  24553. projectSlug:
  24554. description: ProjectSlug is the required slug identifier for the project.
  24555. type: string
  24556. recursive:
  24557. default: false
  24558. description: Recursive indicates whether the secrets should be fetched recursively. Defaults to false if not provided.
  24559. type: boolean
  24560. secretsPath:
  24561. default: /
  24562. description: SecretsPath specifies the path to the secrets within the workspace. Defaults to "/" if not provided.
  24563. type: string
  24564. required:
  24565. - environmentSlug
  24566. - projectSlug
  24567. type: object
  24568. required:
  24569. - auth
  24570. - secretsScope
  24571. type: object
  24572. keepersecurity:
  24573. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  24574. properties:
  24575. authRef:
  24576. description: |-
  24577. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24578. In some instances, `key` is a required field.
  24579. properties:
  24580. key:
  24581. description: |-
  24582. A key in the referenced Secret.
  24583. Some instances of this field may be defaulted, in others it may be required.
  24584. maxLength: 253
  24585. minLength: 1
  24586. pattern: ^[-._a-zA-Z0-9]+$
  24587. type: string
  24588. name:
  24589. description: The name of the Secret resource being referred to.
  24590. maxLength: 253
  24591. minLength: 1
  24592. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24593. type: string
  24594. namespace:
  24595. description: |-
  24596. The namespace of the Secret resource being referred to.
  24597. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24598. maxLength: 63
  24599. minLength: 1
  24600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24601. type: string
  24602. type: object
  24603. folderID:
  24604. type: string
  24605. required:
  24606. - authRef
  24607. - folderID
  24608. type: object
  24609. kubernetes:
  24610. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  24611. properties:
  24612. auth:
  24613. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  24614. maxProperties: 1
  24615. minProperties: 1
  24616. properties:
  24617. cert:
  24618. description: has both clientCert and clientKey as secretKeySelector
  24619. properties:
  24620. clientCert:
  24621. description: |-
  24622. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24623. In some instances, `key` is a required field.
  24624. properties:
  24625. key:
  24626. description: |-
  24627. A key in the referenced Secret.
  24628. Some instances of this field may be defaulted, in others it may be required.
  24629. maxLength: 253
  24630. minLength: 1
  24631. pattern: ^[-._a-zA-Z0-9]+$
  24632. type: string
  24633. name:
  24634. description: The name of the Secret resource being referred to.
  24635. maxLength: 253
  24636. minLength: 1
  24637. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24638. type: string
  24639. namespace:
  24640. description: |-
  24641. The namespace of the Secret resource being referred to.
  24642. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24643. maxLength: 63
  24644. minLength: 1
  24645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24646. type: string
  24647. type: object
  24648. clientKey:
  24649. description: |-
  24650. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24651. In some instances, `key` is a required field.
  24652. properties:
  24653. key:
  24654. description: |-
  24655. A key in the referenced Secret.
  24656. Some instances of this field may be defaulted, in others it may be required.
  24657. maxLength: 253
  24658. minLength: 1
  24659. pattern: ^[-._a-zA-Z0-9]+$
  24660. type: string
  24661. name:
  24662. description: The name of the Secret resource being referred to.
  24663. maxLength: 253
  24664. minLength: 1
  24665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24666. type: string
  24667. namespace:
  24668. description: |-
  24669. The namespace of the Secret resource being referred to.
  24670. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24671. maxLength: 63
  24672. minLength: 1
  24673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24674. type: string
  24675. type: object
  24676. type: object
  24677. serviceAccount:
  24678. description: points to a service account that should be used for authentication
  24679. properties:
  24680. audiences:
  24681. description: |-
  24682. Audience specifies the `aud` claim for the service account token
  24683. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  24684. then this audiences will be appended to the list
  24685. items:
  24686. type: string
  24687. type: array
  24688. name:
  24689. description: The name of the ServiceAccount resource being referred to.
  24690. maxLength: 253
  24691. minLength: 1
  24692. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24693. type: string
  24694. namespace:
  24695. description: |-
  24696. Namespace of the resource being referred to.
  24697. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24698. maxLength: 63
  24699. minLength: 1
  24700. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24701. type: string
  24702. required:
  24703. - name
  24704. type: object
  24705. token:
  24706. description: use static token to authenticate with
  24707. properties:
  24708. bearerToken:
  24709. description: |-
  24710. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  24711. In some instances, `key` is a required field.
  24712. properties:
  24713. key:
  24714. description: |-
  24715. A key in the referenced Secret.
  24716. Some instances of this field may be defaulted, in others it may be required.
  24717. maxLength: 253
  24718. minLength: 1
  24719. pattern: ^[-._a-zA-Z0-9]+$
  24720. type: string
  24721. name:
  24722. description: The name of the Secret resource being referred to.
  24723. maxLength: 253
  24724. minLength: 1
  24725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24726. type: string
  24727. namespace:
  24728. description: |-
  24729. The namespace of the Secret resource being referred to.
  24730. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24731. maxLength: 63
  24732. minLength: 1
  24733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24734. type: string
  24735. type: object
  24736. type: object
  24737. type: object
  24738. authRef:
  24739. description: A reference to a secret that contains the auth information.
  24740. properties:
  24741. key:
  24742. description: |-
  24743. A key in the referenced Secret.
  24744. Some instances of this field may be defaulted, in others it may be required.
  24745. maxLength: 253
  24746. minLength: 1
  24747. pattern: ^[-._a-zA-Z0-9]+$
  24748. type: string
  24749. name:
  24750. description: The name of the Secret resource being referred to.
  24751. maxLength: 253
  24752. minLength: 1
  24753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24754. type: string
  24755. namespace:
  24756. description: |-
  24757. The namespace of the Secret resource being referred to.
  24758. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24759. maxLength: 63
  24760. minLength: 1
  24761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24762. type: string
  24763. type: object
  24764. remoteNamespace:
  24765. default: default
  24766. description: Remote namespace to fetch the secrets from
  24767. maxLength: 63
  24768. minLength: 1
  24769. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24770. type: string
  24771. server:
  24772. description: configures the Kubernetes server Address.
  24773. properties:
  24774. caBundle:
  24775. description: CABundle is a base64-encoded CA certificate
  24776. format: byte
  24777. type: string
  24778. caProvider:
  24779. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  24780. properties:
  24781. key:
  24782. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  24783. maxLength: 253
  24784. minLength: 1
  24785. pattern: ^[-._a-zA-Z0-9]+$
  24786. type: string
  24787. name:
  24788. description: The name of the object located at the provider type.
  24789. maxLength: 253
  24790. minLength: 1
  24791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24792. type: string
  24793. namespace:
  24794. description: |-
  24795. The namespace the Provider type is in.
  24796. Can only be defined when used in a ClusterSecretStore.
  24797. maxLength: 63
  24798. minLength: 1
  24799. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24800. type: string
  24801. type:
  24802. description: The type of provider to use such as "Secret", or "ConfigMap".
  24803. enum:
  24804. - Secret
  24805. - ConfigMap
  24806. type: string
  24807. required:
  24808. - name
  24809. - type
  24810. type: object
  24811. url:
  24812. default: kubernetes.default
  24813. description: configures the Kubernetes server Address.
  24814. type: string
  24815. type: object
  24816. type: object
  24817. onboardbase:
  24818. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  24819. properties:
  24820. apiHost:
  24821. default: https://public.onboardbase.com/api/v1/
  24822. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  24823. type: string
  24824. auth:
  24825. description: Auth configures how the Operator authenticates with the Onboardbase API
  24826. properties:
  24827. apiKeyRef:
  24828. description: |-
  24829. OnboardbaseAPIKey is the APIKey generated by an admin account.
  24830. It is used to recognize and authorize access to a project and environment within onboardbase
  24831. properties:
  24832. key:
  24833. description: |-
  24834. A key in the referenced Secret.
  24835. Some instances of this field may be defaulted, in others it may be required.
  24836. maxLength: 253
  24837. minLength: 1
  24838. pattern: ^[-._a-zA-Z0-9]+$
  24839. type: string
  24840. name:
  24841. description: The name of the Secret resource being referred to.
  24842. maxLength: 253
  24843. minLength: 1
  24844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24845. type: string
  24846. namespace:
  24847. description: |-
  24848. The namespace of the Secret resource being referred to.
  24849. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24850. maxLength: 63
  24851. minLength: 1
  24852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24853. type: string
  24854. type: object
  24855. passcodeRef:
  24856. description: OnboardbasePasscode is the passcode attached to the API Key
  24857. properties:
  24858. key:
  24859. description: |-
  24860. A key in the referenced Secret.
  24861. Some instances of this field may be defaulted, in others it may be required.
  24862. maxLength: 253
  24863. minLength: 1
  24864. pattern: ^[-._a-zA-Z0-9]+$
  24865. type: string
  24866. name:
  24867. description: The name of the Secret resource being referred to.
  24868. maxLength: 253
  24869. minLength: 1
  24870. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24871. type: string
  24872. namespace:
  24873. description: |-
  24874. The namespace of the Secret resource being referred to.
  24875. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24876. maxLength: 63
  24877. minLength: 1
  24878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24879. type: string
  24880. type: object
  24881. required:
  24882. - apiKeyRef
  24883. - passcodeRef
  24884. type: object
  24885. environment:
  24886. default: development
  24887. description: Environment is the name of an environmnent within a project to pull the secrets from
  24888. type: string
  24889. project:
  24890. default: development
  24891. description: Project is an onboardbase project that the secrets should be pulled from
  24892. type: string
  24893. required:
  24894. - apiHost
  24895. - auth
  24896. - environment
  24897. - project
  24898. type: object
  24899. onepassword:
  24900. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  24901. properties:
  24902. auth:
  24903. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  24904. properties:
  24905. secretRef:
  24906. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  24907. properties:
  24908. connectTokenSecretRef:
  24909. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  24910. properties:
  24911. key:
  24912. description: |-
  24913. A key in the referenced Secret.
  24914. Some instances of this field may be defaulted, in others it may be required.
  24915. maxLength: 253
  24916. minLength: 1
  24917. pattern: ^[-._a-zA-Z0-9]+$
  24918. type: string
  24919. name:
  24920. description: The name of the Secret resource being referred to.
  24921. maxLength: 253
  24922. minLength: 1
  24923. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24924. type: string
  24925. namespace:
  24926. description: |-
  24927. The namespace of the Secret resource being referred to.
  24928. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24929. maxLength: 63
  24930. minLength: 1
  24931. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24932. type: string
  24933. type: object
  24934. required:
  24935. - connectTokenSecretRef
  24936. type: object
  24937. required:
  24938. - secretRef
  24939. type: object
  24940. connectHost:
  24941. description: ConnectHost defines the OnePassword Connect Server to connect to
  24942. type: string
  24943. vaults:
  24944. additionalProperties:
  24945. type: integer
  24946. description: Vaults defines which OnePassword vaults to search in which order
  24947. type: object
  24948. required:
  24949. - auth
  24950. - connectHost
  24951. - vaults
  24952. type: object
  24953. oracle:
  24954. description: Oracle configures this store to sync secrets using Oracle Vault provider
  24955. properties:
  24956. auth:
  24957. description: |-
  24958. Auth configures how secret-manager authenticates with the Oracle Vault.
  24959. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  24960. properties:
  24961. secretRef:
  24962. description: SecretRef to pass through sensitive information.
  24963. properties:
  24964. fingerprint:
  24965. description: Fingerprint is the fingerprint of the API private key.
  24966. properties:
  24967. key:
  24968. description: |-
  24969. A key in the referenced Secret.
  24970. Some instances of this field may be defaulted, in others it may be required.
  24971. maxLength: 253
  24972. minLength: 1
  24973. pattern: ^[-._a-zA-Z0-9]+$
  24974. type: string
  24975. name:
  24976. description: The name of the Secret resource being referred to.
  24977. maxLength: 253
  24978. minLength: 1
  24979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  24980. type: string
  24981. namespace:
  24982. description: |-
  24983. The namespace of the Secret resource being referred to.
  24984. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  24985. maxLength: 63
  24986. minLength: 1
  24987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  24988. type: string
  24989. type: object
  24990. privatekey:
  24991. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  24992. properties:
  24993. key:
  24994. description: |-
  24995. A key in the referenced Secret.
  24996. Some instances of this field may be defaulted, in others it may be required.
  24997. maxLength: 253
  24998. minLength: 1
  24999. pattern: ^[-._a-zA-Z0-9]+$
  25000. type: string
  25001. name:
  25002. description: The name of the Secret resource being referred to.
  25003. maxLength: 253
  25004. minLength: 1
  25005. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25006. type: string
  25007. namespace:
  25008. description: |-
  25009. The namespace of the Secret resource being referred to.
  25010. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25011. maxLength: 63
  25012. minLength: 1
  25013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25014. type: string
  25015. type: object
  25016. required:
  25017. - fingerprint
  25018. - privatekey
  25019. type: object
  25020. tenancy:
  25021. description: Tenancy is the tenancy OCID where user is located.
  25022. type: string
  25023. user:
  25024. description: User is an access OCID specific to the account.
  25025. type: string
  25026. required:
  25027. - secretRef
  25028. - tenancy
  25029. - user
  25030. type: object
  25031. compartment:
  25032. description: |-
  25033. Compartment is the vault compartment OCID.
  25034. Required for PushSecret
  25035. type: string
  25036. encryptionKey:
  25037. description: |-
  25038. EncryptionKey is the OCID of the encryption key within the vault.
  25039. Required for PushSecret
  25040. type: string
  25041. principalType:
  25042. description: |-
  25043. The type of principal to use for authentication. If left blank, the Auth struct will
  25044. determine the principal type. This optional field must be specified if using
  25045. workload identity.
  25046. enum:
  25047. - ""
  25048. - UserPrincipal
  25049. - InstancePrincipal
  25050. - Workload
  25051. type: string
  25052. region:
  25053. description: Region is the region where vault is located.
  25054. type: string
  25055. serviceAccountRef:
  25056. description: |-
  25057. ServiceAccountRef specified the service account
  25058. that should be used when authenticating with WorkloadIdentity.
  25059. properties:
  25060. audiences:
  25061. description: |-
  25062. Audience specifies the `aud` claim for the service account token
  25063. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25064. then this audiences will be appended to the list
  25065. items:
  25066. type: string
  25067. type: array
  25068. name:
  25069. description: The name of the ServiceAccount resource being referred to.
  25070. maxLength: 253
  25071. minLength: 1
  25072. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25073. type: string
  25074. namespace:
  25075. description: |-
  25076. Namespace of the resource being referred to.
  25077. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25078. maxLength: 63
  25079. minLength: 1
  25080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25081. type: string
  25082. required:
  25083. - name
  25084. type: object
  25085. vault:
  25086. description: Vault is the vault's OCID of the specific vault where secret is located.
  25087. type: string
  25088. required:
  25089. - region
  25090. - vault
  25091. type: object
  25092. passbolt:
  25093. description: PassboltProvider defines configuration for the Passbolt provider.
  25094. properties:
  25095. auth:
  25096. description: Auth defines the information necessary to authenticate against Passbolt Server
  25097. properties:
  25098. passwordSecretRef:
  25099. description: PasswordSecretRef is a reference to the secret containing the Passbolt password
  25100. properties:
  25101. key:
  25102. description: |-
  25103. A key in the referenced Secret.
  25104. Some instances of this field may be defaulted, in others it may be required.
  25105. maxLength: 253
  25106. minLength: 1
  25107. pattern: ^[-._a-zA-Z0-9]+$
  25108. type: string
  25109. name:
  25110. description: The name of the Secret resource being referred to.
  25111. maxLength: 253
  25112. minLength: 1
  25113. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25114. type: string
  25115. namespace:
  25116. description: |-
  25117. The namespace of the Secret resource being referred to.
  25118. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25119. maxLength: 63
  25120. minLength: 1
  25121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25122. type: string
  25123. type: object
  25124. privateKeySecretRef:
  25125. description: PrivateKeySecretRef is a reference to the secret containing the Passbolt private key
  25126. properties:
  25127. key:
  25128. description: |-
  25129. A key in the referenced Secret.
  25130. Some instances of this field may be defaulted, in others it may be required.
  25131. maxLength: 253
  25132. minLength: 1
  25133. pattern: ^[-._a-zA-Z0-9]+$
  25134. type: string
  25135. name:
  25136. description: The name of the Secret resource being referred to.
  25137. maxLength: 253
  25138. minLength: 1
  25139. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25140. type: string
  25141. namespace:
  25142. description: |-
  25143. The namespace of the Secret resource being referred to.
  25144. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25145. maxLength: 63
  25146. minLength: 1
  25147. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25148. type: string
  25149. type: object
  25150. required:
  25151. - passwordSecretRef
  25152. - privateKeySecretRef
  25153. type: object
  25154. host:
  25155. description: Host defines the Passbolt Server to connect to
  25156. type: string
  25157. required:
  25158. - auth
  25159. - host
  25160. type: object
  25161. passworddepot:
  25162. description: PasswordDepotProvider configures a store to sync secrets with a Password Depot instance.
  25163. properties:
  25164. auth:
  25165. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  25166. properties:
  25167. secretRef:
  25168. description: PasswordDepotSecretRef defines a reference to a secret containing credentials for the Password Depot provider.
  25169. properties:
  25170. credentials:
  25171. description: Username / Password is used for authentication.
  25172. properties:
  25173. key:
  25174. description: |-
  25175. A key in the referenced Secret.
  25176. Some instances of this field may be defaulted, in others it may be required.
  25177. maxLength: 253
  25178. minLength: 1
  25179. pattern: ^[-._a-zA-Z0-9]+$
  25180. type: string
  25181. name:
  25182. description: The name of the Secret resource being referred to.
  25183. maxLength: 253
  25184. minLength: 1
  25185. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25186. type: string
  25187. namespace:
  25188. description: |-
  25189. The namespace of the Secret resource being referred to.
  25190. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25191. maxLength: 63
  25192. minLength: 1
  25193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25194. type: string
  25195. type: object
  25196. type: object
  25197. required:
  25198. - secretRef
  25199. type: object
  25200. database:
  25201. description: Database to use as source
  25202. type: string
  25203. host:
  25204. description: URL configures the Password Depot instance URL.
  25205. type: string
  25206. required:
  25207. - auth
  25208. - database
  25209. - host
  25210. type: object
  25211. previder:
  25212. description: Previder configures this store to sync secrets using the Previder provider
  25213. properties:
  25214. auth:
  25215. description: PreviderAuth contains a secretRef for credentials.
  25216. properties:
  25217. secretRef:
  25218. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  25219. properties:
  25220. accessToken:
  25221. description: The AccessToken is used for authentication
  25222. properties:
  25223. key:
  25224. description: |-
  25225. A key in the referenced Secret.
  25226. Some instances of this field may be defaulted, in others it may be required.
  25227. maxLength: 253
  25228. minLength: 1
  25229. pattern: ^[-._a-zA-Z0-9]+$
  25230. type: string
  25231. name:
  25232. description: The name of the Secret resource being referred to.
  25233. maxLength: 253
  25234. minLength: 1
  25235. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25236. type: string
  25237. namespace:
  25238. description: |-
  25239. The namespace of the Secret resource being referred to.
  25240. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25241. maxLength: 63
  25242. minLength: 1
  25243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25244. type: string
  25245. type: object
  25246. required:
  25247. - accessToken
  25248. type: object
  25249. type: object
  25250. baseUri:
  25251. type: string
  25252. required:
  25253. - auth
  25254. type: object
  25255. pulumi:
  25256. description: Pulumi configures this store to sync secrets using the Pulumi provider
  25257. properties:
  25258. accessToken:
  25259. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  25260. properties:
  25261. secretRef:
  25262. description: SecretRef is a reference to a secret containing the Pulumi API token.
  25263. properties:
  25264. key:
  25265. description: |-
  25266. A key in the referenced Secret.
  25267. Some instances of this field may be defaulted, in others it may be required.
  25268. maxLength: 253
  25269. minLength: 1
  25270. pattern: ^[-._a-zA-Z0-9]+$
  25271. type: string
  25272. name:
  25273. description: The name of the Secret resource being referred to.
  25274. maxLength: 253
  25275. minLength: 1
  25276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25277. type: string
  25278. namespace:
  25279. description: |-
  25280. The namespace of the Secret resource being referred to.
  25281. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25282. maxLength: 63
  25283. minLength: 1
  25284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25285. type: string
  25286. type: object
  25287. type: object
  25288. apiUrl:
  25289. default: https://api.pulumi.com/api/esc
  25290. description: APIURL is the URL of the Pulumi API.
  25291. type: string
  25292. environment:
  25293. description: |-
  25294. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  25295. dynamically retrieved values from supported providers including all major clouds,
  25296. and other Pulumi ESC environments.
  25297. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  25298. type: string
  25299. organization:
  25300. description: |-
  25301. Organization are a space to collaborate on shared projects and stacks.
  25302. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  25303. type: string
  25304. project:
  25305. description: Project is the name of the Pulumi ESC project the environment belongs to.
  25306. type: string
  25307. required:
  25308. - accessToken
  25309. - environment
  25310. - organization
  25311. - project
  25312. type: object
  25313. scaleway:
  25314. description: Scaleway configures this store to sync secrets using the Scaleway provider.
  25315. properties:
  25316. accessKey:
  25317. description: AccessKey is the non-secret part of the api key.
  25318. properties:
  25319. secretRef:
  25320. description: SecretRef references a key in a secret that will be used as value.
  25321. properties:
  25322. key:
  25323. description: |-
  25324. A key in the referenced Secret.
  25325. Some instances of this field may be defaulted, in others it may be required.
  25326. maxLength: 253
  25327. minLength: 1
  25328. pattern: ^[-._a-zA-Z0-9]+$
  25329. type: string
  25330. name:
  25331. description: The name of the Secret resource being referred to.
  25332. maxLength: 253
  25333. minLength: 1
  25334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25335. type: string
  25336. namespace:
  25337. description: |-
  25338. The namespace of the Secret resource being referred to.
  25339. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25340. maxLength: 63
  25341. minLength: 1
  25342. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25343. type: string
  25344. type: object
  25345. value:
  25346. description: Value can be specified directly to set a value without using a secret.
  25347. type: string
  25348. type: object
  25349. apiUrl:
  25350. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  25351. type: string
  25352. projectId:
  25353. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  25354. type: string
  25355. region:
  25356. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  25357. type: string
  25358. secretKey:
  25359. description: SecretKey is the non-secret part of the api key.
  25360. properties:
  25361. secretRef:
  25362. description: SecretRef references a key in a secret that will be used as value.
  25363. properties:
  25364. key:
  25365. description: |-
  25366. A key in the referenced Secret.
  25367. Some instances of this field may be defaulted, in others it may be required.
  25368. maxLength: 253
  25369. minLength: 1
  25370. pattern: ^[-._a-zA-Z0-9]+$
  25371. type: string
  25372. name:
  25373. description: The name of the Secret resource being referred to.
  25374. maxLength: 253
  25375. minLength: 1
  25376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25377. type: string
  25378. namespace:
  25379. description: |-
  25380. The namespace of the Secret resource being referred to.
  25381. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25382. maxLength: 63
  25383. minLength: 1
  25384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25385. type: string
  25386. type: object
  25387. value:
  25388. description: Value can be specified directly to set a value without using a secret.
  25389. type: string
  25390. type: object
  25391. required:
  25392. - accessKey
  25393. - projectId
  25394. - region
  25395. - secretKey
  25396. type: object
  25397. secretserver:
  25398. description: |-
  25399. SecretServer configures this store to sync secrets using SecretServer provider
  25400. https://docs.delinea.com/online-help/secret-server/start.htm
  25401. properties:
  25402. password:
  25403. description: Password is the secret server account password.
  25404. properties:
  25405. secretRef:
  25406. description: SecretRef references a key in a secret that will be used as value.
  25407. properties:
  25408. key:
  25409. description: |-
  25410. A key in the referenced Secret.
  25411. Some instances of this field may be defaulted, in others it may be required.
  25412. maxLength: 253
  25413. minLength: 1
  25414. pattern: ^[-._a-zA-Z0-9]+$
  25415. type: string
  25416. name:
  25417. description: The name of the Secret resource being referred to.
  25418. maxLength: 253
  25419. minLength: 1
  25420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25421. type: string
  25422. namespace:
  25423. description: |-
  25424. The namespace of the Secret resource being referred to.
  25425. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25426. maxLength: 63
  25427. minLength: 1
  25428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25429. type: string
  25430. type: object
  25431. value:
  25432. description: Value can be specified directly to set a value without using a secret.
  25433. type: string
  25434. type: object
  25435. serverURL:
  25436. description: |-
  25437. ServerURL
  25438. URL to your secret server installation
  25439. type: string
  25440. username:
  25441. description: Username is the secret server account username.
  25442. properties:
  25443. secretRef:
  25444. description: SecretRef references a key in a secret that will be used as value.
  25445. properties:
  25446. key:
  25447. description: |-
  25448. A key in the referenced Secret.
  25449. Some instances of this field may be defaulted, in others it may be required.
  25450. maxLength: 253
  25451. minLength: 1
  25452. pattern: ^[-._a-zA-Z0-9]+$
  25453. type: string
  25454. name:
  25455. description: The name of the Secret resource being referred to.
  25456. maxLength: 253
  25457. minLength: 1
  25458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25459. type: string
  25460. namespace:
  25461. description: |-
  25462. The namespace of the Secret resource being referred to.
  25463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25464. maxLength: 63
  25465. minLength: 1
  25466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25467. type: string
  25468. type: object
  25469. value:
  25470. description: Value can be specified directly to set a value without using a secret.
  25471. type: string
  25472. type: object
  25473. required:
  25474. - password
  25475. - serverURL
  25476. - username
  25477. type: object
  25478. senhasegura:
  25479. description: Senhasegura configures this store to sync secrets using senhasegura provider
  25480. properties:
  25481. auth:
  25482. description: Auth defines parameters to authenticate in senhasegura
  25483. properties:
  25484. clientId:
  25485. type: string
  25486. clientSecretSecretRef:
  25487. description: |-
  25488. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  25489. In some instances, `key` is a required field.
  25490. properties:
  25491. key:
  25492. description: |-
  25493. A key in the referenced Secret.
  25494. Some instances of this field may be defaulted, in others it may be required.
  25495. maxLength: 253
  25496. minLength: 1
  25497. pattern: ^[-._a-zA-Z0-9]+$
  25498. type: string
  25499. name:
  25500. description: The name of the Secret resource being referred to.
  25501. maxLength: 253
  25502. minLength: 1
  25503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25504. type: string
  25505. namespace:
  25506. description: |-
  25507. The namespace of the Secret resource being referred to.
  25508. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25509. maxLength: 63
  25510. minLength: 1
  25511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25512. type: string
  25513. type: object
  25514. required:
  25515. - clientId
  25516. - clientSecretSecretRef
  25517. type: object
  25518. ignoreSslCertificate:
  25519. default: false
  25520. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  25521. type: boolean
  25522. module:
  25523. description: Module defines which senhasegura module should be used to get secrets
  25524. type: string
  25525. url:
  25526. description: URL of senhasegura
  25527. type: string
  25528. required:
  25529. - auth
  25530. - module
  25531. - url
  25532. type: object
  25533. vault:
  25534. description: Vault configures this store to sync secrets using the HashiCorp Vault provider.
  25535. properties:
  25536. auth:
  25537. description: Auth configures how secret-manager authenticates with the Vault server.
  25538. properties:
  25539. appRole:
  25540. description: |-
  25541. AppRole authenticates with Vault using the App Role auth mechanism,
  25542. with the role and secret stored in a Kubernetes Secret resource.
  25543. properties:
  25544. path:
  25545. default: approle
  25546. description: |-
  25547. Path where the App Role authentication backend is mounted
  25548. in Vault, e.g: "approle"
  25549. type: string
  25550. roleId:
  25551. description: |-
  25552. RoleID configured in the App Role authentication backend when setting
  25553. up the authentication backend in Vault.
  25554. type: string
  25555. roleRef:
  25556. description: |-
  25557. Reference to a key in a Secret that contains the App Role ID used
  25558. to authenticate with Vault.
  25559. The `key` field must be specified and denotes which entry within the Secret
  25560. resource is used as the app role id.
  25561. properties:
  25562. key:
  25563. description: |-
  25564. A key in the referenced Secret.
  25565. Some instances of this field may be defaulted, in others it may be required.
  25566. maxLength: 253
  25567. minLength: 1
  25568. pattern: ^[-._a-zA-Z0-9]+$
  25569. type: string
  25570. name:
  25571. description: The name of the Secret resource being referred to.
  25572. maxLength: 253
  25573. minLength: 1
  25574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25575. type: string
  25576. namespace:
  25577. description: |-
  25578. The namespace of the Secret resource being referred to.
  25579. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25580. maxLength: 63
  25581. minLength: 1
  25582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25583. type: string
  25584. type: object
  25585. secretRef:
  25586. description: |-
  25587. Reference to a key in a Secret that contains the App Role secret used
  25588. to authenticate with Vault.
  25589. The `key` field must be specified and denotes which entry within the Secret
  25590. resource is used as the app role secret.
  25591. properties:
  25592. key:
  25593. description: |-
  25594. A key in the referenced Secret.
  25595. Some instances of this field may be defaulted, in others it may be required.
  25596. maxLength: 253
  25597. minLength: 1
  25598. pattern: ^[-._a-zA-Z0-9]+$
  25599. type: string
  25600. name:
  25601. description: The name of the Secret resource being referred to.
