bundle.yaml 980 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536135371353813539135401354113542135431354413545135461354713548135491355013551135521355313554135551355613557135581355913560135611356213563135641356513566135671356813569135701357113572135731357413575135761357713578135791358013581135821358313584135851358613587135881358913590135911359213593135941359513596135971359813599136001360113602136031360413605136061360713608136091361013611136121361313614136151361613617136181361913620136211362213623136241362513626136271362813629136301363113632136331363413635136361363713638136391364013641136421364313644136451364613647136481364913650136511365213653136541365513656136571365813659136601366113662136631366413665136661366713668136691367013671136721367313674136751367613677136781367913680136811368213683136841368513686136871368813689136901369113692136931369413695136961369713698136991370013701137021370313704137051370613707137081370913710137111371213713137141371513716137171371813719137201372113722137231372413725137261372713728137291373013731137321373313734137351373613737137381373913740137411374213743137441374513746137471374813749137501375113752137531375413755137561375713758137591376013761137621376313764137651376613767137681376913770137711377213773137741377513776137771377813779137801378113782137831378413785137861378713788137891379013791137921379313794137951379613797137981379913800138011380213803138041380513806138071380813809138101381113812138131381413815138161381713818138191382013821138221382313824138251382613827138281382913830138311383213833138341383513836138371383813839138401384113842138431384413845138461384713848138491385013851138521385313854138551385613857138581385913860138611386213863138641386513866138671386813869138701387113872138731387413875138761387713878138791388013881138821388313884138851388613887138881388913890138911389213893138941389513896138971389813899139001390113902139031390413905139061390713908139091391013911139121391313914139151391613917139181391913920139211392213923139241392513926139271392813929139301393113932139331393413935139361393713938139391394013941139421394313944139451394613947139481394913950139511395213953139541395513956139571395813959139601396113962139631396413965139661396713968139691397013971139721397313974139751397613977139781397913980139811398213983139841398513986139871398813989139901399113992139931399413995139961399713998139991400014001140021400314004140051400614007140081400914010140111401214013140141401514016140171401814019140201402114022140231402414025140261402714028140291403014031140321403314034140351403614037140381403914040140411404214043140441404514046140471404814049140501405114052140531405414055140561405714058140591406014061140621406314064140651406614067140681406914070140711407214073140741407514076140771407814079140801408114082140831408414085140861408714088140891409014091140921409314094140951409614097140981409914100141011410214103141041410514106141071410814109141101411114112141131411414115141161411714118141191412014121141221412314124141251412614127141281412914130141311413214133141341413514136141371413814139141401414114142141431414414145141461414714148141491415014151141521415314154141551415614157141581415914160141611416214163141641416514166141671416814169141701417114172141731417414175141761417714178141791418014181141821418314184141851418614187141881418914190141911419214193141941419514196141971419814199142001420114202142031420414205142061420714208142091421014211142121421314214142151421614217142181421914220142211422214223142241422514226142271422814229142301423114232142331423414235142361423714238142391424014241142421424314244142451424614247142481424914250142511425214253142541425514256142571425814259142601426114262142631426414265142661426714268142691427014271142721427314274142751427614277142781427914280142811428214283142841428514286142871428814289142901429114292142931429414295142961429714298142991430014301143021430314304143051430614307143081430914310143111431214313143141431514316143171431814319143201432114322143231432414325143261432714328143291433014331143321433314334143351433614337143381433914340143411434214343143441434514346143471434814349143501435114352143531435414355143561435714358143591436014361143621436314364143651436614367143681436914370143711437214373143741437514376143771437814379143801438114382143831438414385143861438714388143891439014391143921439314394143951439614397143981439914400144011440214403144041440514406144071440814409144101441114412144131441414415144161441714418144191442014421144221442314424144251442614427144281442914430144311443214433144341443514436144371443814439144401444114442144431444414445144461444714448144491445014451144521445314454144551445614457144581445914460144611446214463144641446514466144671446814469144701447114472144731447414475144761447714478144791448014481144821448314484144851448614487144881448914490144911449214493144941449514496144971449814499145001450114502145031450414505145061450714508145091451014511145121451314514145151451614517145181451914520145211452214523145241452514526145271452814529145301453114532145331453414535145361453714538145391454014541145421454314544145451454614547145481454914550145511455214553145541455514556145571455814559145601456114562145631456414565145661456714568145691457014571145721457314574145751457614577145781457914580145811458214583145841458514586145871458814589145901459114592145931459414595145961459714598145991460014601146021460314604146051460614607146081460914610146111461214613146141461514616146171461814619146201462114622146231462414625146261462714628146291463014631146321463314634146351463614637146381463914640146411464214643146441464514646146471464814649146501465114652146531465414655146561465714658146591466014661146621466314664146651466614667146681466914670146711467214673146741467514676146771467814679146801468114682146831468414685146861468714688146891469014691146921469314694146951469614697146981469914700147011470214703147041470514706147071470814709147101471114712147131471414715147161471714718147191472014721147221472314724147251472614727147281472914730147311473214733147341473514736147371473814739147401474114742147431474414745147461474714748147491475014751147521475314754147551475614757147581475914760147611476214763147641476514766147671476814769147701477114772147731477414775147761477714778147791478014781147821478314784147851478614787147881478914790147911479214793147941479514796147971479814799148001480114802148031480414805148061480714808148091481014811148121481314814148151481614817148181481914820148211482214823148241482514826148271482814829148301483114832148331483414835148361483714838148391484014841148421484314844148451484614847148481484914850148511485214853148541485514856148571485814859148601486114862148631486414865148661486714868148691487014871148721487314874148751487614877148781487914880148811488214883148841488514886148871488814889148901489114892148931489414895148961489714898148991490014901149021490314904149051490614907149081490914910149111491214913149141491514916149171491814919149201492114922149231492414925149261492714928149291493014931149321493314934149351493614937149381493914940149411494214943149441494514946149471494814949149501495114952149531495414955149561495714958149591496014961149621496314964149651496614967149681496914970149711497214973149741497514976149771497814979149801498114982149831498414985149861498714988149891499014991149921499314994149951499614997149981499915000150011500215003150041500515006150071500815009150101501115012150131501415015150161501715018150191502015021150221502315024150251502615027150281502915030150311503215033150341503515036150371503815039150401504115042150431504415045150461504715048150491505015051150521505315054150551505615057150581505915060150611506215063150641506515066150671506815069150701507115072150731507415075150761507715078150791508015081150821508315084150851508615087150881508915090150911509215093150941509515096150971509815099151001510115102151031510415105151061510715108151091511015111151121511315114151151511615117151181511915120151211512215123151241512515126151271512815129151301513115132151331513415135151361513715138151391514015141151421514315144151451514615147151481514915150151511515215153151541515515156151571515815159151601516115162151631516415165151661516715168151691517015171151721517315174151751517615177151781517915180151811518215183151841518515186151871518815189151901519115192151931519415195151961519715198151991520015201152021520315204152051520615207152081520915210152111521215213152141521515216152171521815219152201522115222152231522415225152261522715228152291523015231152321523315234152351523615237152381523915240152411524215243152441524515246152471524815249152501525115252152531525415255152561525715258152591526015261152621526315264152651526615267152681526915270152711527215273152741527515276152771527815279152801528115282152831528415285152861528715288152891529015291152921529315294152951529615297152981529915300153011530215303153041530515306153071530815309153101531115312153131531415315153161531715318153191532015321153221532315324153251532615327153281532915330153311533215333153341533515336153371533815339153401534115342153431534415345153461534715348153491535015351153521535315354153551535615357153581535915360153611536215363153641536515366153671536815369153701537115372153731537415375153761537715378153791538015381153821538315384153851538615387153881538915390153911539215393153941539515396153971539815399154001540115402154031540415405154061540715408154091541015411154121541315414154151541615417154181541915420154211542215423154241542515426154271542815429154301543115432154331543415435154361543715438154391544015441154421544315444154451544615447154481544915450154511545215453154541545515456154571545815459154601546115462154631546415465154661546715468154691547015471154721547315474154751547615477154781547915480154811548215483154841548515486154871548815489154901549115492154931549415495154961549715498154991550015501155021550315504155051550615507155081550915510155111551215513155141551515516155171551815519155201552115522155231552415525155261552715528155291553015531155321553315534155351553615537155381553915540155411554215543155441554515546155471554815549155501555115552155531555415555155561555715558155591556015561155621556315564155651556615567155681556915570155711557215573155741557515576155771557815579155801558115582155831558415585155861558715588155891559015591155921559315594155951559615597155981559915600156011560215603156041560515606156071560815609156101561115612156131561415615156161561715618156191562015621156221562315624156251562615627156281562915630156311563215633156341563515636156371563815639156401564115642156431564415645156461564715648156491565015651156521565315654156551565615657156581565915660156611566215663156641566515666156671566815669156701567115672156731567415675156761567715678156791568015681156821568315684156851568615687156881568915690156911569215693156941569515696156971569815699157001570115702157031570415705157061570715708157091571015711157121571315714157151571615717157181571915720157211572215723157241572515726157271572815729157301573115732157331573415735157361573715738157391574015741157421574315744157451574615747157481574915750157511575215753157541575515756157571575815759157601576115762157631576415765157661576715768157691577015771157721577315774157751577615777157781577915780157811578215783157841578515786157871578815789157901579115792157931579415795157961579715798157991580015801158021580315804158051580615807158081580915810158111581215813158141581515816158171581815819158201582115822158231582415825158261582715828158291583015831158321583315834158351583615837158381583915840158411584215843158441584515846158471584815849158501585115852158531585415855158561585715858158591586015861158621586315864158651586615867158681586915870158711587215873158741587515876158771587815879158801588115882158831588415885158861588715888158891589015891158921589315894158951589615897158981589915900159011590215903159041590515906159071590815909159101591115912159131591415915159161591715918159191592015921159221592315924159251592615927159281592915930159311593215933159341593515936159371593815939159401594115942159431594415945159461594715948159491595015951159521595315954159551595615957159581595915960159611596215963159641596515966159671596815969159701597115972159731597415975159761597715978159791598015981159821598315984159851598615987159881598915990159911599215993159941599515996159971599815999160001600116002160031600416005160061600716008160091601016011160121601316014160151601616017160181601916020160211602216023160241602516026160271602816029160301603116032160331603416035160361603716038160391604016041160421604316044160451604616047160481604916050160511605216053160541605516056160571605816059160601606116062160631606416065160661606716068160691607016071160721607316074160751607616077160781607916080160811608216083160841608516086160871608816089160901609116092160931609416095160961609716098160991610016101161021610316104161051610616107161081610916110161111611216113161141611516116161171611816119161201612116122161231612416125161261612716128161291613016131161321613316134161351613616137161381613916140161411614216143161441614516146161471614816149161501615116152161531615416155161561615716158161591616016161161621616316164161651616616167161681616916170161711617216173161741617516176161771617816179161801618116182161831618416185161861618716188161891619016191161921619316194161951619616197161981619916200162011620216203162041620516206162071620816209162101621116212162131621416215162161621716218162191622016221162221622316224162251622616227162281622916230162311623216233162341623516236162371623816239162401624116242162431624416245162461624716248162491625016251162521625316254162551625616257162581625916260162611626216263162641626516266162671626816269162701627116272162731627416275162761627716278162791628016281162821628316284162851628616287162881628916290162911629216293162941629516296162971629816299163001630116302163031630416305163061630716308163091631016311163121631316314163151631616317163181631916320163211632216323163241632516326163271632816329163301633116332163331633416335163361633716338163391634016341163421634316344163451634616347163481634916350163511635216353163541635516356163571635816359163601636116362163631636416365163661636716368163691637016371163721637316374163751637616377163781637916380163811638216383163841638516386163871638816389163901639116392163931639416395163961639716398163991640016401164021640316404164051640616407164081640916410164111641216413164141641516416164171641816419164201642116422164231642416425164261642716428164291643016431164321643316434164351643616437164381643916440164411644216443164441644516446164471644816449164501645116452164531645416455164561645716458164591646016461164621646316464164651646616467164681646916470164711647216473164741647516476164771647816479164801648116482164831648416485164861648716488164891649016491164921649316494164951649616497164981649916500165011650216503165041650516506165071650816509165101651116512165131651416515165161651716518165191652016521165221652316524165251652616527165281652916530165311653216533165341653516536165371653816539165401654116542165431654416545165461654716548165491655016551165521655316554165551655616557165581655916560165611656216563165641656516566165671656816569165701657116572165731657416575165761657716578165791658016581165821658316584165851658616587165881658916590165911659216593165941659516596165971659816599166001660116602166031660416605166061660716608166091661016611166121661316614166151661616617166181661916620166211662216623166241662516626166271662816629166301663116632166331663416635166361663716638166391664016641166421664316644166451664616647166481664916650166511665216653166541665516656166571665816659166601666116662166631666416665166661666716668166691667016671166721667316674166751667616677166781667916680166811668216683166841668516686166871668816689166901669116692166931669416695166961669716698166991670016701167021670316704167051670616707167081670916710167111671216713167141671516716167171671816719167201672116722167231672416725167261672716728167291673016731167321673316734167351673616737167381673916740167411674216743167441674516746167471674816749167501675116752167531675416755167561675716758167591676016761167621676316764167651676616767167681676916770167711677216773167741677516776167771677816779167801678116782167831678416785167861678716788167891679016791167921679316794167951679616797167981679916800168011680216803168041680516806168071680816809168101681116812168131681416815168161681716818168191682016821168221682316824168251682616827168281682916830168311683216833168341683516836168371683816839168401684116842168431684416845168461684716848168491685016851168521685316854168551685616857168581685916860168611686216863168641686516866168671686816869168701687116872168731687416875168761687716878168791688016881168821688316884168851688616887168881688916890168911689216893168941689516896168971689816899169001690116902169031690416905169061690716908169091691016911169121691316914169151691616917169181691916920169211692216923169241692516926169271692816929169301693116932169331693416935169361693716938169391694016941169421694316944169451694616947169481694916950169511695216953169541695516956169571695816959169601696116962169631696416965169661696716968169691697016971169721697316974169751697616977169781697916980169811698216983169841698516986169871698816989169901699116992169931699416995169961699716998169991700017001170021700317004170051700617007170081700917010170111701217013170141701517016170171701817019170201702117022170231702417025170261702717028170291703017031170321703317034170351703617037170381703917040170411704217043170441704517046170471704817049170501705117052170531705417055170561705717058170591706017061170621706317064170651706617067170681706917070170711707217073170741707517076170771707817079170801708117082170831708417085170861708717088170891709017091170921709317094170951709617097170981709917100171011710217103171041710517106171071710817109171101711117112171131711417115171161711717118171191712017121171221712317124171251712617127171281712917130171311713217133171341713517136171371713817139171401714117142171431714417145171461714717148171491715017151171521715317154171551715617157171581715917160171611716217163171641716517166171671716817169171701717117172171731717417175171761717717178171791718017181171821718317184171851718617187171881718917190171911719217193171941719517196171971719817199172001720117202172031720417205172061720717208172091721017211172121721317214172151721617217172181721917220172211722217223172241722517226172271722817229172301723117232172331723417235172361723717238172391724017241172421724317244172451724617247172481724917250172511725217253172541725517256172571725817259172601726117262172631726417265172661726717268172691727017271172721727317274172751727617277172781727917280172811728217283172841728517286172871728817289172901729117292172931729417295172961729717298172991730017301173021730317304173051730617307173081730917310173111731217313173141731517316173171731817319173201732117322173231732417325173261732717328173291733017331173321733317334173351733617337173381733917340173411734217343173441734517346173471734817349173501735117352173531735417355173561735717358
  1. apiVersion: apiextensions.k8s.io/v1
  2. kind: CustomResourceDefinition
  3. metadata:
  4. annotations:
  5. controller-gen.kubebuilder.io/version: v0.16.5
  6. labels:
  7. external-secrets.io/component: controller
  8. name: clusterexternalsecrets.external-secrets.io
  9. spec:
  10. group: external-secrets.io
  11. names:
  12. categories:
  13. - external-secrets
  14. kind: ClusterExternalSecret
  15. listKind: ClusterExternalSecretList
  16. plural: clusterexternalsecrets
  17. shortNames:
  18. - ces
  19. singular: clusterexternalsecret
  20. scope: Cluster
  21. versions:
  22. - additionalPrinterColumns:
  23. - jsonPath: .spec.externalSecretSpec.secretStoreRef.name
  24. name: Store
  25. type: string
  26. - jsonPath: .spec.refreshTime
  27. name: Refresh Interval
  28. type: string
  29. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  30. name: Ready
  31. type: string
  32. name: v1beta1
  33. schema:
  34. openAPIV3Schema:
  35. description: ClusterExternalSecret is the Schema for the clusterexternalsecrets API.
  36. properties:
  37. apiVersion:
  38. description: |-
  39. APIVersion defines the versioned schema of this representation of an object.
  40. Servers should convert recognized schemas to the latest internal value, and
  41. may reject unrecognized values.
  42. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  43. type: string
  44. kind:
  45. description: |-
  46. Kind is a string value representing the REST resource this object represents.
  47. Servers may infer this from the endpoint the client submits requests to.
  48. Cannot be updated.
  49. In CamelCase.
  50. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  51. type: string
  52. metadata:
  53. type: object
  54. spec:
  55. description: ClusterExternalSecretSpec defines the desired state of ClusterExternalSecret.
  56. properties:
  57. externalSecretMetadata:
  58. description: The metadata of the external secrets to be created
  59. properties:
  60. annotations:
  61. additionalProperties:
  62. type: string
  63. type: object
  64. labels:
  65. additionalProperties:
  66. type: string
  67. type: object
  68. type: object
  69. externalSecretName:
  70. description: |-
  71. The name of the external secrets to be created.
  72. Defaults to the name of the ClusterExternalSecret
  73. maxLength: 253
  74. minLength: 1
  75. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  76. type: string
  77. externalSecretSpec:
  78. description: The spec for the ExternalSecrets to be created
  79. properties:
  80. data:
  81. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  82. items:
  83. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  84. properties:
  85. remoteRef:
  86. description: |-
  87. RemoteRef points to the remote secret and defines
  88. which secret (version/property/..) to fetch.
  89. properties:
  90. conversionStrategy:
  91. default: Default
  92. description: Used to define a conversion Strategy
  93. enum:
  94. - Default
  95. - Unicode
  96. type: string
  97. decodingStrategy:
  98. default: None
  99. description: Used to define a decoding Strategy
  100. enum:
  101. - Auto
  102. - Base64
  103. - Base64URL
  104. - None
  105. type: string
  106. key:
  107. description: Key is the key used in the Provider, mandatory
  108. type: string
  109. metadataPolicy:
  110. default: None
  111. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  112. enum:
  113. - None
  114. - Fetch
  115. type: string
  116. property:
  117. description: Used to select a specific property of the Provider value (if a map), if supported
  118. type: string
  119. version:
  120. description: Used to select a specific version of the Provider value, if supported
  121. type: string
  122. required:
  123. - key
  124. type: object
  125. secretKey:
  126. description: The key in the Kubernetes Secret to store the value.
  127. maxLength: 253
  128. minLength: 1
  129. pattern: ^[-._a-zA-Z0-9]+$
  130. type: string
  131. sourceRef:
  132. description: |-
  133. SourceRef allows you to override the source
  134. from which the value will be pulled.
  135. maxProperties: 1
  136. properties:
  137. generatorRef:
  138. description: |-
  139. GeneratorRef points to a generator custom resource.
  140. Deprecated: The generatorRef is not implemented in .data[].
  141. this will be removed with v1.
  142. properties:
  143. apiVersion:
  144. default: generators.external-secrets.io/v1alpha1
  145. description: Specify the apiVersion of the generator resource
  146. type: string
  147. kind:
  148. description: Specify the Kind of the resource, e.g. Password, ACRAccessToken, ClusterGenerator etc.
  149. type: string
  150. name:
  151. description: Specify the name of the generator resource
  152. maxLength: 253
  153. minLength: 1
  154. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  155. type: string
  156. required:
  157. - kind
  158. - name
  159. type: object
  160. storeRef:
  161. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  162. properties:
  163. kind:
  164. description: |-
  165. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  166. Defaults to `SecretStore`
  167. enum:
  168. - SecretStore
  169. - ClusterSecretStore
  170. type: string
  171. name:
  172. description: Name of the SecretStore resource
  173. maxLength: 253
  174. minLength: 1
  175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  176. type: string
  177. type: object
  178. type: object
  179. required:
  180. - remoteRef
  181. - secretKey
  182. type: object
  183. type: array
  184. dataFrom:
  185. description: |-
  186. DataFrom is used to fetch all properties from a specific Provider data
  187. If multiple entries are specified, the Secret keys are merged in the specified order
  188. items:
  189. properties:
  190. extract:
  191. description: |-
  192. Used to extract multiple key/value pairs from one secret
  193. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  194. properties:
  195. conversionStrategy:
  196. default: Default
  197. description: Used to define a conversion Strategy
  198. enum:
  199. - Default
  200. - Unicode
  201. type: string
  202. decodingStrategy:
  203. default: None
  204. description: Used to define a decoding Strategy
  205. enum:
  206. - Auto
  207. - Base64
  208. - Base64URL
  209. - None
  210. type: string
  211. key:
  212. description: Key is the key used in the Provider, mandatory
  213. type: string
  214. metadataPolicy:
  215. default: None
  216. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  217. enum:
  218. - None
  219. - Fetch
  220. type: string
  221. property:
  222. description: Used to select a specific property of the Provider value (if a map), if supported
  223. type: string
  224. version:
  225. description: Used to select a specific version of the Provider value, if supported
  226. type: string
  227. required:
  228. - key
  229. type: object
  230. find:
  231. description: |-
  232. Used to find secrets based on tags or regular expressions
  233. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  234. properties:
  235. conversionStrategy:
  236. default: Default
  237. description: Used to define a conversion Strategy
  238. enum:
  239. - Default
  240. - Unicode
  241. type: string
  242. decodingStrategy:
  243. default: None
  244. description: Used to define a decoding Strategy
  245. enum:
  246. - Auto
  247. - Base64
  248. - Base64URL
  249. - None
  250. type: string
  251. name:
  252. description: Finds secrets based on the name.
  253. properties:
  254. regexp:
  255. description: Finds secrets base
  256. type: string
  257. type: object
  258. path:
  259. description: A root path to start the find operations.
  260. type: string
  261. tags:
  262. additionalProperties:
  263. type: string
  264. description: Find secrets based on tags.
  265. type: object
  266. type: object
  267. rewrite:
  268. description: |-
  269. Used to rewrite secret Keys after getting them from the secret Provider
  270. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  271. items:
  272. properties:
  273. regexp:
  274. description: |-
  275. Used to rewrite with regular expressions.
  276. The resulting key will be the output of a regexp.ReplaceAll operation.
  277. properties:
  278. source:
  279. description: Used to define the regular expression of a re.Compiler.
  280. type: string
  281. target:
  282. description: Used to define the target pattern of a ReplaceAll operation.
  283. type: string
  284. required:
  285. - source
  286. - target
  287. type: object
  288. transform:
  289. description: |-
  290. Used to apply string transformation on the secrets.
  291. The resulting key will be the output of the template applied by the operation.
  292. properties:
  293. template:
  294. description: |-
  295. Used to define the template to apply on the secret name.
  296. `.value ` will specify the secret name in the template.
  297. type: string
  298. required:
  299. - template
  300. type: object
  301. type: object
  302. type: array
  303. sourceRef:
  304. description: |-
  305. SourceRef points to a store or generator
  306. which contains secret values ready to use.
  307. Use this in combination with Extract or Find pull values out of
  308. a specific SecretStore.
  309. When sourceRef points to a generator Extract or Find is not supported.
  310. The generator returns a static map of values
  311. maxProperties: 1
  312. properties:
  313. generatorRef:
  314. description: GeneratorRef points to a generator custom resource.
  315. properties:
  316. apiVersion:
  317. default: generators.external-secrets.io/v1alpha1
  318. description: Specify the apiVersion of the generator resource
  319. type: string
  320. kind:
  321. description: Specify the Kind of the resource, e.g. Password, ACRAccessToken, ClusterGenerator etc.
  322. type: string
  323. name:
  324. description: Specify the name of the generator resource
  325. maxLength: 253
  326. minLength: 1
  327. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  328. type: string
  329. required:
  330. - kind
  331. - name
  332. type: object
  333. storeRef:
  334. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  335. properties:
  336. kind:
  337. description: |-
  338. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  339. Defaults to `SecretStore`
  340. enum:
  341. - SecretStore
  342. - ClusterSecretStore
  343. type: string
  344. name:
  345. description: Name of the SecretStore resource
  346. maxLength: 253
  347. minLength: 1
  348. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  349. type: string
  350. type: object
  351. type: object
  352. type: object
  353. type: array
  354. refreshInterval:
  355. default: 1h
  356. description: |-
  357. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  358. specified as Golang Duration strings.
  359. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  360. Example values: "1h", "2h30m", "5d", "10s"
  361. May be set to zero to fetch and create it once. Defaults to 1h.
  362. type: string
  363. secretStoreRef:
  364. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  365. properties:
  366. kind:
  367. description: |-
  368. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  369. Defaults to `SecretStore`
  370. enum:
  371. - SecretStore
  372. - ClusterSecretStore
  373. type: string
  374. name:
  375. description: Name of the SecretStore resource
  376. maxLength: 253
  377. minLength: 1
  378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  379. type: string
  380. type: object
  381. target:
  382. default:
  383. creationPolicy: Owner
  384. deletionPolicy: Retain
  385. description: |-
  386. ExternalSecretTarget defines the Kubernetes Secret to be created
  387. There can be only one target per ExternalSecret.
  388. properties:
  389. creationPolicy:
  390. default: Owner
  391. description: |-
  392. CreationPolicy defines rules on how to create the resulting Secret.
  393. Defaults to "Owner"
  394. enum:
  395. - Owner
  396. - Orphan
  397. - Merge
  398. - None
  399. type: string
  400. deletionPolicy:
  401. default: Retain
  402. description: |-
  403. DeletionPolicy defines rules on how to delete the resulting Secret.
  404. Defaults to "Retain"
  405. enum:
  406. - Delete
  407. - Merge
  408. - Retain
  409. type: string
  410. immutable:
  411. description: Immutable defines if the final secret will be immutable
  412. type: boolean
  413. name:
  414. description: |-
  415. The name of the Secret resource to be managed.
  416. Defaults to the .metadata.name of the ExternalSecret resource
  417. maxLength: 253
  418. minLength: 1
  419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  420. type: string
  421. template:
  422. description: Template defines a blueprint for the created Secret resource.
  423. properties:
  424. data:
  425. additionalProperties:
  426. type: string
  427. type: object
  428. engineVersion:
  429. default: v2
  430. description: |-
  431. EngineVersion specifies the template engine version
  432. that should be used to compile/execute the
  433. template specified in .data and .templateFrom[].
  434. enum:
  435. - v1
  436. - v2
  437. type: string
  438. mergePolicy:
  439. default: Replace
  440. enum:
  441. - Replace
  442. - Merge
  443. type: string
  444. metadata:
  445. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  446. properties:
  447. annotations:
  448. additionalProperties:
  449. type: string
  450. type: object
  451. labels:
  452. additionalProperties:
  453. type: string
  454. type: object
  455. type: object
  456. templateFrom:
  457. items:
  458. properties:
  459. configMap:
  460. properties:
  461. items:
  462. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  463. items:
  464. properties:
  465. key:
  466. description: A key in the ConfigMap/Secret
  467. maxLength: 253
  468. minLength: 1
  469. pattern: ^[-._a-zA-Z0-9]+$
  470. type: string
  471. templateAs:
  472. default: Values
  473. enum:
  474. - Values
  475. - KeysAndValues
  476. type: string
  477. required:
  478. - key
  479. type: object
  480. type: array
  481. name:
  482. description: The name of the ConfigMap/Secret resource
  483. maxLength: 253
  484. minLength: 1
  485. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  486. type: string
  487. required:
  488. - items
  489. - name
  490. type: object
  491. literal:
  492. type: string
  493. secret:
  494. properties:
  495. items:
  496. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  497. items:
  498. properties:
  499. key:
  500. description: A key in the ConfigMap/Secret
  501. maxLength: 253
  502. minLength: 1
  503. pattern: ^[-._a-zA-Z0-9]+$
  504. type: string
  505. templateAs:
  506. default: Values
  507. enum:
  508. - Values
  509. - KeysAndValues
  510. type: string
  511. required:
  512. - key
  513. type: object
  514. type: array
  515. name:
  516. description: The name of the ConfigMap/Secret resource
  517. maxLength: 253
  518. minLength: 1
  519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  520. type: string
  521. required:
  522. - items
  523. - name
  524. type: object
  525. target:
  526. default: Data
  527. enum:
  528. - Data
  529. - Annotations
  530. - Labels
  531. type: string
  532. type: object
  533. type: array
  534. type:
  535. type: string
  536. type: object
  537. type: object
  538. type: object
  539. namespaceSelector:
  540. description: |-
  541. The labels to select by to find the Namespaces to create the ExternalSecrets in.
  542. Deprecated: Use NamespaceSelectors instead.
  543. properties:
  544. matchExpressions:
  545. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  546. items:
  547. description: |-
  548. A label selector requirement is a selector that contains values, a key, and an operator that
  549. relates the key and values.
  550. properties:
  551. key:
  552. description: key is the label key that the selector applies to.
  553. type: string
  554. operator:
  555. description: |-
  556. operator represents a key's relationship to a set of values.
  557. Valid operators are In, NotIn, Exists and DoesNotExist.
  558. type: string
  559. values:
  560. description: |-
  561. values is an array of string values. If the operator is In or NotIn,
  562. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  563. the values array must be empty. This array is replaced during a strategic
  564. merge patch.
  565. items:
  566. type: string
  567. type: array
  568. x-kubernetes-list-type: atomic
  569. required:
  570. - key
  571. - operator
  572. type: object
  573. type: array
  574. x-kubernetes-list-type: atomic
  575. matchLabels:
  576. additionalProperties:
  577. type: string
  578. description: |-
  579. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  580. map is equivalent to an element of matchExpressions, whose key field is "key", the
  581. operator is "In", and the values array contains only "value". The requirements are ANDed.
  582. type: object
  583. type: object
  584. x-kubernetes-map-type: atomic
  585. namespaceSelectors:
  586. description: A list of labels to select by to find the Namespaces to create the ExternalSecrets in. The selectors are ORed.
  587. items:
  588. description: |-
  589. A label selector is a label query over a set of resources. The result of matchLabels and
  590. matchExpressions are ANDed. An empty label selector matches all objects. A null
  591. label selector matches no objects.
  592. properties:
  593. matchExpressions:
  594. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  595. items:
  596. description: |-
  597. A label selector requirement is a selector that contains values, a key, and an operator that
  598. relates the key and values.
  599. properties:
  600. key:
  601. description: key is the label key that the selector applies to.
  602. type: string
  603. operator:
  604. description: |-
  605. operator represents a key's relationship to a set of values.
  606. Valid operators are In, NotIn, Exists and DoesNotExist.
  607. type: string
  608. values:
  609. description: |-
  610. values is an array of string values. If the operator is In or NotIn,
  611. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  612. the values array must be empty. This array is replaced during a strategic
  613. merge patch.
  614. items:
  615. type: string
  616. type: array
  617. x-kubernetes-list-type: atomic
  618. required:
  619. - key
  620. - operator
  621. type: object
  622. type: array
  623. x-kubernetes-list-type: atomic
  624. matchLabels:
  625. additionalProperties:
  626. type: string
  627. description: |-
  628. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  629. map is equivalent to an element of matchExpressions, whose key field is "key", the
  630. operator is "In", and the values array contains only "value". The requirements are ANDed.
  631. type: object
  632. type: object
  633. x-kubernetes-map-type: atomic
  634. type: array
  635. namespaces:
  636. description: Choose namespaces by name. This field is ORed with anything that NamespaceSelectors ends up choosing.
  637. items:
  638. maxLength: 63
  639. minLength: 1
  640. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  641. type: string
  642. type: array
  643. refreshTime:
  644. description: The time in which the controller should reconcile its objects and recheck namespaces for labels.
  645. type: string
  646. required:
  647. - externalSecretSpec
  648. type: object
  649. status:
  650. description: ClusterExternalSecretStatus defines the observed state of ClusterExternalSecret.
  651. properties:
  652. conditions:
  653. items:
  654. properties:
  655. message:
  656. type: string
  657. status:
  658. type: string
  659. type:
  660. type: string
  661. required:
  662. - status
  663. - type
  664. type: object
  665. type: array
  666. externalSecretName:
  667. description: ExternalSecretName is the name of the ExternalSecrets created by the ClusterExternalSecret
  668. type: string
  669. failedNamespaces:
  670. description: Failed namespaces are the namespaces that failed to apply an ExternalSecret
  671. items:
  672. description: ClusterExternalSecretNamespaceFailure represents a failed namespace deployment and it's reason.
  673. properties:
  674. namespace:
  675. description: Namespace is the namespace that failed when trying to apply an ExternalSecret
  676. type: string
  677. reason:
  678. description: Reason is why the ExternalSecret failed to apply to the namespace
  679. type: string
  680. required:
  681. - namespace
  682. type: object
  683. type: array
  684. provisionedNamespaces:
  685. description: ProvisionedNamespaces are the namespaces where the ClusterExternalSecret has secrets
  686. items:
  687. type: string
  688. type: array
  689. type: object
  690. type: object
  691. served: true
  692. storage: true
  693. subresources:
  694. status: {}
  695. conversion:
  696. strategy: Webhook
  697. webhook:
  698. conversionReviewVersions:
  699. - v1
  700. clientConfig:
  701. service:
  702. name: kubernetes
  703. namespace: default
  704. path: /convert
  705. ---
  706. apiVersion: apiextensions.k8s.io/v1
  707. kind: CustomResourceDefinition
  708. metadata:
  709. annotations:
  710. controller-gen.kubebuilder.io/version: v0.16.5
  711. labels:
  712. external-secrets.io/component: controller
  713. name: clustersecretstores.external-secrets.io
  714. spec:
  715. group: external-secrets.io
  716. names:
  717. categories:
  718. - external-secrets
  719. kind: ClusterSecretStore
  720. listKind: ClusterSecretStoreList
  721. plural: clustersecretstores
  722. shortNames:
  723. - css
  724. singular: clustersecretstore
  725. scope: Cluster
  726. versions:
  727. - additionalPrinterColumns:
  728. - jsonPath: .metadata.creationTimestamp
  729. name: AGE
  730. type: date
  731. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  732. name: Status
  733. type: string
  734. deprecated: true
  735. name: v1alpha1
  736. schema:
  737. openAPIV3Schema:
  738. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  739. properties:
  740. apiVersion:
  741. description: |-
  742. APIVersion defines the versioned schema of this representation of an object.
  743. Servers should convert recognized schemas to the latest internal value, and
  744. may reject unrecognized values.
  745. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  746. type: string
  747. kind:
  748. description: |-
  749. Kind is a string value representing the REST resource this object represents.
  750. Servers may infer this from the endpoint the client submits requests to.
  751. Cannot be updated.
  752. In CamelCase.
  753. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  754. type: string
  755. metadata:
  756. type: object
  757. spec:
  758. description: SecretStoreSpec defines the desired state of SecretStore.
  759. properties:
  760. controller:
  761. description: |-
  762. Used to select the correct ESO controller (think: ingress.ingressClassName)
  763. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  764. type: string
  765. provider:
  766. description: Used to configure the provider. Only one provider may be set
  767. maxProperties: 1
  768. minProperties: 1
  769. properties:
  770. akeyless:
  771. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  772. properties:
  773. akeylessGWApiURL:
  774. description: Akeyless GW API Url from which the secrets to be fetched from.
  775. type: string
  776. authSecretRef:
  777. description: Auth configures how the operator authenticates with Akeyless.
  778. properties:
  779. kubernetesAuth:
  780. description: |-
  781. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  782. token stored in the named Secret resource.
  783. properties:
  784. accessID:
  785. description: the Akeyless Kubernetes auth-method access-id
  786. type: string
  787. k8sConfName:
  788. description: Kubernetes-auth configuration name in Akeyless-Gateway
  789. type: string
  790. secretRef:
  791. description: |-
  792. Optional secret field containing a Kubernetes ServiceAccount JWT used
  793. for authenticating with Akeyless. If a name is specified without a key,
  794. `token` is the default. If one is not specified, the one bound to
  795. the controller will be used.
  796. properties:
  797. key:
  798. description: |-
  799. A key in the referenced Secret.
  800. Some instances of this field may be defaulted, in others it may be required.
  801. maxLength: 253
  802. minLength: 1
  803. pattern: ^[-._a-zA-Z0-9]+$
  804. type: string
  805. name:
  806. description: The name of the Secret resource being referred to.
  807. maxLength: 253
  808. minLength: 1
  809. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  810. type: string
  811. namespace:
  812. description: |-
  813. The namespace of the Secret resource being referred to.
  814. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  815. maxLength: 63
  816. minLength: 1
  817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  818. type: string
  819. type: object
  820. serviceAccountRef:
  821. description: |-
  822. Optional service account field containing the name of a kubernetes ServiceAccount.
  823. If the service account is specified, the service account secret token JWT will be used
  824. for authenticating with Akeyless. If the service account selector is not supplied,
  825. the secretRef will be used instead.
  826. properties:
  827. audiences:
  828. description: |-
  829. Audience specifies the `aud` claim for the service account token
  830. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  831. then this audiences will be appended to the list
  832. items:
  833. type: string
  834. type: array
  835. name:
  836. description: The name of the ServiceAccount resource being referred to.
  837. maxLength: 253
  838. minLength: 1
  839. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  840. type: string
  841. namespace:
  842. description: |-
  843. Namespace of the resource being referred to.
  844. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  845. maxLength: 63
  846. minLength: 1
  847. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  848. type: string
  849. required:
  850. - name
  851. type: object
  852. required:
  853. - accessID
  854. - k8sConfName
  855. type: object
  856. secretRef:
  857. description: |-
  858. Reference to a Secret that contains the details
  859. to authenticate with Akeyless.
  860. properties:
  861. accessID:
  862. description: The SecretAccessID is used for authentication
  863. properties:
  864. key:
  865. description: |-
  866. A key in the referenced Secret.
  867. Some instances of this field may be defaulted, in others it may be required.
  868. maxLength: 253
  869. minLength: 1
  870. pattern: ^[-._a-zA-Z0-9]+$
  871. type: string
  872. name:
  873. description: The name of the Secret resource being referred to.
  874. maxLength: 253
  875. minLength: 1
  876. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  877. type: string
  878. namespace:
  879. description: |-
  880. The namespace of the Secret resource being referred to.
  881. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  882. maxLength: 63
  883. minLength: 1
  884. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  885. type: string
  886. type: object
  887. accessType:
  888. description: |-
  889. A reference to a specific 'key' within a Secret resource.
  890. In some instances, `key` is a required field.
  891. properties:
  892. key:
  893. description: |-
  894. A key in the referenced Secret.
  895. Some instances of this field may be defaulted, in others it may be required.
  896. maxLength: 253
  897. minLength: 1
  898. pattern: ^[-._a-zA-Z0-9]+$
  899. type: string
  900. name:
  901. description: The name of the Secret resource being referred to.
  902. maxLength: 253
  903. minLength: 1
  904. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  905. type: string
  906. namespace:
  907. description: |-
  908. The namespace of the Secret resource being referred to.
  909. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  910. maxLength: 63
  911. minLength: 1
  912. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  913. type: string
  914. type: object
  915. accessTypeParam:
  916. description: |-
  917. A reference to a specific 'key' within a Secret resource.
  918. In some instances, `key` is a required field.
  919. properties:
  920. key:
  921. description: |-
  922. A key in the referenced Secret.
  923. Some instances of this field may be defaulted, in others it may be required.
  924. maxLength: 253
  925. minLength: 1
  926. pattern: ^[-._a-zA-Z0-9]+$
  927. type: string
  928. name:
  929. description: The name of the Secret resource being referred to.
  930. maxLength: 253
  931. minLength: 1
  932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  933. type: string
  934. namespace:
  935. description: |-
  936. The namespace of the Secret resource being referred to.
  937. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  938. maxLength: 63
  939. minLength: 1
  940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  941. type: string
  942. type: object
  943. type: object
  944. type: object
  945. caBundle:
  946. description: |-
  947. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  948. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  949. are used to validate the TLS connection.
  950. format: byte
  951. type: string
  952. caProvider:
  953. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  954. properties:
  955. key:
  956. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  957. maxLength: 253
  958. minLength: 1
  959. pattern: ^[-._a-zA-Z0-9]+$
  960. type: string
  961. name:
  962. description: The name of the object located at the provider type.
  963. maxLength: 253
  964. minLength: 1
  965. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  966. type: string
  967. namespace:
  968. description: The namespace the Provider type is in.
  969. maxLength: 63
  970. minLength: 1
  971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  972. type: string
  973. type:
  974. description: The type of provider to use such as "Secret", or "ConfigMap".
  975. enum:
  976. - Secret
  977. - ConfigMap
  978. type: string
  979. required:
  980. - name
  981. - type
  982. type: object
  983. required:
  984. - akeylessGWApiURL
  985. - authSecretRef
  986. type: object
  987. alibaba:
  988. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  989. properties:
  990. auth:
  991. description: AlibabaAuth contains a secretRef for credentials.
  992. properties:
  993. rrsa:
  994. description: Authenticate against Alibaba using RRSA.
  995. properties:
  996. oidcProviderArn:
  997. type: string
  998. oidcTokenFilePath:
  999. type: string
  1000. roleArn:
  1001. type: string
  1002. sessionName:
  1003. type: string
  1004. required:
  1005. - oidcProviderArn
  1006. - oidcTokenFilePath
  1007. - roleArn
  1008. - sessionName
  1009. type: object
  1010. secretRef:
  1011. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  1012. properties:
  1013. accessKeyIDSecretRef:
  1014. description: The AccessKeyID is used for authentication
  1015. properties:
  1016. key:
  1017. description: |-
  1018. A key in the referenced Secret.
  1019. Some instances of this field may be defaulted, in others it may be required.
  1020. maxLength: 253
  1021. minLength: 1
  1022. pattern: ^[-._a-zA-Z0-9]+$
  1023. type: string
  1024. name:
  1025. description: The name of the Secret resource being referred to.
  1026. maxLength: 253
  1027. minLength: 1
  1028. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1029. type: string
  1030. namespace:
  1031. description: |-
  1032. The namespace of the Secret resource being referred to.
  1033. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1034. maxLength: 63
  1035. minLength: 1
  1036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1037. type: string
  1038. type: object
  1039. accessKeySecretSecretRef:
  1040. description: The AccessKeySecret is used for authentication
  1041. properties:
  1042. key:
  1043. description: |-
  1044. A key in the referenced Secret.
  1045. Some instances of this field may be defaulted, in others it may be required.
  1046. maxLength: 253
  1047. minLength: 1
  1048. pattern: ^[-._a-zA-Z0-9]+$
  1049. type: string
  1050. name:
  1051. description: The name of the Secret resource being referred to.
  1052. maxLength: 253
  1053. minLength: 1
  1054. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1055. type: string
  1056. namespace:
  1057. description: |-
  1058. The namespace of the Secret resource being referred to.
  1059. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1060. maxLength: 63
  1061. minLength: 1
  1062. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1063. type: string
  1064. type: object
  1065. required:
  1066. - accessKeyIDSecretRef
  1067. - accessKeySecretSecretRef
  1068. type: object
  1069. type: object
  1070. regionID:
  1071. description: Alibaba Region to be used for the provider
  1072. type: string
  1073. required:
  1074. - auth
  1075. - regionID
  1076. type: object
  1077. aws:
  1078. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  1079. properties:
  1080. auth:
  1081. description: |-
  1082. Auth defines the information necessary to authenticate against AWS
  1083. if not set aws sdk will infer credentials from your environment
  1084. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  1085. properties:
  1086. jwt:
  1087. description: Authenticate against AWS using service account tokens.
  1088. properties:
  1089. serviceAccountRef:
  1090. description: A reference to a ServiceAccount resource.
  1091. properties:
  1092. audiences:
  1093. description: |-
  1094. Audience specifies the `aud` claim for the service account token
  1095. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  1096. then this audiences will be appended to the list
  1097. items:
  1098. type: string
  1099. type: array
  1100. name:
  1101. description: The name of the ServiceAccount resource being referred to.
  1102. maxLength: 253
  1103. minLength: 1
  1104. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1105. type: string
  1106. namespace:
  1107. description: |-
  1108. Namespace of the resource being referred to.
  1109. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1110. maxLength: 63
  1111. minLength: 1
  1112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1113. type: string
  1114. required:
  1115. - name
  1116. type: object
  1117. type: object
  1118. secretRef:
  1119. description: |-
  1120. AWSAuthSecretRef holds secret references for AWS credentials
  1121. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  1122. properties:
  1123. accessKeyIDSecretRef:
  1124. description: The AccessKeyID is used for authentication
  1125. properties:
  1126. key:
  1127. description: |-
  1128. A key in the referenced Secret.
  1129. Some instances of this field may be defaulted, in others it may be required.
  1130. maxLength: 253
  1131. minLength: 1
  1132. pattern: ^[-._a-zA-Z0-9]+$
  1133. type: string
  1134. name:
  1135. description: The name of the Secret resource being referred to.
  1136. maxLength: 253
  1137. minLength: 1
  1138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1139. type: string
  1140. namespace:
  1141. description: |-
  1142. The namespace of the Secret resource being referred to.
  1143. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1144. maxLength: 63
  1145. minLength: 1
  1146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1147. type: string
  1148. type: object
  1149. secretAccessKeySecretRef:
  1150. description: The SecretAccessKey is used for authentication
  1151. properties:
  1152. key:
  1153. description: |-
  1154. A key in the referenced Secret.
  1155. Some instances of this field may be defaulted, in others it may be required.
  1156. maxLength: 253
  1157. minLength: 1
  1158. pattern: ^[-._a-zA-Z0-9]+$
  1159. type: string
  1160. name:
  1161. description: The name of the Secret resource being referred to.
  1162. maxLength: 253
  1163. minLength: 1
  1164. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1165. type: string
  1166. namespace:
  1167. description: |-
  1168. The namespace of the Secret resource being referred to.
  1169. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1170. maxLength: 63
  1171. minLength: 1
  1172. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1173. type: string
  1174. type: object
  1175. type: object
  1176. type: object
  1177. region:
  1178. description: AWS Region to be used for the provider
  1179. type: string
  1180. role:
  1181. description: Role is a Role ARN which the SecretManager provider will assume
  1182. type: string
  1183. service:
  1184. description: Service defines which service should be used to fetch the secrets
  1185. enum:
  1186. - SecretsManager
  1187. - ParameterStore
  1188. type: string
  1189. required:
  1190. - region
  1191. - service
  1192. type: object
  1193. azurekv:
  1194. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  1195. properties:
  1196. authSecretRef:
  1197. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  1198. properties:
  1199. clientId:
  1200. description: The Azure clientId of the service principle used for authentication.
  1201. properties:
  1202. key:
  1203. description: |-
  1204. A key in the referenced Secret.
  1205. Some instances of this field may be defaulted, in others it may be required.
  1206. maxLength: 253
  1207. minLength: 1
  1208. pattern: ^[-._a-zA-Z0-9]+$
  1209. type: string
  1210. name:
  1211. description: The name of the Secret resource being referred to.
  1212. maxLength: 253
  1213. minLength: 1
  1214. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1215. type: string
  1216. namespace:
  1217. description: |-
  1218. The namespace of the Secret resource being referred to.
  1219. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1220. maxLength: 63
  1221. minLength: 1
  1222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1223. type: string
  1224. type: object
  1225. clientSecret:
  1226. description: The Azure ClientSecret of the service principle used for authentication.
  1227. properties:
  1228. key:
  1229. description: |-
  1230. A key in the referenced Secret.
  1231. Some instances of this field may be defaulted, in others it may be required.
  1232. maxLength: 253
  1233. minLength: 1
  1234. pattern: ^[-._a-zA-Z0-9]+$
  1235. type: string
  1236. name:
  1237. description: The name of the Secret resource being referred to.
  1238. maxLength: 253
  1239. minLength: 1
  1240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1241. type: string
  1242. namespace:
  1243. description: |-
  1244. The namespace of the Secret resource being referred to.
  1245. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1246. maxLength: 63
  1247. minLength: 1
  1248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1249. type: string
  1250. type: object
  1251. type: object
  1252. authType:
  1253. default: ServicePrincipal
  1254. description: |-
  1255. Auth type defines how to authenticate to the keyvault service.
  1256. Valid values are:
  1257. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  1258. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  1259. enum:
  1260. - ServicePrincipal
  1261. - ManagedIdentity
  1262. - WorkloadIdentity
  1263. type: string
  1264. identityId:
  1265. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  1266. type: string
  1267. serviceAccountRef:
  1268. description: |-
  1269. ServiceAccountRef specified the service account
  1270. that should be used when authenticating with WorkloadIdentity.
  1271. properties:
  1272. audiences:
  1273. description: |-
  1274. Audience specifies the `aud` claim for the service account token
  1275. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  1276. then this audiences will be appended to the list
  1277. items:
  1278. type: string
  1279. type: array
  1280. name:
  1281. description: The name of the ServiceAccount resource being referred to.
  1282. maxLength: 253
  1283. minLength: 1
  1284. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1285. type: string
  1286. namespace:
  1287. description: |-
  1288. Namespace of the resource being referred to.
  1289. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1290. maxLength: 63
  1291. minLength: 1
  1292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1293. type: string
  1294. required:
  1295. - name
  1296. type: object
  1297. tenantId:
  1298. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  1299. type: string
  1300. vaultUrl:
  1301. description: Vault Url from which the secrets to be fetched from.
  1302. type: string
  1303. required:
  1304. - vaultUrl
  1305. type: object
  1306. fake:
  1307. description: Fake configures a store with static key/value pairs
  1308. properties:
  1309. data:
  1310. items:
  1311. properties:
  1312. key:
  1313. type: string
  1314. value:
  1315. type: string
  1316. valueMap:
  1317. additionalProperties:
  1318. type: string
  1319. type: object
  1320. version:
  1321. type: string
  1322. required:
  1323. - key
  1324. type: object
  1325. type: array
  1326. required:
  1327. - data
  1328. type: object
  1329. gcpsm:
  1330. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  1331. properties:
  1332. auth:
  1333. description: Auth defines the information necessary to authenticate against GCP
  1334. properties:
  1335. secretRef:
  1336. properties:
  1337. secretAccessKeySecretRef:
  1338. description: The SecretAccessKey is used for authentication
  1339. properties:
  1340. key:
  1341. description: |-
  1342. A key in the referenced Secret.
  1343. Some instances of this field may be defaulted, in others it may be required.
  1344. maxLength: 253
  1345. minLength: 1
  1346. pattern: ^[-._a-zA-Z0-9]+$
  1347. type: string
  1348. name:
  1349. description: The name of the Secret resource being referred to.
  1350. maxLength: 253
  1351. minLength: 1
  1352. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1353. type: string
  1354. namespace:
  1355. description: |-
  1356. The namespace of the Secret resource being referred to.
  1357. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1358. maxLength: 63
  1359. minLength: 1
  1360. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1361. type: string
  1362. type: object
  1363. type: object
  1364. workloadIdentity:
  1365. properties:
  1366. clusterLocation:
  1367. type: string
  1368. clusterName:
  1369. type: string
  1370. clusterProjectID:
  1371. type: string
  1372. serviceAccountRef:
  1373. description: A reference to a ServiceAccount resource.
  1374. properties:
  1375. audiences:
  1376. description: |-
  1377. Audience specifies the `aud` claim for the service account token
  1378. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  1379. then this audiences will be appended to the list
  1380. items:
  1381. type: string
  1382. type: array
  1383. name:
  1384. description: The name of the ServiceAccount resource being referred to.
  1385. maxLength: 253
  1386. minLength: 1
  1387. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1388. type: string
  1389. namespace:
  1390. description: |-
  1391. Namespace of the resource being referred to.
  1392. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1393. maxLength: 63
  1394. minLength: 1
  1395. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1396. type: string
  1397. required:
  1398. - name
  1399. type: object
  1400. required:
  1401. - clusterLocation
  1402. - clusterName
  1403. - serviceAccountRef
  1404. type: object
  1405. type: object
  1406. projectID:
  1407. description: ProjectID project where secret is located
  1408. type: string
  1409. type: object
  1410. gitlab:
  1411. description: GitLab configures this store to sync secrets using GitLab Variables provider
  1412. properties:
  1413. auth:
  1414. description: Auth configures how secret-manager authenticates with a GitLab instance.
  1415. properties:
  1416. SecretRef:
  1417. properties:
  1418. accessToken:
  1419. description: AccessToken is used for authentication.
  1420. properties:
  1421. key:
  1422. description: |-
  1423. A key in the referenced Secret.
  1424. Some instances of this field may be defaulted, in others it may be required.
  1425. maxLength: 253
  1426. minLength: 1
  1427. pattern: ^[-._a-zA-Z0-9]+$
  1428. type: string
  1429. name:
  1430. description: The name of the Secret resource being referred to.
  1431. maxLength: 253
  1432. minLength: 1
  1433. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1434. type: string
  1435. namespace:
  1436. description: |-
  1437. The namespace of the Secret resource being referred to.
  1438. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1439. maxLength: 63
  1440. minLength: 1
  1441. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1442. type: string
  1443. type: object
  1444. type: object
  1445. required:
  1446. - SecretRef
  1447. type: object
  1448. projectID:
  1449. description: ProjectID specifies a project where secrets are located.
  1450. type: string
  1451. url:
  1452. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  1453. type: string
  1454. required:
  1455. - auth
  1456. type: object
  1457. ibm:
  1458. description: IBM configures this store to sync secrets using IBM Cloud provider
  1459. properties:
  1460. auth:
  1461. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  1462. properties:
  1463. secretRef:
  1464. properties:
  1465. secretApiKeySecretRef:
  1466. description: The SecretAccessKey is used for authentication
  1467. properties:
  1468. key:
  1469. description: |-
  1470. A key in the referenced Secret.
  1471. Some instances of this field may be defaulted, in others it may be required.
  1472. maxLength: 253
  1473. minLength: 1
  1474. pattern: ^[-._a-zA-Z0-9]+$
  1475. type: string
  1476. name:
  1477. description: The name of the Secret resource being referred to.
  1478. maxLength: 253
  1479. minLength: 1
  1480. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1481. type: string
  1482. namespace:
  1483. description: |-
  1484. The namespace of the Secret resource being referred to.
  1485. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1486. maxLength: 63
  1487. minLength: 1
  1488. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1489. type: string
  1490. type: object
  1491. type: object
  1492. required:
  1493. - secretRef
  1494. type: object
  1495. serviceUrl:
  1496. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  1497. type: string
  1498. required:
  1499. - auth
  1500. type: object
  1501. kubernetes:
  1502. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  1503. properties:
  1504. auth:
  1505. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  1506. maxProperties: 1
  1507. minProperties: 1
  1508. properties:
  1509. cert:
  1510. description: has both clientCert and clientKey as secretKeySelector
  1511. properties:
  1512. clientCert:
  1513. description: |-
  1514. A reference to a specific 'key' within a Secret resource.
  1515. In some instances, `key` is a required field.
  1516. properties:
  1517. key:
  1518. description: |-
  1519. A key in the referenced Secret.
  1520. Some instances of this field may be defaulted, in others it may be required.
  1521. maxLength: 253
  1522. minLength: 1
  1523. pattern: ^[-._a-zA-Z0-9]+$
  1524. type: string
  1525. name:
  1526. description: The name of the Secret resource being referred to.
  1527. maxLength: 253
  1528. minLength: 1
  1529. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1530. type: string
  1531. namespace:
  1532. description: |-
  1533. The namespace of the Secret resource being referred to.
  1534. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1535. maxLength: 63
  1536. minLength: 1
  1537. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1538. type: string
  1539. type: object
  1540. clientKey:
  1541. description: |-
  1542. A reference to a specific 'key' within a Secret resource.
  1543. In some instances, `key` is a required field.
  1544. properties:
  1545. key:
  1546. description: |-
  1547. A key in the referenced Secret.
  1548. Some instances of this field may be defaulted, in others it may be required.
  1549. maxLength: 253
  1550. minLength: 1
  1551. pattern: ^[-._a-zA-Z0-9]+$
  1552. type: string
  1553. name:
  1554. description: The name of the Secret resource being referred to.
  1555. maxLength: 253
  1556. minLength: 1
  1557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1558. type: string
  1559. namespace:
  1560. description: |-
  1561. The namespace of the Secret resource being referred to.
  1562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1563. maxLength: 63
  1564. minLength: 1
  1565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1566. type: string
  1567. type: object
  1568. type: object
  1569. serviceAccount:
  1570. description: points to a service account that should be used for authentication
  1571. properties:
  1572. serviceAccount:
  1573. description: A reference to a ServiceAccount resource.
  1574. properties:
  1575. audiences:
  1576. description: |-
  1577. Audience specifies the `aud` claim for the service account token
  1578. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  1579. then this audiences will be appended to the list
  1580. items:
  1581. type: string
  1582. type: array
  1583. name:
  1584. description: The name of the ServiceAccount resource being referred to.
  1585. maxLength: 253
  1586. minLength: 1
  1587. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1588. type: string
  1589. namespace:
  1590. description: |-
  1591. Namespace of the resource being referred to.
  1592. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1593. maxLength: 63
  1594. minLength: 1
  1595. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1596. type: string
  1597. required:
  1598. - name
  1599. type: object
  1600. type: object
  1601. token:
  1602. description: use static token to authenticate with
  1603. properties:
  1604. bearerToken:
  1605. description: |-
  1606. A reference to a specific 'key' within a Secret resource.
  1607. In some instances, `key` is a required field.
  1608. properties:
  1609. key:
  1610. description: |-
  1611. A key in the referenced Secret.
  1612. Some instances of this field may be defaulted, in others it may be required.
  1613. maxLength: 253
  1614. minLength: 1
  1615. pattern: ^[-._a-zA-Z0-9]+$
  1616. type: string
  1617. name:
  1618. description: The name of the Secret resource being referred to.
  1619. maxLength: 253
  1620. minLength: 1
  1621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1622. type: string
  1623. namespace:
  1624. description: |-
  1625. The namespace of the Secret resource being referred to.
  1626. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1627. maxLength: 63
  1628. minLength: 1
  1629. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1630. type: string
  1631. type: object
  1632. type: object
  1633. type: object
  1634. remoteNamespace:
  1635. default: default
  1636. description: Remote namespace to fetch the secrets from
  1637. maxLength: 63
  1638. minLength: 1
  1639. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1640. type: string
  1641. server:
  1642. description: configures the Kubernetes server Address.
  1643. properties:
  1644. caBundle:
  1645. description: CABundle is a base64-encoded CA certificate
  1646. format: byte
  1647. type: string
  1648. caProvider:
  1649. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  1650. properties:
  1651. key:
  1652. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  1653. maxLength: 253
  1654. minLength: 1
  1655. pattern: ^[-._a-zA-Z0-9]+$
  1656. type: string
  1657. name:
  1658. description: The name of the object located at the provider type.
  1659. maxLength: 253
  1660. minLength: 1
  1661. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1662. type: string
  1663. namespace:
  1664. description: The namespace the Provider type is in.
  1665. maxLength: 63
  1666. minLength: 1
  1667. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1668. type: string
  1669. type:
  1670. description: The type of provider to use such as "Secret", or "ConfigMap".
  1671. enum:
  1672. - Secret
  1673. - ConfigMap
  1674. type: string
  1675. required:
  1676. - name
  1677. - type
  1678. type: object
  1679. url:
  1680. default: kubernetes.default
  1681. description: configures the Kubernetes server Address.
  1682. type: string
  1683. type: object
  1684. required:
  1685. - auth
  1686. type: object
  1687. oracle:
  1688. description: Oracle configures this store to sync secrets using Oracle Vault provider
  1689. properties:
  1690. auth:
  1691. description: |-
  1692. Auth configures how secret-manager authenticates with the Oracle Vault.
  1693. If empty, instance principal is used. Optionally, the authenticating principal type
  1694. and/or user data may be supplied for the use of workload identity and user principal.
  1695. properties:
  1696. secretRef:
  1697. description: SecretRef to pass through sensitive information.
  1698. properties:
  1699. fingerprint:
  1700. description: Fingerprint is the fingerprint of the API private key.
  1701. properties:
  1702. key:
  1703. description: |-
  1704. A key in the referenced Secret.
  1705. Some instances of this field may be defaulted, in others it may be required.
  1706. maxLength: 253
  1707. minLength: 1
  1708. pattern: ^[-._a-zA-Z0-9]+$
  1709. type: string
  1710. name:
  1711. description: The name of the Secret resource being referred to.
  1712. maxLength: 253
  1713. minLength: 1
  1714. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1715. type: string
  1716. namespace:
  1717. description: |-
  1718. The namespace of the Secret resource being referred to.
  1719. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1720. maxLength: 63
  1721. minLength: 1
  1722. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1723. type: string
  1724. type: object
  1725. privatekey:
  1726. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  1727. properties:
  1728. key:
  1729. description: |-
  1730. A key in the referenced Secret.
  1731. Some instances of this field may be defaulted, in others it may be required.
  1732. maxLength: 253
  1733. minLength: 1
  1734. pattern: ^[-._a-zA-Z0-9]+$
  1735. type: string
  1736. name:
  1737. description: The name of the Secret resource being referred to.
  1738. maxLength: 253
  1739. minLength: 1
  1740. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1741. type: string
  1742. namespace:
  1743. description: |-
  1744. The namespace of the Secret resource being referred to.
  1745. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1746. maxLength: 63
  1747. minLength: 1
  1748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1749. type: string
  1750. type: object
  1751. required:
  1752. - fingerprint
  1753. - privatekey
  1754. type: object
  1755. tenancy:
  1756. description: Tenancy is the tenancy OCID where user is located.
  1757. type: string
  1758. user:
  1759. description: User is an access OCID specific to the account.
  1760. type: string
  1761. required:
  1762. - secretRef
  1763. - tenancy
  1764. - user
  1765. type: object
  1766. compartment:
  1767. description: |-
  1768. Compartment is the vault compartment OCID.
  1769. Required for PushSecret
  1770. type: string
  1771. encryptionKey:
  1772. description: |-
  1773. EncryptionKey is the OCID of the encryption key within the vault.
  1774. Required for PushSecret
  1775. type: string
  1776. principalType:
  1777. description: |-
  1778. The type of principal to use for authentication. If left blank, the Auth struct will
  1779. determine the principal type. This optional field must be specified if using
  1780. workload identity.
  1781. enum:
  1782. - ""
  1783. - UserPrincipal
  1784. - InstancePrincipal
  1785. - Workload
  1786. type: string
  1787. region:
  1788. description: Region is the region where vault is located.
  1789. type: string
  1790. serviceAccountRef:
  1791. description: |-
  1792. ServiceAccountRef specified the service account
  1793. that should be used when authenticating with WorkloadIdentity.
  1794. properties:
  1795. audiences:
  1796. description: |-
  1797. Audience specifies the `aud` claim for the service account token
  1798. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  1799. then this audiences will be appended to the list
  1800. items:
  1801. type: string
  1802. type: array
  1803. name:
  1804. description: The name of the ServiceAccount resource being referred to.