  25602. maxLength: 253
  25603. minLength: 1
  25604. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25605. type: string
  25606. namespace:
  25607. description: |-
  25608. The namespace of the Secret resource being referred to.
  25609. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25610. maxLength: 63
  25611. minLength: 1
  25612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25613. type: string
  25614. type: object
  25615. required:
  25616. - path
  25617. - secretRef
  25618. type: object
  25619. cert:
  25620. description: |-
  25621. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  25622. Cert authentication method
  25623. properties:
  25624. clientCert:
  25625. description: |-
  25626. ClientCert is a certificate to authenticate using the Cert Vault
  25627. authentication method
  25628. properties:
  25629. key:
  25630. description: |-
  25631. A key in the referenced Secret.
  25632. Some instances of this field may be defaulted, in others it may be required.
  25633. maxLength: 253
  25634. minLength: 1
  25635. pattern: ^[-._a-zA-Z0-9]+$
  25636. type: string
  25637. name:
  25638. description: The name of the Secret resource being referred to.
  25639. maxLength: 253
  25640. minLength: 1
  25641. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25642. type: string
  25643. namespace:
  25644. description: |-
  25645. The namespace of the Secret resource being referred to.
  25646. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25647. maxLength: 63
  25648. minLength: 1
  25649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25650. type: string
  25651. type: object
  25652. secretRef:
  25653. description: |-
  25654. SecretRef to a key in a Secret resource containing client private key to
  25655. authenticate with Vault using the Cert authentication method
  25656. properties:
  25657. key:
  25658. description: |-
  25659. A key in the referenced Secret.
  25660. Some instances of this field may be defaulted, in others it may be required.
  25661. maxLength: 253
  25662. minLength: 1
  25663. pattern: ^[-._a-zA-Z0-9]+$
  25664. type: string
  25665. name:
  25666. description: The name of the Secret resource being referred to.
  25667. maxLength: 253
  25668. minLength: 1
  25669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25670. type: string
  25671. namespace:
  25672. description: |-
  25673. The namespace of the Secret resource being referred to.
  25674. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25675. maxLength: 63
  25676. minLength: 1
  25677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25678. type: string
  25679. type: object
  25680. type: object
  25681. iam:
  25682. description: |-
  25683. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  25684. AWS IAM authentication method
  25685. properties:
  25686. externalID:
  25687. description: AWS External ID set on assumed IAM roles
  25688. type: string
  25689. jwt:
  25690. description: Specify a service account with IRSA enabled
  25691. properties:
  25692. serviceAccountRef:
  25693. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  25694. properties:
  25695. audiences:
  25696. description: |-
  25697. Audience specifies the `aud` claim for the service account token
  25698. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25699. then this audiences will be appended to the list
  25700. items:
  25701. type: string
  25702. type: array
  25703. name:
  25704. description: The name of the ServiceAccount resource being referred to.
  25705. maxLength: 253
  25706. minLength: 1
  25707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25708. type: string
  25709. namespace:
  25710. description: |-
  25711. Namespace of the resource being referred to.
  25712. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25713. maxLength: 63
  25714. minLength: 1
  25715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25716. type: string
  25717. required:
  25718. - name
  25719. type: object
  25720. type: object
  25721. path:
  25722. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  25723. type: string
  25724. region:
  25725. description: AWS region
  25726. type: string
  25727. role:
  25728. description: This is the AWS role to be assumed before talking to vault
  25729. type: string
  25730. secretRef:
  25731. description: Specify credentials in a Secret object
  25732. properties:
  25733. accessKeyIDSecretRef:
  25734. description: The AccessKeyID is used for authentication
  25735. properties:
  25736. key:
  25737. description: |-
  25738. A key in the referenced Secret.
  25739. Some instances of this field may be defaulted, in others it may be required.
  25740. maxLength: 253
  25741. minLength: 1
  25742. pattern: ^[-._a-zA-Z0-9]+$
  25743. type: string
  25744. name:
  25745. description: The name of the Secret resource being referred to.
  25746. maxLength: 253
  25747. minLength: 1
  25748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25749. type: string
  25750. namespace:
  25751. description: |-
  25752. The namespace of the Secret resource being referred to.
  25753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25754. maxLength: 63
  25755. minLength: 1
  25756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25757. type: string
  25758. type: object
  25759. secretAccessKeySecretRef:
  25760. description: The SecretAccessKey is used for authentication
  25761. properties:
  25762. key:
  25763. description: |-
  25764. A key in the referenced Secret.
  25765. Some instances of this field may be defaulted, in others it may be required.
  25766. maxLength: 253
  25767. minLength: 1
  25768. pattern: ^[-._a-zA-Z0-9]+$
  25769. type: string
  25770. name:
  25771. description: The name of the Secret resource being referred to.
  25772. maxLength: 253
  25773. minLength: 1
  25774. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25775. type: string
  25776. namespace:
  25777. description: |-
  25778. The namespace of the Secret resource being referred to.
  25779. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25780. maxLength: 63
  25781. minLength: 1
  25782. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25783. type: string
  25784. type: object
  25785. sessionTokenSecretRef:
  25786. description: |-
  25787. The SessionToken used for authentication
  25788. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  25789. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  25790. properties:
  25791. key:
  25792. description: |-
  25793. A key in the referenced Secret.
  25794. Some instances of this field may be defaulted, in others it may be required.
  25795. maxLength: 253
  25796. minLength: 1
  25797. pattern: ^[-._a-zA-Z0-9]+$
  25798. type: string
  25799. name:
  25800. description: The name of the Secret resource being referred to.
  25801. maxLength: 253
  25802. minLength: 1
  25803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25804. type: string
  25805. namespace:
  25806. description: |-
  25807. The namespace of the Secret resource being referred to.
  25808. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25809. maxLength: 63
  25810. minLength: 1
  25811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25812. type: string
  25813. type: object
  25814. type: object
  25815. vaultAwsIamServerID:
  25816. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  25817. type: string
  25818. vaultRole:
  25819. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  25820. type: string
  25821. required:
  25822. - vaultRole
  25823. type: object
  25824. jwt:
  25825. description: |-
  25826. Jwt authenticates with Vault by passing role and JWT token using the
  25827. JWT/OIDC authentication method
  25828. properties:
  25829. kubernetesServiceAccountToken:
  25830. description: |-
  25831. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  25832. a token for with the `TokenRequest` API.
  25833. properties:
  25834. audiences:
  25835. description: |-
  25836. Optional audiences field that will be used to request a temporary Kubernetes service
  25837. account token for the service account referenced by `serviceAccountRef`.
  25838. Defaults to a single audience `vault` it not specified.
  25839. Deprecated: use serviceAccountRef.Audiences instead
  25840. items:
  25841. type: string
  25842. type: array
  25843. expirationSeconds:
  25844. description: |-
  25845. Optional expiration time in seconds that will be used to request a temporary
  25846. Kubernetes service account token for the service account referenced by
  25847. `serviceAccountRef`.
  25848. Deprecated: this will be removed in the future.
  25849. Defaults to 10 minutes.
  25850. format: int64
  25851. type: integer
  25852. serviceAccountRef:
  25853. description: Service account field containing the name of a kubernetes ServiceAccount.
  25854. properties:
  25855. audiences:
  25856. description: |-
  25857. Audience specifies the `aud` claim for the service account token
  25858. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25859. then this audiences will be appended to the list
  25860. items:
  25861. type: string
  25862. type: array
  25863. name:
  25864. description: The name of the ServiceAccount resource being referred to.
  25865. maxLength: 253
  25866. minLength: 1
  25867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25868. type: string
  25869. namespace:
  25870. description: |-
  25871. Namespace of the resource being referred to.
  25872. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25873. maxLength: 63
  25874. minLength: 1
  25875. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25876. type: string
  25877. required:
  25878. - name
  25879. type: object
  25880. required:
  25881. - serviceAccountRef
  25882. type: object
  25883. path:
  25884. default: jwt
  25885. description: |-
  25886. Path where the JWT authentication backend is mounted
  25887. in Vault, e.g: "jwt"
  25888. type: string
  25889. role:
  25890. description: |-
  25891. Role is a JWT role to authenticate using the JWT/OIDC Vault
  25892. authentication method
  25893. type: string
  25894. secretRef:
  25895. description: |-
  25896. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  25897. authenticate with Vault using the JWT/OIDC authentication method.
  25898. properties:
  25899. key:
  25900. description: |-
  25901. A key in the referenced Secret.
  25902. Some instances of this field may be defaulted, in others it may be required.
  25903. maxLength: 253
  25904. minLength: 1
  25905. pattern: ^[-._a-zA-Z0-9]+$
  25906. type: string
  25907. name:
  25908. description: The name of the Secret resource being referred to.
  25909. maxLength: 253
  25910. minLength: 1
  25911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25912. type: string
  25913. namespace:
  25914. description: |-
  25915. The namespace of the Secret resource being referred to.
  25916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25917. maxLength: 63
  25918. minLength: 1
  25919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25920. type: string
  25921. type: object
  25922. required:
  25923. - path
  25924. type: object
  25925. kubernetes:
  25926. description: |-
  25927. Kubernetes authenticates with Vault by passing the ServiceAccount
  25928. token stored in the named Secret resource to the Vault server.
  25929. properties:
  25930. mountPath:
  25931. default: kubernetes
  25932. description: |-
  25933. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  25934. "kubernetes"
  25935. type: string
  25936. role:
  25937. description: |-
  25938. A required field containing the Vault Role to assume. A Role binds a
  25939. Kubernetes ServiceAccount with a set of Vault policies.
  25940. type: string
  25941. secretRef:
  25942. description: |-
  25943. Optional secret field containing a Kubernetes ServiceAccount JWT used
  25944. for authenticating with Vault. If a name is specified without a key,
  25945. `token` is the default. If one is not specified, the one bound to
  25946. the controller will be used.
  25947. properties:
  25948. key:
  25949. description: |-
  25950. A key in the referenced Secret.
  25951. Some instances of this field may be defaulted, in others it may be required.
  25952. maxLength: 253
  25953. minLength: 1
  25954. pattern: ^[-._a-zA-Z0-9]+$
  25955. type: string
  25956. name:
  25957. description: The name of the Secret resource being referred to.
  25958. maxLength: 253
  25959. minLength: 1
  25960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25961. type: string
  25962. namespace:
  25963. description: |-
  25964. The namespace of the Secret resource being referred to.
  25965. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25966. maxLength: 63
  25967. minLength: 1
  25968. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25969. type: string
  25970. type: object
  25971. serviceAccountRef:
  25972. description: |-
  25973. Optional service account field containing the name of a kubernetes ServiceAccount.
  25974. If the service account is specified, the service account secret token JWT will be used
  25975. for authenticating with Vault. If the service account selector is not supplied,
  25976. the secretRef will be used instead.
  25977. properties:
  25978. audiences:
  25979. description: |-
  25980. Audience specifies the `aud` claim for the service account token
  25981. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  25982. then this audiences will be appended to the list
  25983. items:
  25984. type: string
  25985. type: array
  25986. name:
  25987. description: The name of the ServiceAccount resource being referred to.
  25988. maxLength: 253
  25989. minLength: 1
  25990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  25991. type: string
  25992. namespace:
  25993. description: |-
  25994. Namespace of the resource being referred to.
  25995. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  25996. maxLength: 63
  25997. minLength: 1
  25998. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  25999. type: string
  26000. required:
  26001. - name
  26002. type: object
  26003. required:
  26004. - mountPath
  26005. - role
  26006. type: object
  26007. ldap:
  26008. description: |-
  26009. Ldap authenticates with Vault by passing username/password pair using
  26010. the LDAP authentication method
  26011. properties:
  26012. path:
  26013. default: ldap
  26014. description: |-
  26015. Path where the LDAP authentication backend is mounted
  26016. in Vault, e.g: "ldap"
  26017. type: string
  26018. secretRef:
  26019. description: |-
  26020. SecretRef to a key in a Secret resource containing password for the LDAP
  26021. user used to authenticate with Vault using the LDAP authentication
  26022. method
  26023. properties:
  26024. key:
  26025. description: |-
  26026. A key in the referenced Secret.
  26027. Some instances of this field may be defaulted, in others it may be required.
  26028. maxLength: 253
  26029. minLength: 1
  26030. pattern: ^[-._a-zA-Z0-9]+$
  26031. type: string
  26032. name:
  26033. description: The name of the Secret resource being referred to.
  26034. maxLength: 253
  26035. minLength: 1
  26036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26037. type: string
  26038. namespace:
  26039. description: |-
  26040. The namespace of the Secret resource being referred to.
  26041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26042. maxLength: 63
  26043. minLength: 1
  26044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26045. type: string
  26046. type: object
  26047. username:
  26048. description: |-
  26049. Username is an LDAP username used to authenticate using the LDAP Vault
  26050. authentication method
  26051. type: string
  26052. required:
  26053. - path
  26054. - username
  26055. type: object
  26056. namespace:
  26057. description: |-
  26058. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  26059. Namespaces is a set of features within Vault Enterprise that allows
  26060. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26061. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26062. This will default to Vault.Namespace field if set, or empty otherwise
  26063. type: string
  26064. tokenSecretRef:
  26065. description: TokenSecretRef authenticates with Vault by presenting a token.
  26066. properties:
  26067. key:
  26068. description: |-
  26069. A key in the referenced Secret.
  26070. Some instances of this field may be defaulted, in others it may be required.
  26071. maxLength: 253
  26072. minLength: 1
  26073. pattern: ^[-._a-zA-Z0-9]+$
  26074. type: string
  26075. name:
  26076. description: The name of the Secret resource being referred to.
  26077. maxLength: 253
  26078. minLength: 1
  26079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26080. type: string
  26081. namespace:
  26082. description: |-
  26083. The namespace of the Secret resource being referred to.
  26084. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26085. maxLength: 63
  26086. minLength: 1
  26087. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26088. type: string
  26089. type: object
  26090. userPass:
  26091. description: UserPass authenticates with Vault by passing username/password pair
  26092. properties:
  26093. path:
  26094. default: userpass
  26095. description: |-
  26096. Path where the UserPassword authentication backend is mounted
  26097. in Vault, e.g: "userpass"
  26098. type: string
  26099. secretRef:
  26100. description: |-
  26101. SecretRef to a key in a Secret resource containing password for the
  26102. user used to authenticate with Vault using the UserPass authentication
  26103. method
  26104. properties:
  26105. key:
  26106. description: |-
  26107. A key in the referenced Secret.
  26108. Some instances of this field may be defaulted, in others it may be required.
  26109. maxLength: 253
  26110. minLength: 1
  26111. pattern: ^[-._a-zA-Z0-9]+$
  26112. type: string
  26113. name:
  26114. description: The name of the Secret resource being referred to.
  26115. maxLength: 253
  26116. minLength: 1
  26117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26118. type: string
  26119. namespace:
  26120. description: |-
  26121. The namespace of the Secret resource being referred to.
  26122. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26123. maxLength: 63
  26124. minLength: 1
  26125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26126. type: string
  26127. type: object
  26128. username:
  26129. description: |-
  26130. Username is a username used to authenticate using the UserPass Vault
  26131. authentication method
  26132. type: string
  26133. required:
  26134. - path
  26135. - username
  26136. type: object
  26137. type: object
  26138. caBundle:
  26139. description: |-
  26140. PEM encoded CA bundle used to validate Vault server certificate. Only used
  26141. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26142. plain HTTP protocol connection. If not set the system root certificates
  26143. are used to validate the TLS connection.
  26144. format: byte
  26145. type: string
  26146. caProvider:
  26147. description: The provider for the CA bundle to use to validate Vault server certificate.
  26148. properties:
  26149. key:
  26150. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26151. maxLength: 253
  26152. minLength: 1
  26153. pattern: ^[-._a-zA-Z0-9]+$
  26154. type: string
  26155. name:
  26156. description: The name of the object located at the provider type.
  26157. maxLength: 253
  26158. minLength: 1
  26159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26160. type: string
  26161. namespace:
  26162. description: |-
  26163. The namespace the Provider type is in.
  26164. Can only be defined when used in a ClusterSecretStore.
  26165. maxLength: 63
  26166. minLength: 1
  26167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26168. type: string
  26169. type:
  26170. description: The type of provider to use such as "Secret", or "ConfigMap".
  26171. enum:
  26172. - Secret
  26173. - ConfigMap
  26174. type: string
  26175. required:
  26176. - name
  26177. - type
  26178. type: object
  26179. forwardInconsistent:
  26180. description: |-
  26181. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  26182. leader instead of simply retrying within a loop. This can increase performance if
  26183. the option is enabled serverside.
  26184. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  26185. type: boolean
  26186. headers:
  26187. additionalProperties:
  26188. type: string
  26189. description: Headers to be added in Vault request
  26190. type: object
  26191. namespace:
  26192. description: |-
  26193. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  26194. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  26195. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  26196. type: string
  26197. path:
  26198. description: |-
  26199. Path is the mount path of the Vault KV backend endpoint, e.g:
  26200. "secret". The v2 KV secret engine version specific "/data" path suffix
  26201. for fetching secrets from Vault is optional and will be appended
  26202. if not present in specified path.
  26203. type: string
  26204. readYourWrites:
  26205. description: |-
  26206. ReadYourWrites ensures isolated read-after-write semantics by
  26207. providing discovered cluster replication states in each request.
  26208. More information about eventual consistency in Vault can be found here
  26209. https://www.vaultproject.io/docs/enterprise/consistency
  26210. type: boolean
  26211. server:
  26212. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  26213. type: string
  26214. tls:
  26215. description: |-
  26216. The configuration used for client side related TLS communication, when the Vault server
  26217. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  26218. This parameter is ignored for plain HTTP protocol connection.
  26219. It's worth noting this configuration is different from the "TLS certificates auth method",
  26220. which is available under the `auth.cert` section.
  26221. properties:
  26222. certSecretRef:
  26223. description: |-
  26224. CertSecretRef is a certificate added to the transport layer
  26225. when communicating with the Vault server.
  26226. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  26227. properties:
  26228. key:
  26229. description: |-
  26230. A key in the referenced Secret.
  26231. Some instances of this field may be defaulted, in others it may be required.
  26232. maxLength: 253
  26233. minLength: 1
  26234. pattern: ^[-._a-zA-Z0-9]+$
  26235. type: string
  26236. name:
  26237. description: The name of the Secret resource being referred to.
  26238. maxLength: 253
  26239. minLength: 1
  26240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26241. type: string
  26242. namespace:
  26243. description: |-
  26244. The namespace of the Secret resource being referred to.
  26245. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26246. maxLength: 63
  26247. minLength: 1
  26248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26249. type: string
  26250. type: object
  26251. keySecretRef:
  26252. description: |-
  26253. KeySecretRef to a key in a Secret resource containing client private key
  26254. added to the transport layer when communicating with the Vault server.
  26255. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  26256. properties:
  26257. key:
  26258. description: |-
  26259. A key in the referenced Secret.
  26260. Some instances of this field may be defaulted, in others it may be required.
  26261. maxLength: 253
  26262. minLength: 1
  26263. pattern: ^[-._a-zA-Z0-9]+$
  26264. type: string
  26265. name:
  26266. description: The name of the Secret resource being referred to.
  26267. maxLength: 253
  26268. minLength: 1
  26269. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26270. type: string
  26271. namespace:
  26272. description: |-
  26273. The namespace of the Secret resource being referred to.
  26274. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26275. maxLength: 63
  26276. minLength: 1
  26277. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26278. type: string
  26279. type: object
  26280. type: object
  26281. version:
  26282. default: v2
  26283. description: |-
  26284. Version is the Vault KV secret engine version. This can be either "v1" or
  26285. "v2". Version defaults to "v2".
  26286. enum:
  26287. - v1
  26288. - v2
  26289. type: string
  26290. required:
  26291. - server
  26292. type: object
  26293. webhook:
  26294. description: Webhook configures this store to sync secrets using a generic templated webhook
  26295. properties:
  26296. auth:
  26297. description: Auth specifies a authorization protocol. Only one protocol may be set.
  26298. maxProperties: 1
  26299. minProperties: 1
  26300. properties:
  26301. ntlm:
  26302. description: NTLMProtocol configures the store to use NTLM for auth
  26303. properties:
  26304. passwordSecret:
  26305. description: |-
  26306. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26307. In some instances, `key` is a required field.
  26308. properties:
  26309. key:
  26310. description: |-
  26311. A key in the referenced Secret.
  26312. Some instances of this field may be defaulted, in others it may be required.
  26313. maxLength: 253
  26314. minLength: 1
  26315. pattern: ^[-._a-zA-Z0-9]+$
  26316. type: string
  26317. name:
  26318. description: The name of the Secret resource being referred to.
  26319. maxLength: 253
  26320. minLength: 1
  26321. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26322. type: string
  26323. namespace:
  26324. description: |-
  26325. The namespace of the Secret resource being referred to.
  26326. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26327. maxLength: 63
  26328. minLength: 1
  26329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26330. type: string
  26331. type: object
  26332. usernameSecret:
  26333. description: |-
  26334. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26335. In some instances, `key` is a required field.
  26336. properties:
  26337. key:
  26338. description: |-
  26339. A key in the referenced Secret.
  26340. Some instances of this field may be defaulted, in others it may be required.
  26341. maxLength: 253
  26342. minLength: 1
  26343. pattern: ^[-._a-zA-Z0-9]+$
  26344. type: string
  26345. name:
  26346. description: The name of the Secret resource being referred to.
  26347. maxLength: 253
  26348. minLength: 1
  26349. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26350. type: string
  26351. namespace:
  26352. description: |-
  26353. The namespace of the Secret resource being referred to.
  26354. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26355. maxLength: 63
  26356. minLength: 1
  26357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26358. type: string
  26359. type: object
  26360. required:
  26361. - passwordSecret
  26362. - usernameSecret
  26363. type: object
  26364. type: object
  26365. body:
  26366. description: Body
  26367. type: string
  26368. caBundle:
  26369. description: |-
  26370. PEM encoded CA bundle used to validate webhook server certificate. Only used
  26371. if the Server URL is using HTTPS protocol. This parameter is ignored for
  26372. plain HTTP protocol connection. If not set the system root certificates
  26373. are used to validate the TLS connection.
  26374. format: byte
  26375. type: string
  26376. caProvider:
  26377. description: The provider for the CA bundle to use to validate webhook server certificate.
  26378. properties:
  26379. key:
  26380. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  26381. maxLength: 253
  26382. minLength: 1
  26383. pattern: ^[-._a-zA-Z0-9]+$
  26384. type: string
  26385. name:
  26386. description: The name of the object located at the provider type.
  26387. maxLength: 253
  26388. minLength: 1
  26389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26390. type: string
  26391. namespace:
  26392. description: The namespace the Provider type is in.
  26393. maxLength: 63
  26394. minLength: 1
  26395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26396. type: string
  26397. type:
  26398. description: The type of provider to use such as "Secret", or "ConfigMap".
  26399. enum:
  26400. - Secret
  26401. - ConfigMap
  26402. type: string
  26403. required:
  26404. - name
  26405. - type
  26406. type: object
  26407. headers:
  26408. additionalProperties:
  26409. type: string
  26410. description: Headers
  26411. type: object
  26412. method:
  26413. description: Webhook Method
  26414. type: string
  26415. result:
  26416. description: Result formatting
  26417. properties:
  26418. jsonPath:
  26419. description: Json path of return value
  26420. type: string
  26421. type: object
  26422. secrets:
  26423. description: |-
  26424. Secrets to fill in templates
  26425. These secrets will be passed to the templating function as key value pairs under the given name
  26426. items:
  26427. description: WebhookSecret defines a secret to be used in webhook templates.
  26428. properties:
  26429. name:
  26430. description: Name of this secret in templates
  26431. type: string
  26432. secretRef:
  26433. description: Secret ref to fill in credentials
  26434. properties:
  26435. key:
  26436. description: |-
  26437. A key in the referenced Secret.
  26438. Some instances of this field may be defaulted, in others it may be required.
  26439. maxLength: 253
  26440. minLength: 1
  26441. pattern: ^[-._a-zA-Z0-9]+$
  26442. type: string
  26443. name:
  26444. description: The name of the Secret resource being referred to.
  26445. maxLength: 253
  26446. minLength: 1
  26447. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26448. type: string
  26449. namespace:
  26450. description: |-
  26451. The namespace of the Secret resource being referred to.
  26452. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26453. maxLength: 63
  26454. minLength: 1
  26455. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26456. type: string
  26457. type: object
  26458. required:
  26459. - name
  26460. - secretRef
  26461. type: object
  26462. type: array
  26463. timeout:
  26464. description: Timeout
  26465. type: string
  26466. url:
  26467. description: Webhook url to call
  26468. type: string
  26469. required:
  26470. - result
  26471. - url
  26472. type: object
  26473. yandexcertificatemanager:
  26474. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  26475. properties:
  26476. apiEndpoint:
  26477. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26478. type: string
  26479. auth:
  26480. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  26481. properties:
  26482. authorizedKeySecretRef:
  26483. description: The authorized key used for authentication
  26484. properties:
  26485. key:
  26486. description: |-
  26487. A key in the referenced Secret.
  26488. Some instances of this field may be defaulted, in others it may be required.
  26489. maxLength: 253
  26490. minLength: 1
  26491. pattern: ^[-._a-zA-Z0-9]+$
  26492. type: string
  26493. name:
  26494. description: The name of the Secret resource being referred to.
  26495. maxLength: 253
  26496. minLength: 1
  26497. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26498. type: string
  26499. namespace:
  26500. description: |-
  26501. The namespace of the Secret resource being referred to.
  26502. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26503. maxLength: 63
  26504. minLength: 1
  26505. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26506. type: string
  26507. type: object
  26508. type: object
  26509. caProvider:
  26510. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26511. properties:
  26512. certSecretRef:
  26513. description: |-
  26514. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26515. In some instances, `key` is a required field.
  26516. properties:
  26517. key:
  26518. description: |-
  26519. A key in the referenced Secret.
  26520. Some instances of this field may be defaulted, in others it may be required.
  26521. maxLength: 253
  26522. minLength: 1
  26523. pattern: ^[-._a-zA-Z0-9]+$
  26524. type: string
  26525. name:
  26526. description: The name of the Secret resource being referred to.
  26527. maxLength: 253
  26528. minLength: 1
  26529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26530. type: string
  26531. namespace:
  26532. description: |-
  26533. The namespace of the Secret resource being referred to.
  26534. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26535. maxLength: 63
  26536. minLength: 1
  26537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26538. type: string
  26539. type: object
  26540. type: object
  26541. required:
  26542. - auth
  26543. type: object
  26544. yandexlockbox:
  26545. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  26546. properties:
  26547. apiEndpoint:
  26548. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  26549. type: string
  26550. auth:
  26551. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  26552. properties:
  26553. authorizedKeySecretRef:
  26554. description: The authorized key used for authentication
  26555. properties:
  26556. key:
  26557. description: |-
  26558. A key in the referenced Secret.
  26559. Some instances of this field may be defaulted, in others it may be required.
  26560. maxLength: 253
  26561. minLength: 1
  26562. pattern: ^[-._a-zA-Z0-9]+$
  26563. type: string
  26564. name:
  26565. description: The name of the Secret resource being referred to.
  26566. maxLength: 253
  26567. minLength: 1
  26568. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26569. type: string
  26570. namespace:
  26571. description: |-
  26572. The namespace of the Secret resource being referred to.
  26573. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26574. maxLength: 63
  26575. minLength: 1
  26576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26577. type: string
  26578. type: object
  26579. type: object
  26580. caProvider:
  26581. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  26582. properties:
  26583. certSecretRef:
  26584. description: |-
  26585. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  26586. In some instances, `key` is a required field.
  26587. properties:
  26588. key:
  26589. description: |-
  26590. A key in the referenced Secret.
  26591. Some instances of this field may be defaulted, in others it may be required.
  26592. maxLength: 253
  26593. minLength: 1
  26594. pattern: ^[-._a-zA-Z0-9]+$
  26595. type: string
  26596. name:
  26597. description: The name of the Secret resource being referred to.
  26598. maxLength: 253
  26599. minLength: 1
  26600. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26601. type: string
  26602. namespace:
  26603. description: |-
  26604. The namespace of the Secret resource being referred to.
  26605. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26606. maxLength: 63
  26607. minLength: 1
  26608. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26609. type: string
  26610. type: object
  26611. type: object
  26612. required:
  26613. - auth
  26614. type: object
  26615. type: object
  26616. refreshInterval:
  26617. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  26618. type: integer
  26619. retrySettings:
  26620. description: Used to configure HTTP retries on failures.
  26621. properties:
  26622. maxRetries:
  26623. description: MaxRetries is the maximum number of retry attempts.
  26624. format: int32
  26625. type: integer
  26626. retryInterval:
  26627. description: RetryInterval is the interval between retry attempts.
  26628. type: string
  26629. type: object
  26630. required:
  26631. - provider
  26632. type: object
  26633. status:
  26634. description: SecretStoreStatus defines the observed state of the SecretStore.
  26635. properties:
  26636. capabilities:
  26637. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  26638. type: string
  26639. conditions:
  26640. items:
  26641. description: SecretStoreStatusCondition defines the observed condition of the SecretStore.
  26642. properties:
  26643. lastTransitionTime:
  26644. format: date-time
  26645. type: string
  26646. message:
  26647. type: string
  26648. reason:
  26649. type: string
  26650. status:
  26651. type: string
  26652. type:
  26653. description: SecretStoreConditionType represents the condition type of the SecretStore.
  26654. type: string
  26655. required:
  26656. - status
  26657. - type
  26658. type: object
  26659. type: array
  26660. type: object
  26661. type: object
  26662. served: false
  26663. storage: false
  26664. subresources:
  26665. status: {}
  26666. ---
  26667. apiVersion: apiextensions.k8s.io/v1
  26668. kind: CustomResourceDefinition
  26669. metadata:
  26670. annotations:
  26671. controller-gen.kubebuilder.io/version: v0.19.0
  26672. labels:
  26673. external-secrets.io/component: controller
  26674. name: acraccesstokens.generators.external-secrets.io
  26675. spec:
  26676. group: generators.external-secrets.io
  26677. names:
  26678. categories:
  26679. - external-secrets
  26680. - external-secrets-generators
  26681. kind: ACRAccessToken
  26682. listKind: ACRAccessTokenList
  26683. plural: acraccesstokens
  26684. singular: acraccesstoken
  26685. scope: Namespaced
  26686. versions:
  26687. - name: v1alpha1
  26688. schema:
  26689. openAPIV3Schema:
  26690. description: |-
  26691. ACRAccessToken returns an Azure Container Registry token
  26692. that can be used for pushing/pulling images.
  26693. Note: by default it will return an ACR Refresh Token with full access
  26694. (depending on the identity).
  26695. This can be scoped down to the repository level using .spec.scope.
  26696. In case scope is defined it will return an ACR Access Token.
  26697. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  26698. properties:
  26699. apiVersion:
  26700. description: |-
  26701. APIVersion defines the versioned schema of this representation of an object.
  26702. Servers should convert recognized schemas to the latest internal value, and
  26703. may reject unrecognized values.
  26704. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26705. type: string
  26706. kind:
  26707. description: |-
  26708. Kind is a string value representing the REST resource this object represents.
  26709. Servers may infer this from the endpoint the client submits requests to.
  26710. Cannot be updated.
  26711. In CamelCase.
  26712. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26713. type: string
  26714. metadata:
  26715. type: object
  26716. spec:
  26717. description: |-
  26718. ACRAccessTokenSpec defines how to generate the access token
  26719. e.g. how to authenticate and which registry to use.
  26720. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  26721. properties:
  26722. auth:
  26723. description: ACRAuth defines the authentication methods for Azure Container Registry.
  26724. properties:
  26725. managedIdentity:
  26726. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  26727. properties:
  26728. identityId:
  26729. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  26730. type: string
  26731. type: object
  26732. servicePrincipal:
  26733. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  26734. properties:
  26735. secretRef:
  26736. description: |-
  26737. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  26738. It uses static credentials stored in a Kind=Secret.
  26739. properties:
  26740. clientId:
  26741. description: The Azure clientId of the service principle used for authentication.
  26742. properties:
  26743. key:
  26744. description: |-
  26745. A key in the referenced Secret.
  26746. Some instances of this field may be defaulted, in others it may be required.
  26747. maxLength: 253
  26748. minLength: 1
  26749. pattern: ^[-._a-zA-Z0-9]+$
  26750. type: string
  26751. name:
  26752. description: The name of the Secret resource being referred to.
  26753. maxLength: 253
  26754. minLength: 1
  26755. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26756. type: string
  26757. namespace:
  26758. description: |-
  26759. The namespace of the Secret resource being referred to.
  26760. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26761. maxLength: 63
  26762. minLength: 1
  26763. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26764. type: string
  26765. type: object
  26766. clientSecret:
  26767. description: The Azure ClientSecret of the service principle used for authentication.
  26768. properties:
  26769. key:
  26770. description: |-
  26771. A key in the referenced Secret.
  26772. Some instances of this field may be defaulted, in others it may be required.
  26773. maxLength: 253
  26774. minLength: 1
  26775. pattern: ^[-._a-zA-Z0-9]+$
  26776. type: string
  26777. name:
  26778. description: The name of the Secret resource being referred to.
  26779. maxLength: 253
  26780. minLength: 1
  26781. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26782. type: string
  26783. namespace:
  26784. description: |-
  26785. The namespace of the Secret resource being referred to.
  26786. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26787. maxLength: 63
  26788. minLength: 1
  26789. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26790. type: string
  26791. type: object
  26792. type: object
  26793. required:
  26794. - secretRef
  26795. type: object
  26796. workloadIdentity:
  26797. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  26798. properties:
  26799. serviceAccountRef:
  26800. description: |-
  26801. ServiceAccountRef specified the service account
  26802. that should be used when authenticating with WorkloadIdentity.
  26803. properties:
  26804. audiences:
  26805. description: |-
  26806. Audience specifies the `aud` claim for the service account token
  26807. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  26808. then this audiences will be appended to the list
  26809. items:
  26810. type: string
  26811. type: array
  26812. name:
  26813. description: The name of the ServiceAccount resource being referred to.
  26814. maxLength: 253
  26815. minLength: 1
  26816. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26817. type: string
  26818. namespace:
  26819. description: |-
  26820. Namespace of the resource being referred to.
  26821. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26822. maxLength: 63
  26823. minLength: 1
  26824. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26825. type: string
  26826. required:
  26827. - name
  26828. type: object
  26829. type: object
  26830. type: object
  26831. environmentType:
  26832. default: PublicCloud
  26833. description: |-
  26834. EnvironmentType specifies the Azure cloud environment endpoints to use for
  26835. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  26836. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  26837. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  26838. enum:
  26839. - PublicCloud
  26840. - USGovernmentCloud
  26841. - ChinaCloud
  26842. - GermanCloud
  26843. - AzureStackCloud
  26844. type: string
  26845. registry:
  26846. description: |-
  26847. the domain name of the ACR registry
  26848. e.g. foobarexample.azurecr.io
  26849. type: string
  26850. scope:
  26851. description: |-
  26852. Define the scope for the access token, e.g. pull/push access for a repository.
  26853. if not provided it will return a refresh token that has full scope.
  26854. Note: you need to pin it down to the repository level, there is no wildcard available.
  26855. examples:
  26856. repository:my-repository:pull,push
  26857. repository:my-repository:pull
  26858. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  26859. type: string
  26860. tenantId:
  26861. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  26862. type: string
  26863. required:
  26864. - auth
  26865. - registry
  26866. type: object
  26867. type: object
  26868. served: true
  26869. storage: true
  26870. subresources:
  26871. status: {}
  26872. ---
  26873. apiVersion: apiextensions.k8s.io/v1
  26874. kind: CustomResourceDefinition
  26875. metadata:
  26876. annotations:
  26877. controller-gen.kubebuilder.io/version: v0.19.0
  26878. labels:
  26879. external-secrets.io/component: controller
  26880. name: beyondtrustworkloadcredentialsdynamicsecrets.generators.external-secrets.io
  26881. spec:
  26882. group: generators.external-secrets.io
  26883. names:
  26884. categories:
  26885. - external-secrets
  26886. - external-secrets-generators
  26887. kind: BeyondtrustWorkloadCredentialsDynamicSecret
  26888. listKind: BeyondtrustWorkloadCredentialsDynamicSecretList
  26889. plural: beyondtrustworkloadcredentialsdynamicsecrets
  26890. singular: beyondtrustworkloadcredentialsdynamicsecret
  26891. scope: Namespaced
  26892. versions:
  26893. - name: v1alpha1
  26894. schema:
  26895. openAPIV3Schema:
  26896. description: |-
  26897. BeyondtrustWorkloadCredentialsDynamicSecret represents a generator that requests dynamic credentials from BeyondTrust Workload Credentials.
  26898. This generator calls the BeyondTrust Workload Credentials API to generate fresh, temporary credentials
  26899. (such as AWS STS credentials) each time an ExternalSecret is refreshed.
  26900. Dynamic secret definitions must be created in BeyondTrust Workload Credentials before they can be referenced.
  26901. For complete documentation, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26902. properties:
  26903. apiVersion:
  26904. description: |-
  26905. APIVersion defines the versioned schema of this representation of an object.
  26906. Servers should convert recognized schemas to the latest internal value, and
  26907. may reject unrecognized values.
  26908. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  26909. type: string
  26910. kind:
  26911. description: |-
  26912. Kind is a string value representing the REST resource this object represents.
  26913. Servers may infer this from the endpoint the client submits requests to.
  26914. Cannot be updated.
  26915. In CamelCase.
  26916. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  26917. type: string
  26918. metadata:
  26919. type: object
  26920. spec:
  26921. description: |-
  26922. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  26923. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  26924. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26925. properties:
  26926. controller:
  26927. description: |-
  26928. Controller selects the controller that should handle this generator.
  26929. Leave empty to use the default controller.
  26930. type: string
  26931. provider:
  26932. description: |-
  26933. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  26934. server connection details, and the folder path to the dynamic secret definition.
  26935. The folderPath should point to a dynamic secret definition that has been created in
  26936. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  26937. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  26938. properties:
  26939. auth:
  26940. description: |-
  26941. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  26942. Currently supports API key authentication via Kubernetes secret reference.
  26943. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26944. properties:
  26945. apikey:
  26946. description: |-
  26947. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  26948. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  26949. properties:
  26950. token:
  26951. description: |-
  26952. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  26953. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  26954. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  26955. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  26956. properties:
  26957. key:
  26958. description: |-
  26959. A key in the referenced Secret.
  26960. Some instances of this field may be defaulted, in others it may be required.
  26961. maxLength: 253
  26962. minLength: 1
  26963. pattern: ^[-._a-zA-Z0-9]+$
  26964. type: string
  26965. name:
  26966. description: The name of the Secret resource being referred to.
  26967. maxLength: 253
  26968. minLength: 1
  26969. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  26970. type: string
  26971. namespace:
  26972. description: |-
  26973. The namespace of the Secret resource being referred to.
  26974. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  26975. maxLength: 63
  26976. minLength: 1
  26977. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  26978. type: string
  26979. type: object
  26980. required:
  26981. - token
  26982. type: object
  26983. required:
  26984. - apikey
  26985. type: object
  26986. caBundle:
  26987. description: |-
  26988. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26989. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  26990. If not set, the system's trusted root certificates are used.
  26991. format: byte
  26992. type: string
  26993. caProvider:
  26994. description: |-
  26995. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  26996. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  26997. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  26998. properties:
  26999. key:
  27000. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27001. maxLength: 253
  27002. minLength: 1
  27003. pattern: ^[-._a-zA-Z0-9]+$
  27004. type: string
  27005. name:
  27006. description: The name of the object located at the provider type.
  27007. maxLength: 253
  27008. minLength: 1
  27009. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27010. type: string
  27011. namespace:
  27012. description: |-
  27013. The namespace the Provider type is in.
  27014. Can only be defined when used in a ClusterSecretStore.
  27015. maxLength: 63
  27016. minLength: 1
  27017. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27018. type: string
  27019. type:
  27020. description: The type of provider to use such as "Secret", or "ConfigMap".
  27021. enum:
  27022. - Secret
  27023. - ConfigMap
  27024. type: string
  27025. required:
  27026. - name
  27027. - type
  27028. type: object
  27029. folderPath:
  27030. description: |-
  27031. FolderPath specifies the default folder path for secret retrieval.
  27032. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27033. Example: "production/database" or "dev/api-keys"
  27034. Leave empty to retrieve secrets from the root folder.
  27035. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27036. type: string
  27037. server:
  27038. description: |-
  27039. Server configures the BeyondTrust Workload Credentials server connection details.
  27040. Includes the API URL and Site ID for your BeyondTrust instance.
  27041. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27042. properties:
  27043. apiUrl:
  27044. description: |-
  27045. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27046. This should be the full URL to your BeyondTrust instance.
  27047. Example: https://api.beyondtrust.io/siie
  27048. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27049. type: string
  27050. siteId:
  27051. description: |-
  27052. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27053. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27054. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27055. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27056. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27057. type: string
  27058. required:
  27059. - apiUrl
  27060. - siteId
  27061. type: object
  27062. required:
  27063. - auth
  27064. - server
  27065. type: object
  27066. retrySettings:
  27067. description: |-
  27068. RetrySettings configures exponential backoff for failed API requests.
  27069. If not specified, uses the default retry settings.
  27070. properties:
  27071. maxRetries:
  27072. format: int32
  27073. type: integer
  27074. retryInterval:
  27075. type: string
  27076. type: object
  27077. required:
  27078. - provider
  27079. type: object
  27080. type: object
  27081. served: true
  27082. storage: true
  27083. subresources:
  27084. status: {}
  27085. ---
  27086. apiVersion: apiextensions.k8s.io/v1
  27087. kind: CustomResourceDefinition
  27088. metadata:
  27089. annotations:
  27090. controller-gen.kubebuilder.io/version: v0.19.0
  27091. labels:
  27092. external-secrets.io/component: controller
  27093. name: cloudsmithaccesstokens.generators.external-secrets.io
  27094. spec:
  27095. group: generators.external-secrets.io
  27096. names:
  27097. categories:
  27098. - external-secrets
  27099. - external-secrets-generators
  27100. kind: CloudsmithAccessToken
  27101. listKind: CloudsmithAccessTokenList
  27102. plural: cloudsmithaccesstokens
  27103. singular: cloudsmithaccesstoken
  27104. scope: Namespaced
  27105. versions:
  27106. - name: v1alpha1
  27107. schema:
  27108. openAPIV3Schema:
  27109. description: CloudsmithAccessToken generates Cloudsmith access token using OIDC authentication
  27110. properties:
  27111. apiVersion:
  27112. description: |-
  27113. APIVersion defines the versioned schema of this representation of an object.
  27114. Servers should convert recognized schemas to the latest internal value, and
  27115. may reject unrecognized values.
  27116. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27117. type: string
  27118. kind:
  27119. description: |-
  27120. Kind is a string value representing the REST resource this object represents.
  27121. Servers may infer this from the endpoint the client submits requests to.
  27122. Cannot be updated.
  27123. In CamelCase.
  27124. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27125. type: string
  27126. metadata:
  27127. type: object
  27128. spec:
  27129. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27130. properties:
  27131. apiUrl:
  27132. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27133. type: string
  27134. orgSlug:
  27135. description: OrgSlug is the organization slug in Cloudsmith
  27136. type: string
  27137. serviceAccountRef:
  27138. description: Name of the service account you are federating with
  27139. properties:
  27140. audiences:
  27141. description: |-
  27142. Audience specifies the `aud` claim for the service account token
  27143. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27144. then this audiences will be appended to the list
  27145. items:
  27146. type: string
  27147. type: array
  27148. name:
  27149. description: The name of the ServiceAccount resource being referred to.
  27150. maxLength: 253
  27151. minLength: 1
  27152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27153. type: string
  27154. namespace:
  27155. description: |-
  27156. Namespace of the resource being referred to.
  27157. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27158. maxLength: 63
  27159. minLength: 1
  27160. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27161. type: string
  27162. required:
  27163. - name
  27164. type: object
  27165. serviceSlug:
  27166. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27167. type: string
  27168. required:
  27169. - orgSlug
  27170. - serviceAccountRef
  27171. - serviceSlug
  27172. type: object
  27173. type: object
  27174. served: true
  27175. storage: true
  27176. subresources:
  27177. status: {}
  27178. ---
  27179. apiVersion: apiextensions.k8s.io/v1
  27180. kind: CustomResourceDefinition
  27181. metadata:
  27182. annotations:
  27183. controller-gen.kubebuilder.io/version: v0.19.0
  27184. labels:
  27185. external-secrets.io/component: controller
  27186. name: clustergenerators.generators.external-secrets.io
  27187. spec:
  27188. group: generators.external-secrets.io
  27189. names:
  27190. categories:
  27191. - external-secrets
  27192. - external-secrets-generators
  27193. kind: ClusterGenerator
  27194. listKind: ClusterGeneratorList
  27195. plural: clustergenerators
  27196. singular: clustergenerator
  27197. scope: Cluster
  27198. versions:
  27199. - name: v1alpha1
  27200. schema:
  27201. openAPIV3Schema:
  27202. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  27203. properties:
  27204. apiVersion:
  27205. description: |-
  27206. APIVersion defines the versioned schema of this representation of an object.
  27207. Servers should convert recognized schemas to the latest internal value, and
  27208. may reject unrecognized values.
  27209. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  27210. type: string
  27211. kind:
  27212. description: |-
  27213. Kind is a string value representing the REST resource this object represents.
  27214. Servers may infer this from the endpoint the client submits requests to.
  27215. Cannot be updated.
  27216. In CamelCase.
  27217. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  27218. type: string
  27219. metadata:
  27220. type: object
  27221. spec:
  27222. description: ClusterGeneratorSpec defines the desired state of a ClusterGenerator.
  27223. properties:
  27224. generator:
  27225. description: Generator the spec for this generator, must match the kind.
  27226. maxProperties: 1
  27227. minProperties: 1
  27228. properties:
  27229. acrAccessTokenSpec:
  27230. description: |-
  27231. ACRAccessTokenSpec defines how to generate the access token
  27232. e.g. how to authenticate and which registry to use.
  27233. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  27234. properties:
  27235. auth:
  27236. description: ACRAuth defines the authentication methods for Azure Container Registry.
  27237. properties:
  27238. managedIdentity:
  27239. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  27240. properties:
  27241. identityId:
  27242. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  27243. type: string
  27244. type: object
  27245. servicePrincipal:
  27246. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  27247. properties:
  27248. secretRef:
  27249. description: |-
  27250. AzureACRServicePrincipalAuthSecretRef defines the secret references for Azure Service Principal authentication.
  27251. It uses static credentials stored in a Kind=Secret.
  27252. properties:
  27253. clientId:
  27254. description: The Azure clientId of the service principle used for authentication.
  27255. properties:
  27256. key:
  27257. description: |-
  27258. A key in the referenced Secret.
  27259. Some instances of this field may be defaulted, in others it may be required.
  27260. maxLength: 253
  27261. minLength: 1
  27262. pattern: ^[-._a-zA-Z0-9]+$
  27263. type: string
  27264. name:
  27265. description: The name of the Secret resource being referred to.
  27266. maxLength: 253
  27267. minLength: 1
  27268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27269. type: string
  27270. namespace:
  27271. description: |-
  27272. The namespace of the Secret resource being referred to.
  27273. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27274. maxLength: 63
  27275. minLength: 1
  27276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27277. type: string
  27278. type: object
  27279. clientSecret:
  27280. description: The Azure ClientSecret of the service principle used for authentication.
  27281. properties:
  27282. key:
  27283. description: |-
  27284. A key in the referenced Secret.
  27285. Some instances of this field may be defaulted, in others it may be required.
  27286. maxLength: 253
  27287. minLength: 1
  27288. pattern: ^[-._a-zA-Z0-9]+$
  27289. type: string
  27290. name:
  27291. description: The name of the Secret resource being referred to.
  27292. maxLength: 253
  27293. minLength: 1
  27294. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27295. type: string
  27296. namespace:
  27297. description: |-
  27298. The namespace of the Secret resource being referred to.
  27299. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27300. maxLength: 63
  27301. minLength: 1
  27302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27303. type: string
  27304. type: object
  27305. type: object
  27306. required:
  27307. - secretRef
  27308. type: object
  27309. workloadIdentity:
  27310. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  27311. properties:
  27312. serviceAccountRef:
  27313. description: |-
  27314. ServiceAccountRef specified the service account
  27315. that should be used when authenticating with WorkloadIdentity.
  27316. properties:
  27317. audiences:
  27318. description: |-
  27319. Audience specifies the `aud` claim for the service account token
  27320. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27321. then this audiences will be appended to the list
  27322. items:
  27323. type: string
  27324. type: array
  27325. name:
  27326. description: The name of the ServiceAccount resource being referred to.
  27327. maxLength: 253
  27328. minLength: 1
  27329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27330. type: string
  27331. namespace:
  27332. description: |-
  27333. Namespace of the resource being referred to.
  27334. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27335. maxLength: 63
  27336. minLength: 1
  27337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27338. type: string
  27339. required:
  27340. - name
  27341. type: object
  27342. type: object
  27343. type: object
  27344. environmentType:
  27345. default: PublicCloud
  27346. description: |-
  27347. EnvironmentType specifies the Azure cloud environment endpoints to use for
  27348. connecting and authenticating with Azure. By default, it points to the public cloud AAD endpoint.
  27349. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  27350. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  27351. enum:
  27352. - PublicCloud
  27353. - USGovernmentCloud
  27354. - ChinaCloud
  27355. - GermanCloud
  27356. - AzureStackCloud
  27357. type: string
  27358. registry:
  27359. description: |-
  27360. the domain name of the ACR registry
  27361. e.g. foobarexample.azurecr.io
  27362. type: string
  27363. scope:
  27364. description: |-
  27365. Define the scope for the access token, e.g. pull/push access for a repository.
  27366. if not provided it will return a refresh token that has full scope.
  27367. Note: you need to pin it down to the repository level, there is no wildcard available.
  27368. examples:
  27369. repository:my-repository:pull,push
  27370. repository:my-repository:pull
  27371. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  27372. type: string
  27373. tenantId:
  27374. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  27375. type: string
  27376. required:
  27377. - auth
  27378. - registry
  27379. type: object
  27380. beyondtrustWorkloadCredentialsDynamicSecretSpec:
  27381. description: |-
  27382. BeyondtrustWorkloadCredentialsDynamicSecretSpec defines the desired spec for BeyondtrustWorkloadCredentials dynamic generator.
  27383. This generator enables obtaining temporary, short-lived credentials from BeyondTrust Workload Credentials.
  27384. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27385. properties:
  27386. controller:
  27387. description: |-
  27388. Controller selects the controller that should handle this generator.
  27389. Leave empty to use the default controller.
  27390. type: string
  27391. provider:
  27392. description: |-
  27393. Provider contains the BeyondtrustWorkloadCredentials provider configuration including authentication,
  27394. server connection details, and the folder path to the dynamic secret definition.
  27395. The folderPath should point to a dynamic secret definition that has been created in
  27396. BeyondTrust Workload Credentials (e.g., "production/aws-temp").
  27397. For setup details, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27398. properties:
  27399. auth:
  27400. description: |-
  27401. Auth configures how the Operator authenticates with the BeyondTrust Workload Credentials API.
  27402. Currently supports API key authentication via Kubernetes secret reference.
  27403. For authentication setup, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27404. properties:
  27405. apikey:
  27406. description: |-
  27407. APIKey configures API token authentication for BeyondTrust Workload Credentials.
  27408. The token is retrieved from a Kubernetes secret and used as a Bearer token for API requests.
  27409. properties:
  27410. token:
  27411. description: |-
  27412. Token references the Kubernetes secret containing the BeyondTrust Workload Credentials API token.
  27413. The secret should contain the API key used to authenticate with BeyondTrust Workload Credentials.
  27414. Create an API token in your BeyondTrust Workload Credentials console and store it in a Kubernetes secret.
  27415. For details on creating API tokens, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#authentication
  27416. properties:
  27417. key:
  27418. description: |-
  27419. A key in the referenced Secret.
  27420. Some instances of this field may be defaulted, in others it may be required.
  27421. maxLength: 253
  27422. minLength: 1
  27423. pattern: ^[-._a-zA-Z0-9]+$
  27424. type: string
  27425. name:
  27426. description: The name of the Secret resource being referred to.
  27427. maxLength: 253
  27428. minLength: 1
  27429. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27430. type: string
  27431. namespace:
  27432. description: |-
  27433. The namespace of the Secret resource being referred to.
  27434. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27435. maxLength: 63
  27436. minLength: 1
  27437. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27438. type: string
  27439. type: object
  27440. required:
  27441. - token
  27442. type: object
  27443. required:
  27444. - apikey
  27445. type: object
  27446. caBundle:
  27447. description: |-
  27448. CABundle is a base64-encoded CA certificate used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27449. Use this when your BeyondTrust instance uses a self-signed certificate or internal CA.
  27450. If not set, the system's trusted root certificates are used.
  27451. format: byte
  27452. type: string
  27453. caProvider:
  27454. description: |-
  27455. CAProvider points to a Secret or ConfigMap containing a PEM-encoded CA certificate.
  27456. This is used to validate the BeyondTrust Workload Credentials API TLS certificate.
  27457. Use this as an alternative to CABundle when you want to reference an existing Kubernetes resource.
  27458. properties:
  27459. key:
  27460. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  27461. maxLength: 253
  27462. minLength: 1
  27463. pattern: ^[-._a-zA-Z0-9]+$
  27464. type: string
  27465. name:
  27466. description: The name of the object located at the provider type.
  27467. maxLength: 253
  27468. minLength: 1
  27469. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27470. type: string
  27471. namespace:
  27472. description: |-
  27473. The namespace the Provider type is in.
  27474. Can only be defined when used in a ClusterSecretStore.
  27475. maxLength: 63
  27476. minLength: 1
  27477. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27478. type: string
  27479. type:
  27480. description: The type of provider to use such as "Secret", or "ConfigMap".
  27481. enum:
  27482. - Secret
  27483. - ConfigMap
  27484. type: string
  27485. required:
  27486. - name
  27487. - type
  27488. type: object
  27489. folderPath:
  27490. description: |-
  27491. FolderPath specifies the default folder path for secret retrieval.
  27492. Secrets will be fetched from this folder unless overridden in the ExternalSecret spec.
  27493. Example: "production/database" or "dev/api-keys"
  27494. Leave empty to retrieve secrets from the root folder.
  27495. For folder organization, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#folders
  27496. type: string
  27497. server:
  27498. description: |-
  27499. Server configures the BeyondTrust Workload Credentials server connection details.
  27500. Includes the API URL and Site ID for your BeyondTrust instance.
  27501. For API reference, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27502. properties:
  27503. apiUrl:
  27504. description: |-
  27505. APIURL is the base URL of your BeyondTrust Workload Credentials API server.
  27506. This should be the full URL to your BeyondTrust instance.
  27507. Example: https://api.beyondtrust.io/siie
  27508. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api#base-url
  27509. type: string
  27510. siteId:
  27511. description: |-
  27512. SiteID is your BeyondTrust Workload Credentials site identifier (UUID format).
  27513. This identifier is unique to your BeyondTrust Workload Credentials instance.
  27514. You can find your Site ID in the BeyondTrust Workload Credentials admin console.
  27515. Example: a1b2c3d4-e5f6-4890-abcd-ef1234567890
  27516. For more information, see: https://docs.beyondtrust.com/bt-docs/docs/secrets-api
  27517. type: string
  27518. required:
  27519. - apiUrl
  27520. - siteId
  27521. type: object
  27522. required:
  27523. - auth
  27524. - server
  27525. type: object
  27526. retrySettings:
  27527. description: |-
  27528. RetrySettings configures exponential backoff for failed API requests.
  27529. If not specified, uses the default retry settings.
  27530. properties:
  27531. maxRetries:
  27532. format: int32
  27533. type: integer
  27534. retryInterval:
  27535. type: string
  27536. type: object
  27537. required:
  27538. - provider
  27539. type: object
  27540. cloudsmithAccessTokenSpec:
  27541. description: CloudsmithAccessTokenSpec defines the configuration for generating a Cloudsmith access token using OIDC authentication.
  27542. properties:
  27543. apiUrl:
  27544. description: APIURL configures the Cloudsmith API URL. Defaults to https://api.cloudsmith.io.
  27545. type: string
  27546. orgSlug:
  27547. description: OrgSlug is the organization slug in Cloudsmith
  27548. type: string
  27549. serviceAccountRef:
  27550. description: Name of the service account you are federating with
  27551. properties:
  27552. audiences:
  27553. description: |-
  27554. Audience specifies the `aud` claim for the service account token
  27555. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27556. then this audiences will be appended to the list
  27557. items:
  27558. type: string
  27559. type: array
  27560. name:
  27561. description: The name of the ServiceAccount resource being referred to.
  27562. maxLength: 253
  27563. minLength: 1
  27564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27565. type: string
  27566. namespace:
  27567. description: |-
  27568. Namespace of the resource being referred to.
  27569. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27570. maxLength: 63
  27571. minLength: 1
  27572. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27573. type: string
  27574. required:
  27575. - name
  27576. type: object
  27577. serviceSlug:
  27578. description: ServiceSlug is the service slug in Cloudsmith for OIDC authentication
  27579. type: string
  27580. required:
  27581. - orgSlug
  27582. - serviceAccountRef
  27583. - serviceSlug
  27584. type: object
  27585. ecrAuthorizationTokenSpec:
  27586. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  27587. properties:
  27588. auth:
  27589. description: Auth defines how to authenticate with AWS
  27590. properties:
  27591. jwt:
  27592. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  27593. properties:
  27594. serviceAccountRef:
  27595. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27596. properties:
  27597. audiences:
  27598. description: |-
  27599. Audience specifies the `aud` claim for the service account token
  27600. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27601. then this audiences will be appended to the list
  27602. items:
  27603. type: string
  27604. type: array
  27605. name:
  27606. description: The name of the ServiceAccount resource being referred to.