  1805. maxLength: 253
  1806. minLength: 1
  1807. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1808. type: string
  1809. namespace:
  1810. description: |-
  1811. Namespace of the resource being referred to.
  1812. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1813. maxLength: 63
  1814. minLength: 1
  1815. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1816. type: string
  1817. required:
  1818. - name
  1819. type: object
  1820. vault:
  1821. description: Vault is the vault's OCID of the specific vault where secret is located.
  1822. type: string
  1823. required:
  1824. - region
  1825. - vault
  1826. type: object
  1827. passworddepot:
  1828. description: Configures a store to sync secrets with a Password Depot instance.
  1829. properties:
  1830. auth:
  1831. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  1832. properties:
  1833. secretRef:
  1834. properties:
  1835. credentials:
  1836. description: Username / Password is used for authentication.
  1837. properties:
  1838. key:
  1839. description: |-
  1840. A key in the referenced Secret.
  1841. Some instances of this field may be defaulted, in others it may be required.
  1842. maxLength: 253
  1843. minLength: 1
  1844. pattern: ^[-._a-zA-Z0-9]+$
  1845. type: string
  1846. name:
  1847. description: The name of the Secret resource being referred to.
  1848. maxLength: 253
  1849. minLength: 1
  1850. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1851. type: string
  1852. namespace:
  1853. description: |-
  1854. The namespace of the Secret resource being referred to.
  1855. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1856. maxLength: 63
  1857. minLength: 1
  1858. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1859. type: string
  1860. type: object
  1861. type: object
  1862. required:
  1863. - secretRef
  1864. type: object
  1865. database:
  1866. description: Database to use as source
  1867. type: string
  1868. host:
  1869. description: URL configures the Password Depot instance URL.
  1870. type: string
  1871. required:
  1872. - auth
  1873. - database
  1874. - host
  1875. type: object
  1876. vault:
  1877. description: Vault configures this store to sync secrets using Hashi provider
  1878. properties:
  1879. auth:
  1880. description: Auth configures how secret-manager authenticates with the Vault server.
  1881. properties:
  1882. appRole:
  1883. description: |-
  1884. AppRole authenticates with Vault using the App Role auth mechanism,
  1885. with the role and secret stored in a Kubernetes Secret resource.
  1886. properties:
  1887. path:
  1888. default: approle
  1889. description: |-
  1890. Path where the App Role authentication backend is mounted
  1891. in Vault, e.g: "approle"
  1892. type: string
  1893. roleId:
  1894. description: |-
  1895. RoleID configured in the App Role authentication backend when setting
  1896. up the authentication backend in Vault.
  1897. type: string
  1898. secretRef:
  1899. description: |-
  1900. Reference to a key in a Secret that contains the App Role secret used
  1901. to authenticate with Vault.
  1902. The `key` field must be specified and denotes which entry within the Secret
  1903. resource is used as the app role secret.
  1904. properties:
  1905. key:
  1906. description: |-
  1907. A key in the referenced Secret.
  1908. Some instances of this field may be defaulted, in others it may be required.
  1909. maxLength: 253
  1910. minLength: 1
  1911. pattern: ^[-._a-zA-Z0-9]+$
  1912. type: string
  1913. name:
  1914. description: The name of the Secret resource being referred to.
  1915. maxLength: 253
  1916. minLength: 1
  1917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1918. type: string
  1919. namespace:
  1920. description: |-
  1921. The namespace of the Secret resource being referred to.
  1922. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1923. maxLength: 63
  1924. minLength: 1
  1925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1926. type: string
  1927. type: object
  1928. required:
  1929. - path
  1930. - roleId
  1931. - secretRef
  1932. type: object
  1933. cert:
  1934. description: |-
  1935. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  1936. Cert authentication method
  1937. properties:
  1938. clientCert:
  1939. description: |-
  1940. ClientCert is a certificate to authenticate using the Cert Vault
  1941. authentication method
  1942. properties:
  1943. key:
  1944. description: |-
  1945. A key in the referenced Secret.
  1946. Some instances of this field may be defaulted, in others it may be required.
  1947. maxLength: 253
  1948. minLength: 1
  1949. pattern: ^[-._a-zA-Z0-9]+$
  1950. type: string
  1951. name:
  1952. description: The name of the Secret resource being referred to.
  1953. maxLength: 253
  1954. minLength: 1
  1955. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1956. type: string
  1957. namespace:
  1958. description: |-
  1959. The namespace of the Secret resource being referred to.
  1960. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1961. maxLength: 63
  1962. minLength: 1
  1963. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1964. type: string
  1965. type: object
  1966. secretRef:
  1967. description: |-
  1968. SecretRef to a key in a Secret resource containing client private key to
  1969. authenticate with Vault using the Cert authentication method
  1970. properties:
  1971. key:
  1972. description: |-
  1973. A key in the referenced Secret.
  1974. Some instances of this field may be defaulted, in others it may be required.
  1975. maxLength: 253
  1976. minLength: 1
  1977. pattern: ^[-._a-zA-Z0-9]+$
  1978. type: string
  1979. name:
  1980. description: The name of the Secret resource being referred to.
  1981. maxLength: 253
  1982. minLength: 1
  1983. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  1984. type: string
  1985. namespace:
  1986. description: |-
  1987. The namespace of the Secret resource being referred to.
  1988. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  1989. maxLength: 63
  1990. minLength: 1
  1991. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  1992. type: string
  1993. type: object
  1994. type: object
  1995. jwt:
  1996. description: |-
  1997. Jwt authenticates with Vault by passing role and JWT token using the
  1998. JWT/OIDC authentication method
  1999. properties:
  2000. kubernetesServiceAccountToken:
  2001. description: |-
  2002. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  2003. a token for with the `TokenRequest` API.
  2004. properties:
  2005. audiences:
  2006. description: |-
  2007. Optional audiences field that will be used to request a temporary Kubernetes service
  2008. account token for the service account referenced by `serviceAccountRef`.
  2009. Defaults to a single audience `vault` it not specified.
  2010. items:
  2011. type: string
  2012. type: array
  2013. expirationSeconds:
  2014. description: |-
  2015. Optional expiration time in seconds that will be used to request a temporary
  2016. Kubernetes service account token for the service account referenced by
  2017. `serviceAccountRef`.
  2018. Defaults to 10 minutes.
  2019. format: int64
  2020. type: integer
  2021. serviceAccountRef:
  2022. description: Service account field containing the name of a kubernetes ServiceAccount.
  2023. properties:
  2024. audiences:
  2025. description: |-
  2026. Audience specifies the `aud` claim for the service account token
  2027. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2028. then this audiences will be appended to the list
  2029. items:
  2030. type: string
  2031. type: array
  2032. name:
  2033. description: The name of the ServiceAccount resource being referred to.
  2034. maxLength: 253
  2035. minLength: 1
  2036. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2037. type: string
  2038. namespace:
  2039. description: |-
  2040. Namespace of the resource being referred to.
  2041. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2042. maxLength: 63
  2043. minLength: 1
  2044. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2045. type: string
  2046. required:
  2047. - name
  2048. type: object
  2049. required:
  2050. - serviceAccountRef
  2051. type: object
  2052. path:
  2053. default: jwt
  2054. description: |-
  2055. Path where the JWT authentication backend is mounted
  2056. in Vault, e.g: "jwt"
  2057. type: string
  2058. role:
  2059. description: |-
  2060. Role is a JWT role to authenticate using the JWT/OIDC Vault
  2061. authentication method
  2062. type: string
  2063. secretRef:
  2064. description: |-
  2065. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  2066. authenticate with Vault using the JWT/OIDC authentication method.
  2067. properties:
  2068. key:
  2069. description: |-
  2070. A key in the referenced Secret.
  2071. Some instances of this field may be defaulted, in others it may be required.
  2072. maxLength: 253
  2073. minLength: 1
  2074. pattern: ^[-._a-zA-Z0-9]+$
  2075. type: string
  2076. name:
  2077. description: The name of the Secret resource being referred to.
  2078. maxLength: 253
  2079. minLength: 1
  2080. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2081. type: string
  2082. namespace:
  2083. description: |-
  2084. The namespace of the Secret resource being referred to.
  2085. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2086. maxLength: 63
  2087. minLength: 1
  2088. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2089. type: string
  2090. type: object
  2091. required:
  2092. - path
  2093. type: object
  2094. kubernetes:
  2095. description: |-
  2096. Kubernetes authenticates with Vault by passing the ServiceAccount
  2097. token stored in the named Secret resource to the Vault server.
  2098. properties:
  2099. mountPath:
  2100. default: kubernetes
  2101. description: |-
  2102. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  2103. "kubernetes"
  2104. type: string
  2105. role:
  2106. description: |-
  2107. A required field containing the Vault Role to assume. A Role binds a
  2108. Kubernetes ServiceAccount with a set of Vault policies.
  2109. type: string
  2110. secretRef:
  2111. description: |-
  2112. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2113. for authenticating with Vault. If a name is specified without a key,
  2114. `token` is the default. If one is not specified, the one bound to
  2115. the controller will be used.
  2116. properties:
  2117. key:
  2118. description: |-
  2119. A key in the referenced Secret.
  2120. Some instances of this field may be defaulted, in others it may be required.
  2121. maxLength: 253
  2122. minLength: 1
  2123. pattern: ^[-._a-zA-Z0-9]+$
  2124. type: string
  2125. name:
  2126. description: The name of the Secret resource being referred to.
  2127. maxLength: 253
  2128. minLength: 1
  2129. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2130. type: string
  2131. namespace:
  2132. description: |-
  2133. The namespace of the Secret resource being referred to.
  2134. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2135. maxLength: 63
  2136. minLength: 1
  2137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2138. type: string
  2139. type: object
  2140. serviceAccountRef:
  2141. description: |-
  2142. Optional service account field containing the name of a kubernetes ServiceAccount.
  2143. If the service account is specified, the service account secret token JWT will be used
  2144. for authenticating with Vault. If the service account selector is not supplied,
  2145. the secretRef will be used instead.
  2146. properties:
  2147. audiences:
  2148. description: |-
  2149. Audience specifies the `aud` claim for the service account token
  2150. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2151. then this audiences will be appended to the list
  2152. items:
  2153. type: string
  2154. type: array
  2155. name:
  2156. description: The name of the ServiceAccount resource being referred to.
  2157. maxLength: 253
  2158. minLength: 1
  2159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2160. type: string
  2161. namespace:
  2162. description: |-
  2163. Namespace of the resource being referred to.
  2164. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2165. maxLength: 63
  2166. minLength: 1
  2167. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2168. type: string
  2169. required:
  2170. - name
  2171. type: object
  2172. required:
  2173. - mountPath
  2174. - role
  2175. type: object
  2176. ldap:
  2177. description: |-
  2178. Ldap authenticates with Vault by passing username/password pair using
  2179. the LDAP authentication method
  2180. properties:
  2181. path:
  2182. default: ldap
  2183. description: |-
  2184. Path where the LDAP authentication backend is mounted
  2185. in Vault, e.g: "ldap"
  2186. type: string
  2187. secretRef:
  2188. description: |-
  2189. SecretRef to a key in a Secret resource containing password for the LDAP
  2190. user used to authenticate with Vault using the LDAP authentication
  2191. method
  2192. properties:
  2193. key:
  2194. description: |-
  2195. A key in the referenced Secret.
  2196. Some instances of this field may be defaulted, in others it may be required.
  2197. maxLength: 253
  2198. minLength: 1
  2199. pattern: ^[-._a-zA-Z0-9]+$
  2200. type: string
  2201. name:
  2202. description: The name of the Secret resource being referred to.
  2203. maxLength: 253
  2204. minLength: 1
  2205. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2206. type: string
  2207. namespace:
  2208. description: |-
  2209. The namespace of the Secret resource being referred to.
  2210. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2211. maxLength: 63
  2212. minLength: 1
  2213. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2214. type: string
  2215. type: object
  2216. username:
  2217. description: |-
  2218. Username is a LDAP user name used to authenticate using the LDAP Vault
  2219. authentication method
  2220. type: string
  2221. required:
  2222. - path
  2223. - username
  2224. type: object
  2225. tokenSecretRef:
  2226. description: TokenSecretRef authenticates with Vault by presenting a token.
  2227. properties:
  2228. key:
  2229. description: |-
  2230. A key in the referenced Secret.
  2231. Some instances of this field may be defaulted, in others it may be required.
  2232. maxLength: 253
  2233. minLength: 1
  2234. pattern: ^[-._a-zA-Z0-9]+$
  2235. type: string
  2236. name:
  2237. description: The name of the Secret resource being referred to.
  2238. maxLength: 253
  2239. minLength: 1
  2240. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2241. type: string
  2242. namespace:
  2243. description: |-
  2244. The namespace of the Secret resource being referred to.
  2245. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2246. maxLength: 63
  2247. minLength: 1
  2248. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2249. type: string
  2250. type: object
  2251. type: object
  2252. caBundle:
  2253. description: |-
  2254. PEM encoded CA bundle used to validate Vault server certificate. Only used
  2255. if the Server URL is using HTTPS protocol. This parameter is ignored for
  2256. plain HTTP protocol connection. If not set the system root certificates
  2257. are used to validate the TLS connection.
  2258. format: byte
  2259. type: string
  2260. caProvider:
  2261. description: The provider for the CA bundle to use to validate Vault server certificate.
  2262. properties:
  2263. key:
  2264. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2265. maxLength: 253
  2266. minLength: 1
  2267. pattern: ^[-._a-zA-Z0-9]+$
  2268. type: string
  2269. name:
  2270. description: The name of the object located at the provider type.
  2271. maxLength: 253
  2272. minLength: 1
  2273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2274. type: string
  2275. namespace:
  2276. description: The namespace the Provider type is in.
  2277. maxLength: 63
  2278. minLength: 1
  2279. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2280. type: string
  2281. type:
  2282. description: The type of provider to use such as "Secret", or "ConfigMap".
  2283. enum:
  2284. - Secret
  2285. - ConfigMap
  2286. type: string
  2287. required:
  2288. - name
  2289. - type
  2290. type: object
  2291. forwardInconsistent:
  2292. description: |-
  2293. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  2294. leader instead of simply retrying within a loop. This can increase performance if
  2295. the option is enabled serverside.
  2296. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  2297. type: boolean
  2298. namespace:
  2299. description: |-
  2300. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  2301. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  2302. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  2303. type: string
  2304. path:
  2305. description: |-
  2306. Path is the mount path of the Vault KV backend endpoint, e.g:
  2307. "secret". The v2 KV secret engine version specific "/data" path suffix
  2308. for fetching secrets from Vault is optional and will be appended
  2309. if not present in specified path.
  2310. type: string
  2311. readYourWrites:
  2312. description: |-
  2313. ReadYourWrites ensures isolated read-after-write semantics by
  2314. providing discovered cluster replication states in each request.
  2315. More information about eventual consistency in Vault can be found here
  2316. https://www.vaultproject.io/docs/enterprise/consistency
  2317. type: boolean
  2318. server:
  2319. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  2320. type: string
  2321. version:
  2322. default: v2
  2323. description: |-
  2324. Version is the Vault KV secret engine version. This can be either "v1" or
  2325. "v2". Version defaults to "v2".
  2326. enum:
  2327. - v1
  2328. - v2
  2329. type: string
  2330. required:
  2331. - auth
  2332. - server
  2333. type: object
  2334. webhook:
  2335. description: Webhook configures this store to sync secrets using a generic templated webhook
  2336. properties:
  2337. body:
  2338. description: Body
  2339. type: string
  2340. caBundle:
  2341. description: |-
  2342. PEM encoded CA bundle used to validate webhook server certificate. Only used
  2343. if the Server URL is using HTTPS protocol. This parameter is ignored for
  2344. plain HTTP protocol connection. If not set the system root certificates
  2345. are used to validate the TLS connection.
  2346. format: byte
  2347. type: string
  2348. caProvider:
  2349. description: The provider for the CA bundle to use to validate webhook server certificate.
  2350. properties:
  2351. key:
  2352. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2353. maxLength: 253
  2354. minLength: 1
  2355. pattern: ^[-._a-zA-Z0-9]+$
  2356. type: string
  2357. name:
  2358. description: The name of the object located at the provider type.
  2359. maxLength: 253
  2360. minLength: 1
  2361. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2362. type: string
  2363. namespace:
  2364. description: The namespace the Provider type is in.
  2365. maxLength: 63
  2366. minLength: 1
  2367. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2368. type: string
  2369. type:
  2370. description: The type of provider to use such as "Secret", or "ConfigMap".
  2371. enum:
  2372. - Secret
  2373. - ConfigMap
  2374. type: string
  2375. required:
  2376. - name
  2377. - type
  2378. type: object
  2379. headers:
  2380. additionalProperties:
  2381. type: string
  2382. description: Headers
  2383. type: object
  2384. method:
  2385. description: Webhook Method
  2386. type: string
  2387. result:
  2388. description: Result formatting
  2389. properties:
  2390. jsonPath:
  2391. description: Json path of return value
  2392. type: string
  2393. type: object
  2394. secrets:
  2395. description: |-
  2396. Secrets to fill in templates
  2397. These secrets will be passed to the templating function as key value pairs under the given name
  2398. items:
  2399. properties:
  2400. name:
  2401. description: Name of this secret in templates
  2402. type: string
  2403. secretRef:
  2404. description: Secret ref to fill in credentials
  2405. properties:
  2406. key:
  2407. description: |-
  2408. A key in the referenced Secret.
  2409. Some instances of this field may be defaulted, in others it may be required.
  2410. maxLength: 253
  2411. minLength: 1
  2412. pattern: ^[-._a-zA-Z0-9]+$
  2413. type: string
  2414. name:
  2415. description: The name of the Secret resource being referred to.
  2416. maxLength: 253
  2417. minLength: 1
  2418. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2419. type: string
  2420. namespace:
  2421. description: |-
  2422. The namespace of the Secret resource being referred to.
  2423. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2424. maxLength: 63
  2425. minLength: 1
  2426. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2427. type: string
  2428. type: object
  2429. required:
  2430. - name
  2431. - secretRef
  2432. type: object
  2433. type: array
  2434. timeout:
  2435. description: Timeout
  2436. type: string
  2437. url:
  2438. description: Webhook url to call
  2439. type: string
  2440. required:
  2441. - result
  2442. - url
  2443. type: object
  2444. yandexlockbox:
  2445. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  2446. properties:
  2447. apiEndpoint:
  2448. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  2449. type: string
  2450. auth:
  2451. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  2452. properties:
  2453. authorizedKeySecretRef:
  2454. description: The authorized key used for authentication
  2455. properties:
  2456. key:
  2457. description: |-
  2458. A key in the referenced Secret.
  2459. Some instances of this field may be defaulted, in others it may be required.
  2460. maxLength: 253
  2461. minLength: 1
  2462. pattern: ^[-._a-zA-Z0-9]+$
  2463. type: string
  2464. name:
  2465. description: The name of the Secret resource being referred to.
  2466. maxLength: 253
  2467. minLength: 1
  2468. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2469. type: string
  2470. namespace:
  2471. description: |-
  2472. The namespace of the Secret resource being referred to.
  2473. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2474. maxLength: 63
  2475. minLength: 1
  2476. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2477. type: string
  2478. type: object
  2479. type: object
  2480. caProvider:
  2481. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  2482. properties:
  2483. certSecretRef:
  2484. description: |-
  2485. A reference to a specific 'key' within a Secret resource.
  2486. In some instances, `key` is a required field.
  2487. properties:
  2488. key:
  2489. description: |-
  2490. A key in the referenced Secret.
  2491. Some instances of this field may be defaulted, in others it may be required.
  2492. maxLength: 253
  2493. minLength: 1
  2494. pattern: ^[-._a-zA-Z0-9]+$
  2495. type: string
  2496. name:
  2497. description: The name of the Secret resource being referred to.
  2498. maxLength: 253
  2499. minLength: 1
  2500. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2501. type: string
  2502. namespace:
  2503. description: |-
  2504. The namespace of the Secret resource being referred to.
  2505. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2506. maxLength: 63
  2507. minLength: 1
  2508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2509. type: string
  2510. type: object
  2511. type: object
  2512. required:
  2513. - auth
  2514. type: object
  2515. type: object
  2516. retrySettings:
  2517. description: Used to configure http retries if failed
  2518. properties:
  2519. maxRetries:
  2520. format: int32
  2521. type: integer
  2522. retryInterval:
  2523. type: string
  2524. type: object
  2525. required:
  2526. - provider
  2527. type: object
  2528. status:
  2529. description: SecretStoreStatus defines the observed state of the SecretStore.
  2530. properties:
  2531. conditions:
  2532. items:
  2533. properties:
  2534. lastTransitionTime:
  2535. format: date-time
  2536. type: string
  2537. message:
  2538. type: string
  2539. reason:
  2540. type: string
  2541. status:
  2542. type: string
  2543. type:
  2544. type: string
  2545. required:
  2546. - status
  2547. - type
  2548. type: object
  2549. type: array
  2550. type: object
  2551. type: object
  2552. served: true
  2553. storage: false
  2554. subresources:
  2555. status: {}
  2556. - additionalPrinterColumns:
  2557. - jsonPath: .metadata.creationTimestamp
  2558. name: AGE
  2559. type: date
  2560. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  2561. name: Status
  2562. type: string
  2563. - jsonPath: .status.capabilities
  2564. name: Capabilities
  2565. type: string
  2566. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  2567. name: Ready
  2568. type: string
  2569. name: v1beta1
  2570. schema:
  2571. openAPIV3Schema:
  2572. description: ClusterSecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  2573. properties:
  2574. apiVersion:
  2575. description: |-
  2576. APIVersion defines the versioned schema of this representation of an object.
  2577. Servers should convert recognized schemas to the latest internal value, and
  2578. may reject unrecognized values.
  2579. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  2580. type: string
  2581. kind:
  2582. description: |-
  2583. Kind is a string value representing the REST resource this object represents.
  2584. Servers may infer this from the endpoint the client submits requests to.
  2585. Cannot be updated.
  2586. In CamelCase.
  2587. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  2588. type: string
  2589. metadata:
  2590. type: object
  2591. spec:
  2592. description: SecretStoreSpec defines the desired state of SecretStore.
  2593. properties:
  2594. conditions:
  2595. description: Used to constraint a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore
  2596. items:
  2597. description: |-
  2598. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  2599. for a ClusterSecretStore instance.
  2600. properties:
  2601. namespaceRegexes:
  2602. description: Choose namespaces by using regex matching
  2603. items:
  2604. type: string
  2605. type: array
  2606. namespaceSelector:
  2607. description: Choose namespace using a labelSelector
  2608. properties:
  2609. matchExpressions:
  2610. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  2611. items:
  2612. description: |-
  2613. A label selector requirement is a selector that contains values, a key, and an operator that
  2614. relates the key and values.
  2615. properties:
  2616. key:
  2617. description: key is the label key that the selector applies to.
  2618. type: string
  2619. operator:
  2620. description: |-
  2621. operator represents a key's relationship to a set of values.
  2622. Valid operators are In, NotIn, Exists and DoesNotExist.
  2623. type: string
  2624. values:
  2625. description: |-
  2626. values is an array of string values. If the operator is In or NotIn,
  2627. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  2628. the values array must be empty. This array is replaced during a strategic
  2629. merge patch.
  2630. items:
  2631. type: string
  2632. type: array
  2633. x-kubernetes-list-type: atomic
  2634. required:
  2635. - key
  2636. - operator
  2637. type: object
  2638. type: array
  2639. x-kubernetes-list-type: atomic
  2640. matchLabels:
  2641. additionalProperties:
  2642. type: string
  2643. description: |-
  2644. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  2645. map is equivalent to an element of matchExpressions, whose key field is "key", the
  2646. operator is "In", and the values array contains only "value". The requirements are ANDed.
  2647. type: object
  2648. type: object
  2649. x-kubernetes-map-type: atomic
  2650. namespaces:
  2651. description: Choose namespaces by name
  2652. items:
  2653. maxLength: 63
  2654. minLength: 1
  2655. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2656. type: string
  2657. type: array
  2658. type: object
  2659. type: array
  2660. controller:
  2661. description: |-
  2662. Used to select the correct ESO controller (think: ingress.ingressClassName)
  2663. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  2664. type: string
  2665. provider:
  2666. description: Used to configure the provider. Only one provider may be set
  2667. maxProperties: 1
  2668. minProperties: 1
  2669. properties:
  2670. akeyless:
  2671. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  2672. properties:
  2673. akeylessGWApiURL:
  2674. description: Akeyless GW API Url from which the secrets to be fetched from.
  2675. type: string
  2676. authSecretRef:
  2677. description: Auth configures how the operator authenticates with Akeyless.
  2678. properties:
  2679. kubernetesAuth:
  2680. description: |-
  2681. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  2682. token stored in the named Secret resource.
  2683. properties:
  2684. accessID:
  2685. description: the Akeyless Kubernetes auth-method access-id
  2686. type: string
  2687. k8sConfName:
  2688. description: Kubernetes-auth configuration name in Akeyless-Gateway
  2689. type: string
  2690. secretRef:
  2691. description: |-
  2692. Optional secret field containing a Kubernetes ServiceAccount JWT used
  2693. for authenticating with Akeyless. If a name is specified without a key,
  2694. `token` is the default. If one is not specified, the one bound to
  2695. the controller will be used.
  2696. properties:
  2697. key:
  2698. description: |-
  2699. A key in the referenced Secret.
  2700. Some instances of this field may be defaulted, in others it may be required.
  2701. maxLength: 253
  2702. minLength: 1
  2703. pattern: ^[-._a-zA-Z0-9]+$
  2704. type: string
  2705. name:
  2706. description: The name of the Secret resource being referred to.
  2707. maxLength: 253
  2708. minLength: 1
  2709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2710. type: string
  2711. namespace:
  2712. description: |-
  2713. The namespace of the Secret resource being referred to.
  2714. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2715. maxLength: 63
  2716. minLength: 1
  2717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2718. type: string
  2719. type: object
  2720. serviceAccountRef:
  2721. description: |-
  2722. Optional service account field containing the name of a kubernetes ServiceAccount.
  2723. If the service account is specified, the service account secret token JWT will be used
  2724. for authenticating with Akeyless. If the service account selector is not supplied,
  2725. the secretRef will be used instead.
  2726. properties:
  2727. audiences:
  2728. description: |-
  2729. Audience specifies the `aud` claim for the service account token
  2730. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  2731. then this audiences will be appended to the list
  2732. items:
  2733. type: string
  2734. type: array
  2735. name:
  2736. description: The name of the ServiceAccount resource being referred to.
  2737. maxLength: 253
  2738. minLength: 1
  2739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2740. type: string
  2741. namespace:
  2742. description: |-
  2743. Namespace of the resource being referred to.
  2744. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2745. maxLength: 63
  2746. minLength: 1
  2747. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2748. type: string
  2749. required:
  2750. - name
  2751. type: object
  2752. required:
  2753. - accessID
  2754. - k8sConfName
  2755. type: object
  2756. secretRef:
  2757. description: |-
  2758. Reference to a Secret that contains the details
  2759. to authenticate with Akeyless.
  2760. properties:
  2761. accessID:
  2762. description: The SecretAccessID is used for authentication
  2763. properties:
  2764. key:
  2765. description: |-
  2766. A key in the referenced Secret.
  2767. Some instances of this field may be defaulted, in others it may be required.
  2768. maxLength: 253
  2769. minLength: 1
  2770. pattern: ^[-._a-zA-Z0-9]+$
  2771. type: string
  2772. name:
  2773. description: The name of the Secret resource being referred to.
  2774. maxLength: 253
  2775. minLength: 1
  2776. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2777. type: string
  2778. namespace:
  2779. description: |-
  2780. The namespace of the Secret resource being referred to.
  2781. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2782. maxLength: 63
  2783. minLength: 1
  2784. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2785. type: string
  2786. type: object
  2787. accessType:
  2788. description: |-
  2789. A reference to a specific 'key' within a Secret resource.
  2790. In some instances, `key` is a required field.
  2791. properties:
  2792. key:
  2793. description: |-
  2794. A key in the referenced Secret.
  2795. Some instances of this field may be defaulted, in others it may be required.
  2796. maxLength: 253
  2797. minLength: 1
  2798. pattern: ^[-._a-zA-Z0-9]+$
  2799. type: string
  2800. name:
  2801. description: The name of the Secret resource being referred to.
  2802. maxLength: 253
  2803. minLength: 1
  2804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2805. type: string
  2806. namespace:
  2807. description: |-
  2808. The namespace of the Secret resource being referred to.
  2809. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2810. maxLength: 63
  2811. minLength: 1
  2812. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2813. type: string
  2814. type: object
  2815. accessTypeParam:
  2816. description: |-
  2817. A reference to a specific 'key' within a Secret resource.
  2818. In some instances, `key` is a required field.
  2819. properties:
  2820. key:
  2821. description: |-
  2822. A key in the referenced Secret.
  2823. Some instances of this field may be defaulted, in others it may be required.
  2824. maxLength: 253
  2825. minLength: 1
  2826. pattern: ^[-._a-zA-Z0-9]+$
  2827. type: string
  2828. name:
  2829. description: The name of the Secret resource being referred to.
  2830. maxLength: 253
  2831. minLength: 1
  2832. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2833. type: string
  2834. namespace:
  2835. description: |-
  2836. The namespace of the Secret resource being referred to.
  2837. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2838. maxLength: 63
  2839. minLength: 1
  2840. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2841. type: string
  2842. type: object
  2843. type: object
  2844. type: object
  2845. caBundle:
  2846. description: |-
  2847. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  2848. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  2849. are used to validate the TLS connection.
  2850. format: byte
  2851. type: string
  2852. caProvider:
  2853. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  2854. properties:
  2855. key:
  2856. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  2857. maxLength: 253
  2858. minLength: 1
  2859. pattern: ^[-._a-zA-Z0-9]+$
  2860. type: string
  2861. name:
  2862. description: The name of the object located at the provider type.
  2863. maxLength: 253
  2864. minLength: 1
  2865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2866. type: string
  2867. namespace:
  2868. description: |-
  2869. The namespace the Provider type is in.
  2870. Can only be defined when used in a ClusterSecretStore.
  2871. maxLength: 63
  2872. minLength: 1
  2873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2874. type: string
  2875. type:
  2876. description: The type of provider to use such as "Secret", or "ConfigMap".
  2877. enum:
  2878. - Secret
  2879. - ConfigMap
  2880. type: string
  2881. required:
  2882. - name
  2883. - type
  2884. type: object
  2885. required:
  2886. - akeylessGWApiURL
  2887. - authSecretRef
  2888. type: object
  2889. alibaba:
  2890. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  2891. properties:
  2892. auth:
  2893. description: AlibabaAuth contains a secretRef for credentials.
  2894. properties:
  2895. rrsa:
  2896. description: Authenticate against Alibaba using RRSA.
  2897. properties:
  2898. oidcProviderArn:
  2899. type: string
  2900. oidcTokenFilePath:
  2901. type: string
  2902. roleArn:
  2903. type: string
  2904. sessionName:
  2905. type: string
  2906. required:
  2907. - oidcProviderArn
  2908. - oidcTokenFilePath
  2909. - roleArn
  2910. - sessionName
  2911. type: object
  2912. secretRef:
  2913. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  2914. properties:
  2915. accessKeyIDSecretRef:
  2916. description: The AccessKeyID is used for authentication
  2917. properties:
  2918. key:
  2919. description: |-
  2920. A key in the referenced Secret.
  2921. Some instances of this field may be defaulted, in others it may be required.
  2922. maxLength: 253
  2923. minLength: 1
  2924. pattern: ^[-._a-zA-Z0-9]+$
  2925. type: string
  2926. name:
  2927. description: The name of the Secret resource being referred to.
  2928. maxLength: 253
  2929. minLength: 1
  2930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2931. type: string
  2932. namespace:
  2933. description: |-
  2934. The namespace of the Secret resource being referred to.
  2935. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2936. maxLength: 63
  2937. minLength: 1
  2938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2939. type: string
  2940. type: object
  2941. accessKeySecretSecretRef:
  2942. description: The AccessKeySecret is used for authentication
  2943. properties:
  2944. key:
  2945. description: |-
  2946. A key in the referenced Secret.
  2947. Some instances of this field may be defaulted, in others it may be required.
  2948. maxLength: 253
  2949. minLength: 1
  2950. pattern: ^[-._a-zA-Z0-9]+$
  2951. type: string
  2952. name:
  2953. description: The name of the Secret resource being referred to.
  2954. maxLength: 253
  2955. minLength: 1
  2956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  2957. type: string
  2958. namespace:
  2959. description: |-
  2960. The namespace of the Secret resource being referred to.
  2961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  2962. maxLength: 63
  2963. minLength: 1
  2964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  2965. type: string
  2966. type: object
  2967. required:
  2968. - accessKeyIDSecretRef
  2969. - accessKeySecretSecretRef
  2970. type: object
  2971. type: object
  2972. regionID:
  2973. description: Alibaba Region to be used for the provider
  2974. type: string
  2975. required:
  2976. - auth
  2977. - regionID
  2978. type: object
  2979. aws:
  2980. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  2981. properties:
  2982. additionalRoles:
  2983. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  2984. items:
  2985. type: string
  2986. type: array
  2987. auth:
  2988. description: |-
  2989. Auth defines the information necessary to authenticate against AWS
  2990. if not set aws sdk will infer credentials from your environment
  2991. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  2992. properties:
  2993. jwt:
  2994. description: Authenticate against AWS using service account tokens.
  2995. properties:
  2996. serviceAccountRef:
  2997. description: A reference to a ServiceAccount resource.
  2998. properties:
  2999. audiences:
  3000. description: |-
  3001. Audience specifies the `aud` claim for the service account token
  3002. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3003. then this audiences will be appended to the list
  3004. items:
  3005. type: string
  3006. type: array
  3007. name:
  3008. description: The name of the ServiceAccount resource being referred to.
  3009. maxLength: 253
  3010. minLength: 1
  3011. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3012. type: string
  3013. namespace:
  3014. description: |-
  3015. Namespace of the resource being referred to.
  3016. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3017. maxLength: 63
  3018. minLength: 1
  3019. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3020. type: string
  3021. required:
  3022. - name
  3023. type: object
  3024. type: object
  3025. secretRef:
  3026. description: |-
  3027. AWSAuthSecretRef holds secret references for AWS credentials
  3028. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  3029. properties:
  3030. accessKeyIDSecretRef:
  3031. description: The AccessKeyID is used for authentication
  3032. properties:
  3033. key:
  3034. description: |-
  3035. A key in the referenced Secret.
  3036. Some instances of this field may be defaulted, in others it may be required.
  3037. maxLength: 253
  3038. minLength: 1
  3039. pattern: ^[-._a-zA-Z0-9]+$
  3040. type: string
  3041. name:
  3042. description: The name of the Secret resource being referred to.
  3043. maxLength: 253
  3044. minLength: 1
  3045. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3046. type: string
  3047. namespace:
  3048. description: |-
  3049. The namespace of the Secret resource being referred to.
  3050. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3051. maxLength: 63
  3052. minLength: 1
  3053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3054. type: string
  3055. type: object
  3056. secretAccessKeySecretRef:
  3057. description: The SecretAccessKey is used for authentication
  3058. properties:
  3059. key:
  3060. description: |-
  3061. A key in the referenced Secret.
  3062. Some instances of this field may be defaulted, in others it may be required.
  3063. maxLength: 253
  3064. minLength: 1
  3065. pattern: ^[-._a-zA-Z0-9]+$
  3066. type: string
  3067. name:
  3068. description: The name of the Secret resource being referred to.
  3069. maxLength: 253
  3070. minLength: 1
  3071. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3072. type: string
  3073. namespace:
  3074. description: |-
  3075. The namespace of the Secret resource being referred to.
  3076. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3077. maxLength: 63
  3078. minLength: 1
  3079. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3080. type: string
  3081. type: object
  3082. sessionTokenSecretRef:
  3083. description: |-
  3084. The SessionToken used for authentication
  3085. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  3086. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  3087. properties:
  3088. key:
  3089. description: |-
  3090. A key in the referenced Secret.
  3091. Some instances of this field may be defaulted, in others it may be required.
  3092. maxLength: 253
  3093. minLength: 1
  3094. pattern: ^[-._a-zA-Z0-9]+$
  3095. type: string
  3096. name:
  3097. description: The name of the Secret resource being referred to.
  3098. maxLength: 253
  3099. minLength: 1
  3100. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3101. type: string
  3102. namespace:
  3103. description: |-
  3104. The namespace of the Secret resource being referred to.
  3105. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3106. maxLength: 63
  3107. minLength: 1
  3108. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3109. type: string
  3110. type: object
  3111. type: object
  3112. type: object
  3113. externalID:
  3114. description: AWS External ID set on assumed IAM roles
  3115. type: string
  3116. prefix:
  3117. description: Prefix adds a prefix to all retrieved values.
  3118. type: string
  3119. region:
  3120. description: AWS Region to be used for the provider
  3121. type: string
  3122. role:
  3123. description: Role is a Role ARN which the provider will assume
  3124. type: string
  3125. secretsManager:
  3126. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  3127. properties:
  3128. forceDeleteWithoutRecovery:
  3129. description: |-
  3130. Specifies whether to delete the secret without any recovery window. You
  3131. can't use both this parameter and RecoveryWindowInDays in the same call.
  3132. If you don't use either, then by default Secrets Manager uses a 30 day
  3133. recovery window.
  3134. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  3135. type: boolean
  3136. recoveryWindowInDays:
  3137. description: |-
  3138. The number of days from 7 to 30 that Secrets Manager waits before
  3139. permanently deleting the secret. You can't use both this parameter and
  3140. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  3141. then by default Secrets Manager uses a 30 day recovery window.
  3142. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  3143. format: int64
  3144. type: integer
  3145. type: object
  3146. service:
  3147. description: Service defines which service should be used to fetch the secrets
  3148. enum:
  3149. - SecretsManager
  3150. - ParameterStore
  3151. type: string
  3152. sessionTags:
  3153. description: AWS STS assume role session tags
  3154. items:
  3155. properties:
  3156. key:
  3157. type: string
  3158. value:
  3159. type: string
  3160. required:
  3161. - key
  3162. - value
  3163. type: object
  3164. type: array
  3165. transitiveTagKeys:
  3166. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  3167. items:
  3168. type: string
  3169. type: array
  3170. required:
  3171. - region
  3172. - service
  3173. type: object
  3174. azurekv:
  3175. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  3176. properties:
  3177. authSecretRef:
  3178. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3179. properties:
  3180. clientCertificate:
  3181. description: The Azure ClientCertificate of the service principle used for authentication.
  3182. properties:
  3183. key:
  3184. description: |-
  3185. A key in the referenced Secret.
  3186. Some instances of this field may be defaulted, in others it may be required.
  3187. maxLength: 253
  3188. minLength: 1
  3189. pattern: ^[-._a-zA-Z0-9]+$
  3190. type: string
  3191. name:
  3192. description: The name of the Secret resource being referred to.
  3193. maxLength: 253
  3194. minLength: 1
  3195. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3196. type: string
  3197. namespace:
  3198. description: |-
  3199. The namespace of the Secret resource being referred to.
  3200. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3201. maxLength: 63
  3202. minLength: 1
  3203. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3204. type: string
  3205. type: object
  3206. clientId:
  3207. description: The Azure clientId of the service principle or managed identity used for authentication.
  3208. properties:
  3209. key:
  3210. description: |-
  3211. A key in the referenced Secret.
  3212. Some instances of this field may be defaulted, in others it may be required.
  3213. maxLength: 253
  3214. minLength: 1
  3215. pattern: ^[-._a-zA-Z0-9]+$
  3216. type: string
  3217. name:
  3218. description: The name of the Secret resource being referred to.
  3219. maxLength: 253
  3220. minLength: 1
  3221. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3222. type: string
  3223. namespace:
  3224. description: |-
  3225. The namespace of the Secret resource being referred to.
  3226. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3227. maxLength: 63
  3228. minLength: 1
  3229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3230. type: string
  3231. type: object
  3232. clientSecret:
  3233. description: The Azure ClientSecret of the service principle used for authentication.
  3234. properties:
  3235. key:
  3236. description: |-
  3237. A key in the referenced Secret.
  3238. Some instances of this field may be defaulted, in others it may be required.
  3239. maxLength: 253
  3240. minLength: 1
  3241. pattern: ^[-._a-zA-Z0-9]+$
  3242. type: string
  3243. name:
  3244. description: The name of the Secret resource being referred to.
  3245. maxLength: 253
  3246. minLength: 1
  3247. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3248. type: string
  3249. namespace:
  3250. description: |-
  3251. The namespace of the Secret resource being referred to.
  3252. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3253. maxLength: 63
  3254. minLength: 1
  3255. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3256. type: string
  3257. type: object
  3258. tenantId:
  3259. description: The Azure tenantId of the managed identity used for authentication.
  3260. properties:
  3261. key:
  3262. description: |-
  3263. A key in the referenced Secret.
  3264. Some instances of this field may be defaulted, in others it may be required.
  3265. maxLength: 253
  3266. minLength: 1
  3267. pattern: ^[-._a-zA-Z0-9]+$
  3268. type: string
  3269. name:
  3270. description: The name of the Secret resource being referred to.
  3271. maxLength: 253
  3272. minLength: 1
  3273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3274. type: string
  3275. namespace:
  3276. description: |-
  3277. The namespace of the Secret resource being referred to.
  3278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3279. maxLength: 63
  3280. minLength: 1
  3281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3282. type: string
  3283. type: object
  3284. type: object
  3285. authType:
  3286. default: ServicePrincipal
  3287. description: |-
  3288. Auth type defines how to authenticate to the keyvault service.
  3289. Valid values are:
  3290. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  3291. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  3292. enum:
  3293. - ServicePrincipal
  3294. - ManagedIdentity
  3295. - WorkloadIdentity
  3296. type: string
  3297. environmentType:
  3298. default: PublicCloud
  3299. description: |-
  3300. EnvironmentType specifies the Azure cloud environment endpoints to use for
  3301. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  3302. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  3303. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  3304. enum:
  3305. - PublicCloud
  3306. - USGovernmentCloud
  3307. - ChinaCloud
  3308. - GermanCloud
  3309. type: string
  3310. identityId:
  3311. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  3312. type: string
  3313. serviceAccountRef:
  3314. description: |-
  3315. ServiceAccountRef specified the service account
  3316. that should be used when authenticating with WorkloadIdentity.
  3317. properties:
  3318. audiences:
  3319. description: |-
  3320. Audience specifies the `aud` claim for the service account token
  3321. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3322. then this audiences will be appended to the list
  3323. items:
  3324. type: string
  3325. type: array
  3326. name:
  3327. description: The name of the ServiceAccount resource being referred to.
  3328. maxLength: 253
  3329. minLength: 1
  3330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3331. type: string
  3332. namespace:
  3333. description: |-
  3334. Namespace of the resource being referred to.
  3335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3336. maxLength: 63
  3337. minLength: 1
  3338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3339. type: string
  3340. required:
  3341. - name
  3342. type: object
  3343. tenantId:
  3344. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  3345. type: string
  3346. vaultUrl:
  3347. description: Vault Url from which the secrets to be fetched from.
  3348. type: string
  3349. required:
  3350. - vaultUrl
  3351. type: object
  3352. beyondtrust:
  3353. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  3354. properties:
  3355. auth:
  3356. description: Auth configures how the operator authenticates with Beyondtrust.
  3357. properties:
  3358. apiKey:
  3359. description: APIKey If not provided then ClientID/ClientSecret become required.
  3360. properties:
  3361. secretRef:
  3362. description: SecretRef references a key in a secret that will be used as value.
  3363. properties:
  3364. key:
  3365. description: |-
  3366. A key in the referenced Secret.
  3367. Some instances of this field may be defaulted, in others it may be required.
  3368. maxLength: 253
  3369. minLength: 1
  3370. pattern: ^[-._a-zA-Z0-9]+$
  3371. type: string
  3372. name:
  3373. description: The name of the Secret resource being referred to.
  3374. maxLength: 253
  3375. minLength: 1
  3376. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3377. type: string
  3378. namespace:
  3379. description: |-
  3380. The namespace of the Secret resource being referred to.
  3381. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3382. maxLength: 63
  3383. minLength: 1
  3384. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3385. type: string
  3386. type: object
  3387. value:
  3388. description: Value can be specified directly to set a value without using a secret.
  3389. type: string
  3390. type: object
  3391. certificate:
  3392. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  3393. properties:
  3394. secretRef:
  3395. description: SecretRef references a key in a secret that will be used as value.
  3396. properties:
  3397. key:
  3398. description: |-
  3399. A key in the referenced Secret.
  3400. Some instances of this field may be defaulted, in others it may be required.
  3401. maxLength: 253
  3402. minLength: 1
  3403. pattern: ^[-._a-zA-Z0-9]+$
  3404. type: string
  3405. name:
  3406. description: The name of the Secret resource being referred to.
  3407. maxLength: 253
  3408. minLength: 1
  3409. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3410. type: string
  3411. namespace:
  3412. description: |-
  3413. The namespace of the Secret resource being referred to.
  3414. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3415. maxLength: 63
  3416. minLength: 1
  3417. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3418. type: string
  3419. type: object
  3420. value:
  3421. description: Value can be specified directly to set a value without using a secret.
  3422. type: string
  3423. type: object
  3424. certificateKey:
  3425. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  3426. properties:
  3427. secretRef:
  3428. description: SecretRef references a key in a secret that will be used as value.
  3429. properties:
  3430. key:
  3431. description: |-
  3432. A key in the referenced Secret.
  3433. Some instances of this field may be defaulted, in others it may be required.
  3434. maxLength: 253
  3435. minLength: 1
  3436. pattern: ^[-._a-zA-Z0-9]+$
  3437. type: string
  3438. name:
  3439. description: The name of the Secret resource being referred to.
  3440. maxLength: 253
  3441. minLength: 1
  3442. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3443. type: string
  3444. namespace:
  3445. description: |-
  3446. The namespace of the Secret resource being referred to.
  3447. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3448. maxLength: 63
  3449. minLength: 1
  3450. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3451. type: string
  3452. type: object
  3453. value:
  3454. description: Value can be specified directly to set a value without using a secret.
  3455. type: string
  3456. type: object
  3457. clientId:
  3458. description: ClientID is the API OAuth Client ID.
  3459. properties:
  3460. secretRef:
  3461. description: SecretRef references a key in a secret that will be used as value.
  3462. properties:
  3463. key:
  3464. description: |-
  3465. A key in the referenced Secret.
  3466. Some instances of this field may be defaulted, in others it may be required.
  3467. maxLength: 253
  3468. minLength: 1
  3469. pattern: ^[-._a-zA-Z0-9]+$
  3470. type: string
  3471. name:
  3472. description: The name of the Secret resource being referred to.
  3473. maxLength: 253
  3474. minLength: 1
  3475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3476. type: string
  3477. namespace:
  3478. description: |-
  3479. The namespace of the Secret resource being referred to.
  3480. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3481. maxLength: 63
  3482. minLength: 1
  3483. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3484. type: string
  3485. type: object
  3486. value:
  3487. description: Value can be specified directly to set a value without using a secret.
  3488. type: string
  3489. type: object
  3490. clientSecret:
  3491. description: ClientSecret is the API OAuth Client Secret.
  3492. properties:
  3493. secretRef:
  3494. description: SecretRef references a key in a secret that will be used as value.
  3495. properties:
  3496. key:
  3497. description: |-
  3498. A key in the referenced Secret.
  3499. Some instances of this field may be defaulted, in others it may be required.
  3500. maxLength: 253
  3501. minLength: 1
  3502. pattern: ^[-._a-zA-Z0-9]+$
  3503. type: string
  3504. name:
  3505. description: The name of the Secret resource being referred to.
  3506. maxLength: 253
  3507. minLength: 1
  3508. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3509. type: string
  3510. namespace:
  3511. description: |-
  3512. The namespace of the Secret resource being referred to.
  3513. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3514. maxLength: 63
  3515. minLength: 1
  3516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3517. type: string
  3518. type: object
  3519. value:
  3520. description: Value can be specified directly to set a value without using a secret.
  3521. type: string
  3522. type: object
  3523. type: object
  3524. server:
  3525. description: Auth configures how API server works.
  3526. properties:
  3527. apiUrl:
  3528. type: string
  3529. clientTimeOutSeconds:
  3530. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  3531. type: integer
  3532. retrievalType:
  3533. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  3534. type: string
  3535. separator:
  3536. description: A character that separates the folder names.
  3537. type: string
  3538. verifyCA:
  3539. type: boolean
  3540. required:
  3541. - apiUrl
  3542. - verifyCA
  3543. type: object
  3544. required:
  3545. - auth
  3546. - server
  3547. type: object
  3548. bitwardensecretsmanager:
  3549. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  3550. properties:
  3551. apiURL:
  3552. type: string
  3553. auth:
  3554. description: |-
  3555. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  3556. Make sure that the token being used has permissions on the given secret.
  3557. properties:
  3558. secretRef:
  3559. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  3560. properties:
  3561. credentials:
  3562. description: AccessToken used for the bitwarden instance.
  3563. properties:
  3564. key:
  3565. description: |-
  3566. A key in the referenced Secret.
  3567. Some instances of this field may be defaulted, in others it may be required.
  3568. maxLength: 253
  3569. minLength: 1
  3570. pattern: ^[-._a-zA-Z0-9]+$
  3571. type: string
  3572. name:
  3573. description: The name of the Secret resource being referred to.
  3574. maxLength: 253
  3575. minLength: 1
  3576. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3577. type: string
  3578. namespace:
  3579. description: |-
  3580. The namespace of the Secret resource being referred to.
  3581. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3582. maxLength: 63
  3583. minLength: 1
  3584. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3585. type: string
  3586. type: object
  3587. required:
  3588. - credentials
  3589. type: object
  3590. required:
  3591. - secretRef
  3592. type: object
  3593. bitwardenServerSDKURL:
  3594. type: string
  3595. caBundle:
  3596. description: |-
  3597. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  3598. can be performed.
  3599. type: string
  3600. caProvider:
  3601. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  3602. properties:
  3603. key:
  3604. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3605. maxLength: 253
  3606. minLength: 1
  3607. pattern: ^[-._a-zA-Z0-9]+$
  3608. type: string
  3609. name:
  3610. description: The name of the object located at the provider type.
  3611. maxLength: 253
  3612. minLength: 1
  3613. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3614. type: string
  3615. namespace:
  3616. description: |-
  3617. The namespace the Provider type is in.
  3618. Can only be defined when used in a ClusterSecretStore.
  3619. maxLength: 63
  3620. minLength: 1
  3621. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3622. type: string
  3623. type:
  3624. description: The type of provider to use such as "Secret", or "ConfigMap".
  3625. enum:
  3626. - Secret
  3627. - ConfigMap
  3628. type: string
  3629. required:
  3630. - name
  3631. - type
  3632. type: object
  3633. identityURL:
  3634. type: string
  3635. organizationID:
  3636. description: OrganizationID determines which organization this secret store manages.
  3637. type: string
  3638. projectID:
  3639. description: ProjectID determines which project this secret store manages.
  3640. type: string
  3641. required:
  3642. - auth
  3643. - organizationID
  3644. - projectID
  3645. type: object
  3646. chef:
  3647. description: Chef configures this store to sync secrets with chef server
  3648. properties:
  3649. auth:
  3650. description: Auth defines the information necessary to authenticate against chef Server
  3651. properties:
  3652. secretRef:
  3653. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  3654. properties:
  3655. privateKeySecretRef:
  3656. description: SecretKey is the Signing Key in PEM format, used for authentication.
  3657. properties:
  3658. key:
  3659. description: |-
  3660. A key in the referenced Secret.
  3661. Some instances of this field may be defaulted, in others it may be required.
  3662. maxLength: 253
  3663. minLength: 1
  3664. pattern: ^[-._a-zA-Z0-9]+$
  3665. type: string
  3666. name:
  3667. description: The name of the Secret resource being referred to.
  3668. maxLength: 253
  3669. minLength: 1
  3670. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3671. type: string
  3672. namespace:
  3673. description: |-
  3674. The namespace of the Secret resource being referred to.
  3675. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3676. maxLength: 63
  3677. minLength: 1
  3678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3679. type: string
  3680. type: object
  3681. required:
  3682. - privateKeySecretRef
  3683. type: object
  3684. required:
  3685. - secretRef
  3686. type: object
  3687. serverUrl:
  3688. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  3689. type: string
  3690. username:
  3691. description: UserName should be the user ID on the chef server
  3692. type: string
  3693. required:
  3694. - auth
  3695. - serverUrl
  3696. - username
  3697. type: object
  3698. conjur:
  3699. description: Conjur configures this store to sync secrets using conjur provider
  3700. properties:
  3701. auth:
  3702. properties:
  3703. apikey:
  3704. properties:
  3705. account:
  3706. type: string
  3707. apiKeyRef:
  3708. description: |-
  3709. A reference to a specific 'key' within a Secret resource.
  3710. In some instances, `key` is a required field.
  3711. properties:
  3712. key:
  3713. description: |-
  3714. A key in the referenced Secret.
  3715. Some instances of this field may be defaulted, in others it may be required.
  3716. maxLength: 253
  3717. minLength: 1
  3718. pattern: ^[-._a-zA-Z0-9]+$
  3719. type: string
  3720. name:
  3721. description: The name of the Secret resource being referred to.
  3722. maxLength: 253
  3723. minLength: 1
  3724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3725. type: string
  3726. namespace:
  3727. description: |-
  3728. The namespace of the Secret resource being referred to.
  3729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3730. maxLength: 63
  3731. minLength: 1
  3732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3733. type: string
  3734. type: object
  3735. userRef:
  3736. description: |-
  3737. A reference to a specific 'key' within a Secret resource.
  3738. In some instances, `key` is a required field.
  3739. properties:
  3740. key:
  3741. description: |-
  3742. A key in the referenced Secret.
  3743. Some instances of this field may be defaulted, in others it may be required.
  3744. maxLength: 253
  3745. minLength: 1
  3746. pattern: ^[-._a-zA-Z0-9]+$
  3747. type: string
  3748. name:
  3749. description: The name of the Secret resource being referred to.
  3750. maxLength: 253
  3751. minLength: 1
  3752. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3753. type: string
  3754. namespace:
  3755. description: |-
  3756. The namespace of the Secret resource being referred to.
  3757. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3758. maxLength: 63
  3759. minLength: 1
  3760. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3761. type: string
  3762. type: object
  3763. required:
  3764. - account
  3765. - apiKeyRef
  3766. - userRef
  3767. type: object
  3768. jwt:
  3769. properties:
  3770. account:
  3771. type: string
  3772. hostId:
  3773. description: |-
  3774. Optional HostID for JWT authentication. This may be used depending
  3775. on how the Conjur JWT authenticator policy is configured.
  3776. type: string
  3777. secretRef:
  3778. description: |-
  3779. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  3780. authenticate with Conjur using the JWT authentication method.
  3781. properties:
  3782. key:
  3783. description: |-
  3784. A key in the referenced Secret.
  3785. Some instances of this field may be defaulted, in others it may be required.
  3786. maxLength: 253
  3787. minLength: 1
  3788. pattern: ^[-._a-zA-Z0-9]+$
  3789. type: string
  3790. name:
  3791. description: The name of the Secret resource being referred to.
  3792. maxLength: 253
  3793. minLength: 1
  3794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3795. type: string
  3796. namespace:
  3797. description: |-
  3798. The namespace of the Secret resource being referred to.
  3799. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3800. maxLength: 63
  3801. minLength: 1
  3802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3803. type: string
  3804. type: object
  3805. serviceAccountRef:
  3806. description: |-
  3807. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  3808. a token for with the `TokenRequest` API.
  3809. properties:
  3810. audiences:
  3811. description: |-
  3812. Audience specifies the `aud` claim for the service account token
  3813. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  3814. then this audiences will be appended to the list
  3815. items:
  3816. type: string
  3817. type: array
  3818. name:
  3819. description: The name of the ServiceAccount resource being referred to.
  3820. maxLength: 253
  3821. minLength: 1
  3822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3823. type: string
  3824. namespace:
  3825. description: |-
  3826. Namespace of the resource being referred to.
  3827. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3828. maxLength: 63
  3829. minLength: 1
  3830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3831. type: string
  3832. required:
  3833. - name
  3834. type: object
  3835. serviceID:
  3836. description: The conjur authn jwt webservice id
  3837. type: string
  3838. required:
  3839. - account
  3840. - serviceID
  3841. type: object
  3842. type: object
  3843. caBundle:
  3844. type: string
  3845. caProvider:
  3846. description: |-
  3847. Used to provide custom certificate authority (CA) certificates
  3848. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  3849. that contains a PEM-encoded certificate.
  3850. properties:
  3851. key:
  3852. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  3853. maxLength: 253
  3854. minLength: 1
  3855. pattern: ^[-._a-zA-Z0-9]+$
  3856. type: string
  3857. name:
  3858. description: The name of the object located at the provider type.
  3859. maxLength: 253
  3860. minLength: 1
  3861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3862. type: string
  3863. namespace:
  3864. description: |-
  3865. The namespace the Provider type is in.
  3866. Can only be defined when used in a ClusterSecretStore.
  3867. maxLength: 63
  3868. minLength: 1
  3869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3870. type: string
  3871. type:
  3872. description: The type of provider to use such as "Secret", or "ConfigMap".
  3873. enum:
  3874. - Secret
  3875. - ConfigMap
  3876. type: string
  3877. required:
  3878. - name
  3879. - type
  3880. type: object
  3881. url:
  3882. type: string
  3883. required:
  3884. - auth
  3885. - url
  3886. type: object
  3887. delinea:
  3888. description: |-
  3889. Delinea DevOps Secrets Vault
  3890. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  3891. properties:
  3892. clientId:
  3893. description: ClientID is the non-secret part of the credential.
  3894. properties:
  3895. secretRef:
  3896. description: SecretRef references a key in a secret that will be used as value.
  3897. properties:
  3898. key:
  3899. description: |-
  3900. A key in the referenced Secret.
  3901. Some instances of this field may be defaulted, in others it may be required.
  3902. maxLength: 253
  3903. minLength: 1
  3904. pattern: ^[-._a-zA-Z0-9]+$
  3905. type: string
  3906. name:
  3907. description: The name of the Secret resource being referred to.
  3908. maxLength: 253
  3909. minLength: 1
  3910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3911. type: string
  3912. namespace:
  3913. description: |-
  3914. The namespace of the Secret resource being referred to.
  3915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3916. maxLength: 63
  3917. minLength: 1
  3918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3919. type: string
  3920. type: object
  3921. value:
  3922. description: Value can be specified directly to set a value without using a secret.
  3923. type: string
  3924. type: object
  3925. clientSecret:
  3926. description: ClientSecret is the secret part of the credential.
  3927. properties:
  3928. secretRef:
  3929. description: SecretRef references a key in a secret that will be used as value.
  3930. properties:
  3931. key:
  3932. description: |-
  3933. A key in the referenced Secret.
  3934. Some instances of this field may be defaulted, in others it may be required.
  3935. maxLength: 253
  3936. minLength: 1
  3937. pattern: ^[-._a-zA-Z0-9]+$
  3938. type: string
  3939. name:
  3940. description: The name of the Secret resource being referred to.
  3941. maxLength: 253
  3942. minLength: 1
  3943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  3944. type: string
  3945. namespace:
  3946. description: |-
  3947. The namespace of the Secret resource being referred to.
  3948. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  3949. maxLength: 63
  3950. minLength: 1
  3951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  3952. type: string
  3953. type: object
  3954. value:
  3955. description: Value can be specified directly to set a value without using a secret.
  3956. type: string
  3957. type: object
  3958. tenant:
  3959. description: Tenant is the chosen hostname / site name.
  3960. type: string
  3961. tld:
  3962. description: |-
  3963. TLD is based on the server location that was chosen during provisioning.
  3964. If unset, defaults to "com".
  3965. type: string
  3966. urlTemplate:
  3967. description: |-
  3968. URLTemplate
  3969. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  3970. type: string
  3971. required:
  3972. - clientId
  3973. - clientSecret
  3974. - tenant
  3975. type: object
  3976. device42:
  3977. description: Device42 configures this store to sync secrets using the Device42 provider
  3978. properties:
  3979. auth:
  3980. description: Auth configures how secret-manager authenticates with a Device42 instance.
  3981. properties:
  3982. secretRef:
  3983. properties:
  3984. credentials:
  3985. description: Username / Password is used for authentication.
  3986. properties:
  3987. key:
  3988. description: |-
  3989. A key in the referenced Secret.
  3990. Some instances of this field may be defaulted, in others it may be required.
  3991. maxLength: 253
  3992. minLength: 1
  3993. pattern: ^[-._a-zA-Z0-9]+$
  3994. type: string
  3995. name:
  3996. description: The name of the Secret resource being referred to.
  3997. maxLength: 253
  3998. minLength: 1
  3999. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4000. type: string
  4001. namespace:
  4002. description: |-
  4003. The namespace of the Secret resource being referred to.
  4004. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4005. maxLength: 63
  4006. minLength: 1
  4007. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4008. type: string
  4009. type: object
  4010. type: object
  4011. required:
  4012. - secretRef
  4013. type: object
  4014. host:
  4015. description: URL configures the Device42 instance URL.
  4016. type: string
  4017. required:
  4018. - auth
  4019. - host
  4020. type: object
  4021. doppler:
  4022. description: Doppler configures this store to sync secrets using the Doppler provider
  4023. properties:
  4024. auth:
  4025. description: Auth configures how the Operator authenticates with the Doppler API
  4026. properties:
  4027. secretRef:
  4028. properties:
  4029. dopplerToken:
  4030. description: |-
  4031. The DopplerToken is used for authentication.
  4032. See https://docs.doppler.com/reference/api#authentication for auth token types.
  4033. The Key attribute defaults to dopplerToken if not specified.
  4034. properties:
  4035. key:
  4036. description: |-
  4037. A key in the referenced Secret.
  4038. Some instances of this field may be defaulted, in others it may be required.
  4039. maxLength: 253
  4040. minLength: 1
  4041. pattern: ^[-._a-zA-Z0-9]+$
  4042. type: string
  4043. name:
  4044. description: The name of the Secret resource being referred to.
  4045. maxLength: 253
  4046. minLength: 1
  4047. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4048. type: string
  4049. namespace:
  4050. description: |-
  4051. The namespace of the Secret resource being referred to.
  4052. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4053. maxLength: 63
  4054. minLength: 1
  4055. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4056. type: string
  4057. type: object
  4058. required:
  4059. - dopplerToken
  4060. type: object
  4061. required:
  4062. - secretRef
  4063. type: object
  4064. config:
  4065. description: Doppler config (required if not using a Service Token)
  4066. type: string
  4067. format:
  4068. description: Format enables the downloading of secrets as a file (string)
  4069. enum:
  4070. - json
  4071. - dotnet-json
  4072. - env
  4073. - yaml
  4074. - docker
  4075. type: string
  4076. nameTransformer:
  4077. description: Environment variable compatible name transforms that change secret names to a different format
  4078. enum:
  4079. - upper-camel
  4080. - camel
  4081. - lower-snake
  4082. - tf-var
  4083. - dotnet-env
  4084. - lower-kebab
  4085. type: string
  4086. project:
  4087. description: Doppler project (required if not using a Service Token)
  4088. type: string
  4089. required:
  4090. - auth
  4091. type: object
  4092. fake:
  4093. description: Fake configures a store with static key/value pairs
  4094. properties:
  4095. data:
  4096. items:
  4097. properties:
  4098. key:
  4099. type: string
  4100. value:
  4101. type: string
  4102. valueMap:
  4103. additionalProperties:
  4104. type: string
  4105. description: 'Deprecated: ValueMap is deprecated and is intended to be removed in the future, use the `value` field instead.'