  27607. maxLength: 253
  27608. minLength: 1
  27609. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27610. type: string
  27611. namespace:
  27612. description: |-
  27613. Namespace of the resource being referred to.
  27614. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27615. maxLength: 63
  27616. minLength: 1
  27617. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27618. type: string
  27619. required:
  27620. - name
  27621. type: object
  27622. type: object
  27623. secretRef:
  27624. description: |-
  27625. AWSAuthSecretRef holds secret references for AWS credentials
  27626. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  27627. properties:
  27628. accessKeyIDSecretRef:
  27629. description: The AccessKeyID is used for authentication
  27630. properties:
  27631. key:
  27632. description: |-
  27633. A key in the referenced Secret.
  27634. Some instances of this field may be defaulted, in others it may be required.
  27635. maxLength: 253
  27636. minLength: 1
  27637. pattern: ^[-._a-zA-Z0-9]+$
  27638. type: string
  27639. name:
  27640. description: The name of the Secret resource being referred to.
  27641. maxLength: 253
  27642. minLength: 1
  27643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27644. type: string
  27645. namespace:
  27646. description: |-
  27647. The namespace of the Secret resource being referred to.
  27648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27649. maxLength: 63
  27650. minLength: 1
  27651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27652. type: string
  27653. type: object
  27654. secretAccessKeySecretRef:
  27655. description: The SecretAccessKey is used for authentication
  27656. properties:
  27657. key:
  27658. description: |-
  27659. A key in the referenced Secret.
  27660. Some instances of this field may be defaulted, in others it may be required.
  27661. maxLength: 253
  27662. minLength: 1
  27663. pattern: ^[-._a-zA-Z0-9]+$
  27664. type: string
  27665. name:
  27666. description: The name of the Secret resource being referred to.
  27667. maxLength: 253
  27668. minLength: 1
  27669. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27670. type: string
  27671. namespace:
  27672. description: |-
  27673. The namespace of the Secret resource being referred to.
  27674. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27675. maxLength: 63
  27676. minLength: 1
  27677. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27678. type: string
  27679. type: object
  27680. sessionTokenSecretRef:
  27681. description: |-
  27682. The SessionToken used for authentication
  27683. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  27684. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  27685. properties:
  27686. key:
  27687. description: |-
  27688. A key in the referenced Secret.
  27689. Some instances of this field may be defaulted, in others it may be required.
  27690. maxLength: 253
  27691. minLength: 1
  27692. pattern: ^[-._a-zA-Z0-9]+$
  27693. type: string
  27694. name:
  27695. description: The name of the Secret resource being referred to.
  27696. maxLength: 253
  27697. minLength: 1
  27698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27699. type: string
  27700. namespace:
  27701. description: |-
  27702. The namespace of the Secret resource being referred to.
  27703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27704. maxLength: 63
  27705. minLength: 1
  27706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27707. type: string
  27708. type: object
  27709. type: object
  27710. type: object
  27711. region:
  27712. description: Region specifies the region to operate in.
  27713. type: string
  27714. role:
  27715. description: |-
  27716. You can assume a role before making calls to the
  27717. desired AWS service.
  27718. type: string
  27719. scope:
  27720. description: |-
  27721. Scope specifies the ECR service scope.
  27722. Valid options are private and public.
  27723. type: string
  27724. required:
  27725. - region
  27726. type: object
  27727. fakeSpec:
  27728. description: FakeSpec contains the static data.
  27729. properties:
  27730. controller:
  27731. description: |-
  27732. Used to select the correct ESO controller (think: ingress.ingressClassName)
  27733. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  27734. type: string
  27735. data:
  27736. additionalProperties:
  27737. type: string
  27738. description: |-
  27739. Data defines the static data returned
  27740. by this generator.
  27741. type: object
  27742. type: object
  27743. gcrAccessTokenSpec:
  27744. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  27745. properties:
  27746. auth:
  27747. description: Auth defines the means for authenticating with GCP
  27748. properties:
  27749. secretRef:
  27750. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  27751. properties:
  27752. secretAccessKeySecretRef:
  27753. description: The SecretAccessKey is used for authentication
  27754. properties:
  27755. key:
  27756. description: |-
  27757. A key in the referenced Secret.
  27758. Some instances of this field may be defaulted, in others it may be required.
  27759. maxLength: 253
  27760. minLength: 1
  27761. pattern: ^[-._a-zA-Z0-9]+$
  27762. type: string
  27763. name:
  27764. description: The name of the Secret resource being referred to.
  27765. maxLength: 253
  27766. minLength: 1
  27767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27768. type: string
  27769. namespace:
  27770. description: |-
  27771. The namespace of the Secret resource being referred to.
  27772. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27773. maxLength: 63
  27774. minLength: 1
  27775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27776. type: string
  27777. type: object
  27778. type: object
  27779. workloadIdentity:
  27780. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  27781. properties:
  27782. clusterLocation:
  27783. type: string
  27784. clusterName:
  27785. type: string
  27786. clusterProjectID:
  27787. type: string
  27788. serviceAccountRef:
  27789. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  27790. properties:
  27791. audiences:
  27792. description: |-
  27793. Audience specifies the `aud` claim for the service account token
  27794. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27795. then this audiences will be appended to the list
  27796. items:
  27797. type: string
  27798. type: array
  27799. name:
  27800. description: The name of the ServiceAccount resource being referred to.
  27801. maxLength: 253
  27802. minLength: 1
  27803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27804. type: string
  27805. namespace:
  27806. description: |-
  27807. Namespace of the resource being referred to.
  27808. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27809. maxLength: 63
  27810. minLength: 1
  27811. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27812. type: string
  27813. required:
  27814. - name
  27815. type: object
  27816. required:
  27817. - clusterLocation
  27818. - clusterName
  27819. - serviceAccountRef
  27820. type: object
  27821. workloadIdentityFederation:
  27822. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  27823. properties:
  27824. audience:
  27825. description: |-
  27826. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  27827. If specified, Audience found in the external account credential config will be overridden with the configured value.
  27828. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  27829. type: string
  27830. awsSecurityCredentials:
  27831. description: |-
  27832. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  27833. when using the AWS metadata server is not an option.
  27834. properties:
  27835. awsCredentialsSecretRef:
  27836. description: |-
  27837. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  27838. Secret should be created with below names for keys
  27839. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  27840. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  27841. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  27842. properties:
  27843. name:
  27844. description: name of the secret.
  27845. maxLength: 253
  27846. minLength: 1
  27847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27848. type: string
  27849. namespace:
  27850. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  27851. maxLength: 63
  27852. minLength: 1
  27853. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27854. type: string
  27855. required:
  27856. - name
  27857. type: object
  27858. region:
  27859. description: region is for configuring the AWS region to be used.
  27860. example: ap-south-1
  27861. maxLength: 50
  27862. minLength: 1
  27863. pattern: ^[a-z0-9-]+$
  27864. type: string
  27865. required:
  27866. - awsCredentialsSecretRef
  27867. - region
  27868. type: object
  27869. credConfig:
  27870. description: |-
  27871. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  27872. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  27873. serviceAccountRef must be used by providing operators service account details.
  27874. properties:
  27875. key:
  27876. description: key name holding the external account credential config.
  27877. maxLength: 253
  27878. minLength: 1
  27879. pattern: ^[-._a-zA-Z0-9]+$
  27880. type: string
  27881. name:
  27882. description: name of the configmap.
  27883. maxLength: 253
  27884. minLength: 1
  27885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27886. type: string
  27887. namespace:
  27888. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  27889. maxLength: 63
  27890. minLength: 1
  27891. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27892. type: string
  27893. required:
  27894. - key
  27895. - name
  27896. type: object
  27897. externalTokenEndpoint:
  27898. description: |-
  27899. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  27900. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  27901. URL is having the expected value.
  27902. type: string
  27903. gcpServiceAccountEmail:
  27904. description: |-
  27905. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  27906. after Workload Identity Federation. Use this to grant access through the service account's
  27907. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  27908. service_account_impersonation_url in the external account JSON from credConfig;
  27909. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  27910. on that ServiceAccount.
  27911. example: my-gsa@my-project.iam.gserviceaccount.com
  27912. minLength: 1
  27913. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  27914. type: string
  27915. serviceAccountRef:
  27916. description: |-
  27917. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  27918. when Kubernetes is configured as provider in workload identity pool.
  27919. properties:
  27920. audiences:
  27921. description: |-
  27922. Audience specifies the `aud` claim for the service account token
  27923. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  27924. then this audiences will be appended to the list
  27925. items:
  27926. type: string
  27927. type: array
  27928. name:
  27929. description: The name of the ServiceAccount resource being referred to.
  27930. maxLength: 253
  27931. minLength: 1
  27932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27933. type: string
  27934. namespace:
  27935. description: |-
  27936. Namespace of the resource being referred to.
  27937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27938. maxLength: 63
  27939. minLength: 1
  27940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27941. type: string
  27942. required:
  27943. - name
  27944. type: object
  27945. type: object
  27946. type: object
  27947. projectID:
  27948. description: ProjectID defines which project to use to authenticate with
  27949. type: string
  27950. required:
  27951. - auth
  27952. - projectID
  27953. type: object
  27954. githubAccessTokenSpec:
  27955. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  27956. properties:
  27957. appID:
  27958. type: string
  27959. auth:
  27960. description: Auth configures how ESO authenticates with a Github instance.
  27961. properties:
  27962. privateKey:
  27963. description: GithubSecretRef references a secret containing GitHub credentials.
  27964. properties:
  27965. secretRef:
  27966. description: |-
  27967. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  27968. In some instances, `key` is a required field.
  27969. properties:
  27970. key:
  27971. description: |-
  27972. A key in the referenced Secret.
  27973. Some instances of this field may be defaulted, in others it may be required.
  27974. maxLength: 253
  27975. minLength: 1
  27976. pattern: ^[-._a-zA-Z0-9]+$
  27977. type: string
  27978. name:
  27979. description: The name of the Secret resource being referred to.
  27980. maxLength: 253
  27981. minLength: 1
  27982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  27983. type: string
  27984. namespace:
  27985. description: |-
  27986. The namespace of the Secret resource being referred to.
  27987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  27988. maxLength: 63
  27989. minLength: 1
  27990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  27991. type: string
  27992. type: object
  27993. required:
  27994. - secretRef
  27995. type: object
  27996. required:
  27997. - privateKey
  27998. type: object
  27999. installID:
  28000. type: string
  28001. permissions:
  28002. additionalProperties:
  28003. type: string
  28004. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  28005. type: object
  28006. repositories:
  28007. description: |-
  28008. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  28009. is installed to.
  28010. items:
  28011. type: string
  28012. type: array
  28013. url:
  28014. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  28015. type: string
  28016. required:
  28017. - appID
  28018. - auth
  28019. - installID
  28020. type: object
  28021. gitlabDeployTokenSpec:
  28022. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  28023. properties:
  28024. auth:
  28025. description: Auth configures how ESO authenticates with the GitLab API.
  28026. properties:
  28027. token:
  28028. description: |-
  28029. Token references a secret containing a GitLab access token (personal, group, or
  28030. project) with the api scope and at least the Maintainer role on the target.
  28031. properties:
  28032. secretRef:
  28033. description: |-
  28034. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  28035. In some instances, `key` is a required field.
  28036. properties:
  28037. key:
  28038. description: |-
  28039. A key in the referenced Secret.
  28040. Some instances of this field may be defaulted, in others it may be required.
  28041. maxLength: 253
  28042. minLength: 1
  28043. pattern: ^[-._a-zA-Z0-9]+$
  28044. type: string
  28045. name:
  28046. description: The name of the Secret resource being referred to.
  28047. maxLength: 253
  28048. minLength: 1
  28049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28050. type: string
  28051. namespace:
  28052. description: |-
  28053. The namespace of the Secret resource being referred to.
  28054. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28055. maxLength: 63
  28056. minLength: 1
  28057. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28058. type: string
  28059. type: object
  28060. required:
  28061. - secretRef
  28062. type: object
  28063. required:
  28064. - token
  28065. type: object
  28066. expiresAt:
  28067. description: |-
  28068. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  28069. not expire on the GitLab side and is revoked only when the generator state is
  28070. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  28071. format: date-time
  28072. type: string
  28073. groupID:
  28074. description: |-
  28075. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  28076. create the deploy token in. The generator URL-escapes paths before calling the
  28077. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  28078. minLength: 1
  28079. type: string
  28080. name:
  28081. description: Name of the deploy token.
  28082. minLength: 1
  28083. type: string
  28084. projectID:
  28085. description: |-
  28086. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  28087. project to create the deploy token in. The generator URL-escapes paths before
  28088. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  28089. minLength: 1
  28090. type: string
  28091. scopes:
  28092. description: Scopes granted to the deploy token. At least one scope is required.
  28093. items:
  28094. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  28095. enum:
  28096. - read_repository
  28097. - read_registry
  28098. - write_registry
  28099. - read_package_registry
  28100. - write_package_registry
  28101. - read_virtual_registry
  28102. - write_virtual_registry
  28103. type: string
  28104. minItems: 1
  28105. type: array
  28106. url:
  28107. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  28108. type: string
  28109. username:
  28110. description: |-
  28111. Username is an optional username for the deploy token. GitLab defaults it to
  28112. gitlab+deploy-token-{n} when omitted.
  28113. type: string
  28114. required:
  28115. - auth
  28116. - name
  28117. - scopes
  28118. type: object
  28119. x-kubernetes-validations:
  28120. - message: exactly one of projectID or groupID must be set
  28121. rule: has(self.projectID) != has(self.groupID)
  28122. grafanaSpec:
  28123. description: GrafanaSpec controls the behavior of the grafana generator.
  28124. properties:
  28125. auth:
  28126. description: |-
  28127. Auth is the authentication configuration to authenticate
  28128. against the Grafana instance.
  28129. properties:
  28130. basic:
  28131. description: |-
  28132. Basic auth credentials used to authenticate against the Grafana instance.
  28133. Note: you need a token which has elevated permissions to create service accounts.
  28134. See here for the documentation on basic roles offered by Grafana:
  28135. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28136. properties:
  28137. password:
  28138. description: A basic auth password used to authenticate against the Grafana instance.
  28139. properties:
  28140. key:
  28141. description: The key where the token is found.
  28142. maxLength: 253
  28143. minLength: 1
  28144. pattern: ^[-._a-zA-Z0-9]+$
  28145. type: string
  28146. name:
  28147. description: The name of the Secret resource being referred to.
  28148. maxLength: 253
  28149. minLength: 1
  28150. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28151. type: string
  28152. type: object
  28153. username:
  28154. description: A basic auth username used to authenticate against the Grafana instance.
  28155. type: string
  28156. required:
  28157. - password
  28158. - username
  28159. type: object
  28160. token:
  28161. description: |-
  28162. A service account token used to authenticate against the Grafana instance.
  28163. Note: you need a token which has elevated permissions to create service accounts.
  28164. See here for the documentation on basic roles offered by Grafana:
  28165. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28166. properties:
  28167. key:
  28168. description: The key where the token is found.
  28169. maxLength: 253
  28170. minLength: 1
  28171. pattern: ^[-._a-zA-Z0-9]+$
  28172. type: string
  28173. name:
  28174. description: The name of the Secret resource being referred to.
  28175. maxLength: 253
  28176. minLength: 1
  28177. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28178. type: string
  28179. type: object
  28180. type: object
  28181. serviceAccount:
  28182. description: |-
  28183. ServiceAccount is the configuration for the service account that
  28184. is supposed to be generated by the generator.
  28185. properties:
  28186. name:
  28187. description: Name is the name of the service account that will be created by ESO.
  28188. type: string
  28189. role:
  28190. description: |-
  28191. Role is the role of the service account.
  28192. See here for the documentation on basic roles offered by Grafana:
  28193. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  28194. type: string
  28195. secondsToLive:
  28196. description: |-
  28197. SecondsToLive is the number of seconds before the generated service account token will expire.
  28198. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  28199. format: int64
  28200. minimum: 1
  28201. type: integer
  28202. required:
  28203. - name
  28204. - role
  28205. type: object
  28206. url:
  28207. description: URL is the URL of the Grafana instance.
  28208. type: string
  28209. required:
  28210. - auth
  28211. - serviceAccount
  28212. - url
  28213. type: object
  28214. mfaSpec:
  28215. description: MFASpec controls the behavior of the mfa generator.
  28216. properties:
  28217. algorithm:
  28218. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  28219. type: string
  28220. length:
  28221. description: Length defines the token length. Defaults to 6 characters.
  28222. type: integer
  28223. secret:
  28224. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  28225. properties:
  28226. key:
  28227. description: |-
  28228. A key in the referenced Secret.
  28229. Some instances of this field may be defaulted, in others it may be required.
  28230. maxLength: 253
  28231. minLength: 1
  28232. pattern: ^[-._a-zA-Z0-9]+$
  28233. type: string
  28234. name:
  28235. description: The name of the Secret resource being referred to.
  28236. maxLength: 253
  28237. minLength: 1
  28238. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28239. type: string
  28240. namespace:
  28241. description: |-
  28242. The namespace of the Secret resource being referred to.
  28243. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28244. maxLength: 63
  28245. minLength: 1
  28246. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28247. type: string
  28248. type: object
  28249. timePeriod:
  28250. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  28251. type: integer
  28252. when:
  28253. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  28254. format: date-time
  28255. type: string
  28256. required:
  28257. - secret
  28258. type: object
  28259. passwordSpec:
  28260. description: PasswordSpec controls the behavior of the password generator.
  28261. properties:
  28262. allowRepeat:
  28263. default: false
  28264. description: set AllowRepeat to true to allow repeating characters.
  28265. type: boolean
  28266. digits:
  28267. description: |-
  28268. Digits specifies the number of digits in the generated
  28269. password. If omitted it defaults to 25% of the length of the password
  28270. type: integer
  28271. encoding:
  28272. default: raw
  28273. description: |-
  28274. Encoding specifies the encoding of the generated password.
  28275. Valid values are:
  28276. - "raw" (default): no encoding
  28277. - "base64": standard base64 encoding
  28278. - "base64url": base64url encoding
  28279. - "base32": base32 encoding
  28280. - "hex": hexadecimal encoding
  28281. enum:
  28282. - base64
  28283. - base64url
  28284. - base32
  28285. - hex
  28286. - raw
  28287. type: string
  28288. length:
  28289. default: 24
  28290. description: |-
  28291. Length of the password to be generated.
  28292. Defaults to 24
  28293. type: integer
  28294. noUpper:
  28295. default: false
  28296. description: Set NoUpper to disable uppercase characters
  28297. type: boolean
  28298. secretKeys:
  28299. description: |-
  28300. SecretKeys defines the keys that will be populated with generated passwords.
  28301. Defaults to "password" when not set.
  28302. items:
  28303. type: string
  28304. minItems: 1
  28305. type: array
  28306. symbolCharacters:
  28307. description: |-
  28308. SymbolCharacters specifies the special characters that should be used
  28309. in the generated password.
  28310. type: string
  28311. symbols:
  28312. description: |-
  28313. Symbols specifies the number of symbol characters in the generated
  28314. password. If omitted it defaults to 25% of the length of the password
  28315. type: integer
  28316. required:
  28317. - allowRepeat
  28318. - length
  28319. - noUpper
  28320. type: object
  28321. quayAccessTokenSpec:
  28322. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  28323. properties:
  28324. robotAccount:
  28325. description: Name of the robot account you are federating with
  28326. type: string
  28327. serviceAccountRef:
  28328. description: Name of the service account you are federating with
  28329. properties:
  28330. audiences:
  28331. description: |-
  28332. Audience specifies the `aud` claim for the service account token
  28333. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28334. then this audiences will be appended to the list
  28335. items:
  28336. type: string
  28337. type: array
  28338. name:
  28339. description: The name of the ServiceAccount resource being referred to.
  28340. maxLength: 253
  28341. minLength: 1
  28342. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28343. type: string
  28344. namespace:
  28345. description: |-
  28346. Namespace of the resource being referred to.
  28347. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28348. maxLength: 63
  28349. minLength: 1
  28350. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28351. type: string
  28352. required:
  28353. - name
  28354. type: object
  28355. url:
  28356. description: URL configures the Quay instance URL. Defaults to quay.io.
  28357. type: string
  28358. required:
  28359. - robotAccount
  28360. - serviceAccountRef
  28361. type: object
  28362. sshKeySpec:
  28363. description: SSHKeySpec controls the behavior of the ssh key generator.
  28364. properties:
  28365. comment:
  28366. description: Comment specifies an optional comment for the SSH key
  28367. type: string
  28368. keySize:
  28369. description: |-
  28370. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  28371. For RSA keys: 2048, 3072, 4096
  28372. For ECDSA keys: 256, 384, 521
  28373. Ignored for ed25519 keys
  28374. maximum: 8192
  28375. minimum: 256
  28376. type: integer
  28377. keyType:
  28378. default: rsa
  28379. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  28380. enum:
  28381. - rsa
  28382. - ecdsa
  28383. - ed25519
  28384. type: string
  28385. type: object
  28386. stsSessionTokenSpec:
  28387. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  28388. properties:
  28389. auth:
  28390. description: Auth defines how to authenticate with AWS
  28391. properties:
  28392. jwt:
  28393. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  28394. properties:
  28395. serviceAccountRef:
  28396. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28397. properties:
  28398. audiences:
  28399. description: |-
  28400. Audience specifies the `aud` claim for the service account token
  28401. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28402. then this audiences will be appended to the list
  28403. items:
  28404. type: string
  28405. type: array
  28406. name:
  28407. description: The name of the ServiceAccount resource being referred to.
  28408. maxLength: 253
  28409. minLength: 1
  28410. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28411. type: string
  28412. namespace:
  28413. description: |-
  28414. Namespace of the resource being referred to.
  28415. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28416. maxLength: 63
  28417. minLength: 1
  28418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28419. type: string
  28420. required:
  28421. - name
  28422. type: object
  28423. type: object
  28424. secretRef:
  28425. description: |-
  28426. AWSAuthSecretRef holds secret references for AWS credentials
  28427. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  28428. properties:
  28429. accessKeyIDSecretRef:
  28430. description: The AccessKeyID is used for authentication
  28431. properties:
  28432. key:
  28433. description: |-
  28434. A key in the referenced Secret.
  28435. Some instances of this field may be defaulted, in others it may be required.
  28436. maxLength: 253
  28437. minLength: 1
  28438. pattern: ^[-._a-zA-Z0-9]+$
  28439. type: string
  28440. name:
  28441. description: The name of the Secret resource being referred to.
  28442. maxLength: 253
  28443. minLength: 1
  28444. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28445. type: string
  28446. namespace:
  28447. description: |-
  28448. The namespace of the Secret resource being referred to.
  28449. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28450. maxLength: 63
  28451. minLength: 1
  28452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28453. type: string
  28454. type: object
  28455. secretAccessKeySecretRef:
  28456. description: The SecretAccessKey is used for authentication
  28457. properties:
  28458. key:
  28459. description: |-
  28460. A key in the referenced Secret.
  28461. Some instances of this field may be defaulted, in others it may be required.
  28462. maxLength: 253
  28463. minLength: 1
  28464. pattern: ^[-._a-zA-Z0-9]+$
  28465. type: string
  28466. name:
  28467. description: The name of the Secret resource being referred to.
  28468. maxLength: 253
  28469. minLength: 1
  28470. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28471. type: string
  28472. namespace:
  28473. description: |-
  28474. The namespace of the Secret resource being referred to.
  28475. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28476. maxLength: 63
  28477. minLength: 1
  28478. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28479. type: string
  28480. type: object
  28481. sessionTokenSecretRef:
  28482. description: |-
  28483. The SessionToken used for authentication
  28484. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28485. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28486. properties:
  28487. key:
  28488. description: |-
  28489. A key in the referenced Secret.
  28490. Some instances of this field may be defaulted, in others it may be required.
  28491. maxLength: 253
  28492. minLength: 1
  28493. pattern: ^[-._a-zA-Z0-9]+$
  28494. type: string
  28495. name:
  28496. description: The name of the Secret resource being referred to.
  28497. maxLength: 253
  28498. minLength: 1
  28499. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28500. type: string
  28501. namespace:
  28502. description: |-
  28503. The namespace of the Secret resource being referred to.
  28504. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28505. maxLength: 63
  28506. minLength: 1
  28507. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28508. type: string
  28509. type: object
  28510. type: object
  28511. type: object
  28512. region:
  28513. description: Region specifies the region to operate in.
  28514. type: string
  28515. requestParameters:
  28516. description: RequestParameters contains parameters that can be passed to the STS service.
  28517. properties:
  28518. serialNumber:
  28519. description: |-
  28520. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  28521. the GetSessionToken call.
  28522. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  28523. (such as arn:aws:iam::123456789012:mfa/user)
  28524. type: string
  28525. sessionDuration:
  28526. format: int32
  28527. type: integer
  28528. tokenCode:
  28529. description: TokenCode is the value provided by the MFA device, if MFA is required.
  28530. type: string
  28531. type: object
  28532. role:
  28533. description: |-
  28534. You can assume a role before making calls to the
  28535. desired AWS service.
  28536. type: string
  28537. required:
  28538. - region
  28539. type: object
  28540. uuidSpec:
  28541. description: UUIDSpec controls the behavior of the uuid generator.
  28542. type: object
  28543. vaultDynamicSecretSpec:
  28544. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  28545. properties:
  28546. allowEmptyResponse:
  28547. default: false
  28548. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  28549. type: boolean
  28550. controller:
  28551. description: |-
  28552. Used to select the correct ESO controller (think: ingress.ingressClassName)
  28553. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  28554. type: string
  28555. getParameters:
  28556. additionalProperties:
  28557. items:
  28558. type: string
  28559. type: array
  28560. description: |-
  28561. GetParameters are query-string parameters passed to Vault on GET calls.
  28562. Each key may map to multiple values, matching HTTP query-string semantics.
  28563. Ignored for non-GET methods; use Parameters for write bodies.
  28564. type: object
  28565. method:
  28566. description: Vault API method to use (GET/POST/other)
  28567. type: string
  28568. parameters:
  28569. description: Parameters to pass to Vault write (for non-GET methods)
  28570. x-kubernetes-preserve-unknown-fields: true
  28571. path:
  28572. description: Vault path to obtain the dynamic secret from
  28573. type: string
  28574. provider:
  28575. description: Vault provider common spec
  28576. properties:
  28577. auth:
  28578. description: Auth configures how secret-manager authenticates with the Vault server.
  28579. properties:
  28580. appRole:
  28581. description: |-
  28582. AppRole authenticates with Vault using the App Role auth mechanism,
  28583. with the role and secret stored in a Kubernetes Secret resource.
  28584. properties:
  28585. path:
  28586. default: approle
  28587. description: |-
  28588. Path where the App Role authentication backend is mounted
  28589. in Vault, e.g: "approle"
  28590. type: string
  28591. roleId:
  28592. description: |-
  28593. RoleID configured in the App Role authentication backend when setting
  28594. up the authentication backend in Vault.
  28595. type: string
  28596. roleRef:
  28597. description: |-
  28598. Reference to a key in a Secret that contains the App Role ID used
  28599. to authenticate with Vault.
  28600. The `key` field must be specified and denotes which entry within the Secret
  28601. resource is used as the app role id.
  28602. properties:
  28603. key:
  28604. description: |-
  28605. A key in the referenced Secret.
  28606. Some instances of this field may be defaulted, in others it may be required.
  28607. maxLength: 253
  28608. minLength: 1
  28609. pattern: ^[-._a-zA-Z0-9]+$
  28610. type: string
  28611. name:
  28612. description: The name of the Secret resource being referred to.
  28613. maxLength: 253
  28614. minLength: 1
  28615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28616. type: string
  28617. namespace:
  28618. description: |-
  28619. The namespace of the Secret resource being referred to.
  28620. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28621. maxLength: 63
  28622. minLength: 1
  28623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28624. type: string
  28625. type: object
  28626. secretRef:
  28627. description: |-
  28628. Reference to a key in a Secret that contains the App Role secret used
  28629. to authenticate with Vault.
  28630. The `key` field must be specified and denotes which entry within the Secret
  28631. resource is used as the app role secret.
  28632. properties:
  28633. key:
  28634. description: |-
  28635. A key in the referenced Secret.
  28636. Some instances of this field may be defaulted, in others it may be required.
  28637. maxLength: 253
  28638. minLength: 1
  28639. pattern: ^[-._a-zA-Z0-9]+$
  28640. type: string
  28641. name:
  28642. description: The name of the Secret resource being referred to.
  28643. maxLength: 253
  28644. minLength: 1
  28645. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28646. type: string
  28647. namespace:
  28648. description: |-
  28649. The namespace of the Secret resource being referred to.
  28650. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28651. maxLength: 63
  28652. minLength: 1
  28653. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28654. type: string
  28655. type: object
  28656. required:
  28657. - path
  28658. - secretRef
  28659. type: object
  28660. cert:
  28661. description: |-
  28662. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  28663. Cert authentication method
  28664. properties:
  28665. clientCert:
  28666. description: |-
  28667. ClientCert is a certificate to authenticate using the Cert Vault
  28668. authentication method
  28669. properties:
  28670. key:
  28671. description: |-
  28672. A key in the referenced Secret.
  28673. Some instances of this field may be defaulted, in others it may be required.
  28674. maxLength: 253
  28675. minLength: 1
  28676. pattern: ^[-._a-zA-Z0-9]+$
  28677. type: string
  28678. name:
  28679. description: The name of the Secret resource being referred to.
  28680. maxLength: 253
  28681. minLength: 1
  28682. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28683. type: string
  28684. namespace:
  28685. description: |-
  28686. The namespace of the Secret resource being referred to.
  28687. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28688. maxLength: 63
  28689. minLength: 1
  28690. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28691. type: string
  28692. type: object
  28693. path:
  28694. default: cert
  28695. description: |-
  28696. Path where the Certificate authentication backend is mounted
  28697. in Vault, e.g: "cert"
  28698. type: string
  28699. secretRef:
  28700. description: |-
  28701. SecretRef to a key in a Secret resource containing client private key to
  28702. authenticate with Vault using the Cert authentication method
  28703. properties:
  28704. key:
  28705. description: |-
  28706. A key in the referenced Secret.
  28707. Some instances of this field may be defaulted, in others it may be required.
  28708. maxLength: 253
  28709. minLength: 1
  28710. pattern: ^[-._a-zA-Z0-9]+$
  28711. type: string
  28712. name:
  28713. description: The name of the Secret resource being referred to.
  28714. maxLength: 253
  28715. minLength: 1
  28716. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28717. type: string
  28718. namespace:
  28719. description: |-
  28720. The namespace of the Secret resource being referred to.
  28721. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28722. maxLength: 63
  28723. minLength: 1
  28724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28725. type: string
  28726. type: object
  28727. vaultRole:
  28728. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  28729. type: string
  28730. type: object
  28731. gcp:
  28732. description: |-
  28733. Gcp authenticates with Vault using Google Cloud Platform authentication method
  28734. GCP authentication method
  28735. properties:
  28736. location:
  28737. description: Location optionally defines a location/region for the secret
  28738. type: string
  28739. path:
  28740. default: gcp
  28741. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  28742. type: string
  28743. projectID:
  28744. description: Project ID of the Google Cloud Platform project
  28745. type: string
  28746. role:
  28747. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  28748. type: string
  28749. secretRef:
  28750. description: Specify credentials in a Secret object
  28751. properties:
  28752. secretAccessKeySecretRef:
  28753. description: The SecretAccessKey is used for authentication
  28754. properties:
  28755. key:
  28756. description: |-
  28757. A key in the referenced Secret.
  28758. Some instances of this field may be defaulted, in others it may be required.
  28759. maxLength: 253
  28760. minLength: 1
  28761. pattern: ^[-._a-zA-Z0-9]+$
  28762. type: string
  28763. name:
  28764. description: The name of the Secret resource being referred to.
  28765. maxLength: 253
  28766. minLength: 1
  28767. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28768. type: string
  28769. namespace:
  28770. description: |-
  28771. The namespace of the Secret resource being referred to.
  28772. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28773. maxLength: 63
  28774. minLength: 1
  28775. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28776. type: string
  28777. type: object
  28778. type: object
  28779. serviceAccountRef:
  28780. description: ServiceAccountRef to a service account for impersonation
  28781. properties:
  28782. audiences:
  28783. description: |-
  28784. Audience specifies the `aud` claim for the service account token
  28785. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28786. then this audiences will be appended to the list
  28787. items:
  28788. type: string
  28789. type: array
  28790. name:
  28791. description: The name of the ServiceAccount resource being referred to.
  28792. maxLength: 253
  28793. minLength: 1
  28794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28795. type: string
  28796. namespace:
  28797. description: |-
  28798. Namespace of the resource being referred to.
  28799. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28800. maxLength: 63
  28801. minLength: 1
  28802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28803. type: string
  28804. required:
  28805. - name
  28806. type: object
  28807. workloadIdentity:
  28808. description: Specify a service account with Workload Identity
  28809. properties:
  28810. clusterLocation:
  28811. description: |-
  28812. ClusterLocation is the location of the cluster
  28813. If not specified, it fetches information from the metadata server
  28814. type: string
  28815. clusterName:
  28816. description: |-
  28817. ClusterName is the name of the cluster
  28818. If not specified, it fetches information from the metadata server
  28819. type: string
  28820. clusterProjectID:
  28821. description: |-
  28822. ClusterProjectID is the project ID of the cluster
  28823. If not specified, it fetches information from the metadata server
  28824. type: string
  28825. serviceAccountRef:
  28826. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28827. properties:
  28828. audiences:
  28829. description: |-
  28830. Audience specifies the `aud` claim for the service account token
  28831. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28832. then this audiences will be appended to the list
  28833. items:
  28834. type: string
  28835. type: array
  28836. name:
  28837. description: The name of the ServiceAccount resource being referred to.
  28838. maxLength: 253
  28839. minLength: 1
  28840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28841. type: string
  28842. namespace:
  28843. description: |-
  28844. Namespace of the resource being referred to.
  28845. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28846. maxLength: 63
  28847. minLength: 1
  28848. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28849. type: string
  28850. required:
  28851. - name
  28852. type: object
  28853. required:
  28854. - serviceAccountRef
  28855. type: object
  28856. required:
  28857. - role
  28858. type: object
  28859. iam:
  28860. description: |-
  28861. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  28862. AWS IAM authentication method
  28863. properties:
  28864. externalID:
  28865. description: AWS External ID set on assumed IAM roles
  28866. type: string
  28867. jwt:
  28868. description: Specify a service account with IRSA enabled
  28869. properties:
  28870. serviceAccountRef:
  28871. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  28872. properties:
  28873. audiences:
  28874. description: |-
  28875. Audience specifies the `aud` claim for the service account token
  28876. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  28877. then this audiences will be appended to the list
  28878. items:
  28879. type: string
  28880. type: array
  28881. name:
  28882. description: The name of the ServiceAccount resource being referred to.
  28883. maxLength: 253
  28884. minLength: 1
  28885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28886. type: string
  28887. namespace:
  28888. description: |-
  28889. Namespace of the resource being referred to.
  28890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28891. maxLength: 63
  28892. minLength: 1
  28893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28894. type: string
  28895. required:
  28896. - name
  28897. type: object
  28898. type: object
  28899. path:
  28900. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  28901. type: string
  28902. region:
  28903. description: AWS region
  28904. type: string
  28905. role:
  28906. description: This is the AWS role to be assumed before talking to vault
  28907. type: string
  28908. secretRef:
  28909. description: Specify credentials in a Secret object
  28910. properties:
  28911. accessKeyIDSecretRef:
  28912. description: The AccessKeyID is used for authentication
  28913. properties:
  28914. key:
  28915. description: |-
  28916. A key in the referenced Secret.
  28917. Some instances of this field may be defaulted, in others it may be required.
  28918. maxLength: 253
  28919. minLength: 1
  28920. pattern: ^[-._a-zA-Z0-9]+$
  28921. type: string
  28922. name:
  28923. description: The name of the Secret resource being referred to.
  28924. maxLength: 253
  28925. minLength: 1
  28926. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28927. type: string
  28928. namespace:
  28929. description: |-
  28930. The namespace of the Secret resource being referred to.
  28931. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28932. maxLength: 63
  28933. minLength: 1
  28934. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28935. type: string
  28936. type: object
  28937. secretAccessKeySecretRef:
  28938. description: The SecretAccessKey is used for authentication
  28939. properties:
  28940. key:
  28941. description: |-
  28942. A key in the referenced Secret.
  28943. Some instances of this field may be defaulted, in others it may be required.
  28944. maxLength: 253
  28945. minLength: 1
  28946. pattern: ^[-._a-zA-Z0-9]+$
  28947. type: string
  28948. name:
  28949. description: The name of the Secret resource being referred to.
  28950. maxLength: 253
  28951. minLength: 1
  28952. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28953. type: string
  28954. namespace:
  28955. description: |-
  28956. The namespace of the Secret resource being referred to.
  28957. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28958. maxLength: 63
  28959. minLength: 1
  28960. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28961. type: string
  28962. type: object
  28963. sessionTokenSecretRef:
  28964. description: |-
  28965. The SessionToken used for authentication
  28966. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  28967. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  28968. properties:
  28969. key:
  28970. description: |-
  28971. A key in the referenced Secret.
  28972. Some instances of this field may be defaulted, in others it may be required.
  28973. maxLength: 253
  28974. minLength: 1
  28975. pattern: ^[-._a-zA-Z0-9]+$
  28976. type: string
  28977. name:
  28978. description: The name of the Secret resource being referred to.
  28979. maxLength: 253
  28980. minLength: 1
  28981. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  28982. type: string
  28983. namespace:
  28984. description: |-
  28985. The namespace of the Secret resource being referred to.
  28986. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  28987. maxLength: 63
  28988. minLength: 1
  28989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  28990. type: string
  28991. type: object
  28992. type: object
  28993. vaultAwsIamServerID:
  28994. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  28995. type: string
  28996. vaultRole:
  28997. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  28998. type: string
  28999. required:
  29000. - vaultRole
  29001. type: object
  29002. jwt:
  29003. description: |-
  29004. Jwt authenticates with Vault by passing role and JWT token using the
  29005. JWT/OIDC authentication method
  29006. properties:
  29007. kubernetesServiceAccountToken:
  29008. description: |-
  29009. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  29010. a token for with the `TokenRequest` API.
  29011. properties:
  29012. audiences:
  29013. description: |-
  29014. Optional audiences field that will be used to request a temporary Kubernetes service
  29015. account token for the service account referenced by `serviceAccountRef`.
  29016. Defaults to a single audience `vault` it not specified.
  29017. Deprecated: use serviceAccountRef.Audiences instead
  29018. items:
  29019. type: string
  29020. type: array
  29021. expirationSeconds:
  29022. description: |-
  29023. Optional expiration time in seconds that will be used to request a temporary
  29024. Kubernetes service account token for the service account referenced by
  29025. `serviceAccountRef`.
  29026. Deprecated: this will be removed in the future.
  29027. Defaults to 10 minutes.
  29028. format: int64
  29029. type: integer
  29030. serviceAccountRef:
  29031. description: Service account field containing the name of a kubernetes ServiceAccount.
  29032. properties:
  29033. audiences:
  29034. description: |-
  29035. Audience specifies the `aud` claim for the service account token
  29036. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29037. then this audiences will be appended to the list
  29038. items:
  29039. type: string
  29040. type: array
  29041. name:
  29042. description: The name of the ServiceAccount resource being referred to.
  29043. maxLength: 253
  29044. minLength: 1
  29045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29046. type: string
  29047. namespace:
  29048. description: |-
  29049. Namespace of the resource being referred to.
  29050. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29051. maxLength: 63
  29052. minLength: 1
  29053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29054. type: string
  29055. required:
  29056. - name
  29057. type: object
  29058. required:
  29059. - serviceAccountRef
  29060. type: object
  29061. path:
  29062. default: jwt
  29063. description: |-
  29064. Path where the JWT authentication backend is mounted
  29065. in Vault, e.g: "jwt"
  29066. type: string
  29067. role:
  29068. description: |-
  29069. Role is a JWT role to authenticate using the JWT/OIDC Vault
  29070. authentication method
  29071. type: string
  29072. secretRef:
  29073. description: |-
  29074. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  29075. authenticate with Vault using the JWT/OIDC authentication method.
  29076. properties:
  29077. key:
  29078. description: |-
  29079. A key in the referenced Secret.
  29080. Some instances of this field may be defaulted, in others it may be required.
  29081. maxLength: 253
  29082. minLength: 1
  29083. pattern: ^[-._a-zA-Z0-9]+$
  29084. type: string
  29085. name:
  29086. description: The name of the Secret resource being referred to.
  29087. maxLength: 253
  29088. minLength: 1
  29089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29090. type: string
  29091. namespace:
  29092. description: |-
  29093. The namespace of the Secret resource being referred to.
  29094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29095. maxLength: 63
  29096. minLength: 1
  29097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29098. type: string
  29099. type: object
  29100. required:
  29101. - path
  29102. type: object
  29103. kubernetes:
  29104. description: |-
  29105. Kubernetes authenticates with Vault by passing the ServiceAccount
  29106. token stored in the named Secret resource to the Vault server.
  29107. properties:
  29108. mountPath:
  29109. default: kubernetes
  29110. description: |-
  29111. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  29112. "kubernetes"
  29113. type: string
  29114. role:
  29115. description: |-
  29116. A required field containing the Vault Role to assume. A Role binds a
  29117. Kubernetes ServiceAccount with a set of Vault policies.
  29118. type: string
  29119. secretRef:
  29120. description: |-
  29121. Optional secret field containing a Kubernetes ServiceAccount JWT used
  29122. for authenticating with Vault. If a name is specified without a key,
  29123. `token` is the default. If one is not specified, the one bound to
  29124. the controller will be used.
  29125. properties:
  29126. key:
  29127. description: |-
  29128. A key in the referenced Secret.
  29129. Some instances of this field may be defaulted, in others it may be required.
  29130. maxLength: 253
  29131. minLength: 1
  29132. pattern: ^[-._a-zA-Z0-9]+$
  29133. type: string
  29134. name:
  29135. description: The name of the Secret resource being referred to.
  29136. maxLength: 253
  29137. minLength: 1
  29138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29139. type: string
  29140. namespace:
  29141. description: |-
  29142. The namespace of the Secret resource being referred to.
  29143. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29144. maxLength: 63
  29145. minLength: 1
  29146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29147. type: string
  29148. type: object
  29149. serviceAccountRef:
  29150. description: |-
  29151. Optional service account field containing the name of a kubernetes ServiceAccount.
  29152. If the service account is specified, the service account secret token JWT will be used
  29153. for authenticating with Vault. If the service account selector is not supplied,
  29154. the secretRef will be used instead.
  29155. properties:
  29156. audiences:
  29157. description: |-
  29158. Audience specifies the `aud` claim for the service account token
  29159. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29160. then this audiences will be appended to the list
  29161. items:
  29162. type: string
  29163. type: array
  29164. name:
  29165. description: The name of the ServiceAccount resource being referred to.
  29166. maxLength: 253
  29167. minLength: 1
  29168. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29169. type: string
  29170. namespace:
  29171. description: |-
  29172. Namespace of the resource being referred to.
  29173. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29174. maxLength: 63
  29175. minLength: 1
  29176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29177. type: string
  29178. required:
  29179. - name
  29180. type: object
  29181. required:
  29182. - mountPath
  29183. - role
  29184. type: object
  29185. ldap:
  29186. description: |-
  29187. Ldap authenticates with Vault by passing username/password pair using
  29188. the LDAP authentication method
  29189. properties:
  29190. path:
  29191. default: ldap
  29192. description: |-
  29193. Path where the LDAP authentication backend is mounted
  29194. in Vault, e.g: "ldap"
  29195. type: string
  29196. secretRef:
  29197. description: |-
  29198. SecretRef to a key in a Secret resource containing password for the LDAP
  29199. user used to authenticate with Vault using the LDAP authentication
  29200. method
  29201. properties:
  29202. key:
  29203. description: |-
  29204. A key in the referenced Secret.
  29205. Some instances of this field may be defaulted, in others it may be required.
  29206. maxLength: 253
  29207. minLength: 1
  29208. pattern: ^[-._a-zA-Z0-9]+$
  29209. type: string
  29210. name:
  29211. description: The name of the Secret resource being referred to.
  29212. maxLength: 253
  29213. minLength: 1
  29214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29215. type: string
  29216. namespace:
  29217. description: |-
  29218. The namespace of the Secret resource being referred to.
  29219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29220. maxLength: 63
  29221. minLength: 1
  29222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29223. type: string
  29224. type: object
  29225. username:
  29226. description: |-
  29227. Username is an LDAP username used to authenticate using the LDAP Vault
  29228. authentication method
  29229. type: string
  29230. required:
  29231. - path
  29232. - username
  29233. type: object
  29234. namespace:
  29235. description: |-
  29236. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  29237. Namespaces is a set of features within Vault Enterprise that allows
  29238. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29239. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29240. This will default to Vault.Namespace field if set, or empty otherwise
  29241. type: string
  29242. tokenSecretRef:
  29243. description: TokenSecretRef authenticates with Vault by presenting a token.
  29244. properties:
  29245. key:
  29246. description: |-
  29247. A key in the referenced Secret.
  29248. Some instances of this field may be defaulted, in others it may be required.
  29249. maxLength: 253
  29250. minLength: 1
  29251. pattern: ^[-._a-zA-Z0-9]+$
  29252. type: string
  29253. name:
  29254. description: The name of the Secret resource being referred to.
  29255. maxLength: 253
  29256. minLength: 1
  29257. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29258. type: string
  29259. namespace:
  29260. description: |-
  29261. The namespace of the Secret resource being referred to.
  29262. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29263. maxLength: 63
  29264. minLength: 1
  29265. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29266. type: string
  29267. type: object
  29268. userPass:
  29269. description: UserPass authenticates with Vault by passing username/password pair
  29270. properties:
  29271. path:
  29272. default: userpass
  29273. description: |-
  29274. Path where the UserPassword authentication backend is mounted
  29275. in Vault, e.g: "userpass"
  29276. type: string
  29277. secretRef:
  29278. description: |-
  29279. SecretRef to a key in a Secret resource containing password for the
  29280. user used to authenticate with Vault using the UserPass authentication
  29281. method
  29282. properties:
  29283. key:
  29284. description: |-
  29285. A key in the referenced Secret.
  29286. Some instances of this field may be defaulted, in others it may be required.
  29287. maxLength: 253
  29288. minLength: 1
  29289. pattern: ^[-._a-zA-Z0-9]+$
  29290. type: string
  29291. name:
  29292. description: The name of the Secret resource being referred to.
  29293. maxLength: 253
  29294. minLength: 1
  29295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29296. type: string
  29297. namespace:
  29298. description: |-
  29299. The namespace of the Secret resource being referred to.
  29300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29301. maxLength: 63
  29302. minLength: 1
  29303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29304. type: string
  29305. type: object
  29306. username:
  29307. description: |-
  29308. Username is a username used to authenticate using the UserPass Vault
  29309. authentication method
  29310. type: string
  29311. required:
  29312. - path
  29313. - username
  29314. type: object
  29315. type: object
  29316. caBundle:
  29317. description: |-
  29318. PEM encoded CA bundle used to validate Vault server certificate. Only used
  29319. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29320. plain HTTP protocol connection. If not set the system root certificates
  29321. are used to validate the TLS connection.
  29322. format: byte
  29323. type: string
  29324. caProvider:
  29325. description: The provider for the CA bundle to use to validate Vault server certificate.
  29326. properties:
  29327. key:
  29328. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29329. maxLength: 253
  29330. minLength: 1
  29331. pattern: ^[-._a-zA-Z0-9]+$
  29332. type: string
  29333. name:
  29334. description: The name of the object located at the provider type.
  29335. maxLength: 253
  29336. minLength: 1
  29337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29338. type: string
  29339. namespace:
  29340. description: |-
  29341. The namespace the Provider type is in.
  29342. Can only be defined when used in a ClusterSecretStore.
  29343. maxLength: 63
  29344. minLength: 1
  29345. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29346. type: string
  29347. type:
  29348. description: The type of provider to use such as "Secret", or "ConfigMap".
  29349. enum:
  29350. - Secret
  29351. - ConfigMap
  29352. type: string
  29353. required:
  29354. - name
  29355. - type
  29356. type: object
  29357. checkAndSet:
  29358. description: |-
  29359. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  29360. Only applies to Vault KV v2 stores. When enabled, write operations must include
  29361. the current version of the secret to prevent unintentional overwrites.
  29362. properties:
  29363. required:
  29364. description: |-
  29365. Required when true, all write operations must include a check-and-set parameter.
  29366. This helps prevent unintentional overwrites of secrets.
  29367. type: boolean
  29368. type: object
  29369. forwardInconsistent:
  29370. description: |-
  29371. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  29372. leader instead of simply retrying within a loop. This can increase performance if
  29373. the option is enabled serverside.
  29374. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  29375. type: boolean
  29376. headers:
  29377. additionalProperties:
  29378. type: string
  29379. description: Headers to be added in Vault request
  29380. type: object
  29381. namespace:
  29382. description: |-
  29383. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  29384. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  29385. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  29386. type: string
  29387. path:
  29388. description: |-
  29389. Path is the mount path of the Vault KV backend endpoint, e.g:
  29390. "secret". The v2 KV secret engine version specific "/data" path suffix
  29391. for fetching secrets from Vault is optional and will be appended
  29392. if not present in specified path.
  29393. type: string
  29394. readYourWrites:
  29395. description: |-
  29396. ReadYourWrites ensures isolated read-after-write semantics by
  29397. providing discovered cluster replication states in each request.
  29398. More information about eventual consistency in Vault can be found here
  29399. https://www.vaultproject.io/docs/enterprise/consistency
  29400. type: boolean
  29401. server:
  29402. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  29403. type: string
  29404. tls:
  29405. description: |-
  29406. The configuration used for client side related TLS communication, when the Vault server
  29407. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  29408. This parameter is ignored for plain HTTP protocol connection.
  29409. It's worth noting this configuration is different from the "TLS certificates auth method",
  29410. which is available under the `auth.cert` section.
  29411. properties:
  29412. certSecretRef:
  29413. description: |-
  29414. CertSecretRef is a certificate added to the transport layer
  29415. when communicating with the Vault server.
  29416. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  29417. properties:
  29418. key:
  29419. description: |-
  29420. A key in the referenced Secret.
  29421. Some instances of this field may be defaulted, in others it may be required.
  29422. maxLength: 253
  29423. minLength: 1
  29424. pattern: ^[-._a-zA-Z0-9]+$
  29425. type: string
  29426. name:
  29427. description: The name of the Secret resource being referred to.
  29428. maxLength: 253
  29429. minLength: 1
  29430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29431. type: string
  29432. namespace:
  29433. description: |-
  29434. The namespace of the Secret resource being referred to.
  29435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29436. maxLength: 63
  29437. minLength: 1
  29438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29439. type: string
  29440. type: object
  29441. keySecretRef:
  29442. description: |-
  29443. KeySecretRef to a key in a Secret resource containing client private key
  29444. added to the transport layer when communicating with the Vault server.
  29445. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  29446. properties:
  29447. key:
  29448. description: |-
  29449. A key in the referenced Secret.
  29450. Some instances of this field may be defaulted, in others it may be required.
  29451. maxLength: 253
  29452. minLength: 1
  29453. pattern: ^[-._a-zA-Z0-9]+$
  29454. type: string
  29455. name:
  29456. description: The name of the Secret resource being referred to.
  29457. maxLength: 253
  29458. minLength: 1
  29459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29460. type: string
  29461. namespace:
  29462. description: |-
  29463. The namespace of the Secret resource being referred to.
  29464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29465. maxLength: 63
  29466. minLength: 1
  29467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29468. type: string
  29469. type: object
  29470. type: object
  29471. version:
  29472. default: v2
  29473. description: |-
  29474. Version is the Vault KV secret engine version. This can be either "v1" or
  29475. "v2". Version defaults to "v2".
  29476. enum:
  29477. - v1
  29478. - v2
  29479. type: string
  29480. required:
  29481. - server
  29482. type: object
  29483. resultType:
  29484. default: Data
  29485. description: |-
  29486. Result type defines which data is returned from the generator.
  29487. By default, it is the "data" section of the Vault API response.
  29488. When using e.g. /auth/token/create the "data" section is empty but
  29489. the "auth" section contains the generated token.
  29490. Please refer to the vault docs regarding the result data structure.
  29491. Additionally, accessing the raw response is possibly by using "Raw" result type.
  29492. enum:
  29493. - Data
  29494. - Auth
  29495. - Raw
  29496. type: string
  29497. retrySettings:
  29498. description: Used to configure http retries if failed
  29499. properties:
  29500. maxRetries:
  29501. format: int32
  29502. type: integer
  29503. retryInterval:
  29504. type: string
  29505. type: object
  29506. required:
  29507. - path
  29508. - provider
  29509. type: object
  29510. webhookSpec:
  29511. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  29512. properties:
  29513. auth:
  29514. description: Auth specifies a authorization protocol. Only one protocol may be set.
  29515. maxProperties: 1
  29516. minProperties: 1
  29517. properties:
  29518. ntlm:
  29519. description: NTLMProtocol configures the store to use NTLM for auth
  29520. properties:
  29521. passwordSecret:
  29522. description: |-
  29523. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29524. In some instances, `key` is a required field.
  29525. properties:
  29526. key:
  29527. description: |-
  29528. A key in the referenced Secret.
  29529. Some instances of this field may be defaulted, in others it may be required.
  29530. maxLength: 253
  29531. minLength: 1
  29532. pattern: ^[-._a-zA-Z0-9]+$
  29533. type: string
  29534. name:
  29535. description: The name of the Secret resource being referred to.
  29536. maxLength: 253
  29537. minLength: 1
  29538. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29539. type: string
  29540. namespace:
  29541. description: |-
  29542. The namespace of the Secret resource being referred to.
  29543. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29544. maxLength: 63
  29545. minLength: 1
  29546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29547. type: string
  29548. type: object
  29549. usernameSecret:
  29550. description: |-
  29551. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  29552. In some instances, `key` is a required field.
  29553. properties:
  29554. key:
  29555. description: |-
  29556. A key in the referenced Secret.
  29557. Some instances of this field may be defaulted, in others it may be required.
  29558. maxLength: 253
  29559. minLength: 1
  29560. pattern: ^[-._a-zA-Z0-9]+$
  29561. type: string
  29562. name:
  29563. description: The name of the Secret resource being referred to.
  29564. maxLength: 253
  29565. minLength: 1
  29566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29567. type: string
  29568. namespace:
  29569. description: |-
  29570. The namespace of the Secret resource being referred to.
  29571. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29572. maxLength: 63
  29573. minLength: 1
  29574. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29575. type: string
  29576. type: object
  29577. required:
  29578. - passwordSecret
  29579. - usernameSecret
  29580. type: object
  29581. type: object
  29582. body:
  29583. description: Body
  29584. type: string
  29585. caBundle:
  29586. description: |-
  29587. PEM encoded CA bundle used to validate webhook server certificate. Only used
  29588. if the Server URL is using HTTPS protocol. This parameter is ignored for
  29589. plain HTTP protocol connection. If not set the system root certificates
  29590. are used to validate the TLS connection.
  29591. format: byte
  29592. type: string
  29593. caProvider:
  29594. description: The provider for the CA bundle to use to validate webhook server certificate.
  29595. properties:
  29596. key:
  29597. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  29598. maxLength: 253
  29599. minLength: 1
  29600. pattern: ^[-._a-zA-Z0-9]+$
  29601. type: string
  29602. name:
  29603. description: The name of the object located at the provider type.
  29604. maxLength: 253
  29605. minLength: 1
  29606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29607. type: string
  29608. namespace:
  29609. description: The namespace the Provider type is in.
  29610. maxLength: 63
  29611. minLength: 1
  29612. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29613. type: string
  29614. type:
  29615. description: The type of provider to use such as "Secret", or "ConfigMap".
  29616. enum:
  29617. - Secret
  29618. - ConfigMap
  29619. type: string
  29620. required:
  29621. - name
  29622. - type
  29623. type: object
  29624. headers:
  29625. additionalProperties:
  29626. type: string
  29627. description: Headers
  29628. type: object
  29629. method:
  29630. description: Webhook Method
  29631. type: string
  29632. result:
  29633. description: Result formatting
  29634. properties:
  29635. jsonPath:
  29636. description: Json path of return value
  29637. type: string
  29638. type: object
  29639. secrets:
  29640. description: |-
  29641. Secrets to fill in templates
  29642. These secrets will be passed to the templating function as key value pairs under the given name
  29643. items:
  29644. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  29645. properties:
  29646. name:
  29647. description: Name of this secret in templates
  29648. type: string
  29649. secretRef:
  29650. description: Secret ref to fill in credentials
  29651. properties:
  29652. key:
  29653. description: The key where the token is found.
  29654. maxLength: 253
  29655. minLength: 1
  29656. pattern: ^[-._a-zA-Z0-9]+$
  29657. type: string
  29658. name:
  29659. description: The name of the Secret resource being referred to.
  29660. maxLength: 253
  29661. minLength: 1
  29662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29663. type: string
  29664. type: object
  29665. required:
  29666. - name
  29667. - secretRef
  29668. type: object
  29669. type: array
  29670. timeout:
  29671. description: Timeout
  29672. type: string
  29673. url:
  29674. description: Webhook url to call
  29675. type: string
  29676. required:
  29677. - result
  29678. - url
  29679. type: object
  29680. type: object
  29681. kind:
  29682. description: Kind the kind of this generator.