  4106. type: object
  4107. version:
  4108. type: string
  4109. required:
  4110. - key
  4111. type: object
  4112. type: array
  4113. required:
  4114. - data
  4115. type: object
  4116. fortanix:
  4117. description: Fortanix configures this store to sync secrets using the Fortanix provider
  4118. properties:
  4119. apiKey:
  4120. description: APIKey is the API token to access SDKMS Applications.
  4121. properties:
  4122. secretRef:
  4123. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  4124. properties:
  4125. key:
  4126. description: |-
  4127. A key in the referenced Secret.
  4128. Some instances of this field may be defaulted, in others it may be required.
  4129. maxLength: 253
  4130. minLength: 1
  4131. pattern: ^[-._a-zA-Z0-9]+$
  4132. type: string
  4133. name:
  4134. description: The name of the Secret resource being referred to.
  4135. maxLength: 253
  4136. minLength: 1
  4137. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4138. type: string
  4139. namespace:
  4140. description: |-
  4141. The namespace of the Secret resource being referred to.
  4142. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4143. maxLength: 63
  4144. minLength: 1
  4145. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4146. type: string
  4147. type: object
  4148. type: object
  4149. apiUrl:
  4150. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  4151. type: string
  4152. type: object
  4153. gcpsm:
  4154. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  4155. properties:
  4156. auth:
  4157. description: Auth defines the information necessary to authenticate against GCP
  4158. properties:
  4159. secretRef:
  4160. properties:
  4161. secretAccessKeySecretRef:
  4162. description: The SecretAccessKey is used for authentication
  4163. properties:
  4164. key:
  4165. description: |-
  4166. A key in the referenced Secret.
  4167. Some instances of this field may be defaulted, in others it may be required.
  4168. maxLength: 253
  4169. minLength: 1
  4170. pattern: ^[-._a-zA-Z0-9]+$
  4171. type: string
  4172. name:
  4173. description: The name of the Secret resource being referred to.
  4174. maxLength: 253
  4175. minLength: 1
  4176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4177. type: string
  4178. namespace:
  4179. description: |-
  4180. The namespace of the Secret resource being referred to.
  4181. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4182. maxLength: 63
  4183. minLength: 1
  4184. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4185. type: string
  4186. type: object
  4187. type: object
  4188. workloadIdentity:
  4189. properties:
  4190. clusterLocation:
  4191. type: string
  4192. clusterName:
  4193. type: string
  4194. clusterProjectID:
  4195. type: string
  4196. serviceAccountRef:
  4197. description: A reference to a ServiceAccount resource.
  4198. properties:
  4199. audiences:
  4200. description: |-
  4201. Audience specifies the `aud` claim for the service account token
  4202. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4203. then this audiences will be appended to the list
  4204. items:
  4205. type: string
  4206. type: array
  4207. name:
  4208. description: The name of the ServiceAccount resource being referred to.
  4209. maxLength: 253
  4210. minLength: 1
  4211. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4212. type: string
  4213. namespace:
  4214. description: |-
  4215. Namespace of the resource being referred to.
  4216. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4217. maxLength: 63
  4218. minLength: 1
  4219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4220. type: string
  4221. required:
  4222. - name
  4223. type: object
  4224. required:
  4225. - clusterLocation
  4226. - clusterName
  4227. - serviceAccountRef
  4228. type: object
  4229. type: object
  4230. location:
  4231. description: Location optionally defines a location for a secret
  4232. type: string
  4233. projectID:
  4234. description: ProjectID project where secret is located
  4235. type: string
  4236. type: object
  4237. gitlab:
  4238. description: GitLab configures this store to sync secrets using GitLab Variables provider
  4239. properties:
  4240. auth:
  4241. description: Auth configures how secret-manager authenticates with a GitLab instance.
  4242. properties:
  4243. SecretRef:
  4244. properties:
  4245. accessToken:
  4246. description: AccessToken is used for authentication.
  4247. properties:
  4248. key:
  4249. description: |-
  4250. A key in the referenced Secret.
  4251. Some instances of this field may be defaulted, in others it may be required.
  4252. maxLength: 253
  4253. minLength: 1
  4254. pattern: ^[-._a-zA-Z0-9]+$
  4255. type: string
  4256. name:
  4257. description: The name of the Secret resource being referred to.
  4258. maxLength: 253
  4259. minLength: 1
  4260. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4261. type: string
  4262. namespace:
  4263. description: |-
  4264. The namespace of the Secret resource being referred to.
  4265. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4266. maxLength: 63
  4267. minLength: 1
  4268. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4269. type: string
  4270. type: object
  4271. type: object
  4272. required:
  4273. - SecretRef
  4274. type: object
  4275. environment:
  4276. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  4277. type: string
  4278. groupIDs:
  4279. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  4280. items:
  4281. type: string
  4282. type: array
  4283. inheritFromGroups:
  4284. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  4285. type: boolean
  4286. projectID:
  4287. description: ProjectID specifies a project where secrets are located.
  4288. type: string
  4289. url:
  4290. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  4291. type: string
  4292. required:
  4293. - auth
  4294. type: object
  4295. ibm:
  4296. description: IBM configures this store to sync secrets using IBM Cloud provider
  4297. properties:
  4298. auth:
  4299. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  4300. maxProperties: 1
  4301. minProperties: 1
  4302. properties:
  4303. containerAuth:
  4304. description: IBM Container-based auth with IAM Trusted Profile.
  4305. properties:
  4306. iamEndpoint:
  4307. type: string
  4308. profile:
  4309. description: the IBM Trusted Profile
  4310. type: string
  4311. tokenLocation:
  4312. description: Location the token is mounted on the pod
  4313. type: string
  4314. required:
  4315. - profile
  4316. type: object
  4317. secretRef:
  4318. properties:
  4319. secretApiKeySecretRef:
  4320. description: The SecretAccessKey is used for authentication
  4321. properties:
  4322. key:
  4323. description: |-
  4324. A key in the referenced Secret.
  4325. Some instances of this field may be defaulted, in others it may be required.
  4326. maxLength: 253
  4327. minLength: 1
  4328. pattern: ^[-._a-zA-Z0-9]+$
  4329. type: string
  4330. name:
  4331. description: The name of the Secret resource being referred to.
  4332. maxLength: 253
  4333. minLength: 1
  4334. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4335. type: string
  4336. namespace:
  4337. description: |-
  4338. The namespace of the Secret resource being referred to.
  4339. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4340. maxLength: 63
  4341. minLength: 1
  4342. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4343. type: string
  4344. type: object
  4345. type: object
  4346. type: object
  4347. serviceUrl:
  4348. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  4349. type: string
  4350. required:
  4351. - auth
  4352. type: object
  4353. infisical:
  4354. description: Infisical configures this store to sync secrets using the Infisical provider
  4355. properties:
  4356. auth:
  4357. description: Auth configures how the Operator authenticates with the Infisical API
  4358. properties:
  4359. universalAuthCredentials:
  4360. properties:
  4361. clientId:
  4362. description: |-
  4363. A reference to a specific 'key' within a Secret resource.
  4364. In some instances, `key` is a required field.
  4365. properties:
  4366. key:
  4367. description: |-
  4368. A key in the referenced Secret.
  4369. Some instances of this field may be defaulted, in others it may be required.
  4370. maxLength: 253
  4371. minLength: 1
  4372. pattern: ^[-._a-zA-Z0-9]+$
  4373. type: string
  4374. name:
  4375. description: The name of the Secret resource being referred to.
  4376. maxLength: 253
  4377. minLength: 1
  4378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4379. type: string
  4380. namespace:
  4381. description: |-
  4382. The namespace of the Secret resource being referred to.
  4383. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4384. maxLength: 63
  4385. minLength: 1
  4386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4387. type: string
  4388. type: object
  4389. clientSecret:
  4390. description: |-
  4391. A reference to a specific 'key' within a Secret resource.
  4392. In some instances, `key` is a required field.
  4393. properties:
  4394. key:
  4395. description: |-
  4396. A key in the referenced Secret.
  4397. Some instances of this field may be defaulted, in others it may be required.
  4398. maxLength: 253
  4399. minLength: 1
  4400. pattern: ^[-._a-zA-Z0-9]+$
  4401. type: string
  4402. name:
  4403. description: The name of the Secret resource being referred to.
  4404. maxLength: 253
  4405. minLength: 1
  4406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4407. type: string
  4408. namespace:
  4409. description: |-
  4410. The namespace of the Secret resource being referred to.
  4411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4412. maxLength: 63
  4413. minLength: 1
  4414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4415. type: string
  4416. type: object
  4417. required:
  4418. - clientId
  4419. - clientSecret
  4420. type: object
  4421. type: object
  4422. hostAPI:
  4423. default: https://app.infisical.com/api
  4424. type: string
  4425. secretsScope:
  4426. properties:
  4427. environmentSlug:
  4428. type: string
  4429. projectSlug:
  4430. type: string
  4431. recursive:
  4432. default: false
  4433. type: boolean
  4434. secretsPath:
  4435. default: /
  4436. type: string
  4437. required:
  4438. - environmentSlug
  4439. - projectSlug
  4440. type: object
  4441. required:
  4442. - auth
  4443. - secretsScope
  4444. type: object
  4445. keepersecurity:
  4446. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  4447. properties:
  4448. authRef:
  4449. description: |-
  4450. A reference to a specific 'key' within a Secret resource.
  4451. In some instances, `key` is a required field.
  4452. properties:
  4453. key:
  4454. description: |-
  4455. A key in the referenced Secret.
  4456. Some instances of this field may be defaulted, in others it may be required.
  4457. maxLength: 253
  4458. minLength: 1
  4459. pattern: ^[-._a-zA-Z0-9]+$
  4460. type: string
  4461. name:
  4462. description: The name of the Secret resource being referred to.
  4463. maxLength: 253
  4464. minLength: 1
  4465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4466. type: string
  4467. namespace:
  4468. description: |-
  4469. The namespace of the Secret resource being referred to.
  4470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4471. maxLength: 63
  4472. minLength: 1
  4473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4474. type: string
  4475. type: object
  4476. folderID:
  4477. type: string
  4478. required:
  4479. - authRef
  4480. - folderID
  4481. type: object
  4482. kubernetes:
  4483. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  4484. properties:
  4485. auth:
  4486. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  4487. maxProperties: 1
  4488. minProperties: 1
  4489. properties:
  4490. cert:
  4491. description: has both clientCert and clientKey as secretKeySelector
  4492. properties:
  4493. clientCert:
  4494. description: |-
  4495. A reference to a specific 'key' within a Secret resource.
  4496. In some instances, `key` is a required field.
  4497. properties:
  4498. key:
  4499. description: |-
  4500. A key in the referenced Secret.
  4501. Some instances of this field may be defaulted, in others it may be required.
  4502. maxLength: 253
  4503. minLength: 1
  4504. pattern: ^[-._a-zA-Z0-9]+$
  4505. type: string
  4506. name:
  4507. description: The name of the Secret resource being referred to.
  4508. maxLength: 253
  4509. minLength: 1
  4510. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4511. type: string
  4512. namespace:
  4513. description: |-
  4514. The namespace of the Secret resource being referred to.
  4515. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4516. maxLength: 63
  4517. minLength: 1
  4518. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4519. type: string
  4520. type: object
  4521. clientKey:
  4522. description: |-
  4523. A reference to a specific 'key' within a Secret resource.
  4524. In some instances, `key` is a required field.
  4525. properties:
  4526. key:
  4527. description: |-
  4528. A key in the referenced Secret.
  4529. Some instances of this field may be defaulted, in others it may be required.
  4530. maxLength: 253
  4531. minLength: 1
  4532. pattern: ^[-._a-zA-Z0-9]+$
  4533. type: string
  4534. name:
  4535. description: The name of the Secret resource being referred to.
  4536. maxLength: 253
  4537. minLength: 1
  4538. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4539. type: string
  4540. namespace:
  4541. description: |-
  4542. The namespace of the Secret resource being referred to.
  4543. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4544. maxLength: 63
  4545. minLength: 1
  4546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4547. type: string
  4548. type: object
  4549. type: object
  4550. serviceAccount:
  4551. description: points to a service account that should be used for authentication
  4552. properties:
  4553. audiences:
  4554. description: |-
  4555. Audience specifies the `aud` claim for the service account token
  4556. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4557. then this audiences will be appended to the list
  4558. items:
  4559. type: string
  4560. type: array
  4561. name:
  4562. description: The name of the ServiceAccount resource being referred to.
  4563. maxLength: 253
  4564. minLength: 1
  4565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4566. type: string
  4567. namespace:
  4568. description: |-
  4569. Namespace of the resource being referred to.
  4570. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4571. maxLength: 63
  4572. minLength: 1
  4573. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4574. type: string
  4575. required:
  4576. - name
  4577. type: object
  4578. token:
  4579. description: use static token to authenticate with
  4580. properties:
  4581. bearerToken:
  4582. description: |-
  4583. A reference to a specific 'key' within a Secret resource.
  4584. In some instances, `key` is a required field.
  4585. properties:
  4586. key:
  4587. description: |-
  4588. A key in the referenced Secret.
  4589. Some instances of this field may be defaulted, in others it may be required.
  4590. maxLength: 253
  4591. minLength: 1
  4592. pattern: ^[-._a-zA-Z0-9]+$
  4593. type: string
  4594. name:
  4595. description: The name of the Secret resource being referred to.
  4596. maxLength: 253
  4597. minLength: 1
  4598. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4599. type: string
  4600. namespace:
  4601. description: |-
  4602. The namespace of the Secret resource being referred to.
  4603. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4604. maxLength: 63
  4605. minLength: 1
  4606. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4607. type: string
  4608. type: object
  4609. type: object
  4610. type: object
  4611. authRef:
  4612. description: A reference to a secret that contains the auth information.
  4613. properties:
  4614. key:
  4615. description: |-
  4616. A key in the referenced Secret.
  4617. Some instances of this field may be defaulted, in others it may be required.
  4618. maxLength: 253
  4619. minLength: 1
  4620. pattern: ^[-._a-zA-Z0-9]+$
  4621. type: string
  4622. name:
  4623. description: The name of the Secret resource being referred to.
  4624. maxLength: 253
  4625. minLength: 1
  4626. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4627. type: string
  4628. namespace:
  4629. description: |-
  4630. The namespace of the Secret resource being referred to.
  4631. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4632. maxLength: 63
  4633. minLength: 1
  4634. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4635. type: string
  4636. type: object
  4637. remoteNamespace:
  4638. default: default
  4639. description: Remote namespace to fetch the secrets from
  4640. maxLength: 63
  4641. minLength: 1
  4642. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4643. type: string
  4644. server:
  4645. description: configures the Kubernetes server Address.
  4646. properties:
  4647. caBundle:
  4648. description: CABundle is a base64-encoded CA certificate
  4649. format: byte
  4650. type: string
  4651. caProvider:
  4652. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  4653. properties:
  4654. key:
  4655. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  4656. maxLength: 253
  4657. minLength: 1
  4658. pattern: ^[-._a-zA-Z0-9]+$
  4659. type: string
  4660. name:
  4661. description: The name of the object located at the provider type.
  4662. maxLength: 253
  4663. minLength: 1
  4664. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4665. type: string
  4666. namespace:
  4667. description: |-
  4668. The namespace the Provider type is in.
  4669. Can only be defined when used in a ClusterSecretStore.
  4670. maxLength: 63
  4671. minLength: 1
  4672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4673. type: string
  4674. type:
  4675. description: The type of provider to use such as "Secret", or "ConfigMap".
  4676. enum:
  4677. - Secret
  4678. - ConfigMap
  4679. type: string
  4680. required:
  4681. - name
  4682. - type
  4683. type: object
  4684. url:
  4685. default: kubernetes.default
  4686. description: configures the Kubernetes server Address.
  4687. type: string
  4688. type: object
  4689. type: object
  4690. onboardbase:
  4691. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  4692. properties:
  4693. apiHost:
  4694. default: https://public.onboardbase.com/api/v1/
  4695. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  4696. type: string
  4697. auth:
  4698. description: Auth configures how the Operator authenticates with the Onboardbase API
  4699. properties:
  4700. apiKeyRef:
  4701. description: |-
  4702. OnboardbaseAPIKey is the APIKey generated by an admin account.
  4703. It is used to recognize and authorize access to a project and environment within onboardbase
  4704. properties:
  4705. key:
  4706. description: |-
  4707. A key in the referenced Secret.
  4708. Some instances of this field may be defaulted, in others it may be required.
  4709. maxLength: 253
  4710. minLength: 1
  4711. pattern: ^[-._a-zA-Z0-9]+$
  4712. type: string
  4713. name:
  4714. description: The name of the Secret resource being referred to.
  4715. maxLength: 253
  4716. minLength: 1
  4717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4718. type: string
  4719. namespace:
  4720. description: |-
  4721. The namespace of the Secret resource being referred to.
  4722. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4723. maxLength: 63
  4724. minLength: 1
  4725. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4726. type: string
  4727. type: object
  4728. passcodeRef:
  4729. description: OnboardbasePasscode is the passcode attached to the API Key
  4730. properties:
  4731. key:
  4732. description: |-
  4733. A key in the referenced Secret.
  4734. Some instances of this field may be defaulted, in others it may be required.
  4735. maxLength: 253
  4736. minLength: 1
  4737. pattern: ^[-._a-zA-Z0-9]+$
  4738. type: string
  4739. name:
  4740. description: The name of the Secret resource being referred to.
  4741. maxLength: 253
  4742. minLength: 1
  4743. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4744. type: string
  4745. namespace:
  4746. description: |-
  4747. The namespace of the Secret resource being referred to.
  4748. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4749. maxLength: 63
  4750. minLength: 1
  4751. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4752. type: string
  4753. type: object
  4754. required:
  4755. - apiKeyRef
  4756. - passcodeRef
  4757. type: object
  4758. environment:
  4759. default: development
  4760. description: Environment is the name of an environmnent within a project to pull the secrets from
  4761. type: string
  4762. project:
  4763. default: development
  4764. description: Project is an onboardbase project that the secrets should be pulled from
  4765. type: string
  4766. required:
  4767. - apiHost
  4768. - auth
  4769. - environment
  4770. - project
  4771. type: object
  4772. onepassword:
  4773. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  4774. properties:
  4775. auth:
  4776. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  4777. properties:
  4778. secretRef:
  4779. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  4780. properties:
  4781. connectTokenSecretRef:
  4782. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  4783. properties:
  4784. key:
  4785. description: |-
  4786. A key in the referenced Secret.
  4787. Some instances of this field may be defaulted, in others it may be required.
  4788. maxLength: 253
  4789. minLength: 1
  4790. pattern: ^[-._a-zA-Z0-9]+$
  4791. type: string
  4792. name:
  4793. description: The name of the Secret resource being referred to.
  4794. maxLength: 253
  4795. minLength: 1
  4796. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4797. type: string
  4798. namespace:
  4799. description: |-
  4800. The namespace of the Secret resource being referred to.
  4801. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4802. maxLength: 63
  4803. minLength: 1
  4804. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4805. type: string
  4806. type: object
  4807. required:
  4808. - connectTokenSecretRef
  4809. type: object
  4810. required:
  4811. - secretRef
  4812. type: object
  4813. connectHost:
  4814. description: ConnectHost defines the OnePassword Connect Server to connect to
  4815. type: string
  4816. vaults:
  4817. additionalProperties:
  4818. type: integer
  4819. description: Vaults defines which OnePassword vaults to search in which order
  4820. type: object
  4821. required:
  4822. - auth
  4823. - connectHost
  4824. - vaults
  4825. type: object
  4826. oracle:
  4827. description: Oracle configures this store to sync secrets using Oracle Vault provider
  4828. properties:
  4829. auth:
  4830. description: |-
  4831. Auth configures how secret-manager authenticates with the Oracle Vault.
  4832. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  4833. properties:
  4834. secretRef:
  4835. description: SecretRef to pass through sensitive information.
  4836. properties:
  4837. fingerprint:
  4838. description: Fingerprint is the fingerprint of the API private key.
  4839. properties:
  4840. key:
  4841. description: |-
  4842. A key in the referenced Secret.
  4843. Some instances of this field may be defaulted, in others it may be required.
  4844. maxLength: 253
  4845. minLength: 1
  4846. pattern: ^[-._a-zA-Z0-9]+$
  4847. type: string
  4848. name:
  4849. description: The name of the Secret resource being referred to.
  4850. maxLength: 253
  4851. minLength: 1
  4852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4853. type: string
  4854. namespace:
  4855. description: |-
  4856. The namespace of the Secret resource being referred to.
  4857. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4858. maxLength: 63
  4859. minLength: 1
  4860. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4861. type: string
  4862. type: object
  4863. privatekey:
  4864. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  4865. properties:
  4866. key:
  4867. description: |-
  4868. A key in the referenced Secret.
  4869. Some instances of this field may be defaulted, in others it may be required.
  4870. maxLength: 253
  4871. minLength: 1
  4872. pattern: ^[-._a-zA-Z0-9]+$
  4873. type: string
  4874. name:
  4875. description: The name of the Secret resource being referred to.
  4876. maxLength: 253
  4877. minLength: 1
  4878. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4879. type: string
  4880. namespace:
  4881. description: |-
  4882. The namespace of the Secret resource being referred to.
  4883. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4884. maxLength: 63
  4885. minLength: 1
  4886. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4887. type: string
  4888. type: object
  4889. required:
  4890. - fingerprint
  4891. - privatekey
  4892. type: object
  4893. tenancy:
  4894. description: Tenancy is the tenancy OCID where user is located.
  4895. type: string
  4896. user:
  4897. description: User is an access OCID specific to the account.
  4898. type: string
  4899. required:
  4900. - secretRef
  4901. - tenancy
  4902. - user
  4903. type: object
  4904. compartment:
  4905. description: |-
  4906. Compartment is the vault compartment OCID.
  4907. Required for PushSecret
  4908. type: string
  4909. encryptionKey:
  4910. description: |-
  4911. EncryptionKey is the OCID of the encryption key within the vault.
  4912. Required for PushSecret
  4913. type: string
  4914. principalType:
  4915. description: |-
  4916. The type of principal to use for authentication. If left blank, the Auth struct will
  4917. determine the principal type. This optional field must be specified if using
  4918. workload identity.
  4919. enum:
  4920. - ""
  4921. - UserPrincipal
  4922. - InstancePrincipal
  4923. - Workload
  4924. type: string
  4925. region:
  4926. description: Region is the region where vault is located.
  4927. type: string
  4928. serviceAccountRef:
  4929. description: |-
  4930. ServiceAccountRef specified the service account
  4931. that should be used when authenticating with WorkloadIdentity.
  4932. properties:
  4933. audiences:
  4934. description: |-
  4935. Audience specifies the `aud` claim for the service account token
  4936. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  4937. then this audiences will be appended to the list
  4938. items:
  4939. type: string
  4940. type: array
  4941. name:
  4942. description: The name of the ServiceAccount resource being referred to.
  4943. maxLength: 253
  4944. minLength: 1
  4945. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4946. type: string
  4947. namespace:
  4948. description: |-
  4949. Namespace of the resource being referred to.
  4950. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4951. maxLength: 63
  4952. minLength: 1
  4953. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4954. type: string
  4955. required:
  4956. - name
  4957. type: object
  4958. vault:
  4959. description: Vault is the vault's OCID of the specific vault where secret is located.
  4960. type: string
  4961. required:
  4962. - region
  4963. - vault
  4964. type: object
  4965. passbolt:
  4966. properties:
  4967. auth:
  4968. description: Auth defines the information necessary to authenticate against Passbolt Server
  4969. properties:
  4970. passwordSecretRef:
  4971. description: |-
  4972. A reference to a specific 'key' within a Secret resource.
  4973. In some instances, `key` is a required field.
  4974. properties:
  4975. key:
  4976. description: |-
  4977. A key in the referenced Secret.
  4978. Some instances of this field may be defaulted, in others it may be required.
  4979. maxLength: 253
  4980. minLength: 1
  4981. pattern: ^[-._a-zA-Z0-9]+$
  4982. type: string
  4983. name:
  4984. description: The name of the Secret resource being referred to.
  4985. maxLength: 253
  4986. minLength: 1
  4987. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  4988. type: string
  4989. namespace:
  4990. description: |-
  4991. The namespace of the Secret resource being referred to.
  4992. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  4993. maxLength: 63
  4994. minLength: 1
  4995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  4996. type: string
  4997. type: object
  4998. privateKeySecretRef:
  4999. description: |-
  5000. A reference to a specific 'key' within a Secret resource.
  5001. In some instances, `key` is a required field.
  5002. properties:
  5003. key:
  5004. description: |-
  5005. A key in the referenced Secret.
  5006. Some instances of this field may be defaulted, in others it may be required.
  5007. maxLength: 253
  5008. minLength: 1
  5009. pattern: ^[-._a-zA-Z0-9]+$
  5010. type: string
  5011. name:
  5012. description: The name of the Secret resource being referred to.
  5013. maxLength: 253
  5014. minLength: 1
  5015. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5016. type: string
  5017. namespace:
  5018. description: |-
  5019. The namespace of the Secret resource being referred to.
  5020. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5021. maxLength: 63
  5022. minLength: 1
  5023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5024. type: string
  5025. type: object
  5026. required:
  5027. - passwordSecretRef
  5028. - privateKeySecretRef
  5029. type: object
  5030. host:
  5031. description: Host defines the Passbolt Server to connect to
  5032. type: string
  5033. required:
  5034. - auth
  5035. - host
  5036. type: object
  5037. passworddepot:
  5038. description: Configures a store to sync secrets with a Password Depot instance.
  5039. properties:
  5040. auth:
  5041. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  5042. properties:
  5043. secretRef:
  5044. properties:
  5045. credentials:
  5046. description: Username / Password is used for authentication.
  5047. properties:
  5048. key:
  5049. description: |-
  5050. A key in the referenced Secret.
  5051. Some instances of this field may be defaulted, in others it may be required.
  5052. maxLength: 253
  5053. minLength: 1
  5054. pattern: ^[-._a-zA-Z0-9]+$
  5055. type: string
  5056. name:
  5057. description: The name of the Secret resource being referred to.
  5058. maxLength: 253
  5059. minLength: 1
  5060. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5061. type: string
  5062. namespace:
  5063. description: |-
  5064. The namespace of the Secret resource being referred to.
  5065. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5066. maxLength: 63
  5067. minLength: 1
  5068. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5069. type: string
  5070. type: object
  5071. type: object
  5072. required:
  5073. - secretRef
  5074. type: object
  5075. database:
  5076. description: Database to use as source
  5077. type: string
  5078. host:
  5079. description: URL configures the Password Depot instance URL.
  5080. type: string
  5081. required:
  5082. - auth
  5083. - database
  5084. - host
  5085. type: object
  5086. previder:
  5087. description: Previder configures this store to sync secrets using the Previder provider
  5088. properties:
  5089. auth:
  5090. description: PreviderAuth contains a secretRef for credentials.
  5091. properties:
  5092. secretRef:
  5093. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  5094. properties:
  5095. accessToken:
  5096. description: The AccessToken is used for authentication
  5097. properties:
  5098. key:
  5099. description: |-
  5100. A key in the referenced Secret.
  5101. Some instances of this field may be defaulted, in others it may be required.
  5102. maxLength: 253
  5103. minLength: 1
  5104. pattern: ^[-._a-zA-Z0-9]+$
  5105. type: string
  5106. name:
  5107. description: The name of the Secret resource being referred to.
  5108. maxLength: 253
  5109. minLength: 1
  5110. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5111. type: string
  5112. namespace:
  5113. description: |-
  5114. The namespace of the Secret resource being referred to.
  5115. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5116. maxLength: 63
  5117. minLength: 1
  5118. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5119. type: string
  5120. type: object
  5121. required:
  5122. - accessToken
  5123. type: object
  5124. type: object
  5125. baseUri:
  5126. type: string
  5127. required:
  5128. - auth
  5129. type: object
  5130. pulumi:
  5131. description: Pulumi configures this store to sync secrets using the Pulumi provider
  5132. properties:
  5133. accessToken:
  5134. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  5135. properties:
  5136. secretRef:
  5137. description: SecretRef is a reference to a secret containing the Pulumi API token.
  5138. properties:
  5139. key:
  5140. description: |-
  5141. A key in the referenced Secret.
  5142. Some instances of this field may be defaulted, in others it may be required.
  5143. maxLength: 253
  5144. minLength: 1
  5145. pattern: ^[-._a-zA-Z0-9]+$
  5146. type: string
  5147. name:
  5148. description: The name of the Secret resource being referred to.
  5149. maxLength: 253
  5150. minLength: 1
  5151. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5152. type: string
  5153. namespace:
  5154. description: |-
  5155. The namespace of the Secret resource being referred to.
  5156. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5157. maxLength: 63
  5158. minLength: 1
  5159. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5160. type: string
  5161. type: object
  5162. type: object
  5163. apiUrl:
  5164. default: https://api.pulumi.com/api/esc
  5165. description: APIURL is the URL of the Pulumi API.
  5166. type: string
  5167. environment:
  5168. description: |-
  5169. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  5170. dynamically retrieved values from supported providers including all major clouds,
  5171. and other Pulumi ESC environments.
  5172. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  5173. type: string
  5174. organization:
  5175. description: |-
  5176. Organization are a space to collaborate on shared projects and stacks.
  5177. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  5178. type: string
  5179. project:
  5180. description: Project is the name of the Pulumi ESC project the environment belongs to.
  5181. type: string
  5182. required:
  5183. - accessToken
  5184. - environment
  5185. - organization
  5186. - project
  5187. type: object
  5188. scaleway:
  5189. description: Scaleway
  5190. properties:
  5191. accessKey:
  5192. description: AccessKey is the non-secret part of the api key.
  5193. properties:
  5194. secretRef:
  5195. description: SecretRef references a key in a secret that will be used as value.
  5196. properties:
  5197. key:
  5198. description: |-
  5199. A key in the referenced Secret.
  5200. Some instances of this field may be defaulted, in others it may be required.
  5201. maxLength: 253
  5202. minLength: 1
  5203. pattern: ^[-._a-zA-Z0-9]+$
  5204. type: string
  5205. name:
  5206. description: The name of the Secret resource being referred to.
  5207. maxLength: 253
  5208. minLength: 1
  5209. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5210. type: string
  5211. namespace:
  5212. description: |-
  5213. The namespace of the Secret resource being referred to.
  5214. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5215. maxLength: 63
  5216. minLength: 1
  5217. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5218. type: string
  5219. type: object
  5220. value:
  5221. description: Value can be specified directly to set a value without using a secret.
  5222. type: string
  5223. type: object
  5224. apiUrl:
  5225. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  5226. type: string
  5227. projectId:
  5228. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  5229. type: string
  5230. region:
  5231. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  5232. type: string
  5233. secretKey:
  5234. description: SecretKey is the non-secret part of the api key.
  5235. properties:
  5236. secretRef:
  5237. description: SecretRef references a key in a secret that will be used as value.
  5238. properties:
  5239. key:
  5240. description: |-
  5241. A key in the referenced Secret.
  5242. Some instances of this field may be defaulted, in others it may be required.
  5243. maxLength: 253
  5244. minLength: 1
  5245. pattern: ^[-._a-zA-Z0-9]+$
  5246. type: string
  5247. name:
  5248. description: The name of the Secret resource being referred to.
  5249. maxLength: 253
  5250. minLength: 1
  5251. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5252. type: string
  5253. namespace:
  5254. description: |-
  5255. The namespace of the Secret resource being referred to.
  5256. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5257. maxLength: 63
  5258. minLength: 1
  5259. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5260. type: string
  5261. type: object
  5262. value:
  5263. description: Value can be specified directly to set a value without using a secret.
  5264. type: string
  5265. type: object
  5266. required:
  5267. - accessKey
  5268. - projectId
  5269. - region
  5270. - secretKey
  5271. type: object
  5272. secretserver:
  5273. description: |-
  5274. SecretServer configures this store to sync secrets using SecretServer provider
  5275. https://docs.delinea.com/online-help/secret-server/start.htm
  5276. properties:
  5277. password:
  5278. description: Password is the secret server account password.
  5279. properties:
  5280. secretRef:
  5281. description: SecretRef references a key in a secret that will be used as value.
  5282. properties:
  5283. key:
  5284. description: |-
  5285. A key in the referenced Secret.
  5286. Some instances of this field may be defaulted, in others it may be required.
  5287. maxLength: 253
  5288. minLength: 1
  5289. pattern: ^[-._a-zA-Z0-9]+$
  5290. type: string
  5291. name:
  5292. description: The name of the Secret resource being referred to.
  5293. maxLength: 253
  5294. minLength: 1
  5295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5296. type: string
  5297. namespace:
  5298. description: |-
  5299. The namespace of the Secret resource being referred to.
  5300. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5301. maxLength: 63
  5302. minLength: 1
  5303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5304. type: string
  5305. type: object
  5306. value:
  5307. description: Value can be specified directly to set a value without using a secret.
  5308. type: string
  5309. type: object
  5310. serverURL:
  5311. description: |-
  5312. ServerURL
  5313. URL to your secret server installation
  5314. type: string
  5315. username:
  5316. description: Username is the secret server account username.
  5317. properties:
  5318. secretRef:
  5319. description: SecretRef references a key in a secret that will be used as value.
  5320. properties:
  5321. key:
  5322. description: |-
  5323. A key in the referenced Secret.
  5324. Some instances of this field may be defaulted, in others it may be required.
  5325. maxLength: 253
  5326. minLength: 1
  5327. pattern: ^[-._a-zA-Z0-9]+$
  5328. type: string
  5329. name:
  5330. description: The name of the Secret resource being referred to.
  5331. maxLength: 253
  5332. minLength: 1
  5333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5334. type: string
  5335. namespace:
  5336. description: |-
  5337. The namespace of the Secret resource being referred to.
  5338. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5339. maxLength: 63
  5340. minLength: 1
  5341. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5342. type: string
  5343. type: object
  5344. value:
  5345. description: Value can be specified directly to set a value without using a secret.
  5346. type: string
  5347. type: object
  5348. required:
  5349. - password
  5350. - serverURL
  5351. - username
  5352. type: object
  5353. senhasegura:
  5354. description: Senhasegura configures this store to sync secrets using senhasegura provider
  5355. properties:
  5356. auth:
  5357. description: Auth defines parameters to authenticate in senhasegura
  5358. properties:
  5359. clientId:
  5360. type: string
  5361. clientSecretSecretRef:
  5362. description: |-
  5363. A reference to a specific 'key' within a Secret resource.
  5364. In some instances, `key` is a required field.
  5365. properties:
  5366. key:
  5367. description: |-
  5368. A key in the referenced Secret.
  5369. Some instances of this field may be defaulted, in others it may be required.
  5370. maxLength: 253
  5371. minLength: 1
  5372. pattern: ^[-._a-zA-Z0-9]+$
  5373. type: string
  5374. name:
  5375. description: The name of the Secret resource being referred to.
  5376. maxLength: 253
  5377. minLength: 1
  5378. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5379. type: string
  5380. namespace:
  5381. description: |-
  5382. The namespace of the Secret resource being referred to.
  5383. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5384. maxLength: 63
  5385. minLength: 1
  5386. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5387. type: string
  5388. type: object
  5389. required:
  5390. - clientId
  5391. - clientSecretSecretRef
  5392. type: object
  5393. ignoreSslCertificate:
  5394. default: false
  5395. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  5396. type: boolean
  5397. module:
  5398. description: Module defines which senhasegura module should be used to get secrets
  5399. type: string
  5400. url:
  5401. description: URL of senhasegura
  5402. type: string
  5403. required:
  5404. - auth
  5405. - module
  5406. - url
  5407. type: object
  5408. vault:
  5409. description: Vault configures this store to sync secrets using Hashi provider
  5410. properties:
  5411. auth:
  5412. description: Auth configures how secret-manager authenticates with the Vault server.
  5413. properties:
  5414. appRole:
  5415. description: |-
  5416. AppRole authenticates with Vault using the App Role auth mechanism,
  5417. with the role and secret stored in a Kubernetes Secret resource.
  5418. properties:
  5419. path:
  5420. default: approle
  5421. description: |-
  5422. Path where the App Role authentication backend is mounted
  5423. in Vault, e.g: "approle"
  5424. type: string
  5425. roleId:
  5426. description: |-
  5427. RoleID configured in the App Role authentication backend when setting
  5428. up the authentication backend in Vault.
  5429. type: string
  5430. roleRef:
  5431. description: |-
  5432. Reference to a key in a Secret that contains the App Role ID used
  5433. to authenticate with Vault.
  5434. The `key` field must be specified and denotes which entry within the Secret
  5435. resource is used as the app role id.
  5436. properties:
  5437. key:
  5438. description: |-
  5439. A key in the referenced Secret.
  5440. Some instances of this field may be defaulted, in others it may be required.
  5441. maxLength: 253
  5442. minLength: 1
  5443. pattern: ^[-._a-zA-Z0-9]+$
  5444. type: string
  5445. name:
  5446. description: The name of the Secret resource being referred to.
  5447. maxLength: 253
  5448. minLength: 1
  5449. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5450. type: string
  5451. namespace:
  5452. description: |-
  5453. The namespace of the Secret resource being referred to.
  5454. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5455. maxLength: 63
  5456. minLength: 1
  5457. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5458. type: string
  5459. type: object
  5460. secretRef:
  5461. description: |-
  5462. Reference to a key in a Secret that contains the App Role secret used
  5463. to authenticate with Vault.
  5464. The `key` field must be specified and denotes which entry within the Secret
  5465. resource is used as the app role secret.
  5466. properties:
  5467. key:
  5468. description: |-
  5469. A key in the referenced Secret.
  5470. Some instances of this field may be defaulted, in others it may be required.
  5471. maxLength: 253
  5472. minLength: 1
  5473. pattern: ^[-._a-zA-Z0-9]+$
  5474. type: string
  5475. name:
  5476. description: The name of the Secret resource being referred to.
  5477. maxLength: 253
  5478. minLength: 1
  5479. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5480. type: string
  5481. namespace:
  5482. description: |-
  5483. The namespace of the Secret resource being referred to.
  5484. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5485. maxLength: 63
  5486. minLength: 1
  5487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5488. type: string
  5489. type: object
  5490. required:
  5491. - path
  5492. - secretRef
  5493. type: object
  5494. cert:
  5495. description: |-
  5496. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  5497. Cert authentication method
  5498. properties:
  5499. clientCert:
  5500. description: |-
  5501. ClientCert is a certificate to authenticate using the Cert Vault
  5502. authentication method
  5503. properties:
  5504. key:
  5505. description: |-
  5506. A key in the referenced Secret.
  5507. Some instances of this field may be defaulted, in others it may be required.
  5508. maxLength: 253
  5509. minLength: 1
  5510. pattern: ^[-._a-zA-Z0-9]+$
  5511. type: string
  5512. name:
  5513. description: The name of the Secret resource being referred to.
  5514. maxLength: 253
  5515. minLength: 1
  5516. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5517. type: string
  5518. namespace:
  5519. description: |-
  5520. The namespace of the Secret resource being referred to.
  5521. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5522. maxLength: 63
  5523. minLength: 1
  5524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5525. type: string
  5526. type: object
  5527. secretRef:
  5528. description: |-
  5529. SecretRef to a key in a Secret resource containing client private key to
  5530. authenticate with Vault using the Cert authentication method
  5531. properties:
  5532. key:
  5533. description: |-
  5534. A key in the referenced Secret.
  5535. Some instances of this field may be defaulted, in others it may be required.
  5536. maxLength: 253
  5537. minLength: 1
  5538. pattern: ^[-._a-zA-Z0-9]+$
  5539. type: string
  5540. name:
  5541. description: The name of the Secret resource being referred to.
  5542. maxLength: 253
  5543. minLength: 1
  5544. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5545. type: string
  5546. namespace:
  5547. description: |-
  5548. The namespace of the Secret resource being referred to.
  5549. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5550. maxLength: 63
  5551. minLength: 1
  5552. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5553. type: string
  5554. type: object
  5555. type: object
  5556. iam:
  5557. description: |-
  5558. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  5559. AWS IAM authentication method
  5560. properties:
  5561. externalID:
  5562. description: AWS External ID set on assumed IAM roles
  5563. type: string
  5564. jwt:
  5565. description: Specify a service account with IRSA enabled
  5566. properties:
  5567. serviceAccountRef:
  5568. description: A reference to a ServiceAccount resource.
  5569. properties:
  5570. audiences:
  5571. description: |-
  5572. Audience specifies the `aud` claim for the service account token
  5573. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  5574. then this audiences will be appended to the list
  5575. items:
  5576. type: string
  5577. type: array
  5578. name:
  5579. description: The name of the ServiceAccount resource being referred to.
  5580. maxLength: 253
  5581. minLength: 1
  5582. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5583. type: string
  5584. namespace:
  5585. description: |-
  5586. Namespace of the resource being referred to.
  5587. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5588. maxLength: 63
  5589. minLength: 1
  5590. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5591. type: string
  5592. required:
  5593. - name
  5594. type: object
  5595. type: object
  5596. path:
  5597. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  5598. type: string
  5599. region:
  5600. description: AWS region
  5601. type: string
  5602. role:
  5603. description: This is the AWS role to be assumed before talking to vault
  5604. type: string
  5605. secretRef:
  5606. description: Specify credentials in a Secret object
  5607. properties:
  5608. accessKeyIDSecretRef:
  5609. description: The AccessKeyID is used for authentication
  5610. properties:
  5611. key:
  5612. description: |-
  5613. A key in the referenced Secret.
  5614. Some instances of this field may be defaulted, in others it may be required.
  5615. maxLength: 253
  5616. minLength: 1
  5617. pattern: ^[-._a-zA-Z0-9]+$
  5618. type: string
  5619. name:
  5620. description: The name of the Secret resource being referred to.
  5621. maxLength: 253
  5622. minLength: 1
  5623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5624. type: string
  5625. namespace:
  5626. description: |-
  5627. The namespace of the Secret resource being referred to.
  5628. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5629. maxLength: 63
  5630. minLength: 1
  5631. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5632. type: string
  5633. type: object
  5634. secretAccessKeySecretRef:
  5635. description: The SecretAccessKey is used for authentication
  5636. properties:
  5637. key:
  5638. description: |-
  5639. A key in the referenced Secret.
  5640. Some instances of this field may be defaulted, in others it may be required.
  5641. maxLength: 253
  5642. minLength: 1
  5643. pattern: ^[-._a-zA-Z0-9]+$
  5644. type: string
  5645. name:
  5646. description: The name of the Secret resource being referred to.
  5647. maxLength: 253
  5648. minLength: 1
  5649. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5650. type: string
  5651. namespace:
  5652. description: |-
  5653. The namespace of the Secret resource being referred to.
  5654. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5655. maxLength: 63
  5656. minLength: 1
  5657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5658. type: string
  5659. type: object
  5660. sessionTokenSecretRef:
  5661. description: |-
  5662. The SessionToken used for authentication
  5663. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  5664. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  5665. properties:
  5666. key:
  5667. description: |-
  5668. A key in the referenced Secret.
  5669. Some instances of this field may be defaulted, in others it may be required.
  5670. maxLength: 253
  5671. minLength: 1
  5672. pattern: ^[-._a-zA-Z0-9]+$
  5673. type: string
  5674. name:
  5675. description: The name of the Secret resource being referred to.
  5676. maxLength: 253
  5677. minLength: 1
  5678. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5679. type: string
  5680. namespace:
  5681. description: |-
  5682. The namespace of the Secret resource being referred to.
  5683. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5684. maxLength: 63
  5685. minLength: 1
  5686. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5687. type: string
  5688. type: object
  5689. type: object
  5690. vaultAwsIamServerID:
  5691. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  5692. type: string
  5693. vaultRole:
  5694. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  5695. type: string
  5696. required:
  5697. - vaultRole
  5698. type: object
  5699. jwt:
  5700. description: |-
  5701. Jwt authenticates with Vault by passing role and JWT token using the
  5702. JWT/OIDC authentication method
  5703. properties:
  5704. kubernetesServiceAccountToken:
  5705. description: |-
  5706. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  5707. a token for with the `TokenRequest` API.
  5708. properties:
  5709. audiences:
  5710. description: |-
  5711. Optional audiences field that will be used to request a temporary Kubernetes service
  5712. account token for the service account referenced by `serviceAccountRef`.
  5713. Defaults to a single audience `vault` it not specified.
  5714. Deprecated: use serviceAccountRef.Audiences instead
  5715. items:
  5716. type: string
  5717. type: array
  5718. expirationSeconds:
  5719. description: |-
  5720. Optional expiration time in seconds that will be used to request a temporary
  5721. Kubernetes service account token for the service account referenced by
  5722. `serviceAccountRef`.
  5723. Deprecated: this will be removed in the future.
  5724. Defaults to 10 minutes.
  5725. format: int64
  5726. type: integer
  5727. serviceAccountRef:
  5728. description: Service account field containing the name of a kubernetes ServiceAccount.
  5729. properties:
  5730. audiences:
  5731. description: |-
  5732. Audience specifies the `aud` claim for the service account token
  5733. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  5734. then this audiences will be appended to the list
  5735. items:
  5736. type: string
  5737. type: array
  5738. name:
  5739. description: The name of the ServiceAccount resource being referred to.
  5740. maxLength: 253
  5741. minLength: 1
  5742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5743. type: string
  5744. namespace:
  5745. description: |-
  5746. Namespace of the resource being referred to.
  5747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5748. maxLength: 63
  5749. minLength: 1
  5750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5751. type: string
  5752. required:
  5753. - name
  5754. type: object
  5755. required:
  5756. - serviceAccountRef
  5757. type: object
  5758. path:
  5759. default: jwt
  5760. description: |-
  5761. Path where the JWT authentication backend is mounted
  5762. in Vault, e.g: "jwt"
  5763. type: string
  5764. role:
  5765. description: |-
  5766. Role is a JWT role to authenticate using the JWT/OIDC Vault
  5767. authentication method
  5768. type: string
  5769. secretRef:
  5770. description: |-
  5771. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  5772. authenticate with Vault using the JWT/OIDC authentication method.
  5773. properties:
  5774. key:
  5775. description: |-
  5776. A key in the referenced Secret.
  5777. Some instances of this field may be defaulted, in others it may be required.
  5778. maxLength: 253
  5779. minLength: 1
  5780. pattern: ^[-._a-zA-Z0-9]+$
  5781. type: string
  5782. name:
  5783. description: The name of the Secret resource being referred to.
  5784. maxLength: 253
  5785. minLength: 1
  5786. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5787. type: string
  5788. namespace:
  5789. description: |-
  5790. The namespace of the Secret resource being referred to.
  5791. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5792. maxLength: 63
  5793. minLength: 1
  5794. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5795. type: string
  5796. type: object
  5797. required:
  5798. - path
  5799. type: object
  5800. kubernetes:
  5801. description: |-
  5802. Kubernetes authenticates with Vault by passing the ServiceAccount
  5803. token stored in the named Secret resource to the Vault server.
  5804. properties:
  5805. mountPath:
  5806. default: kubernetes
  5807. description: |-
  5808. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  5809. "kubernetes"
  5810. type: string
  5811. role:
  5812. description: |-
  5813. A required field containing the Vault Role to assume. A Role binds a
  5814. Kubernetes ServiceAccount with a set of Vault policies.
  5815. type: string
  5816. secretRef:
  5817. description: |-
  5818. Optional secret field containing a Kubernetes ServiceAccount JWT used
  5819. for authenticating with Vault. If a name is specified without a key,
  5820. `token` is the default. If one is not specified, the one bound to
  5821. the controller will be used.
  5822. properties:
  5823. key:
  5824. description: |-
  5825. A key in the referenced Secret.
  5826. Some instances of this field may be defaulted, in others it may be required.
  5827. maxLength: 253
  5828. minLength: 1
  5829. pattern: ^[-._a-zA-Z0-9]+$
  5830. type: string
  5831. name:
  5832. description: The name of the Secret resource being referred to.
  5833. maxLength: 253
  5834. minLength: 1
  5835. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5836. type: string
  5837. namespace:
  5838. description: |-
  5839. The namespace of the Secret resource being referred to.
  5840. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5841. maxLength: 63
  5842. minLength: 1
  5843. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5844. type: string
  5845. type: object
  5846. serviceAccountRef:
  5847. description: |-
  5848. Optional service account field containing the name of a kubernetes ServiceAccount.
  5849. If the service account is specified, the service account secret token JWT will be used
  5850. for authenticating with Vault. If the service account selector is not supplied,
  5851. the secretRef will be used instead.
  5852. properties:
  5853. audiences:
  5854. description: |-
  5855. Audience specifies the `aud` claim for the service account token
  5856. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  5857. then this audiences will be appended to the list
  5858. items:
  5859. type: string
  5860. type: array
  5861. name:
  5862. description: The name of the ServiceAccount resource being referred to.
  5863. maxLength: 253
  5864. minLength: 1
  5865. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5866. type: string
  5867. namespace:
  5868. description: |-
  5869. Namespace of the resource being referred to.
  5870. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5871. maxLength: 63
  5872. minLength: 1
  5873. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5874. type: string
  5875. required:
  5876. - name
  5877. type: object
  5878. required:
  5879. - mountPath
  5880. - role
  5881. type: object
  5882. ldap:
  5883. description: |-
  5884. Ldap authenticates with Vault by passing username/password pair using
  5885. the LDAP authentication method
  5886. properties:
  5887. path:
  5888. default: ldap
  5889. description: |-
  5890. Path where the LDAP authentication backend is mounted
  5891. in Vault, e.g: "ldap"
  5892. type: string
  5893. secretRef:
  5894. description: |-
  5895. SecretRef to a key in a Secret resource containing password for the LDAP
  5896. user used to authenticate with Vault using the LDAP authentication
  5897. method
  5898. properties:
  5899. key:
  5900. description: |-
  5901. A key in the referenced Secret.
  5902. Some instances of this field may be defaulted, in others it may be required.
  5903. maxLength: 253
  5904. minLength: 1
  5905. pattern: ^[-._a-zA-Z0-9]+$
  5906. type: string
  5907. name:
  5908. description: The name of the Secret resource being referred to.
  5909. maxLength: 253
  5910. minLength: 1
  5911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5912. type: string
  5913. namespace:
  5914. description: |-
  5915. The namespace of the Secret resource being referred to.
  5916. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5917. maxLength: 63
  5918. minLength: 1
  5919. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5920. type: string
  5921. type: object
  5922. username:
  5923. description: |-
  5924. Username is a LDAP user name used to authenticate using the LDAP Vault
  5925. authentication method
  5926. type: string
  5927. required:
  5928. - path
  5929. - username
  5930. type: object
  5931. namespace:
  5932. description: |-
  5933. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  5934. Namespaces is a set of features within Vault Enterprise that allows
  5935. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  5936. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  5937. This will default to Vault.Namespace field if set, or empty otherwise
  5938. type: string
  5939. tokenSecretRef:
  5940. description: TokenSecretRef authenticates with Vault by presenting a token.
  5941. properties:
  5942. key:
  5943. description: |-
  5944. A key in the referenced Secret.
  5945. Some instances of this field may be defaulted, in others it may be required.
  5946. maxLength: 253
  5947. minLength: 1
  5948. pattern: ^[-._a-zA-Z0-9]+$
  5949. type: string
  5950. name:
  5951. description: The name of the Secret resource being referred to.
  5952. maxLength: 253
  5953. minLength: 1
  5954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5955. type: string
  5956. namespace:
  5957. description: |-
  5958. The namespace of the Secret resource being referred to.
  5959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5960. maxLength: 63
  5961. minLength: 1
  5962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  5963. type: string
  5964. type: object
  5965. userPass:
  5966. description: UserPass authenticates with Vault by passing username/password pair
  5967. properties:
  5968. path:
  5969. default: user
  5970. description: |-
  5971. Path where the UserPassword authentication backend is mounted
  5972. in Vault, e.g: "user"
  5973. type: string
  5974. secretRef:
  5975. description: |-
  5976. SecretRef to a key in a Secret resource containing password for the
  5977. user used to authenticate with Vault using the UserPass authentication
  5978. method
  5979. properties:
  5980. key:
  5981. description: |-
  5982. A key in the referenced Secret.
  5983. Some instances of this field may be defaulted, in others it may be required.
  5984. maxLength: 253
  5985. minLength: 1
  5986. pattern: ^[-._a-zA-Z0-9]+$
  5987. type: string
  5988. name:
  5989. description: The name of the Secret resource being referred to.
  5990. maxLength: 253
  5991. minLength: 1
  5992. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  5993. type: string
  5994. namespace:
  5995. description: |-
  5996. The namespace of the Secret resource being referred to.
  5997. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  5998. maxLength: 63
  5999. minLength: 1
  6000. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6001. type: string
  6002. type: object
  6003. username:
  6004. description: |-
  6005. Username is a user name used to authenticate using the UserPass Vault
  6006. authentication method
  6007. type: string
  6008. required:
  6009. - path
  6010. - username
  6011. type: object
  6012. type: object
  6013. caBundle:
  6014. description: |-
  6015. PEM encoded CA bundle used to validate Vault server certificate. Only used
  6016. if the Server URL is using HTTPS protocol. This parameter is ignored for
  6017. plain HTTP protocol connection. If not set the system root certificates
  6018. are used to validate the TLS connection.
  6019. format: byte
  6020. type: string
  6021. caProvider:
  6022. description: The provider for the CA bundle to use to validate Vault server certificate.
  6023. properties:
  6024. key:
  6025. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6026. maxLength: 253
  6027. minLength: 1
  6028. pattern: ^[-._a-zA-Z0-9]+$
  6029. type: string
  6030. name:
  6031. description: The name of the object located at the provider type.
  6032. maxLength: 253
  6033. minLength: 1
  6034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6035. type: string
  6036. namespace:
  6037. description: |-
  6038. The namespace the Provider type is in.
  6039. Can only be defined when used in a ClusterSecretStore.
  6040. maxLength: 63
  6041. minLength: 1
  6042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6043. type: string
  6044. type:
  6045. description: The type of provider to use such as "Secret", or "ConfigMap".
  6046. enum:
  6047. - Secret
  6048. - ConfigMap
  6049. type: string
  6050. required:
  6051. - name
  6052. - type
  6053. type: object
  6054. forwardInconsistent:
  6055. description: |-
  6056. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  6057. leader instead of simply retrying within a loop. This can increase performance if
  6058. the option is enabled serverside.
  6059. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  6060. type: boolean
  6061. headers:
  6062. additionalProperties:
  6063. type: string
  6064. description: Headers to be added in Vault request
  6065. type: object
  6066. namespace:
  6067. description: |-
  6068. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  6069. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  6070. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  6071. type: string
  6072. path:
  6073. description: |-
  6074. Path is the mount path of the Vault KV backend endpoint, e.g:
  6075. "secret". The v2 KV secret engine version specific "/data" path suffix
  6076. for fetching secrets from Vault is optional and will be appended
  6077. if not present in specified path.
  6078. type: string
  6079. readYourWrites:
  6080. description: |-
  6081. ReadYourWrites ensures isolated read-after-write semantics by
  6082. providing discovered cluster replication states in each request.
  6083. More information about eventual consistency in Vault can be found here
  6084. https://www.vaultproject.io/docs/enterprise/consistency
  6085. type: boolean
  6086. server:
  6087. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  6088. type: string
  6089. tls:
  6090. description: |-
  6091. The configuration used for client side related TLS communication, when the Vault server
  6092. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  6093. This parameter is ignored for plain HTTP protocol connection.
  6094. It's worth noting this configuration is different from the "TLS certificates auth method",
  6095. which is available under the `auth.cert` section.
  6096. properties:
  6097. certSecretRef:
  6098. description: |-
  6099. CertSecretRef is a certificate added to the transport layer
  6100. when communicating with the Vault server.
  6101. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  6102. properties:
  6103. key:
  6104. description: |-
  6105. A key in the referenced Secret.
  6106. Some instances of this field may be defaulted, in others it may be required.
  6107. maxLength: 253
  6108. minLength: 1
  6109. pattern: ^[-._a-zA-Z0-9]+$
  6110. type: string
  6111. name:
  6112. description: The name of the Secret resource being referred to.
  6113. maxLength: 253
  6114. minLength: 1
  6115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6116. type: string
  6117. namespace:
  6118. description: |-
  6119. The namespace of the Secret resource being referred to.
  6120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6121. maxLength: 63
  6122. minLength: 1
  6123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6124. type: string
  6125. type: object
  6126. keySecretRef:
  6127. description: |-
  6128. KeySecretRef to a key in a Secret resource containing client private key
  6129. added to the transport layer when communicating with the Vault server.
  6130. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  6131. properties:
  6132. key:
  6133. description: |-
  6134. A key in the referenced Secret.
  6135. Some instances of this field may be defaulted, in others it may be required.
  6136. maxLength: 253
  6137. minLength: 1
  6138. pattern: ^[-._a-zA-Z0-9]+$
  6139. type: string
  6140. name:
  6141. description: The name of the Secret resource being referred to.
  6142. maxLength: 253
  6143. minLength: 1
  6144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6145. type: string
  6146. namespace:
  6147. description: |-
  6148. The namespace of the Secret resource being referred to.
  6149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6150. maxLength: 63
  6151. minLength: 1
  6152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6153. type: string
  6154. type: object
  6155. type: object
  6156. version:
  6157. default: v2
  6158. description: |-
  6159. Version is the Vault KV secret engine version. This can be either "v1" or
  6160. "v2". Version defaults to "v2".
  6161. enum:
  6162. - v1
  6163. - v2
  6164. type: string
  6165. required:
  6166. - auth
  6167. - server
  6168. type: object
  6169. webhook:
  6170. description: Webhook configures this store to sync secrets using a generic templated webhook
  6171. properties:
  6172. body:
  6173. description: Body
  6174. type: string
  6175. caBundle:
  6176. description: |-
  6177. PEM encoded CA bundle used to validate webhook server certificate. Only used
  6178. if the Server URL is using HTTPS protocol. This parameter is ignored for
  6179. plain HTTP protocol connection. If not set the system root certificates
  6180. are used to validate the TLS connection.
  6181. format: byte
  6182. type: string
  6183. caProvider:
  6184. description: The provider for the CA bundle to use to validate webhook server certificate.
  6185. properties:
  6186. key:
  6187. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  6188. maxLength: 253
  6189. minLength: 1
  6190. pattern: ^[-._a-zA-Z0-9]+$
  6191. type: string
  6192. name:
  6193. description: The name of the object located at the provider type.
  6194. maxLength: 253
  6195. minLength: 1
  6196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6197. type: string
  6198. namespace:
  6199. description: The namespace the Provider type is in.
  6200. maxLength: 63
  6201. minLength: 1
  6202. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6203. type: string
  6204. type:
  6205. description: The type of provider to use such as "Secret", or "ConfigMap".
  6206. enum:
  6207. - Secret
  6208. - ConfigMap
  6209. type: string
  6210. required:
  6211. - name
  6212. - type
  6213. type: object
  6214. headers:
  6215. additionalProperties:
  6216. type: string
  6217. description: Headers
  6218. type: object
  6219. method:
  6220. description: Webhook Method
  6221. type: string
  6222. result:
  6223. description: Result formatting
  6224. properties:
  6225. jsonPath:
  6226. description: Json path of return value
  6227. type: string
  6228. type: object
  6229. secrets:
  6230. description: |-
  6231. Secrets to fill in templates
  6232. These secrets will be passed to the templating function as key value pairs under the given name
  6233. items:
  6234. properties:
  6235. name:
  6236. description: Name of this secret in templates
  6237. type: string
  6238. secretRef:
  6239. description: Secret ref to fill in credentials
  6240. properties:
  6241. key:
  6242. description: |-
  6243. A key in the referenced Secret.
  6244. Some instances of this field may be defaulted, in others it may be required.
  6245. maxLength: 253
  6246. minLength: 1
  6247. pattern: ^[-._a-zA-Z0-9]+$
  6248. type: string
  6249. name:
  6250. description: The name of the Secret resource being referred to.
  6251. maxLength: 253
  6252. minLength: 1
  6253. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6254. type: string
  6255. namespace:
  6256. description: |-
  6257. The namespace of the Secret resource being referred to.
  6258. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6259. maxLength: 63
  6260. minLength: 1
  6261. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6262. type: string
  6263. type: object
  6264. required:
  6265. - name
  6266. - secretRef
  6267. type: object
  6268. type: array
  6269. timeout:
  6270. description: Timeout
  6271. type: string
  6272. url:
  6273. description: Webhook url to call
  6274. type: string
  6275. required:
  6276. - result
  6277. - url
  6278. type: object
  6279. yandexcertificatemanager:
  6280. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  6281. properties:
  6282. apiEndpoint:
  6283. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  6284. type: string
  6285. auth:
  6286. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  6287. properties:
  6288. authorizedKeySecretRef:
  6289. description: The authorized key used for authentication
  6290. properties:
  6291. key:
  6292. description: |-
  6293. A key in the referenced Secret.
  6294. Some instances of this field may be defaulted, in others it may be required.
  6295. maxLength: 253
  6296. minLength: 1
  6297. pattern: ^[-._a-zA-Z0-9]+$
  6298. type: string
  6299. name:
  6300. description: The name of the Secret resource being referred to.
  6301. maxLength: 253
  6302. minLength: 1
  6303. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6304. type: string
  6305. namespace:
  6306. description: |-
  6307. The namespace of the Secret resource being referred to.
  6308. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6309. maxLength: 63
  6310. minLength: 1
  6311. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6312. type: string
  6313. type: object
  6314. type: object
  6315. caProvider:
  6316. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  6317. properties:
  6318. certSecretRef:
  6319. description: |-
  6320. A reference to a specific 'key' within a Secret resource.
  6321. In some instances, `key` is a required field.
  6322. properties:
  6323. key:
  6324. description: |-
  6325. A key in the referenced Secret.
  6326. Some instances of this field may be defaulted, in others it may be required.
  6327. maxLength: 253
  6328. minLength: 1
  6329. pattern: ^[-._a-zA-Z0-9]+$
  6330. type: string
  6331. name:
  6332. description: The name of the Secret resource being referred to.
  6333. maxLength: 253
  6334. minLength: 1
  6335. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6336. type: string
  6337. namespace:
  6338. description: |-
  6339. The namespace of the Secret resource being referred to.
  6340. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6341. maxLength: 63
  6342. minLength: 1
  6343. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6344. type: string
  6345. type: object
  6346. type: object
  6347. required:
  6348. - auth
  6349. type: object
  6350. yandexlockbox:
  6351. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  6352. properties:
  6353. apiEndpoint:
  6354. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  6355. type: string
  6356. auth:
  6357. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  6358. properties:
  6359. authorizedKeySecretRef:
  6360. description: The authorized key used for authentication
  6361. properties:
  6362. key:
  6363. description: |-
  6364. A key in the referenced Secret.
  6365. Some instances of this field may be defaulted, in others it may be required.
  6366. maxLength: 253
  6367. minLength: 1
  6368. pattern: ^[-._a-zA-Z0-9]+$
  6369. type: string
  6370. name:
  6371. description: The name of the Secret resource being referred to.
  6372. maxLength: 253
  6373. minLength: 1
  6374. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6375. type: string
  6376. namespace:
  6377. description: |-
  6378. The namespace of the Secret resource being referred to.
  6379. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6380. maxLength: 63
  6381. minLength: 1
  6382. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6383. type: string
  6384. type: object
  6385. type: object
  6386. caProvider:
  6387. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  6388. properties:
  6389. certSecretRef:
  6390. description: |-
  6391. A reference to a specific 'key' within a Secret resource.
  6392. In some instances, `key` is a required field.
  6393. properties:
  6394. key:
  6395. description: |-
  6396. A key in the referenced Secret.
  6397. Some instances of this field may be defaulted, in others it may be required.
  6398. maxLength: 253
  6399. minLength: 1
  6400. pattern: ^[-._a-zA-Z0-9]+$
  6401. type: string
  6402. name:
  6403. description: The name of the Secret resource being referred to.
  6404. maxLength: 253
  6405. minLength: 1
  6406. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6407. type: string
  6408. namespace:
  6409. description: |-
  6410. The namespace of the Secret resource being referred to.
  6411. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  6412. maxLength: 63
  6413. minLength: 1
  6414. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  6415. type: string
  6416. type: object
  6417. type: object
  6418. required:
  6419. - auth
  6420. type: object
  6421. type: object
  6422. refreshInterval:
  6423. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  6424. type: integer
  6425. retrySettings:
  6426. description: Used to configure http retries if failed
  6427. properties:
  6428. maxRetries:
  6429. format: int32
  6430. type: integer
  6431. retryInterval:
  6432. type: string
  6433. type: object
  6434. required:
  6435. - provider
  6436. type: object
  6437. status:
  6438. description: SecretStoreStatus defines the observed state of the SecretStore.
  6439. properties:
  6440. capabilities:
  6441. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  6442. type: string
  6443. conditions:
  6444. items:
  6445. properties:
  6446. lastTransitionTime:
  6447. format: date-time
  6448. type: string
  6449. message:
  6450. type: string
  6451. reason:
  6452. type: string
  6453. status:
  6454. type: string
  6455. type:
  6456. type: string
  6457. required:
  6458. - status
  6459. - type
  6460. type: object
  6461. type: array
  6462. type: object
  6463. type: object
  6464. served: true
  6465. storage: true
  6466. subresources:
  6467. status: {}
  6468. conversion:
  6469. strategy: Webhook
  6470. webhook:
  6471. conversionReviewVersions:
  6472. - v1
  6473. clientConfig:
  6474. service:
  6475. name: kubernetes
  6476. namespace: default
  6477. path: /convert
  6478. ---
  6479. apiVersion: apiextensions.k8s.io/v1
  6480. kind: CustomResourceDefinition
  6481. metadata:
  6482. annotations:
  6483. controller-gen.kubebuilder.io/version: v0.16.5
  6484. labels:
  6485. external-secrets.io/component: controller
  6486. name: externalsecrets.external-secrets.io
  6487. spec:
  6488. group: external-secrets.io
  6489. names:
  6490. categories:
  6491. - external-secrets
  6492. kind: ExternalSecret
  6493. listKind: ExternalSecretList
  6494. plural: externalsecrets
  6495. shortNames:
  6496. - es
  6497. singular: externalsecret
  6498. scope: Namespaced
  6499. versions:
  6500. - additionalPrinterColumns:
  6501. - jsonPath: .spec.secretStoreRef.name
  6502. name: Store
  6503. type: string
  6504. - jsonPath: .spec.refreshInterval
  6505. name: Refresh Interval
  6506. type: string
  6507. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  6508. name: Status
  6509. type: string
  6510. deprecated: true
  6511. name: v1alpha1
  6512. schema:
  6513. openAPIV3Schema:
  6514. description: ExternalSecret is the Schema for the external-secrets API.
  6515. properties:
  6516. apiVersion:
  6517. description: |-
  6518. APIVersion defines the versioned schema of this representation of an object.
  6519. Servers should convert recognized schemas to the latest internal value, and
  6520. may reject unrecognized values.
  6521. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  6522. type: string
  6523. kind:
  6524. description: |-
  6525. Kind is a string value representing the REST resource this object represents.
  6526. Servers may infer this from the endpoint the client submits requests to.
  6527. Cannot be updated.
  6528. In CamelCase.
  6529. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  6530. type: string
  6531. metadata:
  6532. type: object
  6533. spec:
  6534. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  6535. properties:
  6536. data:
  6537. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  6538. items:
  6539. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  6540. properties:
  6541. remoteRef:
  6542. description: ExternalSecretDataRemoteRef defines Provider data location.
  6543. properties:
  6544. conversionStrategy:
  6545. default: Default
  6546. description: Used to define a conversion Strategy
  6547. enum:
  6548. - Default
  6549. - Unicode
  6550. type: string
  6551. key:
  6552. description: Key is the key used in the Provider, mandatory
  6553. type: string
  6554. property:
  6555. description: Used to select a specific property of the Provider value (if a map), if supported
  6556. type: string
  6557. version:
  6558. description: Used to select a specific version of the Provider value, if supported
  6559. type: string
  6560. required:
  6561. - key
  6562. type: object
  6563. secretKey:
  6564. description: The key in the Kubernetes Secret to store the value.
  6565. maxLength: 253
  6566. minLength: 1
  6567. pattern: ^[-._a-zA-Z0-9]+$
  6568. type: string
  6569. required:
  6570. - remoteRef
  6571. - secretKey
  6572. type: object
  6573. type: array
  6574. dataFrom:
  6575. description: |-
  6576. DataFrom is used to fetch all properties from a specific Provider data
  6577. If multiple entries are specified, the Secret keys are merged in the specified order
  6578. items:
  6579. description: ExternalSecretDataRemoteRef defines Provider data location.
  6580. properties:
  6581. conversionStrategy:
  6582. default: Default
  6583. description: Used to define a conversion Strategy
  6584. enum:
  6585. - Default
  6586. - Unicode
  6587. type: string
  6588. key:
  6589. description: Key is the key used in the Provider, mandatory
  6590. type: string
  6591. property:
  6592. description: Used to select a specific property of the Provider value (if a map), if supported
  6593. type: string
  6594. version:
  6595. description: Used to select a specific version of the Provider value, if supported
  6596. type: string
  6597. required:
  6598. - key
  6599. type: object
  6600. type: array
  6601. refreshInterval:
  6602. default: 1h
  6603. description: |-
  6604. RefreshInterval is the amount of time before the values are read again from the SecretStore provider
  6605. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  6606. May be set to zero to fetch and create it once. Defaults to 1h.
  6607. type: string
  6608. secretStoreRef:
  6609. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  6610. properties:
  6611. kind:
  6612. description: |-
  6613. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  6614. Defaults to `SecretStore`
  6615. enum:
  6616. - SecretStore
  6617. - ClusterSecretStore
  6618. type: string
  6619. name:
  6620. description: Name of the SecretStore resource
  6621. maxLength: 253
  6622. minLength: 1
  6623. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6624. type: string
  6625. type: object
  6626. target:
  6627. description: |-
  6628. ExternalSecretTarget defines the Kubernetes Secret to be created
  6629. There can be only one target per ExternalSecret.
  6630. properties:
  6631. creationPolicy:
  6632. default: Owner
  6633. description: |-
  6634. CreationPolicy defines rules on how to create the resulting Secret.
  6635. Defaults to "Owner"
  6636. enum:
  6637. - Owner
  6638. - Merge
  6639. - None
  6640. type: string
  6641. immutable:
  6642. description: Immutable defines if the final secret will be immutable
  6643. type: boolean
  6644. name:
  6645. description: |-
  6646. The name of the Secret resource to be managed.
  6647. Defaults to the .metadata.name of the ExternalSecret resource
  6648. maxLength: 253
  6649. minLength: 1
  6650. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6651. type: string
  6652. template:
  6653. description: Template defines a blueprint for the created Secret resource.
  6654. properties:
  6655. data:
  6656. additionalProperties:
  6657. type: string
  6658. type: object
  6659. engineVersion:
  6660. default: v1
  6661. description: |-
  6662. EngineVersion specifies the template engine version
  6663. that should be used to compile/execute the
  6664. template specified in .data and .templateFrom[].
  6665. enum:
  6666. - v1
  6667. - v2
  6668. type: string
  6669. metadata:
  6670. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  6671. properties:
  6672. annotations:
  6673. additionalProperties:
  6674. type: string
  6675. type: object
  6676. labels:
  6677. additionalProperties:
  6678. type: string
  6679. type: object
  6680. type: object
  6681. templateFrom:
  6682. items:
  6683. maxProperties: 1
  6684. minProperties: 1
  6685. properties:
  6686. configMap:
  6687. properties:
  6688. items:
  6689. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  6690. items:
  6691. properties:
  6692. key:
  6693. description: A key in the ConfigMap/Secret
  6694. maxLength: 253
  6695. minLength: 1
  6696. pattern: ^[-._a-zA-Z0-9]+$
  6697. type: string
  6698. required:
  6699. - key
  6700. type: object
  6701. type: array
  6702. name:
  6703. description: The name of the ConfigMap/Secret resource
  6704. maxLength: 253
  6705. minLength: 1
  6706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6707. type: string
  6708. required:
  6709. - items
  6710. - name
  6711. type: object
  6712. secret:
  6713. properties:
  6714. items:
  6715. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  6716. items:
  6717. properties:
  6718. key:
  6719. description: A key in the ConfigMap/Secret
  6720. maxLength: 253
  6721. minLength: 1
  6722. pattern: ^[-._a-zA-Z0-9]+$
  6723. type: string
  6724. required:
  6725. - key
  6726. type: object
  6727. type: array
  6728. name:
  6729. description: The name of the ConfigMap/Secret resource
  6730. maxLength: 253
  6731. minLength: 1
  6732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6733. type: string
  6734. required:
  6735. - items
  6736. - name
  6737. type: object
  6738. type: object
  6739. type: array
  6740. type:
  6741. type: string
  6742. type: object
  6743. type: object
  6744. required:
  6745. - secretStoreRef
  6746. - target
  6747. type: object
  6748. status:
  6749. properties:
  6750. binding:
  6751. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  6752. properties:
  6753. name:
  6754. default: ""
  6755. description: |-
  6756. Name of the referent.
  6757. This field is effectively required, but due to backwards compatibility is
  6758. allowed to be empty. Instances of this type with an empty value here are
  6759. almost certainly wrong.
  6760. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  6761. type: string
  6762. type: object
  6763. x-kubernetes-map-type: atomic
  6764. conditions:
  6765. items:
  6766. properties:
  6767. lastTransitionTime:
  6768. format: date-time
  6769. type: string
  6770. message:
  6771. type: string
  6772. reason:
  6773. type: string
  6774. status:
  6775. type: string
  6776. type:
  6777. type: string
  6778. required:
  6779. - status
  6780. - type
  6781. type: object
  6782. type: array
  6783. refreshTime:
  6784. description: |-
  6785. refreshTime is the time and date the external secret was fetched and
  6786. the target secret updated
  6787. format: date-time
  6788. nullable: true
  6789. type: string
  6790. syncedResourceVersion:
  6791. description: SyncedResourceVersion keeps track of the last synced version
  6792. type: string
  6793. type: object
  6794. type: object
  6795. served: true
  6796. storage: false
  6797. subresources:
  6798. status: {}
  6799. - additionalPrinterColumns:
  6800. - jsonPath: .spec.secretStoreRef.name
  6801. name: Store
  6802. type: string
  6803. - jsonPath: .spec.refreshInterval
  6804. name: Refresh Interval
  6805. type: string
  6806. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  6807. name: Status
  6808. type: string
  6809. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  6810. name: Ready
  6811. type: string
  6812. name: v1beta1
  6813. schema:
  6814. openAPIV3Schema:
  6815. description: ExternalSecret is the Schema for the external-secrets API.
  6816. properties:
  6817. apiVersion:
  6818. description: |-
  6819. APIVersion defines the versioned schema of this representation of an object.
  6820. Servers should convert recognized schemas to the latest internal value, and
  6821. may reject unrecognized values.
  6822. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  6823. type: string
  6824. kind:
  6825. description: |-
  6826. Kind is a string value representing the REST resource this object represents.
  6827. Servers may infer this from the endpoint the client submits requests to.
  6828. Cannot be updated.
  6829. In CamelCase.
  6830. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  6831. type: string
  6832. metadata:
  6833. type: object
  6834. spec:
  6835. description: ExternalSecretSpec defines the desired state of ExternalSecret.
  6836. properties:
  6837. data:
  6838. description: Data defines the connection between the Kubernetes Secret keys and the Provider data
  6839. items:
  6840. description: ExternalSecretData defines the connection between the Kubernetes Secret key (spec.data.<key>) and the Provider data.
  6841. properties:
  6842. remoteRef:
  6843. description: |-
  6844. RemoteRef points to the remote secret and defines
  6845. which secret (version/property/..) to fetch.
  6846. properties:
  6847. conversionStrategy:
  6848. default: Default
  6849. description: Used to define a conversion Strategy
  6850. enum:
  6851. - Default
  6852. - Unicode
  6853. type: string
  6854. decodingStrategy:
  6855. default: None
  6856. description: Used to define a decoding Strategy
  6857. enum:
  6858. - Auto
  6859. - Base64
  6860. - Base64URL
  6861. - None
  6862. type: string
  6863. key:
  6864. description: Key is the key used in the Provider, mandatory
  6865. type: string
  6866. metadataPolicy:
  6867. default: None
  6868. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  6869. enum:
  6870. - None
  6871. - Fetch
  6872. type: string
  6873. property:
  6874. description: Used to select a specific property of the Provider value (if a map), if supported
  6875. type: string
  6876. version:
  6877. description: Used to select a specific version of the Provider value, if supported
  6878. type: string
  6879. required:
  6880. - key
  6881. type: object
  6882. secretKey:
  6883. description: The key in the Kubernetes Secret to store the value.
  6884. maxLength: 253
  6885. minLength: 1
  6886. pattern: ^[-._a-zA-Z0-9]+$
  6887. type: string
  6888. sourceRef:
  6889. description: |-
  6890. SourceRef allows you to override the source
  6891. from which the value will be pulled.
  6892. maxProperties: 1
  6893. properties:
  6894. generatorRef:
  6895. description: |-
  6896. GeneratorRef points to a generator custom resource.
  6897. Deprecated: The generatorRef is not implemented in .data[].
  6898. this will be removed with v1.
  6899. properties:
  6900. apiVersion:
  6901. default: generators.external-secrets.io/v1alpha1
  6902. description: Specify the apiVersion of the generator resource
  6903. type: string
  6904. kind:
  6905. description: Specify the Kind of the resource, e.g. Password, ACRAccessToken, ClusterGenerator etc.
  6906. type: string
  6907. name:
  6908. description: Specify the name of the generator resource
  6909. maxLength: 253
  6910. minLength: 1
  6911. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6912. type: string
  6913. required:
  6914. - kind
  6915. - name
  6916. type: object
  6917. storeRef:
  6918. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  6919. properties:
  6920. kind:
  6921. description: |-
  6922. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  6923. Defaults to `SecretStore`
  6924. enum:
  6925. - SecretStore
  6926. - ClusterSecretStore
  6927. type: string
  6928. name:
  6929. description: Name of the SecretStore resource
  6930. maxLength: 253
  6931. minLength: 1
  6932. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  6933. type: string
  6934. type: object
  6935. type: object
  6936. required:
  6937. - remoteRef
  6938. - secretKey
  6939. type: object
  6940. type: array
  6941. dataFrom:
  6942. description: |-
  6943. DataFrom is used to fetch all properties from a specific Provider data
  6944. If multiple entries are specified, the Secret keys are merged in the specified order
  6945. items:
  6946. properties:
  6947. extract:
  6948. description: |-
  6949. Used to extract multiple key/value pairs from one secret
  6950. Note: Extract does not support sourceRef.Generator or sourceRef.GeneratorRef.
  6951. properties:
  6952. conversionStrategy:
  6953. default: Default
  6954. description: Used to define a conversion Strategy
  6955. enum:
  6956. - Default
  6957. - Unicode
  6958. type: string
  6959. decodingStrategy:
  6960. default: None
  6961. description: Used to define a decoding Strategy
  6962. enum:
  6963. - Auto
  6964. - Base64
  6965. - Base64URL
  6966. - None
  6967. type: string
  6968. key:
  6969. description: Key is the key used in the Provider, mandatory
  6970. type: string
  6971. metadataPolicy:
  6972. default: None
  6973. description: Policy for fetching tags/labels from provider secrets, possible options are Fetch, None. Defaults to None
  6974. enum:
  6975. - None
  6976. - Fetch
  6977. type: string
  6978. property:
  6979. description: Used to select a specific property of the Provider value (if a map), if supported
  6980. type: string
  6981. version:
  6982. description: Used to select a specific version of the Provider value, if supported
  6983. type: string
  6984. required:
  6985. - key
  6986. type: object
  6987. find:
  6988. description: |-
  6989. Used to find secrets based on tags or regular expressions
  6990. Note: Find does not support sourceRef.Generator or sourceRef.GeneratorRef.
  6991. properties:
  6992. conversionStrategy:
  6993. default: Default
  6994. description: Used to define a conversion Strategy
  6995. enum:
  6996. - Default
  6997. - Unicode
  6998. type: string
  6999. decodingStrategy:
  7000. default: None
  7001. description: Used to define a decoding Strategy
  7002. enum:
  7003. - Auto
  7004. - Base64
  7005. - Base64URL
  7006. - None
  7007. type: string
  7008. name:
  7009. description: Finds secrets based on the name.
  7010. properties:
  7011. regexp:
  7012. description: Finds secrets base
  7013. type: string
  7014. type: object
  7015. path:
  7016. description: A root path to start the find operations.
  7017. type: string
  7018. tags:
  7019. additionalProperties:
  7020. type: string
  7021. description: Find secrets based on tags.
  7022. type: object
  7023. type: object
  7024. rewrite:
  7025. description: |-
  7026. Used to rewrite secret Keys after getting them from the secret Provider
  7027. Multiple Rewrite operations can be provided. They are applied in a layered order (first to last)
  7028. items:
  7029. properties:
  7030. regexp:
  7031. description: |-
  7032. Used to rewrite with regular expressions.
  7033. The resulting key will be the output of a regexp.ReplaceAll operation.
  7034. properties:
  7035. source:
  7036. description: Used to define the regular expression of a re.Compiler.
  7037. type: string
  7038. target:
  7039. description: Used to define the target pattern of a ReplaceAll operation.
  7040. type: string
  7041. required:
  7042. - source
  7043. - target
  7044. type: object
  7045. transform:
  7046. description: |-
  7047. Used to apply string transformation on the secrets.
  7048. The resulting key will be the output of the template applied by the operation.
  7049. properties:
  7050. template:
  7051. description: |-
  7052. Used to define the template to apply on the secret name.
  7053. `.value ` will specify the secret name in the template.
  7054. type: string
  7055. required:
  7056. - template
  7057. type: object
  7058. type: object
  7059. type: array
  7060. sourceRef:
  7061. description: |-
  7062. SourceRef points to a store or generator
  7063. which contains secret values ready to use.
  7064. Use this in combination with Extract or Find pull values out of
  7065. a specific SecretStore.
  7066. When sourceRef points to a generator Extract or Find is not supported.
  7067. The generator returns a static map of values
  7068. maxProperties: 1
  7069. properties:
  7070. generatorRef:
  7071. description: GeneratorRef points to a generator custom resource.
  7072. properties:
  7073. apiVersion:
  7074. default: generators.external-secrets.io/v1alpha1
  7075. description: Specify the apiVersion of the generator resource
  7076. type: string
  7077. kind:
  7078. description: Specify the Kind of the resource, e.g. Password, ACRAccessToken, ClusterGenerator etc.
  7079. type: string
  7080. name:
  7081. description: Specify the name of the generator resource
  7082. maxLength: 253
  7083. minLength: 1
  7084. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7085. type: string
  7086. required:
  7087. - kind
  7088. - name
  7089. type: object
  7090. storeRef:
  7091. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  7092. properties:
  7093. kind:
  7094. description: |-
  7095. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  7096. Defaults to `SecretStore`
  7097. enum:
  7098. - SecretStore
  7099. - ClusterSecretStore
  7100. type: string
  7101. name:
  7102. description: Name of the SecretStore resource
  7103. maxLength: 253
  7104. minLength: 1
  7105. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7106. type: string
  7107. type: object
  7108. type: object
  7109. type: object
  7110. type: array
  7111. refreshInterval:
  7112. default: 1h
  7113. description: |-
  7114. RefreshInterval is the amount of time before the values are read again from the SecretStore provider,
  7115. specified as Golang Duration strings.
  7116. Valid time units are "ns", "us" (or "µs"), "ms", "s", "m", "h"
  7117. Example values: "1h", "2h30m", "5d", "10s"
  7118. May be set to zero to fetch and create it once. Defaults to 1h.
  7119. type: string
  7120. secretStoreRef:
  7121. description: SecretStoreRef defines which SecretStore to fetch the ExternalSecret data.
  7122. properties:
  7123. kind:
  7124. description: |-
  7125. Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  7126. Defaults to `SecretStore`
  7127. enum:
  7128. - SecretStore
  7129. - ClusterSecretStore
  7130. type: string
  7131. name:
  7132. description: Name of the SecretStore resource
  7133. maxLength: 253
  7134. minLength: 1
  7135. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7136. type: string
  7137. type: object
  7138. target:
  7139. default:
  7140. creationPolicy: Owner
  7141. deletionPolicy: Retain
  7142. description: |-
  7143. ExternalSecretTarget defines the Kubernetes Secret to be created
  7144. There can be only one target per ExternalSecret.
  7145. properties:
  7146. creationPolicy:
  7147. default: Owner
  7148. description: |-
  7149. CreationPolicy defines rules on how to create the resulting Secret.
  7150. Defaults to "Owner"
  7151. enum:
  7152. - Owner
  7153. - Orphan
  7154. - Merge
  7155. - None
  7156. type: string
  7157. deletionPolicy:
  7158. default: Retain
  7159. description: |-
  7160. DeletionPolicy defines rules on how to delete the resulting Secret.
  7161. Defaults to "Retain"
  7162. enum:
  7163. - Delete
  7164. - Merge
  7165. - Retain
  7166. type: string
  7167. immutable:
  7168. description: Immutable defines if the final secret will be immutable
  7169. type: boolean
  7170. name:
  7171. description: |-
  7172. The name of the Secret resource to be managed.
  7173. Defaults to the .metadata.name of the ExternalSecret resource
  7174. maxLength: 253
  7175. minLength: 1
  7176. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7177. type: string
  7178. template:
  7179. description: Template defines a blueprint for the created Secret resource.
  7180. properties:
  7181. data:
  7182. additionalProperties:
  7183. type: string
  7184. type: object
  7185. engineVersion:
  7186. default: v2
  7187. description: |-
  7188. EngineVersion specifies the template engine version
  7189. that should be used to compile/execute the
  7190. template specified in .data and .templateFrom[].
  7191. enum:
  7192. - v1
  7193. - v2
  7194. type: string
  7195. mergePolicy:
  7196. default: Replace
  7197. enum:
  7198. - Replace
  7199. - Merge
  7200. type: string
  7201. metadata:
  7202. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  7203. properties:
  7204. annotations:
  7205. additionalProperties:
  7206. type: string
  7207. type: object
  7208. labels:
  7209. additionalProperties:
  7210. type: string
  7211. type: object
  7212. type: object
  7213. templateFrom:
  7214. items:
  7215. properties:
  7216. configMap:
  7217. properties:
  7218. items:
  7219. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  7220. items:
  7221. properties:
  7222. key:
  7223. description: A key in the ConfigMap/Secret
  7224. maxLength: 253
  7225. minLength: 1
  7226. pattern: ^[-._a-zA-Z0-9]+$
  7227. type: string
  7228. templateAs:
  7229. default: Values
  7230. enum:
  7231. - Values
  7232. - KeysAndValues
  7233. type: string
  7234. required:
  7235. - key
  7236. type: object
  7237. type: array
  7238. name:
  7239. description: The name of the ConfigMap/Secret resource
  7240. maxLength: 253
  7241. minLength: 1
  7242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7243. type: string
  7244. required:
  7245. - items
  7246. - name
  7247. type: object
  7248. literal:
  7249. type: string
  7250. secret:
  7251. properties:
  7252. items:
  7253. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  7254. items:
  7255. properties:
  7256. key:
  7257. description: A key in the ConfigMap/Secret
  7258. maxLength: 253
  7259. minLength: 1
  7260. pattern: ^[-._a-zA-Z0-9]+$
  7261. type: string
  7262. templateAs:
  7263. default: Values
  7264. enum:
  7265. - Values
  7266. - KeysAndValues
  7267. type: string
  7268. required:
  7269. - key
  7270. type: object
  7271. type: array
  7272. name:
  7273. description: The name of the ConfigMap/Secret resource
  7274. maxLength: 253
  7275. minLength: 1
  7276. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7277. type: string
  7278. required:
  7279. - items
  7280. - name
  7281. type: object
  7282. target:
  7283. default: Data
  7284. enum:
  7285. - Data
  7286. - Annotations
  7287. - Labels
  7288. type: string
  7289. type: object
  7290. type: array
  7291. type:
  7292. type: string
  7293. type: object
  7294. type: object
  7295. type: object
  7296. status:
  7297. properties:
  7298. binding:
  7299. description: Binding represents a servicebinding.io Provisioned Service reference to the secret
  7300. properties:
  7301. name:
  7302. default: ""
  7303. description: |-
  7304. Name of the referent.
  7305. This field is effectively required, but due to backwards compatibility is
  7306. allowed to be empty. Instances of this type with an empty value here are
  7307. almost certainly wrong.
  7308. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names
  7309. type: string
  7310. type: object
  7311. x-kubernetes-map-type: atomic
  7312. conditions:
  7313. items:
  7314. properties:
  7315. lastTransitionTime:
  7316. format: date-time
  7317. type: string
  7318. message:
  7319. type: string
  7320. reason:
  7321. type: string
  7322. status:
  7323. type: string
  7324. type:
  7325. type: string
  7326. required:
  7327. - status
  7328. - type
  7329. type: object
  7330. type: array
  7331. refreshTime:
  7332. description: |-
  7333. refreshTime is the time and date the external secret was fetched and
  7334. the target secret updated
  7335. format: date-time
  7336. nullable: true
  7337. type: string
  7338. syncedResourceVersion:
  7339. description: SyncedResourceVersion keeps track of the last synced version
  7340. type: string
  7341. type: object
  7342. type: object
  7343. served: true
  7344. storage: true
  7345. subresources:
  7346. status: {}
  7347. conversion:
  7348. strategy: Webhook
  7349. webhook:
  7350. conversionReviewVersions:
  7351. - v1
  7352. clientConfig:
  7353. service:
  7354. name: kubernetes
  7355. namespace: default
  7356. path: /convert
  7357. ---
  7358. apiVersion: apiextensions.k8s.io/v1
  7359. kind: CustomResourceDefinition
  7360. metadata:
  7361. annotations:
  7362. controller-gen.kubebuilder.io/version: v0.16.5
  7363. labels:
  7364. external-secrets.io/component: controller
  7365. name: pushsecrets.external-secrets.io
  7366. spec:
  7367. group: external-secrets.io
  7368. names:
  7369. categories:
  7370. - external-secrets
  7371. kind: PushSecret
  7372. listKind: PushSecretList
  7373. plural: pushsecrets
  7374. singular: pushsecret
  7375. scope: Namespaced
  7376. versions:
  7377. - additionalPrinterColumns:
  7378. - jsonPath: .metadata.creationTimestamp
  7379. name: AGE
  7380. type: date
  7381. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  7382. name: Status
  7383. type: string
  7384. name: v1alpha1
  7385. schema:
  7386. openAPIV3Schema:
  7387. properties:
  7388. apiVersion:
  7389. description: |-
  7390. APIVersion defines the versioned schema of this representation of an object.
  7391. Servers should convert recognized schemas to the latest internal value, and
  7392. may reject unrecognized values.
  7393. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  7394. type: string
  7395. kind:
  7396. description: |-
  7397. Kind is a string value representing the REST resource this object represents.
  7398. Servers may infer this from the endpoint the client submits requests to.
  7399. Cannot be updated.
  7400. In CamelCase.
  7401. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  7402. type: string
  7403. metadata:
  7404. type: object
  7405. spec:
  7406. description: PushSecretSpec configures the behavior of the PushSecret.
  7407. properties:
  7408. data:
  7409. description: Secret Data that should be pushed to providers
  7410. items:
  7411. properties:
  7412. conversionStrategy:
  7413. default: None
  7414. description: Used to define a conversion Strategy for the secret keys
  7415. enum:
  7416. - None
  7417. - ReverseUnicode
  7418. type: string
  7419. match:
  7420. description: Match a given Secret Key to be pushed to the provider.
  7421. properties:
  7422. remoteRef:
  7423. description: Remote Refs to push to providers.
  7424. properties:
  7425. property:
  7426. description: Name of the property in the resulting secret
  7427. type: string
  7428. remoteKey:
  7429. description: Name of the resulting provider secret.
  7430. type: string
  7431. required:
  7432. - remoteKey
  7433. type: object
  7434. secretKey:
  7435. description: Secret Key to be pushed
  7436. type: string
  7437. required:
  7438. - remoteRef
  7439. type: object
  7440. metadata:
  7441. description: |-
  7442. Metadata is metadata attached to the secret.
  7443. The structure of metadata is provider specific, please look it up in the provider documentation.
  7444. x-kubernetes-preserve-unknown-fields: true
  7445. required:
  7446. - match
  7447. type: object
  7448. type: array
  7449. deletionPolicy:
  7450. default: None
  7451. description: Deletion Policy to handle Secrets in the provider.
  7452. enum:
  7453. - Delete
  7454. - None
  7455. type: string
  7456. refreshInterval:
  7457. description: The Interval to which External Secrets will try to push a secret definition
  7458. type: string
  7459. secretStoreRefs:
  7460. items:
  7461. properties:
  7462. kind:
  7463. default: SecretStore
  7464. description: Kind of the SecretStore resource (SecretStore or ClusterSecretStore)
  7465. enum:
  7466. - SecretStore
  7467. - ClusterSecretStore
  7468. type: string
  7469. labelSelector:
  7470. description: Optionally, sync to secret stores with label selector
  7471. properties:
  7472. matchExpressions:
  7473. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  7474. items:
  7475. description: |-
  7476. A label selector requirement is a selector that contains values, a key, and an operator that
  7477. relates the key and values.
  7478. properties:
  7479. key:
  7480. description: key is the label key that the selector applies to.
  7481. type: string
  7482. operator:
  7483. description: |-
  7484. operator represents a key's relationship to a set of values.
  7485. Valid operators are In, NotIn, Exists and DoesNotExist.
  7486. type: string
  7487. values:
  7488. description: |-
  7489. values is an array of string values. If the operator is In or NotIn,
  7490. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  7491. the values array must be empty. This array is replaced during a strategic
  7492. merge patch.
  7493. items:
  7494. type: string
  7495. type: array
  7496. x-kubernetes-list-type: atomic
  7497. required:
  7498. - key
  7499. - operator
  7500. type: object
  7501. type: array
  7502. x-kubernetes-list-type: atomic
  7503. matchLabels:
  7504. additionalProperties:
  7505. type: string
  7506. description: |-
  7507. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  7508. map is equivalent to an element of matchExpressions, whose key field is "key", the
  7509. operator is "In", and the values array contains only "value". The requirements are ANDed.
  7510. type: object
  7511. type: object
  7512. x-kubernetes-map-type: atomic
  7513. name:
  7514. description: Optionally, sync to the SecretStore of the given name
  7515. maxLength: 253
  7516. minLength: 1
  7517. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7518. type: string
  7519. type: object
  7520. type: array
  7521. selector:
  7522. description: The Secret Selector (k8s source) for the Push Secret
  7523. maxProperties: 1
  7524. minProperties: 1
  7525. properties:
  7526. generatorRef:
  7527. description: Point to a generator to create a Secret.
  7528. properties:
  7529. apiVersion:
  7530. default: generators.external-secrets.io/v1alpha1
  7531. description: Specify the apiVersion of the generator resource
  7532. type: string
  7533. kind:
  7534. description: Specify the Kind of the resource, e.g. Password, ACRAccessToken, ClusterGenerator etc.
  7535. type: string
  7536. name:
  7537. description: Specify the name of the generator resource
  7538. maxLength: 253
  7539. minLength: 1
  7540. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7541. type: string
  7542. required:
  7543. - kind
  7544. - name
  7545. type: object
  7546. secret:
  7547. description: Select a Secret to Push.
  7548. properties:
  7549. name:
  7550. description: |-
  7551. Name of the Secret.
  7552. The Secret must exist in the same namespace as the PushSecret manifest.
  7553. maxLength: 253
  7554. minLength: 1
  7555. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7556. type: string
  7557. required:
  7558. - name
  7559. type: object
  7560. type: object
  7561. template:
  7562. description: Template defines a blueprint for the created Secret resource.
  7563. properties:
  7564. data:
  7565. additionalProperties:
  7566. type: string
  7567. type: object
  7568. engineVersion:
  7569. default: v2
  7570. description: |-
  7571. EngineVersion specifies the template engine version
  7572. that should be used to compile/execute the
  7573. template specified in .data and .templateFrom[].
  7574. enum:
  7575. - v1
  7576. - v2
  7577. type: string
  7578. mergePolicy:
  7579. default: Replace
  7580. enum:
  7581. - Replace
  7582. - Merge
  7583. type: string
  7584. metadata:
  7585. description: ExternalSecretTemplateMetadata defines metadata fields for the Secret blueprint.
  7586. properties:
  7587. annotations:
  7588. additionalProperties:
  7589. type: string
  7590. type: object
  7591. labels:
  7592. additionalProperties:
  7593. type: string
  7594. type: object
  7595. type: object
  7596. templateFrom:
  7597. items:
  7598. properties:
  7599. configMap:
  7600. properties:
  7601. items:
  7602. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  7603. items:
  7604. properties:
  7605. key:
  7606. description: A key in the ConfigMap/Secret
  7607. maxLength: 253
  7608. minLength: 1
  7609. pattern: ^[-._a-zA-Z0-9]+$
  7610. type: string
  7611. templateAs:
  7612. default: Values
  7613. enum:
  7614. - Values
  7615. - KeysAndValues
  7616. type: string
  7617. required:
  7618. - key
  7619. type: object
  7620. type: array
  7621. name:
  7622. description: The name of the ConfigMap/Secret resource
  7623. maxLength: 253
  7624. minLength: 1
  7625. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7626. type: string
  7627. required:
  7628. - items
  7629. - name
  7630. type: object
  7631. literal:
  7632. type: string
  7633. secret:
  7634. properties:
  7635. items:
  7636. description: A list of keys in the ConfigMap/Secret to use as templates for Secret data
  7637. items:
  7638. properties:
  7639. key:
  7640. description: A key in the ConfigMap/Secret
  7641. maxLength: 253
  7642. minLength: 1
  7643. pattern: ^[-._a-zA-Z0-9]+$
  7644. type: string
  7645. templateAs:
  7646. default: Values
  7647. enum:
  7648. - Values
  7649. - KeysAndValues
  7650. type: string
  7651. required:
  7652. - key
  7653. type: object
  7654. type: array
  7655. name:
  7656. description: The name of the ConfigMap/Secret resource
  7657. maxLength: 253
  7658. minLength: 1
  7659. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7660. type: string
  7661. required:
  7662. - items
  7663. - name
  7664. type: object
  7665. target:
  7666. default: Data
  7667. enum:
  7668. - Data
  7669. - Annotations
  7670. - Labels
  7671. type: string
  7672. type: object
  7673. type: array
  7674. type:
  7675. type: string
  7676. type: object
  7677. updatePolicy:
  7678. default: Replace
  7679. description: UpdatePolicy to handle Secrets in the provider.
  7680. enum:
  7681. - Replace
  7682. - IfNotExists
  7683. type: string
  7684. required:
  7685. - secretStoreRefs
  7686. - selector
  7687. type: object
  7688. status:
  7689. description: PushSecretStatus indicates the history of the status of PushSecret.
  7690. properties:
  7691. conditions:
  7692. items:
  7693. description: PushSecretStatusCondition indicates the status of the PushSecret.
  7694. properties:
  7695. lastTransitionTime:
  7696. format: date-time
  7697. type: string
  7698. message:
  7699. type: string
  7700. reason:
  7701. type: string
  7702. status:
  7703. type: string
  7704. type:
  7705. description: PushSecretConditionType indicates the condition of the PushSecret.
  7706. type: string
  7707. required:
  7708. - status
  7709. - type
  7710. type: object
  7711. type: array
  7712. refreshTime:
  7713. description: |-
  7714. refreshTime is the time and date the external secret was fetched and
  7715. the target secret updated
  7716. format: date-time
  7717. nullable: true
  7718. type: string
  7719. syncedPushSecrets:
  7720. additionalProperties:
  7721. additionalProperties:
  7722. properties:
  7723. conversionStrategy:
  7724. default: None
  7725. description: Used to define a conversion Strategy for the secret keys
  7726. enum:
  7727. - None
  7728. - ReverseUnicode
  7729. type: string
  7730. match:
  7731. description: Match a given Secret Key to be pushed to the provider.
  7732. properties:
  7733. remoteRef:
  7734. description: Remote Refs to push to providers.
  7735. properties:
  7736. property:
  7737. description: Name of the property in the resulting secret
  7738. type: string
  7739. remoteKey:
  7740. description: Name of the resulting provider secret.
  7741. type: string
  7742. required:
  7743. - remoteKey
  7744. type: object
  7745. secretKey:
  7746. description: Secret Key to be pushed
  7747. type: string
  7748. required:
  7749. - remoteRef
  7750. type: object
  7751. metadata:
  7752. description: |-
  7753. Metadata is metadata attached to the secret.
  7754. The structure of metadata is provider specific, please look it up in the provider documentation.
  7755. x-kubernetes-preserve-unknown-fields: true
  7756. required:
  7757. - match
  7758. type: object
  7759. type: object
  7760. description: |-
  7761. Synced PushSecrets, including secrets that already exist in provider.
  7762. Matches secret stores to PushSecretData that was stored to that secret store.
  7763. type: object
  7764. syncedResourceVersion:
  7765. description: SyncedResourceVersion keeps track of the last synced version.
  7766. type: string
  7767. type: object
  7768. type: object
  7769. served: true
  7770. storage: true
  7771. subresources:
  7772. status: {}
  7773. conversion:
  7774. strategy: Webhook
  7775. webhook:
  7776. conversionReviewVersions:
  7777. - v1
  7778. clientConfig:
  7779. service:
  7780. name: kubernetes
  7781. namespace: default
  7782. path: /convert
  7783. ---
  7784. apiVersion: apiextensions.k8s.io/v1
  7785. kind: CustomResourceDefinition
  7786. metadata:
  7787. annotations:
  7788. controller-gen.kubebuilder.io/version: v0.16.5
  7789. labels:
  7790. external-secrets.io/component: controller
  7791. name: secretstores.external-secrets.io
  7792. spec:
  7793. group: external-secrets.io
  7794. names:
  7795. categories:
  7796. - external-secrets
  7797. kind: SecretStore
  7798. listKind: SecretStoreList
  7799. plural: secretstores
  7800. shortNames:
  7801. - ss
  7802. singular: secretstore
  7803. scope: Namespaced
  7804. versions:
  7805. - additionalPrinterColumns:
  7806. - jsonPath: .metadata.creationTimestamp
  7807. name: AGE
  7808. type: date
  7809. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  7810. name: Status
  7811. type: string
  7812. deprecated: true
  7813. name: v1alpha1
  7814. schema:
  7815. openAPIV3Schema:
  7816. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  7817. properties:
  7818. apiVersion:
  7819. description: |-
  7820. APIVersion defines the versioned schema of this representation of an object.
  7821. Servers should convert recognized schemas to the latest internal value, and
  7822. may reject unrecognized values.
  7823. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  7824. type: string
  7825. kind:
  7826. description: |-
  7827. Kind is a string value representing the REST resource this object represents.
  7828. Servers may infer this from the endpoint the client submits requests to.
  7829. Cannot be updated.
  7830. In CamelCase.
  7831. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  7832. type: string
  7833. metadata:
  7834. type: object
  7835. spec:
  7836. description: SecretStoreSpec defines the desired state of SecretStore.
  7837. properties:
  7838. controller:
  7839. description: |-
  7840. Used to select the correct ESO controller (think: ingress.ingressClassName)
  7841. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  7842. type: string
  7843. provider:
  7844. description: Used to configure the provider. Only one provider may be set
  7845. maxProperties: 1
  7846. minProperties: 1
  7847. properties:
  7848. akeyless:
  7849. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  7850. properties:
  7851. akeylessGWApiURL:
  7852. description: Akeyless GW API Url from which the secrets to be fetched from.
  7853. type: string
  7854. authSecretRef:
  7855. description: Auth configures how the operator authenticates with Akeyless.
  7856. properties:
  7857. kubernetesAuth:
  7858. description: |-
  7859. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  7860. token stored in the named Secret resource.
  7861. properties:
  7862. accessID:
  7863. description: the Akeyless Kubernetes auth-method access-id
  7864. type: string
  7865. k8sConfName:
  7866. description: Kubernetes-auth configuration name in Akeyless-Gateway
  7867. type: string
  7868. secretRef:
  7869. description: |-
  7870. Optional secret field containing a Kubernetes ServiceAccount JWT used
  7871. for authenticating with Akeyless. If a name is specified without a key,
  7872. `token` is the default. If one is not specified, the one bound to
  7873. the controller will be used.
  7874. properties:
  7875. key:
  7876. description: |-
  7877. A key in the referenced Secret.
  7878. Some instances of this field may be defaulted, in others it may be required.
  7879. maxLength: 253
  7880. minLength: 1
  7881. pattern: ^[-._a-zA-Z0-9]+$
  7882. type: string
  7883. name:
  7884. description: The name of the Secret resource being referred to.
  7885. maxLength: 253
  7886. minLength: 1
  7887. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7888. type: string
  7889. namespace:
  7890. description: |-
  7891. The namespace of the Secret resource being referred to.
  7892. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7893. maxLength: 63
  7894. minLength: 1
  7895. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7896. type: string
  7897. type: object
  7898. serviceAccountRef:
  7899. description: |-
  7900. Optional service account field containing the name of a kubernetes ServiceAccount.
  7901. If the service account is specified, the service account secret token JWT will be used
  7902. for authenticating with Akeyless. If the service account selector is not supplied,
  7903. the secretRef will be used instead.
  7904. properties:
  7905. audiences:
  7906. description: |-
  7907. Audience specifies the `aud` claim for the service account token
  7908. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  7909. then this audiences will be appended to the list
  7910. items:
  7911. type: string
  7912. type: array
  7913. name:
  7914. description: The name of the ServiceAccount resource being referred to.
  7915. maxLength: 253
  7916. minLength: 1
  7917. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7918. type: string
  7919. namespace:
  7920. description: |-
  7921. Namespace of the resource being referred to.
  7922. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7923. maxLength: 63
  7924. minLength: 1
  7925. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7926. type: string
  7927. required:
  7928. - name
  7929. type: object
  7930. required:
  7931. - accessID
  7932. - k8sConfName
  7933. type: object
  7934. secretRef:
  7935. description: |-
  7936. Reference to a Secret that contains the details
  7937. to authenticate with Akeyless.
  7938. properties:
  7939. accessID:
  7940. description: The SecretAccessID is used for authentication
  7941. properties:
  7942. key:
  7943. description: |-
  7944. A key in the referenced Secret.
  7945. Some instances of this field may be defaulted, in others it may be required.
  7946. maxLength: 253
  7947. minLength: 1
  7948. pattern: ^[-._a-zA-Z0-9]+$
  7949. type: string
  7950. name:
  7951. description: The name of the Secret resource being referred to.
  7952. maxLength: 253
  7953. minLength: 1
  7954. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7955. type: string
  7956. namespace:
  7957. description: |-
  7958. The namespace of the Secret resource being referred to.
  7959. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7960. maxLength: 63
  7961. minLength: 1
  7962. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7963. type: string
  7964. type: object
  7965. accessType:
  7966. description: |-
  7967. A reference to a specific 'key' within a Secret resource.
  7968. In some instances, `key` is a required field.
  7969. properties:
  7970. key:
  7971. description: |-
  7972. A key in the referenced Secret.
  7973. Some instances of this field may be defaulted, in others it may be required.
  7974. maxLength: 253
  7975. minLength: 1
  7976. pattern: ^[-._a-zA-Z0-9]+$
  7977. type: string
  7978. name:
  7979. description: The name of the Secret resource being referred to.
  7980. maxLength: 253
  7981. minLength: 1
  7982. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  7983. type: string
  7984. namespace:
  7985. description: |-
  7986. The namespace of the Secret resource being referred to.
  7987. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  7988. maxLength: 63
  7989. minLength: 1
  7990. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  7991. type: string
  7992. type: object
  7993. accessTypeParam:
  7994. description: |-
  7995. A reference to a specific 'key' within a Secret resource.
  7996. In some instances, `key` is a required field.
  7997. properties:
  7998. key:
  7999. description: |-
  8000. A key in the referenced Secret.
  8001. Some instances of this field may be defaulted, in others it may be required.
  8002. maxLength: 253
  8003. minLength: 1
  8004. pattern: ^[-._a-zA-Z0-9]+$
  8005. type: string
  8006. name:
  8007. description: The name of the Secret resource being referred to.
  8008. maxLength: 253
  8009. minLength: 1
  8010. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8011. type: string
  8012. namespace:
  8013. description: |-
  8014. The namespace of the Secret resource being referred to.
  8015. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8016. maxLength: 63
  8017. minLength: 1
  8018. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8019. type: string
  8020. type: object
  8021. type: object
  8022. type: object
  8023. caBundle:
  8024. description: |-
  8025. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  8026. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  8027. are used to validate the TLS connection.
  8028. format: byte
  8029. type: string
  8030. caProvider:
  8031. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  8032. properties:
  8033. key:
  8034. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8035. maxLength: 253
  8036. minLength: 1
  8037. pattern: ^[-._a-zA-Z0-9]+$
  8038. type: string
  8039. name:
  8040. description: The name of the object located at the provider type.
  8041. maxLength: 253
  8042. minLength: 1
  8043. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8044. type: string
  8045. namespace:
  8046. description: The namespace the Provider type is in.
  8047. maxLength: 63
  8048. minLength: 1
  8049. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8050. type: string
  8051. type:
  8052. description: The type of provider to use such as "Secret", or "ConfigMap".
  8053. enum:
  8054. - Secret
  8055. - ConfigMap
  8056. type: string
  8057. required:
  8058. - name
  8059. - type
  8060. type: object
  8061. required:
  8062. - akeylessGWApiURL
  8063. - authSecretRef
  8064. type: object
  8065. alibaba:
  8066. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  8067. properties:
  8068. auth:
  8069. description: AlibabaAuth contains a secretRef for credentials.
  8070. properties:
  8071. rrsa:
  8072. description: Authenticate against Alibaba using RRSA.
  8073. properties:
  8074. oidcProviderArn:
  8075. type: string
  8076. oidcTokenFilePath:
  8077. type: string
  8078. roleArn:
  8079. type: string
  8080. sessionName:
  8081. type: string
  8082. required:
  8083. - oidcProviderArn
  8084. - oidcTokenFilePath
  8085. - roleArn
  8086. - sessionName
  8087. type: object
  8088. secretRef:
  8089. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  8090. properties:
  8091. accessKeyIDSecretRef:
  8092. description: The AccessKeyID is used for authentication
  8093. properties:
  8094. key:
  8095. description: |-
  8096. A key in the referenced Secret.
  8097. Some instances of this field may be defaulted, in others it may be required.
  8098. maxLength: 253
  8099. minLength: 1
  8100. pattern: ^[-._a-zA-Z0-9]+$
  8101. type: string
  8102. name:
  8103. description: The name of the Secret resource being referred to.
  8104. maxLength: 253
  8105. minLength: 1
  8106. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8107. type: string
  8108. namespace:
  8109. description: |-
  8110. The namespace of the Secret resource being referred to.
  8111. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8112. maxLength: 63
  8113. minLength: 1
  8114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8115. type: string
  8116. type: object
  8117. accessKeySecretSecretRef:
  8118. description: The AccessKeySecret is used for authentication
  8119. properties:
  8120. key:
  8121. description: |-
  8122. A key in the referenced Secret.
  8123. Some instances of this field may be defaulted, in others it may be required.
  8124. maxLength: 253
  8125. minLength: 1
  8126. pattern: ^[-._a-zA-Z0-9]+$
  8127. type: string
  8128. name:
  8129. description: The name of the Secret resource being referred to.
  8130. maxLength: 253
  8131. minLength: 1
  8132. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8133. type: string
  8134. namespace:
  8135. description: |-
  8136. The namespace of the Secret resource being referred to.
  8137. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8138. maxLength: 63
  8139. minLength: 1
  8140. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8141. type: string
  8142. type: object
  8143. required:
  8144. - accessKeyIDSecretRef
  8145. - accessKeySecretSecretRef
  8146. type: object
  8147. type: object
  8148. regionID:
  8149. description: Alibaba Region to be used for the provider
  8150. type: string
  8151. required:
  8152. - auth
  8153. - regionID
  8154. type: object
  8155. aws:
  8156. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  8157. properties:
  8158. auth:
  8159. description: |-
  8160. Auth defines the information necessary to authenticate against AWS
  8161. if not set aws sdk will infer credentials from your environment
  8162. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  8163. properties:
  8164. jwt:
  8165. description: Authenticate against AWS using service account tokens.
  8166. properties:
  8167. serviceAccountRef:
  8168. description: A reference to a ServiceAccount resource.
  8169. properties:
  8170. audiences:
  8171. description: |-
  8172. Audience specifies the `aud` claim for the service account token
  8173. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8174. then this audiences will be appended to the list
  8175. items:
  8176. type: string
  8177. type: array
  8178. name:
  8179. description: The name of the ServiceAccount resource being referred to.
  8180. maxLength: 253
  8181. minLength: 1
  8182. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8183. type: string
  8184. namespace:
  8185. description: |-
  8186. Namespace of the resource being referred to.
  8187. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8188. maxLength: 63
  8189. minLength: 1
  8190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8191. type: string
  8192. required:
  8193. - name
  8194. type: object
  8195. type: object
  8196. secretRef:
  8197. description: |-
  8198. AWSAuthSecretRef holds secret references for AWS credentials
  8199. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  8200. properties:
  8201. accessKeyIDSecretRef:
  8202. description: The AccessKeyID is used for authentication
  8203. properties:
  8204. key:
  8205. description: |-
  8206. A key in the referenced Secret.
  8207. Some instances of this field may be defaulted, in others it may be required.
  8208. maxLength: 253
  8209. minLength: 1
  8210. pattern: ^[-._a-zA-Z0-9]+$
  8211. type: string
  8212. name:
  8213. description: The name of the Secret resource being referred to.
  8214. maxLength: 253
  8215. minLength: 1
  8216. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8217. type: string
  8218. namespace:
  8219. description: |-
  8220. The namespace of the Secret resource being referred to.
  8221. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8222. maxLength: 63
  8223. minLength: 1
  8224. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8225. type: string
  8226. type: object
  8227. secretAccessKeySecretRef:
  8228. description: The SecretAccessKey is used for authentication
  8229. properties:
  8230. key:
  8231. description: |-
  8232. A key in the referenced Secret.
  8233. Some instances of this field may be defaulted, in others it may be required.
  8234. maxLength: 253
  8235. minLength: 1
  8236. pattern: ^[-._a-zA-Z0-9]+$
  8237. type: string
  8238. name:
  8239. description: The name of the Secret resource being referred to.
  8240. maxLength: 253
  8241. minLength: 1
  8242. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8243. type: string
  8244. namespace:
  8245. description: |-
  8246. The namespace of the Secret resource being referred to.
  8247. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8248. maxLength: 63
  8249. minLength: 1
  8250. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8251. type: string
  8252. type: object
  8253. type: object
  8254. type: object
  8255. region:
  8256. description: AWS Region to be used for the provider
  8257. type: string
  8258. role:
  8259. description: Role is a Role ARN which the SecretManager provider will assume
  8260. type: string
  8261. service:
  8262. description: Service defines which service should be used to fetch the secrets
  8263. enum:
  8264. - SecretsManager
  8265. - ParameterStore
  8266. type: string
  8267. required:
  8268. - region
  8269. - service
  8270. type: object
  8271. azurekv:
  8272. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  8273. properties:
  8274. authSecretRef:
  8275. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type.
  8276. properties:
  8277. clientId:
  8278. description: The Azure clientId of the service principle used for authentication.
  8279. properties:
  8280. key:
  8281. description: |-
  8282. A key in the referenced Secret.
  8283. Some instances of this field may be defaulted, in others it may be required.
  8284. maxLength: 253
  8285. minLength: 1
  8286. pattern: ^[-._a-zA-Z0-9]+$
  8287. type: string
  8288. name:
  8289. description: The name of the Secret resource being referred to.
  8290. maxLength: 253
  8291. minLength: 1
  8292. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8293. type: string
  8294. namespace:
  8295. description: |-
  8296. The namespace of the Secret resource being referred to.
  8297. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8298. maxLength: 63
  8299. minLength: 1
  8300. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8301. type: string
  8302. type: object
  8303. clientSecret:
  8304. description: The Azure ClientSecret of the service principle used for authentication.
  8305. properties:
  8306. key:
  8307. description: |-
  8308. A key in the referenced Secret.
  8309. Some instances of this field may be defaulted, in others it may be required.
  8310. maxLength: 253
  8311. minLength: 1
  8312. pattern: ^[-._a-zA-Z0-9]+$
  8313. type: string
  8314. name:
  8315. description: The name of the Secret resource being referred to.
  8316. maxLength: 253
  8317. minLength: 1
  8318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8319. type: string
  8320. namespace:
  8321. description: |-
  8322. The namespace of the Secret resource being referred to.
  8323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8324. maxLength: 63
  8325. minLength: 1
  8326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8327. type: string
  8328. type: object
  8329. type: object
  8330. authType:
  8331. default: ServicePrincipal
  8332. description: |-
  8333. Auth type defines how to authenticate to the keyvault service.
  8334. Valid values are:
  8335. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  8336. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  8337. enum:
  8338. - ServicePrincipal
  8339. - ManagedIdentity
  8340. - WorkloadIdentity
  8341. type: string
  8342. identityId:
  8343. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  8344. type: string
  8345. serviceAccountRef:
  8346. description: |-
  8347. ServiceAccountRef specified the service account
  8348. that should be used when authenticating with WorkloadIdentity.
  8349. properties:
  8350. audiences:
  8351. description: |-
  8352. Audience specifies the `aud` claim for the service account token
  8353. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8354. then this audiences will be appended to the list
  8355. items:
  8356. type: string
  8357. type: array
  8358. name:
  8359. description: The name of the ServiceAccount resource being referred to.
  8360. maxLength: 253
  8361. minLength: 1
  8362. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8363. type: string
  8364. namespace:
  8365. description: |-
  8366. Namespace of the resource being referred to.
  8367. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8368. maxLength: 63
  8369. minLength: 1
  8370. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8371. type: string
  8372. required:
  8373. - name
  8374. type: object
  8375. tenantId:
  8376. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  8377. type: string
  8378. vaultUrl:
  8379. description: Vault Url from which the secrets to be fetched from.
  8380. type: string
  8381. required:
  8382. - vaultUrl
  8383. type: object
  8384. fake:
  8385. description: Fake configures a store with static key/value pairs
  8386. properties:
  8387. data:
  8388. items:
  8389. properties:
  8390. key:
  8391. type: string
  8392. value:
  8393. type: string
  8394. valueMap:
  8395. additionalProperties:
  8396. type: string
  8397. type: object
  8398. version:
  8399. type: string
  8400. required:
  8401. - key
  8402. type: object
  8403. type: array
  8404. required:
  8405. - data
  8406. type: object
  8407. gcpsm:
  8408. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  8409. properties:
  8410. auth:
  8411. description: Auth defines the information necessary to authenticate against GCP
  8412. properties:
  8413. secretRef:
  8414. properties:
  8415. secretAccessKeySecretRef:
  8416. description: The SecretAccessKey is used for authentication
  8417. properties:
  8418. key:
  8419. description: |-
  8420. A key in the referenced Secret.
  8421. Some instances of this field may be defaulted, in others it may be required.
  8422. maxLength: 253
  8423. minLength: 1
  8424. pattern: ^[-._a-zA-Z0-9]+$
  8425. type: string
  8426. name:
  8427. description: The name of the Secret resource being referred to.
  8428. maxLength: 253
  8429. minLength: 1
  8430. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8431. type: string
  8432. namespace:
  8433. description: |-
  8434. The namespace of the Secret resource being referred to.
  8435. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8436. maxLength: 63
  8437. minLength: 1
  8438. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8439. type: string
  8440. type: object
  8441. type: object
  8442. workloadIdentity:
  8443. properties:
  8444. clusterLocation:
  8445. type: string
  8446. clusterName:
  8447. type: string
  8448. clusterProjectID:
  8449. type: string
  8450. serviceAccountRef:
  8451. description: A reference to a ServiceAccount resource.
  8452. properties:
  8453. audiences:
  8454. description: |-
  8455. Audience specifies the `aud` claim for the service account token
  8456. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8457. then this audiences will be appended to the list
  8458. items:
  8459. type: string
  8460. type: array
  8461. name:
  8462. description: The name of the ServiceAccount resource being referred to.
  8463. maxLength: 253
  8464. minLength: 1
  8465. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8466. type: string
  8467. namespace:
  8468. description: |-
  8469. Namespace of the resource being referred to.
  8470. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8471. maxLength: 63
  8472. minLength: 1
  8473. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8474. type: string
  8475. required:
  8476. - name
  8477. type: object
  8478. required:
  8479. - clusterLocation
  8480. - clusterName
  8481. - serviceAccountRef
  8482. type: object
  8483. type: object
  8484. projectID:
  8485. description: ProjectID project where secret is located
  8486. type: string
  8487. type: object
  8488. gitlab:
  8489. description: GitLab configures this store to sync secrets using GitLab Variables provider
  8490. properties:
  8491. auth:
  8492. description: Auth configures how secret-manager authenticates with a GitLab instance.
  8493. properties:
  8494. SecretRef:
  8495. properties:
  8496. accessToken:
  8497. description: AccessToken is used for authentication.
  8498. properties:
  8499. key:
  8500. description: |-
  8501. A key in the referenced Secret.
  8502. Some instances of this field may be defaulted, in others it may be required.
  8503. maxLength: 253
  8504. minLength: 1
  8505. pattern: ^[-._a-zA-Z0-9]+$
  8506. type: string
  8507. name:
  8508. description: The name of the Secret resource being referred to.
  8509. maxLength: 253
  8510. minLength: 1
  8511. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8512. type: string
  8513. namespace:
  8514. description: |-
  8515. The namespace of the Secret resource being referred to.
  8516. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8517. maxLength: 63
  8518. minLength: 1
  8519. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8520. type: string
  8521. type: object
  8522. type: object
  8523. required:
  8524. - SecretRef
  8525. type: object
  8526. projectID:
  8527. description: ProjectID specifies a project where secrets are located.
  8528. type: string
  8529. url:
  8530. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  8531. type: string
  8532. required:
  8533. - auth
  8534. type: object
  8535. ibm:
  8536. description: IBM configures this store to sync secrets using IBM Cloud provider
  8537. properties:
  8538. auth:
  8539. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  8540. properties:
  8541. secretRef:
  8542. properties:
  8543. secretApiKeySecretRef:
  8544. description: The SecretAccessKey is used for authentication
  8545. properties:
  8546. key:
  8547. description: |-
  8548. A key in the referenced Secret.
  8549. Some instances of this field may be defaulted, in others it may be required.
  8550. maxLength: 253
  8551. minLength: 1
  8552. pattern: ^[-._a-zA-Z0-9]+$
  8553. type: string
  8554. name:
  8555. description: The name of the Secret resource being referred to.
  8556. maxLength: 253
  8557. minLength: 1
  8558. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8559. type: string
  8560. namespace:
  8561. description: |-
  8562. The namespace of the Secret resource being referred to.
  8563. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8564. maxLength: 63
  8565. minLength: 1
  8566. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8567. type: string
  8568. type: object
  8569. type: object
  8570. required:
  8571. - secretRef
  8572. type: object
  8573. serviceUrl:
  8574. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  8575. type: string
  8576. required:
  8577. - auth
  8578. type: object
  8579. kubernetes:
  8580. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  8581. properties:
  8582. auth:
  8583. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  8584. maxProperties: 1
  8585. minProperties: 1
  8586. properties:
  8587. cert:
  8588. description: has both clientCert and clientKey as secretKeySelector
  8589. properties:
  8590. clientCert:
  8591. description: |-
  8592. A reference to a specific 'key' within a Secret resource.
  8593. In some instances, `key` is a required field.
  8594. properties:
  8595. key:
  8596. description: |-
  8597. A key in the referenced Secret.
  8598. Some instances of this field may be defaulted, in others it may be required.
  8599. maxLength: 253
  8600. minLength: 1
  8601. pattern: ^[-._a-zA-Z0-9]+$
  8602. type: string
  8603. name:
  8604. description: The name of the Secret resource being referred to.
  8605. maxLength: 253
  8606. minLength: 1
  8607. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8608. type: string
  8609. namespace:
  8610. description: |-
  8611. The namespace of the Secret resource being referred to.
  8612. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8613. maxLength: 63
  8614. minLength: 1
  8615. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8616. type: string
  8617. type: object
  8618. clientKey:
  8619. description: |-
  8620. A reference to a specific 'key' within a Secret resource.
  8621. In some instances, `key` is a required field.
  8622. properties:
  8623. key:
  8624. description: |-
  8625. A key in the referenced Secret.
  8626. Some instances of this field may be defaulted, in others it may be required.
  8627. maxLength: 253
  8628. minLength: 1
  8629. pattern: ^[-._a-zA-Z0-9]+$
  8630. type: string
  8631. name:
  8632. description: The name of the Secret resource being referred to.
  8633. maxLength: 253
  8634. minLength: 1
  8635. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8636. type: string
  8637. namespace:
  8638. description: |-
  8639. The namespace of the Secret resource being referred to.
  8640. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8641. maxLength: 63
  8642. minLength: 1
  8643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8644. type: string
  8645. type: object
  8646. type: object
  8647. serviceAccount:
  8648. description: points to a service account that should be used for authentication
  8649. properties:
  8650. serviceAccount:
  8651. description: A reference to a ServiceAccount resource.
  8652. properties:
  8653. audiences:
  8654. description: |-
  8655. Audience specifies the `aud` claim for the service account token
  8656. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8657. then this audiences will be appended to the list
  8658. items:
  8659. type: string
  8660. type: array
  8661. name:
  8662. description: The name of the ServiceAccount resource being referred to.
  8663. maxLength: 253
  8664. minLength: 1
  8665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8666. type: string
  8667. namespace:
  8668. description: |-
  8669. Namespace of the resource being referred to.
  8670. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8671. maxLength: 63
  8672. minLength: 1
  8673. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8674. type: string
  8675. required:
  8676. - name
  8677. type: object
  8678. type: object
  8679. token:
  8680. description: use static token to authenticate with
  8681. properties:
  8682. bearerToken:
  8683. description: |-
  8684. A reference to a specific 'key' within a Secret resource.
  8685. In some instances, `key` is a required field.
  8686. properties:
  8687. key:
  8688. description: |-
  8689. A key in the referenced Secret.
  8690. Some instances of this field may be defaulted, in others it may be required.
  8691. maxLength: 253
  8692. minLength: 1
  8693. pattern: ^[-._a-zA-Z0-9]+$
  8694. type: string
  8695. name:
  8696. description: The name of the Secret resource being referred to.