  29683. enum:
  29684. - ACRAccessToken
  29685. - BeyondtrustWorkloadCredentialsDynamicSecret
  29686. - CloudsmithAccessToken
  29687. - ECRAuthorizationToken
  29688. - Fake
  29689. - GCRAccessToken
  29690. - GithubAccessToken
  29691. - GitlabDeployToken
  29692. - QuayAccessToken
  29693. - Password
  29694. - SSHKey
  29695. - STSSessionToken
  29696. - UUID
  29697. - VaultDynamicSecret
  29698. - Webhook
  29699. - Grafana
  29700. - MFA
  29701. type: string
  29702. required:
  29703. - generator
  29704. - kind
  29705. type: object
  29706. type: object
  29707. served: true
  29708. storage: true
  29709. subresources:
  29710. status: {}
  29711. ---
  29712. apiVersion: apiextensions.k8s.io/v1
  29713. kind: CustomResourceDefinition
  29714. metadata:
  29715. annotations:
  29716. controller-gen.kubebuilder.io/version: v0.19.0
  29717. labels:
  29718. external-secrets.io/component: controller
  29719. name: ecrauthorizationtokens.generators.external-secrets.io
  29720. spec:
  29721. group: generators.external-secrets.io
  29722. names:
  29723. categories:
  29724. - external-secrets
  29725. - external-secrets-generators
  29726. kind: ECRAuthorizationToken
  29727. listKind: ECRAuthorizationTokenList
  29728. plural: ecrauthorizationtokens
  29729. singular: ecrauthorizationtoken
  29730. scope: Namespaced
  29731. versions:
  29732. - name: v1alpha1
  29733. schema:
  29734. openAPIV3Schema:
  29735. description: |-
  29736. ECRAuthorizationToken uses the GetAuthorizationToken API to retrieve an authorization token.
  29737. The authorization token is valid for 12 hours.
  29738. The authorizationToken returned is a base64 encoded string that can be decoded
  29739. and used in a docker login command to authenticate to a registry.
  29740. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  29741. properties:
  29742. apiVersion:
  29743. description: |-
  29744. APIVersion defines the versioned schema of this representation of an object.
  29745. Servers should convert recognized schemas to the latest internal value, and
  29746. may reject unrecognized values.
  29747. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29748. type: string
  29749. kind:
  29750. description: |-
  29751. Kind is a string value representing the REST resource this object represents.
  29752. Servers may infer this from the endpoint the client submits requests to.
  29753. Cannot be updated.
  29754. In CamelCase.
  29755. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29756. type: string
  29757. metadata:
  29758. type: object
  29759. spec:
  29760. description: ECRAuthorizationTokenSpec defines the desired state to generate an AWS ECR authorization token.
  29761. properties:
  29762. auth:
  29763. description: Auth defines how to authenticate with AWS
  29764. properties:
  29765. jwt:
  29766. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  29767. properties:
  29768. serviceAccountRef:
  29769. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  29770. properties:
  29771. audiences:
  29772. description: |-
  29773. Audience specifies the `aud` claim for the service account token
  29774. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  29775. then this audiences will be appended to the list
  29776. items:
  29777. type: string
  29778. type: array
  29779. name:
  29780. description: The name of the ServiceAccount resource being referred to.
  29781. maxLength: 253
  29782. minLength: 1
  29783. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29784. type: string
  29785. namespace:
  29786. description: |-
  29787. Namespace of the resource being referred to.
  29788. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29789. maxLength: 63
  29790. minLength: 1
  29791. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29792. type: string
  29793. required:
  29794. - name
  29795. type: object
  29796. type: object
  29797. secretRef:
  29798. description: |-
  29799. AWSAuthSecretRef holds secret references for AWS credentials
  29800. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  29801. properties:
  29802. accessKeyIDSecretRef:
  29803. description: The AccessKeyID is used for authentication
  29804. properties:
  29805. key:
  29806. description: |-
  29807. A key in the referenced Secret.
  29808. Some instances of this field may be defaulted, in others it may be required.
  29809. maxLength: 253
  29810. minLength: 1
  29811. pattern: ^[-._a-zA-Z0-9]+$
  29812. type: string
  29813. name:
  29814. description: The name of the Secret resource being referred to.
  29815. maxLength: 253
  29816. minLength: 1
  29817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29818. type: string
  29819. namespace:
  29820. description: |-
  29821. The namespace of the Secret resource being referred to.
  29822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29823. maxLength: 63
  29824. minLength: 1
  29825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29826. type: string
  29827. type: object
  29828. secretAccessKeySecretRef:
  29829. description: The SecretAccessKey is used for authentication
  29830. properties:
  29831. key:
  29832. description: |-
  29833. A key in the referenced Secret.
  29834. Some instances of this field may be defaulted, in others it may be required.
  29835. maxLength: 253
  29836. minLength: 1
  29837. pattern: ^[-._a-zA-Z0-9]+$
  29838. type: string
  29839. name:
  29840. description: The name of the Secret resource being referred to.
  29841. maxLength: 253
  29842. minLength: 1
  29843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29844. type: string
  29845. namespace:
  29846. description: |-
  29847. The namespace of the Secret resource being referred to.
  29848. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29849. maxLength: 63
  29850. minLength: 1
  29851. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29852. type: string
  29853. type: object
  29854. sessionTokenSecretRef:
  29855. description: |-
  29856. The SessionToken used for authentication
  29857. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  29858. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  29859. properties:
  29860. key:
  29861. description: |-
  29862. A key in the referenced Secret.
  29863. Some instances of this field may be defaulted, in others it may be required.
  29864. maxLength: 253
  29865. minLength: 1
  29866. pattern: ^[-._a-zA-Z0-9]+$
  29867. type: string
  29868. name:
  29869. description: The name of the Secret resource being referred to.
  29870. maxLength: 253
  29871. minLength: 1
  29872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  29873. type: string
  29874. namespace:
  29875. description: |-
  29876. The namespace of the Secret resource being referred to.
  29877. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  29878. maxLength: 63
  29879. minLength: 1
  29880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  29881. type: string
  29882. type: object
  29883. type: object
  29884. type: object
  29885. region:
  29886. description: Region specifies the region to operate in.
  29887. type: string
  29888. role:
  29889. description: |-
  29890. You can assume a role before making calls to the
  29891. desired AWS service.
  29892. type: string
  29893. scope:
  29894. description: |-
  29895. Scope specifies the ECR service scope.
  29896. Valid options are private and public.
  29897. type: string
  29898. required:
  29899. - region
  29900. type: object
  29901. type: object
  29902. served: true
  29903. storage: true
  29904. subresources:
  29905. status: {}
  29906. ---
  29907. apiVersion: apiextensions.k8s.io/v1
  29908. kind: CustomResourceDefinition
  29909. metadata:
  29910. annotations:
  29911. controller-gen.kubebuilder.io/version: v0.19.0
  29912. labels:
  29913. external-secrets.io/component: controller
  29914. name: fakes.generators.external-secrets.io
  29915. spec:
  29916. group: generators.external-secrets.io
  29917. names:
  29918. categories:
  29919. - external-secrets
  29920. - external-secrets-generators
  29921. kind: Fake
  29922. listKind: FakeList
  29923. plural: fakes
  29924. singular: fake
  29925. scope: Namespaced
  29926. versions:
  29927. - name: v1alpha1
  29928. schema:
  29929. openAPIV3Schema:
  29930. description: |-
  29931. Fake generator is used for testing. It lets you define
  29932. a static set of credentials that is always returned.
  29933. properties:
  29934. apiVersion:
  29935. description: |-
  29936. APIVersion defines the versioned schema of this representation of an object.
  29937. Servers should convert recognized schemas to the latest internal value, and
  29938. may reject unrecognized values.
  29939. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  29940. type: string
  29941. kind:
  29942. description: |-
  29943. Kind is a string value representing the REST resource this object represents.
  29944. Servers may infer this from the endpoint the client submits requests to.
  29945. Cannot be updated.
  29946. In CamelCase.
  29947. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  29948. type: string
  29949. metadata:
  29950. type: object
  29951. spec:
  29952. description: FakeSpec contains the static data.
  29953. properties:
  29954. controller:
  29955. description: |-
  29956. Used to select the correct ESO controller (think: ingress.ingressClassName)
  29957. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  29958. type: string
  29959. data:
  29960. additionalProperties:
  29961. type: string
  29962. description: |-
  29963. Data defines the static data returned
  29964. by this generator.
  29965. type: object
  29966. type: object
  29967. type: object
  29968. served: true
  29969. storage: true
  29970. subresources:
  29971. status: {}
  29972. ---
  29973. apiVersion: apiextensions.k8s.io/v1
  29974. kind: CustomResourceDefinition
  29975. metadata:
  29976. annotations:
  29977. controller-gen.kubebuilder.io/version: v0.19.0
  29978. labels:
  29979. external-secrets.io/component: controller
  29980. name: gcraccesstokens.generators.external-secrets.io
  29981. spec:
  29982. group: generators.external-secrets.io
  29983. names:
  29984. categories:
  29985. - external-secrets
  29986. - external-secrets-generators
  29987. kind: GCRAccessToken
  29988. listKind: GCRAccessTokenList
  29989. plural: gcraccesstokens
  29990. singular: gcraccesstoken
  29991. scope: Namespaced
  29992. versions:
  29993. - name: v1alpha1
  29994. schema:
  29995. openAPIV3Schema:
  29996. description: |-
  29997. GCRAccessToken generates an GCP access token
  29998. that can be used to authenticate with GCR.
  29999. properties:
  30000. apiVersion:
  30001. description: |-
  30002. APIVersion defines the versioned schema of this representation of an object.
  30003. Servers should convert recognized schemas to the latest internal value, and
  30004. may reject unrecognized values.
  30005. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30006. type: string
  30007. kind:
  30008. description: |-
  30009. Kind is a string value representing the REST resource this object represents.
  30010. Servers may infer this from the endpoint the client submits requests to.
  30011. Cannot be updated.
  30012. In CamelCase.
  30013. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30014. type: string
  30015. metadata:
  30016. type: object
  30017. spec:
  30018. description: GCRAccessTokenSpec defines the desired state to generate a Google Container Registry access token.
  30019. properties:
  30020. auth:
  30021. description: Auth defines the means for authenticating with GCP
  30022. properties:
  30023. secretRef:
  30024. description: GCPSMAuthSecretRef defines the reference to a secret containing Google Cloud Platform credentials.
  30025. properties:
  30026. secretAccessKeySecretRef:
  30027. description: The SecretAccessKey is used for authentication
  30028. properties:
  30029. key:
  30030. description: |-
  30031. A key in the referenced Secret.
  30032. Some instances of this field may be defaulted, in others it may be required.
  30033. maxLength: 253
  30034. minLength: 1
  30035. pattern: ^[-._a-zA-Z0-9]+$
  30036. type: string
  30037. name:
  30038. description: The name of the Secret resource being referred to.
  30039. maxLength: 253
  30040. minLength: 1
  30041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30042. type: string
  30043. namespace:
  30044. description: |-
  30045. The namespace of the Secret resource being referred to.
  30046. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30047. maxLength: 63
  30048. minLength: 1
  30049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30050. type: string
  30051. type: object
  30052. type: object
  30053. workloadIdentity:
  30054. description: GCPWorkloadIdentity defines the configuration for using GCP Workload Identity authentication.
  30055. properties:
  30056. clusterLocation:
  30057. type: string
  30058. clusterName:
  30059. type: string
  30060. clusterProjectID:
  30061. type: string
  30062. serviceAccountRef:
  30063. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  30064. properties:
  30065. audiences:
  30066. description: |-
  30067. Audience specifies the `aud` claim for the service account token
  30068. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30069. then this audiences will be appended to the list
  30070. items:
  30071. type: string
  30072. type: array
  30073. name:
  30074. description: The name of the ServiceAccount resource being referred to.
  30075. maxLength: 253
  30076. minLength: 1
  30077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30078. type: string
  30079. namespace:
  30080. description: |-
  30081. Namespace of the resource being referred to.
  30082. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30083. maxLength: 63
  30084. minLength: 1
  30085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30086. type: string
  30087. required:
  30088. - name
  30089. type: object
  30090. required:
  30091. - clusterLocation
  30092. - clusterName
  30093. - serviceAccountRef
  30094. type: object
  30095. workloadIdentityFederation:
  30096. description: GCPWorkloadIdentityFederation holds the configurations required for generating federated access tokens.
  30097. properties:
  30098. audience:
  30099. description: |-
  30100. audience is the Secure Token Service (STS) audience which contains the resource name for the workload identity pool and the provider identifier in that pool.
  30101. If specified, Audience found in the external account credential config will be overridden with the configured value.
  30102. audience must be provided when serviceAccountRef or awsSecurityCredentials is configured.
  30103. type: string
  30104. awsSecurityCredentials:
  30105. description: |-
  30106. awsSecurityCredentials is for configuring AWS region and credentials to use for obtaining the access token,
  30107. when using the AWS metadata server is not an option.
  30108. properties:
  30109. awsCredentialsSecretRef:
  30110. description: |-
  30111. awsCredentialsSecretRef is the reference to the secret which holds the AWS credentials.
  30112. Secret should be created with below names for keys
  30113. - aws_access_key_id: Access Key ID, which is the unique identifier for the AWS account or the IAM user.
  30114. - aws_secret_access_key: Secret Access Key, which is used to authenticate requests made to AWS services.
  30115. - aws_session_token: Session Token, is the short-lived token to authenticate requests made to AWS services.
  30116. properties:
  30117. name:
  30118. description: name of the secret.
  30119. maxLength: 253
  30120. minLength: 1
  30121. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30122. type: string
  30123. namespace:
  30124. description: namespace in which the secret exists. If empty, secret will looked up in local namespace.
  30125. maxLength: 63
  30126. minLength: 1
  30127. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30128. type: string
  30129. required:
  30130. - name
  30131. type: object
  30132. region:
  30133. description: region is for configuring the AWS region to be used.
  30134. example: ap-south-1
  30135. maxLength: 50
  30136. minLength: 1
  30137. pattern: ^[a-z0-9-]+$
  30138. type: string
  30139. required:
  30140. - awsCredentialsSecretRef
  30141. - region
  30142. type: object
  30143. credConfig:
  30144. description: |-
  30145. credConfig holds the configmap reference containing the GCP external account credential configuration in JSON format and the key name containing the json data.
  30146. For using Kubernetes cluster as the identity provider, use serviceAccountRef instead. Operators mounted serviceaccount token cannot be used as the token source, instead
  30147. serviceAccountRef must be used by providing operators service account details.
  30148. properties:
  30149. key:
  30150. description: key name holding the external account credential config.
  30151. maxLength: 253
  30152. minLength: 1
  30153. pattern: ^[-._a-zA-Z0-9]+$
  30154. type: string
  30155. name:
  30156. description: name of the configmap.
  30157. maxLength: 253
  30158. minLength: 1
  30159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30160. type: string
  30161. namespace:
  30162. description: namespace in which the configmap exists. If empty, configmap will looked up in local namespace.
  30163. maxLength: 63
  30164. minLength: 1
  30165. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30166. type: string
  30167. required:
  30168. - key
  30169. - name
  30170. type: object
  30171. externalTokenEndpoint:
  30172. description: |-
  30173. externalTokenEndpoint is the endpoint explicitly set up to provide tokens, which will be matched against the
  30174. credential_source.url in the provided credConfig. This field is merely to double-check the external token source
  30175. URL is having the expected value.
  30176. type: string
  30177. gcpServiceAccountEmail:
  30178. description: |-
  30179. GCPServiceAccountEmail is the email of the Google Cloud service account to impersonate
  30180. after Workload Identity Federation. Use this to grant access through the service account's
  30181. IAM bindings (for example roles/secretmanager.secretAccessor). When set, it overrides
  30182. service_account_impersonation_url in the external account JSON from credConfig;
  30183. when serviceAccountRef is set, it also overrides the "iam.gke.io/gcp-service-account" annotation
  30184. on that ServiceAccount.
  30185. example: my-gsa@my-project.iam.gserviceaccount.com
  30186. minLength: 1
  30187. pattern: ^.*@.*\.iam\.gserviceaccount\.com$
  30188. type: string
  30189. serviceAccountRef:
  30190. description: |-
  30191. serviceAccountRef is the reference to the kubernetes ServiceAccount to be used for obtaining the tokens,
  30192. when Kubernetes is configured as provider in workload identity pool.
  30193. properties:
  30194. audiences:
  30195. description: |-
  30196. Audience specifies the `aud` claim for the service account token
  30197. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  30198. then this audiences will be appended to the list
  30199. items:
  30200. type: string
  30201. type: array
  30202. name:
  30203. description: The name of the ServiceAccount resource being referred to.
  30204. maxLength: 253
  30205. minLength: 1
  30206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30207. type: string
  30208. namespace:
  30209. description: |-
  30210. Namespace of the resource being referred to.
  30211. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30212. maxLength: 63
  30213. minLength: 1
  30214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30215. type: string
  30216. required:
  30217. - name
  30218. type: object
  30219. type: object
  30220. type: object
  30221. projectID:
  30222. description: ProjectID defines which project to use to authenticate with
  30223. type: string
  30224. required:
  30225. - auth
  30226. - projectID
  30227. type: object
  30228. type: object
  30229. served: true
  30230. storage: true
  30231. subresources:
  30232. status: {}
  30233. ---
  30234. apiVersion: apiextensions.k8s.io/v1
  30235. kind: CustomResourceDefinition
  30236. metadata:
  30237. annotations:
  30238. controller-gen.kubebuilder.io/version: v0.19.0
  30239. labels:
  30240. external-secrets.io/component: controller
  30241. name: generatorstates.generators.external-secrets.io
  30242. spec:
  30243. group: generators.external-secrets.io
  30244. names:
  30245. categories:
  30246. - external-secrets
  30247. - external-secrets-generators
  30248. kind: GeneratorState
  30249. listKind: GeneratorStateList
  30250. plural: generatorstates
  30251. shortNames:
  30252. - gs
  30253. singular: generatorstate
  30254. scope: Namespaced
  30255. versions:
  30256. - additionalPrinterColumns:
  30257. - jsonPath: .spec.garbageCollectionDeadline
  30258. name: GC Deadline
  30259. type: string
  30260. - jsonPath: .metadata.creationTimestamp
  30261. name: Age
  30262. type: date
  30263. name: v1alpha1
  30264. schema:
  30265. openAPIV3Schema:
  30266. description: GeneratorState represents the state created and managed by a generator resource.
  30267. properties:
  30268. apiVersion:
  30269. description: |-
  30270. APIVersion defines the versioned schema of this representation of an object.
  30271. Servers should convert recognized schemas to the latest internal value, and
  30272. may reject unrecognized values.
  30273. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30274. type: string
  30275. kind:
  30276. description: |-
  30277. Kind is a string value representing the REST resource this object represents.
  30278. Servers may infer this from the endpoint the client submits requests to.
  30279. Cannot be updated.
  30280. In CamelCase.
  30281. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30282. type: string
  30283. metadata:
  30284. type: object
  30285. spec:
  30286. description: GeneratorStateSpec defines the desired state of a generator state resource.
  30287. properties:
  30288. garbageCollectionDeadline:
  30289. description: |-
  30290. GarbageCollectionDeadline is the time after which the generator state
  30291. will be deleted.
  30292. It is set by the controller which creates the generator state and
  30293. can be set configured by the user.
  30294. If the garbage collection deadline is not set the generator state will not be deleted.
  30295. format: date-time
  30296. type: string
  30297. resource:
  30298. description: |-
  30299. Resource is the generator manifest that produced the state.
  30300. It is a snapshot of the generator manifest at the time the state was produced.
  30301. This manifest will be used to delete the resource. Any configuration that is referenced
  30302. in the manifest should be available at the time of garbage collection. If that is not the case deletion will
  30303. be blocked by a finalizer.
  30304. x-kubernetes-preserve-unknown-fields: true
  30305. state:
  30306. description: State is the state that was produced by the generator implementation.
  30307. x-kubernetes-preserve-unknown-fields: true
  30308. required:
  30309. - resource
  30310. - state
  30311. type: object
  30312. status:
  30313. description: GeneratorStateStatus defines the observed state of a generator state resource.
  30314. properties:
  30315. conditions:
  30316. items:
  30317. description: GeneratorStateStatusCondition represents the observed condition of a generator state.
  30318. properties:
  30319. lastTransitionTime:
  30320. format: date-time
  30321. type: string
  30322. message:
  30323. type: string
  30324. reason:
  30325. type: string
  30326. status:
  30327. type: string
  30328. type:
  30329. description: GeneratorStateConditionType represents the type of condition for a generator state.
  30330. type: string
  30331. required:
  30332. - status
  30333. - type
  30334. type: object
  30335. type: array
  30336. type: object
  30337. type: object
  30338. served: true
  30339. storage: true
  30340. subresources: {}
  30341. ---
  30342. apiVersion: apiextensions.k8s.io/v1
  30343. kind: CustomResourceDefinition
  30344. metadata:
  30345. annotations:
  30346. controller-gen.kubebuilder.io/version: v0.19.0
  30347. labels:
  30348. external-secrets.io/component: controller
  30349. name: githubaccesstokens.generators.external-secrets.io
  30350. spec:
  30351. group: generators.external-secrets.io
  30352. names:
  30353. categories:
  30354. - external-secrets
  30355. - external-secrets-generators
  30356. kind: GithubAccessToken
  30357. listKind: GithubAccessTokenList
  30358. plural: githubaccesstokens
  30359. singular: githubaccesstoken
  30360. scope: Namespaced
  30361. versions:
  30362. - name: v1alpha1
  30363. schema:
  30364. openAPIV3Schema:
  30365. description: GithubAccessToken generates ghs_ accessToken
  30366. properties:
  30367. apiVersion:
  30368. description: |-
  30369. APIVersion defines the versioned schema of this representation of an object.
  30370. Servers should convert recognized schemas to the latest internal value, and
  30371. may reject unrecognized values.
  30372. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30373. type: string
  30374. kind:
  30375. description: |-
  30376. Kind is a string value representing the REST resource this object represents.
  30377. Servers may infer this from the endpoint the client submits requests to.
  30378. Cannot be updated.
  30379. In CamelCase.
  30380. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30381. type: string
  30382. metadata:
  30383. type: object
  30384. spec:
  30385. description: GithubAccessTokenSpec defines the desired state to generate a GitHub access token.
  30386. properties:
  30387. appID:
  30388. type: string
  30389. auth:
  30390. description: Auth configures how ESO authenticates with a Github instance.
  30391. properties:
  30392. privateKey:
  30393. description: GithubSecretRef references a secret containing GitHub credentials.
  30394. properties:
  30395. secretRef:
  30396. description: |-
  30397. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30398. In some instances, `key` is a required field.
  30399. properties:
  30400. key:
  30401. description: |-
  30402. A key in the referenced Secret.
  30403. Some instances of this field may be defaulted, in others it may be required.
  30404. maxLength: 253
  30405. minLength: 1
  30406. pattern: ^[-._a-zA-Z0-9]+$
  30407. type: string
  30408. name:
  30409. description: The name of the Secret resource being referred to.
  30410. maxLength: 253
  30411. minLength: 1
  30412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30413. type: string
  30414. namespace:
  30415. description: |-
  30416. The namespace of the Secret resource being referred to.
  30417. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30418. maxLength: 63
  30419. minLength: 1
  30420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30421. type: string
  30422. type: object
  30423. required:
  30424. - secretRef
  30425. type: object
  30426. required:
  30427. - privateKey
  30428. type: object
  30429. installID:
  30430. type: string
  30431. permissions:
  30432. additionalProperties:
  30433. type: string
  30434. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  30435. type: object
  30436. repositories:
  30437. description: |-
  30438. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  30439. is installed to.
  30440. items:
  30441. type: string
  30442. type: array
  30443. url:
  30444. description: URL configures the GitHub instance URL. Defaults to https://github.com/.
  30445. type: string
  30446. required:
  30447. - appID
  30448. - auth
  30449. - installID
  30450. type: object
  30451. type: object
  30452. served: true
  30453. storage: true
  30454. subresources:
  30455. status: {}
  30456. ---
  30457. apiVersion: apiextensions.k8s.io/v1
  30458. kind: CustomResourceDefinition
  30459. metadata:
  30460. annotations:
  30461. controller-gen.kubebuilder.io/version: v0.19.0
  30462. labels:
  30463. external-secrets.io/component: controller
  30464. name: gitlabdeploytokens.generators.external-secrets.io
  30465. spec:
  30466. group: generators.external-secrets.io
  30467. names:
  30468. categories:
  30469. - external-secrets
  30470. - external-secrets-generators
  30471. kind: GitlabDeployToken
  30472. listKind: GitlabDeployTokenList
  30473. plural: gitlabdeploytokens
  30474. singular: gitlabdeploytoken
  30475. scope: Namespaced
  30476. versions:
  30477. - name: v1alpha1
  30478. schema:
  30479. openAPIV3Schema:
  30480. description: GitlabDeployToken generates a GitLab deploy token.
  30481. properties:
  30482. apiVersion:
  30483. description: |-
  30484. APIVersion defines the versioned schema of this representation of an object.
  30485. Servers should convert recognized schemas to the latest internal value, and
  30486. may reject unrecognized values.
  30487. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30488. type: string
  30489. kind:
  30490. description: |-
  30491. Kind is a string value representing the REST resource this object represents.
  30492. Servers may infer this from the endpoint the client submits requests to.
  30493. Cannot be updated.
  30494. In CamelCase.
  30495. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30496. type: string
  30497. metadata:
  30498. type: object
  30499. spec:
  30500. description: GitlabDeployTokenSpec defines the desired state to generate a GitLab deploy token.
  30501. properties:
  30502. auth:
  30503. description: Auth configures how ESO authenticates with the GitLab API.
  30504. properties:
  30505. token:
  30506. description: |-
  30507. Token references a secret containing a GitLab access token (personal, group, or
  30508. project) with the api scope and at least the Maintainer role on the target.
  30509. properties:
  30510. secretRef:
  30511. description: |-
  30512. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  30513. In some instances, `key` is a required field.
  30514. properties:
  30515. key:
  30516. description: |-
  30517. A key in the referenced Secret.
  30518. Some instances of this field may be defaulted, in others it may be required.
  30519. maxLength: 253
  30520. minLength: 1
  30521. pattern: ^[-._a-zA-Z0-9]+$
  30522. type: string
  30523. name:
  30524. description: The name of the Secret resource being referred to.
  30525. maxLength: 253
  30526. minLength: 1
  30527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30528. type: string
  30529. namespace:
  30530. description: |-
  30531. The namespace of the Secret resource being referred to.
  30532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30533. maxLength: 63
  30534. minLength: 1
  30535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30536. type: string
  30537. type: object
  30538. required:
  30539. - secretRef
  30540. type: object
  30541. required:
  30542. - token
  30543. type: object
  30544. expiresAt:
  30545. description: |-
  30546. ExpiresAt is an optional expiry for the deploy token. If omitted the token does
  30547. not expire on the GitLab side and is revoked only when the generator state is
  30548. cleaned up (on regeneration or when the consuming ExternalSecret is deleted).
  30549. format: date-time
  30550. type: string
  30551. groupID:
  30552. description: |-
  30553. GroupID is the numeric ID or unescaped path (e.g. parent/group) of the group to
  30554. create the deploy token in. The generator URL-escapes paths before calling the
  30555. GitLab API, so do not pre-encode. Mutually exclusive with projectID.
  30556. minLength: 1
  30557. type: string
  30558. name:
  30559. description: Name of the deploy token.
  30560. minLength: 1
  30561. type: string
  30562. projectID:
  30563. description: |-
  30564. ProjectID is the numeric ID or unescaped path (e.g. group/project) of the
  30565. project to create the deploy token in. The generator URL-escapes paths before
  30566. calling the GitLab API, so do not pre-encode. Mutually exclusive with groupID.
  30567. minLength: 1
  30568. type: string
  30569. scopes:
  30570. description: Scopes granted to the deploy token. At least one scope is required.
  30571. items:
  30572. description: GitlabDeployTokenScope is a scope that can be granted to a GitLab deploy token.
  30573. enum:
  30574. - read_repository
  30575. - read_registry
  30576. - write_registry
  30577. - read_package_registry
  30578. - write_package_registry
  30579. - read_virtual_registry
  30580. - write_virtual_registry
  30581. type: string
  30582. minItems: 1
  30583. type: array
  30584. url:
  30585. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com.
  30586. type: string
  30587. username:
  30588. description: |-
  30589. Username is an optional username for the deploy token. GitLab defaults it to
  30590. gitlab+deploy-token-{n} when omitted.
  30591. type: string
  30592. required:
  30593. - auth
  30594. - name
  30595. - scopes
  30596. type: object
  30597. x-kubernetes-validations:
  30598. - message: exactly one of projectID or groupID must be set
  30599. rule: has(self.projectID) != has(self.groupID)
  30600. type: object
  30601. served: true
  30602. storage: true
  30603. subresources:
  30604. status: {}
  30605. ---
  30606. apiVersion: apiextensions.k8s.io/v1
  30607. kind: CustomResourceDefinition
  30608. metadata:
  30609. annotations:
  30610. controller-gen.kubebuilder.io/version: v0.19.0
  30611. labels:
  30612. external-secrets.io/component: controller
  30613. name: grafanas.generators.external-secrets.io
  30614. spec:
  30615. group: generators.external-secrets.io
  30616. names:
  30617. categories:
  30618. - external-secrets
  30619. - external-secrets-generators
  30620. kind: Grafana
  30621. listKind: GrafanaList
  30622. plural: grafanas
  30623. singular: grafana
  30624. scope: Namespaced
  30625. versions:
  30626. - name: v1alpha1
  30627. schema:
  30628. openAPIV3Schema:
  30629. description: Grafana represents a generator for Grafana service account tokens.
  30630. properties:
  30631. apiVersion:
  30632. description: |-
  30633. APIVersion defines the versioned schema of this representation of an object.
  30634. Servers should convert recognized schemas to the latest internal value, and
  30635. may reject unrecognized values.