  8697. maxLength: 253
  8698. minLength: 1
  8699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8700. type: string
  8701. namespace:
  8702. description: |-
  8703. The namespace of the Secret resource being referred to.
  8704. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8705. maxLength: 63
  8706. minLength: 1
  8707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8708. type: string
  8709. type: object
  8710. type: object
  8711. type: object
  8712. remoteNamespace:
  8713. default: default
  8714. description: Remote namespace to fetch the secrets from
  8715. maxLength: 63
  8716. minLength: 1
  8717. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8718. type: string
  8719. server:
  8720. description: configures the Kubernetes server Address.
  8721. properties:
  8722. caBundle:
  8723. description: CABundle is a base64-encoded CA certificate
  8724. format: byte
  8725. type: string
  8726. caProvider:
  8727. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  8728. properties:
  8729. key:
  8730. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  8731. maxLength: 253
  8732. minLength: 1
  8733. pattern: ^[-._a-zA-Z0-9]+$
  8734. type: string
  8735. name:
  8736. description: The name of the object located at the provider type.
  8737. maxLength: 253
  8738. minLength: 1
  8739. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8740. type: string
  8741. namespace:
  8742. description: The namespace the Provider type is in.
  8743. maxLength: 63
  8744. minLength: 1
  8745. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8746. type: string
  8747. type:
  8748. description: The type of provider to use such as "Secret", or "ConfigMap".
  8749. enum:
  8750. - Secret
  8751. - ConfigMap
  8752. type: string
  8753. required:
  8754. - name
  8755. - type
  8756. type: object
  8757. url:
  8758. default: kubernetes.default
  8759. description: configures the Kubernetes server Address.
  8760. type: string
  8761. type: object
  8762. required:
  8763. - auth
  8764. type: object
  8765. oracle:
  8766. description: Oracle configures this store to sync secrets using Oracle Vault provider
  8767. properties:
  8768. auth:
  8769. description: |-
  8770. Auth configures how secret-manager authenticates with the Oracle Vault.
  8771. If empty, instance principal is used. Optionally, the authenticating principal type
  8772. and/or user data may be supplied for the use of workload identity and user principal.
  8773. properties:
  8774. secretRef:
  8775. description: SecretRef to pass through sensitive information.
  8776. properties:
  8777. fingerprint:
  8778. description: Fingerprint is the fingerprint of the API private key.
  8779. properties:
  8780. key:
  8781. description: |-
  8782. A key in the referenced Secret.
  8783. Some instances of this field may be defaulted, in others it may be required.
  8784. maxLength: 253
  8785. minLength: 1
  8786. pattern: ^[-._a-zA-Z0-9]+$
  8787. type: string
  8788. name:
  8789. description: The name of the Secret resource being referred to.
  8790. maxLength: 253
  8791. minLength: 1
  8792. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8793. type: string
  8794. namespace:
  8795. description: |-
  8796. The namespace of the Secret resource being referred to.
  8797. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8798. maxLength: 63
  8799. minLength: 1
  8800. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8801. type: string
  8802. type: object
  8803. privatekey:
  8804. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  8805. properties:
  8806. key:
  8807. description: |-
  8808. A key in the referenced Secret.
  8809. Some instances of this field may be defaulted, in others it may be required.
  8810. maxLength: 253
  8811. minLength: 1
  8812. pattern: ^[-._a-zA-Z0-9]+$
  8813. type: string
  8814. name:
  8815. description: The name of the Secret resource being referred to.
  8816. maxLength: 253
  8817. minLength: 1
  8818. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8819. type: string
  8820. namespace:
  8821. description: |-
  8822. The namespace of the Secret resource being referred to.
  8823. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8824. maxLength: 63
  8825. minLength: 1
  8826. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8827. type: string
  8828. type: object
  8829. required:
  8830. - fingerprint
  8831. - privatekey
  8832. type: object
  8833. tenancy:
  8834. description: Tenancy is the tenancy OCID where user is located.
  8835. type: string
  8836. user:
  8837. description: User is an access OCID specific to the account.
  8838. type: string
  8839. required:
  8840. - secretRef
  8841. - tenancy
  8842. - user
  8843. type: object
  8844. compartment:
  8845. description: |-
  8846. Compartment is the vault compartment OCID.
  8847. Required for PushSecret
  8848. type: string
  8849. encryptionKey:
  8850. description: |-
  8851. EncryptionKey is the OCID of the encryption key within the vault.
  8852. Required for PushSecret
  8853. type: string
  8854. principalType:
  8855. description: |-
  8856. The type of principal to use for authentication. If left blank, the Auth struct will
  8857. determine the principal type. This optional field must be specified if using
  8858. workload identity.
  8859. enum:
  8860. - ""
  8861. - UserPrincipal
  8862. - InstancePrincipal
  8863. - Workload
  8864. type: string
  8865. region:
  8866. description: Region is the region where vault is located.
  8867. type: string
  8868. serviceAccountRef:
  8869. description: |-
  8870. ServiceAccountRef specified the service account
  8871. that should be used when authenticating with WorkloadIdentity.
  8872. properties:
  8873. audiences:
  8874. description: |-
  8875. Audience specifies the `aud` claim for the service account token
  8876. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  8877. then this audiences will be appended to the list
  8878. items:
  8879. type: string
  8880. type: array
  8881. name:
  8882. description: The name of the ServiceAccount resource being referred to.
  8883. maxLength: 253
  8884. minLength: 1
  8885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8886. type: string
  8887. namespace:
  8888. description: |-
  8889. Namespace of the resource being referred to.
  8890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8891. maxLength: 63
  8892. minLength: 1
  8893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8894. type: string
  8895. required:
  8896. - name
  8897. type: object
  8898. vault:
  8899. description: Vault is the vault's OCID of the specific vault where secret is located.
  8900. type: string
  8901. required:
  8902. - region
  8903. - vault
  8904. type: object
  8905. passworddepot:
  8906. description: Configures a store to sync secrets with a Password Depot instance.
  8907. properties:
  8908. auth:
  8909. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  8910. properties:
  8911. secretRef:
  8912. properties:
  8913. credentials:
  8914. description: Username / Password is used for authentication.
  8915. properties:
  8916. key:
  8917. description: |-
  8918. A key in the referenced Secret.
  8919. Some instances of this field may be defaulted, in others it may be required.
  8920. maxLength: 253
  8921. minLength: 1
  8922. pattern: ^[-._a-zA-Z0-9]+$
  8923. type: string
  8924. name:
  8925. description: The name of the Secret resource being referred to.
  8926. maxLength: 253
  8927. minLength: 1
  8928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8929. type: string
  8930. namespace:
  8931. description: |-
  8932. The namespace of the Secret resource being referred to.
  8933. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  8934. maxLength: 63
  8935. minLength: 1
  8936. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  8937. type: string
  8938. type: object
  8939. type: object
  8940. required:
  8941. - secretRef
  8942. type: object
  8943. database:
  8944. description: Database to use as source
  8945. type: string
  8946. host:
  8947. description: URL configures the Password Depot instance URL.
  8948. type: string
  8949. required:
  8950. - auth
  8951. - database
  8952. - host
  8953. type: object
  8954. vault:
  8955. description: Vault configures this store to sync secrets using Hashi provider
  8956. properties:
  8957. auth:
  8958. description: Auth configures how secret-manager authenticates with the Vault server.
  8959. properties:
  8960. appRole:
  8961. description: |-
  8962. AppRole authenticates with Vault using the App Role auth mechanism,
  8963. with the role and secret stored in a Kubernetes Secret resource.
  8964. properties:
  8965. path:
  8966. default: approle
  8967. description: |-
  8968. Path where the App Role authentication backend is mounted
  8969. in Vault, e.g: "approle"
  8970. type: string
  8971. roleId:
  8972. description: |-
  8973. RoleID configured in the App Role authentication backend when setting
  8974. up the authentication backend in Vault.
  8975. type: string
  8976. secretRef:
  8977. description: |-
  8978. Reference to a key in a Secret that contains the App Role secret used
  8979. to authenticate with Vault.
  8980. The `key` field must be specified and denotes which entry within the Secret
  8981. resource is used as the app role secret.
  8982. properties:
  8983. key:
  8984. description: |-
  8985. A key in the referenced Secret.
  8986. Some instances of this field may be defaulted, in others it may be required.
  8987. maxLength: 253
  8988. minLength: 1
  8989. pattern: ^[-._a-zA-Z0-9]+$
  8990. type: string
  8991. name:
  8992. description: The name of the Secret resource being referred to.
  8993. maxLength: 253
  8994. minLength: 1
  8995. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  8996. type: string
  8997. namespace:
  8998. description: |-
  8999. The namespace of the Secret resource being referred to.
  9000. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9001. maxLength: 63
  9002. minLength: 1
  9003. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9004. type: string
  9005. type: object
  9006. required:
  9007. - path
  9008. - roleId
  9009. - secretRef
  9010. type: object
  9011. cert:
  9012. description: |-
  9013. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  9014. Cert authentication method
  9015. properties:
  9016. clientCert:
  9017. description: |-
  9018. ClientCert is a certificate to authenticate using the Cert Vault
  9019. authentication method
  9020. properties:
  9021. key:
  9022. description: |-
  9023. A key in the referenced Secret.
  9024. Some instances of this field may be defaulted, in others it may be required.
  9025. maxLength: 253
  9026. minLength: 1
  9027. pattern: ^[-._a-zA-Z0-9]+$
  9028. type: string
  9029. name:
  9030. description: The name of the Secret resource being referred to.
  9031. maxLength: 253
  9032. minLength: 1
  9033. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9034. type: string
  9035. namespace:
  9036. description: |-
  9037. The namespace of the Secret resource being referred to.
  9038. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9039. maxLength: 63
  9040. minLength: 1
  9041. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9042. type: string
  9043. type: object
  9044. secretRef:
  9045. description: |-
  9046. SecretRef to a key in a Secret resource containing client private key to
  9047. authenticate with Vault using the Cert authentication method
  9048. properties:
  9049. key:
  9050. description: |-
  9051. A key in the referenced Secret.
  9052. Some instances of this field may be defaulted, in others it may be required.
  9053. maxLength: 253
  9054. minLength: 1
  9055. pattern: ^[-._a-zA-Z0-9]+$
  9056. type: string
  9057. name:
  9058. description: The name of the Secret resource being referred to.
  9059. maxLength: 253
  9060. minLength: 1
  9061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9062. type: string
  9063. namespace:
  9064. description: |-
  9065. The namespace of the Secret resource being referred to.
  9066. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9067. maxLength: 63
  9068. minLength: 1
  9069. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9070. type: string
  9071. type: object
  9072. type: object
  9073. jwt:
  9074. description: |-
  9075. Jwt authenticates with Vault by passing role and JWT token using the
  9076. JWT/OIDC authentication method
  9077. properties:
  9078. kubernetesServiceAccountToken:
  9079. description: |-
  9080. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  9081. a token for with the `TokenRequest` API.
  9082. properties:
  9083. audiences:
  9084. description: |-
  9085. Optional audiences field that will be used to request a temporary Kubernetes service
  9086. account token for the service account referenced by `serviceAccountRef`.
  9087. Defaults to a single audience `vault` it not specified.
  9088. items:
  9089. type: string
  9090. type: array
  9091. expirationSeconds:
  9092. description: |-
  9093. Optional expiration time in seconds that will be used to request a temporary
  9094. Kubernetes service account token for the service account referenced by
  9095. `serviceAccountRef`.
  9096. Defaults to 10 minutes.
  9097. format: int64
  9098. type: integer
  9099. serviceAccountRef:
  9100. description: Service account field containing the name of a kubernetes ServiceAccount.
  9101. properties:
  9102. audiences:
  9103. description: |-
  9104. Audience specifies the `aud` claim for the service account token
  9105. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9106. then this audiences will be appended to the list
  9107. items:
  9108. type: string
  9109. type: array
  9110. name:
  9111. description: The name of the ServiceAccount resource being referred to.
  9112. maxLength: 253
  9113. minLength: 1
  9114. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9115. type: string
  9116. namespace:
  9117. description: |-
  9118. Namespace of the resource being referred to.
  9119. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9120. maxLength: 63
  9121. minLength: 1
  9122. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9123. type: string
  9124. required:
  9125. - name
  9126. type: object
  9127. required:
  9128. - serviceAccountRef
  9129. type: object
  9130. path:
  9131. default: jwt
  9132. description: |-
  9133. Path where the JWT authentication backend is mounted
  9134. in Vault, e.g: "jwt"
  9135. type: string
  9136. role:
  9137. description: |-
  9138. Role is a JWT role to authenticate using the JWT/OIDC Vault
  9139. authentication method
  9140. type: string
  9141. secretRef:
  9142. description: |-
  9143. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  9144. authenticate with Vault using the JWT/OIDC authentication method.
  9145. properties:
  9146. key:
  9147. description: |-
  9148. A key in the referenced Secret.
  9149. Some instances of this field may be defaulted, in others it may be required.
  9150. maxLength: 253
  9151. minLength: 1
  9152. pattern: ^[-._a-zA-Z0-9]+$
  9153. type: string
  9154. name:
  9155. description: The name of the Secret resource being referred to.
  9156. maxLength: 253
  9157. minLength: 1
  9158. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9159. type: string
  9160. namespace:
  9161. description: |-
  9162. The namespace of the Secret resource being referred to.
  9163. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9164. maxLength: 63
  9165. minLength: 1
  9166. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9167. type: string
  9168. type: object
  9169. required:
  9170. - path
  9171. type: object
  9172. kubernetes:
  9173. description: |-
  9174. Kubernetes authenticates with Vault by passing the ServiceAccount
  9175. token stored in the named Secret resource to the Vault server.
  9176. properties:
  9177. mountPath:
  9178. default: kubernetes
  9179. description: |-
  9180. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  9181. "kubernetes"
  9182. type: string
  9183. role:
  9184. description: |-
  9185. A required field containing the Vault Role to assume. A Role binds a
  9186. Kubernetes ServiceAccount with a set of Vault policies.
  9187. type: string
  9188. secretRef:
  9189. description: |-
  9190. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9191. for authenticating with Vault. If a name is specified without a key,
  9192. `token` is the default. If one is not specified, the one bound to
  9193. the controller will be used.
  9194. properties:
  9195. key:
  9196. description: |-
  9197. A key in the referenced Secret.
  9198. Some instances of this field may be defaulted, in others it may be required.
  9199. maxLength: 253
  9200. minLength: 1
  9201. pattern: ^[-._a-zA-Z0-9]+$
  9202. type: string
  9203. name:
  9204. description: The name of the Secret resource being referred to.
  9205. maxLength: 253
  9206. minLength: 1
  9207. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9208. type: string
  9209. namespace:
  9210. description: |-
  9211. The namespace of the Secret resource being referred to.
  9212. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9213. maxLength: 63
  9214. minLength: 1
  9215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9216. type: string
  9217. type: object
  9218. serviceAccountRef:
  9219. description: |-
  9220. Optional service account field containing the name of a kubernetes ServiceAccount.
  9221. If the service account is specified, the service account secret token JWT will be used
  9222. for authenticating with Vault. If the service account selector is not supplied,
  9223. the secretRef will be used instead.
  9224. properties:
  9225. audiences:
  9226. description: |-
  9227. Audience specifies the `aud` claim for the service account token
  9228. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9229. then this audiences will be appended to the list
  9230. items:
  9231. type: string
  9232. type: array
  9233. name:
  9234. description: The name of the ServiceAccount resource being referred to.
  9235. maxLength: 253
  9236. minLength: 1
  9237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9238. type: string
  9239. namespace:
  9240. description: |-
  9241. Namespace of the resource being referred to.
  9242. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9243. maxLength: 63
  9244. minLength: 1
  9245. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9246. type: string
  9247. required:
  9248. - name
  9249. type: object
  9250. required:
  9251. - mountPath
  9252. - role
  9253. type: object
  9254. ldap:
  9255. description: |-
  9256. Ldap authenticates with Vault by passing username/password pair using
  9257. the LDAP authentication method
  9258. properties:
  9259. path:
  9260. default: ldap
  9261. description: |-
  9262. Path where the LDAP authentication backend is mounted
  9263. in Vault, e.g: "ldap"
  9264. type: string
  9265. secretRef:
  9266. description: |-
  9267. SecretRef to a key in a Secret resource containing password for the LDAP
  9268. user used to authenticate with Vault using the LDAP authentication
  9269. method
  9270. properties:
  9271. key:
  9272. description: |-
  9273. A key in the referenced Secret.
  9274. Some instances of this field may be defaulted, in others it may be required.
  9275. maxLength: 253
  9276. minLength: 1
  9277. pattern: ^[-._a-zA-Z0-9]+$
  9278. type: string
  9279. name:
  9280. description: The name of the Secret resource being referred to.
  9281. maxLength: 253
  9282. minLength: 1
  9283. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9284. type: string
  9285. namespace:
  9286. description: |-
  9287. The namespace of the Secret resource being referred to.
  9288. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9289. maxLength: 63
  9290. minLength: 1
  9291. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9292. type: string
  9293. type: object
  9294. username:
  9295. description: |-
  9296. Username is a LDAP user name used to authenticate using the LDAP Vault
  9297. authentication method
  9298. type: string
  9299. required:
  9300. - path
  9301. - username
  9302. type: object
  9303. tokenSecretRef:
  9304. description: TokenSecretRef authenticates with Vault by presenting a token.
  9305. properties:
  9306. key:
  9307. description: |-
  9308. A key in the referenced Secret.
  9309. Some instances of this field may be defaulted, in others it may be required.
  9310. maxLength: 253
  9311. minLength: 1
  9312. pattern: ^[-._a-zA-Z0-9]+$
  9313. type: string
  9314. name:
  9315. description: The name of the Secret resource being referred to.
  9316. maxLength: 253
  9317. minLength: 1
  9318. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9319. type: string
  9320. namespace:
  9321. description: |-
  9322. The namespace of the Secret resource being referred to.
  9323. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9324. maxLength: 63
  9325. minLength: 1
  9326. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9327. type: string
  9328. type: object
  9329. type: object
  9330. caBundle:
  9331. description: |-
  9332. PEM encoded CA bundle used to validate Vault server certificate. Only used
  9333. if the Server URL is using HTTPS protocol. This parameter is ignored for
  9334. plain HTTP protocol connection. If not set the system root certificates
  9335. are used to validate the TLS connection.
  9336. format: byte
  9337. type: string
  9338. caProvider:
  9339. description: The provider for the CA bundle to use to validate Vault server certificate.
  9340. properties:
  9341. key:
  9342. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9343. maxLength: 253
  9344. minLength: 1
  9345. pattern: ^[-._a-zA-Z0-9]+$
  9346. type: string
  9347. name:
  9348. description: The name of the object located at the provider type.
  9349. maxLength: 253
  9350. minLength: 1
  9351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9352. type: string
  9353. namespace:
  9354. description: The namespace the Provider type is in.
  9355. maxLength: 63
  9356. minLength: 1
  9357. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9358. type: string
  9359. type:
  9360. description: The type of provider to use such as "Secret", or "ConfigMap".
  9361. enum:
  9362. - Secret
  9363. - ConfigMap
  9364. type: string
  9365. required:
  9366. - name
  9367. - type
  9368. type: object
  9369. forwardInconsistent:
  9370. description: |-
  9371. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  9372. leader instead of simply retrying within a loop. This can increase performance if
  9373. the option is enabled serverside.
  9374. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  9375. type: boolean
  9376. namespace:
  9377. description: |-
  9378. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  9379. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  9380. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  9381. type: string
  9382. path:
  9383. description: |-
  9384. Path is the mount path of the Vault KV backend endpoint, e.g:
  9385. "secret". The v2 KV secret engine version specific "/data" path suffix
  9386. for fetching secrets from Vault is optional and will be appended
  9387. if not present in specified path.
  9388. type: string
  9389. readYourWrites:
  9390. description: |-
  9391. ReadYourWrites ensures isolated read-after-write semantics by
  9392. providing discovered cluster replication states in each request.
  9393. More information about eventual consistency in Vault can be found here
  9394. https://www.vaultproject.io/docs/enterprise/consistency
  9395. type: boolean
  9396. server:
  9397. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  9398. type: string
  9399. version:
  9400. default: v2
  9401. description: |-
  9402. Version is the Vault KV secret engine version. This can be either "v1" or
  9403. "v2". Version defaults to "v2".
  9404. enum:
  9405. - v1
  9406. - v2
  9407. type: string
  9408. required:
  9409. - auth
  9410. - server
  9411. type: object
  9412. webhook:
  9413. description: Webhook configures this store to sync secrets using a generic templated webhook
  9414. properties:
  9415. body:
  9416. description: Body
  9417. type: string
  9418. caBundle:
  9419. description: |-
  9420. PEM encoded CA bundle used to validate webhook server certificate. Only used
  9421. if the Server URL is using HTTPS protocol. This parameter is ignored for
  9422. plain HTTP protocol connection. If not set the system root certificates
  9423. are used to validate the TLS connection.
  9424. format: byte
  9425. type: string
  9426. caProvider:
  9427. description: The provider for the CA bundle to use to validate webhook server certificate.
  9428. properties:
  9429. key:
  9430. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9431. maxLength: 253
  9432. minLength: 1
  9433. pattern: ^[-._a-zA-Z0-9]+$
  9434. type: string
  9435. name:
  9436. description: The name of the object located at the provider type.
  9437. maxLength: 253
  9438. minLength: 1
  9439. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9440. type: string
  9441. namespace:
  9442. description: The namespace the Provider type is in.
  9443. maxLength: 63
  9444. minLength: 1
  9445. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9446. type: string
  9447. type:
  9448. description: The type of provider to use such as "Secret", or "ConfigMap".
  9449. enum:
  9450. - Secret
  9451. - ConfigMap
  9452. type: string
  9453. required:
  9454. - name
  9455. - type
  9456. type: object
  9457. headers:
  9458. additionalProperties:
  9459. type: string
  9460. description: Headers
  9461. type: object
  9462. method:
  9463. description: Webhook Method
  9464. type: string
  9465. result:
  9466. description: Result formatting
  9467. properties:
  9468. jsonPath:
  9469. description: Json path of return value
  9470. type: string
  9471. type: object
  9472. secrets:
  9473. description: |-
  9474. Secrets to fill in templates
  9475. These secrets will be passed to the templating function as key value pairs under the given name
  9476. items:
  9477. properties:
  9478. name:
  9479. description: Name of this secret in templates
  9480. type: string
  9481. secretRef:
  9482. description: Secret ref to fill in credentials
  9483. properties:
  9484. key:
  9485. description: |-
  9486. A key in the referenced Secret.
  9487. Some instances of this field may be defaulted, in others it may be required.
  9488. maxLength: 253
  9489. minLength: 1
  9490. pattern: ^[-._a-zA-Z0-9]+$
  9491. type: string
  9492. name:
  9493. description: The name of the Secret resource being referred to.
  9494. maxLength: 253
  9495. minLength: 1
  9496. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9497. type: string
  9498. namespace:
  9499. description: |-
  9500. The namespace of the Secret resource being referred to.
  9501. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9502. maxLength: 63
  9503. minLength: 1
  9504. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9505. type: string
  9506. type: object
  9507. required:
  9508. - name
  9509. - secretRef
  9510. type: object
  9511. type: array
  9512. timeout:
  9513. description: Timeout
  9514. type: string
  9515. url:
  9516. description: Webhook url to call
  9517. type: string
  9518. required:
  9519. - result
  9520. - url
  9521. type: object
  9522. yandexlockbox:
  9523. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  9524. properties:
  9525. apiEndpoint:
  9526. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  9527. type: string
  9528. auth:
  9529. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  9530. properties:
  9531. authorizedKeySecretRef:
  9532. description: The authorized key used for authentication
  9533. properties:
  9534. key:
  9535. description: |-
  9536. A key in the referenced Secret.
  9537. Some instances of this field may be defaulted, in others it may be required.
  9538. maxLength: 253
  9539. minLength: 1
  9540. pattern: ^[-._a-zA-Z0-9]+$
  9541. type: string
  9542. name:
  9543. description: The name of the Secret resource being referred to.
  9544. maxLength: 253
  9545. minLength: 1
  9546. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9547. type: string
  9548. namespace:
  9549. description: |-
  9550. The namespace of the Secret resource being referred to.
  9551. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9552. maxLength: 63
  9553. minLength: 1
  9554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9555. type: string
  9556. type: object
  9557. type: object
  9558. caProvider:
  9559. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  9560. properties:
  9561. certSecretRef:
  9562. description: |-
  9563. A reference to a specific 'key' within a Secret resource.
  9564. In some instances, `key` is a required field.
  9565. properties:
  9566. key:
  9567. description: |-
  9568. A key in the referenced Secret.
  9569. Some instances of this field may be defaulted, in others it may be required.
  9570. maxLength: 253
  9571. minLength: 1
  9572. pattern: ^[-._a-zA-Z0-9]+$
  9573. type: string
  9574. name:
  9575. description: The name of the Secret resource being referred to.
  9576. maxLength: 253
  9577. minLength: 1
  9578. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9579. type: string
  9580. namespace:
  9581. description: |-
  9582. The namespace of the Secret resource being referred to.
  9583. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9584. maxLength: 63
  9585. minLength: 1
  9586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9587. type: string
  9588. type: object
  9589. type: object
  9590. required:
  9591. - auth
  9592. type: object
  9593. type: object
  9594. retrySettings:
  9595. description: Used to configure http retries if failed
  9596. properties:
  9597. maxRetries:
  9598. format: int32
  9599. type: integer
  9600. retryInterval:
  9601. type: string
  9602. type: object
  9603. required:
  9604. - provider
  9605. type: object
  9606. status:
  9607. description: SecretStoreStatus defines the observed state of the SecretStore.
  9608. properties:
  9609. conditions:
  9610. items:
  9611. properties:
  9612. lastTransitionTime:
  9613. format: date-time
  9614. type: string
  9615. message:
  9616. type: string
  9617. reason:
  9618. type: string
  9619. status:
  9620. type: string
  9621. type:
  9622. type: string
  9623. required:
  9624. - status
  9625. - type
  9626. type: object
  9627. type: array
  9628. type: object
  9629. type: object
  9630. served: true
  9631. storage: false
  9632. subresources:
  9633. status: {}
  9634. - additionalPrinterColumns:
  9635. - jsonPath: .metadata.creationTimestamp
  9636. name: AGE
  9637. type: date
  9638. - jsonPath: .status.conditions[?(@.type=="Ready")].reason
  9639. name: Status
  9640. type: string
  9641. - jsonPath: .status.capabilities
  9642. name: Capabilities
  9643. type: string
  9644. - jsonPath: .status.conditions[?(@.type=="Ready")].status
  9645. name: Ready
  9646. type: string
  9647. name: v1beta1
  9648. schema:
  9649. openAPIV3Schema:
  9650. description: SecretStore represents a secure external location for storing secrets, which can be referenced as part of `storeRef` fields.
  9651. properties:
  9652. apiVersion:
  9653. description: |-
  9654. APIVersion defines the versioned schema of this representation of an object.
  9655. Servers should convert recognized schemas to the latest internal value, and
  9656. may reject unrecognized values.
  9657. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  9658. type: string
  9659. kind:
  9660. description: |-
  9661. Kind is a string value representing the REST resource this object represents.
  9662. Servers may infer this from the endpoint the client submits requests to.
  9663. Cannot be updated.
  9664. In CamelCase.
  9665. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  9666. type: string
  9667. metadata:
  9668. type: object
  9669. spec:
  9670. description: SecretStoreSpec defines the desired state of SecretStore.
  9671. properties:
  9672. conditions:
  9673. description: Used to constraint a ClusterSecretStore to specific namespaces. Relevant only to ClusterSecretStore
  9674. items:
  9675. description: |-
  9676. ClusterSecretStoreCondition describes a condition by which to choose namespaces to process ExternalSecrets in
  9677. for a ClusterSecretStore instance.
  9678. properties:
  9679. namespaceRegexes:
  9680. description: Choose namespaces by using regex matching
  9681. items:
  9682. type: string
  9683. type: array
  9684. namespaceSelector:
  9685. description: Choose namespace using a labelSelector
  9686. properties:
  9687. matchExpressions:
  9688. description: matchExpressions is a list of label selector requirements. The requirements are ANDed.
  9689. items:
  9690. description: |-
  9691. A label selector requirement is a selector that contains values, a key, and an operator that
  9692. relates the key and values.
  9693. properties:
  9694. key:
  9695. description: key is the label key that the selector applies to.
  9696. type: string
  9697. operator:
  9698. description: |-
  9699. operator represents a key's relationship to a set of values.
  9700. Valid operators are In, NotIn, Exists and DoesNotExist.
  9701. type: string
  9702. values:
  9703. description: |-
  9704. values is an array of string values. If the operator is In or NotIn,
  9705. the values array must be non-empty. If the operator is Exists or DoesNotExist,
  9706. the values array must be empty. This array is replaced during a strategic
  9707. merge patch.
  9708. items:
  9709. type: string
  9710. type: array
  9711. x-kubernetes-list-type: atomic
  9712. required:
  9713. - key
  9714. - operator
  9715. type: object
  9716. type: array
  9717. x-kubernetes-list-type: atomic
  9718. matchLabels:
  9719. additionalProperties:
  9720. type: string
  9721. description: |-
  9722. matchLabels is a map of {key,value} pairs. A single {key,value} in the matchLabels
  9723. map is equivalent to an element of matchExpressions, whose key field is "key", the
  9724. operator is "In", and the values array contains only "value". The requirements are ANDed.
  9725. type: object
  9726. type: object
  9727. x-kubernetes-map-type: atomic
  9728. namespaces:
  9729. description: Choose namespaces by name
  9730. items:
  9731. maxLength: 63
  9732. minLength: 1
  9733. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9734. type: string
  9735. type: array
  9736. type: object
  9737. type: array
  9738. controller:
  9739. description: |-
  9740. Used to select the correct ESO controller (think: ingress.ingressClassName)
  9741. The ESO controller is instantiated with a specific controller name and filters ES based on this property
  9742. type: string
  9743. provider:
  9744. description: Used to configure the provider. Only one provider may be set
  9745. maxProperties: 1
  9746. minProperties: 1
  9747. properties:
  9748. akeyless:
  9749. description: Akeyless configures this store to sync secrets using Akeyless Vault provider
  9750. properties:
  9751. akeylessGWApiURL:
  9752. description: Akeyless GW API Url from which the secrets to be fetched from.
  9753. type: string
  9754. authSecretRef:
  9755. description: Auth configures how the operator authenticates with Akeyless.
  9756. properties:
  9757. kubernetesAuth:
  9758. description: |-
  9759. Kubernetes authenticates with Akeyless by passing the ServiceAccount
  9760. token stored in the named Secret resource.
  9761. properties:
  9762. accessID:
  9763. description: the Akeyless Kubernetes auth-method access-id
  9764. type: string
  9765. k8sConfName:
  9766. description: Kubernetes-auth configuration name in Akeyless-Gateway
  9767. type: string
  9768. secretRef:
  9769. description: |-
  9770. Optional secret field containing a Kubernetes ServiceAccount JWT used
  9771. for authenticating with Akeyless. If a name is specified without a key,
  9772. `token` is the default. If one is not specified, the one bound to
  9773. the controller will be used.
  9774. properties:
  9775. key:
  9776. description: |-
  9777. A key in the referenced Secret.
  9778. Some instances of this field may be defaulted, in others it may be required.
  9779. maxLength: 253
  9780. minLength: 1
  9781. pattern: ^[-._a-zA-Z0-9]+$
  9782. type: string
  9783. name:
  9784. description: The name of the Secret resource being referred to.
  9785. maxLength: 253
  9786. minLength: 1
  9787. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9788. type: string
  9789. namespace:
  9790. description: |-
  9791. The namespace of the Secret resource being referred to.
  9792. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9793. maxLength: 63
  9794. minLength: 1
  9795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9796. type: string
  9797. type: object
  9798. serviceAccountRef:
  9799. description: |-
  9800. Optional service account field containing the name of a kubernetes ServiceAccount.
  9801. If the service account is specified, the service account secret token JWT will be used
  9802. for authenticating with Akeyless. If the service account selector is not supplied,
  9803. the secretRef will be used instead.
  9804. properties:
  9805. audiences:
  9806. description: |-
  9807. Audience specifies the `aud` claim for the service account token
  9808. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  9809. then this audiences will be appended to the list
  9810. items:
  9811. type: string
  9812. type: array
  9813. name:
  9814. description: The name of the ServiceAccount resource being referred to.
  9815. maxLength: 253
  9816. minLength: 1
  9817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9818. type: string
  9819. namespace:
  9820. description: |-
  9821. Namespace of the resource being referred to.
  9822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9823. maxLength: 63
  9824. minLength: 1
  9825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9826. type: string
  9827. required:
  9828. - name
  9829. type: object
  9830. required:
  9831. - accessID
  9832. - k8sConfName
  9833. type: object
  9834. secretRef:
  9835. description: |-
  9836. Reference to a Secret that contains the details
  9837. to authenticate with Akeyless.
  9838. properties:
  9839. accessID:
  9840. description: The SecretAccessID is used for authentication
  9841. properties:
  9842. key:
  9843. description: |-
  9844. A key in the referenced Secret.
  9845. Some instances of this field may be defaulted, in others it may be required.
  9846. maxLength: 253
  9847. minLength: 1
  9848. pattern: ^[-._a-zA-Z0-9]+$
  9849. type: string
  9850. name:
  9851. description: The name of the Secret resource being referred to.
  9852. maxLength: 253
  9853. minLength: 1
  9854. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9855. type: string
  9856. namespace:
  9857. description: |-
  9858. The namespace of the Secret resource being referred to.
  9859. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9860. maxLength: 63
  9861. minLength: 1
  9862. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9863. type: string
  9864. type: object
  9865. accessType:
  9866. description: |-
  9867. A reference to a specific 'key' within a Secret resource.
  9868. In some instances, `key` is a required field.
  9869. properties:
  9870. key:
  9871. description: |-
  9872. A key in the referenced Secret.
  9873. Some instances of this field may be defaulted, in others it may be required.
  9874. maxLength: 253
  9875. minLength: 1
  9876. pattern: ^[-._a-zA-Z0-9]+$
  9877. type: string
  9878. name:
  9879. description: The name of the Secret resource being referred to.
  9880. maxLength: 253
  9881. minLength: 1
  9882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9883. type: string
  9884. namespace:
  9885. description: |-
  9886. The namespace of the Secret resource being referred to.
  9887. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9888. maxLength: 63
  9889. minLength: 1
  9890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9891. type: string
  9892. type: object
  9893. accessTypeParam:
  9894. description: |-
  9895. A reference to a specific 'key' within a Secret resource.
  9896. In some instances, `key` is a required field.
  9897. properties:
  9898. key:
  9899. description: |-
  9900. A key in the referenced Secret.
  9901. Some instances of this field may be defaulted, in others it may be required.
  9902. maxLength: 253
  9903. minLength: 1
  9904. pattern: ^[-._a-zA-Z0-9]+$
  9905. type: string
  9906. name:
  9907. description: The name of the Secret resource being referred to.
  9908. maxLength: 253
  9909. minLength: 1
  9910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9911. type: string
  9912. namespace:
  9913. description: |-
  9914. The namespace of the Secret resource being referred to.
  9915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  9916. maxLength: 63
  9917. minLength: 1
  9918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9919. type: string
  9920. type: object
  9921. type: object
  9922. type: object
  9923. caBundle:
  9924. description: |-
  9925. PEM/base64 encoded CA bundle used to validate Akeyless Gateway certificate. Only used
  9926. if the AkeylessGWApiURL URL is using HTTPS protocol. If not set the system root certificates
  9927. are used to validate the TLS connection.
  9928. format: byte
  9929. type: string
  9930. caProvider:
  9931. description: The provider for the CA bundle to use to validate Akeyless Gateway certificate.
  9932. properties:
  9933. key:
  9934. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  9935. maxLength: 253
  9936. minLength: 1
  9937. pattern: ^[-._a-zA-Z0-9]+$
  9938. type: string
  9939. name:
  9940. description: The name of the object located at the provider type.
  9941. maxLength: 253
  9942. minLength: 1
  9943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  9944. type: string
  9945. namespace:
  9946. description: |-
  9947. The namespace the Provider type is in.
  9948. Can only be defined when used in a ClusterSecretStore.
  9949. maxLength: 63
  9950. minLength: 1
  9951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  9952. type: string
  9953. type:
  9954. description: The type of provider to use such as "Secret", or "ConfigMap".
  9955. enum:
  9956. - Secret
  9957. - ConfigMap
  9958. type: string
  9959. required:
  9960. - name
  9961. - type
  9962. type: object
  9963. required:
  9964. - akeylessGWApiURL
  9965. - authSecretRef
  9966. type: object
  9967. alibaba:
  9968. description: Alibaba configures this store to sync secrets using Alibaba Cloud provider
  9969. properties:
  9970. auth:
  9971. description: AlibabaAuth contains a secretRef for credentials.
  9972. properties:
  9973. rrsa:
  9974. description: Authenticate against Alibaba using RRSA.
  9975. properties:
  9976. oidcProviderArn:
  9977. type: string
  9978. oidcTokenFilePath:
  9979. type: string
  9980. roleArn:
  9981. type: string
  9982. sessionName:
  9983. type: string
  9984. required:
  9985. - oidcProviderArn
  9986. - oidcTokenFilePath
  9987. - roleArn
  9988. - sessionName
  9989. type: object
  9990. secretRef:
  9991. description: AlibabaAuthSecretRef holds secret references for Alibaba credentials.
  9992. properties:
  9993. accessKeyIDSecretRef:
  9994. description: The AccessKeyID is used for authentication
  9995. properties:
  9996. key:
  9997. description: |-
  9998. A key in the referenced Secret.
  9999. Some instances of this field may be defaulted, in others it may be required.
  10000. maxLength: 253
  10001. minLength: 1
  10002. pattern: ^[-._a-zA-Z0-9]+$
  10003. type: string
  10004. name:
  10005. description: The name of the Secret resource being referred to.
  10006. maxLength: 253
  10007. minLength: 1
  10008. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10009. type: string
  10010. namespace:
  10011. description: |-
  10012. The namespace of the Secret resource being referred to.
  10013. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10014. maxLength: 63
  10015. minLength: 1
  10016. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10017. type: string
  10018. type: object
  10019. accessKeySecretSecretRef:
  10020. description: The AccessKeySecret is used for authentication
  10021. properties:
  10022. key:
  10023. description: |-
  10024. A key in the referenced Secret.
  10025. Some instances of this field may be defaulted, in others it may be required.
  10026. maxLength: 253
  10027. minLength: 1
  10028. pattern: ^[-._a-zA-Z0-9]+$
  10029. type: string
  10030. name:
  10031. description: The name of the Secret resource being referred to.
  10032. maxLength: 253
  10033. minLength: 1
  10034. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10035. type: string
  10036. namespace:
  10037. description: |-
  10038. The namespace of the Secret resource being referred to.
  10039. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10040. maxLength: 63
  10041. minLength: 1
  10042. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10043. type: string
  10044. type: object
  10045. required:
  10046. - accessKeyIDSecretRef
  10047. - accessKeySecretSecretRef
  10048. type: object
  10049. type: object
  10050. regionID:
  10051. description: Alibaba Region to be used for the provider
  10052. type: string
  10053. required:
  10054. - auth
  10055. - regionID
  10056. type: object
  10057. aws:
  10058. description: AWS configures this store to sync secrets using AWS Secret Manager provider
  10059. properties:
  10060. additionalRoles:
  10061. description: AdditionalRoles is a chained list of Role ARNs which the provider will sequentially assume before assuming the Role
  10062. items:
  10063. type: string
  10064. type: array
  10065. auth:
  10066. description: |-
  10067. Auth defines the information necessary to authenticate against AWS
  10068. if not set aws sdk will infer credentials from your environment
  10069. see: https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html#specifying-credentials
  10070. properties:
  10071. jwt:
  10072. description: Authenticate against AWS using service account tokens.
  10073. properties:
  10074. serviceAccountRef:
  10075. description: A reference to a ServiceAccount resource.
  10076. properties:
  10077. audiences:
  10078. description: |-
  10079. Audience specifies the `aud` claim for the service account token
  10080. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10081. then this audiences will be appended to the list
  10082. items:
  10083. type: string
  10084. type: array
  10085. name:
  10086. description: The name of the ServiceAccount resource being referred to.
  10087. maxLength: 253
  10088. minLength: 1
  10089. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10090. type: string
  10091. namespace:
  10092. description: |-
  10093. Namespace of the resource being referred to.
  10094. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10095. maxLength: 63
  10096. minLength: 1
  10097. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10098. type: string
  10099. required:
  10100. - name
  10101. type: object
  10102. type: object
  10103. secretRef:
  10104. description: |-
  10105. AWSAuthSecretRef holds secret references for AWS credentials
  10106. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  10107. properties:
  10108. accessKeyIDSecretRef:
  10109. description: The AccessKeyID is used for authentication
  10110. properties:
  10111. key:
  10112. description: |-
  10113. A key in the referenced Secret.
  10114. Some instances of this field may be defaulted, in others it may be required.
  10115. maxLength: 253
  10116. minLength: 1
  10117. pattern: ^[-._a-zA-Z0-9]+$
  10118. type: string
  10119. name:
  10120. description: The name of the Secret resource being referred to.
  10121. maxLength: 253
  10122. minLength: 1
  10123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10124. type: string
  10125. namespace:
  10126. description: |-
  10127. The namespace of the Secret resource being referred to.
  10128. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10129. maxLength: 63
  10130. minLength: 1
  10131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10132. type: string
  10133. type: object
  10134. secretAccessKeySecretRef:
  10135. description: The SecretAccessKey is used for authentication
  10136. properties:
  10137. key:
  10138. description: |-
  10139. A key in the referenced Secret.
  10140. Some instances of this field may be defaulted, in others it may be required.
  10141. maxLength: 253
  10142. minLength: 1
  10143. pattern: ^[-._a-zA-Z0-9]+$
  10144. type: string
  10145. name:
  10146. description: The name of the Secret resource being referred to.
  10147. maxLength: 253
  10148. minLength: 1
  10149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10150. type: string
  10151. namespace:
  10152. description: |-
  10153. The namespace of the Secret resource being referred to.
  10154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10155. maxLength: 63
  10156. minLength: 1
  10157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10158. type: string
  10159. type: object
  10160. sessionTokenSecretRef:
  10161. description: |-
  10162. The SessionToken used for authentication
  10163. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  10164. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  10165. properties:
  10166. key:
  10167. description: |-
  10168. A key in the referenced Secret.
  10169. Some instances of this field may be defaulted, in others it may be required.
  10170. maxLength: 253
  10171. minLength: 1
  10172. pattern: ^[-._a-zA-Z0-9]+$
  10173. type: string
  10174. name:
  10175. description: The name of the Secret resource being referred to.
  10176. maxLength: 253
  10177. minLength: 1
  10178. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10179. type: string
  10180. namespace:
  10181. description: |-
  10182. The namespace of the Secret resource being referred to.
  10183. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10184. maxLength: 63
  10185. minLength: 1
  10186. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10187. type: string
  10188. type: object
  10189. type: object
  10190. type: object
  10191. externalID:
  10192. description: AWS External ID set on assumed IAM roles
  10193. type: string
  10194. prefix:
  10195. description: Prefix adds a prefix to all retrieved values.
  10196. type: string
  10197. region:
  10198. description: AWS Region to be used for the provider
  10199. type: string
  10200. role:
  10201. description: Role is a Role ARN which the provider will assume
  10202. type: string
  10203. secretsManager:
  10204. description: SecretsManager defines how the provider behaves when interacting with AWS SecretsManager
  10205. properties:
  10206. forceDeleteWithoutRecovery:
  10207. description: |-
  10208. Specifies whether to delete the secret without any recovery window. You
  10209. can't use both this parameter and RecoveryWindowInDays in the same call.
  10210. If you don't use either, then by default Secrets Manager uses a 30 day
  10211. recovery window.
  10212. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-ForceDeleteWithoutRecovery
  10213. type: boolean
  10214. recoveryWindowInDays:
  10215. description: |-
  10216. The number of days from 7 to 30 that Secrets Manager waits before
  10217. permanently deleting the secret. You can't use both this parameter and
  10218. ForceDeleteWithoutRecovery in the same call. If you don't use either,
  10219. then by default Secrets Manager uses a 30 day recovery window.
  10220. see: https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_DeleteSecret.html#SecretsManager-DeleteSecret-request-RecoveryWindowInDays
  10221. format: int64
  10222. type: integer
  10223. type: object
  10224. service:
  10225. description: Service defines which service should be used to fetch the secrets
  10226. enum:
  10227. - SecretsManager
  10228. - ParameterStore
  10229. type: string
  10230. sessionTags:
  10231. description: AWS STS assume role session tags
  10232. items:
  10233. properties:
  10234. key:
  10235. type: string
  10236. value:
  10237. type: string
  10238. required:
  10239. - key
  10240. - value
  10241. type: object
  10242. type: array
  10243. transitiveTagKeys:
  10244. description: AWS STS assume role transitive session tags. Required when multiple rules are used with the provider
  10245. items:
  10246. type: string
  10247. type: array
  10248. required:
  10249. - region
  10250. - service
  10251. type: object
  10252. azurekv:
  10253. description: AzureKV configures this store to sync secrets using Azure Key Vault provider
  10254. properties:
  10255. authSecretRef:
  10256. description: Auth configures how the operator authenticates with Azure. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10257. properties:
  10258. clientCertificate:
  10259. description: The Azure ClientCertificate of the service principle used for authentication.
  10260. properties:
  10261. key:
  10262. description: |-
  10263. A key in the referenced Secret.
  10264. Some instances of this field may be defaulted, in others it may be required.
  10265. maxLength: 253
  10266. minLength: 1
  10267. pattern: ^[-._a-zA-Z0-9]+$
  10268. type: string
  10269. name:
  10270. description: The name of the Secret resource being referred to.
  10271. maxLength: 253
  10272. minLength: 1
  10273. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10274. type: string
  10275. namespace:
  10276. description: |-
  10277. The namespace of the Secret resource being referred to.
  10278. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10279. maxLength: 63
  10280. minLength: 1
  10281. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10282. type: string
  10283. type: object
  10284. clientId:
  10285. description: The Azure clientId of the service principle or managed identity used for authentication.
  10286. properties:
  10287. key:
  10288. description: |-
  10289. A key in the referenced Secret.
  10290. Some instances of this field may be defaulted, in others it may be required.
  10291. maxLength: 253
  10292. minLength: 1
  10293. pattern: ^[-._a-zA-Z0-9]+$
  10294. type: string
  10295. name:
  10296. description: The name of the Secret resource being referred to.
  10297. maxLength: 253
  10298. minLength: 1
  10299. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10300. type: string
  10301. namespace:
  10302. description: |-
  10303. The namespace of the Secret resource being referred to.
  10304. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10305. maxLength: 63
  10306. minLength: 1
  10307. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10308. type: string
  10309. type: object
  10310. clientSecret:
  10311. description: The Azure ClientSecret of the service principle used for authentication.
  10312. properties:
  10313. key:
  10314. description: |-
  10315. A key in the referenced Secret.
  10316. Some instances of this field may be defaulted, in others it may be required.
  10317. maxLength: 253
  10318. minLength: 1
  10319. pattern: ^[-._a-zA-Z0-9]+$
  10320. type: string
  10321. name:
  10322. description: The name of the Secret resource being referred to.
  10323. maxLength: 253
  10324. minLength: 1
  10325. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10326. type: string
  10327. namespace:
  10328. description: |-
  10329. The namespace of the Secret resource being referred to.
  10330. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10331. maxLength: 63
  10332. minLength: 1
  10333. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10334. type: string
  10335. type: object
  10336. tenantId:
  10337. description: The Azure tenantId of the managed identity used for authentication.
  10338. properties:
  10339. key:
  10340. description: |-
  10341. A key in the referenced Secret.
  10342. Some instances of this field may be defaulted, in others it may be required.
  10343. maxLength: 253
  10344. minLength: 1
  10345. pattern: ^[-._a-zA-Z0-9]+$
  10346. type: string
  10347. name:
  10348. description: The name of the Secret resource being referred to.
  10349. maxLength: 253
  10350. minLength: 1
  10351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10352. type: string
  10353. namespace:
  10354. description: |-
  10355. The namespace of the Secret resource being referred to.
  10356. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10357. maxLength: 63
  10358. minLength: 1
  10359. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10360. type: string
  10361. type: object
  10362. type: object
  10363. authType:
  10364. default: ServicePrincipal
  10365. description: |-
  10366. Auth type defines how to authenticate to the keyvault service.
  10367. Valid values are:
  10368. - "ServicePrincipal" (default): Using a service principal (tenantId, clientId, clientSecret)
  10369. - "ManagedIdentity": Using Managed Identity assigned to the pod (see aad-pod-identity)
  10370. enum:
  10371. - ServicePrincipal
  10372. - ManagedIdentity
  10373. - WorkloadIdentity
  10374. type: string
  10375. environmentType:
  10376. default: PublicCloud
  10377. description: |-
  10378. EnvironmentType specifies the Azure cloud environment endpoints to use for
  10379. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  10380. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  10381. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  10382. enum:
  10383. - PublicCloud
  10384. - USGovernmentCloud
  10385. - ChinaCloud
  10386. - GermanCloud
  10387. type: string
  10388. identityId:
  10389. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  10390. type: string
  10391. serviceAccountRef:
  10392. description: |-
  10393. ServiceAccountRef specified the service account
  10394. that should be used when authenticating with WorkloadIdentity.
  10395. properties:
  10396. audiences:
  10397. description: |-
  10398. Audience specifies the `aud` claim for the service account token
  10399. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10400. then this audiences will be appended to the list
  10401. items:
  10402. type: string
  10403. type: array
  10404. name:
  10405. description: The name of the ServiceAccount resource being referred to.
  10406. maxLength: 253
  10407. minLength: 1
  10408. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10409. type: string
  10410. namespace:
  10411. description: |-
  10412. Namespace of the resource being referred to.
  10413. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10414. maxLength: 63
  10415. minLength: 1
  10416. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10417. type: string
  10418. required:
  10419. - name
  10420. type: object
  10421. tenantId:
  10422. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type. Optional for WorkloadIdentity.
  10423. type: string
  10424. vaultUrl:
  10425. description: Vault Url from which the secrets to be fetched from.
  10426. type: string
  10427. required:
  10428. - vaultUrl
  10429. type: object
  10430. beyondtrust:
  10431. description: Beyondtrust configures this store to sync secrets using Password Safe provider.
  10432. properties:
  10433. auth:
  10434. description: Auth configures how the operator authenticates with Beyondtrust.
  10435. properties:
  10436. apiKey:
  10437. description: APIKey If not provided then ClientID/ClientSecret become required.
  10438. properties:
  10439. secretRef:
  10440. description: SecretRef references a key in a secret that will be used as value.
  10441. properties:
  10442. key:
  10443. description: |-
  10444. A key in the referenced Secret.
  10445. Some instances of this field may be defaulted, in others it may be required.
  10446. maxLength: 253
  10447. minLength: 1
  10448. pattern: ^[-._a-zA-Z0-9]+$
  10449. type: string
  10450. name:
  10451. description: The name of the Secret resource being referred to.
  10452. maxLength: 253
  10453. minLength: 1
  10454. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10455. type: string
  10456. namespace:
  10457. description: |-
  10458. The namespace of the Secret resource being referred to.
  10459. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10460. maxLength: 63
  10461. minLength: 1
  10462. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10463. type: string
  10464. type: object
  10465. value:
  10466. description: Value can be specified directly to set a value without using a secret.
  10467. type: string
  10468. type: object
  10469. certificate:
  10470. description: Certificate (cert.pem) for use when authenticating with an OAuth client Id using a Client Certificate.
  10471. properties:
  10472. secretRef:
  10473. description: SecretRef references a key in a secret that will be used as value.
  10474. properties:
  10475. key:
  10476. description: |-
  10477. A key in the referenced Secret.
  10478. Some instances of this field may be defaulted, in others it may be required.
  10479. maxLength: 253
  10480. minLength: 1
  10481. pattern: ^[-._a-zA-Z0-9]+$
  10482. type: string
  10483. name:
  10484. description: The name of the Secret resource being referred to.
  10485. maxLength: 253
  10486. minLength: 1
  10487. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10488. type: string
  10489. namespace:
  10490. description: |-
  10491. The namespace of the Secret resource being referred to.
  10492. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10493. maxLength: 63
  10494. minLength: 1
  10495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10496. type: string
  10497. type: object
  10498. value:
  10499. description: Value can be specified directly to set a value without using a secret.
  10500. type: string
  10501. type: object
  10502. certificateKey:
  10503. description: Certificate private key (key.pem). For use when authenticating with an OAuth client Id
  10504. properties:
  10505. secretRef:
  10506. description: SecretRef references a key in a secret that will be used as value.
  10507. properties:
  10508. key:
  10509. description: |-
  10510. A key in the referenced Secret.
  10511. Some instances of this field may be defaulted, in others it may be required.
  10512. maxLength: 253
  10513. minLength: 1
  10514. pattern: ^[-._a-zA-Z0-9]+$
  10515. type: string
  10516. name:
  10517. description: The name of the Secret resource being referred to.
  10518. maxLength: 253
  10519. minLength: 1
  10520. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10521. type: string
  10522. namespace:
  10523. description: |-
  10524. The namespace of the Secret resource being referred to.
  10525. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10526. maxLength: 63
  10527. minLength: 1
  10528. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10529. type: string
  10530. type: object
  10531. value:
  10532. description: Value can be specified directly to set a value without using a secret.
  10533. type: string
  10534. type: object
  10535. clientId:
  10536. description: ClientID is the API OAuth Client ID.
  10537. properties:
  10538. secretRef:
  10539. description: SecretRef references a key in a secret that will be used as value.
  10540. properties:
  10541. key:
  10542. description: |-
  10543. A key in the referenced Secret.
  10544. Some instances of this field may be defaulted, in others it may be required.
  10545. maxLength: 253
  10546. minLength: 1
  10547. pattern: ^[-._a-zA-Z0-9]+$
  10548. type: string
  10549. name:
  10550. description: The name of the Secret resource being referred to.
  10551. maxLength: 253
  10552. minLength: 1
  10553. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10554. type: string
  10555. namespace:
  10556. description: |-
  10557. The namespace of the Secret resource being referred to.
  10558. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10559. maxLength: 63
  10560. minLength: 1
  10561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10562. type: string
  10563. type: object
  10564. value:
  10565. description: Value can be specified directly to set a value without using a secret.
  10566. type: string
  10567. type: object
  10568. clientSecret:
  10569. description: ClientSecret is the API OAuth Client Secret.
  10570. properties:
  10571. secretRef:
  10572. description: SecretRef references a key in a secret that will be used as value.
  10573. properties:
  10574. key:
  10575. description: |-
  10576. A key in the referenced Secret.
  10577. Some instances of this field may be defaulted, in others it may be required.
  10578. maxLength: 253
  10579. minLength: 1
  10580. pattern: ^[-._a-zA-Z0-9]+$
  10581. type: string
  10582. name:
  10583. description: The name of the Secret resource being referred to.
  10584. maxLength: 253
  10585. minLength: 1
  10586. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10587. type: string
  10588. namespace:
  10589. description: |-
  10590. The namespace of the Secret resource being referred to.
  10591. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10592. maxLength: 63
  10593. minLength: 1
  10594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10595. type: string
  10596. type: object
  10597. value:
  10598. description: Value can be specified directly to set a value without using a secret.
  10599. type: string
  10600. type: object
  10601. type: object
  10602. server:
  10603. description: Auth configures how API server works.
  10604. properties:
  10605. apiUrl:
  10606. type: string
  10607. clientTimeOutSeconds:
  10608. description: Timeout specifies a time limit for requests made by this Client. The timeout includes connection time, any redirects, and reading the response body. Defaults to 45 seconds.
  10609. type: integer
  10610. retrievalType:
  10611. description: The secret retrieval type. SECRET = Secrets Safe (credential, text, file). MANAGED_ACCOUNT = Password Safe account associated with a system.
  10612. type: string
  10613. separator:
  10614. description: A character that separates the folder names.
  10615. type: string
  10616. verifyCA:
  10617. type: boolean
  10618. required:
  10619. - apiUrl
  10620. - verifyCA
  10621. type: object
  10622. required:
  10623. - auth
  10624. - server
  10625. type: object
  10626. bitwardensecretsmanager:
  10627. description: BitwardenSecretsManager configures this store to sync secrets using BitwardenSecretsManager provider
  10628. properties:
  10629. apiURL:
  10630. type: string
  10631. auth:
  10632. description: |-
  10633. Auth configures how secret-manager authenticates with a bitwarden machine account instance.
  10634. Make sure that the token being used has permissions on the given secret.
  10635. properties:
  10636. secretRef:
  10637. description: BitwardenSecretsManagerSecretRef contains the credential ref to the bitwarden instance.
  10638. properties:
  10639. credentials:
  10640. description: AccessToken used for the bitwarden instance.
  10641. properties:
  10642. key:
  10643. description: |-
  10644. A key in the referenced Secret.
  10645. Some instances of this field may be defaulted, in others it may be required.
  10646. maxLength: 253
  10647. minLength: 1
  10648. pattern: ^[-._a-zA-Z0-9]+$
  10649. type: string
  10650. name:
  10651. description: The name of the Secret resource being referred to.
  10652. maxLength: 253
  10653. minLength: 1
  10654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10655. type: string
  10656. namespace:
  10657. description: |-
  10658. The namespace of the Secret resource being referred to.
  10659. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10660. maxLength: 63
  10661. minLength: 1
  10662. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10663. type: string
  10664. type: object
  10665. required:
  10666. - credentials
  10667. type: object
  10668. required:
  10669. - secretRef
  10670. type: object
  10671. bitwardenServerSDKURL:
  10672. type: string
  10673. caBundle:
  10674. description: |-
  10675. Base64 encoded certificate for the bitwarden server sdk. The sdk MUST run with HTTPS to make sure no MITM attack
  10676. can be performed.
  10677. type: string
  10678. caProvider:
  10679. description: 'see: https://external-secrets.io/latest/spec/#external-secrets.io/v1alpha1.CAProvider'
  10680. properties:
  10681. key:
  10682. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10683. maxLength: 253
  10684. minLength: 1
  10685. pattern: ^[-._a-zA-Z0-9]+$
  10686. type: string
  10687. name:
  10688. description: The name of the object located at the provider type.
  10689. maxLength: 253
  10690. minLength: 1
  10691. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10692. type: string
  10693. namespace:
  10694. description: |-
  10695. The namespace the Provider type is in.
  10696. Can only be defined when used in a ClusterSecretStore.
  10697. maxLength: 63
  10698. minLength: 1
  10699. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10700. type: string
  10701. type:
  10702. description: The type of provider to use such as "Secret", or "ConfigMap".
  10703. enum:
  10704. - Secret
  10705. - ConfigMap
  10706. type: string
  10707. required:
  10708. - name
  10709. - type
  10710. type: object
  10711. identityURL:
  10712. type: string
  10713. organizationID:
  10714. description: OrganizationID determines which organization this secret store manages.
  10715. type: string
  10716. projectID:
  10717. description: ProjectID determines which project this secret store manages.
  10718. type: string
  10719. required:
  10720. - auth
  10721. - organizationID
  10722. - projectID
  10723. type: object
  10724. chef:
  10725. description: Chef configures this store to sync secrets with chef server
  10726. properties:
  10727. auth:
  10728. description: Auth defines the information necessary to authenticate against chef Server
  10729. properties:
  10730. secretRef:
  10731. description: ChefAuthSecretRef holds secret references for chef server login credentials.
  10732. properties:
  10733. privateKeySecretRef:
  10734. description: SecretKey is the Signing Key in PEM format, used for authentication.
  10735. properties:
  10736. key:
  10737. description: |-
  10738. A key in the referenced Secret.
  10739. Some instances of this field may be defaulted, in others it may be required.
  10740. maxLength: 253
  10741. minLength: 1
  10742. pattern: ^[-._a-zA-Z0-9]+$
  10743. type: string
  10744. name:
  10745. description: The name of the Secret resource being referred to.
  10746. maxLength: 253
  10747. minLength: 1
  10748. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10749. type: string
  10750. namespace:
  10751. description: |-
  10752. The namespace of the Secret resource being referred to.
  10753. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10754. maxLength: 63
  10755. minLength: 1
  10756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10757. type: string
  10758. type: object
  10759. required:
  10760. - privateKeySecretRef
  10761. type: object
  10762. required:
  10763. - secretRef
  10764. type: object
  10765. serverUrl:
  10766. description: ServerURL is the chef server URL used to connect to. If using orgs you should include your org in the url and terminate the url with a "/"
  10767. type: string
  10768. username:
  10769. description: UserName should be the user ID on the chef server
  10770. type: string
  10771. required:
  10772. - auth
  10773. - serverUrl
  10774. - username
  10775. type: object
  10776. conjur:
  10777. description: Conjur configures this store to sync secrets using conjur provider
  10778. properties:
  10779. auth:
  10780. properties:
  10781. apikey:
  10782. properties:
  10783. account:
  10784. type: string
  10785. apiKeyRef:
  10786. description: |-
  10787. A reference to a specific 'key' within a Secret resource.
  10788. In some instances, `key` is a required field.
  10789. properties:
  10790. key:
  10791. description: |-
  10792. A key in the referenced Secret.
  10793. Some instances of this field may be defaulted, in others it may be required.
  10794. maxLength: 253
  10795. minLength: 1
  10796. pattern: ^[-._a-zA-Z0-9]+$
  10797. type: string
  10798. name:
  10799. description: The name of the Secret resource being referred to.
  10800. maxLength: 253
  10801. minLength: 1
  10802. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10803. type: string
  10804. namespace:
  10805. description: |-
  10806. The namespace of the Secret resource being referred to.
  10807. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10808. maxLength: 63
  10809. minLength: 1
  10810. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10811. type: string
  10812. type: object
  10813. userRef:
  10814. description: |-
  10815. A reference to a specific 'key' within a Secret resource.
  10816. In some instances, `key` is a required field.
  10817. properties:
  10818. key:
  10819. description: |-
  10820. A key in the referenced Secret.
  10821. Some instances of this field may be defaulted, in others it may be required.
  10822. maxLength: 253
  10823. minLength: 1
  10824. pattern: ^[-._a-zA-Z0-9]+$
  10825. type: string
  10826. name:
  10827. description: The name of the Secret resource being referred to.
  10828. maxLength: 253
  10829. minLength: 1
  10830. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10831. type: string
  10832. namespace:
  10833. description: |-
  10834. The namespace of the Secret resource being referred to.
  10835. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10836. maxLength: 63
  10837. minLength: 1
  10838. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10839. type: string
  10840. type: object
  10841. required:
  10842. - account
  10843. - apiKeyRef
  10844. - userRef
  10845. type: object
  10846. jwt:
  10847. properties:
  10848. account:
  10849. type: string
  10850. hostId:
  10851. description: |-
  10852. Optional HostID for JWT authentication. This may be used depending
  10853. on how the Conjur JWT authenticator policy is configured.