  30636. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30637. type: string
  30638. kind:
  30639. description: |-
  30640. Kind is a string value representing the REST resource this object represents.
  30641. Servers may infer this from the endpoint the client submits requests to.
  30642. Cannot be updated.
  30643. In CamelCase.
  30644. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30645. type: string
  30646. metadata:
  30647. type: object
  30648. spec:
  30649. description: GrafanaSpec controls the behavior of the grafana generator.
  30650. properties:
  30651. auth:
  30652. description: |-
  30653. Auth is the authentication configuration to authenticate
  30654. against the Grafana instance.
  30655. properties:
  30656. basic:
  30657. description: |-
  30658. Basic auth credentials used to authenticate against the Grafana instance.
  30659. Note: you need a token which has elevated permissions to create service accounts.
  30660. See here for the documentation on basic roles offered by Grafana:
  30661. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30662. properties:
  30663. password:
  30664. description: A basic auth password used to authenticate against the Grafana instance.
  30665. properties:
  30666. key:
  30667. description: The key where the token is found.
  30668. maxLength: 253
  30669. minLength: 1
  30670. pattern: ^[-._a-zA-Z0-9]+$
  30671. type: string
  30672. name:
  30673. description: The name of the Secret resource being referred to.
  30674. maxLength: 253
  30675. minLength: 1
  30676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30677. type: string
  30678. type: object
  30679. username:
  30680. description: A basic auth username used to authenticate against the Grafana instance.
  30681. type: string
  30682. required:
  30683. - password
  30684. - username
  30685. type: object
  30686. token:
  30687. description: |-
  30688. A service account token used to authenticate against the Grafana instance.
  30689. Note: you need a token which has elevated permissions to create service accounts.
  30690. See here for the documentation on basic roles offered by Grafana:
  30691. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30692. properties:
  30693. key:
  30694. description: The key where the token is found.
  30695. maxLength: 253
  30696. minLength: 1
  30697. pattern: ^[-._a-zA-Z0-9]+$
  30698. type: string
  30699. name:
  30700. description: The name of the Secret resource being referred to.
  30701. maxLength: 253
  30702. minLength: 1
  30703. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30704. type: string
  30705. type: object
  30706. type: object
  30707. serviceAccount:
  30708. description: |-
  30709. ServiceAccount is the configuration for the service account that
  30710. is supposed to be generated by the generator.
  30711. properties:
  30712. name:
  30713. description: Name is the name of the service account that will be created by ESO.
  30714. type: string
  30715. role:
  30716. description: |-
  30717. Role is the role of the service account.
  30718. See here for the documentation on basic roles offered by Grafana:
  30719. https://grafana.com/docs/grafana/latest/administration/roles-and-permissions/access-control/rbac-fixed-basic-role-definitions/
  30720. type: string
  30721. secondsToLive:
  30722. description: |-
  30723. SecondsToLive is the number of seconds before the generated service account token will expire.
  30724. Some Grafana deployments (e.g. AWS Managed Grafana) require this value to be set.
  30725. format: int64
  30726. minimum: 1
  30727. type: integer
  30728. required:
  30729. - name
  30730. - role
  30731. type: object
  30732. url:
  30733. description: URL is the URL of the Grafana instance.
  30734. type: string
  30735. required:
  30736. - auth
  30737. - serviceAccount
  30738. - url
  30739. type: object
  30740. type: object
  30741. served: true
  30742. storage: true
  30743. subresources:
  30744. status: {}
  30745. ---
  30746. apiVersion: apiextensions.k8s.io/v1
  30747. kind: CustomResourceDefinition
  30748. metadata:
  30749. annotations:
  30750. controller-gen.kubebuilder.io/version: v0.19.0
  30751. labels:
  30752. external-secrets.io/component: controller
  30753. name: mfas.generators.external-secrets.io
  30754. spec:
  30755. group: generators.external-secrets.io
  30756. names:
  30757. categories:
  30758. - external-secrets
  30759. - external-secrets-generators
  30760. kind: MFA
  30761. listKind: MFAList
  30762. plural: mfas
  30763. singular: mfa
  30764. scope: Namespaced
  30765. versions:
  30766. - name: v1alpha1
  30767. schema:
  30768. openAPIV3Schema:
  30769. description: MFA generates a new TOTP token that is compliant with RFC 6238.
  30770. properties:
  30771. apiVersion:
  30772. description: |-
  30773. APIVersion defines the versioned schema of this representation of an object.
  30774. Servers should convert recognized schemas to the latest internal value, and
  30775. may reject unrecognized values.
  30776. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30777. type: string
  30778. kind:
  30779. description: |-
  30780. Kind is a string value representing the REST resource this object represents.
  30781. Servers may infer this from the endpoint the client submits requests to.
  30782. Cannot be updated.
  30783. In CamelCase.
  30784. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30785. type: string
  30786. metadata:
  30787. type: object
  30788. spec:
  30789. description: MFASpec controls the behavior of the mfa generator.
  30790. properties:
  30791. algorithm:
  30792. description: Algorithm to use for encoding. Defaults to SHA1 as per the RFC.
  30793. type: string
  30794. length:
  30795. description: Length defines the token length. Defaults to 6 characters.
  30796. type: integer
  30797. secret:
  30798. description: Secret is a secret selector to a secret containing the seed secret to generate the TOTP value from.
  30799. properties:
  30800. key:
  30801. description: |-
  30802. A key in the referenced Secret.
  30803. Some instances of this field may be defaulted, in others it may be required.
  30804. maxLength: 253
  30805. minLength: 1
  30806. pattern: ^[-._a-zA-Z0-9]+$
  30807. type: string
  30808. name:
  30809. description: The name of the Secret resource being referred to.
  30810. maxLength: 253
  30811. minLength: 1
  30812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  30813. type: string
  30814. namespace:
  30815. description: |-
  30816. The namespace of the Secret resource being referred to.
  30817. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  30818. maxLength: 63
  30819. minLength: 1
  30820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  30821. type: string
  30822. type: object
  30823. timePeriod:
  30824. description: TimePeriod defines how long the token can be active. Defaults to 30 seconds.
  30825. type: integer
  30826. when:
  30827. description: When defines a time parameter that can be used to pin the origin time of the generated token.
  30828. format: date-time
  30829. type: string
  30830. required:
  30831. - secret
  30832. type: object
  30833. type: object
  30834. served: true
  30835. storage: true
  30836. subresources:
  30837. status: {}
  30838. ---
  30839. apiVersion: apiextensions.k8s.io/v1
  30840. kind: CustomResourceDefinition
  30841. metadata:
  30842. annotations:
  30843. controller-gen.kubebuilder.io/version: v0.19.0
  30844. labels:
  30845. external-secrets.io/component: controller
  30846. name: passwords.generators.external-secrets.io
  30847. spec:
  30848. group: generators.external-secrets.io
  30849. names:
  30850. categories:
  30851. - external-secrets
  30852. - external-secrets-generators
  30853. kind: Password
  30854. listKind: PasswordList
  30855. plural: passwords
  30856. singular: password
  30857. scope: Namespaced
  30858. versions:
  30859. - name: v1alpha1
  30860. schema:
  30861. openAPIV3Schema:
  30862. description: |-
  30863. Password generates a random password based on the
  30864. configuration parameters in spec.
  30865. You can specify the length, characterset and other attributes.
  30866. properties:
  30867. apiVersion:
  30868. description: |-
  30869. APIVersion defines the versioned schema of this representation of an object.
  30870. Servers should convert recognized schemas to the latest internal value, and
  30871. may reject unrecognized values.
  30872. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30873. type: string
  30874. kind:
  30875. description: |-
  30876. Kind is a string value representing the REST resource this object represents.
  30877. Servers may infer this from the endpoint the client submits requests to.
  30878. Cannot be updated.
  30879. In CamelCase.
  30880. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30881. type: string
  30882. metadata:
  30883. type: object
  30884. spec:
  30885. description: PasswordSpec controls the behavior of the password generator.
  30886. properties:
  30887. allowRepeat:
  30888. default: false
  30889. description: set AllowRepeat to true to allow repeating characters.
  30890. type: boolean
  30891. digits:
  30892. description: |-
  30893. Digits specifies the number of digits in the generated
  30894. password. If omitted it defaults to 25% of the length of the password
  30895. type: integer
  30896. encoding:
  30897. default: raw
  30898. description: |-
  30899. Encoding specifies the encoding of the generated password.
  30900. Valid values are:
  30901. - "raw" (default): no encoding
  30902. - "base64": standard base64 encoding
  30903. - "base64url": base64url encoding
  30904. - "base32": base32 encoding
  30905. - "hex": hexadecimal encoding
  30906. enum:
  30907. - base64
  30908. - base64url
  30909. - base32
  30910. - hex
  30911. - raw
  30912. type: string
  30913. length:
  30914. default: 24
  30915. description: |-
  30916. Length of the password to be generated.
  30917. Defaults to 24
  30918. type: integer
  30919. noUpper:
  30920. default: false
  30921. description: Set NoUpper to disable uppercase characters
  30922. type: boolean
  30923. secretKeys:
  30924. description: |-
  30925. SecretKeys defines the keys that will be populated with generated passwords.
  30926. Defaults to "password" when not set.
  30927. items:
  30928. type: string
  30929. minItems: 1
  30930. type: array
  30931. symbolCharacters:
  30932. description: |-
  30933. SymbolCharacters specifies the special characters that should be used
  30934. in the generated password.
  30935. type: string
  30936. symbols:
  30937. description: |-
  30938. Symbols specifies the number of symbol characters in the generated
  30939. password. If omitted it defaults to 25% of the length of the password
  30940. type: integer
  30941. required:
  30942. - allowRepeat
  30943. - length
  30944. - noUpper
  30945. type: object
  30946. type: object
  30947. served: true
  30948. storage: true
  30949. subresources:
  30950. status: {}
  30951. ---
  30952. apiVersion: apiextensions.k8s.io/v1
  30953. kind: CustomResourceDefinition
  30954. metadata:
  30955. annotations:
  30956. controller-gen.kubebuilder.io/version: v0.19.0
  30957. labels:
  30958. external-secrets.io/component: controller
  30959. name: quayaccesstokens.generators.external-secrets.io
  30960. spec:
  30961. group: generators.external-secrets.io
  30962. names:
  30963. categories:
  30964. - external-secrets
  30965. - external-secrets-generators
  30966. kind: QuayAccessToken
  30967. listKind: QuayAccessTokenList
  30968. plural: quayaccesstokens
  30969. singular: quayaccesstoken
  30970. scope: Namespaced
  30971. versions:
  30972. - name: v1alpha1
  30973. schema:
  30974. openAPIV3Schema:
  30975. description: QuayAccessToken generates Quay oauth token for pulling/pushing images
  30976. properties:
  30977. apiVersion:
  30978. description: |-
  30979. APIVersion defines the versioned schema of this representation of an object.
  30980. Servers should convert recognized schemas to the latest internal value, and
  30981. may reject unrecognized values.
  30982. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  30983. type: string
  30984. kind:
  30985. description: |-
  30986. Kind is a string value representing the REST resource this object represents.
  30987. Servers may infer this from the endpoint the client submits requests to.
  30988. Cannot be updated.
  30989. In CamelCase.
  30990. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  30991. type: string
  30992. metadata:
  30993. type: object
  30994. spec:
  30995. description: QuayAccessTokenSpec defines the desired state to generate a Quay access token.
  30996. properties:
  30997. robotAccount:
  30998. description: Name of the robot account you are federating with
  30999. type: string
  31000. serviceAccountRef:
  31001. description: Name of the service account you are federating with
  31002. properties:
  31003. audiences:
  31004. description: |-
  31005. Audience specifies the `aud` claim for the service account token
  31006. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31007. then this audiences will be appended to the list
  31008. items:
  31009. type: string
  31010. type: array
  31011. name:
  31012. description: The name of the ServiceAccount resource being referred to.
  31013. maxLength: 253
  31014. minLength: 1
  31015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31016. type: string
  31017. namespace:
  31018. description: |-
  31019. Namespace of the resource being referred to.
  31020. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31021. maxLength: 63
  31022. minLength: 1
  31023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31024. type: string
  31025. required:
  31026. - name
  31027. type: object
  31028. url:
  31029. description: URL configures the Quay instance URL. Defaults to quay.io.
  31030. type: string
  31031. required:
  31032. - robotAccount
  31033. - serviceAccountRef
  31034. type: object
  31035. type: object
  31036. served: true
  31037. storage: true
  31038. subresources:
  31039. status: {}
  31040. ---
  31041. apiVersion: apiextensions.k8s.io/v1
  31042. kind: CustomResourceDefinition
  31043. metadata:
  31044. annotations:
  31045. controller-gen.kubebuilder.io/version: v0.19.0
  31046. labels:
  31047. external-secrets.io/component: controller
  31048. name: sshkeys.generators.external-secrets.io
  31049. spec:
  31050. group: generators.external-secrets.io
  31051. names:
  31052. categories:
  31053. - external-secrets
  31054. - external-secrets-generators
  31055. kind: SSHKey
  31056. listKind: SSHKeyList
  31057. plural: sshkeys
  31058. singular: sshkey
  31059. scope: Namespaced
  31060. versions:
  31061. - name: v1alpha1
  31062. schema:
  31063. openAPIV3Schema:
  31064. description: SSHKey generates SSH key pairs.
  31065. properties:
  31066. apiVersion:
  31067. description: |-
  31068. APIVersion defines the versioned schema of this representation of an object.
  31069. Servers should convert recognized schemas to the latest internal value, and
  31070. may reject unrecognized values.
  31071. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31072. type: string
  31073. kind:
  31074. description: |-
  31075. Kind is a string value representing the REST resource this object represents.
  31076. Servers may infer this from the endpoint the client submits requests to.
  31077. Cannot be updated.
  31078. In CamelCase.
  31079. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31080. type: string
  31081. metadata:
  31082. type: object
  31083. spec:
  31084. description: SSHKeySpec controls the behavior of the ssh key generator.
  31085. properties:
  31086. comment:
  31087. description: Comment specifies an optional comment for the SSH key
  31088. type: string
  31089. keySize:
  31090. description: |-
  31091. KeySize specifies the key size for RSA keys (default: 2048) and ECDSA keys (default: 256).
  31092. For RSA keys: 2048, 3072, 4096
  31093. For ECDSA keys: 256, 384, 521
  31094. Ignored for ed25519 keys
  31095. maximum: 8192
  31096. minimum: 256
  31097. type: integer
  31098. keyType:
  31099. default: rsa
  31100. description: KeyType specifies the SSH key type (rsa, ecdsa, ed25519)
  31101. enum:
  31102. - rsa
  31103. - ecdsa
  31104. - ed25519
  31105. type: string
  31106. type: object
  31107. type: object
  31108. served: true
  31109. storage: true
  31110. subresources:
  31111. status: {}
  31112. ---
  31113. apiVersion: apiextensions.k8s.io/v1
  31114. kind: CustomResourceDefinition
  31115. metadata:
  31116. annotations:
  31117. controller-gen.kubebuilder.io/version: v0.19.0
  31118. labels:
  31119. external-secrets.io/component: controller
  31120. name: stssessiontokens.generators.external-secrets.io
  31121. spec:
  31122. group: generators.external-secrets.io
  31123. names:
  31124. categories:
  31125. - external-secrets
  31126. - external-secrets-generators
  31127. kind: STSSessionToken
  31128. listKind: STSSessionTokenList
  31129. plural: stssessiontokens
  31130. singular: stssessiontoken
  31131. scope: Namespaced
  31132. versions:
  31133. - name: v1alpha1
  31134. schema:
  31135. openAPIV3Schema:
  31136. description: |-
  31137. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  31138. The authorization token is valid for 12 hours.
  31139. The authorizationToken returned is a base64 encoded string that can be decoded.
  31140. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  31141. properties:
  31142. apiVersion:
  31143. description: |-
  31144. APIVersion defines the versioned schema of this representation of an object.
  31145. Servers should convert recognized schemas to the latest internal value, and
  31146. may reject unrecognized values.
  31147. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31148. type: string
  31149. kind:
  31150. description: |-
  31151. Kind is a string value representing the REST resource this object represents.
  31152. Servers may infer this from the endpoint the client submits requests to.
  31153. Cannot be updated.
  31154. In CamelCase.
  31155. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31156. type: string
  31157. metadata:
  31158. type: object
  31159. spec:
  31160. description: STSSessionTokenSpec defines the desired state to generate an AWS STS session token.
  31161. properties:
  31162. auth:
  31163. description: Auth defines how to authenticate with AWS
  31164. properties:
  31165. jwt:
  31166. description: AWSJWTAuth provides configuration to authenticate against AWS using service account tokens.
  31167. properties:
  31168. serviceAccountRef:
  31169. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31170. properties:
  31171. audiences:
  31172. description: |-
  31173. Audience specifies the `aud` claim for the service account token
  31174. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31175. then this audiences will be appended to the list
  31176. items:
  31177. type: string
  31178. type: array
  31179. name:
  31180. description: The name of the ServiceAccount resource being referred to.
  31181. maxLength: 253
  31182. minLength: 1
  31183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31184. type: string
  31185. namespace:
  31186. description: |-
  31187. Namespace of the resource being referred to.
  31188. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31189. maxLength: 63
  31190. minLength: 1
  31191. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31192. type: string
  31193. required:
  31194. - name
  31195. type: object
  31196. type: object
  31197. secretRef:
  31198. description: |-
  31199. AWSAuthSecretRef holds secret references for AWS credentials
  31200. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  31201. properties:
  31202. accessKeyIDSecretRef:
  31203. description: The AccessKeyID is used for authentication
  31204. properties:
  31205. key:
  31206. description: |-
  31207. A key in the referenced Secret.
  31208. Some instances of this field may be defaulted, in others it may be required.
  31209. maxLength: 253
  31210. minLength: 1
  31211. pattern: ^[-._a-zA-Z0-9]+$
  31212. type: string
  31213. name:
  31214. description: The name of the Secret resource being referred to.
  31215. maxLength: 253
  31216. minLength: 1
  31217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31218. type: string
  31219. namespace:
  31220. description: |-
  31221. The namespace of the Secret resource being referred to.
  31222. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31223. maxLength: 63
  31224. minLength: 1
  31225. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31226. type: string
  31227. type: object
  31228. secretAccessKeySecretRef:
  31229. description: The SecretAccessKey is used for authentication
  31230. properties:
  31231. key:
  31232. description: |-
  31233. A key in the referenced Secret.
  31234. Some instances of this field may be defaulted, in others it may be required.
  31235. maxLength: 253
  31236. minLength: 1
  31237. pattern: ^[-._a-zA-Z0-9]+$
  31238. type: string
  31239. name:
  31240. description: The name of the Secret resource being referred to.
  31241. maxLength: 253
  31242. minLength: 1
  31243. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31244. type: string
  31245. namespace:
  31246. description: |-
  31247. The namespace of the Secret resource being referred to.
  31248. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31249. maxLength: 63
  31250. minLength: 1
  31251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31252. type: string
  31253. type: object
  31254. sessionTokenSecretRef:
  31255. description: |-
  31256. The SessionToken used for authentication
  31257. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31258. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31259. properties:
  31260. key:
  31261. description: |-
  31262. A key in the referenced Secret.
  31263. Some instances of this field may be defaulted, in others it may be required.
  31264. maxLength: 253
  31265. minLength: 1
  31266. pattern: ^[-._a-zA-Z0-9]+$
  31267. type: string
  31268. name:
  31269. description: The name of the Secret resource being referred to.
  31270. maxLength: 253
  31271. minLength: 1
  31272. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31273. type: string
  31274. namespace:
  31275. description: |-
  31276. The namespace of the Secret resource being referred to.
  31277. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31278. maxLength: 63
  31279. minLength: 1
  31280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31281. type: string
  31282. type: object
  31283. type: object
  31284. type: object
  31285. region:
  31286. description: Region specifies the region to operate in.
  31287. type: string
  31288. requestParameters:
  31289. description: RequestParameters contains parameters that can be passed to the STS service.
  31290. properties:
  31291. serialNumber:
  31292. description: |-
  31293. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  31294. the GetSessionToken call.
  31295. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  31296. (such as arn:aws:iam::123456789012:mfa/user)
  31297. type: string
  31298. sessionDuration:
  31299. format: int32
  31300. type: integer
  31301. tokenCode:
  31302. description: TokenCode is the value provided by the MFA device, if MFA is required.
  31303. type: string
  31304. type: object
  31305. role:
  31306. description: |-
  31307. You can assume a role before making calls to the
  31308. desired AWS service.
  31309. type: string
  31310. required:
  31311. - region
  31312. type: object
  31313. type: object
  31314. served: true
  31315. storage: true
  31316. subresources:
  31317. status: {}
  31318. ---
  31319. apiVersion: apiextensions.k8s.io/v1
  31320. kind: CustomResourceDefinition
  31321. metadata:
  31322. annotations:
  31323. controller-gen.kubebuilder.io/version: v0.19.0
  31324. labels:
  31325. external-secrets.io/component: controller
  31326. name: uuids.generators.external-secrets.io
  31327. spec:
  31328. group: generators.external-secrets.io
  31329. names:
  31330. categories:
  31331. - external-secrets
  31332. - external-secrets-generators
  31333. kind: UUID
  31334. listKind: UUIDList
  31335. plural: uuids
  31336. singular: uuid
  31337. scope: Namespaced
  31338. versions:
  31339. - name: v1alpha1
  31340. schema:
  31341. openAPIV3Schema:
  31342. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  31343. properties:
  31344. apiVersion:
  31345. description: |-
  31346. APIVersion defines the versioned schema of this representation of an object.
  31347. Servers should convert recognized schemas to the latest internal value, and
  31348. may reject unrecognized values.
  31349. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31350. type: string
  31351. kind:
  31352. description: |-
  31353. Kind is a string value representing the REST resource this object represents.
  31354. Servers may infer this from the endpoint the client submits requests to.
  31355. Cannot be updated.
  31356. In CamelCase.
  31357. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31358. type: string
  31359. metadata:
  31360. type: object
  31361. spec:
  31362. description: UUIDSpec controls the behavior of the uuid generator.
  31363. type: object
  31364. type: object
  31365. served: true
  31366. storage: true
  31367. subresources:
  31368. status: {}
  31369. ---
  31370. apiVersion: apiextensions.k8s.io/v1
  31371. kind: CustomResourceDefinition
  31372. metadata:
  31373. annotations:
  31374. controller-gen.kubebuilder.io/version: v0.19.0
  31375. labels:
  31376. external-secrets.io/component: controller
  31377. name: vaultdynamicsecrets.generators.external-secrets.io
  31378. spec:
  31379. group: generators.external-secrets.io
  31380. names:
  31381. categories:
  31382. - external-secrets
  31383. - external-secrets-generators
  31384. kind: VaultDynamicSecret
  31385. listKind: VaultDynamicSecretList
  31386. plural: vaultdynamicsecrets
  31387. singular: vaultdynamicsecret
  31388. scope: Namespaced
  31389. versions:
  31390. - name: v1alpha1
  31391. schema:
  31392. openAPIV3Schema:
  31393. description: VaultDynamicSecret represents a generator that can create dynamic secrets from HashiCorp Vault.
  31394. properties:
  31395. apiVersion:
  31396. description: |-
  31397. APIVersion defines the versioned schema of this representation of an object.
  31398. Servers should convert recognized schemas to the latest internal value, and
  31399. may reject unrecognized values.
  31400. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  31401. type: string
  31402. kind:
  31403. description: |-
  31404. Kind is a string value representing the REST resource this object represents.
  31405. Servers may infer this from the endpoint the client submits requests to.
  31406. Cannot be updated.
  31407. In CamelCase.
  31408. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  31409. type: string
  31410. metadata:
  31411. type: object
  31412. spec:
  31413. description: VaultDynamicSecretSpec defines the desired spec of VaultDynamicSecret.
  31414. properties:
  31415. allowEmptyResponse:
  31416. default: false
  31417. description: Do not fail if no secrets are found. Useful for requests where no data is expected.
  31418. type: boolean
  31419. controller:
  31420. description: |-
  31421. Used to select the correct ESO controller (think: ingress.ingressClassName)
  31422. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  31423. type: string
  31424. getParameters:
  31425. additionalProperties:
  31426. items:
  31427. type: string
  31428. type: array
  31429. description: |-
  31430. GetParameters are query-string parameters passed to Vault on GET calls.
  31431. Each key may map to multiple values, matching HTTP query-string semantics.
  31432. Ignored for non-GET methods; use Parameters for write bodies.
  31433. type: object
  31434. method:
  31435. description: Vault API method to use (GET/POST/other)
  31436. type: string
  31437. parameters:
  31438. description: Parameters to pass to Vault write (for non-GET methods)
  31439. x-kubernetes-preserve-unknown-fields: true
  31440. path:
  31441. description: Vault path to obtain the dynamic secret from
  31442. type: string
  31443. provider:
  31444. description: Vault provider common spec
  31445. properties:
  31446. auth:
  31447. description: Auth configures how secret-manager authenticates with the Vault server.
  31448. properties:
  31449. appRole:
  31450. description: |-
  31451. AppRole authenticates with Vault using the App Role auth mechanism,
  31452. with the role and secret stored in a Kubernetes Secret resource.
  31453. properties:
  31454. path:
  31455. default: approle
  31456. description: |-
  31457. Path where the App Role authentication backend is mounted
  31458. in Vault, e.g: "approle"
  31459. type: string
  31460. roleId:
  31461. description: |-
  31462. RoleID configured in the App Role authentication backend when setting
  31463. up the authentication backend in Vault.
  31464. type: string
  31465. roleRef:
  31466. description: |-
  31467. Reference to a key in a Secret that contains the App Role ID used
  31468. to authenticate with Vault.
  31469. The `key` field must be specified and denotes which entry within the Secret
  31470. resource is used as the app role id.
  31471. properties:
  31472. key:
  31473. description: |-
  31474. A key in the referenced Secret.
  31475. Some instances of this field may be defaulted, in others it may be required.
  31476. maxLength: 253
  31477. minLength: 1
  31478. pattern: ^[-._a-zA-Z0-9]+$
  31479. type: string
  31480. name:
  31481. description: The name of the Secret resource being referred to.
  31482. maxLength: 253
  31483. minLength: 1
  31484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31485. type: string
  31486. namespace:
  31487. description: |-
  31488. The namespace of the Secret resource being referred to.
  31489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31490. maxLength: 63
  31491. minLength: 1
  31492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31493. type: string
  31494. type: object
  31495. secretRef:
  31496. description: |-
  31497. Reference to a key in a Secret that contains the App Role secret used
  31498. to authenticate with Vault.
  31499. The `key` field must be specified and denotes which entry within the Secret
  31500. resource is used as the app role secret.
  31501. properties:
  31502. key:
  31503. description: |-
  31504. A key in the referenced Secret.
  31505. Some instances of this field may be defaulted, in others it may be required.
  31506. maxLength: 253
  31507. minLength: 1
  31508. pattern: ^[-._a-zA-Z0-9]+$
  31509. type: string
  31510. name:
  31511. description: The name of the Secret resource being referred to.
  31512. maxLength: 253
  31513. minLength: 1
  31514. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31515. type: string
  31516. namespace:
  31517. description: |-
  31518. The namespace of the Secret resource being referred to.
  31519. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31520. maxLength: 63
  31521. minLength: 1
  31522. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31523. type: string
  31524. type: object
  31525. required:
  31526. - path
  31527. - secretRef
  31528. type: object
  31529. cert:
  31530. description: |-
  31531. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  31532. Cert authentication method
  31533. properties:
  31534. clientCert:
  31535. description: |-
  31536. ClientCert is a certificate to authenticate using the Cert Vault
  31537. authentication method
  31538. properties:
  31539. key:
  31540. description: |-
  31541. A key in the referenced Secret.
  31542. Some instances of this field may be defaulted, in others it may be required.
  31543. maxLength: 253
  31544. minLength: 1
  31545. pattern: ^[-._a-zA-Z0-9]+$
  31546. type: string
  31547. name:
  31548. description: The name of the Secret resource being referred to.
  31549. maxLength: 253
  31550. minLength: 1
  31551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31552. type: string
  31553. namespace:
  31554. description: |-
  31555. The namespace of the Secret resource being referred to.
  31556. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31557. maxLength: 63
  31558. minLength: 1
  31559. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31560. type: string
  31561. type: object
  31562. path:
  31563. default: cert
  31564. description: |-
  31565. Path where the Certificate authentication backend is mounted
  31566. in Vault, e.g: "cert"
  31567. type: string
  31568. secretRef:
  31569. description: |-
  31570. SecretRef to a key in a Secret resource containing client private key to
  31571. authenticate with Vault using the Cert authentication method
  31572. properties:
  31573. key:
  31574. description: |-
  31575. A key in the referenced Secret.
  31576. Some instances of this field may be defaulted, in others it may be required.
  31577. maxLength: 253
  31578. minLength: 1
  31579. pattern: ^[-._a-zA-Z0-9]+$
  31580. type: string
  31581. name:
  31582. description: The name of the Secret resource being referred to.
  31583. maxLength: 253
  31584. minLength: 1
  31585. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31586. type: string
  31587. namespace:
  31588. description: |-
  31589. The namespace of the Secret resource being referred to.
  31590. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31591. maxLength: 63
  31592. minLength: 1
  31593. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31594. type: string
  31595. type: object
  31596. vaultRole:
  31597. description: VaultRole specifies the Vault role to use for TLS certificate authentication.