  10854. type: string
  10855. secretRef:
  10856. description: |-
  10857. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  10858. authenticate with Conjur using the JWT authentication method.
  10859. properties:
  10860. key:
  10861. description: |-
  10862. A key in the referenced Secret.
  10863. Some instances of this field may be defaulted, in others it may be required.
  10864. maxLength: 253
  10865. minLength: 1
  10866. pattern: ^[-._a-zA-Z0-9]+$
  10867. type: string
  10868. name:
  10869. description: The name of the Secret resource being referred to.
  10870. maxLength: 253
  10871. minLength: 1
  10872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10873. type: string
  10874. namespace:
  10875. description: |-
  10876. The namespace of the Secret resource being referred to.
  10877. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10878. maxLength: 63
  10879. minLength: 1
  10880. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10881. type: string
  10882. type: object
  10883. serviceAccountRef:
  10884. description: |-
  10885. Optional ServiceAccountRef specifies the Kubernetes service account for which to request
  10886. a token for with the `TokenRequest` API.
  10887. properties:
  10888. audiences:
  10889. description: |-
  10890. Audience specifies the `aud` claim for the service account token
  10891. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  10892. then this audiences will be appended to the list
  10893. items:
  10894. type: string
  10895. type: array
  10896. name:
  10897. description: The name of the ServiceAccount resource being referred to.
  10898. maxLength: 253
  10899. minLength: 1
  10900. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10901. type: string
  10902. namespace:
  10903. description: |-
  10904. Namespace of the resource being referred to.
  10905. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10906. maxLength: 63
  10907. minLength: 1
  10908. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10909. type: string
  10910. required:
  10911. - name
  10912. type: object
  10913. serviceID:
  10914. description: The conjur authn jwt webservice id
  10915. type: string
  10916. required:
  10917. - account
  10918. - serviceID
  10919. type: object
  10920. type: object
  10921. caBundle:
  10922. type: string
  10923. caProvider:
  10924. description: |-
  10925. Used to provide custom certificate authority (CA) certificates
  10926. for a secret store. The CAProvider points to a Secret or ConfigMap resource
  10927. that contains a PEM-encoded certificate.
  10928. properties:
  10929. key:
  10930. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  10931. maxLength: 253
  10932. minLength: 1
  10933. pattern: ^[-._a-zA-Z0-9]+$
  10934. type: string
  10935. name:
  10936. description: The name of the object located at the provider type.
  10937. maxLength: 253
  10938. minLength: 1
  10939. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10940. type: string
  10941. namespace:
  10942. description: |-
  10943. The namespace the Provider type is in.
  10944. Can only be defined when used in a ClusterSecretStore.
  10945. maxLength: 63
  10946. minLength: 1
  10947. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10948. type: string
  10949. type:
  10950. description: The type of provider to use such as "Secret", or "ConfigMap".
  10951. enum:
  10952. - Secret
  10953. - ConfigMap
  10954. type: string
  10955. required:
  10956. - name
  10957. - type
  10958. type: object
  10959. url:
  10960. type: string
  10961. required:
  10962. - auth
  10963. - url
  10964. type: object
  10965. delinea:
  10966. description: |-
  10967. Delinea DevOps Secrets Vault
  10968. https://docs.delinea.com/online-help/products/devops-secrets-vault/current
  10969. properties:
  10970. clientId:
  10971. description: ClientID is the non-secret part of the credential.
  10972. properties:
  10973. secretRef:
  10974. description: SecretRef references a key in a secret that will be used as value.
  10975. properties:
  10976. key:
  10977. description: |-
  10978. A key in the referenced Secret.
  10979. Some instances of this field may be defaulted, in others it may be required.
  10980. maxLength: 253
  10981. minLength: 1
  10982. pattern: ^[-._a-zA-Z0-9]+$
  10983. type: string
  10984. name:
  10985. description: The name of the Secret resource being referred to.
  10986. maxLength: 253
  10987. minLength: 1
  10988. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  10989. type: string
  10990. namespace:
  10991. description: |-
  10992. The namespace of the Secret resource being referred to.
  10993. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  10994. maxLength: 63
  10995. minLength: 1
  10996. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  10997. type: string
  10998. type: object
  10999. value:
  11000. description: Value can be specified directly to set a value without using a secret.
  11001. type: string
  11002. type: object
  11003. clientSecret:
  11004. description: ClientSecret is the secret part of the credential.
  11005. properties:
  11006. secretRef:
  11007. description: SecretRef references a key in a secret that will be used as value.
  11008. properties:
  11009. key:
  11010. description: |-
  11011. A key in the referenced Secret.
  11012. Some instances of this field may be defaulted, in others it may be required.
  11013. maxLength: 253
  11014. minLength: 1
  11015. pattern: ^[-._a-zA-Z0-9]+$
  11016. type: string
  11017. name:
  11018. description: The name of the Secret resource being referred to.
  11019. maxLength: 253
  11020. minLength: 1
  11021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11022. type: string
  11023. namespace:
  11024. description: |-
  11025. The namespace of the Secret resource being referred to.
  11026. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11027. maxLength: 63
  11028. minLength: 1
  11029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11030. type: string
  11031. type: object
  11032. value:
  11033. description: Value can be specified directly to set a value without using a secret.
  11034. type: string
  11035. type: object
  11036. tenant:
  11037. description: Tenant is the chosen hostname / site name.
  11038. type: string
  11039. tld:
  11040. description: |-
  11041. TLD is based on the server location that was chosen during provisioning.
  11042. If unset, defaults to "com".
  11043. type: string
  11044. urlTemplate:
  11045. description: |-
  11046. URLTemplate
  11047. If unset, defaults to "https://%s.secretsvaultcloud.%s/v1/%s%s".
  11048. type: string
  11049. required:
  11050. - clientId
  11051. - clientSecret
  11052. - tenant
  11053. type: object
  11054. device42:
  11055. description: Device42 configures this store to sync secrets using the Device42 provider
  11056. properties:
  11057. auth:
  11058. description: Auth configures how secret-manager authenticates with a Device42 instance.
  11059. properties:
  11060. secretRef:
  11061. properties:
  11062. credentials:
  11063. description: Username / Password is used for authentication.
  11064. properties:
  11065. key:
  11066. description: |-
  11067. A key in the referenced Secret.
  11068. Some instances of this field may be defaulted, in others it may be required.
  11069. maxLength: 253
  11070. minLength: 1
  11071. pattern: ^[-._a-zA-Z0-9]+$
  11072. type: string
  11073. name:
  11074. description: The name of the Secret resource being referred to.
  11075. maxLength: 253
  11076. minLength: 1
  11077. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11078. type: string
  11079. namespace:
  11080. description: |-
  11081. The namespace of the Secret resource being referred to.
  11082. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11083. maxLength: 63
  11084. minLength: 1
  11085. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11086. type: string
  11087. type: object
  11088. type: object
  11089. required:
  11090. - secretRef
  11091. type: object
  11092. host:
  11093. description: URL configures the Device42 instance URL.
  11094. type: string
  11095. required:
  11096. - auth
  11097. - host
  11098. type: object
  11099. doppler:
  11100. description: Doppler configures this store to sync secrets using the Doppler provider
  11101. properties:
  11102. auth:
  11103. description: Auth configures how the Operator authenticates with the Doppler API
  11104. properties:
  11105. secretRef:
  11106. properties:
  11107. dopplerToken:
  11108. description: |-
  11109. The DopplerToken is used for authentication.
  11110. See https://docs.doppler.com/reference/api#authentication for auth token types.
  11111. The Key attribute defaults to dopplerToken if not specified.
  11112. properties:
  11113. key:
  11114. description: |-
  11115. A key in the referenced Secret.
  11116. Some instances of this field may be defaulted, in others it may be required.
  11117. maxLength: 253
  11118. minLength: 1
  11119. pattern: ^[-._a-zA-Z0-9]+$
  11120. type: string
  11121. name:
  11122. description: The name of the Secret resource being referred to.
  11123. maxLength: 253
  11124. minLength: 1
  11125. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11126. type: string
  11127. namespace:
  11128. description: |-
  11129. The namespace of the Secret resource being referred to.
  11130. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11131. maxLength: 63
  11132. minLength: 1
  11133. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11134. type: string
  11135. type: object
  11136. required:
  11137. - dopplerToken
  11138. type: object
  11139. required:
  11140. - secretRef
  11141. type: object
  11142. config:
  11143. description: Doppler config (required if not using a Service Token)
  11144. type: string
  11145. format:
  11146. description: Format enables the downloading of secrets as a file (string)
  11147. enum:
  11148. - json
  11149. - dotnet-json
  11150. - env
  11151. - yaml
  11152. - docker
  11153. type: string
  11154. nameTransformer:
  11155. description: Environment variable compatible name transforms that change secret names to a different format
  11156. enum:
  11157. - upper-camel
  11158. - camel
  11159. - lower-snake
  11160. - tf-var
  11161. - dotnet-env
  11162. - lower-kebab
  11163. type: string
  11164. project:
  11165. description: Doppler project (required if not using a Service Token)
  11166. type: string
  11167. required:
  11168. - auth
  11169. type: object
  11170. fake:
  11171. description: Fake configures a store with static key/value pairs
  11172. properties:
  11173. data:
  11174. items:
  11175. properties:
  11176. key:
  11177. type: string
  11178. value:
  11179. type: string
  11180. valueMap:
  11181. additionalProperties:
  11182. type: string
  11183. description: 'Deprecated: ValueMap is deprecated and is intended to be removed in the future, use the `value` field instead.'
  11184. type: object
  11185. version:
  11186. type: string
  11187. required:
  11188. - key
  11189. type: object
  11190. type: array
  11191. required:
  11192. - data
  11193. type: object
  11194. fortanix:
  11195. description: Fortanix configures this store to sync secrets using the Fortanix provider
  11196. properties:
  11197. apiKey:
  11198. description: APIKey is the API token to access SDKMS Applications.
  11199. properties:
  11200. secretRef:
  11201. description: SecretRef is a reference to a secret containing the SDKMS API Key.
  11202. properties:
  11203. key:
  11204. description: |-
  11205. A key in the referenced Secret.
  11206. Some instances of this field may be defaulted, in others it may be required.
  11207. maxLength: 253
  11208. minLength: 1
  11209. pattern: ^[-._a-zA-Z0-9]+$
  11210. type: string
  11211. name:
  11212. description: The name of the Secret resource being referred to.
  11213. maxLength: 253
  11214. minLength: 1
  11215. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11216. type: string
  11217. namespace:
  11218. description: |-
  11219. The namespace of the Secret resource being referred to.
  11220. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11221. maxLength: 63
  11222. minLength: 1
  11223. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11224. type: string
  11225. type: object
  11226. type: object
  11227. apiUrl:
  11228. description: APIURL is the URL of SDKMS API. Defaults to `sdkms.fortanix.com`.
  11229. type: string
  11230. type: object
  11231. gcpsm:
  11232. description: GCPSM configures this store to sync secrets using Google Cloud Platform Secret Manager provider
  11233. properties:
  11234. auth:
  11235. description: Auth defines the information necessary to authenticate against GCP
  11236. properties:
  11237. secretRef:
  11238. properties:
  11239. secretAccessKeySecretRef:
  11240. description: The SecretAccessKey is used for authentication
  11241. properties:
  11242. key:
  11243. description: |-
  11244. A key in the referenced Secret.
  11245. Some instances of this field may be defaulted, in others it may be required.
  11246. maxLength: 253
  11247. minLength: 1
  11248. pattern: ^[-._a-zA-Z0-9]+$
  11249. type: string
  11250. name:
  11251. description: The name of the Secret resource being referred to.
  11252. maxLength: 253
  11253. minLength: 1
  11254. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11255. type: string
  11256. namespace:
  11257. description: |-
  11258. The namespace of the Secret resource being referred to.
  11259. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11260. maxLength: 63
  11261. minLength: 1
  11262. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11263. type: string
  11264. type: object
  11265. type: object
  11266. workloadIdentity:
  11267. properties:
  11268. clusterLocation:
  11269. type: string
  11270. clusterName:
  11271. type: string
  11272. clusterProjectID:
  11273. type: string
  11274. serviceAccountRef:
  11275. description: A reference to a ServiceAccount resource.
  11276. properties:
  11277. audiences:
  11278. description: |-
  11279. Audience specifies the `aud` claim for the service account token
  11280. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11281. then this audiences will be appended to the list
  11282. items:
  11283. type: string
  11284. type: array
  11285. name:
  11286. description: The name of the ServiceAccount resource being referred to.
  11287. maxLength: 253
  11288. minLength: 1
  11289. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11290. type: string
  11291. namespace:
  11292. description: |-
  11293. Namespace of the resource being referred to.
  11294. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11295. maxLength: 63
  11296. minLength: 1
  11297. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11298. type: string
  11299. required:
  11300. - name
  11301. type: object
  11302. required:
  11303. - clusterLocation
  11304. - clusterName
  11305. - serviceAccountRef
  11306. type: object
  11307. type: object
  11308. location:
  11309. description: Location optionally defines a location for a secret
  11310. type: string
  11311. projectID:
  11312. description: ProjectID project where secret is located
  11313. type: string
  11314. type: object
  11315. gitlab:
  11316. description: GitLab configures this store to sync secrets using GitLab Variables provider
  11317. properties:
  11318. auth:
  11319. description: Auth configures how secret-manager authenticates with a GitLab instance.
  11320. properties:
  11321. SecretRef:
  11322. properties:
  11323. accessToken:
  11324. description: AccessToken is used for authentication.
  11325. properties:
  11326. key:
  11327. description: |-
  11328. A key in the referenced Secret.
  11329. Some instances of this field may be defaulted, in others it may be required.
  11330. maxLength: 253
  11331. minLength: 1
  11332. pattern: ^[-._a-zA-Z0-9]+$
  11333. type: string
  11334. name:
  11335. description: The name of the Secret resource being referred to.
  11336. maxLength: 253
  11337. minLength: 1
  11338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11339. type: string
  11340. namespace:
  11341. description: |-
  11342. The namespace of the Secret resource being referred to.
  11343. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11344. maxLength: 63
  11345. minLength: 1
  11346. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11347. type: string
  11348. type: object
  11349. type: object
  11350. required:
  11351. - SecretRef
  11352. type: object
  11353. environment:
  11354. description: Environment environment_scope of gitlab CI/CD variables (Please see https://docs.gitlab.com/ee/ci/environments/#create-a-static-environment on how to create environments)
  11355. type: string
  11356. groupIDs:
  11357. description: GroupIDs specify, which gitlab groups to pull secrets from. Group secrets are read from left to right followed by the project variables.
  11358. items:
  11359. type: string
  11360. type: array
  11361. inheritFromGroups:
  11362. description: InheritFromGroups specifies whether parent groups should be discovered and checked for secrets.
  11363. type: boolean
  11364. projectID:
  11365. description: ProjectID specifies a project where secrets are located.
  11366. type: string
  11367. url:
  11368. description: URL configures the GitLab instance URL. Defaults to https://gitlab.com/.
  11369. type: string
  11370. required:
  11371. - auth
  11372. type: object
  11373. ibm:
  11374. description: IBM configures this store to sync secrets using IBM Cloud provider
  11375. properties:
  11376. auth:
  11377. description: Auth configures how secret-manager authenticates with the IBM secrets manager.
  11378. maxProperties: 1
  11379. minProperties: 1
  11380. properties:
  11381. containerAuth:
  11382. description: IBM Container-based auth with IAM Trusted Profile.
  11383. properties:
  11384. iamEndpoint:
  11385. type: string
  11386. profile:
  11387. description: the IBM Trusted Profile
  11388. type: string
  11389. tokenLocation:
  11390. description: Location the token is mounted on the pod
  11391. type: string
  11392. required:
  11393. - profile
  11394. type: object
  11395. secretRef:
  11396. properties:
  11397. secretApiKeySecretRef:
  11398. description: The SecretAccessKey is used for authentication
  11399. properties:
  11400. key:
  11401. description: |-
  11402. A key in the referenced Secret.
  11403. Some instances of this field may be defaulted, in others it may be required.
  11404. maxLength: 253
  11405. minLength: 1
  11406. pattern: ^[-._a-zA-Z0-9]+$
  11407. type: string
  11408. name:
  11409. description: The name of the Secret resource being referred to.
  11410. maxLength: 253
  11411. minLength: 1
  11412. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11413. type: string
  11414. namespace:
  11415. description: |-
  11416. The namespace of the Secret resource being referred to.
  11417. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11418. maxLength: 63
  11419. minLength: 1
  11420. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11421. type: string
  11422. type: object
  11423. type: object
  11424. type: object
  11425. serviceUrl:
  11426. description: ServiceURL is the Endpoint URL that is specific to the Secrets Manager service instance
  11427. type: string
  11428. required:
  11429. - auth
  11430. type: object
  11431. infisical:
  11432. description: Infisical configures this store to sync secrets using the Infisical provider
  11433. properties:
  11434. auth:
  11435. description: Auth configures how the Operator authenticates with the Infisical API
  11436. properties:
  11437. universalAuthCredentials:
  11438. properties:
  11439. clientId:
  11440. description: |-
  11441. A reference to a specific 'key' within a Secret resource.
  11442. In some instances, `key` is a required field.
  11443. properties:
  11444. key:
  11445. description: |-
  11446. A key in the referenced Secret.
  11447. Some instances of this field may be defaulted, in others it may be required.
  11448. maxLength: 253
  11449. minLength: 1
  11450. pattern: ^[-._a-zA-Z0-9]+$
  11451. type: string
  11452. name:
  11453. description: The name of the Secret resource being referred to.
  11454. maxLength: 253
  11455. minLength: 1
  11456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11457. type: string
  11458. namespace:
  11459. description: |-
  11460. The namespace of the Secret resource being referred to.
  11461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11462. maxLength: 63
  11463. minLength: 1
  11464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11465. type: string
  11466. type: object
  11467. clientSecret:
  11468. description: |-
  11469. A reference to a specific 'key' within a Secret resource.
  11470. In some instances, `key` is a required field.
  11471. properties:
  11472. key:
  11473. description: |-
  11474. A key in the referenced Secret.
  11475. Some instances of this field may be defaulted, in others it may be required.
  11476. maxLength: 253
  11477. minLength: 1
  11478. pattern: ^[-._a-zA-Z0-9]+$
  11479. type: string
  11480. name:
  11481. description: The name of the Secret resource being referred to.
  11482. maxLength: 253
  11483. minLength: 1
  11484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11485. type: string
  11486. namespace:
  11487. description: |-
  11488. The namespace of the Secret resource being referred to.
  11489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11490. maxLength: 63
  11491. minLength: 1
  11492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11493. type: string
  11494. type: object
  11495. required:
  11496. - clientId
  11497. - clientSecret
  11498. type: object
  11499. type: object
  11500. hostAPI:
  11501. default: https://app.infisical.com/api
  11502. type: string
  11503. secretsScope:
  11504. properties:
  11505. environmentSlug:
  11506. type: string
  11507. projectSlug:
  11508. type: string
  11509. recursive:
  11510. default: false
  11511. type: boolean
  11512. secretsPath:
  11513. default: /
  11514. type: string
  11515. required:
  11516. - environmentSlug
  11517. - projectSlug
  11518. type: object
  11519. required:
  11520. - auth
  11521. - secretsScope
  11522. type: object
  11523. keepersecurity:
  11524. description: KeeperSecurity configures this store to sync secrets using the KeeperSecurity provider
  11525. properties:
  11526. authRef:
  11527. description: |-
  11528. A reference to a specific 'key' within a Secret resource.
  11529. In some instances, `key` is a required field.
  11530. properties:
  11531. key:
  11532. description: |-
  11533. A key in the referenced Secret.
  11534. Some instances of this field may be defaulted, in others it may be required.
  11535. maxLength: 253
  11536. minLength: 1
  11537. pattern: ^[-._a-zA-Z0-9]+$
  11538. type: string
  11539. name:
  11540. description: The name of the Secret resource being referred to.
  11541. maxLength: 253
  11542. minLength: 1
  11543. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11544. type: string
  11545. namespace:
  11546. description: |-
  11547. The namespace of the Secret resource being referred to.
  11548. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11549. maxLength: 63
  11550. minLength: 1
  11551. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11552. type: string
  11553. type: object
  11554. folderID:
  11555. type: string
  11556. required:
  11557. - authRef
  11558. - folderID
  11559. type: object
  11560. kubernetes:
  11561. description: Kubernetes configures this store to sync secrets using a Kubernetes cluster provider
  11562. properties:
  11563. auth:
  11564. description: Auth configures how secret-manager authenticates with a Kubernetes instance.
  11565. maxProperties: 1
  11566. minProperties: 1
  11567. properties:
  11568. cert:
  11569. description: has both clientCert and clientKey as secretKeySelector
  11570. properties:
  11571. clientCert:
  11572. description: |-
  11573. A reference to a specific 'key' within a Secret resource.
  11574. In some instances, `key` is a required field.
  11575. properties:
  11576. key:
  11577. description: |-
  11578. A key in the referenced Secret.
  11579. Some instances of this field may be defaulted, in others it may be required.
  11580. maxLength: 253
  11581. minLength: 1
  11582. pattern: ^[-._a-zA-Z0-9]+$
  11583. type: string
  11584. name:
  11585. description: The name of the Secret resource being referred to.
  11586. maxLength: 253
  11587. minLength: 1
  11588. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11589. type: string
  11590. namespace:
  11591. description: |-
  11592. The namespace of the Secret resource being referred to.
  11593. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11594. maxLength: 63
  11595. minLength: 1
  11596. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11597. type: string
  11598. type: object
  11599. clientKey:
  11600. description: |-
  11601. A reference to a specific 'key' within a Secret resource.
  11602. In some instances, `key` is a required field.
  11603. properties:
  11604. key:
  11605. description: |-
  11606. A key in the referenced Secret.
  11607. Some instances of this field may be defaulted, in others it may be required.
  11608. maxLength: 253
  11609. minLength: 1
  11610. pattern: ^[-._a-zA-Z0-9]+$
  11611. type: string
  11612. name:
  11613. description: The name of the Secret resource being referred to.
  11614. maxLength: 253
  11615. minLength: 1
  11616. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11617. type: string
  11618. namespace:
  11619. description: |-
  11620. The namespace of the Secret resource being referred to.
  11621. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11622. maxLength: 63
  11623. minLength: 1
  11624. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11625. type: string
  11626. type: object
  11627. type: object
  11628. serviceAccount:
  11629. description: points to a service account that should be used for authentication
  11630. properties:
  11631. audiences:
  11632. description: |-
  11633. Audience specifies the `aud` claim for the service account token
  11634. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  11635. then this audiences will be appended to the list
  11636. items:
  11637. type: string
  11638. type: array
  11639. name:
  11640. description: The name of the ServiceAccount resource being referred to.
  11641. maxLength: 253
  11642. minLength: 1
  11643. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11644. type: string
  11645. namespace:
  11646. description: |-
  11647. Namespace of the resource being referred to.
  11648. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11649. maxLength: 63
  11650. minLength: 1
  11651. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11652. type: string
  11653. required:
  11654. - name
  11655. type: object
  11656. token:
  11657. description: use static token to authenticate with
  11658. properties:
  11659. bearerToken:
  11660. description: |-
  11661. A reference to a specific 'key' within a Secret resource.
  11662. In some instances, `key` is a required field.
  11663. properties:
  11664. key:
  11665. description: |-
  11666. A key in the referenced Secret.
  11667. Some instances of this field may be defaulted, in others it may be required.
  11668. maxLength: 253
  11669. minLength: 1
  11670. pattern: ^[-._a-zA-Z0-9]+$
  11671. type: string
  11672. name:
  11673. description: The name of the Secret resource being referred to.
  11674. maxLength: 253
  11675. minLength: 1
  11676. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11677. type: string
  11678. namespace:
  11679. description: |-
  11680. The namespace of the Secret resource being referred to.
  11681. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11682. maxLength: 63
  11683. minLength: 1
  11684. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11685. type: string
  11686. type: object
  11687. type: object
  11688. type: object
  11689. authRef:
  11690. description: A reference to a secret that contains the auth information.
  11691. properties:
  11692. key:
  11693. description: |-
  11694. A key in the referenced Secret.
  11695. Some instances of this field may be defaulted, in others it may be required.
  11696. maxLength: 253
  11697. minLength: 1
  11698. pattern: ^[-._a-zA-Z0-9]+$
  11699. type: string
  11700. name:
  11701. description: The name of the Secret resource being referred to.
  11702. maxLength: 253
  11703. minLength: 1
  11704. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11705. type: string
  11706. namespace:
  11707. description: |-
  11708. The namespace of the Secret resource being referred to.
  11709. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11710. maxLength: 63
  11711. minLength: 1
  11712. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11713. type: string
  11714. type: object
  11715. remoteNamespace:
  11716. default: default
  11717. description: Remote namespace to fetch the secrets from
  11718. maxLength: 63
  11719. minLength: 1
  11720. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11721. type: string
  11722. server:
  11723. description: configures the Kubernetes server Address.
  11724. properties:
  11725. caBundle:
  11726. description: CABundle is a base64-encoded CA certificate
  11727. format: byte
  11728. type: string
  11729. caProvider:
  11730. description: 'see: https://external-secrets.io/v0.4.1/spec/#external-secrets.io/v1alpha1.CAProvider'
  11731. properties:
  11732. key:
  11733. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  11734. maxLength: 253
  11735. minLength: 1
  11736. pattern: ^[-._a-zA-Z0-9]+$
  11737. type: string
  11738. name:
  11739. description: The name of the object located at the provider type.
  11740. maxLength: 253
  11741. minLength: 1
  11742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11743. type: string
  11744. namespace:
  11745. description: |-
  11746. The namespace the Provider type is in.
  11747. Can only be defined when used in a ClusterSecretStore.
  11748. maxLength: 63
  11749. minLength: 1
  11750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11751. type: string
  11752. type:
  11753. description: The type of provider to use such as "Secret", or "ConfigMap".
  11754. enum:
  11755. - Secret
  11756. - ConfigMap
  11757. type: string
  11758. required:
  11759. - name
  11760. - type
  11761. type: object
  11762. url:
  11763. default: kubernetes.default
  11764. description: configures the Kubernetes server Address.
  11765. type: string
  11766. type: object
  11767. type: object
  11768. onboardbase:
  11769. description: Onboardbase configures this store to sync secrets using the Onboardbase provider
  11770. properties:
  11771. apiHost:
  11772. default: https://public.onboardbase.com/api/v1/
  11773. description: APIHost use this to configure the host url for the API for selfhosted installation, default is https://public.onboardbase.com/api/v1/
  11774. type: string
  11775. auth:
  11776. description: Auth configures how the Operator authenticates with the Onboardbase API
  11777. properties:
  11778. apiKeyRef:
  11779. description: |-
  11780. OnboardbaseAPIKey is the APIKey generated by an admin account.
  11781. It is used to recognize and authorize access to a project and environment within onboardbase
  11782. properties:
  11783. key:
  11784. description: |-
  11785. A key in the referenced Secret.
  11786. Some instances of this field may be defaulted, in others it may be required.
  11787. maxLength: 253
  11788. minLength: 1
  11789. pattern: ^[-._a-zA-Z0-9]+$
  11790. type: string
  11791. name:
  11792. description: The name of the Secret resource being referred to.
  11793. maxLength: 253
  11794. minLength: 1
  11795. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11796. type: string
  11797. namespace:
  11798. description: |-
  11799. The namespace of the Secret resource being referred to.
  11800. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11801. maxLength: 63
  11802. minLength: 1
  11803. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11804. type: string
  11805. type: object
  11806. passcodeRef:
  11807. description: OnboardbasePasscode is the passcode attached to the API Key
  11808. properties:
  11809. key:
  11810. description: |-
  11811. A key in the referenced Secret.
  11812. Some instances of this field may be defaulted, in others it may be required.
  11813. maxLength: 253
  11814. minLength: 1
  11815. pattern: ^[-._a-zA-Z0-9]+$
  11816. type: string
  11817. name:
  11818. description: The name of the Secret resource being referred to.
  11819. maxLength: 253
  11820. minLength: 1
  11821. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11822. type: string
  11823. namespace:
  11824. description: |-
  11825. The namespace of the Secret resource being referred to.
  11826. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11827. maxLength: 63
  11828. minLength: 1
  11829. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11830. type: string
  11831. type: object
  11832. required:
  11833. - apiKeyRef
  11834. - passcodeRef
  11835. type: object
  11836. environment:
  11837. default: development
  11838. description: Environment is the name of an environmnent within a project to pull the secrets from
  11839. type: string
  11840. project:
  11841. default: development
  11842. description: Project is an onboardbase project that the secrets should be pulled from
  11843. type: string
  11844. required:
  11845. - apiHost
  11846. - auth
  11847. - environment
  11848. - project
  11849. type: object
  11850. onepassword:
  11851. description: OnePassword configures this store to sync secrets using the 1Password Cloud provider
  11852. properties:
  11853. auth:
  11854. description: Auth defines the information necessary to authenticate against OnePassword Connect Server
  11855. properties:
  11856. secretRef:
  11857. description: OnePasswordAuthSecretRef holds secret references for 1Password credentials.
  11858. properties:
  11859. connectTokenSecretRef:
  11860. description: The ConnectToken is used for authentication to a 1Password Connect Server.
  11861. properties:
  11862. key:
  11863. description: |-
  11864. A key in the referenced Secret.
  11865. Some instances of this field may be defaulted, in others it may be required.
  11866. maxLength: 253
  11867. minLength: 1
  11868. pattern: ^[-._a-zA-Z0-9]+$
  11869. type: string
  11870. name:
  11871. description: The name of the Secret resource being referred to.
  11872. maxLength: 253
  11873. minLength: 1
  11874. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11875. type: string
  11876. namespace:
  11877. description: |-
  11878. The namespace of the Secret resource being referred to.
  11879. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11880. maxLength: 63
  11881. minLength: 1
  11882. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11883. type: string
  11884. type: object
  11885. required:
  11886. - connectTokenSecretRef
  11887. type: object
  11888. required:
  11889. - secretRef
  11890. type: object
  11891. connectHost:
  11892. description: ConnectHost defines the OnePassword Connect Server to connect to
  11893. type: string
  11894. vaults:
  11895. additionalProperties:
  11896. type: integer
  11897. description: Vaults defines which OnePassword vaults to search in which order
  11898. type: object
  11899. required:
  11900. - auth
  11901. - connectHost
  11902. - vaults
  11903. type: object
  11904. oracle:
  11905. description: Oracle configures this store to sync secrets using Oracle Vault provider
  11906. properties:
  11907. auth:
  11908. description: |-
  11909. Auth configures how secret-manager authenticates with the Oracle Vault.
  11910. If empty, use the instance principal, otherwise the user credentials specified in Auth.
  11911. properties:
  11912. secretRef:
  11913. description: SecretRef to pass through sensitive information.
  11914. properties:
  11915. fingerprint:
  11916. description: Fingerprint is the fingerprint of the API private key.
  11917. properties:
  11918. key:
  11919. description: |-
  11920. A key in the referenced Secret.
  11921. Some instances of this field may be defaulted, in others it may be required.
  11922. maxLength: 253
  11923. minLength: 1
  11924. pattern: ^[-._a-zA-Z0-9]+$
  11925. type: string
  11926. name:
  11927. description: The name of the Secret resource being referred to.
  11928. maxLength: 253
  11929. minLength: 1
  11930. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11931. type: string
  11932. namespace:
  11933. description: |-
  11934. The namespace of the Secret resource being referred to.
  11935. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11936. maxLength: 63
  11937. minLength: 1
  11938. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11939. type: string
  11940. type: object
  11941. privatekey:
  11942. description: PrivateKey is the user's API Signing Key in PEM format, used for authentication.
  11943. properties:
  11944. key:
  11945. description: |-
  11946. A key in the referenced Secret.
  11947. Some instances of this field may be defaulted, in others it may be required.
  11948. maxLength: 253
  11949. minLength: 1
  11950. pattern: ^[-._a-zA-Z0-9]+$
  11951. type: string
  11952. name:
  11953. description: The name of the Secret resource being referred to.
  11954. maxLength: 253
  11955. minLength: 1
  11956. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  11957. type: string
  11958. namespace:
  11959. description: |-
  11960. The namespace of the Secret resource being referred to.
  11961. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  11962. maxLength: 63
  11963. minLength: 1
  11964. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  11965. type: string
  11966. type: object
  11967. required:
  11968. - fingerprint
  11969. - privatekey
  11970. type: object
  11971. tenancy:
  11972. description: Tenancy is the tenancy OCID where user is located.
  11973. type: string
  11974. user:
  11975. description: User is an access OCID specific to the account.
  11976. type: string
  11977. required:
  11978. - secretRef
  11979. - tenancy
  11980. - user
  11981. type: object
  11982. compartment:
  11983. description: |-
  11984. Compartment is the vault compartment OCID.
  11985. Required for PushSecret
  11986. type: string
  11987. encryptionKey:
  11988. description: |-
  11989. EncryptionKey is the OCID of the encryption key within the vault.
  11990. Required for PushSecret
  11991. type: string
  11992. principalType:
  11993. description: |-
  11994. The type of principal to use for authentication. If left blank, the Auth struct will
  11995. determine the principal type. This optional field must be specified if using
  11996. workload identity.
  11997. enum:
  11998. - ""
  11999. - UserPrincipal
  12000. - InstancePrincipal
  12001. - Workload
  12002. type: string
  12003. region:
  12004. description: Region is the region where vault is located.
  12005. type: string
  12006. serviceAccountRef:
  12007. description: |-
  12008. ServiceAccountRef specified the service account
  12009. that should be used when authenticating with WorkloadIdentity.
  12010. properties:
  12011. audiences:
  12012. description: |-
  12013. Audience specifies the `aud` claim for the service account token
  12014. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12015. then this audiences will be appended to the list
  12016. items:
  12017. type: string
  12018. type: array
  12019. name:
  12020. description: The name of the ServiceAccount resource being referred to.
  12021. maxLength: 253
  12022. minLength: 1
  12023. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12024. type: string
  12025. namespace:
  12026. description: |-
  12027. Namespace of the resource being referred to.
  12028. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12029. maxLength: 63
  12030. minLength: 1
  12031. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12032. type: string
  12033. required:
  12034. - name
  12035. type: object
  12036. vault:
  12037. description: Vault is the vault's OCID of the specific vault where secret is located.
  12038. type: string
  12039. required:
  12040. - region
  12041. - vault
  12042. type: object
  12043. passbolt:
  12044. properties:
  12045. auth:
  12046. description: Auth defines the information necessary to authenticate against Passbolt Server
  12047. properties:
  12048. passwordSecretRef:
  12049. description: |-
  12050. A reference to a specific 'key' within a Secret resource.
  12051. In some instances, `key` is a required field.
  12052. properties:
  12053. key:
  12054. description: |-
  12055. A key in the referenced Secret.
  12056. Some instances of this field may be defaulted, in others it may be required.
  12057. maxLength: 253
  12058. minLength: 1
  12059. pattern: ^[-._a-zA-Z0-9]+$
  12060. type: string
  12061. name:
  12062. description: The name of the Secret resource being referred to.
  12063. maxLength: 253
  12064. minLength: 1
  12065. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12066. type: string
  12067. namespace:
  12068. description: |-
  12069. The namespace of the Secret resource being referred to.
  12070. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12071. maxLength: 63
  12072. minLength: 1
  12073. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12074. type: string
  12075. type: object
  12076. privateKeySecretRef:
  12077. description: |-
  12078. A reference to a specific 'key' within a Secret resource.
  12079. In some instances, `key` is a required field.
  12080. properties:
  12081. key:
  12082. description: |-
  12083. A key in the referenced Secret.
  12084. Some instances of this field may be defaulted, in others it may be required.
  12085. maxLength: 253
  12086. minLength: 1
  12087. pattern: ^[-._a-zA-Z0-9]+$
  12088. type: string
  12089. name:
  12090. description: The name of the Secret resource being referred to.
  12091. maxLength: 253
  12092. minLength: 1
  12093. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12094. type: string
  12095. namespace:
  12096. description: |-
  12097. The namespace of the Secret resource being referred to.
  12098. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12099. maxLength: 63
  12100. minLength: 1
  12101. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12102. type: string
  12103. type: object
  12104. required:
  12105. - passwordSecretRef
  12106. - privateKeySecretRef
  12107. type: object
  12108. host:
  12109. description: Host defines the Passbolt Server to connect to
  12110. type: string
  12111. required:
  12112. - auth
  12113. - host
  12114. type: object
  12115. passworddepot:
  12116. description: Configures a store to sync secrets with a Password Depot instance.
  12117. properties:
  12118. auth:
  12119. description: Auth configures how secret-manager authenticates with a Password Depot instance.
  12120. properties:
  12121. secretRef:
  12122. properties:
  12123. credentials:
  12124. description: Username / Password is used for authentication.
  12125. properties:
  12126. key:
  12127. description: |-
  12128. A key in the referenced Secret.
  12129. Some instances of this field may be defaulted, in others it may be required.
  12130. maxLength: 253
  12131. minLength: 1
  12132. pattern: ^[-._a-zA-Z0-9]+$
  12133. type: string
  12134. name:
  12135. description: The name of the Secret resource being referred to.
  12136. maxLength: 253
  12137. minLength: 1
  12138. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12139. type: string
  12140. namespace:
  12141. description: |-
  12142. The namespace of the Secret resource being referred to.
  12143. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12144. maxLength: 63
  12145. minLength: 1
  12146. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12147. type: string
  12148. type: object
  12149. type: object
  12150. required:
  12151. - secretRef
  12152. type: object
  12153. database:
  12154. description: Database to use as source
  12155. type: string
  12156. host:
  12157. description: URL configures the Password Depot instance URL.
  12158. type: string
  12159. required:
  12160. - auth
  12161. - database
  12162. - host
  12163. type: object
  12164. previder:
  12165. description: Previder configures this store to sync secrets using the Previder provider
  12166. properties:
  12167. auth:
  12168. description: PreviderAuth contains a secretRef for credentials.
  12169. properties:
  12170. secretRef:
  12171. description: PreviderAuthSecretRef holds secret references for Previder Vault credentials.
  12172. properties:
  12173. accessToken:
  12174. description: The AccessToken is used for authentication
  12175. properties:
  12176. key:
  12177. description: |-
  12178. A key in the referenced Secret.
  12179. Some instances of this field may be defaulted, in others it may be required.
  12180. maxLength: 253
  12181. minLength: 1
  12182. pattern: ^[-._a-zA-Z0-9]+$
  12183. type: string
  12184. name:
  12185. description: The name of the Secret resource being referred to.
  12186. maxLength: 253
  12187. minLength: 1
  12188. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12189. type: string
  12190. namespace:
  12191. description: |-
  12192. The namespace of the Secret resource being referred to.
  12193. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12194. maxLength: 63
  12195. minLength: 1
  12196. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12197. type: string
  12198. type: object
  12199. required:
  12200. - accessToken
  12201. type: object
  12202. type: object
  12203. baseUri:
  12204. type: string
  12205. required:
  12206. - auth
  12207. type: object
  12208. pulumi:
  12209. description: Pulumi configures this store to sync secrets using the Pulumi provider
  12210. properties:
  12211. accessToken:
  12212. description: AccessToken is the access tokens to sign in to the Pulumi Cloud Console.
  12213. properties:
  12214. secretRef:
  12215. description: SecretRef is a reference to a secret containing the Pulumi API token.
  12216. properties:
  12217. key:
  12218. description: |-
  12219. A key in the referenced Secret.
  12220. Some instances of this field may be defaulted, in others it may be required.
  12221. maxLength: 253
  12222. minLength: 1
  12223. pattern: ^[-._a-zA-Z0-9]+$
  12224. type: string
  12225. name:
  12226. description: The name of the Secret resource being referred to.
  12227. maxLength: 253
  12228. minLength: 1
  12229. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12230. type: string
  12231. namespace:
  12232. description: |-
  12233. The namespace of the Secret resource being referred to.
  12234. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12235. maxLength: 63
  12236. minLength: 1
  12237. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12238. type: string
  12239. type: object
  12240. type: object
  12241. apiUrl:
  12242. default: https://api.pulumi.com/api/esc
  12243. description: APIURL is the URL of the Pulumi API.
  12244. type: string
  12245. environment:
  12246. description: |-
  12247. Environment are YAML documents composed of static key-value pairs, programmatic expressions,
  12248. dynamically retrieved values from supported providers including all major clouds,
  12249. and other Pulumi ESC environments.
  12250. To create a new environment, visit https://www.pulumi.com/docs/esc/environments/ for more information.
  12251. type: string
  12252. organization:
  12253. description: |-
  12254. Organization are a space to collaborate on shared projects and stacks.
  12255. To create a new organization, visit https://app.pulumi.com/ and click "New Organization".
  12256. type: string
  12257. project:
  12258. description: Project is the name of the Pulumi ESC project the environment belongs to.
  12259. type: string
  12260. required:
  12261. - accessToken
  12262. - environment
  12263. - organization
  12264. - project
  12265. type: object
  12266. scaleway:
  12267. description: Scaleway
  12268. properties:
  12269. accessKey:
  12270. description: AccessKey is the non-secret part of the api key.
  12271. properties:
  12272. secretRef:
  12273. description: SecretRef references a key in a secret that will be used as value.
  12274. properties:
  12275. key:
  12276. description: |-
  12277. A key in the referenced Secret.
  12278. Some instances of this field may be defaulted, in others it may be required.
  12279. maxLength: 253
  12280. minLength: 1
  12281. pattern: ^[-._a-zA-Z0-9]+$
  12282. type: string
  12283. name:
  12284. description: The name of the Secret resource being referred to.
  12285. maxLength: 253
  12286. minLength: 1
  12287. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12288. type: string
  12289. namespace:
  12290. description: |-
  12291. The namespace of the Secret resource being referred to.
  12292. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12293. maxLength: 63
  12294. minLength: 1
  12295. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12296. type: string
  12297. type: object
  12298. value:
  12299. description: Value can be specified directly to set a value without using a secret.
  12300. type: string
  12301. type: object
  12302. apiUrl:
  12303. description: APIURL is the url of the api to use. Defaults to https://api.scaleway.com
  12304. type: string
  12305. projectId:
  12306. description: 'ProjectID is the id of your project, which you can find in the console: https://console.scaleway.com/project/settings'
  12307. type: string
  12308. region:
  12309. description: 'Region where your secrets are located: https://developers.scaleway.com/en/quickstart/#region-and-zone'
  12310. type: string
  12311. secretKey:
  12312. description: SecretKey is the non-secret part of the api key.
  12313. properties:
  12314. secretRef:
  12315. description: SecretRef references a key in a secret that will be used as value.
  12316. properties:
  12317. key:
  12318. description: |-
  12319. A key in the referenced Secret.
  12320. Some instances of this field may be defaulted, in others it may be required.
  12321. maxLength: 253
  12322. minLength: 1
  12323. pattern: ^[-._a-zA-Z0-9]+$
  12324. type: string
  12325. name:
  12326. description: The name of the Secret resource being referred to.
  12327. maxLength: 253
  12328. minLength: 1
  12329. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12330. type: string
  12331. namespace:
  12332. description: |-
  12333. The namespace of the Secret resource being referred to.
  12334. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12335. maxLength: 63
  12336. minLength: 1
  12337. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12338. type: string
  12339. type: object
  12340. value:
  12341. description: Value can be specified directly to set a value without using a secret.
  12342. type: string
  12343. type: object
  12344. required:
  12345. - accessKey
  12346. - projectId
  12347. - region
  12348. - secretKey
  12349. type: object
  12350. secretserver:
  12351. description: |-
  12352. SecretServer configures this store to sync secrets using SecretServer provider
  12353. https://docs.delinea.com/online-help/secret-server/start.htm
  12354. properties:
  12355. password:
  12356. description: Password is the secret server account password.
  12357. properties:
  12358. secretRef:
  12359. description: SecretRef references a key in a secret that will be used as value.
  12360. properties:
  12361. key:
  12362. description: |-
  12363. A key in the referenced Secret.
  12364. Some instances of this field may be defaulted, in others it may be required.
  12365. maxLength: 253
  12366. minLength: 1
  12367. pattern: ^[-._a-zA-Z0-9]+$
  12368. type: string
  12369. name:
  12370. description: The name of the Secret resource being referred to.
  12371. maxLength: 253
  12372. minLength: 1
  12373. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12374. type: string
  12375. namespace:
  12376. description: |-
  12377. The namespace of the Secret resource being referred to.
  12378. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12379. maxLength: 63
  12380. minLength: 1
  12381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12382. type: string
  12383. type: object
  12384. value:
  12385. description: Value can be specified directly to set a value without using a secret.
  12386. type: string
  12387. type: object
  12388. serverURL:
  12389. description: |-
  12390. ServerURL
  12391. URL to your secret server installation
  12392. type: string
  12393. username:
  12394. description: Username is the secret server account username.
  12395. properties:
  12396. secretRef:
  12397. description: SecretRef references a key in a secret that will be used as value.
  12398. properties:
  12399. key:
  12400. description: |-
  12401. A key in the referenced Secret.
  12402. Some instances of this field may be defaulted, in others it may be required.
  12403. maxLength: 253
  12404. minLength: 1
  12405. pattern: ^[-._a-zA-Z0-9]+$
  12406. type: string
  12407. name:
  12408. description: The name of the Secret resource being referred to.
  12409. maxLength: 253
  12410. minLength: 1
  12411. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12412. type: string
  12413. namespace:
  12414. description: |-
  12415. The namespace of the Secret resource being referred to.
  12416. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12417. maxLength: 63
  12418. minLength: 1
  12419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12420. type: string
  12421. type: object
  12422. value:
  12423. description: Value can be specified directly to set a value without using a secret.
  12424. type: string
  12425. type: object
  12426. required:
  12427. - password
  12428. - serverURL
  12429. - username
  12430. type: object
  12431. senhasegura:
  12432. description: Senhasegura configures this store to sync secrets using senhasegura provider
  12433. properties:
  12434. auth:
  12435. description: Auth defines parameters to authenticate in senhasegura
  12436. properties:
  12437. clientId:
  12438. type: string
  12439. clientSecretSecretRef:
  12440. description: |-
  12441. A reference to a specific 'key' within a Secret resource.
  12442. In some instances, `key` is a required field.
  12443. properties:
  12444. key:
  12445. description: |-
  12446. A key in the referenced Secret.
  12447. Some instances of this field may be defaulted, in others it may be required.
  12448. maxLength: 253
  12449. minLength: 1
  12450. pattern: ^[-._a-zA-Z0-9]+$
  12451. type: string
  12452. name:
  12453. description: The name of the Secret resource being referred to.
  12454. maxLength: 253
  12455. minLength: 1
  12456. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12457. type: string
  12458. namespace:
  12459. description: |-
  12460. The namespace of the Secret resource being referred to.
  12461. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12462. maxLength: 63
  12463. minLength: 1
  12464. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12465. type: string
  12466. type: object
  12467. required:
  12468. - clientId
  12469. - clientSecretSecretRef
  12470. type: object
  12471. ignoreSslCertificate:
  12472. default: false
  12473. description: IgnoreSslCertificate defines if SSL certificate must be ignored
  12474. type: boolean
  12475. module:
  12476. description: Module defines which senhasegura module should be used to get secrets
  12477. type: string
  12478. url:
  12479. description: URL of senhasegura
  12480. type: string
  12481. required:
  12482. - auth
  12483. - module
  12484. - url
  12485. type: object
  12486. vault:
  12487. description: Vault configures this store to sync secrets using Hashi provider
  12488. properties:
  12489. auth:
  12490. description: Auth configures how secret-manager authenticates with the Vault server.
  12491. properties:
  12492. appRole:
  12493. description: |-
  12494. AppRole authenticates with Vault using the App Role auth mechanism,
  12495. with the role and secret stored in a Kubernetes Secret resource.
  12496. properties:
  12497. path:
  12498. default: approle
  12499. description: |-
  12500. Path where the App Role authentication backend is mounted
  12501. in Vault, e.g: "approle"
  12502. type: string
  12503. roleId:
  12504. description: |-
  12505. RoleID configured in the App Role authentication backend when setting
  12506. up the authentication backend in Vault.
  12507. type: string
  12508. roleRef:
  12509. description: |-
  12510. Reference to a key in a Secret that contains the App Role ID used
  12511. to authenticate with Vault.
  12512. The `key` field must be specified and denotes which entry within the Secret
  12513. resource is used as the app role id.
  12514. properties:
  12515. key:
  12516. description: |-
  12517. A key in the referenced Secret.
  12518. Some instances of this field may be defaulted, in others it may be required.
  12519. maxLength: 253
  12520. minLength: 1
  12521. pattern: ^[-._a-zA-Z0-9]+$
  12522. type: string
  12523. name:
  12524. description: The name of the Secret resource being referred to.
  12525. maxLength: 253
  12526. minLength: 1
  12527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12528. type: string
  12529. namespace:
  12530. description: |-
  12531. The namespace of the Secret resource being referred to.
  12532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12533. maxLength: 63
  12534. minLength: 1
  12535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12536. type: string
  12537. type: object
  12538. secretRef:
  12539. description: |-
  12540. Reference to a key in a Secret that contains the App Role secret used
  12541. to authenticate with Vault.
  12542. The `key` field must be specified and denotes which entry within the Secret
  12543. resource is used as the app role secret.
  12544. properties:
  12545. key:
  12546. description: |-
  12547. A key in the referenced Secret.
  12548. Some instances of this field may be defaulted, in others it may be required.
  12549. maxLength: 253
  12550. minLength: 1
  12551. pattern: ^[-._a-zA-Z0-9]+$
  12552. type: string
  12553. name:
  12554. description: The name of the Secret resource being referred to.
  12555. maxLength: 253
  12556. minLength: 1
  12557. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12558. type: string
  12559. namespace:
  12560. description: |-
  12561. The namespace of the Secret resource being referred to.
  12562. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12563. maxLength: 63
  12564. minLength: 1
  12565. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12566. type: string
  12567. type: object
  12568. required:
  12569. - path
  12570. - secretRef
  12571. type: object
  12572. cert:
  12573. description: |-
  12574. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  12575. Cert authentication method
  12576. properties:
  12577. clientCert:
  12578. description: |-
  12579. ClientCert is a certificate to authenticate using the Cert Vault
  12580. authentication method
  12581. properties:
  12582. key:
  12583. description: |-
  12584. A key in the referenced Secret.
  12585. Some instances of this field may be defaulted, in others it may be required.
  12586. maxLength: 253
  12587. minLength: 1
  12588. pattern: ^[-._a-zA-Z0-9]+$
  12589. type: string
  12590. name:
  12591. description: The name of the Secret resource being referred to.
  12592. maxLength: 253
  12593. minLength: 1
  12594. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12595. type: string
  12596. namespace:
  12597. description: |-
  12598. The namespace of the Secret resource being referred to.
  12599. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12600. maxLength: 63
  12601. minLength: 1
  12602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12603. type: string
  12604. type: object
  12605. secretRef:
  12606. description: |-
  12607. SecretRef to a key in a Secret resource containing client private key to
  12608. authenticate with Vault using the Cert authentication method
  12609. properties:
  12610. key:
  12611. description: |-
  12612. A key in the referenced Secret.
  12613. Some instances of this field may be defaulted, in others it may be required.
  12614. maxLength: 253
  12615. minLength: 1
  12616. pattern: ^[-._a-zA-Z0-9]+$
  12617. type: string
  12618. name:
  12619. description: The name of the Secret resource being referred to.
  12620. maxLength: 253
  12621. minLength: 1
  12622. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12623. type: string
  12624. namespace:
  12625. description: |-
  12626. The namespace of the Secret resource being referred to.
  12627. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12628. maxLength: 63
  12629. minLength: 1
  12630. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12631. type: string
  12632. type: object
  12633. type: object
  12634. iam:
  12635. description: |-
  12636. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  12637. AWS IAM authentication method
  12638. properties:
  12639. externalID:
  12640. description: AWS External ID set on assumed IAM roles
  12641. type: string
  12642. jwt:
  12643. description: Specify a service account with IRSA enabled
  12644. properties:
  12645. serviceAccountRef:
  12646. description: A reference to a ServiceAccount resource.
  12647. properties:
  12648. audiences:
  12649. description: |-
  12650. Audience specifies the `aud` claim for the service account token
  12651. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12652. then this audiences will be appended to the list
  12653. items:
  12654. type: string
  12655. type: array
  12656. name:
  12657. description: The name of the ServiceAccount resource being referred to.
  12658. maxLength: 253
  12659. minLength: 1
  12660. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12661. type: string
  12662. namespace:
  12663. description: |-
  12664. Namespace of the resource being referred to.
  12665. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12666. maxLength: 63
  12667. minLength: 1
  12668. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12669. type: string
  12670. required:
  12671. - name
  12672. type: object
  12673. type: object
  12674. path:
  12675. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  12676. type: string
  12677. region:
  12678. description: AWS region
  12679. type: string
  12680. role:
  12681. description: This is the AWS role to be assumed before talking to vault
  12682. type: string
  12683. secretRef:
  12684. description: Specify credentials in a Secret object
  12685. properties:
  12686. accessKeyIDSecretRef:
  12687. description: The AccessKeyID is used for authentication
  12688. properties:
  12689. key:
  12690. description: |-
  12691. A key in the referenced Secret.
  12692. Some instances of this field may be defaulted, in others it may be required.
  12693. maxLength: 253
  12694. minLength: 1
  12695. pattern: ^[-._a-zA-Z0-9]+$
  12696. type: string
  12697. name:
  12698. description: The name of the Secret resource being referred to.
  12699. maxLength: 253
  12700. minLength: 1
  12701. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12702. type: string
  12703. namespace:
  12704. description: |-
  12705. The namespace of the Secret resource being referred to.
  12706. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12707. maxLength: 63
  12708. minLength: 1
  12709. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12710. type: string
  12711. type: object
  12712. secretAccessKeySecretRef:
  12713. description: The SecretAccessKey is used for authentication
  12714. properties:
  12715. key:
  12716. description: |-
  12717. A key in the referenced Secret.
  12718. Some instances of this field may be defaulted, in others it may be required.
  12719. maxLength: 253
  12720. minLength: 1
  12721. pattern: ^[-._a-zA-Z0-9]+$
  12722. type: string
  12723. name:
  12724. description: The name of the Secret resource being referred to.
  12725. maxLength: 253
  12726. minLength: 1
  12727. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12728. type: string
  12729. namespace:
  12730. description: |-
  12731. The namespace of the Secret resource being referred to.
  12732. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12733. maxLength: 63
  12734. minLength: 1
  12735. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12736. type: string
  12737. type: object
  12738. sessionTokenSecretRef:
  12739. description: |-
  12740. The SessionToken used for authentication
  12741. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  12742. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  12743. properties:
  12744. key:
  12745. description: |-
  12746. A key in the referenced Secret.
  12747. Some instances of this field may be defaulted, in others it may be required.
  12748. maxLength: 253
  12749. minLength: 1
  12750. pattern: ^[-._a-zA-Z0-9]+$
  12751. type: string
  12752. name:
  12753. description: The name of the Secret resource being referred to.
  12754. maxLength: 253
  12755. minLength: 1
  12756. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12757. type: string
  12758. namespace:
  12759. description: |-
  12760. The namespace of the Secret resource being referred to.
  12761. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12762. maxLength: 63
  12763. minLength: 1
  12764. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12765. type: string
  12766. type: object
  12767. type: object
  12768. vaultAwsIamServerID:
  12769. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  12770. type: string
  12771. vaultRole:
  12772. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  12773. type: string
  12774. required:
  12775. - vaultRole
  12776. type: object
  12777. jwt:
  12778. description: |-
  12779. Jwt authenticates with Vault by passing role and JWT token using the
  12780. JWT/OIDC authentication method
  12781. properties:
  12782. kubernetesServiceAccountToken:
  12783. description: |-
  12784. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  12785. a token for with the `TokenRequest` API.
  12786. properties:
  12787. audiences:
  12788. description: |-
  12789. Optional audiences field that will be used to request a temporary Kubernetes service
  12790. account token for the service account referenced by `serviceAccountRef`.
  12791. Defaults to a single audience `vault` it not specified.
  12792. Deprecated: use serviceAccountRef.Audiences instead
  12793. items:
  12794. type: string
  12795. type: array
  12796. expirationSeconds:
  12797. description: |-
  12798. Optional expiration time in seconds that will be used to request a temporary
  12799. Kubernetes service account token for the service account referenced by
  12800. `serviceAccountRef`.
  12801. Deprecated: this will be removed in the future.
  12802. Defaults to 10 minutes.
  12803. format: int64
  12804. type: integer
  12805. serviceAccountRef:
  12806. description: Service account field containing the name of a kubernetes ServiceAccount.
  12807. properties:
  12808. audiences:
  12809. description: |-
  12810. Audience specifies the `aud` claim for the service account token
  12811. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12812. then this audiences will be appended to the list
  12813. items:
  12814. type: string
  12815. type: array
  12816. name:
  12817. description: The name of the ServiceAccount resource being referred to.
  12818. maxLength: 253
  12819. minLength: 1
  12820. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12821. type: string
  12822. namespace:
  12823. description: |-
  12824. Namespace of the resource being referred to.
  12825. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12826. maxLength: 63
  12827. minLength: 1
  12828. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12829. type: string
  12830. required:
  12831. - name
  12832. type: object
  12833. required:
  12834. - serviceAccountRef
  12835. type: object
  12836. path:
  12837. default: jwt
  12838. description: |-
  12839. Path where the JWT authentication backend is mounted
  12840. in Vault, e.g: "jwt"
  12841. type: string
  12842. role:
  12843. description: |-
  12844. Role is a JWT role to authenticate using the JWT/OIDC Vault
  12845. authentication method
  12846. type: string
  12847. secretRef:
  12848. description: |-
  12849. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  12850. authenticate with Vault using the JWT/OIDC authentication method.
  12851. properties:
  12852. key:
  12853. description: |-
  12854. A key in the referenced Secret.
  12855. Some instances of this field may be defaulted, in others it may be required.
  12856. maxLength: 253
  12857. minLength: 1
  12858. pattern: ^[-._a-zA-Z0-9]+$
  12859. type: string
  12860. name:
  12861. description: The name of the Secret resource being referred to.
  12862. maxLength: 253
  12863. minLength: 1
  12864. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12865. type: string
  12866. namespace:
  12867. description: |-
  12868. The namespace of the Secret resource being referred to.
  12869. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12870. maxLength: 63
  12871. minLength: 1
  12872. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12873. type: string
  12874. type: object
  12875. required:
  12876. - path
  12877. type: object
  12878. kubernetes:
  12879. description: |-
  12880. Kubernetes authenticates with Vault by passing the ServiceAccount
  12881. token stored in the named Secret resource to the Vault server.
  12882. properties:
  12883. mountPath:
  12884. default: kubernetes
  12885. description: |-
  12886. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  12887. "kubernetes"
  12888. type: string
  12889. role:
  12890. description: |-
  12891. A required field containing the Vault Role to assume. A Role binds a
  12892. Kubernetes ServiceAccount with a set of Vault policies.
  12893. type: string
  12894. secretRef:
  12895. description: |-
  12896. Optional secret field containing a Kubernetes ServiceAccount JWT used
  12897. for authenticating with Vault. If a name is specified without a key,
  12898. `token` is the default. If one is not specified, the one bound to
  12899. the controller will be used.
  12900. properties:
  12901. key:
  12902. description: |-
  12903. A key in the referenced Secret.
  12904. Some instances of this field may be defaulted, in others it may be required.
  12905. maxLength: 253
  12906. minLength: 1
  12907. pattern: ^[-._a-zA-Z0-9]+$
  12908. type: string
  12909. name:
  12910. description: The name of the Secret resource being referred to.
  12911. maxLength: 253
  12912. minLength: 1
  12913. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12914. type: string
  12915. namespace:
  12916. description: |-
  12917. The namespace of the Secret resource being referred to.
  12918. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12919. maxLength: 63
  12920. minLength: 1
  12921. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12922. type: string
  12923. type: object
  12924. serviceAccountRef:
  12925. description: |-
  12926. Optional service account field containing the name of a kubernetes ServiceAccount.
  12927. If the service account is specified, the service account secret token JWT will be used
  12928. for authenticating with Vault. If the service account selector is not supplied,
  12929. the secretRef will be used instead.
  12930. properties:
  12931. audiences:
  12932. description: |-
  12933. Audience specifies the `aud` claim for the service account token
  12934. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  12935. then this audiences will be appended to the list
  12936. items:
  12937. type: string
  12938. type: array
  12939. name:
  12940. description: The name of the ServiceAccount resource being referred to.
  12941. maxLength: 253
  12942. minLength: 1
  12943. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12944. type: string
  12945. namespace:
  12946. description: |-
  12947. Namespace of the resource being referred to.
  12948. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12949. maxLength: 63
  12950. minLength: 1
  12951. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12952. type: string
  12953. required:
  12954. - name
  12955. type: object
  12956. required:
  12957. - mountPath
  12958. - role
  12959. type: object
  12960. ldap:
  12961. description: |-
  12962. Ldap authenticates with Vault by passing username/password pair using
  12963. the LDAP authentication method
  12964. properties:
  12965. path:
  12966. default: ldap
  12967. description: |-
  12968. Path where the LDAP authentication backend is mounted
  12969. in Vault, e.g: "ldap"
  12970. type: string
  12971. secretRef:
  12972. description: |-
  12973. SecretRef to a key in a Secret resource containing password for the LDAP
  12974. user used to authenticate with Vault using the LDAP authentication
  12975. method
  12976. properties:
  12977. key:
  12978. description: |-
  12979. A key in the referenced Secret.
  12980. Some instances of this field may be defaulted, in others it may be required.
  12981. maxLength: 253
  12982. minLength: 1
  12983. pattern: ^[-._a-zA-Z0-9]+$
  12984. type: string
  12985. name:
  12986. description: The name of the Secret resource being referred to.
  12987. maxLength: 253
  12988. minLength: 1
  12989. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  12990. type: string
  12991. namespace:
  12992. description: |-
  12993. The namespace of the Secret resource being referred to.
  12994. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  12995. maxLength: 63
  12996. minLength: 1
  12997. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  12998. type: string
  12999. type: object
  13000. username:
  13001. description: |-
  13002. Username is a LDAP user name used to authenticate using the LDAP Vault
  13003. authentication method
  13004. type: string
  13005. required:
  13006. - path
  13007. - username
  13008. type: object
  13009. namespace:
  13010. description: |-
  13011. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  13012. Namespaces is a set of features within Vault Enterprise that allows
  13013. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13014. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13015. This will default to Vault.Namespace field if set, or empty otherwise
  13016. type: string
  13017. tokenSecretRef:
  13018. description: TokenSecretRef authenticates with Vault by presenting a token.
  13019. properties:
  13020. key:
  13021. description: |-
  13022. A key in the referenced Secret.
  13023. Some instances of this field may be defaulted, in others it may be required.
  13024. maxLength: 253
  13025. minLength: 1
  13026. pattern: ^[-._a-zA-Z0-9]+$
  13027. type: string
  13028. name:
  13029. description: The name of the Secret resource being referred to.
  13030. maxLength: 253
  13031. minLength: 1
  13032. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13033. type: string
  13034. namespace:
  13035. description: |-
  13036. The namespace of the Secret resource being referred to.
  13037. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13038. maxLength: 63
  13039. minLength: 1
  13040. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13041. type: string
  13042. type: object
  13043. userPass:
  13044. description: UserPass authenticates with Vault by passing username/password pair
  13045. properties:
  13046. path:
  13047. default: user
  13048. description: |-
  13049. Path where the UserPassword authentication backend is mounted
  13050. in Vault, e.g: "user"
  13051. type: string
  13052. secretRef:
  13053. description: |-
  13054. SecretRef to a key in a Secret resource containing password for the
  13055. user used to authenticate with Vault using the UserPass authentication
  13056. method
  13057. properties:
  13058. key:
  13059. description: |-
  13060. A key in the referenced Secret.
  13061. Some instances of this field may be defaulted, in others it may be required.
  13062. maxLength: 253
  13063. minLength: 1
  13064. pattern: ^[-._a-zA-Z0-9]+$
  13065. type: string
  13066. name:
  13067. description: The name of the Secret resource being referred to.
  13068. maxLength: 253
  13069. minLength: 1
  13070. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13071. type: string
  13072. namespace:
  13073. description: |-
  13074. The namespace of the Secret resource being referred to.
  13075. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13076. maxLength: 63
  13077. minLength: 1
  13078. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13079. type: string
  13080. type: object
  13081. username:
  13082. description: |-
  13083. Username is a user name used to authenticate using the UserPass Vault
  13084. authentication method
  13085. type: string
  13086. required:
  13087. - path
  13088. - username
  13089. type: object
  13090. type: object
  13091. caBundle:
  13092. description: |-
  13093. PEM encoded CA bundle used to validate Vault server certificate. Only used
  13094. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13095. plain HTTP protocol connection. If not set the system root certificates
  13096. are used to validate the TLS connection.
  13097. format: byte
  13098. type: string
  13099. caProvider:
  13100. description: The provider for the CA bundle to use to validate Vault server certificate.
  13101. properties:
  13102. key:
  13103. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13104. maxLength: 253
  13105. minLength: 1
  13106. pattern: ^[-._a-zA-Z0-9]+$
  13107. type: string
  13108. name:
  13109. description: The name of the object located at the provider type.
  13110. maxLength: 253
  13111. minLength: 1
  13112. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13113. type: string
  13114. namespace:
  13115. description: |-
  13116. The namespace the Provider type is in.
  13117. Can only be defined when used in a ClusterSecretStore.
  13118. maxLength: 63
  13119. minLength: 1
  13120. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13121. type: string
  13122. type:
  13123. description: The type of provider to use such as "Secret", or "ConfigMap".
  13124. enum:
  13125. - Secret
  13126. - ConfigMap
  13127. type: string
  13128. required:
  13129. - name
  13130. - type
  13131. type: object
  13132. forwardInconsistent:
  13133. description: |-
  13134. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  13135. leader instead of simply retrying within a loop. This can increase performance if
  13136. the option is enabled serverside.
  13137. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  13138. type: boolean
  13139. headers:
  13140. additionalProperties:
  13141. type: string
  13142. description: Headers to be added in Vault request
  13143. type: object
  13144. namespace:
  13145. description: |-
  13146. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  13147. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  13148. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  13149. type: string
  13150. path:
  13151. description: |-
  13152. Path is the mount path of the Vault KV backend endpoint, e.g:
  13153. "secret". The v2 KV secret engine version specific "/data" path suffix
  13154. for fetching secrets from Vault is optional and will be appended
  13155. if not present in specified path.
  13156. type: string
  13157. readYourWrites:
  13158. description: |-
  13159. ReadYourWrites ensures isolated read-after-write semantics by
  13160. providing discovered cluster replication states in each request.
  13161. More information about eventual consistency in Vault can be found here
  13162. https://www.vaultproject.io/docs/enterprise/consistency
  13163. type: boolean
  13164. server:
  13165. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  13166. type: string
  13167. tls:
  13168. description: |-
  13169. The configuration used for client side related TLS communication, when the Vault server
  13170. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  13171. This parameter is ignored for plain HTTP protocol connection.
  13172. It's worth noting this configuration is different from the "TLS certificates auth method",
  13173. which is available under the `auth.cert` section.
  13174. properties:
  13175. certSecretRef:
  13176. description: |-
  13177. CertSecretRef is a certificate added to the transport layer
  13178. when communicating with the Vault server.
  13179. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  13180. properties:
  13181. key:
  13182. description: |-
  13183. A key in the referenced Secret.
  13184. Some instances of this field may be defaulted, in others it may be required.
  13185. maxLength: 253
  13186. minLength: 1
  13187. pattern: ^[-._a-zA-Z0-9]+$
  13188. type: string
  13189. name:
  13190. description: The name of the Secret resource being referred to.
  13191. maxLength: 253
  13192. minLength: 1
  13193. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13194. type: string
  13195. namespace:
  13196. description: |-
  13197. The namespace of the Secret resource being referred to.
  13198. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13199. maxLength: 63
  13200. minLength: 1
  13201. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13202. type: string
  13203. type: object
  13204. keySecretRef:
  13205. description: |-
  13206. KeySecretRef to a key in a Secret resource containing client private key
  13207. added to the transport layer when communicating with the Vault server.
  13208. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  13209. properties:
  13210. key:
  13211. description: |-
  13212. A key in the referenced Secret.
  13213. Some instances of this field may be defaulted, in others it may be required.
  13214. maxLength: 253
  13215. minLength: 1
  13216. pattern: ^[-._a-zA-Z0-9]+$
  13217. type: string
  13218. name:
  13219. description: The name of the Secret resource being referred to.
  13220. maxLength: 253
  13221. minLength: 1
  13222. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13223. type: string
  13224. namespace:
  13225. description: |-
  13226. The namespace of the Secret resource being referred to.
  13227. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13228. maxLength: 63
  13229. minLength: 1
  13230. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13231. type: string
  13232. type: object
  13233. type: object
  13234. version:
  13235. default: v2
  13236. description: |-
  13237. Version is the Vault KV secret engine version. This can be either "v1" or
  13238. "v2". Version defaults to "v2".
  13239. enum:
  13240. - v1
  13241. - v2
  13242. type: string
  13243. required:
  13244. - auth
  13245. - server
  13246. type: object
  13247. webhook:
  13248. description: Webhook configures this store to sync secrets using a generic templated webhook
  13249. properties:
  13250. body:
  13251. description: Body
  13252. type: string
  13253. caBundle:
  13254. description: |-
  13255. PEM encoded CA bundle used to validate webhook server certificate. Only used
  13256. if the Server URL is using HTTPS protocol. This parameter is ignored for
  13257. plain HTTP protocol connection. If not set the system root certificates
  13258. are used to validate the TLS connection.
  13259. format: byte
  13260. type: string
  13261. caProvider:
  13262. description: The provider for the CA bundle to use to validate webhook server certificate.
  13263. properties:
  13264. key:
  13265. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  13266. maxLength: 253
  13267. minLength: 1
  13268. pattern: ^[-._a-zA-Z0-9]+$
  13269. type: string
  13270. name:
  13271. description: The name of the object located at the provider type.
  13272. maxLength: 253
  13273. minLength: 1
  13274. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13275. type: string
  13276. namespace:
  13277. description: The namespace the Provider type is in.
  13278. maxLength: 63
  13279. minLength: 1
  13280. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13281. type: string
  13282. type:
  13283. description: The type of provider to use such as "Secret", or "ConfigMap".
  13284. enum:
  13285. - Secret
  13286. - ConfigMap
  13287. type: string
  13288. required:
  13289. - name
  13290. - type
  13291. type: object
  13292. headers:
  13293. additionalProperties:
  13294. type: string
  13295. description: Headers
  13296. type: object
  13297. method:
  13298. description: Webhook Method
  13299. type: string
  13300. result:
  13301. description: Result formatting
  13302. properties:
  13303. jsonPath:
  13304. description: Json path of return value
  13305. type: string
  13306. type: object
  13307. secrets:
  13308. description: |-
  13309. Secrets to fill in templates
  13310. These secrets will be passed to the templating function as key value pairs under the given name
  13311. items:
  13312. properties:
  13313. name:
  13314. description: Name of this secret in templates
  13315. type: string
  13316. secretRef:
  13317. description: Secret ref to fill in credentials
  13318. properties:
  13319. key:
  13320. description: |-
  13321. A key in the referenced Secret.
  13322. Some instances of this field may be defaulted, in others it may be required.
  13323. maxLength: 253
  13324. minLength: 1
  13325. pattern: ^[-._a-zA-Z0-9]+$
  13326. type: string
  13327. name:
  13328. description: The name of the Secret resource being referred to.
  13329. maxLength: 253
  13330. minLength: 1
  13331. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13332. type: string
  13333. namespace:
  13334. description: |-
  13335. The namespace of the Secret resource being referred to.
  13336. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13337. maxLength: 63
  13338. minLength: 1
  13339. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13340. type: string
  13341. type: object
  13342. required:
  13343. - name
  13344. - secretRef
  13345. type: object
  13346. type: array
  13347. timeout:
  13348. description: Timeout
  13349. type: string
  13350. url:
  13351. description: Webhook url to call
  13352. type: string
  13353. required:
  13354. - result
  13355. - url
  13356. type: object
  13357. yandexcertificatemanager:
  13358. description: YandexCertificateManager configures this store to sync secrets using Yandex Certificate Manager provider
  13359. properties:
  13360. apiEndpoint:
  13361. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13362. type: string
  13363. auth:
  13364. description: Auth defines the information necessary to authenticate against Yandex Certificate Manager
  13365. properties:
  13366. authorizedKeySecretRef:
  13367. description: The authorized key used for authentication
  13368. properties:
  13369. key:
  13370. description: |-
  13371. A key in the referenced Secret.
  13372. Some instances of this field may be defaulted, in others it may be required.
  13373. maxLength: 253
  13374. minLength: 1
  13375. pattern: ^[-._a-zA-Z0-9]+$
  13376. type: string
  13377. name:
  13378. description: The name of the Secret resource being referred to.
  13379. maxLength: 253
  13380. minLength: 1
  13381. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13382. type: string
  13383. namespace:
  13384. description: |-
  13385. The namespace of the Secret resource being referred to.
  13386. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13387. maxLength: 63
  13388. minLength: 1
  13389. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13390. type: string
  13391. type: object
  13392. type: object
  13393. caProvider:
  13394. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13395. properties:
  13396. certSecretRef:
  13397. description: |-
  13398. A reference to a specific 'key' within a Secret resource.
  13399. In some instances, `key` is a required field.
  13400. properties:
  13401. key:
  13402. description: |-
  13403. A key in the referenced Secret.
  13404. Some instances of this field may be defaulted, in others it may be required.
  13405. maxLength: 253
  13406. minLength: 1
  13407. pattern: ^[-._a-zA-Z0-9]+$
  13408. type: string
  13409. name:
  13410. description: The name of the Secret resource being referred to.
  13411. maxLength: 253
  13412. minLength: 1
  13413. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13414. type: string
  13415. namespace:
  13416. description: |-
  13417. The namespace of the Secret resource being referred to.
  13418. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13419. maxLength: 63
  13420. minLength: 1
  13421. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13422. type: string
  13423. type: object
  13424. type: object
  13425. required:
  13426. - auth
  13427. type: object
  13428. yandexlockbox:
  13429. description: YandexLockbox configures this store to sync secrets using Yandex Lockbox provider
  13430. properties:
  13431. apiEndpoint:
  13432. description: Yandex.Cloud API endpoint (e.g. 'api.cloud.yandex.net:443')
  13433. type: string
  13434. auth:
  13435. description: Auth defines the information necessary to authenticate against Yandex Lockbox
  13436. properties:
  13437. authorizedKeySecretRef:
  13438. description: The authorized key used for authentication
  13439. properties:
  13440. key:
  13441. description: |-
  13442. A key in the referenced Secret.
  13443. Some instances of this field may be defaulted, in others it may be required.
  13444. maxLength: 253
  13445. minLength: 1
  13446. pattern: ^[-._a-zA-Z0-9]+$
  13447. type: string
  13448. name:
  13449. description: The name of the Secret resource being referred to.
  13450. maxLength: 253
  13451. minLength: 1
  13452. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13453. type: string
  13454. namespace:
  13455. description: |-
  13456. The namespace of the Secret resource being referred to.
  13457. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13458. maxLength: 63
  13459. minLength: 1
  13460. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13461. type: string
  13462. type: object
  13463. type: object
  13464. caProvider:
  13465. description: The provider for the CA bundle to use to validate Yandex.Cloud server certificate.
  13466. properties:
  13467. certSecretRef:
  13468. description: |-
  13469. A reference to a specific 'key' within a Secret resource.
  13470. In some instances, `key` is a required field.
  13471. properties:
  13472. key:
  13473. description: |-
  13474. A key in the referenced Secret.
  13475. Some instances of this field may be defaulted, in others it may be required.
  13476. maxLength: 253
  13477. minLength: 1
  13478. pattern: ^[-._a-zA-Z0-9]+$
  13479. type: string
  13480. name:
  13481. description: The name of the Secret resource being referred to.
  13482. maxLength: 253
  13483. minLength: 1
  13484. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13485. type: string
  13486. namespace:
  13487. description: |-
  13488. The namespace of the Secret resource being referred to.
  13489. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13490. maxLength: 63
  13491. minLength: 1
  13492. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13493. type: string
  13494. type: object
  13495. type: object
  13496. required:
  13497. - auth
  13498. type: object
  13499. type: object
  13500. refreshInterval:
  13501. description: Used to configure store refresh interval in seconds. Empty or 0 will default to the controller config.
  13502. type: integer
  13503. retrySettings:
  13504. description: Used to configure http retries if failed
  13505. properties:
  13506. maxRetries:
  13507. format: int32
  13508. type: integer
  13509. retryInterval:
  13510. type: string
  13511. type: object
  13512. required:
  13513. - provider
  13514. type: object
  13515. status:
  13516. description: SecretStoreStatus defines the observed state of the SecretStore.
  13517. properties:
  13518. capabilities:
  13519. description: SecretStoreCapabilities defines the possible operations a SecretStore can do.
  13520. type: string
  13521. conditions:
  13522. items:
  13523. properties:
  13524. lastTransitionTime:
  13525. format: date-time
  13526. type: string
  13527. message:
  13528. type: string
  13529. reason:
  13530. type: string
  13531. status:
  13532. type: string
  13533. type:
  13534. type: string
  13535. required:
  13536. - status
  13537. - type
  13538. type: object
  13539. type: array
  13540. type: object
  13541. type: object
  13542. served: true
  13543. storage: true
  13544. subresources:
  13545. status: {}
  13546. conversion:
  13547. strategy: Webhook
  13548. webhook:
  13549. conversionReviewVersions:
  13550. - v1
  13551. clientConfig:
  13552. service:
  13553. name: kubernetes
  13554. namespace: default
  13555. path: /convert
  13556. ---
  13557. apiVersion: apiextensions.k8s.io/v1
  13558. kind: CustomResourceDefinition
  13559. metadata:
  13560. annotations:
  13561. controller-gen.kubebuilder.io/version: v0.16.5
  13562. labels:
  13563. external-secrets.io/component: controller
  13564. name: acraccesstokens.generators.external-secrets.io
  13565. spec:
  13566. group: generators.external-secrets.io
  13567. names:
  13568. categories:
  13569. - external-secrets
  13570. - external-secrets-generators
  13571. kind: ACRAccessToken
  13572. listKind: ACRAccessTokenList
  13573. plural: acraccesstokens
  13574. shortNames:
  13575. - acraccesstoken
  13576. singular: acraccesstoken
  13577. scope: Namespaced
  13578. versions:
  13579. - name: v1alpha1
  13580. schema:
  13581. openAPIV3Schema:
  13582. description: |-
  13583. ACRAccessToken returns a Azure Container Registry token
  13584. that can be used for pushing/pulling images.
  13585. Note: by default it will return an ACR Refresh Token with full access
  13586. (depending on the identity).
  13587. This can be scoped down to the repository level using .spec.scope.
  13588. In case scope is defined it will return an ACR Access Token.
  13589. See docs: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md
  13590. properties:
  13591. apiVersion:
  13592. description: |-
  13593. APIVersion defines the versioned schema of this representation of an object.
  13594. Servers should convert recognized schemas to the latest internal value, and
  13595. may reject unrecognized values.
  13596. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13597. type: string
  13598. kind:
  13599. description: |-
  13600. Kind is a string value representing the REST resource this object represents.
  13601. Servers may infer this from the endpoint the client submits requests to.
  13602. Cannot be updated.
  13603. In CamelCase.
  13604. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13605. type: string
  13606. metadata:
  13607. type: object
  13608. spec:
  13609. description: |-
  13610. ACRAccessTokenSpec defines how to generate the access token
  13611. e.g. how to authenticate and which registry to use.
  13612. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  13613. properties:
  13614. auth:
  13615. properties:
  13616. managedIdentity:
  13617. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  13618. properties:
  13619. identityId:
  13620. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  13621. type: string
  13622. type: object
  13623. servicePrincipal:
  13624. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  13625. properties:
  13626. secretRef:
  13627. description: |-
  13628. Configuration used to authenticate with Azure using static
  13629. credentials stored in a Kind=Secret.
  13630. properties:
  13631. clientId:
  13632. description: The Azure clientId of the service principle used for authentication.
  13633. properties:
  13634. key:
  13635. description: |-
  13636. A key in the referenced Secret.
  13637. Some instances of this field may be defaulted, in others it may be required.
  13638. maxLength: 253
  13639. minLength: 1
  13640. pattern: ^[-._a-zA-Z0-9]+$
  13641. type: string
  13642. name:
  13643. description: The name of the Secret resource being referred to.
  13644. maxLength: 253
  13645. minLength: 1
  13646. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13647. type: string
  13648. namespace:
  13649. description: |-
  13650. The namespace of the Secret resource being referred to.
  13651. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13652. maxLength: 63
  13653. minLength: 1
  13654. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13655. type: string
  13656. type: object
  13657. clientSecret:
  13658. description: The Azure ClientSecret of the service principle used for authentication.
  13659. properties:
  13660. key:
  13661. description: |-
  13662. A key in the referenced Secret.
  13663. Some instances of this field may be defaulted, in others it may be required.
  13664. maxLength: 253
  13665. minLength: 1
  13666. pattern: ^[-._a-zA-Z0-9]+$
  13667. type: string
  13668. name:
  13669. description: The name of the Secret resource being referred to.
  13670. maxLength: 253
  13671. minLength: 1
  13672. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13673. type: string
  13674. namespace:
  13675. description: |-
  13676. The namespace of the Secret resource being referred to.
  13677. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13678. maxLength: 63
  13679. minLength: 1
  13680. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13681. type: string
  13682. type: object
  13683. type: object
  13684. required:
  13685. - secretRef
  13686. type: object
  13687. workloadIdentity:
  13688. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  13689. properties:
  13690. serviceAccountRef:
  13691. description: |-
  13692. ServiceAccountRef specified the service account
  13693. that should be used when authenticating with WorkloadIdentity.
  13694. properties:
  13695. audiences:
  13696. description: |-
  13697. Audience specifies the `aud` claim for the service account token
  13698. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  13699. then this audiences will be appended to the list
  13700. items:
  13701. type: string
  13702. type: array
  13703. name:
  13704. description: The name of the ServiceAccount resource being referred to.
  13705. maxLength: 253
  13706. minLength: 1
  13707. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13708. type: string
  13709. namespace:
  13710. description: |-
  13711. Namespace of the resource being referred to.
  13712. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13713. maxLength: 63
  13714. minLength: 1
  13715. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13716. type: string
  13717. required:
  13718. - name
  13719. type: object
  13720. type: object
  13721. type: object
  13722. environmentType:
  13723. default: PublicCloud
  13724. description: |-
  13725. EnvironmentType specifies the Azure cloud environment endpoints to use for
  13726. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  13727. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  13728. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  13729. enum:
  13730. - PublicCloud
  13731. - USGovernmentCloud
  13732. - ChinaCloud
  13733. - GermanCloud
  13734. type: string
  13735. registry:
  13736. description: |-
  13737. the domain name of the ACR registry
  13738. e.g. foobarexample.azurecr.io
  13739. type: string
  13740. scope:
  13741. description: |-
  13742. Define the scope for the access token, e.g. pull/push access for a repository.
  13743. if not provided it will return a refresh token that has full scope.
  13744. Note: you need to pin it down to the repository level, there is no wildcard available.
  13745. examples:
  13746. repository:my-repository:pull,push
  13747. repository:my-repository:pull
  13748. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  13749. type: string
  13750. tenantId:
  13751. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  13752. type: string
  13753. required:
  13754. - auth
  13755. - registry
  13756. type: object
  13757. type: object
  13758. served: true
  13759. storage: true
  13760. subresources:
  13761. status: {}
  13762. conversion:
  13763. strategy: Webhook
  13764. webhook:
  13765. conversionReviewVersions:
  13766. - v1
  13767. clientConfig:
  13768. service:
  13769. name: kubernetes
  13770. namespace: default
  13771. path: /convert
  13772. ---
  13773. apiVersion: apiextensions.k8s.io/v1
  13774. kind: CustomResourceDefinition
  13775. metadata:
  13776. annotations:
  13777. controller-gen.kubebuilder.io/version: v0.16.5
  13778. labels:
  13779. external-secrets.io/component: controller
  13780. name: clustergenerators.generators.external-secrets.io
  13781. spec:
  13782. group: generators.external-secrets.io
  13783. names:
  13784. categories:
  13785. - external-secrets
  13786. - external-secrets-generators
  13787. kind: ClusterGenerator
  13788. listKind: ClusterGeneratorList
  13789. plural: clustergenerators
  13790. shortNames:
  13791. - cg
  13792. singular: clustergenerator
  13793. scope: Cluster
  13794. versions:
  13795. - name: v1alpha1
  13796. schema:
  13797. openAPIV3Schema:
  13798. description: ClusterGenerator represents a cluster-wide generator which can be referenced as part of `generatorRef` fields.
  13799. properties:
  13800. apiVersion:
  13801. description: |-
  13802. APIVersion defines the versioned schema of this representation of an object.
  13803. Servers should convert recognized schemas to the latest internal value, and
  13804. may reject unrecognized values.
  13805. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  13806. type: string
  13807. kind:
  13808. description: |-
  13809. Kind is a string value representing the REST resource this object represents.
  13810. Servers may infer this from the endpoint the client submits requests to.
  13811. Cannot be updated.
  13812. In CamelCase.
  13813. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  13814. type: string
  13815. metadata:
  13816. type: object
  13817. spec:
  13818. properties:
  13819. generator:
  13820. properties:
  13821. acrAccessTokenSpec:
  13822. description: |-
  13823. ACRAccessTokenSpec defines how to generate the access token
  13824. e.g. how to authenticate and which registry to use.
  13825. see: https://github.com/Azure/acr/blob/main/docs/AAD-OAuth.md#overview
  13826. properties:
  13827. auth:
  13828. properties:
  13829. managedIdentity:
  13830. description: ManagedIdentity uses Azure Managed Identity to authenticate with Azure.
  13831. properties:
  13832. identityId:
  13833. description: If multiple Managed Identity is assigned to the pod, you can select the one to be used
  13834. type: string
  13835. type: object
  13836. servicePrincipal:
  13837. description: ServicePrincipal uses Azure Service Principal credentials to authenticate with Azure.
  13838. properties:
  13839. secretRef:
  13840. description: |-
  13841. Configuration used to authenticate with Azure using static
  13842. credentials stored in a Kind=Secret.
  13843. properties:
  13844. clientId:
  13845. description: The Azure clientId of the service principle used for authentication.
  13846. properties:
  13847. key:
  13848. description: |-
  13849. A key in the referenced Secret.
  13850. Some instances of this field may be defaulted, in others it may be required.
  13851. maxLength: 253
  13852. minLength: 1
  13853. pattern: ^[-._a-zA-Z0-9]+$
  13854. type: string
  13855. name:
  13856. description: The name of the Secret resource being referred to.
  13857. maxLength: 253
  13858. minLength: 1
  13859. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13860. type: string
  13861. namespace:
  13862. description: |-
  13863. The namespace of the Secret resource being referred to.
  13864. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13865. maxLength: 63
  13866. minLength: 1
  13867. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13868. type: string
  13869. type: object
  13870. clientSecret:
  13871. description: The Azure ClientSecret of the service principle used for authentication.
  13872. properties:
  13873. key:
  13874. description: |-
  13875. A key in the referenced Secret.
  13876. Some instances of this field may be defaulted, in others it may be required.
  13877. maxLength: 253
  13878. minLength: 1
  13879. pattern: ^[-._a-zA-Z0-9]+$
  13880. type: string
  13881. name:
  13882. description: The name of the Secret resource being referred to.
  13883. maxLength: 253
  13884. minLength: 1
  13885. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13886. type: string
  13887. namespace:
  13888. description: |-
  13889. The namespace of the Secret resource being referred to.
  13890. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13891. maxLength: 63
  13892. minLength: 1
  13893. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13894. type: string
  13895. type: object
  13896. type: object
  13897. required:
  13898. - secretRef
  13899. type: object
  13900. workloadIdentity:
  13901. description: WorkloadIdentity uses Azure Workload Identity to authenticate with Azure.
  13902. properties:
  13903. serviceAccountRef:
  13904. description: |-
  13905. ServiceAccountRef specified the service account
  13906. that should be used when authenticating with WorkloadIdentity.
  13907. properties:
  13908. audiences:
  13909. description: |-
  13910. Audience specifies the `aud` claim for the service account token
  13911. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  13912. then this audiences will be appended to the list
  13913. items:
  13914. type: string
  13915. type: array
  13916. name:
  13917. description: The name of the ServiceAccount resource being referred to.
  13918. maxLength: 253
  13919. minLength: 1
  13920. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13921. type: string
  13922. namespace:
  13923. description: |-
  13924. Namespace of the resource being referred to.
  13925. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13926. maxLength: 63
  13927. minLength: 1
  13928. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  13929. type: string
  13930. required:
  13931. - name
  13932. type: object
  13933. type: object
  13934. type: object
  13935. environmentType:
  13936. default: PublicCloud
  13937. description: |-
  13938. EnvironmentType specifies the Azure cloud environment endpoints to use for
  13939. connecting and authenticating with Azure. By default it points to the public cloud AAD endpoint.
  13940. The following endpoints are available, also see here: https://github.com/Azure/go-autorest/blob/main/autorest/azure/environments.go#L152
  13941. PublicCloud, USGovernmentCloud, ChinaCloud, GermanCloud
  13942. enum:
  13943. - PublicCloud
  13944. - USGovernmentCloud
  13945. - ChinaCloud
  13946. - GermanCloud
  13947. type: string
  13948. registry:
  13949. description: |-
  13950. the domain name of the ACR registry
  13951. e.g. foobarexample.azurecr.io
  13952. type: string
  13953. scope:
  13954. description: |-
  13955. Define the scope for the access token, e.g. pull/push access for a repository.
  13956. if not provided it will return a refresh token that has full scope.
  13957. Note: you need to pin it down to the repository level, there is no wildcard available.
  13958. examples:
  13959. repository:my-repository:pull,push
  13960. repository:my-repository:pull
  13961. see docs for details: https://docs.docker.com/registry/spec/auth/scope/
  13962. type: string
  13963. tenantId:
  13964. description: TenantID configures the Azure Tenant to send requests to. Required for ServicePrincipal auth type.
  13965. type: string
  13966. required:
  13967. - auth
  13968. - registry
  13969. type: object
  13970. ecrRAuthorizationTokenSpec:
  13971. properties:
  13972. auth:
  13973. description: Auth defines how to authenticate with AWS
  13974. properties:
  13975. jwt:
  13976. description: Authenticate against AWS using service account tokens.
  13977. properties:
  13978. serviceAccountRef:
  13979. description: A reference to a ServiceAccount resource.
  13980. properties:
  13981. audiences:
  13982. description: |-
  13983. Audience specifies the `aud` claim for the service account token
  13984. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  13985. then this audiences will be appended to the list
  13986. items:
  13987. type: string
  13988. type: array
  13989. name:
  13990. description: The name of the ServiceAccount resource being referred to.
  13991. maxLength: 253
  13992. minLength: 1
  13993. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  13994. type: string
  13995. namespace:
  13996. description: |-
  13997. Namespace of the resource being referred to.
  13998. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  13999. maxLength: 63
  14000. minLength: 1
  14001. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14002. type: string
  14003. required:
  14004. - name
  14005. type: object
  14006. type: object
  14007. secretRef:
  14008. description: |-
  14009. AWSAuthSecretRef holds secret references for AWS credentials
  14010. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  14011. properties:
  14012. accessKeyIDSecretRef:
  14013. description: The AccessKeyID is used for authentication
  14014. properties:
  14015. key:
  14016. description: |-
  14017. A key in the referenced Secret.
  14018. Some instances of this field may be defaulted, in others it may be required.
  14019. maxLength: 253
  14020. minLength: 1
  14021. pattern: ^[-._a-zA-Z0-9]+$
  14022. type: string
  14023. name:
  14024. description: The name of the Secret resource being referred to.
  14025. maxLength: 253
  14026. minLength: 1
  14027. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14028. type: string
  14029. namespace:
  14030. description: |-
  14031. The namespace of the Secret resource being referred to.
  14032. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14033. maxLength: 63
  14034. minLength: 1
  14035. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14036. type: string
  14037. type: object
  14038. secretAccessKeySecretRef:
  14039. description: The SecretAccessKey is used for authentication
  14040. properties:
  14041. key:
  14042. description: |-
  14043. A key in the referenced Secret.
  14044. Some instances of this field may be defaulted, in others it may be required.
  14045. maxLength: 253
  14046. minLength: 1
  14047. pattern: ^[-._a-zA-Z0-9]+$
  14048. type: string
  14049. name:
  14050. description: The name of the Secret resource being referred to.
  14051. maxLength: 253
  14052. minLength: 1
  14053. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14054. type: string
  14055. namespace:
  14056. description: |-
  14057. The namespace of the Secret resource being referred to.
  14058. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14059. maxLength: 63
  14060. minLength: 1
  14061. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14062. type: string
  14063. type: object
  14064. sessionTokenSecretRef:
  14065. description: |-
  14066. The SessionToken used for authentication
  14067. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  14068. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  14069. properties:
  14070. key:
  14071. description: |-
  14072. A key in the referenced Secret.
  14073. Some instances of this field may be defaulted, in others it may be required.
  14074. maxLength: 253
  14075. minLength: 1
  14076. pattern: ^[-._a-zA-Z0-9]+$
  14077. type: string
  14078. name:
  14079. description: The name of the Secret resource being referred to.
  14080. maxLength: 253
  14081. minLength: 1
  14082. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14083. type: string
  14084. namespace:
  14085. description: |-
  14086. The namespace of the Secret resource being referred to.
  14087. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14088. maxLength: 63
  14089. minLength: 1
  14090. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14091. type: string
  14092. type: object
  14093. type: object
  14094. type: object
  14095. region:
  14096. description: Region specifies the region to operate in.
  14097. type: string
  14098. role:
  14099. description: |-
  14100. You can assume a role before making calls to the
  14101. desired AWS service.
  14102. type: string
  14103. required:
  14104. - region
  14105. type: object
  14106. fakeSpec:
  14107. description: FakeSpec contains the static data.
  14108. properties:
  14109. controller:
  14110. description: |-
  14111. Used to select the correct ESO controller (think: ingress.ingressClassName)
  14112. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  14113. type: string
  14114. data:
  14115. additionalProperties:
  14116. type: string
  14117. description: |-
  14118. Data defines the static data returned
  14119. by this generator.
  14120. type: object
  14121. type: object
  14122. gcrAccessTokenSpec:
  14123. properties:
  14124. auth:
  14125. description: Auth defines the means for authenticating with GCP
  14126. properties:
  14127. secretRef:
  14128. properties:
  14129. secretAccessKeySecretRef:
  14130. description: The SecretAccessKey is used for authentication
  14131. properties:
  14132. key:
  14133. description: |-
  14134. A key in the referenced Secret.
  14135. Some instances of this field may be defaulted, in others it may be required.
  14136. maxLength: 253
  14137. minLength: 1
  14138. pattern: ^[-._a-zA-Z0-9]+$
  14139. type: string
  14140. name:
  14141. description: The name of the Secret resource being referred to.
  14142. maxLength: 253
  14143. minLength: 1
  14144. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14145. type: string
  14146. namespace:
  14147. description: |-
  14148. The namespace of the Secret resource being referred to.
  14149. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14150. maxLength: 63
  14151. minLength: 1
  14152. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14153. type: string
  14154. type: object
  14155. type: object
  14156. workloadIdentity:
  14157. properties:
  14158. clusterLocation:
  14159. type: string
  14160. clusterName:
  14161. type: string
  14162. clusterProjectID:
  14163. type: string
  14164. serviceAccountRef:
  14165. description: A reference to a ServiceAccount resource.
  14166. properties:
  14167. audiences:
  14168. description: |-
  14169. Audience specifies the `aud` claim for the service account token
  14170. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  14171. then this audiences will be appended to the list
  14172. items:
  14173. type: string
  14174. type: array
  14175. name:
  14176. description: The name of the ServiceAccount resource being referred to.
  14177. maxLength: 253
  14178. minLength: 1
  14179. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14180. type: string
  14181. namespace:
  14182. description: |-
  14183. Namespace of the resource being referred to.
  14184. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14185. maxLength: 63
  14186. minLength: 1
  14187. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14188. type: string
  14189. required:
  14190. - name
  14191. type: object
  14192. required:
  14193. - clusterLocation
  14194. - clusterName
  14195. - serviceAccountRef
  14196. type: object
  14197. type: object
  14198. projectID:
  14199. description: ProjectID defines which project to use to authenticate with
  14200. type: string
  14201. required:
  14202. - auth
  14203. - projectID
  14204. type: object
  14205. githubAccessTokenSpec:
  14206. properties:
  14207. appID:
  14208. type: string
  14209. auth:
  14210. description: Auth configures how ESO authenticates with a Github instance.
  14211. properties:
  14212. privateKey:
  14213. properties:
  14214. secretRef:
  14215. description: |-
  14216. A reference to a specific 'key' within a Secret resource.
  14217. In some instances, `key` is a required field.
  14218. properties:
  14219. key:
  14220. description: |-
  14221. A key in the referenced Secret.
  14222. Some instances of this field may be defaulted, in others it may be required.
  14223. maxLength: 253
  14224. minLength: 1
  14225. pattern: ^[-._a-zA-Z0-9]+$
  14226. type: string
  14227. name:
  14228. description: The name of the Secret resource being referred to.
  14229. maxLength: 253
  14230. minLength: 1
  14231. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14232. type: string
  14233. namespace:
  14234. description: |-
  14235. The namespace of the Secret resource being referred to.
  14236. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14237. maxLength: 63
  14238. minLength: 1
  14239. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14240. type: string
  14241. type: object
  14242. required:
  14243. - secretRef
  14244. type: object
  14245. required:
  14246. - privateKey
  14247. type: object
  14248. installID:
  14249. type: string
  14250. permissions:
  14251. additionalProperties:
  14252. type: string
  14253. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  14254. type: object
  14255. repositories:
  14256. description: |-
  14257. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  14258. is installed to.
  14259. items:
  14260. type: string
  14261. type: array
  14262. url:
  14263. description: URL configures the Github instance URL. Defaults to https://github.com/.
  14264. type: string
  14265. required:
  14266. - appID
  14267. - auth
  14268. - installID
  14269. type: object
  14270. passwordSpec:
  14271. description: PasswordSpec controls the behavior of the password generator.
  14272. properties:
  14273. allowRepeat:
  14274. default: false
  14275. description: set AllowRepeat to true to allow repeating characters.
  14276. type: boolean
  14277. digits:
  14278. description: |-
  14279. Digits specifies the number of digits in the generated
  14280. password. If omitted it defaults to 25% of the length of the password
  14281. type: integer
  14282. length:
  14283. default: 24
  14284. description: |-
  14285. Length of the password to be generated.
  14286. Defaults to 24
  14287. type: integer
  14288. noUpper:
  14289. default: false
  14290. description: Set NoUpper to disable uppercase characters
  14291. type: boolean
  14292. symbolCharacters:
  14293. description: |-
  14294. SymbolCharacters specifies the special characters that should be used
  14295. in the generated password.
  14296. type: string
  14297. symbols:
  14298. description: |-
  14299. Symbols specifies the number of symbol characters in the generated
  14300. password. If omitted it defaults to 25% of the length of the password
  14301. type: integer
  14302. required:
  14303. - allowRepeat
  14304. - length
  14305. - noUpper
  14306. type: object
  14307. stsSessionTokenSpec:
  14308. properties:
  14309. auth:
  14310. description: Auth defines how to authenticate with AWS
  14311. properties:
  14312. jwt:
  14313. description: Authenticate against AWS using service account tokens.
  14314. properties:
  14315. serviceAccountRef:
  14316. description: A reference to a ServiceAccount resource.
  14317. properties:
  14318. audiences:
  14319. description: |-
  14320. Audience specifies the `aud` claim for the service account token
  14321. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  14322. then this audiences will be appended to the list
  14323. items:
  14324. type: string
  14325. type: array
  14326. name:
  14327. description: The name of the ServiceAccount resource being referred to.
  14328. maxLength: 253
  14329. minLength: 1
  14330. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14331. type: string
  14332. namespace:
  14333. description: |-
  14334. Namespace of the resource being referred to.
  14335. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14336. maxLength: 63
  14337. minLength: 1
  14338. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14339. type: string
  14340. required:
  14341. - name
  14342. type: object
  14343. type: object
  14344. secretRef:
  14345. description: |-
  14346. AWSAuthSecretRef holds secret references for AWS credentials
  14347. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  14348. properties:
  14349. accessKeyIDSecretRef:
  14350. description: The AccessKeyID is used for authentication
  14351. properties:
  14352. key:
  14353. description: |-
  14354. A key in the referenced Secret.
  14355. Some instances of this field may be defaulted, in others it may be required.
  14356. maxLength: 253
  14357. minLength: 1
  14358. pattern: ^[-._a-zA-Z0-9]+$
  14359. type: string
  14360. name:
  14361. description: The name of the Secret resource being referred to.
  14362. maxLength: 253
  14363. minLength: 1
  14364. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14365. type: string
  14366. namespace:
  14367. description: |-
  14368. The namespace of the Secret resource being referred to.
  14369. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14370. maxLength: 63
  14371. minLength: 1
  14372. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14373. type: string
  14374. type: object
  14375. secretAccessKeySecretRef:
  14376. description: The SecretAccessKey is used for authentication
  14377. properties:
  14378. key:
  14379. description: |-
  14380. A key in the referenced Secret.
  14381. Some instances of this field may be defaulted, in others it may be required.
  14382. maxLength: 253
  14383. minLength: 1
  14384. pattern: ^[-._a-zA-Z0-9]+$
  14385. type: string
  14386. name:
  14387. description: The name of the Secret resource being referred to.
  14388. maxLength: 253
  14389. minLength: 1
  14390. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14391. type: string
  14392. namespace:
  14393. description: |-
  14394. The namespace of the Secret resource being referred to.
  14395. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14396. maxLength: 63
  14397. minLength: 1
  14398. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14399. type: string
  14400. type: object
  14401. sessionTokenSecretRef:
  14402. description: |-
  14403. The SessionToken used for authentication
  14404. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  14405. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  14406. properties:
  14407. key:
  14408. description: |-
  14409. A key in the referenced Secret.
  14410. Some instances of this field may be defaulted, in others it may be required.
  14411. maxLength: 253
  14412. minLength: 1
  14413. pattern: ^[-._a-zA-Z0-9]+$
  14414. type: string
  14415. name:
  14416. description: The name of the Secret resource being referred to.
  14417. maxLength: 253
  14418. minLength: 1
  14419. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14420. type: string
  14421. namespace:
  14422. description: |-
  14423. The namespace of the Secret resource being referred to.
  14424. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14425. maxLength: 63
  14426. minLength: 1
  14427. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14428. type: string
  14429. type: object
  14430. type: object
  14431. type: object
  14432. region:
  14433. description: Region specifies the region to operate in.
  14434. type: string
  14435. requestParameters:
  14436. description: RequestParameters contains parameters that can be passed to the STS service.
  14437. properties:
  14438. serialNumber:
  14439. description: |-
  14440. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  14441. the GetSessionToken call.
  14442. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  14443. (such as arn:aws:iam::123456789012:mfa/user)
  14444. type: string
  14445. sessionDuration:
  14446. description: |-
  14447. SessionDuration The duration, in seconds, that the credentials should remain valid. Acceptable durations for
  14448. IAM user sessions range from 900 seconds (15 minutes) to 129,600 seconds (36 hours), with 43,200 seconds
  14449. (12 hours) as the default.
  14450. format: int64
  14451. type: integer
  14452. tokenCode:
  14453. description: TokenCode is the value provided by the MFA device, if MFA is required.
  14454. type: string
  14455. type: object
  14456. role:
  14457. description: |-
  14458. You can assume a role before making calls to the
  14459. desired AWS service.
  14460. type: string
  14461. required:
  14462. - region
  14463. type: object
  14464. uuidSpec:
  14465. description: UUIDSpec controls the behavior of the uuid generator.
  14466. type: object
  14467. vaultDynamicSecretSpec:
  14468. properties:
  14469. controller:
  14470. description: |-
  14471. Used to select the correct ESO controller (think: ingress.ingressClassName)
  14472. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  14473. type: string
  14474. method:
  14475. description: Vault API method to use (GET/POST/other)
  14476. type: string
  14477. parameters:
  14478. description: Parameters to pass to Vault write (for non-GET methods)
  14479. x-kubernetes-preserve-unknown-fields: true
  14480. path:
  14481. description: Vault path to obtain the dynamic secret from
  14482. type: string
  14483. provider:
  14484. description: Vault provider common spec
  14485. properties:
  14486. auth:
  14487. description: Auth configures how secret-manager authenticates with the Vault server.
  14488. properties:
  14489. appRole:
  14490. description: |-
  14491. AppRole authenticates with Vault using the App Role auth mechanism,
  14492. with the role and secret stored in a Kubernetes Secret resource.
  14493. properties:
  14494. path:
  14495. default: approle
  14496. description: |-
  14497. Path where the App Role authentication backend is mounted
  14498. in Vault, e.g: "approle"
  14499. type: string
  14500. roleId:
  14501. description: |-
  14502. RoleID configured in the App Role authentication backend when setting
  14503. up the authentication backend in Vault.
  14504. type: string
  14505. roleRef:
  14506. description: |-
  14507. Reference to a key in a Secret that contains the App Role ID used
  14508. to authenticate with Vault.
  14509. The `key` field must be specified and denotes which entry within the Secret
  14510. resource is used as the app role id.
  14511. properties:
  14512. key:
  14513. description: |-
  14514. A key in the referenced Secret.
  14515. Some instances of this field may be defaulted, in others it may be required.
  14516. maxLength: 253
  14517. minLength: 1
  14518. pattern: ^[-._a-zA-Z0-9]+$
  14519. type: string
  14520. name:
  14521. description: The name of the Secret resource being referred to.
  14522. maxLength: 253
  14523. minLength: 1
  14524. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14525. type: string
  14526. namespace:
  14527. description: |-
  14528. The namespace of the Secret resource being referred to.
  14529. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14530. maxLength: 63
  14531. minLength: 1
  14532. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14533. type: string
  14534. type: object
  14535. secretRef:
  14536. description: |-
  14537. Reference to a key in a Secret that contains the App Role secret used
  14538. to authenticate with Vault.
  14539. The `key` field must be specified and denotes which entry within the Secret
  14540. resource is used as the app role secret.
  14541. properties:
  14542. key:
  14543. description: |-
  14544. A key in the referenced Secret.
  14545. Some instances of this field may be defaulted, in others it may be required.
  14546. maxLength: 253
  14547. minLength: 1
  14548. pattern: ^[-._a-zA-Z0-9]+$
  14549. type: string
  14550. name:
  14551. description: The name of the Secret resource being referred to.
  14552. maxLength: 253
  14553. minLength: 1
  14554. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14555. type: string
  14556. namespace:
  14557. description: |-
  14558. The namespace of the Secret resource being referred to.
  14559. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14560. maxLength: 63
  14561. minLength: 1
  14562. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14563. type: string
  14564. type: object
  14565. required:
  14566. - path
  14567. - secretRef
  14568. type: object
  14569. cert:
  14570. description: |-
  14571. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  14572. Cert authentication method
  14573. properties:
  14574. clientCert:
  14575. description: |-
  14576. ClientCert is a certificate to authenticate using the Cert Vault
  14577. authentication method
  14578. properties:
  14579. key:
  14580. description: |-
  14581. A key in the referenced Secret.
  14582. Some instances of this field may be defaulted, in others it may be required.
  14583. maxLength: 253
  14584. minLength: 1
  14585. pattern: ^[-._a-zA-Z0-9]+$
  14586. type: string
  14587. name:
  14588. description: The name of the Secret resource being referred to.
  14589. maxLength: 253
  14590. minLength: 1
  14591. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14592. type: string
  14593. namespace:
  14594. description: |-
  14595. The namespace of the Secret resource being referred to.
  14596. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14597. maxLength: 63
  14598. minLength: 1
  14599. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14600. type: string
  14601. type: object
  14602. secretRef:
  14603. description: |-
  14604. SecretRef to a key in a Secret resource containing client private key to
  14605. authenticate with Vault using the Cert authentication method
  14606. properties:
  14607. key:
  14608. description: |-
  14609. A key in the referenced Secret.
  14610. Some instances of this field may be defaulted, in others it may be required.
  14611. maxLength: 253
  14612. minLength: 1
  14613. pattern: ^[-._a-zA-Z0-9]+$
  14614. type: string
  14615. name:
  14616. description: The name of the Secret resource being referred to.
  14617. maxLength: 253
  14618. minLength: 1
  14619. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14620. type: string
  14621. namespace:
  14622. description: |-
  14623. The namespace of the Secret resource being referred to.
  14624. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14625. maxLength: 63
  14626. minLength: 1
  14627. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14628. type: string
  14629. type: object
  14630. type: object
  14631. iam:
  14632. description: |-
  14633. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  14634. AWS IAM authentication method
  14635. properties:
  14636. externalID:
  14637. description: AWS External ID set on assumed IAM roles
  14638. type: string
  14639. jwt:
  14640. description: Specify a service account with IRSA enabled
  14641. properties:
  14642. serviceAccountRef:
  14643. description: A reference to a ServiceAccount resource.
  14644. properties:
  14645. audiences:
  14646. description: |-
  14647. Audience specifies the `aud` claim for the service account token
  14648. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  14649. then this audiences will be appended to the list
  14650. items:
  14651. type: string
  14652. type: array
  14653. name:
  14654. description: The name of the ServiceAccount resource being referred to.
  14655. maxLength: 253
  14656. minLength: 1
  14657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14658. type: string
  14659. namespace:
  14660. description: |-
  14661. Namespace of the resource being referred to.
  14662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14663. maxLength: 63
  14664. minLength: 1
  14665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14666. type: string
  14667. required:
  14668. - name
  14669. type: object
  14670. type: object
  14671. path:
  14672. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  14673. type: string
  14674. region:
  14675. description: AWS region
  14676. type: string
  14677. role:
  14678. description: This is the AWS role to be assumed before talking to vault
  14679. type: string
  14680. secretRef:
  14681. description: Specify credentials in a Secret object
  14682. properties:
  14683. accessKeyIDSecretRef:
  14684. description: The AccessKeyID is used for authentication
  14685. properties:
  14686. key:
  14687. description: |-
  14688. A key in the referenced Secret.
  14689. Some instances of this field may be defaulted, in others it may be required.
  14690. maxLength: 253
  14691. minLength: 1
  14692. pattern: ^[-._a-zA-Z0-9]+$
  14693. type: string
  14694. name:
  14695. description: The name of the Secret resource being referred to.
  14696. maxLength: 253
  14697. minLength: 1
  14698. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14699. type: string
  14700. namespace:
  14701. description: |-
  14702. The namespace of the Secret resource being referred to.
  14703. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14704. maxLength: 63
  14705. minLength: 1
  14706. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14707. type: string
  14708. type: object
  14709. secretAccessKeySecretRef:
  14710. description: The SecretAccessKey is used for authentication
  14711. properties:
  14712. key:
  14713. description: |-
  14714. A key in the referenced Secret.
  14715. Some instances of this field may be defaulted, in others it may be required.
  14716. maxLength: 253
  14717. minLength: 1
  14718. pattern: ^[-._a-zA-Z0-9]+$
  14719. type: string
  14720. name:
  14721. description: The name of the Secret resource being referred to.
  14722. maxLength: 253
  14723. minLength: 1
  14724. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14725. type: string
  14726. namespace:
  14727. description: |-
  14728. The namespace of the Secret resource being referred to.
  14729. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14730. maxLength: 63
  14731. minLength: 1
  14732. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14733. type: string
  14734. type: object
  14735. sessionTokenSecretRef:
  14736. description: |-
  14737. The SessionToken used for authentication
  14738. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  14739. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  14740. properties:
  14741. key:
  14742. description: |-
  14743. A key in the referenced Secret.
  14744. Some instances of this field may be defaulted, in others it may be required.
  14745. maxLength: 253
  14746. minLength: 1
  14747. pattern: ^[-._a-zA-Z0-9]+$
  14748. type: string
  14749. name:
  14750. description: The name of the Secret resource being referred to.
  14751. maxLength: 253
  14752. minLength: 1
  14753. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14754. type: string
  14755. namespace:
  14756. description: |-
  14757. The namespace of the Secret resource being referred to.
  14758. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14759. maxLength: 63
  14760. minLength: 1
  14761. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14762. type: string
  14763. type: object
  14764. type: object
  14765. vaultAwsIamServerID:
  14766. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  14767. type: string
  14768. vaultRole:
  14769. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  14770. type: string
  14771. required:
  14772. - vaultRole
  14773. type: object
  14774. jwt:
  14775. description: |-
  14776. Jwt authenticates with Vault by passing role and JWT token using the
  14777. JWT/OIDC authentication method
  14778. properties:
  14779. kubernetesServiceAccountToken:
  14780. description: |-
  14781. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  14782. a token for with the `TokenRequest` API.
  14783. properties:
  14784. audiences:
  14785. description: |-
  14786. Optional audiences field that will be used to request a temporary Kubernetes service
  14787. account token for the service account referenced by `serviceAccountRef`.
  14788. Defaults to a single audience `vault` it not specified.
  14789. Deprecated: use serviceAccountRef.Audiences instead
  14790. items:
  14791. type: string
  14792. type: array
  14793. expirationSeconds:
  14794. description: |-
  14795. Optional expiration time in seconds that will be used to request a temporary
  14796. Kubernetes service account token for the service account referenced by
  14797. `serviceAccountRef`.
  14798. Deprecated: this will be removed in the future.
  14799. Defaults to 10 minutes.
  14800. format: int64
  14801. type: integer
  14802. serviceAccountRef:
  14803. description: Service account field containing the name of a kubernetes ServiceAccount.
  14804. properties:
  14805. audiences:
  14806. description: |-
  14807. Audience specifies the `aud` claim for the service account token
  14808. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  14809. then this audiences will be appended to the list
  14810. items:
  14811. type: string
  14812. type: array
  14813. name:
  14814. description: The name of the ServiceAccount resource being referred to.
  14815. maxLength: 253
  14816. minLength: 1
  14817. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14818. type: string
  14819. namespace:
  14820. description: |-
  14821. Namespace of the resource being referred to.
  14822. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14823. maxLength: 63
  14824. minLength: 1
  14825. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14826. type: string
  14827. required:
  14828. - name
  14829. type: object
  14830. required:
  14831. - serviceAccountRef
  14832. type: object
  14833. path:
  14834. default: jwt
  14835. description: |-
  14836. Path where the JWT authentication backend is mounted
  14837. in Vault, e.g: "jwt"
  14838. type: string
  14839. role:
  14840. description: |-
  14841. Role is a JWT role to authenticate using the JWT/OIDC Vault
  14842. authentication method
  14843. type: string
  14844. secretRef:
  14845. description: |-
  14846. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  14847. authenticate with Vault using the JWT/OIDC authentication method.
  14848. properties:
  14849. key:
  14850. description: |-
  14851. A key in the referenced Secret.
  14852. Some instances of this field may be defaulted, in others it may be required.
  14853. maxLength: 253
  14854. minLength: 1
  14855. pattern: ^[-._a-zA-Z0-9]+$
  14856. type: string
  14857. name:
  14858. description: The name of the Secret resource being referred to.
  14859. maxLength: 253
  14860. minLength: 1
  14861. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14862. type: string
  14863. namespace:
  14864. description: |-
  14865. The namespace of the Secret resource being referred to.
  14866. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14867. maxLength: 63
  14868. minLength: 1
  14869. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14870. type: string
  14871. type: object
  14872. required:
  14873. - path
  14874. type: object
  14875. kubernetes:
  14876. description: |-
  14877. Kubernetes authenticates with Vault by passing the ServiceAccount
  14878. token stored in the named Secret resource to the Vault server.
  14879. properties:
  14880. mountPath:
  14881. default: kubernetes
  14882. description: |-
  14883. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  14884. "kubernetes"
  14885. type: string
  14886. role:
  14887. description: |-
  14888. A required field containing the Vault Role to assume. A Role binds a
  14889. Kubernetes ServiceAccount with a set of Vault policies.
  14890. type: string
  14891. secretRef:
  14892. description: |-
  14893. Optional secret field containing a Kubernetes ServiceAccount JWT used
  14894. for authenticating with Vault. If a name is specified without a key,
  14895. `token` is the default. If one is not specified, the one bound to
  14896. the controller will be used.
  14897. properties:
  14898. key:
  14899. description: |-
  14900. A key in the referenced Secret.
  14901. Some instances of this field may be defaulted, in others it may be required.
  14902. maxLength: 253
  14903. minLength: 1
  14904. pattern: ^[-._a-zA-Z0-9]+$
  14905. type: string
  14906. name:
  14907. description: The name of the Secret resource being referred to.
  14908. maxLength: 253
  14909. minLength: 1
  14910. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14911. type: string
  14912. namespace:
  14913. description: |-
  14914. The namespace of the Secret resource being referred to.
  14915. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14916. maxLength: 63
  14917. minLength: 1
  14918. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14919. type: string
  14920. type: object
  14921. serviceAccountRef:
  14922. description: |-
  14923. Optional service account field containing the name of a kubernetes ServiceAccount.
  14924. If the service account is specified, the service account secret token JWT will be used
  14925. for authenticating with Vault. If the service account selector is not supplied,
  14926. the secretRef will be used instead.
  14927. properties:
  14928. audiences:
  14929. description: |-
  14930. Audience specifies the `aud` claim for the service account token
  14931. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  14932. then this audiences will be appended to the list
  14933. items:
  14934. type: string
  14935. type: array
  14936. name:
  14937. description: The name of the ServiceAccount resource being referred to.
  14938. maxLength: 253
  14939. minLength: 1
  14940. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14941. type: string
  14942. namespace:
  14943. description: |-
  14944. Namespace of the resource being referred to.
  14945. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14946. maxLength: 63
  14947. minLength: 1
  14948. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14949. type: string
  14950. required:
  14951. - name
  14952. type: object
  14953. required:
  14954. - mountPath
  14955. - role
  14956. type: object
  14957. ldap:
  14958. description: |-
  14959. Ldap authenticates with Vault by passing username/password pair using
  14960. the LDAP authentication method
  14961. properties:
  14962. path:
  14963. default: ldap
  14964. description: |-
  14965. Path where the LDAP authentication backend is mounted
  14966. in Vault, e.g: "ldap"
  14967. type: string
  14968. secretRef:
  14969. description: |-
  14970. SecretRef to a key in a Secret resource containing password for the LDAP
  14971. user used to authenticate with Vault using the LDAP authentication
  14972. method
  14973. properties:
  14974. key:
  14975. description: |-
  14976. A key in the referenced Secret.
  14977. Some instances of this field may be defaulted, in others it may be required.
  14978. maxLength: 253
  14979. minLength: 1
  14980. pattern: ^[-._a-zA-Z0-9]+$
  14981. type: string
  14982. name:
  14983. description: The name of the Secret resource being referred to.
  14984. maxLength: 253
  14985. minLength: 1
  14986. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  14987. type: string
  14988. namespace:
  14989. description: |-
  14990. The namespace of the Secret resource being referred to.
  14991. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  14992. maxLength: 63
  14993. minLength: 1
  14994. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  14995. type: string
  14996. type: object
  14997. username:
  14998. description: |-
  14999. Username is a LDAP user name used to authenticate using the LDAP Vault
  15000. authentication method
  15001. type: string
  15002. required:
  15003. - path
  15004. - username
  15005. type: object
  15006. namespace:
  15007. description: |-
  15008. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  15009. Namespaces is a set of features within Vault Enterprise that allows
  15010. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  15011. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  15012. This will default to Vault.Namespace field if set, or empty otherwise
  15013. type: string
  15014. tokenSecretRef:
  15015. description: TokenSecretRef authenticates with Vault by presenting a token.
  15016. properties:
  15017. key:
  15018. description: |-
  15019. A key in the referenced Secret.
  15020. Some instances of this field may be defaulted, in others it may be required.
  15021. maxLength: 253
  15022. minLength: 1
  15023. pattern: ^[-._a-zA-Z0-9]+$
  15024. type: string
  15025. name:
  15026. description: The name of the Secret resource being referred to.
  15027. maxLength: 253
  15028. minLength: 1
  15029. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15030. type: string
  15031. namespace:
  15032. description: |-
  15033. The namespace of the Secret resource being referred to.
  15034. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15035. maxLength: 63
  15036. minLength: 1
  15037. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15038. type: string
  15039. type: object
  15040. userPass:
  15041. description: UserPass authenticates with Vault by passing username/password pair
  15042. properties:
  15043. path:
  15044. default: user
  15045. description: |-
  15046. Path where the UserPassword authentication backend is mounted
  15047. in Vault, e.g: "user"
  15048. type: string
  15049. secretRef:
  15050. description: |-
  15051. SecretRef to a key in a Secret resource containing password for the
  15052. user used to authenticate with Vault using the UserPass authentication
  15053. method
  15054. properties:
  15055. key:
  15056. description: |-
  15057. A key in the referenced Secret.
  15058. Some instances of this field may be defaulted, in others it may be required.
  15059. maxLength: 253
  15060. minLength: 1
  15061. pattern: ^[-._a-zA-Z0-9]+$
  15062. type: string
  15063. name:
  15064. description: The name of the Secret resource being referred to.
  15065. maxLength: 253
  15066. minLength: 1
  15067. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15068. type: string
  15069. namespace:
  15070. description: |-
  15071. The namespace of the Secret resource being referred to.
  15072. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15073. maxLength: 63
  15074. minLength: 1
  15075. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15076. type: string
  15077. type: object
  15078. username:
  15079. description: |-
  15080. Username is a user name used to authenticate using the UserPass Vault
  15081. authentication method
  15082. type: string
  15083. required:
  15084. - path
  15085. - username
  15086. type: object
  15087. type: object
  15088. caBundle:
  15089. description: |-
  15090. PEM encoded CA bundle used to validate Vault server certificate. Only used
  15091. if the Server URL is using HTTPS protocol. This parameter is ignored for
  15092. plain HTTP protocol connection. If not set the system root certificates
  15093. are used to validate the TLS connection.
  15094. format: byte
  15095. type: string
  15096. caProvider:
  15097. description: The provider for the CA bundle to use to validate Vault server certificate.
  15098. properties:
  15099. key:
  15100. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15101. maxLength: 253
  15102. minLength: 1
  15103. pattern: ^[-._a-zA-Z0-9]+$
  15104. type: string
  15105. name:
  15106. description: The name of the object located at the provider type.
  15107. maxLength: 253
  15108. minLength: 1
  15109. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15110. type: string
  15111. namespace:
  15112. description: |-
  15113. The namespace the Provider type is in.
  15114. Can only be defined when used in a ClusterSecretStore.
  15115. maxLength: 63
  15116. minLength: 1
  15117. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15118. type: string
  15119. type:
  15120. description: The type of provider to use such as "Secret", or "ConfigMap".
  15121. enum:
  15122. - Secret
  15123. - ConfigMap
  15124. type: string
  15125. required:
  15126. - name
  15127. - type
  15128. type: object
  15129. forwardInconsistent:
  15130. description: |-
  15131. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  15132. leader instead of simply retrying within a loop. This can increase performance if
  15133. the option is enabled serverside.
  15134. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  15135. type: boolean
  15136. headers:
  15137. additionalProperties:
  15138. type: string
  15139. description: Headers to be added in Vault request
  15140. type: object
  15141. namespace:
  15142. description: |-
  15143. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  15144. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  15145. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  15146. type: string
  15147. path:
  15148. description: |-
  15149. Path is the mount path of the Vault KV backend endpoint, e.g:
  15150. "secret". The v2 KV secret engine version specific "/data" path suffix
  15151. for fetching secrets from Vault is optional and will be appended
  15152. if not present in specified path.
  15153. type: string
  15154. readYourWrites:
  15155. description: |-
  15156. ReadYourWrites ensures isolated read-after-write semantics by
  15157. providing discovered cluster replication states in each request.
  15158. More information about eventual consistency in Vault can be found here
  15159. https://www.vaultproject.io/docs/enterprise/consistency
  15160. type: boolean
  15161. server:
  15162. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  15163. type: string
  15164. tls:
  15165. description: |-
  15166. The configuration used for client side related TLS communication, when the Vault server
  15167. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  15168. This parameter is ignored for plain HTTP protocol connection.
  15169. It's worth noting this configuration is different from the "TLS certificates auth method",
  15170. which is available under the `auth.cert` section.
  15171. properties:
  15172. certSecretRef:
  15173. description: |-
  15174. CertSecretRef is a certificate added to the transport layer
  15175. when communicating with the Vault server.
  15176. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  15177. properties:
  15178. key:
  15179. description: |-
  15180. A key in the referenced Secret.
  15181. Some instances of this field may be defaulted, in others it may be required.
  15182. maxLength: 253
  15183. minLength: 1
  15184. pattern: ^[-._a-zA-Z0-9]+$
  15185. type: string
  15186. name:
  15187. description: The name of the Secret resource being referred to.
  15188. maxLength: 253
  15189. minLength: 1
  15190. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15191. type: string
  15192. namespace:
  15193. description: |-
  15194. The namespace of the Secret resource being referred to.
  15195. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15196. maxLength: 63
  15197. minLength: 1
  15198. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15199. type: string
  15200. type: object
  15201. keySecretRef:
  15202. description: |-
  15203. KeySecretRef to a key in a Secret resource containing client private key
  15204. added to the transport layer when communicating with the Vault server.
  15205. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  15206. properties:
  15207. key:
  15208. description: |-
  15209. A key in the referenced Secret.
  15210. Some instances of this field may be defaulted, in others it may be required.
  15211. maxLength: 253
  15212. minLength: 1
  15213. pattern: ^[-._a-zA-Z0-9]+$
  15214. type: string
  15215. name:
  15216. description: The name of the Secret resource being referred to.
  15217. maxLength: 253
  15218. minLength: 1
  15219. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15220. type: string
  15221. namespace:
  15222. description: |-
  15223. The namespace of the Secret resource being referred to.
  15224. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15225. maxLength: 63
  15226. minLength: 1
  15227. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15228. type: string
  15229. type: object
  15230. type: object
  15231. version:
  15232. default: v2
  15233. description: |-
  15234. Version is the Vault KV secret engine version. This can be either "v1" or
  15235. "v2". Version defaults to "v2".