  31598. type: string
  31599. type: object
  31600. gcp:
  31601. description: |-
  31602. Gcp authenticates with Vault using Google Cloud Platform authentication method
  31603. GCP authentication method
  31604. properties:
  31605. location:
  31606. description: Location optionally defines a location/region for the secret
  31607. type: string
  31608. path:
  31609. default: gcp
  31610. description: 'Path where the GCP auth method is enabled in Vault, e.g: "gcp"'
  31611. type: string
  31612. projectID:
  31613. description: Project ID of the Google Cloud Platform project
  31614. type: string
  31615. role:
  31616. description: Vault Role. In Vault, a role describes an identity with a set of permissions, groups, or policies you want to attach to a user of the secrets engine.
  31617. type: string
  31618. secretRef:
  31619. description: Specify credentials in a Secret object
  31620. properties:
  31621. secretAccessKeySecretRef:
  31622. description: The SecretAccessKey is used for authentication
  31623. properties:
  31624. key:
  31625. description: |-
  31626. A key in the referenced Secret.
  31627. Some instances of this field may be defaulted, in others it may be required.
  31628. maxLength: 253
  31629. minLength: 1
  31630. pattern: ^[-._a-zA-Z0-9]+$
  31631. type: string
  31632. name:
  31633. description: The name of the Secret resource being referred to.
  31634. maxLength: 253
  31635. minLength: 1
  31636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31637. type: string
  31638. namespace:
  31639. description: |-
  31640. The namespace of the Secret resource being referred to.
  31641. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31642. maxLength: 63
  31643. minLength: 1
  31644. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31645. type: string
  31646. type: object
  31647. type: object
  31648. serviceAccountRef:
  31649. description: ServiceAccountRef to a service account for impersonation
  31650. properties:
  31651. audiences:
  31652. description: |-
  31653. Audience specifies the `aud` claim for the service account token
  31654. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31655. then this audiences will be appended to the list
  31656. items:
  31657. type: string
  31658. type: array
  31659. name:
  31660. description: The name of the ServiceAccount resource being referred to.
  31661. maxLength: 253
  31662. minLength: 1
  31663. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31664. type: string
  31665. namespace:
  31666. description: |-
  31667. Namespace of the resource being referred to.
  31668. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31669. maxLength: 63
  31670. minLength: 1
  31671. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31672. type: string
  31673. required:
  31674. - name
  31675. type: object
  31676. workloadIdentity:
  31677. description: Specify a service account with Workload Identity
  31678. properties:
  31679. clusterLocation:
  31680. description: |-
  31681. ClusterLocation is the location of the cluster
  31682. If not specified, it fetches information from the metadata server
  31683. type: string
  31684. clusterName:
  31685. description: |-
  31686. ClusterName is the name of the cluster
  31687. If not specified, it fetches information from the metadata server
  31688. type: string
  31689. clusterProjectID:
  31690. description: |-
  31691. ClusterProjectID is the project ID of the cluster
  31692. If not specified, it fetches information from the metadata server
  31693. type: string
  31694. serviceAccountRef:
  31695. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31696. properties:
  31697. audiences:
  31698. description: |-
  31699. Audience specifies the `aud` claim for the service account token
  31700. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31701. then this audiences will be appended to the list
  31702. items:
  31703. type: string
  31704. type: array
  31705. name:
  31706. description: The name of the ServiceAccount resource being referred to.
  31707. maxLength: 253
  31708. minLength: 1
  31709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31710. type: string
  31711. namespace:
  31712. description: |-
  31713. Namespace of the resource being referred to.
  31714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31715. maxLength: 63
  31716. minLength: 1
  31717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31718. type: string
  31719. required:
  31720. - name
  31721. type: object
  31722. required:
  31723. - serviceAccountRef
  31724. type: object
  31725. required:
  31726. - role
  31727. type: object
  31728. iam:
  31729. description: |-
  31730. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  31731. AWS IAM authentication method
  31732. properties:
  31733. externalID:
  31734. description: AWS External ID set on assumed IAM roles
  31735. type: string
  31736. jwt:
  31737. description: Specify a service account with IRSA enabled
  31738. properties:
  31739. serviceAccountRef:
  31740. description: ServiceAccountSelector is a reference to a ServiceAccount resource.
  31741. properties:
  31742. audiences:
  31743. description: |-
  31744. Audience specifies the `aud` claim for the service account token
  31745. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31746. then this audiences will be appended to the list
  31747. items:
  31748. type: string
  31749. type: array
  31750. name:
  31751. description: The name of the ServiceAccount resource being referred to.
  31752. maxLength: 253
  31753. minLength: 1
  31754. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31755. type: string
  31756. namespace:
  31757. description: |-
  31758. Namespace of the resource being referred to.
  31759. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31760. maxLength: 63
  31761. minLength: 1
  31762. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31763. type: string
  31764. required:
  31765. - name
  31766. type: object
  31767. type: object
  31768. path:
  31769. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  31770. type: string
  31771. region:
  31772. description: AWS region
  31773. type: string
  31774. role:
  31775. description: This is the AWS role to be assumed before talking to vault
  31776. type: string
  31777. secretRef:
  31778. description: Specify credentials in a Secret object
  31779. properties:
  31780. accessKeyIDSecretRef:
  31781. description: The AccessKeyID is used for authentication
  31782. properties:
  31783. key:
  31784. description: |-
  31785. A key in the referenced Secret.
  31786. Some instances of this field may be defaulted, in others it may be required.
  31787. maxLength: 253
  31788. minLength: 1
  31789. pattern: ^[-._a-zA-Z0-9]+$
  31790. type: string
  31791. name:
  31792. description: The name of the Secret resource being referred to.
  31793. maxLength: 253
  31794. minLength: 1
  31795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31796. type: string
  31797. namespace:
  31798. description: |-
  31799. The namespace of the Secret resource being referred to.
  31800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31801. maxLength: 63
  31802. minLength: 1
  31803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31804. type: string
  31805. type: object
  31806. secretAccessKeySecretRef:
  31807. description: The SecretAccessKey is used for authentication
  31808. properties:
  31809. key:
  31810. description: |-
  31811. A key in the referenced Secret.
  31812. Some instances of this field may be defaulted, in others it may be required.
  31813. maxLength: 253
  31814. minLength: 1
  31815. pattern: ^[-._a-zA-Z0-9]+$
  31816. type: string
  31817. name:
  31818. description: The name of the Secret resource being referred to.
  31819. maxLength: 253
  31820. minLength: 1
  31821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31822. type: string
  31823. namespace:
  31824. description: |-
  31825. The namespace of the Secret resource being referred to.
  31826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31827. maxLength: 63
  31828. minLength: 1
  31829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31830. type: string
  31831. type: object
  31832. sessionTokenSecretRef:
  31833. description: |-
  31834. The SessionToken used for authentication
  31835. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  31836. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  31837. properties:
  31838. key:
  31839. description: |-
  31840. A key in the referenced Secret.
  31841. Some instances of this field may be defaulted, in others it may be required.
  31842. maxLength: 253
  31843. minLength: 1
  31844. pattern: ^[-._a-zA-Z0-9]+$
  31845. type: string
  31846. name:
  31847. description: The name of the Secret resource being referred to.
  31848. maxLength: 253
  31849. minLength: 1
  31850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31851. type: string
  31852. namespace:
  31853. description: |-
  31854. The namespace of the Secret resource being referred to.
  31855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31856. maxLength: 63
  31857. minLength: 1
  31858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31859. type: string
  31860. type: object
  31861. type: object
  31862. vaultAwsIamServerID:
  31863. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  31864. type: string
  31865. vaultRole:
  31866. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  31867. type: string
  31868. required:
  31869. - vaultRole
  31870. type: object
  31871. jwt:
  31872. description: |-
  31873. Jwt authenticates with Vault by passing role and JWT token using the
  31874. JWT/OIDC authentication method
  31875. properties:
  31876. kubernetesServiceAccountToken:
  31877. description: |-
  31878. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  31879. a token for with the `TokenRequest` API.
  31880. properties:
  31881. audiences:
  31882. description: |-
  31883. Optional audiences field that will be used to request a temporary Kubernetes service
  31884. account token for the service account referenced by `serviceAccountRef`.
  31885. Defaults to a single audience `vault` it not specified.
  31886. Deprecated: use serviceAccountRef.Audiences instead
  31887. items:
  31888. type: string
  31889. type: array
  31890. expirationSeconds:
  31891. description: |-
  31892. Optional expiration time in seconds that will be used to request a temporary
  31893. Kubernetes service account token for the service account referenced by
  31894. `serviceAccountRef`.
  31895. Deprecated: this will be removed in the future.
  31896. Defaults to 10 minutes.
  31897. format: int64
  31898. type: integer
  31899. serviceAccountRef:
  31900. description: Service account field containing the name of a kubernetes ServiceAccount.
  31901. properties:
  31902. audiences:
  31903. description: |-
  31904. Audience specifies the `aud` claim for the service account token
  31905. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  31906. then this audiences will be appended to the list
  31907. items:
  31908. type: string
  31909. type: array
  31910. name:
  31911. description: The name of the ServiceAccount resource being referred to.
  31912. maxLength: 253
  31913. minLength: 1
  31914. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31915. type: string
  31916. namespace:
  31917. description: |-
  31918. Namespace of the resource being referred to.
  31919. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31920. maxLength: 63
  31921. minLength: 1
  31922. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31923. type: string
  31924. required:
  31925. - name
  31926. type: object
  31927. required:
  31928. - serviceAccountRef
  31929. type: object
  31930. path:
  31931. default: jwt
  31932. description: |-
  31933. Path where the JWT authentication backend is mounted
  31934. in Vault, e.g: "jwt"
  31935. type: string
  31936. role:
  31937. description: |-
  31938. Role is a JWT role to authenticate using the JWT/OIDC Vault
  31939. authentication method
  31940. type: string
  31941. secretRef:
  31942. description: |-
  31943. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  31944. authenticate with Vault using the JWT/OIDC authentication method.
  31945. properties:
  31946. key:
  31947. description: |-
  31948. A key in the referenced Secret.
  31949. Some instances of this field may be defaulted, in others it may be required.
  31950. maxLength: 253
  31951. minLength: 1
  31952. pattern: ^[-._a-zA-Z0-9]+$
  31953. type: string
  31954. name:
  31955. description: The name of the Secret resource being referred to.
  31956. maxLength: 253
  31957. minLength: 1
  31958. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  31959. type: string
  31960. namespace:
  31961. description: |-
  31962. The namespace of the Secret resource being referred to.
  31963. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  31964. maxLength: 63
  31965. minLength: 1
  31966. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  31967. type: string
  31968. type: object
  31969. required:
  31970. - path
  31971. type: object
  31972. kubernetes:
  31973. description: |-
  31974. Kubernetes authenticates with Vault by passing the ServiceAccount
  31975. token stored in the named Secret resource to the Vault server.
  31976. properties:
  31977. mountPath:
  31978. default: kubernetes
  31979. description: |-
  31980. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  31981. "kubernetes"
  31982. type: string
  31983. role:
  31984. description: |-
  31985. A required field containing the Vault Role to assume. A Role binds a
  31986. Kubernetes ServiceAccount with a set of Vault policies.
  31987. type: string
  31988. secretRef:
  31989. description: |-
  31990. Optional secret field containing a Kubernetes ServiceAccount JWT used
  31991. for authenticating with Vault. If a name is specified without a key,
  31992. `token` is the default. If one is not specified, the one bound to
  31993. the controller will be used.
  31994. properties:
  31995. key:
  31996. description: |-
  31997. A key in the referenced Secret.
  31998. Some instances of this field may be defaulted, in others it may be required.
  31999. maxLength: 253
  32000. minLength: 1
  32001. pattern: ^[-._a-zA-Z0-9]+$
  32002. type: string
  32003. name:
  32004. description: The name of the Secret resource being referred to.
  32005. maxLength: 253
  32006. minLength: 1
  32007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32008. type: string
  32009. namespace:
  32010. description: |-
  32011. The namespace of the Secret resource being referred to.
  32012. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32013. maxLength: 63
  32014. minLength: 1
  32015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32016. type: string
  32017. type: object
  32018. serviceAccountRef:
  32019. description: |-
  32020. Optional service account field containing the name of a kubernetes ServiceAccount.
  32021. If the service account is specified, the service account secret token JWT will be used
  32022. for authenticating with Vault. If the service account selector is not supplied,
  32023. the secretRef will be used instead.
  32024. properties:
  32025. audiences:
  32026. description: |-
  32027. Audience specifies the `aud` claim for the service account token
  32028. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  32029. then this audiences will be appended to the list
  32030. items:
  32031. type: string
  32032. type: array
  32033. name:
  32034. description: The name of the ServiceAccount resource being referred to.
  32035. maxLength: 253
  32036. minLength: 1
  32037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32038. type: string
  32039. namespace:
  32040. description: |-
  32041. Namespace of the resource being referred to.
  32042. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32043. maxLength: 63
  32044. minLength: 1
  32045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32046. type: string
  32047. required:
  32048. - name
  32049. type: object
  32050. required:
  32051. - mountPath
  32052. - role
  32053. type: object
  32054. ldap:
  32055. description: |-
  32056. Ldap authenticates with Vault by passing username/password pair using
  32057. the LDAP authentication method
  32058. properties:
  32059. path:
  32060. default: ldap
  32061. description: |-
  32062. Path where the LDAP authentication backend is mounted
  32063. in Vault, e.g: "ldap"
  32064. type: string
  32065. secretRef:
  32066. description: |-
  32067. SecretRef to a key in a Secret resource containing password for the LDAP
  32068. user used to authenticate with Vault using the LDAP authentication
  32069. method
  32070. properties:
  32071. key:
  32072. description: |-
  32073. A key in the referenced Secret.
  32074. Some instances of this field may be defaulted, in others it may be required.
  32075. maxLength: 253
  32076. minLength: 1
  32077. pattern: ^[-._a-zA-Z0-9]+$
  32078. type: string
  32079. name:
  32080. description: The name of the Secret resource being referred to.
  32081. maxLength: 253
  32082. minLength: 1
  32083. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32084. type: string
  32085. namespace:
  32086. description: |-
  32087. The namespace of the Secret resource being referred to.
  32088. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32089. maxLength: 63
  32090. minLength: 1
  32091. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32092. type: string
  32093. type: object
  32094. username:
  32095. description: |-
  32096. Username is an LDAP username used to authenticate using the LDAP Vault
  32097. authentication method
  32098. type: string
  32099. required:
  32100. - path
  32101. - username
  32102. type: object
  32103. namespace:
  32104. description: |-
  32105. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  32106. Namespaces is a set of features within Vault Enterprise that allows
  32107. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32108. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32109. This will default to Vault.Namespace field if set, or empty otherwise
  32110. type: string
  32111. tokenSecretRef:
  32112. description: TokenSecretRef authenticates with Vault by presenting a token.
  32113. properties:
  32114. key:
  32115. description: |-
  32116. A key in the referenced Secret.
  32117. Some instances of this field may be defaulted, in others it may be required.
  32118. maxLength: 253
  32119. minLength: 1
  32120. pattern: ^[-._a-zA-Z0-9]+$
  32121. type: string
  32122. name:
  32123. description: The name of the Secret resource being referred to.
  32124. maxLength: 253
  32125. minLength: 1
  32126. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32127. type: string
  32128. namespace:
  32129. description: |-
  32130. The namespace of the Secret resource being referred to.
  32131. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32132. maxLength: 63
  32133. minLength: 1
  32134. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32135. type: string
  32136. type: object
  32137. userPass:
  32138. description: UserPass authenticates with Vault by passing username/password pair
  32139. properties:
  32140. path:
  32141. default: userpass
  32142. description: |-
  32143. Path where the UserPassword authentication backend is mounted
  32144. in Vault, e.g: "userpass"
  32145. type: string
  32146. secretRef:
  32147. description: |-
  32148. SecretRef to a key in a Secret resource containing password for the
  32149. user used to authenticate with Vault using the UserPass authentication
  32150. method
  32151. properties:
  32152. key:
  32153. description: |-
  32154. A key in the referenced Secret.
  32155. Some instances of this field may be defaulted, in others it may be required.
  32156. maxLength: 253
  32157. minLength: 1
  32158. pattern: ^[-._a-zA-Z0-9]+$
  32159. type: string
  32160. name:
  32161. description: The name of the Secret resource being referred to.
  32162. maxLength: 253
  32163. minLength: 1
  32164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32165. type: string
  32166. namespace:
  32167. description: |-
  32168. The namespace of the Secret resource being referred to.
  32169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32170. maxLength: 63
  32171. minLength: 1
  32172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32173. type: string
  32174. type: object
  32175. username:
  32176. description: |-
  32177. Username is a username used to authenticate using the UserPass Vault
  32178. authentication method
  32179. type: string
  32180. required:
  32181. - path
  32182. - username
  32183. type: object
  32184. type: object
  32185. caBundle:
  32186. description: |-
  32187. PEM encoded CA bundle used to validate Vault server certificate. Only used
  32188. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32189. plain HTTP protocol connection. If not set the system root certificates
  32190. are used to validate the TLS connection.
  32191. format: byte
  32192. type: string
  32193. caProvider:
  32194. description: The provider for the CA bundle to use to validate Vault server certificate.
  32195. properties:
  32196. key:
  32197. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32198. maxLength: 253
  32199. minLength: 1
  32200. pattern: ^[-._a-zA-Z0-9]+$
  32201. type: string
  32202. name:
  32203. description: The name of the object located at the provider type.
  32204. maxLength: 253
  32205. minLength: 1
  32206. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32207. type: string
  32208. namespace:
  32209. description: |-
  32210. The namespace the Provider type is in.
  32211. Can only be defined when used in a ClusterSecretStore.
  32212. maxLength: 63
  32213. minLength: 1
  32214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32215. type: string
  32216. type:
  32217. description: The type of provider to use such as "Secret", or "ConfigMap".
  32218. enum:
  32219. - Secret
  32220. - ConfigMap
  32221. type: string
  32222. required:
  32223. - name
  32224. - type
  32225. type: object
  32226. checkAndSet:
  32227. description: |-
  32228. CheckAndSet defines the Check-And-Set (CAS) settings for PushSecret operations.
  32229. Only applies to Vault KV v2 stores. When enabled, write operations must include
  32230. the current version of the secret to prevent unintentional overwrites.
  32231. properties:
  32232. required:
  32233. description: |-
  32234. Required when true, all write operations must include a check-and-set parameter.
  32235. This helps prevent unintentional overwrites of secrets.
  32236. type: boolean
  32237. type: object
  32238. forwardInconsistent:
  32239. description: |-
  32240. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  32241. leader instead of simply retrying within a loop. This can increase performance if
  32242. the option is enabled serverside.
  32243. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  32244. type: boolean
  32245. headers:
  32246. additionalProperties:
  32247. type: string
  32248. description: Headers to be added in Vault request
  32249. type: object
  32250. namespace:
  32251. description: |-
  32252. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  32253. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  32254. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  32255. type: string
  32256. path:
  32257. description: |-
  32258. Path is the mount path of the Vault KV backend endpoint, e.g:
  32259. "secret". The v2 KV secret engine version specific "/data" path suffix
  32260. for fetching secrets from Vault is optional and will be appended
  32261. if not present in specified path.
  32262. type: string
  32263. readYourWrites:
  32264. description: |-
  32265. ReadYourWrites ensures isolated read-after-write semantics by
  32266. providing discovered cluster replication states in each request.
  32267. More information about eventual consistency in Vault can be found here
  32268. https://www.vaultproject.io/docs/enterprise/consistency
  32269. type: boolean
  32270. server:
  32271. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  32272. type: string
  32273. tls:
  32274. description: |-
  32275. The configuration used for client side related TLS communication, when the Vault server
  32276. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  32277. This parameter is ignored for plain HTTP protocol connection.
  32278. It's worth noting this configuration is different from the "TLS certificates auth method",
  32279. which is available under the `auth.cert` section.
  32280. properties:
  32281. certSecretRef:
  32282. description: |-
  32283. CertSecretRef is a certificate added to the transport layer
  32284. when communicating with the Vault server.
  32285. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  32286. properties:
  32287. key:
  32288. description: |-
  32289. A key in the referenced Secret.
  32290. Some instances of this field may be defaulted, in others it may be required.
  32291. maxLength: 253
  32292. minLength: 1
  32293. pattern: ^[-._a-zA-Z0-9]+$
  32294. type: string
  32295. name:
  32296. description: The name of the Secret resource being referred to.
  32297. maxLength: 253
  32298. minLength: 1
  32299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32300. type: string
  32301. namespace:
  32302. description: |-
  32303. The namespace of the Secret resource being referred to.
  32304. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32305. maxLength: 63
  32306. minLength: 1
  32307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32308. type: string
  32309. type: object
  32310. keySecretRef:
  32311. description: |-
  32312. KeySecretRef to a key in a Secret resource containing client private key
  32313. added to the transport layer when communicating with the Vault server.
  32314. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  32315. properties:
  32316. key:
  32317. description: |-
  32318. A key in the referenced Secret.
  32319. Some instances of this field may be defaulted, in others it may be required.
  32320. maxLength: 253
  32321. minLength: 1
  32322. pattern: ^[-._a-zA-Z0-9]+$
  32323. type: string
  32324. name:
  32325. description: The name of the Secret resource being referred to.
  32326. maxLength: 253
  32327. minLength: 1
  32328. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32329. type: string
  32330. namespace:
  32331. description: |-
  32332. The namespace of the Secret resource being referred to.
  32333. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32334. maxLength: 63
  32335. minLength: 1
  32336. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32337. type: string
  32338. type: object
  32339. type: object
  32340. version:
  32341. default: v2
  32342. description: |-
  32343. Version is the Vault KV secret engine version. This can be either "v1" or
  32344. "v2". Version defaults to "v2".
  32345. enum:
  32346. - v1
  32347. - v2
  32348. type: string
  32349. required:
  32350. - server
  32351. type: object
  32352. resultType:
  32353. default: Data
  32354. description: |-
  32355. Result type defines which data is returned from the generator.
  32356. By default, it is the "data" section of the Vault API response.
  32357. When using e.g. /auth/token/create the "data" section is empty but
  32358. the "auth" section contains the generated token.
  32359. Please refer to the vault docs regarding the result data structure.
  32360. Additionally, accessing the raw response is possibly by using "Raw" result type.
  32361. enum:
  32362. - Data
  32363. - Auth
  32364. - Raw
  32365. type: string
  32366. retrySettings:
  32367. description: Used to configure http retries if failed
  32368. properties:
  32369. maxRetries:
  32370. format: int32
  32371. type: integer
  32372. retryInterval:
  32373. type: string
  32374. type: object
  32375. required:
  32376. - path
  32377. - provider
  32378. type: object
  32379. type: object
  32380. served: true
  32381. storage: true
  32382. subresources:
  32383. status: {}
  32384. ---
  32385. apiVersion: apiextensions.k8s.io/v1
  32386. kind: CustomResourceDefinition
  32387. metadata:
  32388. annotations:
  32389. controller-gen.kubebuilder.io/version: v0.19.0
  32390. labels:
  32391. external-secrets.io/component: controller
  32392. name: webhooks.generators.external-secrets.io
  32393. spec:
  32394. group: generators.external-secrets.io
  32395. names:
  32396. categories:
  32397. - external-secrets
  32398. - external-secrets-generators
  32399. kind: Webhook
  32400. listKind: WebhookList
  32401. plural: webhooks
  32402. singular: webhook
  32403. scope: Namespaced
  32404. versions:
  32405. - name: v1alpha1
  32406. schema:
  32407. openAPIV3Schema:
  32408. description: |-
  32409. Webhook connects to a third party API server to handle the secrets generation
  32410. configuration parameters in spec.
  32411. You can specify the server, the token, and additional body parameters.
  32412. See documentation for the full API specification for requests and responses.
  32413. properties:
  32414. apiVersion:
  32415. description: |-
  32416. APIVersion defines the versioned schema of this representation of an object.
  32417. Servers should convert recognized schemas to the latest internal value, and
  32418. may reject unrecognized values.
  32419. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  32420. type: string
  32421. kind:
  32422. description: |-
  32423. Kind is a string value representing the REST resource this object represents.
  32424. Servers may infer this from the endpoint the client submits requests to.
  32425. Cannot be updated.
  32426. In CamelCase.
  32427. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  32428. type: string
  32429. metadata:
  32430. type: object
  32431. spec:
  32432. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  32433. properties:
  32434. auth:
  32435. description: Auth specifies a authorization protocol. Only one protocol may be set.
  32436. maxProperties: 1
  32437. minProperties: 1
  32438. properties:
  32439. ntlm:
  32440. description: NTLMProtocol configures the store to use NTLM for auth
  32441. properties:
  32442. passwordSecret:
  32443. description: |-
  32444. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32445. In some instances, `key` is a required field.
  32446. properties:
  32447. key:
  32448. description: |-
  32449. A key in the referenced Secret.
  32450. Some instances of this field may be defaulted, in others it may be required.
  32451. maxLength: 253
  32452. minLength: 1
  32453. pattern: ^[-._a-zA-Z0-9]+$
  32454. type: string
  32455. name:
  32456. description: The name of the Secret resource being referred to.
  32457. maxLength: 253
  32458. minLength: 1
  32459. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32460. type: string
  32461. namespace:
  32462. description: |-
  32463. The namespace of the Secret resource being referred to.
  32464. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32465. maxLength: 63
  32466. minLength: 1
  32467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32468. type: string
  32469. type: object
  32470. usernameSecret:
  32471. description: |-
  32472. SecretKeySelector is a reference to a specific 'key' within a Secret resource.
  32473. In some instances, `key` is a required field.
  32474. properties:
  32475. key:
  32476. description: |-
  32477. A key in the referenced Secret.
  32478. Some instances of this field may be defaulted, in others it may be required.
  32479. maxLength: 253
  32480. minLength: 1
  32481. pattern: ^[-._a-zA-Z0-9]+$
  32482. type: string
  32483. name:
  32484. description: The name of the Secret resource being referred to.
  32485. maxLength: 253
  32486. minLength: 1
  32487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32488. type: string
  32489. namespace:
  32490. description: |-
  32491. The namespace of the Secret resource being referred to.
  32492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  32493. maxLength: 63
  32494. minLength: 1
  32495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32496. type: string
  32497. type: object
  32498. required:
  32499. - passwordSecret
  32500. - usernameSecret
  32501. type: object
  32502. type: object
  32503. body:
  32504. description: Body
  32505. type: string
  32506. caBundle:
  32507. description: |-
  32508. PEM encoded CA bundle used to validate webhook server certificate. Only used
  32509. if the Server URL is using HTTPS protocol. This parameter is ignored for
  32510. plain HTTP protocol connection. If not set the system root certificates
  32511. are used to validate the TLS connection.
  32512. format: byte
  32513. type: string
  32514. caProvider:
  32515. description: The provider for the CA bundle to use to validate webhook server certificate.
  32516. properties:
  32517. key:
  32518. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  32519. maxLength: 253
  32520. minLength: 1
  32521. pattern: ^[-._a-zA-Z0-9]+$
  32522. type: string
  32523. name:
  32524. description: The name of the object located at the provider type.
  32525. maxLength: 253
  32526. minLength: 1
  32527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32528. type: string
  32529. namespace:
  32530. description: The namespace the Provider type is in.
  32531. maxLength: 63
  32532. minLength: 1
  32533. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  32534. type: string
  32535. type:
  32536. description: The type of provider to use such as "Secret", or "ConfigMap".
  32537. enum:
  32538. - Secret
  32539. - ConfigMap
  32540. type: string
  32541. required:
  32542. - name
  32543. - type
  32544. type: object
  32545. headers:
  32546. additionalProperties:
  32547. type: string
  32548. description: Headers
  32549. type: object
  32550. method:
  32551. description: Webhook Method
  32552. type: string
  32553. result:
  32554. description: Result formatting
  32555. properties:
  32556. jsonPath:
  32557. description: Json path of return value
  32558. type: string
  32559. type: object
  32560. secrets:
  32561. description: |-
  32562. Secrets to fill in templates
  32563. These secrets will be passed to the templating function as key value pairs under the given name
  32564. items:
  32565. description: WebhookSecret defines a secret reference that will be used in webhook templates.
  32566. properties:
  32567. name:
  32568. description: Name of this secret in templates
  32569. type: string
  32570. secretRef:
  32571. description: Secret ref to fill in credentials
  32572. properties:
  32573. key:
  32574. description: The key where the token is found.
  32575. maxLength: 253
  32576. minLength: 1
  32577. pattern: ^[-._a-zA-Z0-9]+$
  32578. type: string
  32579. name:
  32580. description: The name of the Secret resource being referred to.
  32581. maxLength: 253
  32582. minLength: 1
  32583. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  32584. type: string
  32585. type: object
  32586. required:
  32587. - name
  32588. - secretRef
  32589. type: object
  32590. type: array
  32591. timeout:
  32592. description: Timeout
  32593. type: string
  32594. url:
  32595. description: Webhook url to call
  32596. type: string
  32597. required:
  32598. - result
  32599. - url
  32600. type: object
  32601. type: object
  32602. served: true
  32603. storage: true
  32604. subresources:
  32605. status: {}