  15236. enum:
  15237. - v1
  15238. - v2
  15239. type: string
  15240. required:
  15241. - auth
  15242. - server
  15243. type: object
  15244. resultType:
  15245. default: Data
  15246. description: |-
  15247. Result type defines which data is returned from the generator.
  15248. By default it is the "data" section of the Vault API response.
  15249. When using e.g. /auth/token/create the "data" section is empty but
  15250. the "auth" section contains the generated token.
  15251. Please refer to the vault docs regarding the result data structure.
  15252. enum:
  15253. - Data
  15254. - Auth
  15255. type: string
  15256. retrySettings:
  15257. description: Used to configure http retries if failed
  15258. properties:
  15259. maxRetries:
  15260. format: int32
  15261. type: integer
  15262. retryInterval:
  15263. type: string
  15264. type: object
  15265. required:
  15266. - path
  15267. - provider
  15268. type: object
  15269. webhookSpec:
  15270. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  15271. properties:
  15272. body:
  15273. description: Body
  15274. type: string
  15275. caBundle:
  15276. description: |-
  15277. PEM encoded CA bundle used to validate webhook server certificate. Only used
  15278. if the Server URL is using HTTPS protocol. This parameter is ignored for
  15279. plain HTTP protocol connection. If not set the system root certificates
  15280. are used to validate the TLS connection.
  15281. format: byte
  15282. type: string
  15283. caProvider:
  15284. description: The provider for the CA bundle to use to validate webhook server certificate.
  15285. properties:
  15286. key:
  15287. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  15288. maxLength: 253
  15289. minLength: 1
  15290. pattern: ^[-._a-zA-Z0-9]+$
  15291. type: string
  15292. name:
  15293. description: The name of the object located at the provider type.
  15294. maxLength: 253
  15295. minLength: 1
  15296. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15297. type: string
  15298. namespace:
  15299. description: The namespace the Provider type is in.
  15300. maxLength: 63
  15301. minLength: 1
  15302. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15303. type: string
  15304. type:
  15305. description: The type of provider to use such as "Secret", or "ConfigMap".
  15306. enum:
  15307. - Secret
  15308. - ConfigMap
  15309. type: string
  15310. required:
  15311. - name
  15312. - type
  15313. type: object
  15314. headers:
  15315. additionalProperties:
  15316. type: string
  15317. description: Headers
  15318. type: object
  15319. method:
  15320. description: Webhook Method
  15321. type: string
  15322. result:
  15323. description: Result formatting
  15324. properties:
  15325. jsonPath:
  15326. description: Json path of return value
  15327. type: string
  15328. type: object
  15329. secrets:
  15330. description: |-
  15331. Secrets to fill in templates
  15332. These secrets will be passed to the templating function as key value pairs under the given name
  15333. items:
  15334. properties:
  15335. name:
  15336. description: Name of this secret in templates
  15337. type: string
  15338. secretRef:
  15339. description: Secret ref to fill in credentials
  15340. properties:
  15341. key:
  15342. description: The key where the token is found.
  15343. maxLength: 253
  15344. minLength: 1
  15345. pattern: ^[-._a-zA-Z0-9]+$
  15346. type: string
  15347. name:
  15348. description: The name of the Secret resource being referred to.
  15349. maxLength: 253
  15350. minLength: 1
  15351. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15352. type: string
  15353. type: object
  15354. required:
  15355. - name
  15356. - secretRef
  15357. type: object
  15358. type: array
  15359. timeout:
  15360. description: Timeout
  15361. type: string
  15362. url:
  15363. description: Webhook url to call
  15364. type: string
  15365. required:
  15366. - result
  15367. - url
  15368. type: object
  15369. type: object
  15370. kind:
  15371. type: string
  15372. required:
  15373. - generator
  15374. - kind
  15375. type: object
  15376. status:
  15377. type: object
  15378. type: object
  15379. served: true
  15380. storage: true
  15381. subresources:
  15382. status: {}
  15383. conversion:
  15384. strategy: Webhook
  15385. webhook:
  15386. conversionReviewVersions:
  15387. - v1
  15388. clientConfig:
  15389. service:
  15390. name: kubernetes
  15391. namespace: default
  15392. path: /convert
  15393. ---
  15394. apiVersion: apiextensions.k8s.io/v1
  15395. kind: CustomResourceDefinition
  15396. metadata:
  15397. annotations:
  15398. controller-gen.kubebuilder.io/version: v0.16.5
  15399. labels:
  15400. external-secrets.io/component: controller
  15401. name: ecrauthorizationtokens.generators.external-secrets.io
  15402. spec:
  15403. group: generators.external-secrets.io
  15404. names:
  15405. categories:
  15406. - external-secrets
  15407. - external-secrets-generators
  15408. kind: ECRAuthorizationToken
  15409. listKind: ECRAuthorizationTokenList
  15410. plural: ecrauthorizationtokens
  15411. shortNames:
  15412. - ecrauthorizationtoken
  15413. singular: ecrauthorizationtoken
  15414. scope: Namespaced
  15415. versions:
  15416. - name: v1alpha1
  15417. schema:
  15418. openAPIV3Schema:
  15419. description: |-
  15420. ECRAuthorizationTokenSpec uses the GetAuthorizationToken API to retrieve an
  15421. authorization token.
  15422. The authorization token is valid for 12 hours.
  15423. The authorizationToken returned is a base64 encoded string that can be decoded
  15424. and used in a docker login command to authenticate to a registry.
  15425. For more information, see Registry authentication (https://docs.aws.amazon.com/AmazonECR/latest/userguide/Registries.html#registry_auth) in the Amazon Elastic Container Registry User Guide.
  15426. properties:
  15427. apiVersion:
  15428. description: |-
  15429. APIVersion defines the versioned schema of this representation of an object.
  15430. Servers should convert recognized schemas to the latest internal value, and
  15431. may reject unrecognized values.
  15432. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15433. type: string
  15434. kind:
  15435. description: |-
  15436. Kind is a string value representing the REST resource this object represents.
  15437. Servers may infer this from the endpoint the client submits requests to.
  15438. Cannot be updated.
  15439. In CamelCase.
  15440. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15441. type: string
  15442. metadata:
  15443. type: object
  15444. spec:
  15445. properties:
  15446. auth:
  15447. description: Auth defines how to authenticate with AWS
  15448. properties:
  15449. jwt:
  15450. description: Authenticate against AWS using service account tokens.
  15451. properties:
  15452. serviceAccountRef:
  15453. description: A reference to a ServiceAccount resource.
  15454. properties:
  15455. audiences:
  15456. description: |-
  15457. Audience specifies the `aud` claim for the service account token
  15458. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15459. then this audiences will be appended to the list
  15460. items:
  15461. type: string
  15462. type: array
  15463. name:
  15464. description: The name of the ServiceAccount resource being referred to.
  15465. maxLength: 253
  15466. minLength: 1
  15467. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15468. type: string
  15469. namespace:
  15470. description: |-
  15471. Namespace of the resource being referred to.
  15472. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15473. maxLength: 63
  15474. minLength: 1
  15475. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15476. type: string
  15477. required:
  15478. - name
  15479. type: object
  15480. type: object
  15481. secretRef:
  15482. description: |-
  15483. AWSAuthSecretRef holds secret references for AWS credentials
  15484. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  15485. properties:
  15486. accessKeyIDSecretRef:
  15487. description: The AccessKeyID is used for authentication
  15488. properties:
  15489. key:
  15490. description: |-
  15491. A key in the referenced Secret.
  15492. Some instances of this field may be defaulted, in others it may be required.
  15493. maxLength: 253
  15494. minLength: 1
  15495. pattern: ^[-._a-zA-Z0-9]+$
  15496. type: string
  15497. name:
  15498. description: The name of the Secret resource being referred to.
  15499. maxLength: 253
  15500. minLength: 1
  15501. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15502. type: string
  15503. namespace:
  15504. description: |-
  15505. The namespace of the Secret resource being referred to.
  15506. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15507. maxLength: 63
  15508. minLength: 1
  15509. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15510. type: string
  15511. type: object
  15512. secretAccessKeySecretRef:
  15513. description: The SecretAccessKey is used for authentication
  15514. properties:
  15515. key:
  15516. description: |-
  15517. A key in the referenced Secret.
  15518. Some instances of this field may be defaulted, in others it may be required.
  15519. maxLength: 253
  15520. minLength: 1
  15521. pattern: ^[-._a-zA-Z0-9]+$
  15522. type: string
  15523. name:
  15524. description: The name of the Secret resource being referred to.
  15525. maxLength: 253
  15526. minLength: 1
  15527. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15528. type: string
  15529. namespace:
  15530. description: |-
  15531. The namespace of the Secret resource being referred to.
  15532. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15533. maxLength: 63
  15534. minLength: 1
  15535. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15536. type: string
  15537. type: object
  15538. sessionTokenSecretRef:
  15539. description: |-
  15540. The SessionToken used for authentication
  15541. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  15542. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  15543. properties:
  15544. key:
  15545. description: |-
  15546. A key in the referenced Secret.
  15547. Some instances of this field may be defaulted, in others it may be required.
  15548. maxLength: 253
  15549. minLength: 1
  15550. pattern: ^[-._a-zA-Z0-9]+$
  15551. type: string
  15552. name:
  15553. description: The name of the Secret resource being referred to.
  15554. maxLength: 253
  15555. minLength: 1
  15556. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15557. type: string
  15558. namespace:
  15559. description: |-
  15560. The namespace of the Secret resource being referred to.
  15561. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15562. maxLength: 63
  15563. minLength: 1
  15564. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15565. type: string
  15566. type: object
  15567. type: object
  15568. type: object
  15569. region:
  15570. description: Region specifies the region to operate in.
  15571. type: string
  15572. role:
  15573. description: |-
  15574. You can assume a role before making calls to the
  15575. desired AWS service.
  15576. type: string
  15577. required:
  15578. - region
  15579. type: object
  15580. type: object
  15581. served: true
  15582. storage: true
  15583. subresources:
  15584. status: {}
  15585. conversion:
  15586. strategy: Webhook
  15587. webhook:
  15588. conversionReviewVersions:
  15589. - v1
  15590. clientConfig:
  15591. service:
  15592. name: kubernetes
  15593. namespace: default
  15594. path: /convert
  15595. ---
  15596. apiVersion: apiextensions.k8s.io/v1
  15597. kind: CustomResourceDefinition
  15598. metadata:
  15599. annotations:
  15600. controller-gen.kubebuilder.io/version: v0.16.5
  15601. labels:
  15602. external-secrets.io/component: controller
  15603. name: fakes.generators.external-secrets.io
  15604. spec:
  15605. group: generators.external-secrets.io
  15606. names:
  15607. categories:
  15608. - external-secrets
  15609. - external-secrets-generators
  15610. kind: Fake
  15611. listKind: FakeList
  15612. plural: fakes
  15613. shortNames:
  15614. - fake
  15615. singular: fake
  15616. scope: Namespaced
  15617. versions:
  15618. - name: v1alpha1
  15619. schema:
  15620. openAPIV3Schema:
  15621. description: |-
  15622. Fake generator is used for testing. It lets you define
  15623. a static set of credentials that is always returned.
  15624. properties:
  15625. apiVersion:
  15626. description: |-
  15627. APIVersion defines the versioned schema of this representation of an object.
  15628. Servers should convert recognized schemas to the latest internal value, and
  15629. may reject unrecognized values.
  15630. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15631. type: string
  15632. kind:
  15633. description: |-
  15634. Kind is a string value representing the REST resource this object represents.
  15635. Servers may infer this from the endpoint the client submits requests to.
  15636. Cannot be updated.
  15637. In CamelCase.
  15638. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15639. type: string
  15640. metadata:
  15641. type: object
  15642. spec:
  15643. description: FakeSpec contains the static data.
  15644. properties:
  15645. controller:
  15646. description: |-
  15647. Used to select the correct ESO controller (think: ingress.ingressClassName)
  15648. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  15649. type: string
  15650. data:
  15651. additionalProperties:
  15652. type: string
  15653. description: |-
  15654. Data defines the static data returned
  15655. by this generator.
  15656. type: object
  15657. type: object
  15658. type: object
  15659. served: true
  15660. storage: true
  15661. subresources:
  15662. status: {}
  15663. conversion:
  15664. strategy: Webhook
  15665. webhook:
  15666. conversionReviewVersions:
  15667. - v1
  15668. clientConfig:
  15669. service:
  15670. name: kubernetes
  15671. namespace: default
  15672. path: /convert
  15673. ---
  15674. apiVersion: apiextensions.k8s.io/v1
  15675. kind: CustomResourceDefinition
  15676. metadata:
  15677. annotations:
  15678. controller-gen.kubebuilder.io/version: v0.16.5
  15679. labels:
  15680. external-secrets.io/component: controller
  15681. name: gcraccesstokens.generators.external-secrets.io
  15682. spec:
  15683. group: generators.external-secrets.io
  15684. names:
  15685. categories:
  15686. - external-secrets
  15687. - external-secrets-generators
  15688. kind: GCRAccessToken
  15689. listKind: GCRAccessTokenList
  15690. plural: gcraccesstokens
  15691. shortNames:
  15692. - gcraccesstoken
  15693. singular: gcraccesstoken
  15694. scope: Namespaced
  15695. versions:
  15696. - name: v1alpha1
  15697. schema:
  15698. openAPIV3Schema:
  15699. description: |-
  15700. GCRAccessToken generates an GCP access token
  15701. that can be used to authenticate with GCR.
  15702. properties:
  15703. apiVersion:
  15704. description: |-
  15705. APIVersion defines the versioned schema of this representation of an object.
  15706. Servers should convert recognized schemas to the latest internal value, and
  15707. may reject unrecognized values.
  15708. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15709. type: string
  15710. kind:
  15711. description: |-
  15712. Kind is a string value representing the REST resource this object represents.
  15713. Servers may infer this from the endpoint the client submits requests to.
  15714. Cannot be updated.
  15715. In CamelCase.
  15716. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15717. type: string
  15718. metadata:
  15719. type: object
  15720. spec:
  15721. properties:
  15722. auth:
  15723. description: Auth defines the means for authenticating with GCP
  15724. properties:
  15725. secretRef:
  15726. properties:
  15727. secretAccessKeySecretRef:
  15728. description: The SecretAccessKey is used for authentication
  15729. properties:
  15730. key:
  15731. description: |-
  15732. A key in the referenced Secret.
  15733. Some instances of this field may be defaulted, in others it may be required.
  15734. maxLength: 253
  15735. minLength: 1
  15736. pattern: ^[-._a-zA-Z0-9]+$
  15737. type: string
  15738. name:
  15739. description: The name of the Secret resource being referred to.
  15740. maxLength: 253
  15741. minLength: 1
  15742. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15743. type: string
  15744. namespace:
  15745. description: |-
  15746. The namespace of the Secret resource being referred to.
  15747. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15748. maxLength: 63
  15749. minLength: 1
  15750. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15751. type: string
  15752. type: object
  15753. type: object
  15754. workloadIdentity:
  15755. properties:
  15756. clusterLocation:
  15757. type: string
  15758. clusterName:
  15759. type: string
  15760. clusterProjectID:
  15761. type: string
  15762. serviceAccountRef:
  15763. description: A reference to a ServiceAccount resource.
  15764. properties:
  15765. audiences:
  15766. description: |-
  15767. Audience specifies the `aud` claim for the service account token
  15768. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  15769. then this audiences will be appended to the list
  15770. items:
  15771. type: string
  15772. type: array
  15773. name:
  15774. description: The name of the ServiceAccount resource being referred to.
  15775. maxLength: 253
  15776. minLength: 1
  15777. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15778. type: string
  15779. namespace:
  15780. description: |-
  15781. Namespace of the resource being referred to.
  15782. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15783. maxLength: 63
  15784. minLength: 1
  15785. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15786. type: string
  15787. required:
  15788. - name
  15789. type: object
  15790. required:
  15791. - clusterLocation
  15792. - clusterName
  15793. - serviceAccountRef
  15794. type: object
  15795. type: object
  15796. projectID:
  15797. description: ProjectID defines which project to use to authenticate with
  15798. type: string
  15799. required:
  15800. - auth
  15801. - projectID
  15802. type: object
  15803. type: object
  15804. served: true
  15805. storage: true
  15806. subresources:
  15807. status: {}
  15808. conversion:
  15809. strategy: Webhook
  15810. webhook:
  15811. conversionReviewVersions:
  15812. - v1
  15813. clientConfig:
  15814. service:
  15815. name: kubernetes
  15816. namespace: default
  15817. path: /convert
  15818. ---
  15819. apiVersion: apiextensions.k8s.io/v1
  15820. kind: CustomResourceDefinition
  15821. metadata:
  15822. annotations:
  15823. controller-gen.kubebuilder.io/version: v0.16.5
  15824. labels:
  15825. external-secrets.io/component: controller
  15826. name: githubaccesstokens.generators.external-secrets.io
  15827. spec:
  15828. group: generators.external-secrets.io
  15829. names:
  15830. categories:
  15831. - external-secrets
  15832. - external-secrets-generators
  15833. kind: GithubAccessToken
  15834. listKind: GithubAccessTokenList
  15835. plural: githubaccesstokens
  15836. shortNames:
  15837. - githubaccesstoken
  15838. singular: githubaccesstoken
  15839. scope: Namespaced
  15840. versions:
  15841. - name: v1alpha1
  15842. schema:
  15843. openAPIV3Schema:
  15844. description: GithubAccessToken generates ghs_ accessToken
  15845. properties:
  15846. apiVersion:
  15847. description: |-
  15848. APIVersion defines the versioned schema of this representation of an object.
  15849. Servers should convert recognized schemas to the latest internal value, and
  15850. may reject unrecognized values.
  15851. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15852. type: string
  15853. kind:
  15854. description: |-
  15855. Kind is a string value representing the REST resource this object represents.
  15856. Servers may infer this from the endpoint the client submits requests to.
  15857. Cannot be updated.
  15858. In CamelCase.
  15859. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15860. type: string
  15861. metadata:
  15862. type: object
  15863. spec:
  15864. properties:
  15865. appID:
  15866. type: string
  15867. auth:
  15868. description: Auth configures how ESO authenticates with a Github instance.
  15869. properties:
  15870. privateKey:
  15871. properties:
  15872. secretRef:
  15873. description: |-
  15874. A reference to a specific 'key' within a Secret resource.
  15875. In some instances, `key` is a required field.
  15876. properties:
  15877. key:
  15878. description: |-
  15879. A key in the referenced Secret.
  15880. Some instances of this field may be defaulted, in others it may be required.
  15881. maxLength: 253
  15882. minLength: 1
  15883. pattern: ^[-._a-zA-Z0-9]+$
  15884. type: string
  15885. name:
  15886. description: The name of the Secret resource being referred to.
  15887. maxLength: 253
  15888. minLength: 1
  15889. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  15890. type: string
  15891. namespace:
  15892. description: |-
  15893. The namespace of the Secret resource being referred to.
  15894. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  15895. maxLength: 63
  15896. minLength: 1
  15897. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  15898. type: string
  15899. type: object
  15900. required:
  15901. - secretRef
  15902. type: object
  15903. required:
  15904. - privateKey
  15905. type: object
  15906. installID:
  15907. type: string
  15908. permissions:
  15909. additionalProperties:
  15910. type: string
  15911. description: Map of permissions the token will have. If omitted, defaults to all permissions the GitHub App has.
  15912. type: object
  15913. repositories:
  15914. description: |-
  15915. List of repositories the token will have access to. If omitted, defaults to all repositories the GitHub App
  15916. is installed to.
  15917. items:
  15918. type: string
  15919. type: array
  15920. url:
  15921. description: URL configures the Github instance URL. Defaults to https://github.com/.
  15922. type: string
  15923. required:
  15924. - appID
  15925. - auth
  15926. - installID
  15927. type: object
  15928. type: object
  15929. served: true
  15930. storage: true
  15931. subresources:
  15932. status: {}
  15933. conversion:
  15934. strategy: Webhook
  15935. webhook:
  15936. conversionReviewVersions:
  15937. - v1
  15938. clientConfig:
  15939. service:
  15940. name: kubernetes
  15941. namespace: default
  15942. path: /convert
  15943. ---
  15944. apiVersion: apiextensions.k8s.io/v1
  15945. kind: CustomResourceDefinition
  15946. metadata:
  15947. annotations:
  15948. controller-gen.kubebuilder.io/version: v0.16.5
  15949. labels:
  15950. external-secrets.io/component: controller
  15951. name: passwords.generators.external-secrets.io
  15952. spec:
  15953. group: generators.external-secrets.io
  15954. names:
  15955. categories:
  15956. - external-secrets
  15957. - external-secrets-generators
  15958. kind: Password
  15959. listKind: PasswordList
  15960. plural: passwords
  15961. shortNames:
  15962. - password
  15963. singular: password
  15964. scope: Namespaced
  15965. versions:
  15966. - name: v1alpha1
  15967. schema:
  15968. openAPIV3Schema:
  15969. description: |-
  15970. Password generates a random password based on the
  15971. configuration parameters in spec.
  15972. You can specify the length, characterset and other attributes.
  15973. properties:
  15974. apiVersion:
  15975. description: |-
  15976. APIVersion defines the versioned schema of this representation of an object.
  15977. Servers should convert recognized schemas to the latest internal value, and
  15978. may reject unrecognized values.
  15979. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  15980. type: string
  15981. kind:
  15982. description: |-
  15983. Kind is a string value representing the REST resource this object represents.
  15984. Servers may infer this from the endpoint the client submits requests to.
  15985. Cannot be updated.
  15986. In CamelCase.
  15987. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  15988. type: string
  15989. metadata:
  15990. type: object
  15991. spec:
  15992. description: PasswordSpec controls the behavior of the password generator.
  15993. properties:
  15994. allowRepeat:
  15995. default: false
  15996. description: set AllowRepeat to true to allow repeating characters.
  15997. type: boolean
  15998. digits:
  15999. description: |-
  16000. Digits specifies the number of digits in the generated
  16001. password. If omitted it defaults to 25% of the length of the password
  16002. type: integer
  16003. length:
  16004. default: 24
  16005. description: |-
  16006. Length of the password to be generated.
  16007. Defaults to 24
  16008. type: integer
  16009. noUpper:
  16010. default: false
  16011. description: Set NoUpper to disable uppercase characters
  16012. type: boolean
  16013. symbolCharacters:
  16014. description: |-
  16015. SymbolCharacters specifies the special characters that should be used
  16016. in the generated password.
  16017. type: string
  16018. symbols:
  16019. description: |-
  16020. Symbols specifies the number of symbol characters in the generated
  16021. password. If omitted it defaults to 25% of the length of the password
  16022. type: integer
  16023. required:
  16024. - allowRepeat
  16025. - length
  16026. - noUpper
  16027. type: object
  16028. type: object
  16029. served: true
  16030. storage: true
  16031. subresources:
  16032. status: {}
  16033. conversion:
  16034. strategy: Webhook
  16035. webhook:
  16036. conversionReviewVersions:
  16037. - v1
  16038. clientConfig:
  16039. service:
  16040. name: kubernetes
  16041. namespace: default
  16042. path: /convert
  16043. ---
  16044. apiVersion: apiextensions.k8s.io/v1
  16045. kind: CustomResourceDefinition
  16046. metadata:
  16047. annotations:
  16048. controller-gen.kubebuilder.io/version: v0.16.5
  16049. labels:
  16050. external-secrets.io/component: controller
  16051. name: stssessiontokens.generators.external-secrets.io
  16052. spec:
  16053. group: generators.external-secrets.io
  16054. names:
  16055. categories:
  16056. - external-secrets
  16057. - external-secrets-generators
  16058. kind: STSSessionToken
  16059. listKind: STSSessionTokenList
  16060. plural: stssessiontokens
  16061. shortNames:
  16062. - stssessiontoken
  16063. singular: stssessiontoken
  16064. scope: Namespaced
  16065. versions:
  16066. - name: v1alpha1
  16067. schema:
  16068. openAPIV3Schema:
  16069. description: |-
  16070. STSSessionToken uses the GetSessionToken API to retrieve an authorization token.
  16071. The authorization token is valid for 12 hours.
  16072. The authorizationToken returned is a base64 encoded string that can be decoded.
  16073. For more information, see GetSessionToken (https://docs.aws.amazon.com/STS/latest/APIReference/API_GetSessionToken.html).
  16074. properties:
  16075. apiVersion:
  16076. description: |-
  16077. APIVersion defines the versioned schema of this representation of an object.
  16078. Servers should convert recognized schemas to the latest internal value, and
  16079. may reject unrecognized values.
  16080. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  16081. type: string
  16082. kind:
  16083. description: |-
  16084. Kind is a string value representing the REST resource this object represents.
  16085. Servers may infer this from the endpoint the client submits requests to.
  16086. Cannot be updated.
  16087. In CamelCase.
  16088. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  16089. type: string
  16090. metadata:
  16091. type: object
  16092. spec:
  16093. properties:
  16094. auth:
  16095. description: Auth defines how to authenticate with AWS
  16096. properties:
  16097. jwt:
  16098. description: Authenticate against AWS using service account tokens.
  16099. properties:
  16100. serviceAccountRef:
  16101. description: A reference to a ServiceAccount resource.
  16102. properties:
  16103. audiences:
  16104. description: |-
  16105. Audience specifies the `aud` claim for the service account token
  16106. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16107. then this audiences will be appended to the list
  16108. items:
  16109. type: string
  16110. type: array
  16111. name:
  16112. description: The name of the ServiceAccount resource being referred to.
  16113. maxLength: 253
  16114. minLength: 1
  16115. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16116. type: string
  16117. namespace:
  16118. description: |-
  16119. Namespace of the resource being referred to.
  16120. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16121. maxLength: 63
  16122. minLength: 1
  16123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16124. type: string
  16125. required:
  16126. - name
  16127. type: object
  16128. type: object
  16129. secretRef:
  16130. description: |-
  16131. AWSAuthSecretRef holds secret references for AWS credentials
  16132. both AccessKeyID and SecretAccessKey must be defined in order to properly authenticate.
  16133. properties:
  16134. accessKeyIDSecretRef:
  16135. description: The AccessKeyID is used for authentication
  16136. properties:
  16137. key:
  16138. description: |-
  16139. A key in the referenced Secret.
  16140. Some instances of this field may be defaulted, in others it may be required.
  16141. maxLength: 253
  16142. minLength: 1
  16143. pattern: ^[-._a-zA-Z0-9]+$
  16144. type: string
  16145. name:
  16146. description: The name of the Secret resource being referred to.
  16147. maxLength: 253
  16148. minLength: 1
  16149. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16150. type: string
  16151. namespace:
  16152. description: |-
  16153. The namespace of the Secret resource being referred to.
  16154. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16155. maxLength: 63
  16156. minLength: 1
  16157. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16158. type: string
  16159. type: object
  16160. secretAccessKeySecretRef:
  16161. description: The SecretAccessKey is used for authentication
  16162. properties:
  16163. key:
  16164. description: |-
  16165. A key in the referenced Secret.
  16166. Some instances of this field may be defaulted, in others it may be required.
  16167. maxLength: 253
  16168. minLength: 1
  16169. pattern: ^[-._a-zA-Z0-9]+$
  16170. type: string
  16171. name:
  16172. description: The name of the Secret resource being referred to.
  16173. maxLength: 253
  16174. minLength: 1
  16175. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16176. type: string
  16177. namespace:
  16178. description: |-
  16179. The namespace of the Secret resource being referred to.
  16180. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16181. maxLength: 63
  16182. minLength: 1
  16183. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16184. type: string
  16185. type: object
  16186. sessionTokenSecretRef:
  16187. description: |-
  16188. The SessionToken used for authentication
  16189. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16190. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16191. properties:
  16192. key:
  16193. description: |-
  16194. A key in the referenced Secret.
  16195. Some instances of this field may be defaulted, in others it may be required.
  16196. maxLength: 253
  16197. minLength: 1
  16198. pattern: ^[-._a-zA-Z0-9]+$
  16199. type: string
  16200. name:
  16201. description: The name of the Secret resource being referred to.
  16202. maxLength: 253
  16203. minLength: 1
  16204. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16205. type: string
  16206. namespace:
  16207. description: |-
  16208. The namespace of the Secret resource being referred to.
  16209. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16210. maxLength: 63
  16211. minLength: 1
  16212. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16213. type: string
  16214. type: object
  16215. type: object
  16216. type: object
  16217. region:
  16218. description: Region specifies the region to operate in.
  16219. type: string
  16220. requestParameters:
  16221. description: RequestParameters contains parameters that can be passed to the STS service.
  16222. properties:
  16223. serialNumber:
  16224. description: |-
  16225. SerialNumber is the identification number of the MFA device that is associated with the IAM user who is making
  16226. the GetSessionToken call.
  16227. Possible values: hardware device (such as GAHT12345678) or an Amazon Resource Name (ARN) for a virtual device
  16228. (such as arn:aws:iam::123456789012:mfa/user)
  16229. type: string
  16230. sessionDuration:
  16231. description: |-
  16232. SessionDuration The duration, in seconds, that the credentials should remain valid. Acceptable durations for
  16233. IAM user sessions range from 900 seconds (15 minutes) to 129,600 seconds (36 hours), with 43,200 seconds
  16234. (12 hours) as the default.
  16235. format: int64
  16236. type: integer
  16237. tokenCode:
  16238. description: TokenCode is the value provided by the MFA device, if MFA is required.
  16239. type: string
  16240. type: object
  16241. role:
  16242. description: |-
  16243. You can assume a role before making calls to the
  16244. desired AWS service.
  16245. type: string
  16246. required:
  16247. - region
  16248. type: object
  16249. type: object
  16250. served: true
  16251. storage: true
  16252. subresources:
  16253. status: {}
  16254. conversion:
  16255. strategy: Webhook
  16256. webhook:
  16257. conversionReviewVersions:
  16258. - v1
  16259. clientConfig:
  16260. service:
  16261. name: kubernetes
  16262. namespace: default
  16263. path: /convert
  16264. ---
  16265. apiVersion: apiextensions.k8s.io/v1
  16266. kind: CustomResourceDefinition
  16267. metadata:
  16268. annotations:
  16269. controller-gen.kubebuilder.io/version: v0.16.5
  16270. labels:
  16271. external-secrets.io/component: controller
  16272. name: uuids.generators.external-secrets.io
  16273. spec:
  16274. group: generators.external-secrets.io
  16275. names:
  16276. categories:
  16277. - external-secrets
  16278. - external-secrets-generators
  16279. kind: UUID
  16280. listKind: UUIDList
  16281. plural: uuids
  16282. shortNames:
  16283. - uuids
  16284. singular: uuid
  16285. scope: Namespaced
  16286. versions:
  16287. - name: v1alpha1
  16288. schema:
  16289. openAPIV3Schema:
  16290. description: UUID generates a version 1 UUID (e56657e3-764f-11ef-a397-65231a88c216).
  16291. properties:
  16292. apiVersion:
  16293. description: |-
  16294. APIVersion defines the versioned schema of this representation of an object.
  16295. Servers should convert recognized schemas to the latest internal value, and
  16296. may reject unrecognized values.
  16297. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  16298. type: string
  16299. kind:
  16300. description: |-
  16301. Kind is a string value representing the REST resource this object represents.
  16302. Servers may infer this from the endpoint the client submits requests to.
  16303. Cannot be updated.
  16304. In CamelCase.
  16305. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  16306. type: string
  16307. metadata:
  16308. type: object
  16309. spec:
  16310. description: UUIDSpec controls the behavior of the uuid generator.
  16311. type: object
  16312. type: object
  16313. served: true
  16314. storage: true
  16315. subresources:
  16316. status: {}
  16317. conversion:
  16318. strategy: Webhook
  16319. webhook:
  16320. conversionReviewVersions:
  16321. - v1
  16322. clientConfig:
  16323. service:
  16324. name: kubernetes
  16325. namespace: default
  16326. path: /convert
  16327. ---
  16328. apiVersion: apiextensions.k8s.io/v1
  16329. kind: CustomResourceDefinition
  16330. metadata:
  16331. annotations:
  16332. controller-gen.kubebuilder.io/version: v0.16.5
  16333. labels:
  16334. external-secrets.io/component: controller
  16335. name: vaultdynamicsecrets.generators.external-secrets.io
  16336. spec:
  16337. group: generators.external-secrets.io
  16338. names:
  16339. categories:
  16340. - external-secrets
  16341. - external-secrets-generators
  16342. kind: VaultDynamicSecret
  16343. listKind: VaultDynamicSecretList
  16344. plural: vaultdynamicsecrets
  16345. shortNames:
  16346. - vaultdynamicsecret
  16347. singular: vaultdynamicsecret
  16348. scope: Namespaced
  16349. versions:
  16350. - name: v1alpha1
  16351. schema:
  16352. openAPIV3Schema:
  16353. properties:
  16354. apiVersion:
  16355. description: |-
  16356. APIVersion defines the versioned schema of this representation of an object.
  16357. Servers should convert recognized schemas to the latest internal value, and
  16358. may reject unrecognized values.
  16359. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  16360. type: string
  16361. kind:
  16362. description: |-
  16363. Kind is a string value representing the REST resource this object represents.
  16364. Servers may infer this from the endpoint the client submits requests to.
  16365. Cannot be updated.
  16366. In CamelCase.
  16367. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  16368. type: string
  16369. metadata:
  16370. type: object
  16371. spec:
  16372. properties:
  16373. controller:
  16374. description: |-
  16375. Used to select the correct ESO controller (think: ingress.ingressClassName)
  16376. The ESO controller is instantiated with a specific controller name and filters VDS based on this property
  16377. type: string
  16378. method:
  16379. description: Vault API method to use (GET/POST/other)
  16380. type: string
  16381. parameters:
  16382. description: Parameters to pass to Vault write (for non-GET methods)
  16383. x-kubernetes-preserve-unknown-fields: true
  16384. path:
  16385. description: Vault path to obtain the dynamic secret from
  16386. type: string
  16387. provider:
  16388. description: Vault provider common spec
  16389. properties:
  16390. auth:
  16391. description: Auth configures how secret-manager authenticates with the Vault server.
  16392. properties:
  16393. appRole:
  16394. description: |-
  16395. AppRole authenticates with Vault using the App Role auth mechanism,
  16396. with the role and secret stored in a Kubernetes Secret resource.
  16397. properties:
  16398. path:
  16399. default: approle
  16400. description: |-
  16401. Path where the App Role authentication backend is mounted
  16402. in Vault, e.g: "approle"
  16403. type: string
  16404. roleId:
  16405. description: |-
  16406. RoleID configured in the App Role authentication backend when setting
  16407. up the authentication backend in Vault.
  16408. type: string
  16409. roleRef:
  16410. description: |-
  16411. Reference to a key in a Secret that contains the App Role ID used
  16412. to authenticate with Vault.
  16413. The `key` field must be specified and denotes which entry within the Secret
  16414. resource is used as the app role id.
  16415. properties:
  16416. key:
  16417. description: |-
  16418. A key in the referenced Secret.
  16419. Some instances of this field may be defaulted, in others it may be required.
  16420. maxLength: 253
  16421. minLength: 1
  16422. pattern: ^[-._a-zA-Z0-9]+$
  16423. type: string
  16424. name:
  16425. description: The name of the Secret resource being referred to.
  16426. maxLength: 253
  16427. minLength: 1
  16428. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16429. type: string
  16430. namespace:
  16431. description: |-
  16432. The namespace of the Secret resource being referred to.
  16433. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16434. maxLength: 63
  16435. minLength: 1
  16436. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16437. type: string
  16438. type: object
  16439. secretRef:
  16440. description: |-
  16441. Reference to a key in a Secret that contains the App Role secret used
  16442. to authenticate with Vault.
  16443. The `key` field must be specified and denotes which entry within the Secret
  16444. resource is used as the app role secret.
  16445. properties:
  16446. key:
  16447. description: |-
  16448. A key in the referenced Secret.
  16449. Some instances of this field may be defaulted, in others it may be required.
  16450. maxLength: 253
  16451. minLength: 1
  16452. pattern: ^[-._a-zA-Z0-9]+$
  16453. type: string
  16454. name:
  16455. description: The name of the Secret resource being referred to.
  16456. maxLength: 253
  16457. minLength: 1
  16458. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16459. type: string
  16460. namespace:
  16461. description: |-
  16462. The namespace of the Secret resource being referred to.
  16463. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16464. maxLength: 63
  16465. minLength: 1
  16466. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16467. type: string
  16468. type: object
  16469. required:
  16470. - path
  16471. - secretRef
  16472. type: object
  16473. cert:
  16474. description: |-
  16475. Cert authenticates with TLS Certificates by passing client certificate, private key and ca certificate
  16476. Cert authentication method
  16477. properties:
  16478. clientCert:
  16479. description: |-
  16480. ClientCert is a certificate to authenticate using the Cert Vault
  16481. authentication method
  16482. properties:
  16483. key:
  16484. description: |-
  16485. A key in the referenced Secret.
  16486. Some instances of this field may be defaulted, in others it may be required.
  16487. maxLength: 253
  16488. minLength: 1
  16489. pattern: ^[-._a-zA-Z0-9]+$
  16490. type: string
  16491. name:
  16492. description: The name of the Secret resource being referred to.
  16493. maxLength: 253
  16494. minLength: 1
  16495. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16496. type: string
  16497. namespace:
  16498. description: |-
  16499. The namespace of the Secret resource being referred to.
  16500. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16501. maxLength: 63
  16502. minLength: 1
  16503. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16504. type: string
  16505. type: object
  16506. secretRef:
  16507. description: |-
  16508. SecretRef to a key in a Secret resource containing client private key to
  16509. authenticate with Vault using the Cert authentication method
  16510. properties:
  16511. key:
  16512. description: |-
  16513. A key in the referenced Secret.
  16514. Some instances of this field may be defaulted, in others it may be required.
  16515. maxLength: 253
  16516. minLength: 1
  16517. pattern: ^[-._a-zA-Z0-9]+$
  16518. type: string
  16519. name:
  16520. description: The name of the Secret resource being referred to.
  16521. maxLength: 253
  16522. minLength: 1
  16523. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16524. type: string
  16525. namespace:
  16526. description: |-
  16527. The namespace of the Secret resource being referred to.
  16528. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16529. maxLength: 63
  16530. minLength: 1
  16531. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16532. type: string
  16533. type: object
  16534. type: object
  16535. iam:
  16536. description: |-
  16537. Iam authenticates with vault by passing a special AWS request signed with AWS IAM credentials
  16538. AWS IAM authentication method
  16539. properties:
  16540. externalID:
  16541. description: AWS External ID set on assumed IAM roles
  16542. type: string
  16543. jwt:
  16544. description: Specify a service account with IRSA enabled
  16545. properties:
  16546. serviceAccountRef:
  16547. description: A reference to a ServiceAccount resource.
  16548. properties:
  16549. audiences:
  16550. description: |-
  16551. Audience specifies the `aud` claim for the service account token
  16552. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16553. then this audiences will be appended to the list
  16554. items:
  16555. type: string
  16556. type: array
  16557. name:
  16558. description: The name of the ServiceAccount resource being referred to.
  16559. maxLength: 253
  16560. minLength: 1
  16561. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16562. type: string
  16563. namespace:
  16564. description: |-
  16565. Namespace of the resource being referred to.
  16566. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16567. maxLength: 63
  16568. minLength: 1
  16569. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16570. type: string
  16571. required:
  16572. - name
  16573. type: object
  16574. type: object
  16575. path:
  16576. description: 'Path where the AWS auth method is enabled in Vault, e.g: "aws"'
  16577. type: string
  16578. region:
  16579. description: AWS region
  16580. type: string
  16581. role:
  16582. description: This is the AWS role to be assumed before talking to vault
  16583. type: string
  16584. secretRef:
  16585. description: Specify credentials in a Secret object
  16586. properties:
  16587. accessKeyIDSecretRef:
  16588. description: The AccessKeyID is used for authentication
  16589. properties:
  16590. key:
  16591. description: |-
  16592. A key in the referenced Secret.
  16593. Some instances of this field may be defaulted, in others it may be required.
  16594. maxLength: 253
  16595. minLength: 1
  16596. pattern: ^[-._a-zA-Z0-9]+$
  16597. type: string
  16598. name:
  16599. description: The name of the Secret resource being referred to.
  16600. maxLength: 253
  16601. minLength: 1
  16602. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16603. type: string
  16604. namespace:
  16605. description: |-
  16606. The namespace of the Secret resource being referred to.
  16607. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16608. maxLength: 63
  16609. minLength: 1
  16610. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16611. type: string
  16612. type: object
  16613. secretAccessKeySecretRef:
  16614. description: The SecretAccessKey is used for authentication
  16615. properties:
  16616. key:
  16617. description: |-
  16618. A key in the referenced Secret.
  16619. Some instances of this field may be defaulted, in others it may be required.
  16620. maxLength: 253
  16621. minLength: 1
  16622. pattern: ^[-._a-zA-Z0-9]+$
  16623. type: string
  16624. name:
  16625. description: The name of the Secret resource being referred to.
  16626. maxLength: 253
  16627. minLength: 1
  16628. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16629. type: string
  16630. namespace:
  16631. description: |-
  16632. The namespace of the Secret resource being referred to.
  16633. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16634. maxLength: 63
  16635. minLength: 1
  16636. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16637. type: string
  16638. type: object
  16639. sessionTokenSecretRef:
  16640. description: |-
  16641. The SessionToken used for authentication
  16642. This must be defined if AccessKeyID and SecretAccessKey are temporary credentials
  16643. see: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_use-resources.html
  16644. properties:
  16645. key:
  16646. description: |-
  16647. A key in the referenced Secret.
  16648. Some instances of this field may be defaulted, in others it may be required.
  16649. maxLength: 253
  16650. minLength: 1
  16651. pattern: ^[-._a-zA-Z0-9]+$
  16652. type: string
  16653. name:
  16654. description: The name of the Secret resource being referred to.
  16655. maxLength: 253
  16656. minLength: 1
  16657. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16658. type: string
  16659. namespace:
  16660. description: |-
  16661. The namespace of the Secret resource being referred to.
  16662. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16663. maxLength: 63
  16664. minLength: 1
  16665. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16666. type: string
  16667. type: object
  16668. type: object
  16669. vaultAwsIamServerID:
  16670. description: 'X-Vault-AWS-IAM-Server-ID is an additional header used by Vault IAM auth method to mitigate against different types of replay attacks. More details here: https://developer.hashicorp.com/vault/docs/auth/aws'
  16671. type: string
  16672. vaultRole:
  16673. description: Vault Role. In vault, a role describes an identity with a set of permissions, groups, or policies you want to attach a user of the secrets engine
  16674. type: string
  16675. required:
  16676. - vaultRole
  16677. type: object
  16678. jwt:
  16679. description: |-
  16680. Jwt authenticates with Vault by passing role and JWT token using the
  16681. JWT/OIDC authentication method
  16682. properties:
  16683. kubernetesServiceAccountToken:
  16684. description: |-
  16685. Optional ServiceAccountToken specifies the Kubernetes service account for which to request
  16686. a token for with the `TokenRequest` API.
  16687. properties:
  16688. audiences:
  16689. description: |-
  16690. Optional audiences field that will be used to request a temporary Kubernetes service
  16691. account token for the service account referenced by `serviceAccountRef`.
  16692. Defaults to a single audience `vault` it not specified.
  16693. Deprecated: use serviceAccountRef.Audiences instead
  16694. items:
  16695. type: string
  16696. type: array
  16697. expirationSeconds:
  16698. description: |-
  16699. Optional expiration time in seconds that will be used to request a temporary
  16700. Kubernetes service account token for the service account referenced by
  16701. `serviceAccountRef`.
  16702. Deprecated: this will be removed in the future.
  16703. Defaults to 10 minutes.
  16704. format: int64
  16705. type: integer
  16706. serviceAccountRef:
  16707. description: Service account field containing the name of a kubernetes ServiceAccount.
  16708. properties:
  16709. audiences:
  16710. description: |-
  16711. Audience specifies the `aud` claim for the service account token
  16712. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16713. then this audiences will be appended to the list
  16714. items:
  16715. type: string
  16716. type: array
  16717. name:
  16718. description: The name of the ServiceAccount resource being referred to.
  16719. maxLength: 253
  16720. minLength: 1
  16721. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16722. type: string
  16723. namespace:
  16724. description: |-
  16725. Namespace of the resource being referred to.
  16726. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16727. maxLength: 63
  16728. minLength: 1
  16729. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16730. type: string
  16731. required:
  16732. - name
  16733. type: object
  16734. required:
  16735. - serviceAccountRef
  16736. type: object
  16737. path:
  16738. default: jwt
  16739. description: |-
  16740. Path where the JWT authentication backend is mounted
  16741. in Vault, e.g: "jwt"
  16742. type: string
  16743. role:
  16744. description: |-
  16745. Role is a JWT role to authenticate using the JWT/OIDC Vault
  16746. authentication method
  16747. type: string
  16748. secretRef:
  16749. description: |-
  16750. Optional SecretRef that refers to a key in a Secret resource containing JWT token to
  16751. authenticate with Vault using the JWT/OIDC authentication method.
  16752. properties:
  16753. key:
  16754. description: |-
  16755. A key in the referenced Secret.
  16756. Some instances of this field may be defaulted, in others it may be required.
  16757. maxLength: 253
  16758. minLength: 1
  16759. pattern: ^[-._a-zA-Z0-9]+$
  16760. type: string
  16761. name:
  16762. description: The name of the Secret resource being referred to.
  16763. maxLength: 253
  16764. minLength: 1
  16765. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16766. type: string
  16767. namespace:
  16768. description: |-
  16769. The namespace of the Secret resource being referred to.
  16770. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16771. maxLength: 63
  16772. minLength: 1
  16773. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16774. type: string
  16775. type: object
  16776. required:
  16777. - path
  16778. type: object
  16779. kubernetes:
  16780. description: |-
  16781. Kubernetes authenticates with Vault by passing the ServiceAccount
  16782. token stored in the named Secret resource to the Vault server.
  16783. properties:
  16784. mountPath:
  16785. default: kubernetes
  16786. description: |-
  16787. Path where the Kubernetes authentication backend is mounted in Vault, e.g:
  16788. "kubernetes"
  16789. type: string
  16790. role:
  16791. description: |-
  16792. A required field containing the Vault Role to assume. A Role binds a
  16793. Kubernetes ServiceAccount with a set of Vault policies.
  16794. type: string
  16795. secretRef:
  16796. description: |-
  16797. Optional secret field containing a Kubernetes ServiceAccount JWT used
  16798. for authenticating with Vault. If a name is specified without a key,
  16799. `token` is the default. If one is not specified, the one bound to
  16800. the controller will be used.
  16801. properties:
  16802. key:
  16803. description: |-
  16804. A key in the referenced Secret.
  16805. Some instances of this field may be defaulted, in others it may be required.
  16806. maxLength: 253
  16807. minLength: 1
  16808. pattern: ^[-._a-zA-Z0-9]+$
  16809. type: string
  16810. name:
  16811. description: The name of the Secret resource being referred to.
  16812. maxLength: 253
  16813. minLength: 1
  16814. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16815. type: string
  16816. namespace:
  16817. description: |-
  16818. The namespace of the Secret resource being referred to.
  16819. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16820. maxLength: 63
  16821. minLength: 1
  16822. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16823. type: string
  16824. type: object
  16825. serviceAccountRef:
  16826. description: |-
  16827. Optional service account field containing the name of a kubernetes ServiceAccount.
  16828. If the service account is specified, the service account secret token JWT will be used
  16829. for authenticating with Vault. If the service account selector is not supplied,
  16830. the secretRef will be used instead.
  16831. properties:
  16832. audiences:
  16833. description: |-
  16834. Audience specifies the `aud` claim for the service account token
  16835. If the service account uses a well-known annotation for e.g. IRSA or GCP Workload Identity
  16836. then this audiences will be appended to the list
  16837. items:
  16838. type: string
  16839. type: array
  16840. name:
  16841. description: The name of the ServiceAccount resource being referred to.
  16842. maxLength: 253
  16843. minLength: 1
  16844. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16845. type: string
  16846. namespace:
  16847. description: |-
  16848. Namespace of the resource being referred to.
  16849. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16850. maxLength: 63
  16851. minLength: 1
  16852. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16853. type: string
  16854. required:
  16855. - name
  16856. type: object
  16857. required:
  16858. - mountPath
  16859. - role
  16860. type: object
  16861. ldap:
  16862. description: |-
  16863. Ldap authenticates with Vault by passing username/password pair using
  16864. the LDAP authentication method
  16865. properties:
  16866. path:
  16867. default: ldap
  16868. description: |-
  16869. Path where the LDAP authentication backend is mounted
  16870. in Vault, e.g: "ldap"
  16871. type: string
  16872. secretRef:
  16873. description: |-
  16874. SecretRef to a key in a Secret resource containing password for the LDAP
  16875. user used to authenticate with Vault using the LDAP authentication
  16876. method
  16877. properties:
  16878. key:
  16879. description: |-
  16880. A key in the referenced Secret.
  16881. Some instances of this field may be defaulted, in others it may be required.
  16882. maxLength: 253
  16883. minLength: 1
  16884. pattern: ^[-._a-zA-Z0-9]+$
  16885. type: string
  16886. name:
  16887. description: The name of the Secret resource being referred to.
  16888. maxLength: 253
  16889. minLength: 1
  16890. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16891. type: string
  16892. namespace:
  16893. description: |-
  16894. The namespace of the Secret resource being referred to.
  16895. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16896. maxLength: 63
  16897. minLength: 1
  16898. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16899. type: string
  16900. type: object
  16901. username:
  16902. description: |-
  16903. Username is a LDAP user name used to authenticate using the LDAP Vault
  16904. authentication method
  16905. type: string
  16906. required:
  16907. - path
  16908. - username
  16909. type: object
  16910. namespace:
  16911. description: |-
  16912. Name of the vault namespace to authenticate to. This can be different than the namespace your secret is in.
  16913. Namespaces is a set of features within Vault Enterprise that allows
  16914. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  16915. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  16916. This will default to Vault.Namespace field if set, or empty otherwise
  16917. type: string
  16918. tokenSecretRef:
  16919. description: TokenSecretRef authenticates with Vault by presenting a token.
  16920. properties:
  16921. key:
  16922. description: |-
  16923. A key in the referenced Secret.
  16924. Some instances of this field may be defaulted, in others it may be required.
  16925. maxLength: 253
  16926. minLength: 1
  16927. pattern: ^[-._a-zA-Z0-9]+$
  16928. type: string
  16929. name:
  16930. description: The name of the Secret resource being referred to.
  16931. maxLength: 253
  16932. minLength: 1
  16933. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16934. type: string
  16935. namespace:
  16936. description: |-
  16937. The namespace of the Secret resource being referred to.
  16938. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16939. maxLength: 63
  16940. minLength: 1
  16941. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16942. type: string
  16943. type: object
  16944. userPass:
  16945. description: UserPass authenticates with Vault by passing username/password pair
  16946. properties:
  16947. path:
  16948. default: user
  16949. description: |-
  16950. Path where the UserPassword authentication backend is mounted
  16951. in Vault, e.g: "user"
  16952. type: string
  16953. secretRef:
  16954. description: |-
  16955. SecretRef to a key in a Secret resource containing password for the
  16956. user used to authenticate with Vault using the UserPass authentication
  16957. method
  16958. properties:
  16959. key:
  16960. description: |-
  16961. A key in the referenced Secret.
  16962. Some instances of this field may be defaulted, in others it may be required.
  16963. maxLength: 253
  16964. minLength: 1
  16965. pattern: ^[-._a-zA-Z0-9]+$
  16966. type: string
  16967. name:
  16968. description: The name of the Secret resource being referred to.
  16969. maxLength: 253
  16970. minLength: 1
  16971. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  16972. type: string
  16973. namespace:
  16974. description: |-
  16975. The namespace of the Secret resource being referred to.
  16976. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  16977. maxLength: 63
  16978. minLength: 1
  16979. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  16980. type: string
  16981. type: object
  16982. username:
  16983. description: |-
  16984. Username is a user name used to authenticate using the UserPass Vault
  16985. authentication method
  16986. type: string
  16987. required:
  16988. - path
  16989. - username
  16990. type: object
  16991. type: object
  16992. caBundle:
  16993. description: |-
  16994. PEM encoded CA bundle used to validate Vault server certificate. Only used
  16995. if the Server URL is using HTTPS protocol. This parameter is ignored for
  16996. plain HTTP protocol connection. If not set the system root certificates
  16997. are used to validate the TLS connection.
  16998. format: byte
  16999. type: string
  17000. caProvider:
  17001. description: The provider for the CA bundle to use to validate Vault server certificate.
  17002. properties:
  17003. key:
  17004. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17005. maxLength: 253
  17006. minLength: 1
  17007. pattern: ^[-._a-zA-Z0-9]+$
  17008. type: string
  17009. name:
  17010. description: The name of the object located at the provider type.
  17011. maxLength: 253
  17012. minLength: 1
  17013. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17014. type: string
  17015. namespace:
  17016. description: |-
  17017. The namespace the Provider type is in.
  17018. Can only be defined when used in a ClusterSecretStore.
  17019. maxLength: 63
  17020. minLength: 1
  17021. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17022. type: string
  17023. type:
  17024. description: The type of provider to use such as "Secret", or "ConfigMap".
  17025. enum:
  17026. - Secret
  17027. - ConfigMap
  17028. type: string
  17029. required:
  17030. - name
  17031. - type
  17032. type: object
  17033. forwardInconsistent:
  17034. description: |-
  17035. ForwardInconsistent tells Vault to forward read-after-write requests to the Vault
  17036. leader instead of simply retrying within a loop. This can increase performance if
  17037. the option is enabled serverside.
  17038. https://www.vaultproject.io/docs/configuration/replication#allow_forwarding_via_header
  17039. type: boolean
  17040. headers:
  17041. additionalProperties:
  17042. type: string
  17043. description: Headers to be added in Vault request
  17044. type: object
  17045. namespace:
  17046. description: |-
  17047. Name of the vault namespace. Namespaces is a set of features within Vault Enterprise that allows
  17048. Vault environments to support Secure Multi-tenancy. e.g: "ns1".
  17049. More about namespaces can be found here https://www.vaultproject.io/docs/enterprise/namespaces
  17050. type: string
  17051. path:
  17052. description: |-
  17053. Path is the mount path of the Vault KV backend endpoint, e.g:
  17054. "secret". The v2 KV secret engine version specific "/data" path suffix
  17055. for fetching secrets from Vault is optional and will be appended
  17056. if not present in specified path.
  17057. type: string
  17058. readYourWrites:
  17059. description: |-
  17060. ReadYourWrites ensures isolated read-after-write semantics by
  17061. providing discovered cluster replication states in each request.
  17062. More information about eventual consistency in Vault can be found here
  17063. https://www.vaultproject.io/docs/enterprise/consistency
  17064. type: boolean
  17065. server:
  17066. description: 'Server is the connection address for the Vault server, e.g: "https://vault.example.com:8200".'
  17067. type: string
  17068. tls:
  17069. description: |-
  17070. The configuration used for client side related TLS communication, when the Vault server
  17071. requires mutual authentication. Only used if the Server URL is using HTTPS protocol.
  17072. This parameter is ignored for plain HTTP protocol connection.
  17073. It's worth noting this configuration is different from the "TLS certificates auth method",
  17074. which is available under the `auth.cert` section.
  17075. properties:
  17076. certSecretRef:
  17077. description: |-
  17078. CertSecretRef is a certificate added to the transport layer
  17079. when communicating with the Vault server.
  17080. If no key for the Secret is specified, external-secret will default to 'tls.crt'.
  17081. properties:
  17082. key:
  17083. description: |-
  17084. A key in the referenced Secret.
  17085. Some instances of this field may be defaulted, in others it may be required.
  17086. maxLength: 253
  17087. minLength: 1
  17088. pattern: ^[-._a-zA-Z0-9]+$
  17089. type: string
  17090. name:
  17091. description: The name of the Secret resource being referred to.
  17092. maxLength: 253
  17093. minLength: 1
  17094. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17095. type: string
  17096. namespace:
  17097. description: |-
  17098. The namespace of the Secret resource being referred to.
  17099. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17100. maxLength: 63
  17101. minLength: 1
  17102. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17103. type: string
  17104. type: object
  17105. keySecretRef:
  17106. description: |-
  17107. KeySecretRef to a key in a Secret resource containing client private key
  17108. added to the transport layer when communicating with the Vault server.
  17109. If no key for the Secret is specified, external-secret will default to 'tls.key'.
  17110. properties:
  17111. key:
  17112. description: |-
  17113. A key in the referenced Secret.
  17114. Some instances of this field may be defaulted, in others it may be required.
  17115. maxLength: 253
  17116. minLength: 1
  17117. pattern: ^[-._a-zA-Z0-9]+$
  17118. type: string
  17119. name:
  17120. description: The name of the Secret resource being referred to.
  17121. maxLength: 253
  17122. minLength: 1
  17123. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17124. type: string
  17125. namespace:
  17126. description: |-
  17127. The namespace of the Secret resource being referred to.
  17128. Ignored if referent is not cluster-scoped, otherwise defaults to the namespace of the referent.
  17129. maxLength: 63
  17130. minLength: 1
  17131. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17132. type: string
  17133. type: object
  17134. type: object
  17135. version:
  17136. default: v2
  17137. description: |-
  17138. Version is the Vault KV secret engine version. This can be either "v1" or
  17139. "v2". Version defaults to "v2".
  17140. enum:
  17141. - v1
  17142. - v2
  17143. type: string
  17144. required:
  17145. - auth
  17146. - server
  17147. type: object
  17148. resultType:
  17149. default: Data
  17150. description: |-
  17151. Result type defines which data is returned from the generator.
  17152. By default it is the "data" section of the Vault API response.
  17153. When using e.g. /auth/token/create the "data" section is empty but
  17154. the "auth" section contains the generated token.
  17155. Please refer to the vault docs regarding the result data structure.
  17156. enum:
  17157. - Data
  17158. - Auth
  17159. type: string
  17160. retrySettings:
  17161. description: Used to configure http retries if failed
  17162. properties:
  17163. maxRetries:
  17164. format: int32
  17165. type: integer
  17166. retryInterval:
  17167. type: string
  17168. type: object
  17169. required:
  17170. - path
  17171. - provider
  17172. type: object
  17173. type: object
  17174. served: true
  17175. storage: true
  17176. subresources:
  17177. status: {}
  17178. conversion:
  17179. strategy: Webhook
  17180. webhook:
  17181. conversionReviewVersions:
  17182. - v1
  17183. clientConfig:
  17184. service:
  17185. name: kubernetes
  17186. namespace: default
  17187. path: /convert
  17188. ---
  17189. apiVersion: apiextensions.k8s.io/v1
  17190. kind: CustomResourceDefinition
  17191. metadata:
  17192. annotations:
  17193. controller-gen.kubebuilder.io/version: v0.16.5
  17194. labels:
  17195. external-secrets.io/component: controller
  17196. name: webhooks.generators.external-secrets.io
  17197. spec:
  17198. group: generators.external-secrets.io
  17199. names:
  17200. categories:
  17201. - external-secrets
  17202. - external-secrets-generators
  17203. kind: Webhook
  17204. listKind: WebhookList
  17205. plural: webhooks
  17206. shortNames:
  17207. - webhookl
  17208. singular: webhook
  17209. scope: Namespaced
  17210. versions:
  17211. - name: v1alpha1
  17212. schema:
  17213. openAPIV3Schema:
  17214. description: |-
  17215. Webhook connects to a third party API server to handle the secrets generation
  17216. configuration parameters in spec.
  17217. You can specify the server, the token, and additional body parameters.
  17218. See documentation for the full API specification for requests and responses.
  17219. properties:
  17220. apiVersion:
  17221. description: |-
  17222. APIVersion defines the versioned schema of this representation of an object.
  17223. Servers should convert recognized schemas to the latest internal value, and
  17224. may reject unrecognized values.
  17225. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
  17226. type: string
  17227. kind:
  17228. description: |-
  17229. Kind is a string value representing the REST resource this object represents.
  17230. Servers may infer this from the endpoint the client submits requests to.
  17231. Cannot be updated.
  17232. In CamelCase.
  17233. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
  17234. type: string
  17235. metadata:
  17236. type: object
  17237. spec:
  17238. description: WebhookSpec controls the behavior of the external generator. Any body parameters should be passed to the server through the parameters field.
  17239. properties:
  17240. body:
  17241. description: Body
  17242. type: string
  17243. caBundle:
  17244. description: |-
  17245. PEM encoded CA bundle used to validate webhook server certificate. Only used
  17246. if the Server URL is using HTTPS protocol. This parameter is ignored for
  17247. plain HTTP protocol connection. If not set the system root certificates
  17248. are used to validate the TLS connection.
  17249. format: byte
  17250. type: string
  17251. caProvider:
  17252. description: The provider for the CA bundle to use to validate webhook server certificate.
  17253. properties:
  17254. key:
  17255. description: The key where the CA certificate can be found in the Secret or ConfigMap.
  17256. maxLength: 253
  17257. minLength: 1
  17258. pattern: ^[-._a-zA-Z0-9]+$
  17259. type: string
  17260. name:
  17261. description: The name of the object located at the provider type.
  17262. maxLength: 253
  17263. minLength: 1
  17264. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17265. type: string
  17266. namespace:
  17267. description: The namespace the Provider type is in.
  17268. maxLength: 63
  17269. minLength: 1
  17270. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?$
  17271. type: string
  17272. type:
  17273. description: The type of provider to use such as "Secret", or "ConfigMap".
  17274. enum:
  17275. - Secret
  17276. - ConfigMap
  17277. type: string
  17278. required:
  17279. - name
  17280. - type
  17281. type: object
  17282. headers:
  17283. additionalProperties:
  17284. type: string
  17285. description: Headers
  17286. type: object
  17287. method:
  17288. description: Webhook Method
  17289. type: string
  17290. result:
  17291. description: Result formatting
  17292. properties:
  17293. jsonPath:
  17294. description: Json path of return value
  17295. type: string
  17296. type: object
  17297. secrets:
  17298. description: |-
  17299. Secrets to fill in templates
  17300. These secrets will be passed to the templating function as key value pairs under the given name
  17301. items:
  17302. properties:
  17303. name:
  17304. description: Name of this secret in templates
  17305. type: string
  17306. secretRef:
  17307. description: Secret ref to fill in credentials
  17308. properties:
  17309. key:
  17310. description: The key where the token is found.
  17311. maxLength: 253
  17312. minLength: 1
  17313. pattern: ^[-._a-zA-Z0-9]+$
  17314. type: string
  17315. name:
  17316. description: The name of the Secret resource being referred to.
  17317. maxLength: 253
  17318. minLength: 1
  17319. pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$
  17320. type: string
  17321. type: object
  17322. required:
  17323. - name
  17324. - secretRef
  17325. type: object
  17326. type: array
  17327. timeout:
  17328. description: Timeout
  17329. type: string
  17330. url:
  17331. description: Webhook url to call
  17332. type: string
  17333. required:
  17334. - result
  17335. - url
  17336. type: object
  17337. type: object
  17338. served: true
  17339. storage: true
  17340. subresources:
  17341. status: {}
  17342. conversion:
  17343. strategy: Webhook
  17344. webhook:
  17345. conversionReviewVersions:
  17346. - v1
  17347. clientConfig:
  17348. service:
  17349. name: kubernetes
  17350. namespace: default
  17351. path: /convert